Information Sharing Method and Apparatus, Storage Medium, and Electronic Device
By sharing encrypted and signed boarding authentication information between airports, the problem that OneID service cannot be shared between airports is solved, and passengers can seamlessly use OneID service between multiple airports and ensure the security of information.
Patent Information
- Application Number
- CN202310034637.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-10
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2043-01-10
AI Technical Summary
The existing technology cannot share the authentication information of passengers when using OneID services between airports, resulting in passengers requiring registration and input authentication information at each airport, affecting their experience.
By receiving passenger information sharing requests, identify the airport to be selected, collect and encrypt the boarding authentication information, generate a digital signature, upload it to the blockchain, and send a consensus request to the authorized airport to complete information sharing.
It realizes information sharing between airports, allowing passengers to directly use OneID services after arriving at the airport, improves passenger experience, and ensures the secure transmission of information through blockchain and encryption technology.
Smart Images

Figure CN116055057B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information processing, and particularly relates to an information sharing method, device, storage medium and electronic device. Background Art
[0002] OneID is a concept proposed by the International Air Transport Association (IATA), aiming to apply identity management and biometric technologies to avoid passengers' dependence on identity documents during travel, thereby optimizing the travel experience of passengers. The core idea of OneID is to enable passengers to share their digital identities and other required documents with airlines, airports and other institutions before travel, so as to eliminate the repeated identity document inspection process during travel and reduce the queuing time consumed in check-in, baggage check, boarding, customs clearance and other links.
[0003] The ideal state of the OneID service is that passengers can use the authenticated digital identity to pass through all necessary processes and enjoy corresponding services from the moment they enter the departure airport until they leave the destination airport. At present, however, airports cannot share the authentication information required by passengers when using the OneID service, so that passengers need to register and enter the information required for authentication at each new airport they arrive at in order to use the OneID service, resulting in a poor experience for passengers. Summary of the Invention
[0004] In view of this, the present invention provides an information sharing method, device, storage medium and electronic device, which can share the information of passengers among various airports, ensure that passengers can directly use the OneID service after arriving at the airport, and provide better services for passengers.
[0005] To achieve the above object, the embodiments of the present invention provide the following technical solutions:
[0006] An information sharing method, comprising:
[0007] Receiving an information sharing request sent by a passenger, and determining each candidate airport based on the information sharing request;
[0008] Determining an authorized airport selected by the passenger from each of the candidate airports;
[0009] Collecting the boarding authentication information of the passenger, and encrypting the boarding authentication information using the public key of the authorized airport to obtain encrypted data;
[0010] Generating a digital signature of the boarding authentication information, and adding the digital signature to the encrypted data to obtain shared data;
[0011] Uploading the shared data to a preset blockchain, and sending a consensus request to the authorized airport;
[0012] Trigger the authorized airport to obtain the shared data in the blockchain based on the consensus request, and perform signature verification on the shared data. When the shared data passes the signature verification, save the boarding authentication information in the shared data and update the authorized passenger list.
[0013] In the above method, optionally, determining each candidate airport based on the information sharing request includes:
[0014] Parse a preset airport data sharing protocol to obtain the signing information in the airport data sharing protocol;
[0015] Based on the signing information, determine each participating airport that has signed the airport data sharing protocol;
[0016] Determine each of the participating airports as a candidate airport.
[0017] In the above method, optionally, generating a digital signature of the boarding authentication information includes:
[0018] Determine the private key of the airport where the passenger is located, and use the private key to sign the boarding authentication information to obtain a digital signature.
[0019] In the above method, optionally, saving the boarding authentication information in the shared data and updating the authorized passenger list includes:
[0020] The authorized airport obtains the encrypted data in the shared data, and calls its own private key to decrypt the encrypted data to obtain the boarding authentication information;
[0021] Save the boarding authentication information, and update the passenger's information to the authorized passenger list.
