Decoding method, device, equipment and storage medium based on code engine service component
The code string and decoding type of the graphics identification code are obtained through the code engine service component, and the decoding rules are matched in the preset rule library, which solves the problem of poor universality of the decoding scheme in the prior art, and realizes complex graphics identification code analysis and service information inclusion in various scenarios.
Patent Information
- Application Number
- CN202110343150.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-30
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2041-03-30
AI Technical Summary
The decoding schemes in the prior art are poor in versatility, and the decoding service is subject to specific scenarios. Decoding rules, keys, decryption algorithms, etc. cannot be flexibly configured. The offline decoding device can only process simple QR code content and cannot work normally in an unstable network environment.
The code string and decoding type corresponding to the graphic identification code are obtained through the code engine service component, and the corresponding decoding rules are matched in the preset rule library to perform signature verification and decoding processing. It supports the coexistence settings of multiple decoding rules, which are suitable for a variety of scenarios.
Improve the universality of the decoding process and support the analysis of complex graphic identification code content. The graphic identification code can contain more service information and is suitable for unstable environments in LANs or networks.
Smart Images

Figure CN115150626B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of Internet technology, and are related to, but not limited to, a decoding method, apparatus, device, and storage medium based on a code engine service component. Background Art
[0002] With the rapid development of mobile information technology, the practice of displaying a QR code (or QR code) on a mobile phone, scanning it, and then decoding it to complete a business transaction has become widely used in all aspects of work and life. To protect the security of the information contained in the QR code, the information within the code is often encrypted using specific encoding rules, encryption algorithms, and signature technologies. This requires that the decoding device must be connected to the internet and access a network service that has the decoding rules to complete the decoding and the underlying business logic.
[0003] Offline decoding in related technologies is more common in QR code payment scenarios such as buses and subways. Technically, the QR code scanning device is required to save only one decoding rule, key and algorithm in advance, and must match the QR code displayed on the mobile phone in terms of encoding rules, encryption algorithms and other technologies. The parsed QR code content is simple, generally a set of ID information representing uniqueness. The decoding of the QR code scanning device essentially realizes the accounting function, and ultimately it still needs to periodically connect to the server in the Internet to realize the settlement business.
[0004] It can be seen from this that the decoding solutions in related technologies have poor versatility, and the decoding services are severely restricted by specific scenarios. Different application scenarios require customized development of decoding programs on the scanning device side; and the decoding rules, keys, decryption algorithms, etc. cannot be flexibly configured, and need to be pre-determined and uniquely matched with the encoding rules and encryption algorithms of the code generation service. Summary of the Invention
[0005] Embodiments of the present application provide a decoding method, apparatus, device, and storage medium based on a code engine service component, relating to the field of cloud technology. The code engine service component matches a decoding rule corresponding to the decoding type of a graphic identification code in a preset rule library, and then completes signature verification and decoding processing according to the decoding rule. As the code engine service component is flexible in deployment and independent of the application scenario, it can be applied to a variety of scenarios, improving the versatility of the decoding process.
[0006] The technical solution of the embodiment of the present application is implemented as follows:
[0007] The embodiment of the present application provides a decoding method based on a code engine service component, the method comprising:
[0008] Obtaining, through the code engine service component, a code string corresponding to the graphic identification code sent by the application server and a decoding type corresponding to the graphic identification code;
[0009] Matching a decoding rule corresponding to the decoding type in a preset rule library;
[0010] Performing signature verification and decoding processing on the code string using the decoding rule to obtain a decoding result;
[0011] The decoding result is sent to the application server, so that the application server performs a terminal control operation according to the decoding result.
[0012] The embodiment of the present application provides a decoding system based on a code engine service component, the system comprising: a code scanning device, an application server, and a code engine service component;
[0013] The code scanning device is used to scan and obtain the graphic identification code generated by the code generating terminal, and parse the graphic identification code to obtain a code string; and send the code string to the application server;
[0014] The application server is configured to determine a decoding type corresponding to the graphic identification code according to the code string, and send the code string and the decoding type to the code engine service component;
[0015] The code engine service component is used to match a decoding rule corresponding to the decoding type in a preset rule library; and use the decoding rule to verify and decode the code string to obtain a decoding result; and send the decoding result to the application server so that the application server can perform terminal control operations based on the decoding result.
[0016] The embodiment of the present application provides a decoding device based on a code engine service component, the device comprising:
[0017] An acquisition module, configured to acquire a code string corresponding to a graphic identification code sent by an application server and a decoding type corresponding to the graphic identification code;
[0018] A matching module, configured to match a decoding rule corresponding to the decoding type in a preset rule library;
[0019] A processing module, configured to perform signature verification and decoding processing on the code string using the decoding rule to obtain a decoding result;
[0020] The sending module is used to send the decoding result to the application server, so that the application server performs the terminal control operation according to the decoding result.
[0021] An embodiment of the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium; wherein a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor is used to execute the computer instructions to implement the above-mentioned decoding method based on the code engine service component.
[0022] An embodiment of the present application provides a decoding device based on a code engine service component, comprising: a memory for storing executable instructions; and a processor for implementing the above-mentioned decoding method based on the code engine service component when executing the executable instructions stored in the memory.
[0023] An embodiment of the present application provides a computer-readable storage medium storing executable instructions for causing a processor to execute the executable instructions to implement the above-mentioned decoding method based on the code engine service component.
