Key retrieval method, server and identification card

By dividing operator servers in the metaverse, the security of user key recovery is achieved, and the asset risk problem caused by operator control is solved, ensuring the security of user information and assets.

CN115734215BActive Publication Date: 2025-08-19CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211064489.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-01
Publication Date
2025-08-19
Estimated Expiration
2042-09-01

AI Technical Summary

Technical Problem

In the metaverse, after a user loses his private key, the operator takes control and leads to criminals being prone to maliciously obtaining the user's private key, resulting in the inability to protect asset risks.

Method used

The server on the operator side is divided into the operator service server and the operator security server. The operator service server performs key recovery and the operator security server performs identification card configuration to ensure that the key and information are not known by the service server.

Benefits of technology

Through business and server division, the security of the user's key recovery process is guaranteed and the risk of information and asset losses caused by criminals maliciously obtaining user's private keys is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115734215B_ABST
    Figure CN115734215B_ABST
Patent Text Reader

Abstract

The present application discloses a key retrieval method, server, and identification card, relating to the field of communication technology. The method comprises: in the event that a first identification card is lost, a terminal sends a key retrieval request to an operator service server; in the event that a first encryption result is returned by the operator service server, the first encryption result is decrypted based on a first key parameter to obtain random information; in the event that a second encryption result sent by the first identification card is obtained from a preset address, the second encryption result is decrypted based on the random information to obtain a key; the key, the first key parameter, and the preset address are provided to the operator security server, so that the operator security server configures a second identification card based on the key, the first key parameter, and the preset address, allowing the terminal to log in to the preset client through the second identification card. This method can improve the security of user key retrieval and reduce the occurrence of situations such as loss of user information and assets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a key retrieval method, a server, and an identification card. Background Art

[0002] The Metaverse is a virtual world connected and created through technological means, mirroring and interacting with the real world. It is a digital living space that embodies a new social system. User information and assets in the Metaverse exist in digital form. User identity relies on private keys. Loss of private keys can lead to the collapse of the user's personal universe.

[0003] In related technologies, after a user loses his private key, he can retrieve it through the operator.

[0004] However, since operators have relatively absolute control over private keys, it is easy for criminals to maliciously obtain user private keys through operators, thereby posing a greater risk to users' assets in the metaverse and failing to effectively protect users' interests. Summary of the Invention

[0005] To this end, the present application provides a key retrieval method, server, and identification card to solve the problem of criminals maliciously obtaining user private keys through operators, resulting in loss of user information and assets.

[0006] In order to achieve the above-mentioned object, the first aspect of the present application provides a key retrieval method, applied to a terminal, the method comprising:

[0007] In the event that the first identification card is lost, a key retrieval request is sent to the operator service server; wherein the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key, and the key retrieval request is used to trigger the operator service server to send a key retrieval instruction to the first identification card;

[0008] Upon receiving the first encryption result returned by the operator service server, decrypting the first encryption result based on the first key parameter to obtain random information; wherein the first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter;

[0009] When a second encryption result sent by the first identification card is obtained from the preset address, the second encryption result is decrypted according to the random information to obtain the key; wherein the second encryption result is a result of the first identification card encrypting the built-in key based on the random information;

[0010] The key, the first key parameter and the preset address are provided to the operator security server, so that the operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

[0011] Furthermore, in the case where the first identification card is lost, after sending the key retrieval request to the operator service server, the method further includes:

[0012] Receiving identity authentication from the operator's service server and obtaining an identity authentication result;

[0013] Wherein, when the identity authentication result is passed, the operator service server sends the key retrieval instruction to the first identification card.

[0014] Furthermore, providing the key, the first key parameter, and the preset address to the operator security server includes:

[0015] Inputting the key, the first key parameter, and the preset address into the operator security server through a preset security keyboard;

[0016] The processing process and results of the operator security server are not displayed to the operator business server.

[0017] In order to achieve the above-mentioned purpose, the second aspect of the present application provides a key retrieval method applied to an operator service server, the method comprising:

[0018] In response to a key retrieval request sent by the terminal, sending a key retrieval instruction to the first identification card; wherein the key retrieval request is sent when the first identification card is lost, and the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key;

[0019] receiving a first encryption result sent by the first identification card; wherein the first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter;

[0020] The first encryption result is forwarded to the terminal so that the terminal decrypts the first encryption result based on the first key parameter to obtain the random information, and decrypts the second encryption result based on the random information to obtain the key. The operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card; wherein the second encryption result is the result of the first identification card encrypting the built-in key based on the random information.

[0021] Furthermore, the sending of the key retrieval instruction to the first identification card includes:

[0022] The key retrieval instruction is sent to the first identification card through a preset signaling channel.

[0023] To achieve the above-mentioned object, the third aspect of the present application provides a key retrieval method, which is applied to a first identification card, wherein the first identification card has a built-in key for logging into a preset client, and a first key parameter and a preset address for retrieving the key, the method comprising:

[0024] generating random information in response to a key retrieval instruction sent by the operator service server;

[0025] Encrypting the random information based on the first built-in key parameter to obtain a first encryption result;

[0026] Encrypting the built-in key based on the random information to obtain a second encryption result;

[0027] Forwarding the first encryption result to the terminal through the operator service server;

[0028] The second encryption result is sent to the preset address so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key. The operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0029] Furthermore, before generating random information in response to the key retrieval instruction sent by the operator service server, the method further includes:

[0030] Upon receiving the key retrieval instruction, determining the number of times the key retrieval instruction is received within a preset period;

[0031] Determine whether to respond to the key retrieval instruction based on a preset threshold and the number of times.

