Transaction processing method and system without background review in asymmetric certificate system

By establishing a two-layer certificate system and a data model in the state without backend audit under the asymmetric certificate system, the problem of no backend audit transactions and low security in the existing technology is solved, and the security of multiple transactions and the authenticity of transaction information is realized.

CN114066453BActive Publication Date: 2025-05-06BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111364443.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-17
Publication Date
2025-05-06
Estimated Expiration
2041-11-17

AI Technical Summary

Technical Problem

The existing technology cannot realize multiple transactions without backend review, and the security is low.

Method used

Establish a two-layer asymmetric certificate system for the backend system and mobile terminals, and verify the authenticity of transaction information through a data model without backend auditing state, using private key signature and public key verification.

Benefits of technology

It realizes multiple transactions without background auditing, while improving the security of transactions and ensuring the authenticity of transaction information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114066453B_ABST
    Figure CN114066453B_ABST
Patent Text Reader

Abstract

The present invention proposes a method and system for processing transactions without background review under an asymmetric certificate system, and relates to the field of information security technology. The method comprises: establishing a double-layer asymmetric certificate system of a background system and each terminal, using two pairs of private keys of the background system to sign a transaction unique identifier and a public key of the terminal respectively, issuing the system public key and the terminal personal certificate to each terminal, so that the terminal can perform transactions without background review, the terminals can exchange personal certificates, use the second system public key to verify the other party's personal certificate, obtain the other party's personal public key, use the first system public key to verify the transaction unique identifier of the transaction data, the transaction initiator uses the personal private key to sign the transaction information, and the transaction counterparty verifies the transaction information based on the personal public key of the transaction initiator, so as to ensure the authenticity of the transaction information in the transaction process without background review, realize multiple transactions and improve the security of the transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method and system for processing transactions without background review in an asymmetric certificate system. Background Art

[0002] This section is intended to provide a background or context to the embodiments of the invention recited in the claims. No admission is made that the description herein is prior art by inclusion in this section.

[0003] In the existing terminal transaction processing process that does not rely on the background transaction system, the terminal application can sign an authorization contract with the system in advance, obtain multiple transaction vouchers and temporarily store them in the terminal application. The transaction initiator can directly present the transaction voucher without connecting to the background when trading. The transaction counterparty can interact with the transaction system to complete the transaction after identifying the transaction voucher. However, this method cannot perform multiple transactions without background review, and has low security.

[0004] To address the above problems, no effective solution has been proposed yet. Summary of the invention

[0005] In order to solve the problems existing in the prior art, the present invention proposes a method and system for processing transactions without background review under an asymmetric certificate system. The present invention establishes a two-layer asymmetric certificate system of a background system and a mobile terminal, and combines the data model in a state without background review. In the transaction process without background review, the transaction initiator terminal uses a private key to sign the transaction unique identifier, and exchanges a public key certificate with the counterparty's terminal. The counterparty terminal uses the public key certificate of the initiator terminal to verify the authenticity of the transaction unique identifier. Thereby verifying the authenticity of the transaction information in the transaction process without background review.

[0006] In a first aspect of an embodiment of the present invention, a method for processing transactions without background review in an asymmetric certificate system is proposed, the method comprising:

[0007] Obtain the personal certificate issued by the backend system; wherein the backend system uses the second system private key S S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal;

[0008] When the first terminal initiates a transaction application, the backend system is notified; wherein the backend system generates a transaction unique identifier based on the initiated transaction application, and uses the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier;

[0009] Get S S1 The signature transaction unique identifier is based on the S S1Sign the transaction unique identifier and variable elements to generate root node information;

[0010] When the first terminal initiates a transaction with the second terminal, the first terminal and the second terminal exchange personal certificates of both parties and use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction based on the variable elements, and append the transaction information of this transaction to the string of the root node information; wherein, the second terminal uses the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ;

[0011] Using the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data;

[0012] The first transaction data is sent to the second terminal; wherein the second terminal uses the personal public key P of the first terminal M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal.

