A digital certificate application method and system

By generating universal credentials and decryption factors, and combining biometric verification and encryption algorithms, the security and uniformity issues of physical document management are solved, realizing the digital management and secure application of identity documents, and improving user experience and data protection.

CN113918965BActive Publication Date: 2026-02-10NEW CONTINENT (FUJIAN) PUBLIC SERVICE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202111076068.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-14
Publication Date
2026-02-10
Estimated Expiration
2041-09-14

AI Technical Summary

Technical Problem

In the current technology, physical identity documents are difficult to manage uniformly, and there is a risk of them being stolen and forged. In addition, the information security of electronic identity documents is insufficient, and they cannot be effectively used for user business processing.

Method used

By generating universal credentials and decryption factors, using reading terminals to collect biometric information, and combining this with verification by an identity authentication center, the secure management and application of digital certificate information is achieved. Encryption algorithms and decryption factors are used to protect the key and ensure data security.

Benefits of technology

Effectively prevent identity documents from being misused or forged, ensure data security, simplify business processing procedures, reduce server load, and improve parsing and decryption speed and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113918965B_ABST
    Figure CN113918965B_ABST
Patent Text Reader

Abstract

The application relates to a digital certificate application method, which comprises the following steps: a digital certificate center pre-generates a general voucher and a decryption factor; the general voucher comprises digital certificate information ciphertext and general information, and the general information comprises an identity authentication factor; a reading terminal reads and analyzes the general voucher, obtains the general information, and sends the general information to a business system; and if the business system requests digital certificate information, the reading terminal continues to obtain the digital certificate information and sends the digital certificate information to the business system. The general voucher is generated based on the digital certificate information and the general information, the general voucher is used as a digital carrier for identity certificate management and application, and the risk that an identity certificate is illegally obtained by a criminal through means such as card skimming is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method and system for applying digital certificates, belonging to the field of electronic certificates and real-name authentication. Background Technology

[0002] To facilitate user management, various organizations, institutions, and industries often require users to register with relevant identification documents, such as ID cards, medical insurance cards, and citizen cards. However, physical identification documents are difficult to manage uniformly and are susceptible to risks such as theft and forgery. Currently, there is a lack of effective and secure methods for the unified management and application of documents other than physical identification documents.

[0003] Patent CN109685383A, entitled "An Internet-Based Electronic Certificate Application Management System," includes: an internet computer management platform, an electronic certificate client, an electronic certificate server, and electronic certificate database software. For its usage method, please refer to... Figure 3 This invention includes: users installing an electronic certificate client on their mobile phones and uploading their ID card information to query corresponding registration information and facial image information for registration; the electronic certificate client reviews the information uploaded by the user during registration through the corresponding document in the Internet computer management platform; if the review is successful, it is entered into the electronic certificate database software; the electronic certificate database software associates the information uploaded by the user during registration; the Internet computer management platform sends a registration success command to the electronic certificate client; after successful registration, the registered user's ID card information is displayed on the registered user's mobile phone client. This invention registers various certificates and cards as electronic certificate information in the system, eliminating the need to carry the original documents for inspection or management by authorized departments. However, the storage and transmission of electronic certificate information in this solution do not employ reasonable encryption methods, failing to guarantee the security of electronic certificate information; furthermore, the deployment and interaction methods of the Internet computer management platform, electronic certificate client, electronic certificate server, and electronic certificate database software in the system only facilitate the inspection of ID card information of passing personnel by authorized departments (displaying the ID card information of the registered user to be queried on the electronic certificate server during use), and users cannot use the electronic certificate information to further complete the required business transactions. Summary of the Invention

[0004] To address the problems existing in the prior art, this invention provides a method for applying digital certificates. Based on digital certificate information and general information, a general credential is generated, which serves as a digital carrier for the management and application of identity documents, thus avoiding the risk of identity documents being illegally obtained by criminals through theft or other means.

[0005] The technical solution of the present invention is as follows:

[0006] Technical Solution 1:

[0007] A method for applying digital certificates includes the following steps:

[0008] The digital certificate center pre-generates a general credential and a decryption factor. The general credential includes encrypted digital certificate information and general information, and the general information includes an identity authentication factor.

[0009] The reader terminal reads and parses the general credential to obtain general information and sends it to the business system. If the business system requests digital document information, the reader terminal continues to acquire digital document information and sends it to the business system. The specific steps are as follows:

[0010] The reader collects the user's biometric information and sends the general certificate and the user's biometric information to the digital certificate center.