[0032] In order to achieve the above-mentioned object, the fourth aspect of the present application provides a terminal, which includes:

[0033] a first sending module, configured to send a key retrieval request to an operator service server when a first identification card is lost; wherein the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key, and the key retrieval request is configured to trigger the operator service server to send a key retrieval instruction to the first identification card;

[0034] a first decryption module, configured to, upon receiving a first encryption result returned by the operator service server, decrypt the first encryption result based on the first key parameter to obtain random information; wherein the first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter;

[0035] a second decryption module configured to, upon obtaining a second encryption result sent by the first identification card from the preset address, decrypt the second encryption result according to the random information to obtain the key; wherein the second encryption result is a result of the first identification card encrypting the built-in key based on the random information;

[0036] A configuration module is used to provide the key, the first key parameter and the preset address to the operator security server, so that the operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

[0037] In order to achieve the above-mentioned purpose, the fifth aspect of the present application provides an operator service server, which includes:

[0038] a second sending module, configured to send a key retrieval instruction to the first identification card in response to a key retrieval request sent by the terminal; wherein the key retrieval request is sent when the first identification card is lost, and the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key;

[0039] a receiving module, configured to receive a first encryption result sent by the first identification card; wherein the first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter;

[0040] A third sending module is used to forward the first encryption result to the terminal, so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card; wherein, the second encryption result is the result of the first identification card encrypting the built-in key based on the random information.

[0041] To achieve the above-mentioned object, the sixth aspect of the present application provides a first identification card, wherein the first identification card has a built-in key for logging into a preset client, and a first key parameter and a preset address for retrieving the key, the first identification card comprising:

[0042] A generating module, configured to generate random information in response to a key retrieval instruction sent by an operator service server;

[0043] a first encryption module, configured to encrypt the random information based on the first built-in key parameter to obtain a first encryption result;

[0044] A second encryption module, configured to encrypt the built-in key based on the random information to obtain a second encryption result;

[0045] a fourth sending module, configured to forward the first encryption result to the terminal through the operator service server;

[0046] The fifth sending module is used to send the second encryption result to the preset address, so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0047] In order to achieve the above-mentioned objectives, the seventh aspect of the present application provides an electronic device and a readable storage medium.

[0048] The present application provides an electronic device, comprising: one or more processors; a memory on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement any one of the key retrieval methods in the embodiments of the present application.

[0049] An embodiment of the present application provides a readable storage medium, which stores a computer program. When the computer program is executed by a processor, any one of the key retrieval methods in the embodiments of the present application is implemented.

[0050] This application has the following advantages:

[0051] The present application provides a key retrieval method, server, and identification card. In the event that a first identification card is lost, a terminal sends a key retrieval request to an operator service server. The first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key. The key retrieval request is used to trigger the operator service server to send a key retrieval instruction to the first identification card. Upon receiving a first encryption result returned by the operator service server, the first encryption result is decrypted based on the first key parameter to obtain random information. The first encryption result is the result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter. Upon obtaining a second encryption result sent by the first identification card from the preset address, the second encryption result is decrypted based on the random information to obtain a key. The second encryption result is the result of the first identification card encrypting the built-in key based on the random information. The key, first key parameter, and preset address are provided to the operator security server so that the operator security server can configure a second identification card based on the key, first key parameter, and preset address, so that the terminal can log in to the preset client through the second identification card. This method divides the operator's server into an operator business server and an operator security server. The operator business server performs basic services such as signaling interaction before key retrieval, while the operator security server performs identification card configuration operations, so that the key and related information are not known to the operator business server. Through business division and server division, the security of the user key retrieval process is guaranteed, thereby effectively reducing the possibility of criminals maliciously obtaining user private keys through the operator, resulting in loss of user information and assets. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings are used to provide further understanding of the present application and constitute a part of the specification. Together with the following specific embodiments, they are used to explain the present application, but do not constitute a limitation to the present application.

[0053] Figure 1 This is a flowchart of a key retrieval method provided in an embodiment of the present application;

[0054] Figure 2 This is a flowchart of a key retrieval method provided in an embodiment of the present application;

[0055] Figure 3This is a flowchart of a key retrieval method provided in an embodiment of the present application;

[0056] Figure 4 This is a block diagram of a terminal provided in an embodiment of the present application;

[0057] Figure 5 This is a block diagram of an operator service server provided in an embodiment of the present application;

[0058] Figure 6 This is a block diagram of an identification card provided in an embodiment of the present application;

[0059] Figure 7 This is a schematic diagram of the working process of a key retrieval method provided in an embodiment of the present application;

[0060] Figure 8 This is a signaling diagram of a key retrieval method provided in an embodiment of the present application;

[0061] Figure 9 This is a block diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] The following describes the specific embodiments of the present application in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the present application and are not intended to limit the present application.