[0013] When the first terminal receives the transaction completion information, the variable elements in the root node information are updated.

[0014] Further, the method comprises:

[0015] When the second terminal initiates a transaction to the third terminal based on the first branch node information, the second terminal exchanges personal certificates with the third terminal and uses the second system public key P S2 Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction based on the variable elements, and append the transaction information of this transaction to the string of the first branch node information; wherein, the third terminal uses the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ;

[0016] Using the personal private key S of the second terminal M2Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data;

[0017] The second transaction data and the personal public key P of the first terminal M1 Sent to the third terminal; wherein the third terminal uses the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal.

[0018] When the second terminal receives the transaction completion information, it updates the variable elements in the first branch node information.

[0019] Furthermore, the background system is configured with at least two pairs of keys, including a first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ;

[0020] Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

[0021] Furthermore, the variable elements at least include:

[0022] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount;

[0023] After the transaction is completed, the updated variable elements also include the transaction status.

[0024] Furthermore, the transaction information at least includes:

[0025] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

[0026] In a second aspect of an embodiment of the present invention, a transaction processing system without background review in an asymmetric certificate system is proposed, the system at least comprising: a first terminal and a second terminal; wherein:

[0027] The first terminal and the second terminal are respectively provided with a certificate receiving module for obtaining a personal certificate issued by the background system; wherein the background system receives the personal certificate according to the private key S of the second system. S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal;

[0028] The notification module of the first terminal is used to notify the backend system when the first terminal initiates a transaction application; wherein the backend system generates a transaction unique identifier according to the initiated transaction application, and uses the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier;

[0029] The root node generation module of the first terminal is used to obtain S S1 The signature transaction unique identifier is based on the S S1 Sign the transaction unique identifier and variable elements to generate root node information;

[0030] When the first terminal initiates a transaction with the second terminal, the certificate exchange module of the first terminal exchanges personal certificates of both parties with the certificate exchange module of the second terminal;

[0031] The certificate verification module of the first terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the end of the character string of the root node information;

[0032] The certificate verification module of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ;

[0033] The signature module of the first terminal is used to use the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data;

[0034] A data sending module of the first terminal, used for sending the first transaction data to the second terminal;

[0035] The transaction processing module of the second terminal is used to use the personal public key P of the first terminal M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction dataS1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal.

[0036] The updating module of the first terminal is used to update the variable elements in the root node information when the first terminal receives the transaction completion information.

[0037] Furthermore, the system also includes: a third terminal; wherein,

[0038] When the second terminal initiates a transaction to the third terminal based on the first branch node information, the certificate exchange module of the second terminal exchanges personal certificates of both parties with the certificate exchange module of the third terminal;

[0039] The certificate verification module of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the string of the first branch node information;

[0040] The certificate verification module of the third terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ;

[0041] The signature module of the second terminal is used to use the personal private key S of the second terminal M2 Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data;

[0042] The data sending module of the second terminal is used to send the second transaction data and the personal public key P of the first terminal M1 Send to a third terminal;

[0043] The transaction processing module of the third terminal is used to use the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal.

[0044] The updating module of the second terminal is used to update the variable elements in the first branch node information when the second terminal receives the transaction completion information.

[0045] Furthermore, the background system is configured with at least two pairs of keys, including a first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ;

[0046] Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

[0047] Furthermore, the variable elements include at least:

[0048] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount;

[0049] After the transaction is completed, the updated variable elements also include the transaction status.

[0050] Furthermore, the transaction information at least includes:

[0051] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

[0052] In a third aspect of an embodiment of the present invention, a computer device is proposed, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, a method for processing transactions without background review under an asymmetric certificate system is implemented.

[0053] In a fourth aspect of an embodiment of the present invention, a computer-readable storage medium is proposed, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, a transaction processing method without background review is implemented in an asymmetric certificate system.

