A method and system for password service management of road passenger transport e-tickets
Through the three-level key architecture at the ministerial, provincial and station level, electronic tickets are encrypted and managed, which solves the problem that real-name data of passengers cannot be effectively protected in the existing technology, and realizes secure data transmission and cross-provincial management.
Patent Information
- Application Number
- CN202210774201.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-01
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2042-07-01
AI Technical Summary
The existing electronic ticket encryption methods cannot effectively protect passenger real-name data in business processes such as ticket sales, ticket inspection, ticket inspection and flow summary, resulting in easy leakage of personal information.
The electronic ticket is encrypted and managed by the ministerial, provincial and station-level three-level key architecture, including the ministerial key management center generating provincial keys and encrypting, the provincial cryptographic service management platform decrypting and signing, the electronic ticket system encrypting and signing, and the ticket verification system performs information verification to ensure the security of data transmission.
Effectively protect passenger real-name data in business processes such as ticket sales, ticket inspection, ticket inspection and flow summary, improve the security during data transmission, and realize the cross-provincial circulation and use management of electronic tickets.
Smart Images

Figure CN115242391B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic tickets, and in particular to a password service management method and system for road passenger electronic tickets. Background Art
[0002] The electronic ticketing system is a transportation information system directly serving the public and is also the most widely used. However, electronic ticket information contains sensitive information such as passenger personal information and travel information. Existing electronic ticket encryption methods only use conventional encryption methods at the station level, which makes personal information easily leaked and fails to effectively protect passenger real-name data during business processes such as ticket sales, ticket verification, ticket inspection, and transaction aggregation. Summary of the Invention
[0003] The present invention aims to solve the problem that the existing electronic ticket encryption method cannot effectively protect the real-name data of passengers in business processes such as ticket sales, ticket verification, ticket inspection and flow summary. In order to solve the above technical problems, the present invention provides a road passenger electronic ticket password service management method and system.
[0004] The first aspect provides a method for managing password services for road passenger electronic tickets, including:
[0005] The ministerial key management center generates a provincial key, encrypts the provincial key using a pre-agreed master key, and issues the encrypted provincial key to the provincial cryptographic service management platform;
[0006] After receiving the encrypted provincial key, the provincial cryptographic service management platform uses the pre-agreed master key to decrypt the encrypted provincial key, obtains the provincial key, and imports it into the provincial platform certificate;
[0007] When the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key, and uses the provincial platform certificate to sign the encrypted electronic ticket QR code;
[0008] The provincial platform certificate sends the signed electronic ticket QR code to the electronic ticket system, and the electronic ticket system sends the signed electronic ticket QR code to the user terminal;
[0009] When the electronic ticket verification system receives the ticket verification request, the electronic ticket verification system scans the electronic ticket QR code, reads the electronic ticket information, and sends the electronic ticket information to the provincial password service management platform;
[0010] The provincial cryptographic service management platform verifies whether the electronic ticket information is correct through the provincial key, and returns the verification result to the electronic ticket verification system.
[0011] In a possible implementation of the first aspect, before the ministerial key management center generates the provincial key, the process further includes:
[0012] The ministerial key management center and the provincial cryptographic service management platform synchronize the master key.
[0013] In one possible implementation of the first aspect, when the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key, specifically including:
[0014] When the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to obtain a station key by disentangling the provincial key and the station code, and encrypts the electronic ticket QR code with the station key;
[0015] The station code is the unique code of the station where the electronic ticket system is located.
[0016] In a possible implementation of the first aspect, the method further includes:
[0017] When the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset period of time, the electronic ticket verification system sends a local ticket verification request containing the electronic ticket information to the station-level encryption machine;
[0018] After receiving the local ticket verification request, the station-level encryption machine checks whether the electronic ticket information is correct and returns the verification result to the electronic ticket verification system.
[0019] In a possible implementation of the first aspect, the method further includes:
[0020] The provincial cryptographic service management platform puts the electronic ticket information that has passed the verification into a synchronization queue, encrypts the electronic ticket information in the synchronization queue, and sends the encrypted electronic ticket information to the ministerial key management center in the form of a digital envelope for storage.