[0063] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0064] The terms used in this application are only used to describe particular embodiments and are not intended to limit this application.As used in this application, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0065] When the terms "comprising" and / or "made of..." are used in this application, it specifies the existence of the stated features, integers, steps, operations, elements and / or components, but does not preclude the existence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0066] Unless otherwise defined, all terms (including technical and scientific terms) used in this application have the same meaning as commonly understood by those skilled in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this application, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined in this application.

[0067] The Metaverse is a virtual world connected and created through technological means, mirroring and interacting with the real world. It is a digital living space that embodies a new social system. User information and assets in the Metaverse exist in digital form. User identity is identified by their private key (i.e., secret key). Users can log in to their Metaverse client using their identification card to view relevant information or conduct transactions. Similarly, users can use identification cards to log in to clients based on technologies such as blockchain.

[0068] Losing a key could lead to the collapse of a user's personal universe / blockchain. In related technologies, users can retrieve their lost keys through their operators. However, because operators have relatively absolute control over the keys, it's easy for criminals to maliciously obtain users' private keys through them, posing a significant risk to users' assets in the metaverse and failing to effectively protect their interests.

[0069] In view of this, in an embodiment of the present application, when retrieving user keys, the server on the operator side is divided into an operator business server and an operator security server. The operator business server performs basic services such as signaling interaction before key retrieval, and the operator security server performs identification card configuration operations, so that the key and related information are not known to the operator business server. Through business division and server division, the security of the user key retrieval process is guaranteed, thereby effectively reducing the occurrence of situations where criminals maliciously obtain user private keys through operators, resulting in loss of user information and assets.

[0070] In a first aspect, an embodiment of the present application provides a key retrieval method.

[0071] Figure 1 This is a flowchart of a key retrieval method provided by an embodiment of the present application, which can be applied to a terminal. Figure 1 As shown, the key retrieval method includes the following steps:

[0072] Step S101: When the first identification card is lost, a key retrieval request is sent to the operator's service server.

[0073] The first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key. The key retrieval request is used to trigger the operator service server to send a key retrieval instruction to the first identification card.

[0074] In some possible implementations, the first identification card may be a Subscriber Identity Model Card (SIM card), and the user may pre-embed a key and a first key parameter in the first identification card, so that the user can log in to a preset client based on the key. The preset client may be a metaverse client, a blockchain client, etc. The first key parameter is a parameter used to retrieve the first key, which may be a password, a verification code, etc., and the first key parameter may be updated as needed (for example, updated according to a preset period or updated when the identification card is reconfigured). The embodiment of the present application does not limit the type and update method of the first key parameter.

[0075] In some possible implementations, after a user loses the first identification card, the user sends a key retrieval request to the operator service server to retrieve the key embedded in the first identification card. In response to the key retrieval request, the operator service server sends a key retrieval instruction to the first identification card.

[0076] It should be noted that a user can initiate a key retrieval request to an operator's service server either online or offline. For example, after losing their first identification card, the user can use their terminal to send a key retrieval request to the operator's service server via a network (wired network, wireless network, etc.). Alternatively, after losing their first identification card, the user can initiate a key retrieval request at the operator's business hall.

[0077] It should also be noted that in some possible implementations, after the operator service server receives the key retrieval request initiated by the user, it will also authenticate the terminal to ensure that the key retrieval request is initiated by a legitimate terminal or legitimate user, thereby minimizing the risk of a third party impersonating the user to steal the key.

[0078] For example, after receiving the key retrieval request, the operator service server authenticates the terminal and obtains an authentication result. Moreover, only if the authentication result is passed, the operator service server will perform subsequent key retrieval operations (for example, sending a key retrieval instruction to the first identification card).

[0079] Among them, identity authentication can be implemented based on any one or more methods such as identity information reserved by the user on the operator side, security answers corresponding to preset security questions, dynamic verification code verification, biometric information recognition, etc. This application does not limit the implementation method of identity authentication.

[0080] Step S102: upon receiving the first encryption result returned by the operator service server, decrypt the first encryption result based on the first key parameter to obtain random information.

[0081] The first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter.

[0082] In some possible implementations, after step S101, after the first identification card receives the key retrieval instruction sent by the operator service server, it generates random information, encrypts the random information based on the built-in first key parameter to obtain a first encryption result, and forwards the first encryption result to the terminal via the operator service server. Upon receiving the first encryption result sent by the first identification card, the operator service server forwards the first encryption result to the terminal. After receiving the first encryption result, the terminal decrypts the first encryption result based on the first key parameter to obtain random information. This random information can be used to decrypt the second encryption result.

[0083] In some possible implementations, the random information can be random numbers, random strings, or other random information. This embodiment of the present application does not limit the random information. It should be understood that applying random information to the encryption and decryption process can, to a certain extent, enhance the difficulty of encryption and decryption and reduce the possibility of stealing user information.

[0084] For example, the first identification card generates a random number in response to the key retrieval instruction and encrypts the random number using a first key parameter based on a preset first encryption algorithm to obtain a first encryption result. Upon receiving the first encryption result sent by the first identification card and forwarded by the operator's service server, the terminal decrypts the first encryption result using a preset first decryption algorithm to obtain random information. The first decryption algorithm is a decryption algorithm corresponding to the first encryption algorithm.