[0054] In a fifth aspect of an embodiment of the present invention, a computer program product is proposed. The computer program product includes a computer program. When the computer program is executed by a processor, a transaction processing method without background review is implemented in an asymmetric certificate system.

[0055] The method and system for processing transactions without background review under an asymmetric certificate system proposed in the present invention establish a two-layer asymmetric certificate system of a background system and each terminal, use two pairs of private keys of the background system to sign the transaction unique identifier and the public key of the terminal respectively, and send the system public key and the terminal personal certificate to each terminal, so that the terminal can conduct transactions without background review. The terminals can exchange personal certificates, use the second system public key to verify the other party's personal certificate, obtain the other party's personal public key, and use the first system public key to verify the transaction unique identifier of the transaction data. The transaction initiator uses the personal private key to sign the transaction information, and the transaction counterparty verifies the transaction information based on the personal public key of the transaction initiator, thereby ensuring the authenticity of the transaction information during the transaction without background review, being able to realize multiple transactions and improving the security of the transaction. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0057] Figure 1 It is a flowchart of a method for processing transactions without background review in an asymmetric certificate system according to an embodiment of the present invention.

[0058] Figure 2 It is a flowchart of a method for processing transactions without background review in an asymmetric certificate system according to another embodiment of the present invention.

[0059] Figure 3 It is a schematic diagram of the architecture of a transaction processing system without background review in an asymmetric certificate system according to an embodiment of the present invention.

[0060] Figure 4 It is a schematic diagram of the architecture of a transaction processing system without background review in an asymmetric certificate system according to another embodiment of the present invention.

[0061] Figure 5 It is a schematic diagram of the structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0062] The principles and spirit of the present invention will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided only to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0063] Those skilled in the art will appreciate that the embodiments of the present invention may be implemented as a system, device, apparatus, method or computer program product. Therefore, the present disclosure may be specifically implemented in the following forms, namely: complete hardware, complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0064] According to an embodiment of the present invention, a method and system for processing transactions without background review in an asymmetric certificate system are proposed, which relate to the field of information security technology.

[0065] In this embodiment, the terms that need to be explained are:

[0066] Anchor: Anchor identifier. The present invention uses Anchor as a unique transaction identifier, which is generated by the background system and has uniqueness, scalability, value, can be transferred between devices, can be identified and authenticated, and can be traced as "transaction identification information".

[0067] Transactions without background review: The two parties can complete the transaction without relying on the background system by transmitting transaction data containing Anchor between devices without the need for background review.

[0068] Multiple transactions without background review: After receiving transaction data containing Anchor without background review, the counterparty can continue trading using the previously received transaction data containing Anchor without connecting to the background system.

[0069] The principle and spirit of the present invention are explained in detail below with reference to several representative embodiments of the present invention.

[0070] Figure 1 FIG. 1 is a flow chart of a method for processing transactions without background review in an asymmetric certificate system according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0071] S101, obtaining a personal certificate issued by the backend system;

[0072] Among them, the background system uses the second system private key S S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal;

[0073] S102, when the first terminal initiates a transaction application, notifying the backend system;

[0074] Among them, the backend system generates a unique transaction identifier based on the initiated transaction application, using the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier;

[0075] S103, obtain S S1 The signature transaction unique identifier is based on the S S1 Sign the transaction unique identifier and variable elements to generate root node information;

[0076] S104, when the first terminal initiates a transaction with the second terminal, the first terminal and the second terminal exchange personal certificates of both parties, using the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the end of the character string of the root node information;

[0077] The second terminal uses the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ;

[0078] S105, using the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data;

[0079] S106, sending the first transaction data to the second terminal;

[0080] The second terminal uses the personal public key P of the first terminal. M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal.

[0081] S107: When the first terminal receives the transaction completion information, it updates the variable elements in the root node information.