[0011] The digital certificate center obtains the identity authentication factor from the general credential and sends the identity authentication factor and user biometric information to the identity authentication center; the identity authentication center verifies the identity authentication factor and user biometric information and returns the identity verification result to the digital certificate center; if the identity verification result is successful, the digital certificate center returns the identity verification result and decryption factor to the reader terminal.

[0012] The reading terminal decrypts the ciphertext of the digital certificate information in the general certificate according to the decryption factor, obtains the digital certificate information, and sends it to the business system.

[0013] Furthermore, it also includes: the universal credential and the decryption factor are in one-to-one correspondence; the digital certificate center queries the decryption factor corresponding to the universal credential and returns the decryption factor and identity verification result corresponding to the universal credential to the reading terminal.

[0014] Furthermore, the specific steps for generating the general credential are as follows:

[0015] Obtain digital certificate information and identity authentication factors;

[0016] Generate decryption factors;

[0017] The digital document information and the decryption factor are combined to obtain the first string; the first string is then encrypted using an encryption algorithm to obtain the ciphertext of the digital document information.

[0018] Generate general information based on the identity authentication factors;

[0019] Generate a universal credential based on the encrypted information of the digital document and general information.

[0020] Furthermore, the universal credential is transmitted using a QR code, sound wave, or radio wave as a carrier.

[0021] Furthermore, it also includes encrypting the transmission of the decryption factor, specifically as follows:

[0022] The decryption factor protection key is pre-stored in the reader terminal, and the decryption factor protection key is generated based on the terminal identifier of the reader terminal;

[0023] The reader sends the terminal identifier to the digital document center;

[0024] The digital document center generates a decryption factor protection key based on the terminal identifier, encrypts the decryption factor using the decryption factor protection key, and then sends the decryption factor ciphertext to the reading terminal.

[0025] The reading terminal decrypts the ciphertext of the decryption factor based on the decryption factor protection key to obtain the decryption factor.

[0026] Furthermore, the reading terminal is also equipped with a security module for storing decryption factor protection keys.

[0027] Furthermore, the specific steps for generating the decryption factor protection key are as follows:

[0028] Set a key; perform a one-way irreversible derivation operation on the terminal identifier of the reading terminal based on the root key to obtain a string, and use this string as the decryption factor protection key of the reading terminal.

[0029] Furthermore, it also includes: the digital certificate center records the received general certificate and terminal identifier, and associates the general certificate and terminal identifier.

[0030] Furthermore, it also includes: the digital certificate center recording the recipients and the number of times the decryption factor or decryption factor ciphertext is issued.

[0031] Furthermore, it also includes: a one-to-one correspondence between identity authentication factors and user biometric information; and the identity authentication center verifying the correspondence between the identity authentication factors and user biometric information.

[0032] Technical Solution Two:

[0033] A digital document application system includes a reader terminal, a business system, a digital document center, and an identity authentication center;

[0034] The reading terminal is used to read and parse the general credential, obtain general information, and send it to the business system. The general credential includes encrypted digital document information and general information, and the general information includes an identity authentication factor. When the business system requests digital document information, the reading terminal is also used to collect user biometric information, send the general credential and user biometric information to the digital document center, receive identity verification results and decryption factors, decrypt the encrypted digital document information in the general credential according to the decryption factors, obtain digital document information, and send it to the business system.

[0035] The digital certificate center is used to pre-generate the general certificate, obtain the identity authentication factor in the general certificate, send the identity authentication factor and user biometric information to the identity authentication center, receive the identity verification result returned by the identity authentication center, and if the identity verification result is passed, query the decryption factor corresponding to the general certificate and return the identity verification result and decryption factor to the reading terminal.

[0036] The identity authentication center is used to receive and verify the identity authentication factors and user biometric information, and return the identity verification results to the digital certificate center.

[0037] Furthermore, it also includes: the universal credential and the decryption factor are in one-to-one correspondence; the digital certificate center queries the decryption factor corresponding to the universal credential and returns the decryption factor and identity verification result corresponding to the universal credential to the reading terminal.