[0085] Step S103: when the second encryption result sent by the first identification card is obtained from the preset address, the second encryption result is decrypted according to the random information to obtain the key.

[0086] The second encryption result is a result of the first identification card encrypting the built-in key based on the random information. The random information is information generated by the first identification card in response to the key retrieval instruction.

[0087] In some possible implementations, after step S101, in addition to generating the first encryption result, the first identification card further encrypts the built-in key based on the random information to obtain a second encryption result, and sends the second encryption result to a preset address. After the terminal obtains the second encryption result from the preset address, the terminal decrypts the second encryption result using the random information obtained based on step S102 to obtain the key.

[0088] In some possible implementations, the preset address may be a mailbox. In other words, the first identification card sends the second encryption result to the mailbox, and the terminal obtains the second encryption result from the mailbox.

[0089] It should be noted that the preset address may also be other types of addresses such as a network hard disk, and the embodiment of the present application does not limit the type of the preset address.

[0090] For example, the first identification card generates a random number in response to the key retrieval instruction, and uses the random number to encrypt the built-in key based on a preset second encryption algorithm to obtain a second encryption result, and then sends the second encryption result to a mailbox corresponding to a preset address. Upon receiving the second encryption result from the mailbox, the terminal uses a preset second decryption algorithm to decrypt the second encryption result based on the random information obtained by decryption to obtain the key. The second decryption algorithm is a decryption algorithm corresponding to the second encryption algorithm.

[0091] Step S104: providing the key, the first key parameter and the preset address to the operator security server, so that the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

[0092] Among them, the security level of the operator security server is higher than that of the operator business server, and there is a physical isolation or logical isolation structure between it and the operator business server, so that the processing process and processing results of the operator security server are not displayed to the operator business server, thereby further ensuring the security of user information.

[0093] In some possible implementations, the key, the first key parameter, and the preset address are input into the operator security server through a preset security keyboard.

[0094] In some possible implementations, the terminal sends the key, the first key parameter, and the preset address to the operator's security server through a dedicated communication link.

[0095] It should also be noted that, for security reasons, after retrieving the key, the user can change the first key parameters and / or preset address and use the key and the changed first key parameters and / or preset address to configure a second identification card. The terminal can log in to the preset client through the configured second identification card.

[0096] In an embodiment of the present application, in the event that the first identification card is lost, the terminal sends a key retrieval request to the operator service server; upon receiving the first encryption result returned by the operator service server, the first encryption result is decrypted based on the first key parameter to obtain random information; upon obtaining the second encryption result sent by the first identification card from the preset address, the second encryption result is decrypted based on the random information to obtain the key; the key, the first key parameter and the preset address are provided to the operator security server, so that the operator security server can configure the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card. This method divides the server on the operator side into an operator service server and an operator security server, with the operator service server performing basic services such as signaling interaction in the early stage of key retrieval, and the operator security server performing identification card configuration operations, so that the key and related information are not known to the operator service server. Through service division and server division, the security of the user key retrieval process is guaranteed, thereby effectively reducing the occurrence of situations where criminals maliciously obtain user private keys through operators, resulting in loss of user information and assets.

[0097] Figure 2 This is a flowchart of a key retrieval method provided by an embodiment of the present application, which can be applied to an operator's service server. Figure 2 As shown, the key retrieval method includes the following steps:

[0098] Step S201: In response to a key retrieval request sent by a terminal, a key retrieval instruction is sent to a first identification card.

[0099] The key retrieval request is a request sent when the first identification card is lost. The first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key.

[0100] In some possible implementations, after a user loses the first identification card, the user sends a key retrieval request to the operator service server to retrieve the key embedded in the first identification card. In response to the key retrieval request, the operator service server sends a key retrieval instruction to the first identification card.

[0101] In some possible implementations, the operator's service server sends a key retrieval instruction to the first identification card via a pre-set signaling channel. It should be noted that a signaling channel is a channel used by telecommunications operators specifically for sending various types of signaling. Unlike conventional service-level data channels, it has a relatively high level of security. Furthermore, regardless of the terminal device in which the first identification card is located, as long as the terminal device is powered on, the first identification card will receive the key retrieval instruction.

[0102] Step S202: receiving a first encryption result sent by a first identification card.

[0103] The first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter.

[0104] In some possible implementations, the first identification card generates random information locally in response to a key retrieval instruction sent by the operator service server, and encrypts the random information using a preset first encryption algorithm using a built-in first key parameter to obtain a first encryption result, and sends the first encryption result to the operator service server through a preset signaling channel.

[0105] In step S203, the first encryption result is forwarded to the terminal so that the terminal decrypts the first encryption result based on the first key parameter to obtain random information, and decrypts the second encryption result based on the random information to obtain the key. The operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

[0106] In some possible implementations, in addition to generating the first encryption result, the first identification card also encrypts a built-in key based on random information to obtain a second encryption result, and sends the second encryption result to a preset address. After the terminal obtains the second encryption result from the preset address, it decrypts the second encryption result using the random information obtained by decrypting the first encryption result to obtain the key. Furthermore, the terminal provides the key, first key parameters, and preset address to the operator security server. The operator security server configures the second identification card based on the key, first key parameters, and preset address, allowing the terminal to log in to the preset client through the second identification card.