[0021] The second aspect provides a road passenger electronic ticket cryptographic service management system, including: a ministerial key management center, a provincial cryptographic service management platform, an electronic ticket system, and an electronic ticket verification system, wherein:
[0022] The ministerial key management center is used to generate provincial keys, encrypt the provincial keys using a pre-agreed master key, and issue the encrypted provincial keys to the provincial cryptographic service management platform;
[0023] After receiving the encrypted provincial key, the provincial cryptographic service management platform is used to decrypt the encrypted provincial key using a pre-agreed master key to obtain the provincial key and import it into the provincial platform certificate;
[0024] When the electronic ticket system receives a ticket purchase request, the electronic ticket system is configured to call the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the provincial key, and use the provincial platform certificate to sign the encrypted electronic ticket QR code;
[0025] The provincial platform certificate is also used to send the signed electronic ticket QR code to the electronic ticket system, and the electronic ticket system is also used to send the signed electronic ticket QR code to the user terminal;
[0026] When the electronic ticket verification system receives the ticket verification request, the electronic ticket verification system is used to scan the electronic ticket QR code, read the electronic ticket information, and send the electronic ticket information to the provincial password service management platform;
[0027] The provincial cryptographic service management platform is also used to verify whether the electronic ticket information is correct through the provincial key, and return the verification result to the electronic ticket verification system.
[0028] In a possible implementation of the second aspect, the ministerial key management center and the provincial cryptographic service management platform are also used to synchronize master keys.
[0029] In one possible implementation of the second aspect, when the electronic ticket system receives a ticket purchase request, the electronic ticket system is specifically configured to call the provincial cryptographic service management platform to obtain a station key by discretizing the provincial key and the station code, and encrypt the electronic ticket QR code using the station key.
[0030] The station code is the unique code of the station where the electronic ticket system is located.
[0031] In one possible implementation of the second aspect, the system further includes: a station-level encryption machine, wherein when the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset period of time, the electronic ticket verification system is further configured to send a local ticket verification request containing the electronic ticket information to the station-level encryption machine;
[0032] The station-level encryption machine is used to check whether the electronic ticket information is correct after receiving the local ticket verification request, and return the verification result to the electronic ticket verification system.
[0033] In a possible implementation of the second aspect, the provincial cryptographic service management platform is also used to place the electronic ticket information that has passed verification into a synchronization queue, encrypt the electronic ticket information in the synchronization queue, and send the encrypted electronic ticket information in the form of a digital envelope to the ministerial key management center for storage.
[0034] Electronic tickets are encrypted and managed through a three-level key system architecture at the ministerial, provincial and station levels, which can effectively protect the real-name data of passengers in business processes such as ticket sales, ticket verification, ticket inspection and flow summary, thereby improving the security of data during transmission. In addition, a complete closed-loop ticket management function is provided for the provincial electronic ticket system through the ministerial key management center, which can realize the management function of the cross-provincial circulation and use of electronic tickets, and provide passengers with functions such as electronic ticket verification and issuance of electronic invoices.
[0035] Advantages of additional aspects of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 A flowchart illustrating an embodiment of a cryptographic service management method of the present invention is provided;
[0037] Figure 2 A schematic diagram of the electronic ticket key system architecture provided for an embodiment of the cryptographic service management method of the present invention;
[0038] Figure 3 A schematic diagram of the structure of an embodiment of the cryptographic service management system of the present invention is provided. DETAILED DESCRIPTION
[0039] The principles and features of the present invention are described below with reference to the accompanying drawings. The embodiments given are only used to explain the present invention and are not used to limit the scope of the present invention.
[0040] The electronic ticket password service management method provided by the present invention is implemented based on the corresponding electronic ticket system. The electronic ticket system can include a provincial electronic ticket system, a ministerial electronic ticket system and a passenger station ticket sales and inspection system. The provincial electronic ticket system mainly completes the monitoring and application of electronic tickets. When passengers purchase tickets from different distribution platforms, the provincial electronic ticket system will assign an electronic ticket number to the order that has been successfully paid, generate a ticket record and synchronize the information with the station service system and the ministerial electronic ticket system. The ministerial electronic ticket system mainly provides the provincial electronic ticket system with a complete closed-loop ticket management function and realizes the management function of the cross-provincial circulation and use of electronic tickets; after passengers purchase tickets, they are provided with functions such as electronic ticket verification and issuance of electronic invoices; and a national electronic ticket data center is established to be responsible for the collection, storage, processing, distribution, and big data analysis of national electronic ticket data.