[0038] Furthermore, the specific steps for generating the universal credential are as follows:

[0039] Obtain digital certificate information and identity authentication factors;

[0040] Generate decryption factors;

[0041] The digital document information and the decryption factor are combined to obtain a first string; the first string is encrypted using an encryption algorithm to obtain the ciphertext of the digital document information, wherein the ciphertext of the digital document information corresponds one-to-one with the decryption factor;

[0042] Generate general information based on the identity authentication factors;

[0043] Generate a universal credential based on the encrypted information of the digital document and general information.

[0044] Furthermore, the universal credential is transmitted using a QR code, sound wave, or radio wave as a carrier.

[0045] Furthermore, it also includes encrypting the transmission of the decryption factor, specifically as follows:

[0046] The decryption factor protection key is pre-stored in the reader terminal, and the decryption factor protection key is generated based on the terminal identifier of the reader terminal;

[0047] The reader sends the terminal identifier to the digital document center;

[0048] The digital document center generates a decryption factor protection key based on the terminal identifier, encrypts the decryption factor using the decryption factor protection key, and then sends the decryption factor ciphertext to the reading terminal.

[0049] The reading terminal decrypts the ciphertext of the decryption factor based on the decryption factor protection key to obtain the decryption factor.

[0050] Furthermore, the reading terminal is also equipped with a security module for storing decryption factor protection keys.

[0051] Furthermore, the specific steps for generating the decryption factor protection key are as follows:

[0052] Set a key; perform a one-way irreversible derivation operation on the terminal identifier of the reading terminal based on the root key to obtain a string, and use this string as the decryption factor protection key of the reading terminal.

[0053] Furthermore, it also includes: the digital certificate center records the received general certificate and terminal identifier, and associates the general certificate and terminal identifier.

[0054] Furthermore, it also includes: the digital certificate center recording the recipients and the number of times the decryption factor or decryption factor ciphertext is issued.

[0055] Furthermore, it also includes: a one-to-one correspondence between identity authentication factors and user biometric information; and the identity authentication center verifying the correspondence between the identity authentication factors and user biometric information.

[0056] The present invention has the following beneficial effects:

[0057] 1. This invention generates universal credentials based on digital document information and general information. These universal credentials serve as a digital carrier for the management and application of identity documents, avoiding the risk of criminals illegally obtaining identity documents through fraudulent means such as card skimming. Organizations can choose to operate a digital document center independently or collaboratively, managing the generation and parsing of these universal credentials through the center, thereby achieving digital management and application of various types of identity documents. Furthermore, the generation and parsing of universal credentials require the user's consent to obtain their biometric information and verification of the user's identity through an identity authentication center. Therefore, the universal credentials represent the user's true intentions and authentic information, effectively preventing identity document misuse, forgery, or unauthorized use.

[0058] 2. This invention sets different data output mechanisms for digital certificate information and general information in general vouchers: general information with lower data security requirements simplifies its output process and speeds up the processing of general business; digital certificate information with higher data security requirements verifies the user's identity through an identity authentication center and issues the decryption factor corresponding to the general voucher through a digital certificate center to ensure data security.

[0059] 3. This invention utilizes a digital document center to uniformly store the decryption factors corresponding to universal credentials, and uses a reader terminal to complete the parsing and decryption of universal credentials. This eliminates the need for the digital document center to perform parsing and decryption, reducing the server load on the digital document center. The parsing and decryption speed is fast, with strong real-time performance, resulting in a good user experience. For general business transactions that do not require identity authentication, it eliminates the reader terminal's dependence on the network.

[0060] 4. In this invention, the decryption factor corresponds one-to-one with the general certificate, and the data security of the digital certificate information in the general certificate is guaranteed by the decryption factor; moreover, the decryption factors are not related to each other, which can effectively prevent the leakage of all general certificate data due to the cracking of one decryption factor.

[0061] 5. This invention sets a decryption factor protection key and uses an algorithm to ensure that the decryption factor protection key is irreversible. Only reading terminals pre-loaded with the decryption factor protection key can decipher the decryption factor and obtain digital document information, thus ensuring user data security. Even if an attacker illegally controls a legitimate reading terminal and obtains the reading terminal's SN number and decryption factor protection key H, they cannot reverse-engineer the root key K to obtain the decryption factor protection key H of other reading terminals, thus avoiding the leakage of general credential data caused by attackers eavesdropping on / intercepting the communication data of other reading terminals.