[0107] Among them, the security level of the operator security server is higher than that of the operator business server, and there is a physical isolation or logical isolation structure between it and the operator business server, so that the processing process and processing results of the operator security server are not displayed to the operator business server, thereby further ensuring the security of user information.

[0108] It should be noted that for security reasons, after retrieving the key, the user can change the first key parameters and / or preset address, so that the operator's security server can use the key and the changed first key parameters and / or preset address to configure the second identification card. The terminal can then log in to the preset client using the configured second identification card.

[0109] Figure 3This is a flowchart of a key retrieval method provided by an embodiment of the present application. The key retrieval method can be applied to a first identification card, which has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key. Figure 3 As shown, the key retrieval method includes the following steps:

[0110] Step S301: Generate random information in response to a key retrieval instruction sent by an operator service server.

[0111] In some possible implementations, the operator service server sends a key retrieval instruction to the first identification card through a preset signaling channel. In response to the key retrieval instruction, the first identification card generates random information locally.

[0112] It should be noted that the signaling channel is a channel dedicated by telecommunications operators for sending various types of signaling. Unlike conventional service-level data channels, it has a relatively high level of security. Furthermore, regardless of which terminal device the first identification card is located in, as long as the terminal device is powered on, the first identification card will receive the key retrieval instruction.

[0113] Step S302: Encrypt the random information based on the built-in first key parameter to obtain a first encryption result.

[0114] In some possible implementations, the random information can be random numbers, random strings, or other random information. This embodiment of the present application does not limit the random information. It should be understood that applying random information to the encryption and decryption process can, to a certain extent, enhance the difficulty of encryption and decryption and reduce the possibility of stealing user information.

[0115] For example, the first identification card generates a random number in response to the key retrieval instruction, and encrypts the random number using a first key parameter based on a preset first encryption algorithm to obtain a first encryption result.

[0116] Step S303: encrypt the built-in key based on the random information to obtain a second encryption result.

[0117] For example, the first identification card generates a random number in response to the key retrieval instruction, and uses the random number to encrypt the built-in key based on a preset second encryption algorithm to obtain a second encryption result.

[0118] It should be noted that step S302 and step S303 can be executed simultaneously, or step S302 can be executed first and then step S303, or step S303 can be executed first and then step S302. The embodiment of the present application does not limit the execution order of step S302 and step S303.

[0119] Step S304: forward the first encryption result to the terminal through the operator service server.

[0120] In some possible implementations, the first identification card sends the first encryption result to the operator server through a preset signaling channel, and the operator server then forwards the first encryption result to the terminal.

[0121] In step S305, the second encryption result is sent to a preset address so that the terminal can decrypt the first encryption result based on the first key parameter to obtain random information, and decrypt the second encryption result based on the random information to obtain the key. The operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0122] In some possible implementations, the preset address may be a mailbox. In other words, the first identification card sends the second encryption result to the mailbox, and the terminal obtains the second encryption result from the mailbox.

[0123] It should be noted that the preset address may also be other types of addresses such as a network hard disk, and the embodiment of the present application does not limit the type of the preset address.

[0124] In some possible implementations, upon receiving a first encryption result sent by a first identification card and forwarded by an operator's service server, the terminal decrypts the first encryption result using a preset first decryption algorithm to obtain random information. Upon obtaining a second encryption result from a preset address, the terminal decrypts the second encryption result using a preset second decryption algorithm based on the random information obtained through decryption to obtain a key. The first decryption algorithm is a decryption algorithm corresponding to the first encryption algorithm, and the second decryption algorithm is a decryption algorithm corresponding to the second encryption algorithm. The terminal provides the key, first key parameters, and preset address to the operator's security server. The operator's security server configures the second identification card based on the key, first key parameters, and preset address, allowing the terminal to log in to the preset client through the second identification card.

[0125] Among them, the security level of the operator security server is higher than that of the operator business server, and there is a physical isolation or logical isolation structure between it and the operator business server, so that the processing process and processing results of the operator security server are not displayed to the operator business server, thereby further ensuring the security of user information.

[0126] It should also be noted that, for security reasons, after retrieving the key, the user can change the first key parameters and / or preset address and use the key and the changed first key parameters and / or preset address to configure a second identification card. The terminal can log in to the preset client through the configured second identification card.

[0127] In some possible implementations, before step S301, the process further includes: upon receiving a key retrieval instruction, determining the number of key retrieval instructions received within a preset period; and determining whether to respond to the key retrieval instruction based on a preset threshold and the number of times. The preset threshold can be set based on experience, statistical data, actual needs, etc., and is not limited in this embodiment of the present application.

[0128] In some possible implementations, determining whether to respond to the key retrieval instruction based on a preset threshold and number of times includes:

[0129] When the number of times is greater than or equal to the preset threshold, the key retrieval instruction is delayed, or the key retrieval instruction is refused to be responded to; when the number of times is less than the preset threshold, the key retrieval instruction is responded to.