[0041] The following is an explanation with specific examples.
[0042] like Figure 1 FIG. 1 is a flow chart of an embodiment of a cryptographic service management method of the present invention. The cryptographic service management method for road passenger electronic tickets includes:
[0043] S1: The ministerial key management center generates a provincial key, encrypts the provincial key using a pre-agreed master key, and sends the encrypted provincial key to the provincial cryptographic service management platform.
[0044] It should be understood that the specific encryption algorithm can be selected according to actual needs, for example, it can be the national standard SM4 algorithm and SM2 algorithm.
[0045] S2, after receiving the encrypted provincial key, the provincial cryptographic service management platform uses the pre-agreed master key to decrypt the encrypted provincial key, obtains the provincial key, and imports it into the provincial platform certificate;
[0046] It should be understood that the pre-agreement here refers to the pre-agreement of the master key between the ministerial key management center and each provincial cryptographic service management platform.
[0047] S3: When the electronic ticket system receives a ticket purchase request, it calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key and signs the encrypted electronic ticket QR code using the provincial platform certificate.
[0048] For example, when issuing e-tickets through the electronic ticketing system, this key can be used to encrypt the ticket information and personal information contained in the e-ticket QR code, and the complete e-ticket information can be signed using the provincial platform certificate. The SM4 key imported into the cryptographic service platform is used to protect the QR code data, and the SM2 key within the cryptographic machine is used to sign the ticket information. The SM4 key imported into the cryptographic service platform is used to decrypt the QR code data, and the SM2 key within the cryptographic machine is used to verify the validity of the ticket.
[0049] Optionally, the user's personal information on the ticket may include: ID number and passenger name.
[0050] Ticket information may include: electronic ticket number, flight number, seat number and other information.
[0051] S4: The provincial platform certificate sends the signed e-ticket QR code to the e-ticket system, and the e-ticket system sends the signed e-ticket QR code to the user terminal;
[0052] S5, when the electronic ticket verification system receives the ticket verification request, the electronic ticket verification system scans the electronic ticket QR code, reads the electronic ticket information, and sends the electronic ticket information to the provincial password service management platform;
[0053] It should be understood that the electronic ticket verification system can read the electronic ticket information by scanning the QR code, authenticate the electronic ticket by calling the identity authentication interface of the provincial cryptographic service management platform, decrypt the QR code ciphertext data after the authentication is passed, and obtain the ticket information and personal information.
[0054] S6. The provincial cryptographic service management platform verifies whether the electronic ticket information is correct through the provincial key and returns the verification result to the electronic ticket verification system.
[0055] It should be understood that the provincial cryptographic service management platform can store the corresponding electronic ticket information in the corresponding database after purchasing the ticket. When the electronic ticket is received, the database can be searched to find the corresponding electronic ticket information, and then it can be determined whether the status of the electronic ticket is purchased but not used. If so, the verification is considered to be successful and the electronic ticket information is correct; otherwise, if the corresponding electronic ticket information is not found in the database, or the status of the queried electronic ticket is used or refunded, then the verification fails.
[0056] It should be noted that the key system involved in the system of the present invention is divided into three levels. The first level is the master key, the second level is the provincial key, and the third level includes the transmission key, signature key and station key. Figure 2 As shown, a schematic diagram of an exemplary electronic ticket key architecture is provided.
[0057] The master key, the root key of the entire key system, is stored in the ministry-level key management center. The ministry-level key management center synchronizes the master key through backup and recovery during online operations. After receiving encrypted ticket data from the provincial cryptographic service management platform, the ministry-level key management center parses the digital envelope, decrypts the random SM4 key using the SM2 private key in the cipher machine, decrypts the ticket data using the SM4 key, and stores each ticket information item in the database.