[0024] The embodiment of the present application has the following beneficial effects: the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code are obtained through the code engine service component; the decoding rule corresponding to the decoding type is matched in the preset rule library; the code string is verified and decoded using the decoding rule to obtain the decoding result, thereby completing the decoding. In this way, since the code engine service component is flexibly deployed and does not depend on the application scenario, the scanning device can access the code engine service component. Therefore, it can be applied to a variety of scenarios, improving the versatility of the decoding process. At the same time, the decoding rules, keys, and decryption algorithms can be flexibly configured in the preset rule library according to the encoding rules and encryption algorithm requirements, supporting the coexistence and use of multiple decoding rules, so that the code engine service component can support complex parsing of the content of the graphic identification code, and the graphic identification code can contain more business information. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is a flowchart of an offline decoding method in related art;
[0026] Figure 2 This is an optional architectural diagram of a decoding system based on a code engine service component provided in an embodiment of the present application;
[0027] Figure 3 Schematic diagram of the structure of a decoding device based on a code engine service component provided in an embodiment of the present application;
[0028] Figure 4 This is an optional flowchart of a decoding method based on a code engine service component provided in an embodiment of the present application;
[0029] Figure 5This is an optional flowchart of a decoding method based on a code engine service component provided in an embodiment of the present application;
[0030] Figure 6 This is an optional flowchart of a decoding method based on a code engine service component provided in an embodiment of the present application;
[0031] Figure 7 This is a schematic diagram of an application scenario of a decoding method based on a code engine service component provided in an embodiment of the present application;
[0032] Figure 8 This is a schematic diagram of an application scenario of a decoding method based on a code engine service component provided in an embodiment of the present application;
[0033] Figure 9 This is an internal decoding logic diagram of the code engine service component provided in an embodiment of the present application;
[0034] Figure 10 This is a schematic diagram of the internal fields of the QR code provided in an embodiment of the present application;
[0035] Figure 11 This is a schematic diagram of the first signature algorithm of the digital dual signature function provided in an embodiment of the present application;
[0036] Figure 12 This is a schematic diagram of the signature verification process corresponding to the first signature algorithm provided in an embodiment of the present application;
[0037] Figure 13 This is a schematic diagram of the second signature algorithm of the digital dual signature function provided in an embodiment of the present application;
[0038] Figure 14 This is a schematic diagram of the signature verification process corresponding to the second signature algorithm provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0040] In the following description, reference is made to "some embodiments," which describe a subset of all possible embodiments. However, it will be understood that "some embodiments" may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict. Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by those skilled in the art to which the embodiments of this application pertain. The terms used in the embodiments of this application are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0041] Before describing the decoding method based on the code engine service component according to the embodiment of the present application, the decoding method based on the code engine service component in the related art is first described:
[0042] At present, offline decoding is more common in scanning payment scenarios such as buses and subways. Technically, the scanning device is required to store only one decoding rule, key and algorithm in advance, and must match the encoding rule, encryption algorithm and other technical aspects of the QR code displayed on the mobile phone. The parsed QR code content is simple, generally a set of unique ID information. The decoding of the scanning device essentially realizes the accounting function, and ultimately it still needs to periodically connect to the server in the Internet to realize the settlement business. Figure 1 The figure shows a flowchart of an offline decoding method in the related art. A code generation service 101 generates a code based on encoding rules and an encryption algorithm 102 via a network 103. The generated QR code is then displayed on a mobile phone 104. The mobile phone 104 then displays the code and a scanning device 105 scans the QR code. The scanning device 105 decodes the code based on pre-stored decoding rules, a key, and a decoding algorithm 106, and sends the decoded result to an accounting service 107. The encoding rules and encryption algorithm 102 uniquely correspond to the decoding rules, key, and decoding algorithm 106. After obtaining the decoded result, the accounting service 107 stores the ID information contained in the decoded result. Simultaneously, when the network is functioning properly, the accounting service 107 periodically connects to the network 103 to synchronize data, enabling the debit service 108 to connect to the network 103 to debit the account.
[0043] However, the technical solutions of related technologies have poor versatility, and the decoding services are severely restricted by specific scenarios. Different application scenarios require customized development of decoding programs on the scanning device side; and the decoding rules, keys, decryption algorithms, etc. cannot be flexibly configured, and need to be pre-determined and uniquely matched with the encoding rules and encryption algorithms of the code generation service; at the same time, in an offline environment, the scanning device side can only process QR codes with relatively simple content. For example, the content of the payment scene code is generally only ID information; and it cannot be completely offline, and periodic networking and business system data synchronization are required to ensure data consistency between businesses, which leads to poor timeliness of the business and errors can only be discovered after the fact.
[0044] Based on the above-mentioned problems existing in the related technologies, the embodiments of the present application provide a decoding method based on a code engine service component. The method implements offline decoding technology based on the code engine service component. The method is to set a variety of different parsing rules, decryption algorithms and signature verification technologies in the code engine service component, and deploy it on the same server or the same local area network environment as the code scanning device in the form of a technical component or engine service, providing the code scanning device with a variety of rules and complex content decoding services, thereby solving the problem that the code scanning device can only parse specific graphic identification codes and must be connected to the Internet for decoding. The method provided in the embodiments of the present application, through the offline decoding technology based on the code engine service component, can effectively solve the code usage business scenarios such as hospitals and access control that require the use of local area networks or unstable network environments.
[0045] The decoding method based on the code engine service component provided in the embodiment of the present application first obtains the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code through the code engine service component; then, matches the decoding rule corresponding to the decoding type in the preset rule library; finally, uses the decoding rule to verify and decode the code string to obtain a decoding result; and sends the decoding result to the application server so that the application server can perform terminal control operations based on the decoding result. In this way, since the code engine service component is flexibly deployed and does not depend on the application scenario, the scanning device can access the code engine service component. Therefore, it can be applied to various scenarios, improving the versatility of the decoding process solution. At the same time, the decoding rules, keys, and decryption algorithms can be flexibly configured in the preset rule library according to the encoding rules and encryption algorithm requirements, supporting the coexistence and use of multiple decoding rules, so that the code engine service component can support complex parsing of the graphic identification code content, and the graphic identification code can contain more business information.
[0046] The following describes an exemplary application of a decoding device based on a code engine service component according to an embodiment of the present application. In one implementation, the decoding device based on a code engine service component according to an embodiment of the present application can be implemented as any terminal with data processing and data storage capabilities, such as a laptop computer, a tablet computer, a desktop computer, a mobile device (e.g., a mobile phone, a portable music player, a personal digital assistant, a dedicated messaging device, a portable gaming device), or an intelligent robot. In another implementation, the decoding device based on a code engine service component according to an embodiment of the present application can also be implemented as a server in which the code engine service component is deployed. The following describes an exemplary application of a decoding device based on a code engine service component implemented as a server in which the code engine service component is deployed.
[0047] See also Figure 2 , Figure 2This is an optional architectural diagram of a decoding system 10 based on a code engine service component provided in an embodiment of the present application. In order to achieve accurate decoding of the graphic identification code generated by the code generation terminal in different environments, the decoding system 10 based on the code engine service component provided in an embodiment of the present application includes a code generation terminal 100, a code scanning device 200, an application server 300, and a code engine service component 400. The code generation terminal 100 has a code generation service. The code generation terminal 100 generates a graphic identification code through the code generation service and displays the code in front of the code scanning device 200 so that the code scanning device 200 scans the graphic identification code. After the code scanning device 200 scans and obtains the graphic identification code generated by the code generation terminal, it parses the graphic identification code to obtain a code string and sends the code string to the application server 300. The application server 300 refers to a server for a business application that provides the code generation service and decoding service. For example, in an access control scenario, the application server 300 can be a server for an access control application. The application server 300 determines the decoding type corresponding to the graphic identification code based on the code string, and sends the code string and decoding type to the code engine service component 400. After receiving the code string and decoding type, the code engine service component 400 matches the decoding rule corresponding to the decoding type in the preset rule library, and uses the decoding rule to verify the signature and decode the code string to obtain a decoding result. The decoding result is sent to the application server 300. The application server 300 performs terminal control operations based on the decoding result, for example, generating a control instruction to control the opening of a gate valve, and sends the control instruction to the gate valve (not shown in the figure).