[0082] Furthermore, in the absence of background review, the second terminal can continue to trade based on the first branch node, realizing multiple transactions without background review. For specific methods, refer to Figure 2 As shown, the method includes:

[0083] S201, when the second terminal initiates a transaction to the third terminal based on the first branch node information, the second terminal and the third terminal exchange personal certificates of both parties, using the second system public key P S2Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the string of the first branch node information;

[0084] Among them, the third terminal uses the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ;

[0085] It should be noted that each terminal will obtain its own personal certificate in S101, that is, the personal certificate of the third terminal has been obtained in S101.

[0086] S202, using the personal private key S of the second terminal M2 Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data;

[0087] S203, the second transaction data and the personal public key P of the first terminal M1 Send to a third terminal;

[0088] Among them, the third terminal uses the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal.

[0089] S204: When the second terminal receives the transaction completion information, it updates the variable elements in the first branch node information.

[0090] In this embodiment, the background system is configured with at least two pairs of keys, including a first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ;

[0091] Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

[0092] In this embodiment, the variable elements include at least: transaction initiator information, transaction counterparty information, transaction time, and transaction amount;

[0093] After the transaction is completed, the updated variable elements also include the transaction status.

[0094] In actual application scenarios, variable elements can be modified.

[0095] Correspondingly, the transaction information includes at least: transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

[0096] In the root node information, the transaction unique identifier cannot be modified;

[0097] In the first transaction data and the first branch node information, the transaction unique identifier and transaction information (this transaction) cannot be modified;

[0098] In the second transaction data and the second branch node information, the transaction unique identifier and transaction information (historical transaction or current transaction) cannot be modified.

[0099] In order to explain the transaction data processing method without background review more clearly, a specific embodiment is described below.

[0100] Taking users A, B, and C as an example, their corresponding terminals are terminals M1, M2, and M3.

[0101] The personal private key of terminal M1 is S M1 , personal public key is P M1 ;

[0102] The personal private key of terminal M2 is S M2 , personal public key is P M2 ;

[0103] The personal private key of terminal M3 is S M3 , personal public key is P M3 ;

[0104] The backend system is set up with two pairs of keys, the first system private key S S1 , the first system public key P S1 , the second system private key S S2 , the second system public key P S2 ;in,

[0105] The first system private key S S1 Used to sign the transaction unique identifier, the first system public key P S1 Send to each terminal;

[0106] Second system private key S S2The personal public key (P M1 , P M2 , P M3 ) to sign and generate a personal certificate (C M1 , C M2 , C M3 ), the second system public key P S2 And personal certificates are sent to each terminal M1, M2, and M3 respectively.

[0107] When user A initiates a transaction application at terminal M1, the backend system is notified;

[0108] The backend system generates a unique transaction identifier and uses the first system private key S S1 Sign it to get Sign(S S1 ), appended to the end of the string to obtain the original Anchor, as shown in Table 1, which is the structure of the original Anchor; the original Anchor is sent to the terminal M1, and after receiving it, the terminal M1 appends the variable element Factor to become the root node Anchor-A0, as shown in Table 2, which is the structure of the root node Anchor-A0.

[0109] Table 1 Original Anchor structure

[0110] {Anchor <![CDATA[}Sign(S S1 )]]>

[0111] Table 2 Root node Anchor-A0 structure

[0112] Factor {Anchor <![CDATA[}Sign(S S1 )]]>

[0113] In the scenario without background review, user A initiates a transaction request to user B, and the terminals M1 and M2 of both parties exchange certificates C M1 , C M2 , respectively use the second system public key P S2 , verify the authenticity of the other party's certificate and parse the other party's public key P M1 , P M2 ;

[0114] User A inputs the variable factor Factor1 (such as transaction party information, transaction time, transaction amount, etc.); the transaction initiator's terminal M1 appends the transaction information TranInfoA1 of this transaction to the string of the root node Anchor-A0 according to the variable factor, and uses the terminal's personal private key S M1 Sign the original Anchor and transaction information M1 ), get the signature Sign(S M1 )'s transaction data Anchor-A1 (as shown in Table 3) and sends it to the counterparty (terminal M2);