[0058] The provincial key is generated by the ministerial key management center and distributed to the provincial cryptographic service management platform. The ministerial key management center uses SM4 to generate two key components. The provincial cryptographic service management platform then sequentially inserts the key components generated by the ministerial key management center into the corresponding component positions to form the provincial key. At the designated time, the provincial cryptographic service management platform digitally encapsulates the ticket and sends it to the ministerial key management center. The ticket data is encrypted using a random SM4 key, and the random SM4 key is encrypted using the ministerial SM2 public key.
[0059] The transmission key is generated by the key management center of each transmission initiator at each level, using the SM4 algorithm to encrypt the transmitted information. The signature key is generated by the ministerial key management center, encrypted with the provincial key, and distributed to the provincial cryptographic service management platform. The transmission key is encrypted in the transmitted information to implement the signature envelope. The station key is obtained by adding the provincial key to the station code discretization. It is used to encrypt the user's personal information and access information on the ticket. The station code is a unique code preset for each station in each province.
[0060] The electronic ticket password service management method provided in this embodiment encrypts and manages electronic tickets through a three-level key system structure at the ministerial, provincial and station levels. It can effectively protect the real-name data of passengers in business processes such as ticket sales, ticket verification, ticket inspection and flow summary, thereby improving the security of data during transmission. In addition, a complete closed-loop ticket management function is provided for the provincial electronic ticket system through the ministerial key management center, which can realize the management function of the circulation and use of electronic tickets across provinces, and provide passengers with functions such as electronic ticket verification and issuance of electronic invoices.
[0061] Optionally, in some possible implementations, before the ministerial key management center generates the provincial key, the process further includes:
[0062] The ministerial key management center and the provincial cryptographic service management platform synchronize the master key.
[0063] Optionally, in some possible implementations, when the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key, specifically including:
[0064] When the electronic ticket system receives a ticket purchase request, it calls the provincial cryptographic service management platform to obtain the station key by dividing the provincial key and the station code, and then encrypts the electronic ticket QR code with the station key.
[0065] Among them, the station code is the unique code of the station where the electronic ticket system is located.
[0066] Optionally, the station code can have 9 digits, for example, the first two digits are the province code, 3-4 digits are the region code, 5-6 digits are the county code, and the last three digits are the passenger station sequence code.
[0067] Optionally, in some possible implementations, the method further includes:
[0068] When the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset period of time, the electronic ticket verification system sends a local verification request containing the electronic ticket information to the station-level encryption machine;
[0069] After receiving the local ticket verification request, the station-level encryption machine checks whether the electronic ticket information is correct and returns the verification result to the electronic ticket verification system.
[0070] Optionally, in some possible implementations, the method further includes:
[0071] The provincial cryptographic service management platform will put the electronic ticket information that has passed the inspection into the synchronization queue, encrypt the electronic ticket information in the synchronization queue, and send the encrypted electronic ticket information in the form of a digital envelope to the ministerial key management center for storage.
[0072] The present invention also provides a road passenger electronic ticket password service management system, comprising: a ministerial key management center, a provincial password service management platform, an electronic ticket system, and an electronic ticket verification system, wherein:
[0073] The ministerial key management center is responsible for generating provincial keys, encrypting the provincial keys using a pre-agreed master key, and issuing the encrypted provincial keys to the provincial cryptographic service management platform;
[0074] After receiving the encrypted provincial key, the provincial cryptographic service management platform is used to decrypt the encrypted provincial key using the pre-agreed master key to obtain the provincial key and import it into the provincial platform certificate;
[0075] When the electronic ticket system receives a ticket purchase request, it calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the provincial key and signs the encrypted electronic ticket QR code using the provincial platform certificate.
[0076] The provincial platform certificate is also used to send the signed e-ticket QR code to the e-ticket system, and the e-ticket system is also used to send the signed e-ticket QR code to the user terminal;
[0077] When the electronic ticket verification system receives a ticket verification request, it scans the electronic ticket QR code, reads the electronic ticket information, and sends the electronic ticket information to the provincial password service management platform;
[0078] The provincial cryptographic service management platform is also used to verify whether the electronic ticket information is correct through the provincial key, and return the verification results to the electronic ticket verification system.
