Communication method and apparatus, computer device, and storage medium
By employing a certificate segmentation mechanism and collaborative signature encryption technology in the bank's server system, the security issues arising from physical hardware access have been resolved, achieving higher security and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-08
- Publication Date
- 2026-03-20
AI Technical Summary
The existing technology of accessing bank servers through physical hardware has low security, which can easily lead to data loss and security incidents.
A certificate segmentation mechanism is adopted to generate and store first and second certificates with different encryption algorithms, including local certificates and cloud certificates. These certificates are used for authentication and communication, and combined with collaborative signature and encryption technology for secure communication.
This improves the security of accessing bank servers, prevents certificate theft, and ensures the security and reliability of communication.
Smart Images

Figure CN114238916B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of big data data access, and in particular to a communication method and device, computer equipment and a storage medium. BACKGROUND
[0002] Banks are one of the important institutions that people need to use in daily life. With the development of network technology, online banking technology has emerged, and users can access the bank's system through the network. As an important system, the bank server needs to ensure the security of the bank server. At present, in order to ensure the security of the bank server, the user needs to use a specific physical hardware as an identity certificate when accessing the bank server. However, the way of accessing the bank server through physical hardware has a high risk of loss, which leads to the occurrence of security incidents.
[0003] Therefore, the current way of accessing the bank server through physical hardware has the following defects: the way of accessing the bank server based on physical hardware is prone to loss, which will lead to the occurrence of security incidents, so this method of communication with the bank has the defect of low security. SUMMARY
[0004] Therefore, it is necessary to provide a communication method, device, computer equipment and storage medium capable of improving the security of accessing the bank server.
[0005] A communication method applied to a cloud server, the method comprising:
[0006] According to the user identity information corresponding to the cloud server, a certificate application request is generated and sent to a target server; the target server is used to generate certificate information according to the user identity information and return; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the encryption algorithm of the first certificate is different from that of the second certificate;
[0007] Obtain the certificate information sent by the target server, store the first certificate and the local certificate, and send the cloud certificate to the target server; the target server is used to store the cloud certificate;
[0008] According to the first certificate and the local certificate, a communication request is sent to the target server; the target server is used to establish a communication connection with the cloud server after the cloud server is verified according to the cloud certificate, the local certificate and the first certificate.
[0009] In one of the embodiments, the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate.
[0010] The certificate information sent by the target server is acquired, the first certificate and the local certificate are stored, and the cloud certificate is sent to the target server.
[0011] The RSA certificate and the SM2 certificate sent by the target server are acquired.
[0012] The RSA certificate and the local SM2 certificate are stored, and the cloud SM2 certificate is sent to the target server; and the target server is configured to store the cloud SM2 certificate.
[0013] In one of the embodiments, the communication request is sent to the target server according to the first certificate and the local certificate, and the communication request includes:
[0014] A hypertext transfer protocol secure (HTTPS) communication request including the RSA certificate and the local SM2 certificate is generated, and the HTTPS communication request is sent to the target server.
[0015] In one of the embodiments, after the communication request is sent to the target server according to the first certificate and the local certificate, the method further includes:
[0016] A transaction request is received, a cooperative signature request is generated according to a transaction message, and the cooperative signature request is sent to the target server; and the target server is configured to send a processing pass result to the cloud server after the cooperative signature request is processed and passed.
[0017] The processing pass result sent by the target server is received, a transaction message signature corresponding to the transaction message is generated, and the transaction message is encrypted to obtain an encrypted transaction message.
[0018] The encrypted transaction message and the transaction message signature are sent to the target server; and the target server is configured to process the transaction message after the encrypted transaction message and the transaction message signature are verified and passed.
[0019] A communication method applied to a target server, the method including:
[0020] The cloud server sends a certificate application request including user identity information, and the target server generates corresponding certificate information according to the user identity information and returns the certificate information to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms; the cloud server stores the first certificate and the local certificate and sends the cloud certificate to the target server;
[0021] The cloud server sends a certificate application request including user identity information, and the target server generates corresponding certificate information according to the user identity information and returns the certificate information to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms; the cloud server stores the first certificate and the local certificate and sends the cloud certificate to the target server;
[0022] The cloud server sends a certificate application request including user identity information, and the target server generates corresponding certificate information according to the user identity information and returns the certificate information to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms; the cloud server stores the first certificate and the local certificate and sends the cloud certificate to the target server;
[0023] In one embodiment, after the communication connection is established with the cloud server when the verification is passed, the method further includes:
[0024] The cloud server sends a collaborative signature request, and the target server sends a processing pass result to the cloud server after processing the system signature request through a secure server interface; the cloud server receives the processing pass result, sends an encrypted transaction message and a transaction message signature to the target server, and establishes a communication connection with the target server when the verification is passed.
[0025] The cloud server sends a collaborative signature request, and the target server sends a processing pass result to the cloud server after processing the system signature request through a secure server interface; the cloud server receives the processing pass result, sends an encrypted transaction message and a transaction message signature to the target server, and establishes a communication connection with the target server when the verification is passed.
[0026] A communication system, the system includes: a cloud server and a target server:
[0027] The cloud server generates a certificate application request according to user identity information corresponding to the cloud server and sends the certificate application request to the target server.
[0028] The cloud server generates a certificate application request according to user identity information corresponding to the cloud server and sends the certificate application request to the target server.
[0029] The cloud server generates a certificate application request according to user identity information corresponding to the cloud server and sends the certificate application request to the target server.