[0115] Table 3 Transaction data Anchor-A1 structure

[0116]

[0117] After receiving the transaction data Anchor-A1, the counterparty's terminal M2 uses the personal public key P of the transaction initiator (terminal M1) M1 Verify the initiator's signature Sign(S M1 ), confirm that the transaction data Anchor-A1 is sent by the transaction initiator and authenticate the authenticity of the transaction information;

[0118] After verification, use the first system public key P S1 Verify the system signature Sign(S S1 ), confirm that the original Anchor is issued by the backend system and authenticate its authenticity;

[0119] After two layers of authentication, the authenticity of the transaction data Anchor-A1 can be authenticated, the transaction is completed, and the transaction data is recorded. The variable factor Factor2 is updated according to the transaction status to obtain the branch node Anchor-B0, and the transaction completion information is replied to the terminal M1; wherein, the structure of Anchor-B0 is shown in Table 4.

[0120] Table 4 Branch node Anchor-B0 structure

[0121]

[0122] When the counterparty terminal M2 continues to use the branch node Anchor-B0 to trade without background review, it exchanges certificates with the next counterparty terminal M3 for identity authentication.

[0123] Terminal M2 can use the second system public key P S2 Verify the personal certificate C of terminal M3 M3 ;

[0124] Terminal M3 can use the second system public key P S2 Verify the personal certificate C of terminal M2 M2 If the verification is successful, the personal public key P of terminal M2 is parsed M2 .

[0125] User B inputs the variable factor Factor3 (such as transaction party information, transaction time, transaction amount, etc.); the transaction initiator's terminal M2 adds the transaction information (TranInfoB1) of this transaction after the string of the branch node Anchor-B0 according to the variable factor, and uses the personal private key S M2Sign and get the signature Sign(S M2 ) and transmits it to the counterparty (terminal M3); at the same time, in order to ensure that terminal M3 can verify the signature, it is also necessary to transmit the personal public key P of terminal M1 M1 ; Among them, the structure of Anchor-B1 is shown in Table 5.

[0126] Table 5 Transaction data Anchor-B1 structure

[0127]

[0128] Terminal M3 acts as a counterparty to verify the transaction; using the personal public key P of terminal M2 M2 Verify the signature Sign(S M2 ), confirm that the transaction data Anchor-B1 is sent by the transaction initiator;

[0129] Then use the personal public key P of terminal M1 M1 Verify the signature Sign(S M1 ), after verification, the first system public key P S1 Verify the signature Sign(S S1 ), confirm that the original Anchor is issued by the backend system and authenticate its authenticity;

[0130] After multiple authentications, the authenticity of the transaction data Anchor-B1 can be authenticated, the transaction is completed, and the transaction data is recorded. The variable factor Factor4 is updated according to the transaction status to obtain the branch node Anchor-C0, and the transaction completion information is replied to the terminal M2; wherein, the structure of Anchor-C0 is shown in Table 6.

[0131] The structure of the branch node Anchor-C0 in Table 6 is as follows:

[0132]

[0133]

[0134] Based on the above-mentioned asymmetric encryption method and the transaction processing flow without background review, the problem of dynamic data authentication in transactions without background review can be solved, thereby ensuring the security of transaction processing.

[0135] It should be noted that, although the operations of the method of the present invention are described in a specific order in the above embodiments and the accompanying drawings, this does not require or imply that the operations must be performed in the specific order, or that all the operations shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0136] After introducing the method of the exemplary embodiment of the present invention, next, refer to Figure 3 to Figure 4 A transaction processing system without background audit in an asymmetric certificate system according to an exemplary embodiment of the present invention is introduced.