[0130] In summary, if the number of times is less than the preset threshold, it indicates that the first identification card has not frequently received the key retrieval instruction. Therefore, it can be preliminarily determined that the key retrieval instruction is a relatively safe and authentic instruction. Conversely, if the number of times exceeds the preset threshold, it indicates that the first identification card has received the key retrieval instruction relatively frequently, which is not normal. Therefore, the first identification card can avoid leaking the key by delaying or rejecting the response mechanism.

[0131] In summary, by setting a preset threshold and determining the execution method of the key retrieval instruction based on the preset threshold, it is possible to effectively deal with hackers who attempt to illegally obtain keys through massive data, thereby improving the security of key retrieval.

[0132] In an embodiment of the present application, the first identification card sends the first encryption result and the second encryption result through the signaling channel and the data channel respectively, and the terminal obtains the key through the decryption operation. Finally, the operator's security server with higher security configures a new second identification card, which effectively improves the security of key retrieval and ensures the user's information security.

[0133] The steps of the various methods above are divided only for the purpose of clear description. During implementation, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process without changing the core design of the algorithm and process are all within the scope of protection of this patent.

[0134] In a second aspect, an embodiment of the present application provides a terminal and a server.

[0135] Figure 4 This is a block diagram of a terminal provided by an embodiment of the present application. Figure 4 As shown, the terminal includes:

[0136] The first sending module 401 is configured to send a key retrieval request to the operator service server when the first identification card is lost.

[0137] The first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key. The key retrieval request is used to trigger the operator service server to send a key retrieval instruction to the first identification card.

[0138] The first decryption module 402 is configured to, upon receiving the first encryption result returned by the operator service server, decrypt the first encryption result based on the first key parameter to obtain random information.

[0139] The first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter.

[0140] The second decryption module 403 is configured to, when obtaining the second encryption result sent by the first identification card from the preset address, decrypt the second encryption result according to the random information to obtain a key.

[0141] The second encryption result is a result of the first identification card encrypting the built-in key based on the random information.

[0142] The configuration module 404 is used to provide the key, the first key parameter and the preset address to the operator security server, so that the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0143] Figure 5 This is a block diagram of an operator service server provided in an embodiment of the present application. Figure 5 As shown, the operator service server includes:

[0144] The second sending module 501 is configured to send a key retrieval instruction to the first identification card in response to the key retrieval request sent by the terminal.

[0145] The key retrieval request is a request sent when the first identification card is lost. The first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key.

[0146] The receiving module 502 is configured to receive a first encryption result sent by a first identification card.

[0147] The first encryption result is a result of the first identification card generating random information in response to the key retrieval instruction and encrypting the random information based on the built-in first key parameter.

[0148] The third sending module 503 is used to forward the first encryption result to the terminal, so that the terminal can decrypt the first encryption result based on the first key parameter to obtain random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card; wherein, the second encryption result is the result of the first identification card encrypting the built-in key based on the random information.

[0149] Figure 6 This is a block diagram of an identification card provided in an embodiment of the present application. Figure 6 As shown, the identification card includes:

[0150] The generating module 601 is configured to generate random information in response to a key retrieval instruction sent by the operator service server.

[0151] The first encryption module 602 is configured to encrypt the random information based on a built-in first key parameter to obtain a first encryption result.

[0152] The second encryption module 603 is configured to encrypt the built-in key based on the random information to obtain a second encryption result.

[0153] The fourth sending module 604 is configured to forward the first encryption result to the terminal through the operator service server.

[0154] The fifth sending module 605 is used to send the second encryption result to a preset address so that the terminal can decrypt the first encryption result based on the first key parameter to obtain random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0155] The functions or modules included in the device provided in the embodiments of the present application can be used to execute the method described in the first aspect method embodiment above. Its specific implementation and technical effects can refer to the description of the above method embodiment. For the sake of brevity, they will not be repeated here.

[0156] It should be noted that all modules involved in this embodiment are logical modules. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovation of this application, this embodiment does not include units that are not closely related to solving the technical problem proposed by this application. However, this does not mean that other units do not exist in this embodiment.

[0157] The following combination Figure 7 The key retrieval method of the embodiment of the present application is described in detail.

[0158] Figure 7 This is a schematic diagram of the working process of a key retrieval method provided in an embodiment of the present application. Figure 7 As shown, the working process includes:

[0159] Step S701: The user embeds a key SK, a first key parameter PWD, and a preset address addr in a first SIM card.

[0160] Among them, SK is equivalent to the user's metaverse blockchain private key, PWD is the password set by the user, and addr is the user's email address.

[0161] Step S702: When the user loses the first SIM card, the user goes to the operator's business hall to initiate a key retrieval request, and the operator's service server sends a key retrieval instruction to the first SIM card through a signaling channel.

[0162] The operator service server may perform identity authentication on the user, and only when the identity authentication is passed will the operator service server send a key retrieval instruction to the first SIM card.

[0163] It should be noted that no matter which terminal device the first SIM card is in, as long as the terminal where the first SIM card is located is powered on, the first SIM card can receive the key retrieval instruction sent by the operator's service server.