[0030] The cloud server generates a certificate application request according to user identity information corresponding to the cloud server and sends the certificate application request to the target server.
[0031] The cloud server is configured to send a communication request to the target server according to the first certificate and the local certificate.
[0032] The target server is configured to establish a communication connection with the cloud server after passing the verification of the cloud server according to the cloud certificate, the local certificate and the first certificate.
[0033] A communication device applied to a cloud server, the device comprising:
[0034] An application module is configured to generate a certificate application request according to user identity information corresponding to the cloud server and send the request to a target server; the target server is configured to generate certificate information according to the user identity information and return the information; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms;
[0035] An acquisition module is configured to acquire the certificate information sent by the target server, store the first certificate and the local certificate and send the cloud certificate to the target server; the target server is configured to store the cloud certificate;
[0036] A communication module is configured to send a communication request to the target server according to the first certificate and the local certificate; the target server is configured to establish a communication connection with the cloud server after passing the verification of the cloud server according to the cloud certificate, the local certificate and the first certificate.
[0037] In one embodiment, the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate and the cloud certificate is a cloud SM2 certificate.
[0038] The acquisition module is specifically configured to:
[0039] Acquire the RSA certificate and the SM2 certificate sent by the target server;
[0040] Store the RSA certificate and the local SM2 certificate and send the cloud SM2 certificate to the target server; the target server is configured to store the cloud SM2 certificate.
[0041] In one embodiment, the communication module is specifically configured to:
[0042] Generate a hypertext transfer protocol secure communication request including the RSA certificate and the local SM2 certificate and send the request to the target server.
[0043] In one embodiment, the device further comprises a transaction request module for:
[0044] Upon receiving the transaction request, generating a co-signature request according to the transaction message and sending it to the target server; the target server is configured to send a processing pass result to the cloud server after processing the co-signature request;
[0045] Receiving the processing pass result sent by the target server, generating a transaction message signature corresponding to the transaction message and encrypting the transaction message to obtain an encrypted transaction message;
[0046] Sending the encrypted transaction message and the transaction message signature to the target server; the target server is configured to process the transaction message after verifying the encrypted transaction message and the transaction message signature.
[0047] A communication device applied to a target server, the device comprising:
[0048] A receiving module configured to receive a certificate application request sent by a cloud server, the request information including user identity information, generate corresponding certificate information according to the user identity information and return it to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the encryption algorithm of the first certificate is different from that of the second certificate; the cloud server is configured to store the first certificate and the local certificate and send the cloud certificate to the target server;
[0049] A storage module configured to receive the cloud certificate sent by the cloud server and store it;
[0050] A verification module configured to obtain a communication request sent by the cloud server, the request information including the first certificate and the local certificate, verify the cloud certificate, the local certificate and the first certificate, and establish a communication connection with the cloud server when the verification is passed.
[0051] In one embodiment, the device further comprises a transaction processing module for:
[0052] Obtaining a co-signature request sent by the cloud server, processing the system signature request through a secure server interface and sending a processing pass result to the cloud server; the cloud server is configured to receive the processing pass result, send an encrypted transaction message and a transaction message signature to the target server;
[0053] Obtaining the encrypted transaction message and the transaction message signature, decrypting the encrypted transaction message, verifying the decrypted transaction message and the transaction message signature through the secure server interface, and processing the transaction message if the verification is passed.
[0054] A computer device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the steps of the method when executing the computer program.
[0055] A computer readable storage medium having a computer program stored thereon, the computer program implementing the steps of the method when executed by a processor.
[0056] A computer program product comprising a computer program, wherein the computer program implements the steps of the method when executed by a processor.
[0057] The communication method, device, computer device and storage medium described above can achieve the following technical effects compared with the traditional way of accessing the bank system through physical hardware:
[0058] By using the certificate information corresponding to the user identity as the verification basis, and dividing the certificate information into locally stored certificates and cloud-stored certificates, the security of accessing the bank system is improved.
[0059] In addition, the communication request is initiated to the target server by the request information generated based on the RSA certificate and the local SM2 certificate in the embodiment of the present application. Since the certificate information in the cloud server is closely connected with the user identity information of the cloud server, the target server verifies the communication qualification of the cloud server through the certificate-based verification method, thereby improving the security of accessing the bank system. Moreover, the cloud server can communicate with the target server through the collaborative signature, encryption and signature method, thereby improving the security of accessing the bank system. BRIEF DESCRIPTION OF DRAWINGS
[0060] Figure 1 The application environment diagram of the communication method in one embodiment is shown;
[0061] Figure 2 The flowchart of the communication method in one embodiment is shown;
[0062] Figure 3 The flowchart of the communication method in another embodiment is shown;
[0063] Figure 4 The flowchart of the communication method in another embodiment is shown;
[0064] Figure 5 The flowchart of the certificate generation step in one embodiment is shown;
[0065] Figure 6 a flowchart of transaction message processing steps in one embodiment;
[0066] Figure 7 a block diagram of a communication device in one embodiment;
[0067] Figure 8 a block diagram of a communication device in another embodiment;
[0068] Figure 9 an internal block diagram of a computer device in one embodiment. DETAILED DESCRIPTION
[0069] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application. It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solutions of the present application all comply with the relevant provisions of national laws and regulations, and the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, analyzed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. Correspondingly, the present application also provides a corresponding user authorization portal for the user to choose to authorize or choose to refuse.