[0022] In the above method, optionally, after determining the authorized airport selected by the passenger among each of the candidate airports, it further includes:
[0023] Obtain the passenger's historical authorization list;
[0024] Based on each of the authorized airports and the historical authorization list, determine whether there is an airport with authorization cancellation;
[0025] When it is determined that there is an airport with authorization cancellation, send an information deletion request to the airport with authorization cancellation, so that the airport with authorization cancellation deletes the passenger's information based on the information deletion request.
[0026] An information sharing device, including:
[0027] A receiving unit, configured to receive an information sharing request sent by a passenger, and determine each candidate airport based on the information sharing request;
[0028] A determining unit, configured to determine an authorized airport selected by the passenger from each of the candidate airports;
[0029] An acquisition unit, configured to acquire the boarding authentication information of the passenger, and encrypt the boarding authentication information using the public key of the authorized airport to obtain encrypted data;
[0030] A generating unit, configured to generate a digital signature of the boarding authentication information, and add the digital signature to the encrypted data to obtain shared data;
[0031] A sending unit, configured to upload the shared data to a preset blockchain, and send a consensus request to the authorized airport;
[0032] A triggering unit, configured to trigger the authorized airport to obtain the shared data in the blockchain based on the consensus request, and perform signature verification on the shared data. When the shared data passes the signature verification, save the boarding authentication information in the shared data and update the authorized passenger list.
[0033] For the above device, optionally, the receiving unit includes:
[0034] A first obtaining subunit, configured to parse a preset airport data sharing protocol to obtain the signing information in the airport data sharing protocol;
[0035] A first determining subunit, configured to determine each participating airport that has signed the airport data sharing protocol based on the signing information;
[0036] A second determining subunit, configured to determine each of the participating airports as a candidate airport.
[0037] For the above device, optionally, the generating unit includes:
[0038] A third determining subunit, configured to determine the private key of the airport where the passenger is located, and use the private key to sign the boarding authentication information to obtain a digital signature.
[0039] For the above device, optionally, the triggering unit includes:
[0040] An invocation subunit, configured to enable the authorized airport to obtain the encrypted data in the shared data, and invoke its own private key to decrypt the encrypted data to obtain the boarding authentication information;
[0041] A saving subunit, configured to save the boarding authentication information and update the information of the passenger to the authorized visitor list.
[0042] Optionally, the above-mentioned device further includes:
[0043] A second obtaining subunit, configured to obtain the historical authorization list of the passenger;
[0044] A judging subunit, configured to judge whether there is an airport with cancelled authorization based on each of the authorized airports and the historical authorization list;
[0045] A deleting subunit, configured to send an information deletion request to the airport with cancelled authorization when it is determined that there is an airport with cancelled authorization, so that the airport with cancelled authorization deletes the information of the passenger based on the information deletion request.
[0046] A storage medium, including stored instructions, wherein when the instructions run, the device where the storage medium is located is controlled to execute the information sharing method as described above.
[0047] An electronic device, including a memory, and one or more instructions, wherein one or more instructions are stored in the memory and are configured to be executed by one or more processors to execute the information sharing method as described above.
[0048] Compared with the background art, the present invention has the following advantages:
[0049] In the information sharing method, device, storage medium and electronic device provided by the present invention, an information sharing request sent by a passenger is received, and based on the information sharing request, each candidate airport is determined; the authorized airports selected by the passenger among each candidate airport are determined; the boarding authentication information of the passenger is collected, and the boarding authentication information is encrypted using the public key of the authorized airport to obtain encrypted data; a digital signature of the boarding authentication information is generated and added to the encrypted data to obtain shared data; the shared data is uploaded to a preset blockchain, and a consensus request is sent to the authorized airport; the authorized airport is triggered to obtain the shared data in the blockchain based on the consensus request and perform signature verification on the shared data. When the shared data passes the signature verification, the boarding authentication information in the shared data is saved and the authorized visitor list is updated. The boarding authentication information of the passenger is signed, encrypted and other operations are performed and then uploaded to the blockchain, and a consensus request is sent to the corresponding authorized airport, so that the authorized airport obtains the boarding authentication information of the passenger from the blockchain, completing the information sharing, enabling the passenger to directly use the OneID service at each authorized airport, providing high-quality services for the passenger, improving the passenger's usage experience, and ensuring the secure transmission of information throughout the information sharing process and preventing information from being tampered with. Description of the Drawings
[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided drawings.