[0164] In step S703, the first SIM card generates a random string Rand locally in response to the key retrieval instruction, calculates a first encryption result EPWD(Rand) according to a pre-agreed first encryption algorithm, and sends the first encryption result to the operator service server, where EPWD() represents the first encryption algorithm with PWD as the calculation parameter.

[0165] In step S704, the first SIM card calculates ERand(SK) according to the pre-agreed second encryption algorithm to obtain a second encryption result, and sends the second encryption result to the preset address addr, where ERand() represents the second encryption algorithm using Rand as a calculation parameter.

[0166] Step S705: The operator service server receives the first encryption result and feeds the first encryption result back to the user or the user's terminal.

[0167] Step S706: The user or terminal decrypts the first encryption result using the PWD according to a pre-agreed first decryption algorithm to obtain a random character string Rand.

[0168] Step S707: The user or terminal obtains the second encryption result from addr, and decrypts the second encryption result using Rand according to the pre-agreed second encryption algorithm to obtain SK.

[0169] In step S708, the user inputs PWD, SK and addr to the operator's security server through the PIN pad. The operator's security server configures the second SIM card using the above information and delivers the second SIM card to the user.

[0170] In step S709, the user places the second SIM card into the terminal and uses the information in the second SIM card to log in to the Metaverse client again.

[0171] Figure 8 This is a signaling diagram of a key retrieval method provided in an embodiment of the present application.

[0172] like Figure 8 As shown, the signaling interaction process includes:

[0173] Step S801: The terminal sends a key retrieval request to the operator's service server.

[0174] Step S802: The service server performs identity authentication on the terminal in response to the key retrieval request.

[0175] Step S803: When the terminal passes the identity authentication, the operator service server sends a key retrieval instruction to the first identification card.

[0176] Step S804: The first identification card receives the key retrieval instruction, generates random information, encrypts the random information using the built-in first key parameter, obtains a first encryption result, and sends the first encryption result to the operator service server.

[0177] Step S805: The operator service server forwards the first encryption result to the terminal.

[0178] Step S806: The first identification card encrypts the built-in key using the random information to obtain a second encryption result, and sends the second encryption result to a preset address.

[0179] Step S807: The terminal decrypts the first encryption result based on the first key parameter to obtain random information.

[0180] Step S808: The terminal obtains a second encryption result from a preset address.

[0181] Step S809: The terminal decrypts the second encryption result according to the random information to obtain a key.

[0182] In step S810 , the terminal provides the key, the first key parameter, and the preset address to the operator's security server.

[0183] In step S811 , the operator security server configures a second identification card based on the key, the first key parameter, and the preset address, so that the terminal can log in to the preset client through the second identification card.

[0184] Figure 9 This is a block diagram of an electronic device provided in an embodiment of the present application.

[0185] Reference Figure 9 , an embodiment of the present application provides an electronic device, comprising:

[0186] One or more processors 901;

[0187] A memory 902 storing one or more programs, which, when executed by one or more processors, enable the one or more processors to implement any one of the aforementioned key retrieval methods;

[0188] One or more I / O interfaces 903 are connected between the processor and the memory and are configured to implement information exchange between the processor and the memory.

[0189] Among them, the processor 901 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 902 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) 903 is connected between the processor 901 and the memory 902, and can realize information interaction between the processor 901 and the memory 902, including but not limited to a data bus (Bus), etc.

[0190] In some embodiments, the processor 901 , the memory 902 , and the I / O interface 903 are connected to each other via a bus, and further connected to other components of the computing device.

[0191] This embodiment further provides a computer-readable medium having a computer program stored thereon. When the program is executed by a processor, the key retrieval method provided in this embodiment is implemented. To avoid repeated description, the specific steps of the key retrieval method are not repeated here.

[0192] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods invented above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0193] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0194] Those skilled in the art will understand that although some embodiments described herein include certain features included in other embodiments but not other features, the combination of features from different embodiments is meant to be within the scope of the present embodiment and to form different embodiments.

[0195] It is understood that the above embodiments are merely exemplary embodiments for illustrating the principles of the present application, and the present application is not limited thereto. Those skilled in the art may make various modifications and improvements without departing from the spirit and substance of the present application, and such modifications and improvements are also considered to be within the scope of protection of the present application.

Claims

1. A key retrieval method, characterized in that: Applied to a terminal, the method includes: In the event that the first identification card is lost, a key retrieval request is sent to the operator service server; wherein the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key, and the key retrieval request is used to trigger the operator service server to send a key retrieval instruction to the first identification card; Upon receiving the first encryption result returned by the operator service server, decrypting the first encryption result based on the first key parameter to obtain random information; wherein the first encryption result is a result generated by the first identification card encrypting the random information based on the first built-in key parameter, and the random information is information generated by the first identification card in response to the key retrieval instruction; When a second encryption result sent by the first identification card is obtained from the preset address, the second encryption result is decrypted according to the random information to obtain the key; wherein the second encryption result is a result of the first identification card encrypting the built-in key based on the random information; The key, the first key parameter and the preset address are provided to the operator security server, so that the operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

2. The key retrieval method according to claim 1, characterized in that: In the case where the first identification card is lost, after sending a key retrieval request to the operator service server, the method further includes: Receiving identity authentication from the operator's service server and obtaining an identity authentication result; Wherein, when the identity authentication result is passed, the operator service server sends the key retrieval instruction to the first identification card.