[0048] In an embodiment of the present application, the application server 300 and the code engine service component 400 can be deployed as two independent components in the same server, or the application server 300 and the code engine service component 400 can be deployed separately, that is, the application server 300 is independent of the server on which the code engine service component 400 is deployed, and the code engine service component 400 can be applied to any business application as an independent service component.
[0049] In the embodiment of the present application, the decoding and business processing logic are completely decoupled through the code engine service component 400, that is, the decoding processing is performed through the code engine service component 400, and the business processing logic of the business application is implemented through the application server 300. The application server 300 and the code engine service component 400 can interact through the interface service mode, thereby realizing the offline decoding function.
[0050] The decoding method based on the code engine service component provided in the embodiments of the present application can also be implemented on a cloud platform and through cloud technology. For example, the server used to deploy the code engine service component can be a cloud server, and the code engine service component can be detected and updated by the cloud server. For example, the cloud server can import rules, update rules, and other processes into the preset rule library of the code engine service component to ensure that the preset rule library stores sufficient and up-to-date decoding rules. Alternatively, a cloud storage can be provided, and the decoding rules in the preset rule library can be stored in the cloud storage, or the latest decoding rules to be updated to the preset rule library can be stored in the cloud storage. In this way, when the code engine service component is online, the latest decoding rules can be directly obtained from the cloud storage and the decoding rules in the preset rule library can be updated using the obtained latest decoding rules; alternatively, the preset rule library can be regularly updated through the cloud storage.
[0051] It's important to note that cloud technology refers to a managed technology that unifies hardware, software, and network resources within a wide or local area network (WAN) to enable data computing, storage, processing, and sharing. Cloud technology is a general term for network, information technology, integration technology, management platform technology, and application technology, all based on the cloud computing business model. It can form a resource pool for on-demand, flexible, and convenient use. Cloud computing will become a crucial support. Backend services for technical network systems, such as those for video sites, image sites, and more portals, require significant computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identifier, requiring transmission to backend systems for logical processing. Data of varying levels will be processed separately, and data from all industries will require robust system support, which can only be achieved through cloud computing.
[0052] Figure 3 is a structural diagram of a decoding device based on a code engine service component provided in an embodiment of the present application, Figure 3 The decoding device based on the code engine service component shown includes: at least one processor 310, a memory 350, at least one network interface 320, and a user interface 330. The various components in the decoding device based on the code engine service component are coupled together via a bus system 340. It is understood that the bus system 340 is used to achieve connection and communication between these components. In addition to including a data bus, the bus system 340 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, the bus system 340 is not described in detail. Figure 3 Various buses are labeled as bus system 340 .
[0053] The processor 310 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.
[0054] The user interface 330 includes one or more output devices 331 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 330 also includes one or more input devices 332, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.
[0055] The memory 350 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, and the like. The memory 350 may optionally include one or more storage devices physically remote from the processor 310. The memory 350 may include volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), and volatile memory may be random access memory (RAM). The memory 350 described in the embodiments of the present application is intended to include any suitable type of memory. In some embodiments, the memory 350 is capable of storing data to support various operations. Examples of such data include programs, modules, and data structures, or subsets or supersets thereof, as exemplified below.
[0056] Operating system 351, including system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and process hardware-based tasks;
[0057] A network communication module 352 for reaching other computing devices via one or more (wired or wireless) network interfaces 320 , exemplary network interfaces 320 including Bluetooth, WiFi, and USB;
[0058] The input processing module 353 is configured to detect one or more user inputs or interactions from one of the one or more input devices 332 and to translate the detected inputs or interactions.
[0059] In some embodiments, the apparatus provided in the embodiments of the present application may be implemented in software. Figure 3 A decoding device 354 based on a code engine service component stored in memory 350 is shown. This decoding device 354 based on a code engine service component can be a decoding device based on a code engine service component. It can be software in the form of a program or plug-in, and includes the following software modules: an acquisition module 3541, a matching module 3542, a processing module 3543, and a sending module 3544. These modules are logical and can be arbitrarily combined or further separated according to the functions they implement. The functions of each module are described below.
[0060] In other embodiments, the apparatus provided in the embodiments of the present application may be implemented in hardware. As an example, the apparatus provided in the embodiments of the present application may be a processor in the form of a hardware decoding processor, which is programmed to execute the decoding method based on the code engine service component provided in the embodiments of the present application. For example, the processor in the form of a hardware decoding processor may be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0061] The decoding method based on the code engine service component provided in the embodiment of the present application will be described below in conjunction with an exemplary application and implementation of a decoding device based on the code engine service component provided in the embodiment of the present application. The decoding device based on the code engine service component can be any terminal with data processing and data storage functions, or can also be a server in which the code engine service component is deployed. That is, the decoding method based on the code engine service component in the embodiment of the present application can be executed by the terminal, or by a server deployed with the code engine service component, or can also be executed by the terminal interacting with the server deployed with the code engine service component.
[0062] See also Figure 4 , Figure 4 This is an optional flow chart of the decoding method based on the code engine service component provided in the embodiment of the present application. Figure 4 The steps shown are explained, and it should be noted that Figure 4 The decoding method based on the code engine service component is implemented by using the code engine service component deployed in the server as the execution subject.
[0063] Step S401: Obtain, through the code engine service component, a code string corresponding to the graphic identification code sent by the application server and a decoding type corresponding to the graphic identification code.
[0064] Here, the application server is a server for business applications, and the business application can be any application that involves a graphic identification code for authentication and identity recognition. For example, the business application can be a gate application, a health code application, or a payment application.
[0065] In an embodiment of the present application, a user's terminal has a client or mini-program for a business application installed. The user, through the client or mini-program, requests the application server to generate a graphical identification code for identity authentication or payment. After the graphical identification code is generated on the terminal, the terminal displays the code, which is scanned by a scanning device to obtain the graphical identification code. The scanning device is connected to the application server, and the scanning device sends the scanned graphical identification code to the application server. The application server and the code engine service component can be deployed on the same device, or the code engine service component and the application server can be connected via a network. After the application server obtains the graphical identification code, it sends the code string corresponding to the graphical identification code and the decoding type corresponding to the graphical identification code to the code engine service component, requesting the code engine service component to decode the graphical identification code.
[0066] In the embodiments of the present application, a scanning device can identify and parse the graphic identification code to obtain a code string, or an application server can identify and parse the graphic identification code to obtain a code string. The decoding type corresponding to the graphic identification code corresponds to the encoding type of the graphic identification code. That is, when the graphic identification code is identified and parsed, not only the code string can be obtained, but also the encoding type of the graphic identification code can be obtained. After obtaining the encoding type, the decoding type corresponding to the graphic identification code can be obtained based on the encoding type. Each encoding type corresponds to a decoding type.