[0051] Figure 1 It is a flowchart of a method for an information sharing method provided by an embodiment of the present invention;
[0052] Figure 2 It is a flowchart of a method for determining each candidate airport based on an information sharing request provided by an embodiment of the present invention;
[0053] Figure 3 It is a flowchart of a method for saving and updating an authorized visitor list with boarding authentication information in shared data provided by an embodiment of the present invention;
[0054] Figure 4 It is a flowchart of a method for canceling information sharing provided by an embodiment of the present invention;
[0055] Figure 5 It is a scenario example diagram of information sharing provided by an embodiment of the present invention;
[0056] Figure 6 It is a schematic structural diagram of an information sharing device provided by an embodiment of the present invention;
[0057] Figure 7 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0059] In this application, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, elements defined by the statement "including one..." do not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0060] The present invention can be used in numerous general or specific computing device environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor devices, distributed computing environments including any of the above devices or equipment, and so on. The present invention can be applied to the system of an airport, and the execution entity can be the processor of the system.
[0061] Refer to Figure 1 , which is a flowchart of a method for information sharing provided by an embodiment of the present invention, and is specifically described as follows:
[0062] S101. Receive an information sharing request sent by a passenger, and based on the information sharing request, determine each candidate airport.
[0063] The system of the airport where the passenger is currently located receives the information sharing request sent by the passenger. Preferably, the passenger can use a mobile terminal to connect to the system of the airport, and then send an information sharing request to the system. The passenger can also send an information sharing request to the system through the airport's APP.
[0064] Furthermore, the passenger can be a passenger who has registered for the OneID service of the airport, a newly registered passenger for the OneID service, or a passenger who has registered for the OneID service for a certain period of time.
[0065] The information sharing request is used to trigger the processing system to provide an information sharing service for the passenger, so that the passenger can select the airports for information sharing, and then share the information required for boarding among these airports, so that the OneID service can be used among the airports, and further, the identity authentication process for the passenger to use the OneID service for boarding from entering the departure airport until leaving the destination airport can be realized.
[0066] Refer to Figure 2 , which is a flowchart of a method for determining each candidate airport based on the information sharing request provided by an embodiment of the present invention, and is specifically described as follows:
[0067] S201. Parse a preset airport data sharing protocol to obtain the signing information in the airport data sharing protocol.
[0068] The airport data sharing protocol is a protocol saved in advance. This protocol is the protocol saved after the airport signs with other airports sharing data. Further, all airports that have signed this protocol will save this protocol.
[0069] For example, if it is determined that information sharing can be carried out among Airport A, Airport B, and Airport C, then Airport A, Airport B, and Airport C sign a data sharing agreement. The signed data sharing agreement includes the airport information of Airport A, Airport B, and Airport C, as well as the agreement content that each airport needs to abide by, the specific data that can be shared, and so on.
[0070] Parse the airport data sharing agreement to obtain the signing information in the airport data sharing agreement.
[0071] S202. Based on the signing information, determine each participating airport that signs the airport data sharing agreement.
[0072] The signing information includes the information of each airport participating in signing the airport data sharing agreement, such as airport name, signing airport representative, airport identifier, and other information.
[0073] Determine each airport in the signing information as a participating airport. Here, the participating airport can be understood as the airport that signs the airport data sharing agreement.
[0074] S203. Determine each participating airport as an alternative airport.
[0075] It should be noted that the alternative airport is an airport where passengers can choose to share data, that is, the authorized airport obtains the personal information of passengers, enabling passengers to use the OneID service of the airport to support various identity verification services at the airport.
[0076] S102. Determine the authorized airport selected by the passenger among each alternative airport.
[0077] Furthermore, generate a list of alternative airports based on each alternative airport. The list of alternative airports includes information such as the airport name and airport identification number of each alternative airport; display the list of alternative airports to passengers so that passengers can select an airport based on their own needs. Preferably, passengers can select an airport according to their current travel itinerary. Obtain the airport selection information input by the passenger. The airport selection information includes at least one selection identifier; for each selection identifier, determine the airport to which the airport identifier identical to the selection identifier belongs as the authorized airport.