3. The key retrieval method according to claim 1, characterized in that: Providing the key, the first key parameter, and the preset address to the operator security server includes: Inputting the key, the first key parameter, and the preset address into the operator security server through a preset security keyboard; The processing process and results of the operator security server are not displayed to the operator business server.

4. A key retrieval method, characterized in that: Applied to an operator service server, the method includes: In response to a key retrieval request sent by the terminal, sending a key retrieval instruction to the first identification card; wherein the key retrieval request is sent when the first identification card is lost, and the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key; receiving a first encryption result sent by the first identification card; wherein the first encryption result is a result generated by the first identification card encrypting random information based on the first built-in key parameter, and the random information is information generated by the first identification card in response to the key retrieval instruction; The first encryption result is forwarded to the terminal so that the terminal decrypts the first encryption result based on the first key parameter to obtain the random information, and decrypts the second encryption result based on the random information to obtain the key. The operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card; wherein the second encryption result is the result of the first identification card encrypting the built-in key based on the random information.

5. The key retrieval method according to claim 4, characterized in that: The sending of the key retrieval instruction to the first identification card includes: The key retrieval instruction is sent to the first identification card through a preset signaling channel.

6. A key retrieval method, characterized in that: Applied to a first identification card, the first identification card having a built-in key for logging into a preset client, and a first key parameter and a preset address for retrieving the key, the method includes: generating random information in response to a key retrieval instruction sent by the operator service server; Encrypting the random information based on the first built-in key parameter to obtain a first encryption result; Encrypting the built-in key based on the random information to obtain a second encryption result; Forwarding the first encryption result to the terminal through the operator service server; The second encryption result is sent to the preset address so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key. The operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

7. The key retrieval method according to claim 6, characterized in that: Before generating random information in response to the key retrieval instruction sent by the operator service server, the method further includes: Upon receiving the key retrieval instruction, determining the number of times the key retrieval instruction is received within a preset period; Determine whether to respond to the key retrieval instruction based on a preset threshold and the number of times.

8. A terminal, characterized in that: include: a first sending module, configured to send a key retrieval request to an operator service server when a first identification card is lost; wherein the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key, and the key retrieval request is configured to trigger the operator service server to send a key retrieval instruction to the first identification card; a first decryption module configured to, upon receiving a first encryption result returned by the operator service server, decrypt the first encryption result based on the first key parameter to obtain random information; wherein the first encryption result is a result of the first identification card encrypting the random information based on the first built-in key parameter, and the random information is information generated by the first identification card in response to the key retrieval instruction; a second decryption module configured to, upon obtaining a second encryption result sent by the first identification card from the preset address, decrypt the second encryption result according to the random information to obtain the key; wherein the second encryption result is a result of the first identification card encrypting the built-in key based on the random information; A configuration module is used to provide the key, the first key parameter and the preset address to the operator security server, so that the operator security server configures a second identification card based on the key, the first key parameter and the preset address, so that the terminal logs in to the preset client through the second identification card.

9. An operator service server, characterized in that: include: a second sending module, configured to send a key retrieval instruction to the first identification card in response to a key retrieval request sent by the terminal; wherein the key retrieval request is sent when the first identification card is lost, and the first identification card has a built-in key for logging into a preset client, as well as a first key parameter and a preset address for retrieving the key; a receiving module, configured to receive a first encryption result sent by the first identification card; wherein the first encryption result is a result generated by the first identification card encrypting random information based on the first built-in key parameter, and the random information is information generated by the first identification card in response to the key retrieval instruction; A third sending module is used to forward the first encryption result to the terminal, so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card; wherein, the second encryption result is the result of the first identification card encrypting the built-in key based on the random information.

10. A first identification card, characterized in that: The first identification card has a built-in key for logging into a preset client, and a first key parameter and a preset address for retrieving the key. The first identification card includes: A generating module, configured to generate random information in response to a key retrieval instruction sent by an operator service server; a first encryption module, configured to encrypt the random information based on the first built-in key parameter to obtain a first encryption result; A second encryption module, configured to encrypt the built-in key based on the random information to obtain a second encryption result; a fourth sending module, configured to forward the first encryption result to the terminal through the operator service server; The fifth sending module is used to send the second encryption result to the preset address, so that the terminal can decrypt the first encryption result based on the first key parameter to obtain the random information, and decrypt the second encryption result based on the random information to obtain the key, and the operator security server configures the second identification card based on the key, the first key parameter and the preset address, so that the terminal can log in to the preset client through the second identification card.

11. An electronic device, characterized in that: include: one or more processors; A memory having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the key retrieval method according to any one of claims 1 to 3, or claims 4 to 5, or claims 6 to 7.

12. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the key retrieval method according to any one of claims 1 to 3, or claims 4 to 5, or claims 6 to 7 is implemented.

Citation Information

Patent Citations

  • Data processing method based on negotiation secret keys

    CN103888942A

  • Information transmission method, client, server and computer readable storage medium

    CN109347835A