[0070] The communication method provided by the present application can be applied to an application environment as shown in Figure 1 The cloud server 102 communicates with the target server 104 through the network. The cloud server 102 can send a certificate application to the target server 104 according to the user identity information corresponding to itself, the target server 104 can return corresponding certificate information to the cloud server 102 based on the user identity information, the cloud server 102 can split the certificate information, store part of it locally, and store another part to the target server 104, and the cloud server 102 can also send a communication request to the target server 104 according to the local certificate, and the target server 104 establishes a communication connection with the cloud server 102 after verifying that the certificate is passed. The cloud server 102 and the target server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0071] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, analyzed data, etc.) involved in the present disclosure are all information and data authorized by the user or fully authorized by all parties. Correspondingly, the present disclosure also provides a corresponding user authorization portal for the user to choose to authorize or choose to refuse.
[0072] In one embodiment, as shown in Figure 2 a communication method is provided, which is applied to a cloud server in Figure 1 for example, including the following steps:
[0073] Step S202, generating a certificate application request according to the user identity information corresponding to the cloud server and sending it to the target server; the target server is used to generate certificate information according to the user identity information and return; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the encryption algorithm of the first certificate is different from that of the second certificate.
[0074] Among them, the above-mentioned communication method can be a communication method based on bank system, the cloud server 102 can be a server set in the cloud, such as an enterprise financial system set in the third party public cloud. Because it is set in the public cloud, the cloud server 102 cannot be connected with the bank system by inserting physical hardware. Since the cloud server 102 has corresponding user identity information, when the cloud server 102 needs to be connected with the bank system, the cloud server 102 can generate a corresponding certificate application request based on its own corresponding user identity information and send it to the target server 104, so that the target server 104 can generate corresponding certificate information according to the user identity information and return the certificate information to the cloud server 102. Among them, the public cloud refers to the cloud provided by the third party provider for users to use, which can be used through the Internet, which may be free or low cost, and the core attribute of the public cloud is shared resource service. There are many instances of such clouds, which can provide services in the whole open public network today. The above-mentioned cloud server 102 can be a service user, for example, the enterprise financial system deployed in the third party public cloud directly calls the interface provided by the bank to use the related financial services; the above-mentioned target server 104 can be a bank server, which can be a server corresponding to the bank system, and the bank system can be a service provider, for example, the bank's bank-enterprise direct connection system provides related financial services for enterprises through open interface form. Among them, bank-enterprise direct connection refers to the direct interconnection between enterprise financial system and bank system, and the enterprise financial system directly uses related financial services by calling the Internet interface published by the bank.
[0075] The digital certificate refers to a digital authentication for identifying the identity information of each communication party in Internet communication. People can use it to identify the identity of the other party on the network. The certificate information includes a first certificate and a second certificate, and the second certificate can be divided into a local certificate and a cloud certificate. The first certificate and the second certificate can be certificates obtained by using different encryption algorithms. For example, in an embodiment, the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate. In this embodiment, SM2 is an elliptic curve public key cryptography algorithm issued by the National Cryptography Administration. RSA is an encryption algorithm, and RSA public key cryptography is a cryptographic system that uses different encryption and decryption keys, and it is computationally infeasible to derive the decryption key from the encryption key. The SM2 certificate can be divided into two parts, one part is the local SM2 certificate existing in the cloud server 102, and the other part is the cloud SM2 certificate existing in the target server 104.
[0076] In step S204, the certificate information sent by the target server is obtained, the first certificate and the local certificate are stored, and the cloud certificate is sent to the target server; and the target server is configured to store the cloud certificate.
[0077] The target server 104 can send certificate information generated according to the user identity information of the cloud server 102 to the cloud server 102, wherein the certificate information can include a first certificate and a second certificate, and the second certificate can be divided into a local certificate and a cloud certificate. After the cloud server 102 obtains the certificate information sent by the target server 104, the cloud server 102 can store the first certificate and the local certificate part of the second certificate in the cloud server 102, and send the cloud certificate part of the second certificate to the target server 104. After receiving the cloud certificate, the target server 104 stores it.
[0078] The first certificate can be an RSA certificate, and the second certificate can be an SM2 certificate. The cloud server 102 can store the two types of digital certificates obtained according to different encryption algorithms. For example, in an embodiment, the cloud server 102 obtains the certificate information sent by the target server, stores the first certificate and the local certificate, and sends the cloud certificate to the target server. The cloud server 102 obtains the RSA certificate and the SM2 certificate sent by the target server 104, stores the RSA certificate and the local SM2 certificate, and sends the cloud SM2 certificate to the target server 104. The target server 104 stores the cloud SM2 certificate. In this embodiment, the cloud server 102 obtains the RSA certificate and the SM2 certificate sent by the target server 104. The cloud server 102 can also divide the SM2 certificate into a local SM2 certificate and a cloud SM2 certificate. The cloud server 102 can store the RSA certificate and the local SM2 certificate, and send the cloud SM2 certificate to the target server 104 for storage. The target server 104 can store the cloud SM2 certificate after receiving it. Thus, the risk of copying and moving the file certificate used in the bank-enterprise direct connection service can be prevented. Because the cloud server 102 stores part of the signature certificate information on the bank-enterprise direct connection server, that is, the target server 104, and the other part of the signature certificate is closely associated with the local environment information, the copied signature certificate cannot be used.
[0079] In step S206, a communication request is sent to the target server according to the first certificate and the local certificate. The target server establishes a communication connection with the cloud server after the cloud server is verified according to the cloud certificate, the local certificate, and the first certificate.