[0062] 6. This invention sets up digital certificate information to be parsed online, and records and associates the general certificates, reading terminals and decryption factors issued to the recipients and the number of issuances during the process. Then, based on the records, the specific reading terminals and personnel identities can be traced and located, further strengthening the management of general certificates and ensuring data security. Attached Figure Description

[0063] Figure 1 and Figure 2 This is a flowchart of the present invention;

[0064] Figure 3 This is a schematic diagram of the existing patent "An Internet-based Electronic Certificate Application Management System". Detailed Implementation

[0065] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.

[0066] Example 1

[0067] See Figure 1 and Figure 2 A method for applying digital certificates includes the following steps:

[0068] 1. Users upload digital certificate information and general information (general information includes identity authentication factors and data required for various business processing) to the digital certificate center.

[0069] In this embodiment, the digital document information includes the document number and name of documents such as citizen cards, social security cards, medical insurance cards, public transport cards, and second-generation ID cards. General information includes user age, user consumption records, and user company employee ID. The specific requirements for the above information depend on the operation and management unit of the digital document center. The identity authentication factor is a string of unique identifiers issued to users by the identity authentication center. In this embodiment, it is a string obtained from identity information (such as ID card number) through irreversible operations.

[0070] 2. The digital certificate center uses decryption factors to encrypt the digital certificate information and generates a general credential based on the encrypted digital certificate information and general information (the general credential can be a QR code or other data format suitable for Bluetooth, NFC, and other interaction methods). Each general credential corresponds one-to-one with a decryption factor.

[0071] 3. When a business system (such as a BAS system) requests general information and digital certificate information, the reader terminal reads and parses the general certificate to obtain the general information. The reader terminal has a built-in security module (readers without a security module can only obtain general information), and the security module stores the decryption factor protection key.

[0072] 4. The terminal collects the user's biometric information (face, voice, fingerprint, palm print, etc.).

[0073] 5. The reader sends a general credential, user biometric information, and a terminal identifier (including the reader's serial number, firmware version number, key version number, and security module identifier within the reader) to the digital certificate center.

[0074] 6. The Digital Document Center sends the user's biometric information and identity authentication factor to the Identity Authentication Center. The Identity Authentication Center verifies the identity authentication factor, the user's biometric information, and the correspondence between the identity authentication factor and the user's biometric information, and returns the identity verification result to the Digital Document Center.

[0075] 7. If the identity verification result is successful, the digital certificate center queries the decryption factor corresponding to the general certificate, calculates the decryption factor protection key according to the terminal identifier, encrypts the decryption factor according to the decryption factor protection key, and returns the identity verification result and the decryption factor ciphertext to the reading terminal; otherwise, the digital certificate center only returns the identity verification result to the reading terminal.

[0076] 8. The terminal reads the decryption factor protected key within the security module, decrypts the ciphertext of the decryption factor, and obtains the decryption factor. The decryption factor is then used to decrypt the general credential to obtain the digital document information.

[0077] 9. The reading terminal converts the digital certificate information and general information into a format that the business system can accept before sending it to the business system.

[0078] The beneficial effect of this embodiment is that,

[0079] 1. A universal credential is generated based on digital document information and general information. This universal credential serves as a digital carrier for the management and application of identity documents, avoiding the risk of criminals illegally obtaining identity documents through fraudulent means such as card skimming. Organizations can choose to operate a digital document center independently or collaboratively, managing the generation and parsing of the universal credential through the center, thereby achieving digital management and application of various identity documents. Furthermore, the generation and parsing of the universal credential requires the user's consent to obtain their biometric information and verification of the user's identity through an identity authentication center. Therefore, the universal credential represents the user's true intentions and authentic information, effectively preventing identity document misuse, forgery, or unauthorized use.

[0080] 2. Set different data output mechanisms for digital certificate information and general information in general vouchers: simplify the output process for general information with lower data security requirements and speed up the processing of general business; for digital certificate information with higher data security requirements, verify the user's identity through the identity authentication center and issue the decryption factor corresponding to the general voucher through the digital certificate center to ensure data security.

[0081] 3. By using a digital document center to uniformly store the decryption factors corresponding to universal credentials, and using reader terminals to complete the parsing and decryption of universal credentials, the digital document center is no longer required to perform parsing and decryption of universal credentials, reducing the server load on the digital document center. This results in faster parsing and decryption speeds, stronger real-time performance, and a better user experience. For general business transactions that do not require identity authentication, it eliminates the reader terminals' dependence on the network.

[0082] Example 2

[0083] Furthermore, the steps for generating the general credential are as follows:

[0084] The digital certificate center obtains digital certificate information and general information, and generates a random number, which is used as the decryption factor.