[0137] The implementation of the transaction processing system without background audit under the asymmetric certificate system can refer to the implementation of the above method, and the repeated parts will not be repeated. The term "module" or "unit" used below can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0138] Based on the same inventive concept, the present invention also proposes a transaction processing system without background review under an asymmetric certificate system, such as Figure 3 As shown, the system includes: a first terminal 100 and a second terminal 200; wherein,

[0139] The first terminal 100 and the second terminal 200 are respectively provided with a certificate receiving module 110 and a certificate receiving module 210 for obtaining a personal certificate issued by a background system; wherein the background system obtains a personal certificate according to a private key S of the second system. S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal;

[0140] The notification module 120 of the first terminal is used to notify the backend system when the first terminal initiates a transaction application; wherein the backend system generates a transaction unique identifier according to the initiated transaction application, and uses the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier;

[0141] The root node generation module 130 of the first terminal is used to obtain S S1 The signature transaction unique identifier is based on the S S1 Sign the transaction unique identifier and variable elements to generate root node information;

[0142] When the first terminal 100 initiates a transaction with the second terminal 200, the certificate exchange module 140 of the first terminal exchanges personal certificates of both parties with the certificate exchange module 240 of the second terminal;

[0143] The certificate verification module 150 of the first terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the end of the character string of the root node information;

[0144] The certificate verification module 250 of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ;

[0145] The signature module 160 of the first terminal is used to use the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data;

[0146] The data sending module 170 of the first terminal is used to send the first transaction data to the second terminal;

[0147] The transaction processing module 280 of the second terminal is used to use the personal public key P of the first terminal M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal.

[0148] The updating module 190 of the first terminal is used to update the variable elements in the root node information when the first terminal receives the transaction completion information.

[0149] The present invention can realize that during a transaction without background review, the terminals need to authenticate each other's identities through the certificate, and then use the other party's certificate to verify the authenticity of the transaction without background review.

[0150] Based on the present invention, multiple transactions can also be realized without background review. For details, refer to Figure 4 , is a schematic diagram of the architecture of a transaction processing system without background review in an asymmetric certificate system according to another embodiment of the present invention. Figure 4 As shown, the system further includes: a third terminal 300; wherein,

[0151] When the second terminal 200 initiates a transaction to the third terminal 300 based on the first branch node information, the certificate exchange module 240 of the second terminal exchanges personal certificates of both parties with the certificate exchange module 340 of the third terminal;

[0152] The certificate verification module 250 of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the string of the first branch node information;

[0153] The certificate verification module 350 of the third terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ;

[0154] It should be noted that each terminal may include a certificate receiving module, that is, the certificate receiving module 310 of the third terminal is used to obtain a personal certificate issued by the background system.

[0155] The signature module 260 of the second terminal is used to use the personal private key S of the second terminal M2 Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data;

[0156] The data sending module 270 of the second terminal is used to send the second transaction data and the personal public key P of the first terminal to the M1 Send to a third terminal;

[0157] The transaction processing module 380 of the third terminal is used to use the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal.

[0158] The updating module 290 of the second terminal is used to update the variable elements in the first branch node information when the second terminal receives the transaction completion information.

[0159] In this embodiment, the background system is configured with at least two pairs of keys, including a first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ;

[0160] Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

[0161] In this embodiment, the variable elements include at least:

[0162] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount;

[0163] After the transaction is completed, the updated variable elements also include the transaction status.

[0164] Accordingly, the transaction information at least includes:

[0165] Transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

[0166] In this embodiment, refer to Figure 3 and Figure 4 As shown in the figure, each terminal includes a certificate receiving module, a notification module, a root node generation module, a root node generation module, a certificate verification module, a signature module, a data sending module, a transaction processing module, and an update module; the dotted box in the figure indicates that the module does not work during the processing of the above embodiment. In the actual application scenario, each terminal can act as the initiator of the first transaction application, notify the background system, and obtain the private key S of the first system. S1 The signed transaction unique identifier generates a root node, so as to conduct transactions with other terminals. Other terminals can also use branch nodes to conduct transactions, thereby realizing multiple transactions without background review. In addition, the present invention uses multi-layer asymmetric encryption to ensure the verification of the identities of all parties to the transaction and the verification of transaction information, thereby improving transaction security.