[0080] After the cloud server 102 completes the application and storage of the certificate information, the cloud server 102 can establish communication with the target server 104 based on the certificate information. The cloud server 102 can generate a corresponding communication request based on the first certificate and the local certificate in the second certificate, and send the communication request to the target server 104. The target server 104 can verify the communication qualification of the cloud server 102 based on the cloud certificate, the local certificate in the received communication request, and the first certificate, and establish a communication connection with the cloud server 102 after the verification is passed. Thus, the cloud server 102 on the third-party public cloud can communicate with the target server 104 of the bank system with security requirements. After the cloud server 102 and the target server 104 establish a communication connection, the transaction message can be exchanged.
[0081] In the communication method, the target server generates certificate information based on user identity information in a certificate application request sent by the cloud server and returns the certificate information, the cloud server saves a first certificate in the certificate information sent by the target server and a local certificate in a second certificate, and sends the cloud-end certificate in the second certificate to the target server for storage; the cloud server sends a communication request to the target server according to the first certificate and the local certificate, and the target server establishes a communication connection with the cloud server after verifying the cloud server according to the cloud-end certificate, the local certificate and the first certificate. Compared with the traditional way of accessing the bank system through physical hardware, the present application uses certificate information corresponding to the user identity as the verification basis, and divides the certificate information into a locally stored certificate and a cloud-stored certificate, preventing it from being stolen by others and improving the security of accessing the bank system.
[0082] In one embodiment, the communication request is sent to the target server according to the first certificate and the local certificate, including generating a https (Hypertext Transfer Protocol Secure) communication request including the RSA certificate and the local SM2 certificate, and sending the communication request to the target server.
[0083] In the present embodiment, the certificate information received by the cloud server 102 includes a first certificate and a second certificate generated based on different encryption algorithms, and the cloud server 102 can divide the second certificate into a local certificate and a cloud-end certificate, and generate a communication request based on the first certificate and the local certificate and send the communication request to the target server 104. Wherein the first certificate can be an RSA certificate, and the second certificate can be an SM2 certificate, and the cloud server 102 can generate a https (Hypertext Transfer Protocol Secure) communication request including the RSA certificate and the local SM2 certificate, and send the communication request to the target server 104. Thus, the target server 104 can verify the qualification of the cloud server 102 based on the certificates in the received communication request. For example, the target server 104 can determine whether the cloud server 102 passes the verification by verifying the information of the received certificate.
[0084] Through the present embodiment, the cloud server 102 initiates a communication request to the target server 104 based on the request information generated based on the RSA certificate and the local SM2 certificate. Since the certificate information in the cloud server 102 is closely related to the user identity information of the cloud server 102, the target server 104 verifies the communication qualification of the cloud server 102 through the certificate-based verification method, thereby improving the security of accessing the bank system.
[0085] In one embodiment, after sending the communication request to the target server according to the first certificate and the local certificate, the method further includes: receiving a transaction request, generating a co-signature request according to the transaction message, and sending the co-signature request to the target server; the target server is configured to send a processing pass result to the cloud server after processing the co-signature request; receiving the processing pass result sent by the target server, generating a transaction message signature corresponding to the transaction message, and encrypting the transaction message to obtain an encrypted transaction message; sending the encrypted transaction message and the transaction message signature to the target server; and the target server is configured to process the transaction message after verifying the encrypted transaction message and the transaction message signature.
[0086] In this embodiment, after the cloud server 102 and the target server 104 establish a communication connection, the transaction message can be interacted. When the cloud server 102 receives a transaction request, the cloud server 102 can generate a co-signature request according to the transaction message in the transaction request, and send the co-signature request to the target server 104. The target server 104 can process the co-signature request, and send a processing pass result to the cloud server 102 after processing. After the cloud server 102 receives the processing pass result sent by the target server 104, the cloud server 102 can generate a transaction message signature corresponding to the transaction message. The cloud server 102 can also encrypt the transaction message to obtain an encrypted transaction message. For example, the cloud server 102 can encrypt the transaction message by using a 3DES algorithm. The 3DES is a common name of TDEA (Triple Data Encryption Algorithm) block cipher. It is equivalent to applying the DES encryption algorithm three times to each data block. The cloud server 102 can send the encrypted transaction message and the transaction message signature to the target server 104, so that the target server 104 can verify the encrypted transaction message and the transaction message signature, and process the transaction message after verification. For example, the target server 104 can decrypt the encrypted transaction message, and verify the decrypted transaction message and the transaction message signature, so that the target server 104 can process the business logic of the transaction message after the above verification.
[0087] Through this embodiment, the cloud server 102 can communicate with the target server 104 by using the co-signature, encryption and signature, thereby improving the security of accessing the bank system.
[0088] In one embodiment, as shown in Figure 3 , a communication method is provided. The method is applied to a terminal in Figure 1 for example, and includes the following steps:
[0089] Step S302, receiving the certificate application request including user identity information sent by the cloud server, generating corresponding certificate information according to the user identity information and returning to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the encryption algorithm of the first certificate is different from that of the second certificate; the cloud server is used for storing the first certificate and the local certificate and sending the cloud certificate to the target server.
[0090] The cloud server 102 can be a server arranged in the cloud, such as an enterprise financial system arranged in a third-party public cloud. Since it is arranged in a public cloud, the cloud server 102 cannot be connected to the bank system by inserting physical hardware. However, the cloud server 102 has corresponding user identity information, so when the cloud server 102 needs to be connected to the bank system, the cloud server 102 can send a corresponding certificate application request based on its own corresponding user identity information to the target server 104, so that the target server 104 can generate corresponding certificate information according to the user identity information and return the certificate information to the cloud server 102. The public cloud refers to a cloud provided by a third-party provider for users to use. The public cloud can generally be used through the Internet and can be free or low-cost. The core attribute of the public cloud is shared resource service. There are many instances of such clouds that can provide services in the entire open public network today. The above-mentioned cloud server 102 can be a service user, such as an enterprise financial system deployed in a third-party public cloud directly calling an interface provided by a bank through the Internet to use related financial services. The bank system can be a service provider, such as a bank's direct connection system providing related financial services to enterprises through an open interface.