[0067] In the embodiment of the present application, the graphic identification code can be any type of identification code, for example, it can be a QR code, a barcode, a 3D code, etc.
[0068] Step S402: Match a decoding rule corresponding to the decoding type in a preset rule library.
[0069] Here, the preset rule library stores at least one decoding rule, each decoding rule includes specific character cutting algorithm, signature verification algorithm, key and decryption algorithm and other information. The decoding rule can be used to determine the specific implementation process of signature verification and decoding of the code string of the graphic identification code.
[0070] In the embodiments of the present application, the preset rule base is a pre-configured rule base corresponding to the code engine service component. The code engine service component can match the decoding rules corresponding to the decoding type from the preset rule base. In other words, the preset rule base stores decoding rules corresponding to different decoding types, and the decoding rules in the preset rule base can be regularly updated, that is, different decoding rules can be flexibly configured. The preset rule base enables the code engine service component to decode different types of code strings.
[0071] Step S403: perform signature verification and decoding processing on the code string using the decoding rule to obtain a decoding result.
[0072] Here, when a decoding rule corresponding to the decoding type is obtained, the decoding rule is used to perform signature verification and decoding processing on the code string of the graphic identification code to obtain a decoding result. In the embodiment of the present application, if the signature verification passes, the decoding process is performed to obtain a decoding result. If the signature verification fails, the decoding process is prohibited.
[0073] In some embodiments, when the graphic identification code is used for identity identification, for example, when user identity identification is performed in an access control switch scenario, the decoding result may be identity authentication passed; when the graphic identification code is used for payment, for example, when scanning the code to pay in a bus or subway payment scenario, the decoding result may be a payment settlement to an account of a specific identity.
[0074] Step S404: Send the decoding result to the application server, so that the application server performs the terminal control operation according to the decoding result.
[0075] In an embodiment of the present application, the application server performs corresponding terminal control operations based on the decoding results to control the terminal connected to the application server, wherein the terminal connected to the application server includes but is not limited to a user terminal, an execution terminal (for example, a valve in an access control switch scenario), etc.
[0076] The decoding method based on the code engine service component provided in the embodiment of the present application obtains the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code through the code engine service component; matches the decoding rule corresponding to the decoding type in the preset rule library; uses the decoding rule to verify the signature and decode the code string to obtain the decoding result, thereby completing the decoding. In this way, since the code engine service component is flexible to deploy and does not rely on the application scenario, the scanning device can access the code engine service component. Therefore, it can be applied to a variety of scenarios, improving the versatility of the decoding process. At the same time, the decoding rules, keys, and decryption algorithms can be flexibly configured in the preset rule library according to the encoding rules and encryption algorithm requirements, supporting the coexistence and use of multiple decoding rules, so that the code engine service component can support complex parsing of the content of the graphic identification code, and the graphic identification code can contain more business information.
[0077] In some embodiments, a decoding method based on a code engine service component can be applied to a decoding system, wherein the decoding system includes: a code generating terminal, a code scanning device, an application server and a code engine service component, wherein the code generating terminal is used to generate a graphic identification code; the code scanning device is used to scan and obtain the graphic identification code generated by the code generating terminal, and parse the graphic identification code to obtain a code string; the code string is sent to the application server; the application server is used to determine the decoding type corresponding to the graphic identification code based on the code string, and send the code string and the decoding type to the code engine service component; the code engine service component is used to match the decoding rule corresponding to the decoding type in a preset rule library; and use the decoding rule to verify and decode the code string to obtain a decoding result; and, the decoding result is sent to the application server, so that the terminal control operation is performed according to the decoding result through the application server.
[0078] The decoding method based on the code engine service component provided in the embodiment of the present application is described below using the decoding system as an example. Figure 5 This is an optional flow chart of a decoding method based on a code engine service component provided in an embodiment of the present application, such as Figure 5 As shown, the method includes the following steps:
[0079] Step S501: The code generating terminal generates a graphic identification code and displays the graphic identification code.
[0080] Step S502: The code scanning device scans and obtains the graphic identification code.
[0081] Step S503: The code scanning device parses the graphic identification code to obtain a code string.
[0082] Here, while parsing to obtain the code string, the encoding rule of the graphic identification code can also be obtained, wherein the encoding rule is the encoding method of the graphic identification code. Each graphic identification code corresponds to an encoding rule. When the code generation terminal generates the graphic identification code, the encoding rule is used to encode it to obtain the graphic identification code.
[0083] Step S504: The code scanning device sends the code string to the application server.
[0084] Step S505: The application server determines the decoding type corresponding to the graphic identification code according to the code string.
[0085] Here, the decoding type corresponds to the encoding type of the graphic identification code, and the encoding type is the above-mentioned encoding rule.
[0086] Step S506: The application server sends the code string and decoding type to the code engine service component.
[0087] In some embodiments, the code engine service component may also obtain the decoding type corresponding to the graphic identification code. That is, steps S504 to S506 may be replaced by the following steps S51 to S54:
[0088] In step S51, the scanning device sends the graphic identification code to the application server. In step S52, the application server sends the graphic identification code to the code engine service component. In step S53, the code engine service component parses the graphic identification code to obtain the code string corresponding to the graphic identification code and the encoding type of the graphic identification code. In step S54, the code engine service component determines the decoding type corresponding to the graphic identification code based on the encoding type.
[0089] In step S507, the code engine service component matches a decoding rule corresponding to the decoding type in a preset rule library.
[0090] In step S508, the code engine service component uses the decoding rules to perform signature verification and decoding processing on the code string to obtain a decoding result.
[0091] Step S509: The code engine service component sends the decoding result to the application server.
[0092] Step S510: The application server performs a terminal control operation according to the decoding result to control the terminal to be controlled.
[0093] It should be noted that the above steps S507 to S510 are the same as the above steps S402 to S404, and will not be repeated in this embodiment of the application.
[0094] In some embodiments, the preset rule base includes at least one decoding rule, and the decoding rule is stored in the preset rule base through the following steps:
[0095] In step S11 , different types of decoding rules are stored in a preset rule library by rule import or online docking.
[0096] Here, rule import refers to directly importing the generated decoding rules into the preset rule base, and online docking refers to obtaining the decoding rules and storing them in the preset rule base in an online state. It can be an online docking with other rule bases, that is, obtaining the decoding rules from other rule bases and storing them.
[0097] In an embodiment of the present application, the preset rule base can be updated regularly or irregularly through rule import or online docking, so that different types of decoding rules can be stored in the preset rule base. In addition, decoding rules that have not been used for a long time or are no longer used in the preset rule base can be deleted to reduce the number of decoding rules in the preset rule base and improve the efficiency of rule matching.