[0167] It should be noted that although several modules of the transaction processing system without background audit under the asymmetric certificate system are mentioned in the above detailed description, this division is only exemplary and not mandatory. In fact, according to the embodiment of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided into multiple modules for embodiment.

[0168] Based on the above invention concept, Figure 5As shown, the present invention also proposes a computer device 500, including a memory 510, a processor 520, and a computer program 530 stored in the memory 510 and executable on the processor 520, wherein the processor 520 implements the aforementioned transaction processing method without background review under an asymmetric certificate system when executing the computer program 530.

[0169] Based on the aforementioned inventive concept, the present invention proposes a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the aforementioned method for processing transactions without background review under an asymmetric certificate system is implemented.

[0170] Based on the aforementioned inventive concept, the present invention proposes a computer program product, which includes a computer program. When the computer program is executed by a processor, a transaction processing method without background review is implemented under an asymmetric certificate system.

[0171] The method and system for processing transactions without background review under an asymmetric certificate system proposed in the present invention establish a two-layer asymmetric certificate system of a background system and each terminal, use two pairs of private keys of the background system to sign the transaction unique identifier and the public key of the terminal respectively, and send the system public key and the terminal personal certificate to each terminal, so that the terminal can conduct transactions without background review. The terminals can exchange personal certificates, use the second system public key to verify the other party's personal certificate, obtain the other party's personal public key, and use the first system public key to verify the transaction unique identifier of the transaction data. The transaction initiator uses the personal private key to sign the transaction information, and the transaction counterparty verifies the transaction information based on the personal public key of the transaction initiator, thereby ensuring the authenticity of the transaction information during the transaction without background review, being able to realize multiple transactions and improving the security of the transaction.

[0172] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0173] The present invention is described with reference to flowcharts and / or block diagrams of methods and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0174] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0175] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0176] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A method for processing transactions without background review in an asymmetric certificate system, characterized in that: The method includes: Obtain the personal certificate issued by the background system; wherein the background system uses the second system private key S S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal; When the first terminal initiates a transaction application, the backend system is notified; wherein the backend system generates a transaction unique identifier based on the initiated transaction application, and uses the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier; Get S S1 The signature transaction unique identifier is based on the S S1 Sign the transaction unique identifier and variable elements to generate root node information; When the first terminal initiates a transaction with the second terminal, the first terminal and the second terminal exchange personal certificates of both parties and use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction based on the variable elements, and append the transaction information of this transaction to the string of the root node information; wherein, the second terminal uses the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ; Using the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data; The first transaction data is sent to the second terminal; wherein the second terminal uses the personal public key P of the first terminal M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal. When the first terminal receives the transaction completion information, it updates the variable elements in the root node information; When the second terminal initiates a transaction to the third terminal based on the first branch node information, the second terminal exchanges personal certificates with the third terminal and uses the second system public key P S2 Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction based on the variable elements, and append the transaction information of this transaction to the string of the first branch node information; wherein, the third terminal uses the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ; Using the personal private key S of the second terminal M2 Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data; The second transaction data and the personal public key P of the first terminal M1 Sent to the third terminal; wherein the third terminal uses the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal. When the second terminal receives the transaction completion information, it updates the variable elements in the first branch node information; The variable elements include at least: Transaction initiator information, transaction counterparty information, transaction time, and transaction amount; After the transaction is completed, the updated variable elements also include the transaction status.

2. The method for processing transactions without background review in an asymmetric certificate system according to claim 1, characterized in that: The backend system is configured with at least two pairs of keys, including the first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ; Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

3. The method for processing transactions without background review in an asymmetric certificate system according to claim 1, characterized in that: The transaction information at least includes: Transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