[0091] The digital certificate refers to a digital authentication that marks the identity information of each party in Internet communication. People can use it to identify the identity of the other party on the Internet. The above-mentioned certificate information includes a first certificate and a second certificate, and the second certificate can also be divided into a local certificate and a cloud certificate. The first certificate and the second certificate can be certificates obtained using different encryption algorithms. For example, in an embodiment, the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate. The SM2 certificate can be divided into two parts, one part is the local SM2 certificate existing in the local cloud server 102, and the other part is the cloud SM2 certificate existing in the target server 104.
[0092] Step S304, receiving the cloud certificate sent by the cloud server and storing it.
[0093] The target server 104 can send the certificate information generated according to the user identity information of the cloud server 102 to the cloud server 102, wherein the certificate information can include a first certificate and a second certificate, and the second certificate can be divided into a local certificate and a cloud certificate. After the cloud server 102 obtains the certificate information sent by the target server 104, the cloud server 102 can store the first certificate and the local certificate part of the second certificate in the cloud server 102, and send the cloud certificate part of the second certificate to the target server 104, and the target server 104 stores the cloud certificate after receiving it. The first certificate can be an RSA certificate, and the second certificate can be an SM2 certificate, and the cloud server 102 can store the two digital certificates obtained according to different encryption algorithms. For example, the cloud server 102 can store the RSA certificate and the local SM2 certificate, and send the cloud SM2 certificate to the target server; the target server is used to store the cloud SM2 certificate.
[0094] In step S306, the communication request including the first certificate and the local certificate sent by the cloud server is obtained, the cloud certificate, the local certificate and the first certificate are verified, and when the verification is passed, the communication connection with the cloud server is established.
[0095] After the cloud server 102 completes the application and storage of the above-mentioned certificate information, the cloud server 102 can establish communication with the target server 104 based on the certificate information. The cloud server 102 can generate a corresponding communication request based on the first certificate and the local certificate in the second certificate, and send the communication request to the target server 104. The target server 104 can verify the communication qualification of the cloud server 102 with the cloud certificate stored in the target server 104, the local certificate in the received communication request and the first certificate, and establish a communication connection with the cloud server 102 after the verification is passed, so as to realize the communication between the cloud server 102 on the third-party public cloud and the target server 104 of the bank system with security requirements. After the cloud server 102 and the target server 104 establish the communication connection, the transaction message can be exchanged.
[0096] In the communication method, the target server generates and returns certificate information based on user identity information in a certificate application request sent by the cloud server; the cloud server saves a first certificate in the certificate information sent by the target server and a local certificate in a second certificate, and sends a cloud-end certificate in the second certificate to the target server for storage; the cloud server sends a communication request to the target server according to the first certificate and the local certificate; and the target server establishes a communication connection with the cloud server after verifying the cloud server according to the cloud-end certificate, the local certificate and the first certificate. Compared with the traditional way of accessing a bank system through physical hardware, the present application uses certificate information corresponding to the user identity as the verification basis, and divides the certificate information into a locally stored certificate and a cloud-end stored certificate, thereby preventing the certificate information from being stolen by others and improving the security of accessing the bank system.
[0097] In one embodiment, after the communication connection with the cloud server is established when the verification is passed, the method further includes: obtaining a cooperative signature request sent by the cloud server, sending a processing pass result to the cloud server after processing the signature request through the secure server interface processing system; the cloud server is configured to receive the processing pass result, send an encrypted transaction message and a transaction message signature to the target server; obtain the encrypted transaction message and the transaction message signature, decrypt the encrypted transaction message, verify the decrypted transaction message and the transaction message signature through the secure server interface, and process the transaction message if the verification is passed.
[0098] In the present embodiment, after the cloud server 102 establishes a communication connection with the target server 104, the cloud server 102 and the target server 104 can interact with each other. When the cloud server 102 receives a transaction request, the cloud server 102 can generate a cooperative signature request according to a transaction message in the transaction request, and send the cooperative signature request to the target server 104. The target server 104 can process the cooperative signature request, and send a processing pass result to the cloud server 102 after the processing is passed. For example, the target server 104 can call a secure server interface to process the cooperative signature, and return the result to the cloud server 102. The cloud server 102 can send an encrypted transaction message and a transaction message signature to the target server 104 after receiving the processing pass result. The target server 104 can verify the encrypted transaction message and the transaction message signature, and process the transaction message after the verification is passed. For example, the target server 104 can decrypt the encrypted transaction message, and verify the decrypted transaction message and the transaction message signature through the secure server. Thus, the target server 104 can process the business logic of the transaction message after the verification is passed.
[0099] Through the embodiment, the target server 104 can determine whether the cloud server 102 has the qualification to communicate with the target server 104 by calling the security server to process the co-signature, decrypt the transaction message and verify the signature, thereby improving the security of accessing the bank system.