[0079] like Figure 3 As shown, a schematic diagram of the structure of an exemplary electronic ticket cryptographic service management system is provided, which includes: a ministerial key management center, a provincial cryptographic service management platform, and a station-level server cryptographic machine, wherein:
[0080] The ministerial key management center manages the national keys, including the master key, provincial keys and working keys of each province.
[0081] The Ministry-level Key Management Center primarily includes a cryptographic service management platform and server cryptographic machines. Aside from decrypting ticket information, the Ministry-level Key Management Center does not participate in specific cryptographic operations related to provincial ticket information. Its primary functions include managing master keys, generating and distributing provincial-level keys, and decrypting and aggregating electronic ticket transaction information sent by provincial centers.
[0082] The provincial platform primarily consists of a cryptographic service management platform and a server cryptographic machine. The provincial cryptographic service management platform manages the province's provincial keys and working keys, and is responsible for encrypting, decrypting, signing, and verifying provincial ticket information. It also packages provincial ticket data into digital envelopes for encrypted upload and encrypted upload. The provincial cryptographic service management platform is the security core of electronic tickets, and its main functions include:
[0083] a) Responsible for receiving provincial keys issued by the ministerial platform.
[0084] b) Responsible for receiving the work keys issued by the ministerial platform.
[0085] c) Encrypt the QR code data of the electronic ticket. The encrypted electronic ticket QR code information is generated through a discrete method of adding a provincial key and a site code. The QR code contains the ticket information and personal information.
[0086] d) Signature function. The platform pre-installs a provincial platform certificate to sign the e-ticket QR code data sent by the site platform. The e-ticket QR code data is decrypted using a discrete method of provincial key + site code. The decrypted e-ticket QR code contains both ticket information and personal information.
[0087] e) Signature verification function: After receiving the signature verification request sent by the station entrance, the signature of the sent QR code data is verified and the verification result is returned to the station entrance.
[0088] The station-level server cryptographic machine serves as a backup for the provincial cryptographic service management platform. In extreme cases, if the station loses connection with the provincial center network, the station-level server cryptographic machine will serve as an emergency function, taking on the decryption and signature verification of ticket information to ensure that passengers' travel is not affected. The station cryptographic module uses cryptographic devices or cryptographic programs to implement encryption and decryption functions. Its main functions are:
[0089] a) Decrypt the QR code data of the electronic ticket. The decrypted QR code of the electronic ticket contains ticket information and personal information through a discrete method of provincial key + site code.
[0090] b) Signature Verification. Upon receiving a signature verification request from the station entrance, the station verifies the signature of the QR code data and returns the verification result to the station entrance. The station platform primarily includes a USB password module or password program. It serves as a functional backup for the provincial center's password service management platform.
[0091] Optionally, in some possible implementations, the ministerial key management center and the provincial cryptographic service management platform are also used to synchronize the master key.
[0092] Optionally, in some possible implementations, when the electronic ticket system receives a ticket purchase request, the electronic ticket system is specifically configured to call a provincial cryptographic service management platform to obtain a station key by using a provincial key and a station code, and encrypt the electronic ticket QR code using the station key;
[0093] Among them, the station code is the unique code of the station where the electronic ticket system is located.
[0094] Optionally, in some possible implementations, the system further includes: a station-level encryption machine, wherein when the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset period of time, the electronic ticket verification system is further configured to send a local ticket verification request containing the electronic ticket information to the station-level encryption machine;
[0095] The station-level encryption machine is used to check whether the electronic ticket information is correct after receiving the local ticket verification request, and return the verification result to the electronic ticket verification system.
[0096] Optionally, in some possible implementations, the provincial cryptographic service management platform is also used to place the electronic ticket information that has passed verification into a synchronization queue, encrypt the electronic ticket information in the synchronization queue, and send the encrypted electronic ticket information in the form of a digital envelope to the ministerial key management center for storage.
[0097] It should be understood that the above-mentioned implementation is a product implementation corresponding to the previous method implementation. For the description of the product implementation, reference can be made to the description of the previous method implementation, and no further details will be given here.
[0098] It should be understood that, without departing from the spirit of the present invention, those skilled in the art may arbitrarily combine the above embodiments, all of which are within the scope of protection of the present invention.
[0099] The reader should understand that in the description of this specification, reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.