[0098] Step S12: periodically updating the decoding rules stored in the preset rule base.
[0099] Here, periodically updating the decoding rules in the preset rule base may be periodically updating new decoding rules to the preset rule base, and periodically deleting from the preset rule base decoding rules that are no longer used or have not been used for a preset period of time or have undergone rule updates or have exceeded their service life.
[0100] In some embodiments, a restriction condition may be set for each decoding rule in the preset rule base. For example, a validity period may be set. Setting the validity period may be achieved by the following steps:
[0101] Step S13 sets an expiration time for each decoding rule in the preset rule library. Step S14 prohibits further use of any decoding rule when its expiration time has expired. Step S15 updates the decoding rule via the main platform corresponding to the code engine service component when the decoding rule is prohibited. This can be done while connected to the network.
[0102] In some embodiments, the decoding rules include at least a character segmentation algorithm, a signature verification algorithm, a key, and a decryption algorithm. Before explaining the embodiments of the present application, the structure of the code string corresponding to the graphic identification code is first described.
[0103] The internal fields of the graphic identification code of the embodiment of the present application can be composed of a preset number of fields, which are divided into three parts, namely the boot field, the main segment and the security field. Among them, the boot field includes boot information; the main segment includes the standard field and the extended field. The standard field is created by the main platform and contains some prescribed information that cannot be changed, including type, identity, timestamp, etc. The extended field can be personalized by the sub-platform corresponding to the decoding system or the offline decoding platform through the pre-provided configuration tool or platform management tool. The security field is used to confirm whether the data of the graphic identification code has been tampered with after verifying the data of the main segment by encryption, hash calculation or delay.
[0104] It should be noted that the boot field in the graphic identification code includes at least "boot information", and the main segment includes at least "system identification", "classification identification", "code body version identification" and main field. Among them, the four fields of "boot information", "system identification", "classification identification" and "code body version identification" are not encrypted during the encoding process, and the main field in the code is encrypted into ciphertext. During the decoding process, the ciphertext is decrypted.
[0105] Among them, "system identification" is used to distinguish the graphic identification codes of different systems. Because there are many types of graphic identification codes, it is difficult to distinguish what the code is, who the code belongs to, and whether it can be scanned simply by looking at the graphic identification code. Therefore, the system identification can determine whether the code is scannable by the user through scanning. If not, a prompt message will be given after scanning the code. If it is, the subsequent process of signature verification and decryption will continue;
[0106] "Classification Identifier": It is an identifier that classifies the types of graphic identification codes. For example, graphic identification codes can be divided into three major types: person codes, object codes, and event codes.
[0107] "Code body version identification": Because there will be some version upgrades under different classification identifications, for example, the same city code will be divided into different versions such as V1 and V2, the version differences between different graphic identification codes can be distinguished through the code body version identification. Because it may be necessary to achieve compatibility after a version upgrade, the previous version of the graphic identification code and the current version of the graphic identification code can be identified through the code body version identification.
[0108] In an embodiment of the present application, the entire process of encryption (i.e., encoding) and decryption (i.e., decoding) of the graphic identification code can be: first, the graphic identification code is encrypted, and the final signature is generated after encryption, and the signature is assembled into the security domain of the code string; then, in the verification process of the decoding process, because the number of bits of the characters in the several character strings before the security domain can be known through a specific algorithm, the code string can be disassembled according to the number of bits, and after disassembly, the code string is verified by the provided signature verification algorithm. After the verification is passed, the boot domain and the main segment can be reversely parsed to obtain the main field in the main segment, and then split according to the length rule of the main field to obtain the attributes of each field, thereby completing the decoding process.
[0109] based on Figure 4 , Figure 6 This is an optional flow chart of a decoding method based on a code engine service component provided in an embodiment of the present application, such as Figure 6 As shown, step S403 can be implemented by the following steps:
[0110] Step S601: Using a character segmentation algorithm to perform character segmentation processing on the code string to obtain the main body segment and security domain corresponding to the code string.
[0111] Step S602: Use a signature verification algorithm to perform signature verification on the security domain to obtain a signature verification result.
[0112] In some embodiments, step S602 may be completed by at least one of the following signature verification methods:
[0113] Method 1: Use the terminal public key of the scanning device that recognizes the graphic identification code to decrypt the code body data signature in the security domain to achieve signature verification.
[0114] Here, in method one, the terminal public key of the scanning device that identifies the graphic identification code can be obtained from the security domain; then, the first preset digest algorithm is used to calculate the first digest of the main segment (which can be the main field of the main segment of the code string); the terminal public key is used to decrypt the signature of the code body data to obtain the second digest; finally, the security domain is verified based on the first digest and the second digest to obtain the verification result.
[0115] Here, the first preset digest algorithm may be a hash algorithm, and the first preset digest algorithm corresponds to the preset algorithm used during encryption. For example, the same hash algorithm may be used, or different algorithms may be used.
[0116] Corresponding to the signature verification process of method 1, during the encryption process, the signature can be obtained in the following way: using a preset algorithm (which can be a hash algorithm, for example, the SM3 algorithm) to obtain a digest of the main field of the code string main segment, and then using the terminal private key to encrypt the obtained digest, for example, the SM2 algorithm can be used for encryption, and finally obtaining the above-mentioned code body data signature.
[0117] Method 2: Use the platform public key of the platform where the code engine service component is located to decrypt the public key certificate signature in the security domain to implement signature verification.
[0118] Here, in method two, the third digest corresponding to the terminal public key can be calculated using the second preset digest algorithm; then, the platform public key of the platform where the code engine service component is located is obtained; the platform public key is used to decrypt the public key certificate signature to obtain the fourth digest; finally, the security domain is verified based on the third digest and the fourth digest to obtain the verification result.
[0119] Here, the second preset digest algorithm may also be a hash algorithm, and the second preset digest algorithm corresponds to the preset algorithm used during encryption. For example, the same hash algorithm may be used, or different algorithms may be used.
[0120] Corresponding to the signature verification process of method 2, during the encryption process, the signature can be obtained in the following way: use a preset algorithm (which can be a hash algorithm, for example, the SM3 algorithm) to obtain a digest of the terminal public key, and then use the platform private key to encrypt the obtained digest. For example, the encryption can use the SM2 algorithm, and finally obtain the public key certificate signature.
[0121] Step S603: If the signature verification result is passed, a decryption algorithm is used to decode the main body segment using the key to obtain a decoding result. If the signature verification result is failed, the process ends.
[0122] In some embodiments, the above decoding method is applied to a decoding system, which includes at least a code engine service component, an application server and a code scanning device; wherein the code engine service component and the application server are deployed in the same network environment; when the decoding system is offline, the private key can be synchronized to the application server through the code scanning device; thereby, the code engine service component verifies and decodes the code string according to the private key to obtain the above decoding result.