[0100] In one embodiment, as shown in Figure 4 , Figure 4 is a flowchart of the communication method in another embodiment. The cloud server 102 described above can be an enterprise financial system deployed on a third-party public cloud, that is, a client; and the target server 104 described above can be a bank system, that is, a server. The method includes the following processes: as shown in Figure 4 , the method process includes that the client initiates a request to the server to generate a client certificate, the client initiates to establish a transaction link, and the client initiates a transaction message request, and the server responds to each of the above processes.
[0101] The process of generating the certificate is as shown in Figure 5 , Figure 5 is a flowchart of the certificate generation step in one embodiment. The enterprise financial system deployed on the public cloud initiates a certificate generation request to the bank server. The bank server receives the certificate generation request initiated by the client financial system, calls the certificate system to generate relevant certificate information and returns it to the client financial system, and binds the certificate information with the client identity. The client identity information can be obtained from the certificate generation request described above. The enterprise financial system receives the bank processing result, including the RSA certificate and the SM2 certificate, and the enterprise financial system can store the RSA certificate locally; the SM2 certificate is divided into two parts, one part is stored locally in the financial system, and the other part is stored in the target server. After the enterprise financial system completes the certificate application and storage, it can establish a transaction link with the bank-enterprise direct connection application. For example, the enterprise financial system uses the local RSA certificate information to initiate a request to the bank server to establish a two-way https communication; the bank server verifies the client certificate information, and if the verification is passed, the connection is successfully established.
[0102] After the client of the enterprise financial system completes the establishment of the transaction link, it can interact with the server of the bank system. The interaction process between the client and the server can be as shown in Figure 6 , Figure 6A flowchart of the transaction message processing steps in an embodiment is shown. The server can be in communication connection with a security server, which can be a server set in the bank system for verification. In the transaction message processing process, the client can first perform signature initialization on the transaction message; then initiate a co-signature request to the server; the server calls the security server interface to process the co-signature, and returns the result to the client; after the client obtains the co-signature result, the complete transaction message signature is performed, and the client can use the 3DES algorithm to encrypt the transaction message; the client sends the transaction message encryption result and the transaction message signature result to the server; the server decrypts the encrypted message result, and sends the decryption result and the message signature to the security server for signature verification; if the security server transaction fails, an error result is returned to the client; if the verification is passed, the server can continue to process the transaction message business logic, and returns the result to the client; the client receives the transaction message processing result, and the transaction process ends.
[0103] Through the above embodiment, the certificate information corresponding to the user identity is used as the verification basis, and the certificate information is divided into locally stored certificates and cloud-stored certificates, preventing being stolen by others, improving the security of accessing the bank system, and after establishing the communication link, the transaction message processing can also be realized by verifying the signature and other information of the transaction message, so that the financial system deployed in the third-party public cloud can also be safely and reliably used without using a physical U disk, improving the security of accessing the bank system, and providing protection for enterprises using bank financial services.
[0104] It should be understood that, although Figures 2-6 The steps in the flowchart are displayed in sequence according to the arrows, but these steps are not necessarily executed in sequence according to the arrows. Unless otherwise specified in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, Figures 2-6 At least part of the steps in the flowchart can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with other steps or steps or stages in other steps.
[0105] In one embodiment, a communication system is provided, comprising: a cloud server 102 and a target server 104, wherein:
[0106] The cloud server is configured to generate a certificate application request according to the user identity information corresponding to the cloud server, and send the certificate application request to the target server;
[0107] The target server is configured to receive a certificate application request sent by the cloud server and including user identity information, generate corresponding certificate information according to the user identity information, and return the certificate information to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms.
[0108] The cloud server is configured to store the first certificate and the local certificate, and send the cloud certificate to the target server.
[0109] The target server is configured to store the cloud certificate.
[0110] The cloud server is configured to send a communication request to the target server according to the first certificate and the local certificate.
[0111] The target server is configured to establish a communication connection with the cloud server after the cloud server is verified according to the cloud certificate, the local certificate, and the first certificate.
[0112] The specific limitations of the communication system can refer to the limitations of the communication method described above, and will not be repeated here.
[0113] In one embodiment, as shown in Figure 7 A communication device is provided, including an application module 500, an acquisition module 502, and a communication module 504, wherein:
[0114] The application module 500 is configured to generate a certificate application request according to user identity information corresponding to the cloud server, and send the certificate application request to the target server; the target server is configured to generate certificate information according to the user identity information and return the certificate information; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the first certificate and the second certificate use different encryption algorithms.
[0115] The acquisition module 502 is configured to acquire the certificate information sent by the target server, store the first certificate and the local certificate, and send the cloud certificate to the target server; the target server is configured to store the cloud certificate.
[0116] The communication module 504 is configured to send a communication request to the target server according to the first certificate and the local certificate; the target server is configured to establish a communication connection with the cloud server after the cloud server is verified according to the cloud certificate, the local certificate, and the first certificate.
[0117] In one embodiment, the acquisition module 502 is specifically configured to acquire an RSA certificate and an SM2 certificate sent by the target server; store the RSA certificate and a local SM2 certificate, and send a cloud SM2 certificate to the target server; the target server is configured to store the cloud SM2 certificate.
[0118] In one embodiment, the communication module 504 described above is specifically configured to generate a two-way hypertext transfer protocol secure communication request including an RSA certificate and a local SM2 certificate, and send the request to a target server.
[0119] In one embodiment, the device further includes a transaction request module configured to receive a transaction request, generate a co-signature request according to the transaction message, and send the request to a target server; the target server is configured to send a processing pass result to the cloud server after processing the co-signature request; the cloud server is configured to receive the processing pass result sent by the target server, generate a transaction message signature corresponding to the transaction message, encrypt the transaction message to obtain an encrypted transaction message, and send the encrypted transaction message and the transaction message signature to the target server; and the target server is configured to process the transaction message after verifying the encrypted transaction message and the transaction message signature.