[0100] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the method embodiments described above are merely illustrative. For example, the division of steps is merely a logical function division. In actual implementation, other division methods may be used. For example, multiple steps may be combined or integrated into another step, or some features may be ignored or not performed.
[0101] If the above method is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0102] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A road passenger electronic ticket password service management method, characterized in that: include: The ministerial key management center generates a provincial key, encrypts the provincial key using a pre-agreed master key, and issues the encrypted provincial key to the provincial cryptographic service management platform; After receiving the encrypted provincial key, the provincial cryptographic service management platform uses the pre-agreed master key to decrypt the encrypted provincial key, obtains the provincial key, and imports it into the provincial platform certificate; When the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key, and uses the provincial platform certificate to sign the encrypted electronic ticket QR code; The provincial platform certificate sends the signed electronic ticket QR code to the electronic ticket system, and the electronic ticket system sends the signed electronic ticket QR code to the user terminal; When the electronic ticket verification system receives the ticket verification request, the electronic ticket verification system scans the electronic ticket QR code, reads the electronic ticket information, and sends the electronic ticket information to the provincial password service management platform; The provincial cryptographic service management platform verifies whether the electronic ticket information is correct using the provincial key, and returns the verification result to the electronic ticket verification system; Among them, the key system is divided into three levels: the first level is the master key, the second level is the provincial key, and the third level includes the transmission key, signature key and station key; The master key is the root key of the entire key system and is stored in the ministry-level key management center. The ministry-level key management center synchronizes the master key through backup and recovery when going online. After receiving the encrypted ticket data from the provincial cryptographic service management platform, the ministry-level key management center parses the digital envelope content, uses the SM2 private key in the cipher machine to decrypt the random SM4 key, uses the SM4 key to decrypt the ticket data, and stores the ticket information item by item in the database. The provincial key is generated by the ministerial key management center and distributed to the provincial cryptographic service management platform. The ministerial key management center uses SM4 to generate two key components. The provincial cryptographic service management platform sequentially fills the key components generated by the ministerial key management center into the corresponding component positions to form the provincial key. At the designated time, the provincial cryptographic service management platform digitally encapsulates the passenger ticket and sends it to the ministerial key management center. The ticket data is encrypted using a random SM4 key, and the random SM4 key is encrypted using the ministerial SM2 public key. The transmission key is generated by the key management center of the transmission initiator at all levels. The algorithm used is SM4 to encrypt the transmission information; the signature key is generated by the ministerial key management center, encrypted by the provincial key, and sent to the provincial cryptographic service management platform. The transmission key is encrypted in the transmission information to realize the signature envelope; the station key is discretized by the provincial key plus the station code, and is used to encrypt user personal information and pass information on the ticket. The station code is a unique code preset for the station in each province.
2. The road passenger electronic ticket password service management method according to claim 1, characterized in that: Before the ministerial key management center generates provincial keys, it also includes: The ministerial key management center and the provincial cryptographic service management platform synchronize the master key.
3. The road passenger transport electronic ticket password service management method according to claim 1, characterized in that: When the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the station key, specifically including: When the electronic ticket system receives a ticket purchase request, the electronic ticket system calls the provincial cryptographic service management platform to obtain a station key by disentangling the provincial key and the station code, and encrypts the electronic ticket QR code with the station key; The station code is the unique code of the station where the electronic ticket system is located.
4. The method for managing password services for road passenger electronic tickets according to claim 1, characterized in that: Also includes: When the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset period of time, the electronic ticket verification system sends a local ticket verification request containing the electronic ticket information to the station-level encryption machine; After receiving the local ticket verification request, the station-level encryption machine checks whether the electronic ticket information is correct and returns the verification result to the electronic ticket verification system.
5. The road passenger electronic ticket password service management method according to claim 1, characterized in that: Also includes: The provincial cryptographic service management platform puts the electronic ticket information that has passed the verification into a synchronization queue, encrypts the electronic ticket information in the synchronization queue, and sends the encrypted electronic ticket information to the ministerial key management center in the form of a digital envelope for storage.