[0123] In some embodiments, the code engine service component may further provide an interface service; correspondingly, the decoding method further includes the following steps:
[0124] Step S21 : in an offline state, obtaining a code string corresponding to the graphic identification code and a decoding type corresponding to the graphic identification code by calling an interface service.
[0125] Step S22: In an offline state, the decoding result is sent to the application server by calling the interface service.
[0126] In the embodiment of the present application, since the code engine service component also provides an offline data transmission interface, this can ensure that the graphic identification code can be decoded in a timely manner even in an offline state or when the network conditions are relatively poor, making the solution applicable to more scenarios and solving the bottleneck problems of many offline application scenarios.
[0127] The following describes an exemplary application of the embodiments of the present application in a practical application scenario.
[0128] The present application provides a decoding method based on a code engine service component, wherein the code engine service component centralizes the decoding logic implementation in the engine service, enabling flexible deployment and application in various online or offline decoding scenarios. Here, the access control scenario is used as an example for illustration.
[0129] like Figure 7 As shown, this is a schematic diagram of the application scenario of the decoding method based on the code engine service component provided in an embodiment of the present application. The community owner requests code generation from the business identity code generation service 701 through the mini program in the mobile phone. The code generation service completes the code generation according to the owner identity code encoding rules and encryption algorithm and returns it to the mini program end. After obtaining the QR code, the code is displayed on the mobile phone 702 and then scanned at the gate 703. The gate's code scanning device parses the QR code into a code string and then requests decoding from the access control service 704. The access control service 704 passes the code string to the code engine service component 705. The code engine service component 705 decodes the code through the preset owner identity QR code decoding rules, keys and decryption algorithms, and returns the user identity information to the access control service 704. The access control service 704 determines whether the user is the owner and returns information to control the gate switch.
[0130] In the embodiment of the present application, the code engine service component adopts a microservice design concept during offline decoding, encapsulating decoding-related algorithm technologies to form an independent engine service. Compared with traditional decoding applications, the code engine service component completely decouples decoding and business logic, and realizes offline decoding functions through an interface service model.
[0131] Figure 8 This is a timing flow chart of the offline decoding method based on the code engine service component provided in the embodiment of the present application, such as Figure 8 As shown, the method includes the following steps:
[0132] In step S801, the mobile app or APP displays the code, which is then scanned by a code scanning device.
[0133] In step S802, the code scanning device parses the two-dimensional code image into a code string based on the QR code standard.
[0134] Step S803: The code scanning device transmits the code string to the business application service.
[0135] Step S804: The business application service calls the decoding interface service of the code engine service component and passes the decoding type and code string.
[0136] In step S805, the internal service of the code engine service component selects the corresponding signature verification, decryption algorithm and key according to the decoding type to complete the parsing of the code body content and complete the decoding.
[0137] Step S806: The code engine service component returns the decoding result to the business application service.
[0138] Step S807: The business application service completes corresponding business logic processing according to the decoding result.
[0139] Step S808: The business application service returns the processing result to the code scanning device.
[0140] In the embodiment of the present application, a variety of general asymmetric decryption algorithms have been set up inside the code engine service component, such as the RSA algorithm, SM2 algorithm, etc., which can realize conventional plaintext encryption and digital signatures; the code engine service component can also provide import and online docking methods to synchronize the decryption rules of various types of codes, which can meet the needs of decoding multiple types of codes in the same service; the code engine service component is deployed in the form of a service, supporting both offline and online docking services.
[0141] Figure 9 This is the internal decoding logic diagram of the code engine service component provided by the embodiment of the present application, such as Figure 9 As shown, in step S901, the code engine service component receives the decoding type and code string through the interface; then, in step S902, the decoding rules are found through decoding type matching, where the decoding rules include character segmentation, signature verification, key, decryption algorithm, etc.; then, in step S903, the code string is processed through the decoding rules, that is, character string segmentation, signature verification, decryption, etc. are performed through the decoding rules to finally obtain the plaintext information in the code; finally, in step S904, the decoding result is output through the interface.
[0142] In the embodiment of the present application, when the QR code is online, encryption and decryption are performed by the server, but when it is offline, decryption needs to be performed on the client. Based on the above requirements, the asymmetric encryption algorithm SM2 can be selected. Figure 10 This is a schematic diagram of the internal fields of the QR code provided in the embodiment of the present application, such as Figure 10As shown, the internal fields of the QR code are basically composed of 17 fields. These 17 fields are divided into three parts, namely the boot field 1001, the main body 1002 and the security field 1003. Among them, the boot field 1001 includes the boot information (1), which is marked (1) in the figure; the main body 1002 includes the standard field and the extension field. The standard field is created by the main platform and contains some prescribed information that cannot be changed, including type, identity, timestamp, etc. The extension field can be personalized by the sub-platform or offline decoding platform through the pre-provided configuration tool or platform management tool. It should be noted that the four fields of "boot information" (1), "system identification" (2), "classification identification" (3) and "code body version identification" in the QR code are not encrypted. The fields in the code (4 to 10) are encrypted into ciphertext CT (ciphertext), field 1+2+CT=code string F; code string F-1-2=CT, and the ciphertext CT is decrypted into plaintext (3 to 10). The security domain 1003 is used to encrypt, hash or delay the data in the main segment 1002 to confirm whether it has been tampered with.
[0143] In this embodiment of the application, the code content is encrypted with a public key and decrypted with a private key. When online, the code body data is encrypted with the user's public key and decrypted with the user's private key; when offline, the code generating terminal synchronizes the private key to the client, which then decrypts it.
[0144] To prevent the code string from being tampered with during the encryption and decryption process, the embodiment of the present application uses a digital double signature function:
[0145] Figure 11 This is a schematic diagram of the first signature algorithm of the digital dual signature function provided in the embodiment of the present application, such as Figure 11 As shown, in signature 1: a hash algorithm 1101 (such as the SM3 algorithm) can be used to obtain a digest of (code body data 2 to 10) to obtain a code body digest 1102, and then the terminal private key 1103 is used to encrypt the code body digest 1102. The encryption here can use the SM2 algorithm, and finally the code body data signature (16) is obtained.
[0146] Figure 12 This is a schematic diagram of the signature verification process corresponding to the first signature algorithm provided in the embodiment of the present application. Figure 12 As shown, during signature verification, a hash algorithm 1201 (e.g., SM3 algorithm) can be used to calculate the digest of the code body data (2-10) to obtain the code body digest 1202. At the same time, the terminal public key (13) is used to decrypt the code body data signature (16) to obtain a digest. The two digests are then compared to determine whether they are consistent and whether they have been tampered with. If the digests obtained in the two processes are the same, the signature verification is successful.