[0120] In one embodiment, as shown in FIG. 6, Figure 8 a communication device is provided, which includes a receiving module 600, a storage module 602, and a verification module 604, wherein:
[0121] The receiving module 600 is configured to receive a certificate application request sent by a cloud server, the request including user identity information, generate corresponding certificate information according to the user identity information, and return the information to the cloud server; the certificate information includes a first certificate and a second certificate; the second certificate includes a local certificate and a cloud certificate; the encryption algorithm of the first certificate is different from that of the second certificate; the cloud server is configured to store the first certificate and the local certificate, and send the cloud certificate to a target server.
[0122] The storage module 602 is configured to receive and store the cloud certificate sent by the cloud server.
[0123] The verification module 604 is configured to obtain a communication request sent by the cloud server, the request including the first certificate and the local certificate, verify the cloud certificate, the local certificate, and the first certificate, and establish a communication connection with the cloud server when the verification is passed.
[0124] In one embodiment, the device further includes a transaction processing module configured to obtain a co-signature request sent by the cloud server, send a processing pass result to the cloud server after processing the signature request through a secure server interface processing system; the cloud server is configured to receive the processing pass result, send an encrypted transaction message and a transaction message signature to a target server; obtain the encrypted transaction message and the transaction message signature, decrypt the encrypted transaction message, verify the decrypted transaction message and the transaction message signature through a secure server interface, and process the transaction message if the verification is passed.
[0125] The specific limitations of the communication device can refer to the limitations of the communication method described above, which will not be repeated here. Each module in the above communication device can be implemented by software, hardware and their combination. The above modules can be embedded in the processor in the computer device in hardware form or independent of the processor in the computer device, or stored in the memory in the computer device in software form, so that the processor can call and execute the operations of the above modules.
[0126] In one embodiment, a computer device is provided, which can be a terminal, and its internal structure diagram can be as shown in Figure 9 The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected by a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved by WIFI, operator network, NFC (near field communication) or other technologies. The computer program is executed by the processor to implement a communication method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.
[0127] Those skilled in the art can understand that Figure 9 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0128] In one embodiment, a computer device is provided, which includes a memory and a processor, and the memory stores a computer program. The processor executes the computer program to implement the above-mentioned communication method.
[0129] In one embodiment, a computer readable storage medium is provided, which stores a computer program. The computer program is executed by the processor to implement the above-mentioned communication method.
[0130] In one embodiment, a computer program product is provided, which includes a computer program. The computer program is executed by the processor to implement the above-mentioned communication method.
[0131] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, storage, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0132] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, but as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.
[0133] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent. It should be pointed out that for those skilled in the art, without departing from the concept of the present application, some modifications and improvements can be made, which are all within the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A communication method, characterized in that, Applied to cloud servers, the method includes: Based on the user identity information corresponding to the cloud server, a certificate application request is generated and sent to the target server; the target server is used to generate certificate information based on the user identity information and return it; the certificate information includes a first certificate and a second certificate. Obtain the certificate information sent by the target server, divide the second certificate into a local certificate and a cloud certificate, store the first certificate and the local certificate, and send the cloud certificate to the target server; the target server is used to store the cloud certificate; the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate; Based on the first certificate and the local certificate, a communication request is sent to the target server, including: using the RSA certificate to initiate a communication request to the target server to establish bidirectional Hypertext Transfer Security Protocol (HTTP) communication; the communication request includes the local certificate; the target server is used to establish a communication connection with the cloud server after verifying the cloud server based on the cloud certificate, the local certificate, and the first certificate. It also includes: generating a collaborative signature request based on a received transaction request containing a transaction message and sending it to the target server; receiving a processing pass result sent by the target server to the cloud server after the collaborative signature request has been successfully processed through the security server interface, generating a transaction message signature corresponding to the transaction message and encrypting the transaction message according to the 3DES algorithm; sending the encrypted transaction message and the transaction message signature to the target server; and the target server processing the transaction message after verifying the decrypted transaction message and the transaction message signature through the security server interface.
2. The method according to claim 1, characterized in that, The step of obtaining the certificate information sent by the target server, dividing the second certificate into a local certificate and a cloud certificate, storing the first certificate and the local certificate, and sending the cloud certificate to the target server includes: Obtain the RSA certificate and SM2 certificate sent by the target server; The RSA certificate and the local SM2 certificate are stored, and the cloud SM2 certificate is sent to the target server; the target server is used to store the cloud SM2 certificate.
3. The method according to claim 2, characterized in that, Sending a communication request to the target server based on the first certificate and the local certificate includes: The generated request information includes a bidirectional Hypertext Transfer Security Protocol (HTTP) communication request for the RSA certificate and the local SM2 certificate, and is sent to the target server.
4. A communication method, characterized in that, Applied to a target server, the method includes: The system receives a certificate application request from a cloud server, including user identity information. Based on the user identity information, it generates corresponding certificate information and returns it to the cloud server. The certificate information includes a first certificate and a second certificate. The cloud server divides the second certificate into a local certificate and a cloud certificate, stores the first certificate and the local certificate, and sends the cloud certificate to the target server. The first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate. Receive and store the cloud certificate sent by the cloud server; Obtaining the request information sent by the cloud server, including the communication request of the first certificate and the local certificate, includes: obtaining the communication request initiated by the cloud server using the RSA certificate to establish bidirectional Hypertext Transfer Security Protocol communication; the communication request includes the local certificate; verifying the cloud certificate, the local certificate and the first certificate, and establishing a communication connection with the cloud server when the verification is successful; It also includes: after processing the collaborative signature request sent by the cloud server through the security server interface, sending a processing pass result to the cloud server, obtaining the encrypted transaction message and transaction message signature sent by the cloud server after receiving the processing pass result, verifying the decrypted transaction message and the transaction message signature through the security server interface, and then processing the transaction message; the encrypted transaction message is encrypted based on the 3DES algorithm.