[0085] The digital document center combines the digital document information and decryption factors to obtain the first string. This first string is then encrypted using an encryption algorithm (such as the national cryptographic algorithm) to obtain the ciphertext of the digital document information.

[0086] A general credential is generated based on a general credential identifier (used to uniquely identify a general credential, which can be a one-time token value, timestamp, or other data), encrypted digital document information, and general information. The general credential identifier is then associated with a decryption factor, creating a one-to-one correspondence between the general credential and the decryption factor. The digital document center uses the general credential identifier to query the decryption factor corresponding to that general credential.

[0087] Furthermore, the decryption factor needs to be kept strictly confidential. Therefore, in this embodiment, a corresponding decryption factor protection key is set, and each decryption factor protection key corresponds one-to-one with a reading terminal, ensuring that only designated terminals can obtain the decryption factor. The digital document center and the reading terminal ensure the data security of the decryption factor and the decryption factor protection key by setting up a security module to store the decryption factor protection key.

[0088] The process of reading the terminal by pre-loading the decryption factor protection key is as follows:

[0089] 1. Users submit an application form to the Key Management Center;

[0090] 2. The key management center reviews the user's qualifications and approves them;

[0091] 3. The user brings the reader to the key management center;

[0092] 4. The key management center reviews the application form and registers and verifies the serial number of the reading terminal;

[0093] 5. Connect the reading terminal to the encryption machine in the key management center via a communication cable, run the key download and filling program, and write the decryption factor protection key;

[0094] 6. Perform the terminal key detection process to confirm successful key loading and record the results.

[0095] 7. The reader is returned to the user.

[0096] The decryption factor protection key is generated based on the terminal identifier of the reading terminal (in this embodiment, the terminal identifier is the SN number), and the steps are as follows:

[0097] 1. A key K is installed in the encryption machine of the key management center;

[0098] 2. Enter the serial number (SN) of the reader terminal;

[0099] 3. Perform one-way irreversible derivation operations on the SN number using the root key K, such as hash operations or SM4 cryptographic operations, to obtain the string H;

[0100] 4. Output string H as the decryption factor protection key for this reader terminal.

[0101] The advantage of this embodiment is that:

[0102] 1. Each decryption factor corresponds one-to-one with a general certificate, ensuring the data security of the digital certificate information in the general certificate; and the decryption factors are independent of each other, which can effectively prevent the leakage of all general certificate data due to the cracking of one decryption factor.

[0103] 2. A decryption factor protection key is set, and an algorithm ensures that the decryption factor protection key is irreversible. Only reading terminals pre-loaded with the decryption factor protection key can decipher the decryption factor and obtain digital document information, thus ensuring user data security. Even if an attacker illegally controls a legitimate reading terminal and obtains the reading terminal's SN number and decryption factor protection key H, they cannot reverse-engineer the root key K to obtain the decryption factor protection key H of other reading terminals. This avoids the leakage of general credential data caused by attackers eavesdropping on / intercepting the communication data of other reading terminals.

[0104] Example 3

[0105] In this embodiment, the universal credential is a QR code, which contains an identity authentication factor (i.e., a string of unique identifiers issued by the identity authentication center to employees), encrypted digital document information, and data required for various business transactions.

[0106] The digital certificate center generates a QR code as a universal credential based on the identity authentication factor, encrypted digital certificate information (encrypted employee ID number), and general information (employee ID). This universal credential can be used for daily company access. Employees scan the universal credential at the company's access control device, which only reads the general information within the credential. If an employee needs to conduct a significant transaction, they scan the universal credential at the corresponding reader terminal (which has a security module and pre-loaded with a decryption factor protection key). This reader terminal then retrieves the employee ID and employee ID number through the process described in Example 1.

[0107] Example 4

[0108] Furthermore, the digital document center records the recipients (i.e., terminal identifiers) and the number of times each universal credential and terminal identifier, along with the decryption factor or decryption factor ciphertext, are issued. The digital document center associates the universal credential with the terminal identifier.

[0109] The advancement of this embodiment lies in setting up online parsing of digital certificate information and recording and associating the recipients and issuance times of general certificates, reading terminals, and decryption factors during the process. Subsequently, based on this record, the specific reading terminal and personnel identity can be traced and located, further strengthening the management of general certificates and ensuring data security.