4. A transaction processing system without background review under an asymmetric certificate system, characterized in that: The system at least includes: a first terminal, a second terminal and a third terminal; wherein, The first terminal and the second terminal are respectively provided with a certificate receiving module for obtaining a personal certificate issued by the background system; wherein the background system receives the personal certificate according to the private key S of the second system. S2 Sign the personal public key corresponding to the terminal to obtain the personal certificate of the terminal; The notification module of the first terminal is used to notify the backend system when the first terminal initiates a transaction application; wherein the backend system generates a transaction unique identifier according to the initiated transaction application, and uses the first system private key S S1 Sign the transaction unique identifier and get S S1 Signature transaction unique identifier; The root node generation module of the first terminal is used to obtain S S1 The signature transaction unique identifier is based on the S S1 Sign the transaction unique identifier and variable elements to generate root node information; When the first terminal initiates a transaction with the second terminal, the certificate exchange module of the first terminal exchanges personal certificates of both parties with the certificate exchange module of the second terminal; The certificate verification module of the first terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the end of the character string of the root node information; The certificate verification module of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the first terminal. If the verification is successful, parse the personal public key P of the first terminal. M1 ; The signature module of the first terminal is used to use the personal private key S of the first terminal M1 For S S1 Sign the unique transaction identifier and the transaction information of this transaction to obtain S M1 Signature information, based on variable elements and S M1 The signature information generates first transaction data; A data sending module of the first terminal, used for sending the first transaction data to the second terminal; The transaction processing module of the second terminal is used to use the personal public key P of the first terminal M1 Verify S in the first transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the first transaction data is recorded. The variable elements are updated according to the transaction status, the first branch node information is obtained, and the transaction completion information is replied to the first terminal. An updating module of the first terminal, configured to update the variable elements in the root node information when the first terminal receives the transaction completion information; When the second terminal initiates a transaction to the third terminal based on the first branch node information, the certificate exchange module of the second terminal exchanges personal certificates of both parties with the certificate exchange module of the third terminal; The certificate verification module of the second terminal is used to use the second system public key P S2 Verify the personal certificate of the third terminal. If the verification is successful, collect the variable elements input by the user, obtain the transaction information of this transaction according to the variable elements, and append the transaction information of this transaction to the string of the first branch node information; The certificate verification module of the third terminal is used to use the second system public key P S2 Verify the personal certificate of the second terminal. If the verification is successful, parse the personal public key P of the second terminal. M2 ; The signature module of the second terminal is used to use the personal private key S of the second terminal M2 Sign the first branch node information and the transaction information of this transaction after removing the variable elements to obtain S M2 Signature information, based on variable elements and S M2 The signature information generates second transaction data; The data sending module of the second terminal is used to send the second transaction data and the personal public key P of the first terminal M1 Send to a third terminal; The transaction processing module of the third terminal is used to use the personal public key P of the second terminal M2 Verify S in the second transaction data M2 Signature, if verified, the next step is to use the personal public key P of the first terminal M1 Verify S in the second transaction data M1 Signature, if verified, further use the first system public key P S1 Verify S in the first transaction data S1 Signature. If the verification is successful, the transaction is completed and the second transaction data is recorded. The variable elements are updated according to the transaction status, the second branch node information is obtained, and the transaction completion information is replied to the second terminal. An updating module of the second terminal, configured to update the variable elements in the first branch node information when the second terminal receives the transaction completion information; The variable elements include at least: Transaction initiator information, transaction counterparty information, transaction time, and transaction amount; After the transaction is completed, the updated variable elements also include the transaction status.

5. The transaction processing system without background audit in an asymmetric certificate system according to claim 4, characterized in that: The backend system is configured with at least two pairs of keys, including the first system private key S S1 , the first system public key P S1 , Second system private key S S2 and the second system public key P S2 ; Each terminal is configured with at least one pair of keys, including a personal private key and a personal public key.

6. The transaction processing system without background audit in an asymmetric certificate system according to claim 4, characterized in that: The transaction information at least includes: Transaction initiator information, transaction counterparty information, transaction time, and transaction amount.

7. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 3 is implemented.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

9. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Identity authentication method and system, and computer readable storage medium

    CN108777684A

  • A method of trading via a two-tier coalition chain

    CN109409878A