6. A road passenger electronic ticket password service management system, characterized in that: include: Ministry-level key management center, provincial-level cryptographic service management platform, electronic ticket system and electronic ticket verification system, including: The ministerial key management center is used to generate provincial keys, encrypt the provincial keys using a pre-agreed master key, and issue the encrypted provincial keys to the provincial cryptographic service management platform; After receiving the encrypted provincial key, the provincial cryptographic service management platform is used to decrypt the encrypted provincial key using a pre-agreed master key to obtain the provincial key and import it into the provincial platform certificate; When the electronic ticket system receives a ticket purchase request, the electronic ticket system is configured to call the provincial cryptographic service management platform to encrypt the electronic ticket QR code using the provincial key, and use the provincial platform certificate to sign the encrypted electronic ticket QR code; The provincial platform certificate is also used to send the signed electronic ticket QR code to the electronic ticket system, and the electronic ticket system is also used to send the signed electronic ticket QR code to the user terminal; When the electronic ticket verification system receives the ticket verification request, the electronic ticket verification system is used to scan the electronic ticket QR code, read the electronic ticket information, and send the electronic ticket information to the provincial password service management platform; The provincial cryptographic service management platform is further configured to verify whether the electronic ticket information is correct using the provincial key and return the verification result to the electronic ticket verification system; Among them, the key system is divided into three levels: the first level is the master key, the second level is the provincial key, and the third level includes the transmission key, signature key and station key; The master key is the root key of the entire key system and is stored in the ministry-level key management center. The ministry-level key management center synchronizes the master key through backup and recovery when going online. After receiving the encrypted ticket data from the provincial cryptographic service management platform, the ministry-level key management center parses the digital envelope content, uses the SM2 private key in the cipher machine to decrypt the random SM4 key, uses the SM4 key to decrypt the ticket data, and stores the ticket information item by item in the database. The provincial key is generated by the ministerial key management center and distributed to the provincial cryptographic service management platform. The ministerial key management center uses SM4 to generate two key components. The provincial cryptographic service management platform sequentially fills the key components generated by the ministerial key management center into the corresponding component positions to form the provincial key. At the designated time, the provincial cryptographic service management platform digitally encapsulates the passenger ticket and sends it to the ministerial key management center. The ticket data is encrypted using a random SM4 key, and the random SM4 key is encrypted using the ministerial SM2 public key. The transmission key is generated by the key management center of the transmission initiator at all levels. The algorithm used is SM4 to encrypt the transmission information; the signature key is generated by the ministerial key management center, encrypted by the provincial key, and sent to the provincial cryptographic service management platform. The transmission key is encrypted in the transmission information to realize the signature envelope; the station key is discretized by the provincial key plus the station code, and is used to encrypt user personal information and pass information on the ticket. The station code is a unique code preset for the station in each province.
7. The road passenger electronic ticket password service management system according to claim 6 is characterized in that: The ministerial key management center and the provincial cryptographic service management platform are also used to synchronize master keys.
8. The road passenger electronic ticket password service management system according to claim 6 is characterized in that: When the electronic ticket system receives a ticket purchase request, the electronic ticket system is specifically configured to call the provincial cryptographic service management platform to obtain a station key by disentangling the provincial key and the station code, and encrypt the electronic ticket QR code by using the station key; The station code is the unique code of the station where the electronic ticket system is located.
9. The road passenger electronic ticket password service management system according to claim 6, characterized in that: The system further includes: a station-level encryption machine, wherein when the electronic ticket verification system does not receive the verification result returned by the provincial cryptographic service management platform for a preset time, the electronic ticket verification system is further configured to send a local ticket verification request containing the electronic ticket information to the station-level encryption machine; The station-level encryption machine is used to check whether the electronic ticket information is correct after receiving the local ticket verification request, and return the verification result to the electronic ticket verification system.
10. The road passenger electronic ticket password service management system according to claim 6, characterized in that: The provincial cryptographic service management platform is also used to place the electronic ticket information that has passed verification into a synchronization queue, encrypt the electronic ticket information in the synchronization queue, and send the encrypted electronic ticket information to the ministerial key management center in the form of a digital envelope for storage.
Citation Information
Patent Citations
Bill information verification method and system, server, and computer readable storage medium
CN107835172A
Air ticket management method and device
CN109472667A