[0110] Example 5

[0111] A digital document application system includes a reader terminal, a business system, a digital document center, and an identity authentication center.

[0112] The reading terminal is used to read and parse the general credential, obtain general information, and send it to the business system. The general credential includes encrypted digital document information and general information, and the general information includes an identity authentication factor. When the business system requests digital document information, the reading terminal is also used to collect user biometric information, send the general credential and user biometric information to the digital document center, receive identity verification results and decryption factors, decrypt the encrypted digital document information in the general credential according to the decryption factors, obtain the digital document information, and send it to the business system.

[0113] The digital certificate center is used to pre-generate the general certificate, obtain the identity authentication factor in the general certificate, send the identity authentication factor and user biometric information to the identity authentication center, receive the identity verification result returned by the identity authentication center, and if the identity verification result is passed, query the decryption factor corresponding to the general certificate and return the identity verification result and decryption factor to the reading terminal.

[0114] The identity authentication center is used to receive and verify the identity authentication factors and user biometric information, and return the identity verification results to the digital certificate center.

[0115] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for applying digital certificates, characterized in that, Includes the following steps: The digital document center pre-generates a general credential and a decryption factor. The digital document center uses the decryption factor to encrypt the digital document information to obtain ciphertext. The general credential includes the ciphertext and general information. The general information includes data required for business processing and does not require encryption. The reader terminal reads and parses the general credential to obtain the general information and sends it to the business system. If the business system requests digital document information, the reader terminal continues to acquire and send the digital document information to the business system. The specific steps are as follows: The reader collects the user's biometric information and sends the general certificate and the user's biometric information to the digital certificate center. The digital certificate center obtains the identity authentication factor from the universal certificate and sends the identity authentication factor and the user's biometric information to the identity authentication center; The identity authentication center verifies the identity authentication factor and the user's biometric information, and returns the identity verification result to the digital document center; if the identity verification result is successful, the digital document center returns the identity verification result and decryption factor to the reading terminal. The reading terminal decrypts the ciphertext of the digital certificate information in the general certificate using a decryption factor, obtains the digital certificate information, and sends it to the business system.

2. The method for applying digital certificates according to claim 1, characterized in that, It also includes encrypting and transmitting the decryption factor, specifically: The decryption factor protection key is pre-stored in the reader terminal, and the decryption factor protection key is generated based on the terminal identifier of the reader terminal; The reader sends the terminal identifier to the digital document center; The digital document center generates a decryption factor protection key based on the terminal identifier, encrypts the decryption factor using the decryption factor protection key, and then sends the decryption factor ciphertext to the reading terminal. The reading terminal decrypts the ciphertext of the decryption factor based on the decryption factor protection key to obtain the decryption factor.

3. A method for applying digital certificates according to any one of claims 1-2, characterized in that, Also includes: The general credential corresponds one-to-one with the decryption factor; the digital certificate center queries the decryption factor corresponding to the general credential and returns the decryption factor and identity verification result corresponding to the general credential to the reading terminal.

4. A method for applying digital certificates according to any one of claims 1-2, characterized in that, The specific steps for generating the general credential are as follows: Obtain digital certificate information and identity authentication factors; Generate decryption factors; The digital document information and the decryption factor are combined to obtain the first string; the first string is then encrypted using an encryption algorithm to obtain the ciphertext of the digital document information. Generate general information based on the identity authentication factors; Generate a universal credential based on the encrypted information of the digital document and general information.

5. A method for applying digital certificates according to any one of claims 1-2, characterized in that, The universal credential is transmitted via QR code, sound wave, or radio wave.

6. A method for applying digital certificates according to any one of claims 1-2, characterized in that, The reading terminal is also equipped with a security module for storing decryption factor protection keys.

7. The method for applying digital certificates according to claim 2, characterized in that, The specific steps for generating the decryption factor protection key are as follows: Set a key; perform a one-way irreversible derivation operation on the terminal identifier of the reading terminal based on the root key to obtain a string, and use this string as the decryption factor protection key of the reading terminal.

8. A method for applying digital certificates according to any one of claims 1-2, characterized in that, Also includes: The digital certificate center records the received general credential and terminal identifier, and associates the general credential with the terminal identifier.

9. A method for applying digital certificates according to any one of claims 1-2, characterized in that, Also includes: The digital certificate center records the recipients and the number of times the decryption factor or decryption factor ciphertext is issued.