[0147] Figure 13 This is a schematic diagram of the second signature algorithm of the digital dual signature function provided in the embodiment of the present application, such as Figure 13 As shown, in signature 2: a hash algorithm 1301 (such as the SM3 algorithm) can be used to obtain a summary of the terminal public key (13) to obtain a terminal public key summary 1302, and then the platform private key 1303 is used to encrypt the terminal public key summary 1302, and the encryption uses the SM2 algorithm to finally obtain a public key certificate signature (15).
[0148] Figure 14 This is a schematic diagram of the signature verification process corresponding to the second signature algorithm provided in the embodiment of the present application. Figure 14 As shown, during signature verification, a hash algorithm 1401 (e.g., SM3 algorithm) can be used to obtain a digest of the terminal public key (13) to obtain a terminal public key digest 1402. At the same time, the platform public key 1403 is used to decrypt the public key certificate signature (15) to obtain a digest. The two digests are then compared to determine whether they are consistent and whether they have been tampered with. If the digests obtained in the two processes are the same, the signature verification is successful.
[0149] In some embodiments, it is also possible to use only the first signature algorithm and the corresponding signature verification process, or only the second signature algorithm and the corresponding signature verification process, that is, the digital single signature function can be used to implement signing and verification.
[0150] In the embodiment of the present application, the key point of the technical solution of the code engine service component is to completely decouple the complex decoding logic from the business. A variety of different decoding rules can be pre-set in the code engine service component, thereby supporting the code engine service component to be deployed offline in the production environment, and then supporting more complex encoding logic, solving the bottleneck problems of many offline application scenarios.
[0151] The following continues to describe the exemplary structure of the decoding device 354 based on the code engine service component provided in the embodiment of the present application implemented as a software module. In some embodiments, such as Figure 3 As shown, the decoding device 354 based on the code engine service component includes:
[0152] An acquisition module 3541 is used to obtain the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code; a matching module 3542 is used to match the decoding rule corresponding to the decoding type in a preset rule library; a processing module 3543 is used to use the decoding rule to verify and decode the code string to obtain a decoding result; and a sending module 3544 is used to send the decoding result to the application server so that the application server can perform terminal control operations based on the decoding result.
[0153] In some embodiments, the acquisition module is further used to: receive the graphic identification code sent by the application server; parse the graphic identification code to obtain the code string corresponding to the graphic identification code and the encoding type of the graphic identification code; and determine the decoding type corresponding to the graphic identification code based on the encoding type.
[0154] In some embodiments, the device further includes: a storage module for storing different types of decoding rules into the preset rule base by rule import or online docking; and an update module for periodically updating the decoding rules stored in the preset rule base.
[0155] In some embodiments, the apparatus further comprises: a setting module for setting an effective time for each decoding rule in the preset rule base; a prohibition module for prohibiting the continued use of any decoding rule when the effective time of any decoding rule is reached; and a rule updating module for updating any decoding rule through a main platform corresponding to the code engine service component when the use of any decoding rule is prohibited.
[0156] In some embodiments, the decoding rules include a character cutting algorithm, a signature verification algorithm, a key and a decryption algorithm; the processing module is also used to: use the character cutting algorithm to perform character cutting processing on the code string to obtain the main segment and security domain corresponding to the code string; use the signature verification algorithm to perform signature verification processing on the security domain to obtain a signature verification result; when the signature verification result is that the signature verification is passed, use the decryption algorithm to decode the main segment using the key to obtain the decoding result.
[0157] In some embodiments, the processing module is also used to: use at least one of the following signature verification methods to complete the signature verification process and obtain the signature verification result: use the terminal public key of the scanning device that recognizes the graphic identification code to decrypt the code body data signature in the security domain to achieve the signature verification process; use the platform public key of the platform where the code engine service component is located to decrypt the public key certificate signature in the security domain to achieve the signature verification process.
[0158] In some embodiments, the processing module is also used to: obtain the terminal public key of the scanning device that identifies the graphic identification code from the security domain; use a first preset digest algorithm to calculate the first digest of the main segment; use the terminal public key to decrypt the code body data signature to obtain a second digest; and perform signature verification on the security domain based on the first digest and the second digest to obtain a verification result.
[0159] In some embodiments, the processing module is also used to: use a second preset digest algorithm to calculate a third digest corresponding to the terminal public key; obtain the platform public key of the platform where the code engine service component is located; use the platform public key to decrypt the public key certificate signature to obtain a fourth digest; and perform signature verification on the security domain based on the third digest and the fourth digest to obtain a signature verification result.
[0160] In some embodiments, the decoding method is applied to a decoding system, which includes at least the code engine service component, the application server and a code scanning device; the code engine service component and the application server are deployed in the same network environment; when the decoding system is offline, the private key is synchronized to the application server through the code scanning device; so that the code engine service component verifies and decodes the code string according to the private key to obtain the decoding result.
[0161] In some embodiments, the code engine service component provides an interface service; the acquisition module is further used to: in an offline state, obtain the code string corresponding to the graphic identification code and the decoding type corresponding to the graphic identification code by calling the interface service; and the sending module is further used to: in an offline state, send the decoding result to the application server by calling the interface service.
[0162] It should be noted that the description of the device embodiment of the present application is similar to the description of the method embodiment described above, and has similar beneficial effects as the method embodiment, so it will not be repeated. For technical details not disclosed in the device embodiment, please refer to the description of the method embodiment of the present application for understanding.
[0163] The present invention provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method described above in the present invention.
[0164] The embodiment of the present application provides a storage medium storing executable instructions, wherein the executable instructions are stored. When the executable instructions are executed by a processor, the processor will execute the method provided by the embodiment of the present application, for example, Figure 4 The method shown.
[0165] In some embodiments, the storage medium can be a computer-readable storage medium, such as a ferroelectric random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); it can also be various devices including one or any combination of the above memories.
[0166] In some embodiments, executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0167] By way of example, executable instructions may, but need not necessarily, correspond to a file in a file system, may be stored as part of a file storing other programs or data, such as one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions). By way of example, executable instructions may be deployed for execution on one computing device, on multiple computing devices located at one site, or on multiple computing devices distributed across multiple sites and interconnected by a communication network.
[0168] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are included in the scope of protection of the present application.
Claims
1. A decoding method based on a code engine service component, characterized in that: The decoding method is applied to a decoding system, which includes at least a code engine service component, an application server, and a code scanning device; The code engine service component and the application server are deployed in the same network environment; The code engine service component provides an interface service; the method includes: In an offline state, by calling the interface service provided by the code engine service component, obtaining the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code; Matching a decoding rule corresponding to the decoding type in a preset rule library; The code string is subjected to signature verification and decoding processing using the decoding rule to obtain a decoding result; wherein, when the decoding system is in an offline state, the private key is synchronized to the application server via the code scanning device, so that the code engine service component performs signature verification and decoding processing on the code string according to the private key to obtain the decoding result; The decoding result is sent to the application server by calling the interface service, so that the terminal control operation is performed according to the decoding result by the application server.