5. A communication system, characterized in that, The system includes: a cloud server and a target server. The cloud server is used to generate a certificate application request based on the user identity information corresponding to the cloud server and send it to the target server. The target server is configured to receive a certificate application request, including user identity information, sent by the cloud server; generate corresponding certificate information based on the user identity information and return it to the cloud server; the certificate information includes a first certificate and a second certificate. The cloud server is used to divide the second certificate into a local certificate and a cloud certificate, store the first certificate and the local certificate, and send the cloud certificate to the target server; the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate; The target server is used to store the cloud certificate; The cloud server is configured to send a communication request to the target server based on the first certificate and the local certificate, including: initiating a communication request to the target server to establish bidirectional Hypertext Transfer Security Protocol communication using the RSA certificate; the communication request includes the local certificate; The target server is used to establish a communication connection with the cloud server after verifying the cloud server based on the cloud certificate, the local certificate, and the first certificate. The cloud server is used to generate a collaborative signature request based on the received transaction request containing the transaction message and send it to the target server. The target server is used to process the successful processing result of the collaborative signature request and send it to the cloud server through the security server interface; The cloud server is configured to receive the processing result, generate a transaction message signature corresponding to the transaction message, encrypt the transaction message according to the 3DES algorithm, and send the encrypted transaction message and the transaction message signature to the target server. The target server is used to process the transaction message after verifying the decrypted transaction message and the transaction message signature through the security server interface.
6. A communication device, characterized in that, The device, applied to a cloud server, includes: The application module is used to generate a certificate application request based on the user identity information corresponding to the cloud server and send it to the target server; the target server is used to generate certificate information based on the user identity information and return it; the certificate information includes a first certificate and a second certificate; The acquisition module is used to acquire certificate information sent by the target server, divide the second certificate into a local certificate and a cloud certificate, store the first certificate and the local certificate, and send the cloud certificate to the target server; the target server is used to store the cloud certificate; the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate; A communication module is configured to send a communication request to the target server based on the first certificate and the local certificate, including: initiating a communication request to the target server to establish bidirectional Hypertext Transfer Security Protocol (HTTP) communication using the RSA certificate; the communication request includes the local certificate; the target server is configured to establish a communication connection with the cloud server after verifying the cloud server based on the cloud certificate, the local certificate, and the first certificate; It also includes: a transaction request module, used to generate a collaborative signature request based on a received transaction request containing a transaction message and send it to the target server; receive a processing pass result sent by the target server to the cloud server after the collaborative signature request has been successfully processed through the security server interface, generate a transaction message signature corresponding to the transaction message and encrypt the transaction message according to the 3DES algorithm; send the encrypted transaction message and the transaction message signature to the target server; the target server is used to process the transaction message after verifying the decrypted transaction message and the transaction message signature through the security server interface.
7. The apparatus according to claim 6, characterized in that, The acquisition module is specifically used for: Obtain the RSA certificate and SM2 certificate sent by the target server; Store the RSA certificate and the local SM2 certificate, and send the cloud SM2 certificate to the target server; The target server is used to store the cloud-based SM2 certificate.
8. The apparatus according to claim 7, characterized in that, The communication module is specifically used for: The generated request information includes a bidirectional Hypertext Transfer Security Protocol (HTTP) communication request for the RSA certificate and the local SM2 certificate, and is sent to the target server.
9. A communication device, characterized in that, Applied to a target server, the apparatus includes: A receiving module is configured to receive a certificate application request, including user identity information, sent by a cloud server; generate corresponding certificate information based on the user identity information and return it to the cloud server; the certificate information includes a first certificate and a second certificate; the cloud server is configured to divide the second certificate into a local certificate and a cloud certificate, store the first certificate and the local certificate, and send the cloud certificate to the target server; the first certificate is an RSA certificate, the second certificate is an SM2 certificate, the local certificate is a local SM2 certificate, and the cloud certificate is a cloud SM2 certificate; The storage module is used to receive and store the cloud certificate sent by the cloud server. The verification module is used to obtain the communication request information sent by the cloud server, including the first certificate and the local certificate, including: obtaining the communication request initiated by the cloud server using the RSA certificate to establish bidirectional Hypertext Transfer Security Protocol communication; the communication request includes the local certificate; verifying the cloud certificate, the local certificate and the first certificate, and establishing a communication connection with the cloud server when the verification is successful; It also includes: a transaction processing module, used to process the collaborative signature request sent by the cloud server through the security server interface and then send a processing pass result to the cloud server, obtain the encrypted transaction message and transaction message signature sent by the cloud server after receiving the processing pass result, verify the decrypted transaction message and the transaction message signature through the security server interface, and then process the transaction message; the encrypted transaction message is encrypted based on the 3DES algorithm.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Digital certificate storage method, digital certificate storage system, digital certificate reading method and digital certificate reading system
CN103885723A
Certificate receiving method, certificate sending method, transaction system, storage medium and electronic device
CN112766962A