10. A method for applying digital certificates according to any one of claims 1-2, characterized in that, Also includes: The identity authentication factor corresponds one-to-one with the user's biometric information; the identity authentication center verifies the correspondence between the identity authentication factor and the user's biometric information.

11. A digital certificate application system, characterized in that, This includes a digital document center, reading terminals, business systems, and an identity authentication center; The digital certificate center pre-generates a general certificate and a decryption factor. The digital certificate center uses the decryption factor to encrypt the digital certificate information to obtain the encrypted digital certificate information. The general certificate includes the encrypted digital certificate information and general information. The general information includes the data required for business processing and does not need to be encrypted. The reading terminal is used to read and parse the general certificate, obtain the general information, and send it to the business system. When the business system requests digital certificate information, the reading terminal continues to obtain digital certificate information and sends it to the business system. The general information also includes identity authentication factors; The identity authentication center is used to receive and verify the identity authentication factors and user biometric information, and return the identity verification results to the digital certificate center. The digital certificate center is also used to obtain the identity authentication factor in the general certificate, send the identity authentication factor and user biometric information to the identity authentication center, receive the identity verification result returned by the identity authentication center, and if the identity verification result is passed, query the decryption factor corresponding to the general certificate and return the identity verification result and decryption factor to the reading terminal. The reader terminal is also used to collect user biometric information, send the identity authentication factor and user biometric information in the general certificate to the digital certificate center, receive the identity verification result and decryption factor, decrypt the ciphertext of digital certificate information in the general certificate according to the decryption factor, obtain the digital certificate information and send it to the business system.

12. A digital certificate application system according to claim 11, characterized in that, It also includes encrypting the transmission of the decryption factor, specifically: The decryption factor protection key is pre-stored in the reader terminal, and the decryption factor protection key is generated based on the terminal identifier of the reader terminal; The reader sends the terminal identifier to the digital document center; The digital document center generates a decryption factor protection key based on the terminal identifier, encrypts the decryption factor using the decryption factor protection key, and then sends the decryption factor ciphertext to the reading terminal. The reading terminal decrypts the ciphertext of the decryption factor based on the decryption factor protection key to obtain the decryption factor.

13. A digital certificate application system according to any one of claims 11-12, characterized in that, Also includes: The general credential corresponds one-to-one with the decryption factor; the digital certificate center queries the decryption factor corresponding to the general credential and returns the decryption factor and identity verification result corresponding to the general credential to the reading terminal.

14. A digital certificate application system according to any one of claims 11-12, characterized in that, The specific steps for generating the universal credential are as follows: Obtain digital certificate information and identity authentication factors; Generate decryption factors; The digital document information and the decryption factor are combined to obtain a first string; the first string is encrypted using an encryption algorithm to obtain the ciphertext of the digital document information, wherein the ciphertext of the digital document information corresponds one-to-one with the decryption factor; Generate general information based on the identity authentication factors; Generate a universal credential based on the encrypted information of the digital document and general information.

15. A digital certificate application system according to any one of claims 11-12, characterized in that, The universal credential is transmitted via QR code, sound wave, or radio wave.

16. A digital certificate application system according to any one of claims 11-12, characterized in that, The reading terminal is also equipped with a security module for storing decryption factor protection keys.

17. A digital certificate application system according to claim 12, characterized in that, The specific steps for generating the decryption factor protection key are as follows: Set a key; perform a one-way irreversible derivation operation on the terminal identifier of the reading terminal based on the root key to obtain a string, and use this string as the decryption factor protection key of the reading terminal.

18. A digital certificate application system according to any one of claims 11-12, characterized in that, Also includes: The digital certificate center records the received general credential and terminal identifier, and associates the general credential with the terminal identifier.

19. A digital certificate application system according to any one of claims 11-12, characterized in that, Also includes: The digital certificate center records the recipients and the number of times the decryption factor or decryption factor ciphertext is issued.

20. A digital certificate application system according to any one of claims 11-12, characterized in that, Also includes: The identity authentication factor corresponds one-to-one with the user's biometric information; the identity authentication center verifies the correspondence between the identity authentication factor and the user's biometric information.

Citation Information

Patent Citations

  • An electronic certificate application management system based on the Internet

    CN109685383A

  • Certificate chain instant messaging system and using method thereof

    CN109600296A

  • Certificate reading method and system for service hall

    CN111538981A

  • Identity card reading system and method based on card body information

    CN111711634A