2. The method according to claim 1, characterized in that The obtaining of a code string corresponding to the graphic identification code sent by the application server and a decoding type corresponding to the graphic identification code includes: receiving the graphic identification code sent by the application server; Parsing the graphic identification code to obtain a code string corresponding to the graphic identification code and an encoding type of the graphic identification code; A decoding type corresponding to the graphic identification code is determined according to the encoding type.
3. The method according to claim 1, characterized in that The method further comprises: By importing rules or connecting online, different types of decoding rules are stored in the preset rule library; The decoding rules stored in the preset rule base are updated periodically.
4. The method according to claim 3, characterized in that The method further comprises: Setting an effective time for each decoding rule in the preset rule base; When the validity period of any decoding rule is reached, further use of any decoding rule is prohibited; When any one of the decoding rules is prohibited from being used, the any one of the decoding rules is updated through a main platform corresponding to the code engine service component.
5. The method according to claim 1, wherein The decoding rules include character cutting algorithm, signature verification algorithm, key and decryption algorithm; The using the decoding rule to perform signature verification and decoding processing on the code string to obtain a decoding result includes: Performing character segmentation processing on the code string using the character segmentation algorithm to obtain a main body segment and a security domain corresponding to the code string; Performing signature verification on the security domain using the signature verification algorithm to obtain a signature verification result; When the signature verification result is passed, the decryption algorithm is used to decode the main body segment using the key to obtain the decoding result.
6. The method according to claim 5, characterized in that The performing signature verification on the security domain using the signature verification algorithm to obtain a signature verification result includes: The signature verification process is completed using at least one of the following signature verification methods to obtain the signature verification result: Decrypting the signature of the code body data in the security domain using the terminal public key of the scanning device that recognizes the graphic identification code to implement the signature verification process; The platform public key of the platform where the code engine service component is located is used to decrypt the public key certificate signature in the security domain to implement the signature verification process.
7. The method according to claim 6, characterized in that The method of using the terminal public key of the scanning device that recognizes the graphic identification code to decrypt the code body data signature in the security domain to implement the signature verification process includes: Obtaining a terminal public key of a scanning device that identifies the graphic identification code from the security domain; Calculating a first summary of the body segment using a first preset summary algorithm; Decrypting the code body data signature using the terminal public key to obtain a second digest; Perform signature verification on the security domain according to the first digest and the second digest to obtain a signature verification result.
8. The method according to claim 6, characterized in that The method further comprises: using the platform public key of the platform where the code engine service component is located to decrypt the public key certificate signature in the security domain to implement the signature verification process; Calculating a third digest corresponding to the terminal public key using a second preset digest algorithm; Obtain the platform public key of the platform where the code engine service component is located; Decrypting the public key certificate signature using the platform public key to obtain a fourth digest; The security domain is subjected to signature verification processing according to the third digest and the fourth digest to obtain a signature verification result.
9. A decoding system based on a code engine service component, characterized in that: The system includes: a code scanning device, an application server and a code engine service component; the code engine service component and the application server are deployed in the same network environment; the code engine service component provides an interface service; The code scanning device is used to scan and obtain the graphic identification code generated by the code generating terminal, and parse the graphic identification code to obtain a code string; and send the code string to the application server; The application server is configured to determine a decoding type corresponding to the graphic identification code according to the code string, and send the code string and the decoding type to the code engine service component; The code engine service component is used to obtain the code string corresponding to the graphic identification code sent by the application server and the decoding type corresponding to the graphic identification code by calling the interface service in an offline state; match the decoding rule corresponding to the decoding type in the preset rule library; and use the decoding rule to verify and decode the code string to obtain a decoding result; wherein, when the decoding system is in an offline state, the private key is synchronized to the application server through the code scanning device, so that the code engine service component verifies and decodes the code string according to the private key to obtain the decoding result; the decoding result is sent to the application server by calling the interface service, so that the terminal control operation is performed by the application server according to the decoding result.
10. A decoding device based on a code engine service component, characterized in that: The decoding device is applied to a decoding system, which includes at least a code engine service component, an application server, and a code scanning device; The code engine service component and the application server are deployed in the same network environment; The code engine service component provides an interface service; the device includes: an acquisition module, configured to acquire, in an offline state, a code string corresponding to the graphic identification code sent by the application server and a decoding type corresponding to the graphic identification code by calling an interface service provided by the code engine service component; A matching module, configured to match a decoding rule corresponding to the decoding type in a preset rule library; a processing module, configured to perform signature verification and decoding processing on the code string using the decoding rule to obtain a decoding result; wherein, when the decoding system is in an offline state, the private key is synchronized to the application server via the code scanning device, so that the code engine service component performs signature verification and decoding processing on the code string according to the private key to obtain the decoding result; The sending module is used to send the decoding result to the application server by calling the interface service, so that the terminal control operation is performed according to the decoding result by the application server.
11. The device according to claim 10, characterized in that The code string and the decoding type are obtained by the code scanning device identifying and parsing the graphic identification code, or by the application server identifying and parsing the graphic identification code.
12. The device according to claim 10, characterized in that The acquisition module is further used to: receive the graphic identification code sent by the application server; parse the graphic identification code to obtain a code string corresponding to the graphic identification code and an encoding type of the graphic identification code; and determine a decoding type corresponding to the graphic identification code according to the encoding type.
13. The device according to claim 10, characterized in that The device further includes a storage module, which is used to: store different types of decoding rules in the preset rule base by rule import or online docking; and periodically update the decoding rules stored in the preset rule base.
14. The device according to claim 13, characterized in that The device also includes an update module, which is used to: set an effective time for each decoding rule in the preset rule base; when the effective time of any decoding rule is reached, prohibit further use of any decoding rule; when the use of any decoding rule is prohibited, update any decoding rule through the main platform corresponding to the code engine service component.
15. A decoding device based on a code engine service component, characterized in that: include: a memory for storing executable instructions; The processor is configured to implement the decoding method based on the code engine service component according to any one of claims 1 to 8 when executing the executable instructions stored in the memory.
16. A computer-readable storage medium, characterized in that Executable instructions are stored, which are used to cause a processor to execute the executable instructions to implement the decoding method based on the code engine service component according to any one of claims 1 to 8.
17. A computer program product, characterized in that The computer program product includes computer instructions stored in a computer-readable storage medium; The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor is used to execute the computer instructions to implement the decoding method based on the code engine service component according to any one of claims 1 to 8.
Citation Information
Patent Citations
Access control method and device, electronic device and storage medium
CN110288734A
Safety control method and device for two-dimensional code payment
CN111612459A