[0078] Optionally, after determining each authorized airport, the system of the airport generates an authorization agreement based on each authorized airport. The authorization agreement includes, but is not limited to, the information of each authorized airport, such as the airport name and identification identifier, etc., and also includes the content of the passenger authorizing each authorized airport to use the passenger's information, as well as the rules and precautions that the passenger and each authorized airport need to abide by. Preferably, the passenger needs to sign this authorization agreement with each authorized airport.
[0079] The number of authorized airports is at least one, and the process of sharing information for each authorized airport is the same.
[0080] S103. Collect the boarding authentication information of the passenger, and encrypt the boarding authentication information using the public key of the authorized airport to obtain encrypted data.
[0081] The boarding authentication information includes but is not limited to the passenger's biometric information, basic information, authorization information, etc. Further, the biometric information can be collected using a biometric system, and the biometric information includes but is not limited to the passenger's face picture, iris, fingerprint, voice information, etc. Preferably, in order to improve the accuracy of subsequent authentication, the face picture can be the picture collected this time.
[0082] The basic information includes but is not limited to the passenger's name, gender, date of birth, flight information of the travel itinerary, etc.
[0083] The authorization information includes but is not limited to the above authorization agreement, information of each authorized airport, such as the airport name and airport logo of each authorized airport.
[0084] It should be noted that there is a public-private key pair for each authorized airport, and the public key can be published through broadcasting or other means. The public keys of each authorized airport are different. For each authorized airport, the boarding authentication information is encrypted using the public key of the authorized airport to obtain encrypted data corresponding to the authorized airport.
[0085] S104. Generate a digital signature of the boarding authentication information, and add the digital signature to the encrypted data to obtain shared data.
[0086] Determine the private key of the airport where the passenger is located, and use the private key to sign the boarding authentication information to obtain a digital signature; preferably, the airport where the passenger is located is the airport of the current system.
[0087] Preferably, use the private key of the airport where the passenger is located to sign the digest information of the boarding authentication information to obtain a digital signature; it is also possible to use the private key to sign all the content of the boarding authentication information to obtain a digital signature; it should be noted that the method for generating the digital signature in the present invention is not limited to the method exemplified in the present invention, and other methods can also be used to generate the digital signature.
[0088] After generating the digital signature, the digital signature and the encrypted data can be used as shared data.
[0089] S105. Upload the shared data to a preset blockchain, and send a consensus request to the authorized airport.
[0090] Uploading shared data to the blockchain can prevent criminals from tampering with the shared data, and since the shared data is encrypted data, it can avoid the situation where the shared data is called, improving the security of data sharing between airports and ensuring the reliability of the data during sharing.
[0091] Send a consensus request to each authorized airport. Preferably, the authorized airports in the present invention may include the airport where the passenger is currently located, or may not include the airport where the passenger is currently located.
[0092] The consensus request is used to trigger the authorized airport to obtain the information shared by the passenger. Preferably, the identification code of the shared data uploaded to the blockchain is included in the consensus request.
[0093] S106. Trigger the authorized airport to obtain the shared data in the blockchain based on the consensus request and perform signature verification on the shared data. When the shared data passes the signature verification, save the boarding authentication information in the shared data and update the authorized passenger list.
[0094] It should be noted that each authorized airport needs to execute step S106.
[0095] The authorized airport obtains the shared data in the blockchain according to the identification code in the consensus request. Using the identification code can accurately obtain the shared data and avoid obtaining incorrect data.
[0096] The authorized airport determines the system that uploaded the shared data and uses the public key of the airport to which the system belongs to perform signature authentication on the shared data, thereby verifying the identity of the system that uploaded the shared data, effectively avoiding criminals posing as the system to upload data, and improving the security of the data sharing environment.
[0097] When the shared data passes the signature verification, it proves that the system that uploaded the shared data is a trusted system and the shared data is secure data; when the shared data fails the signature verification, it indicates that the system that uploaded the shared data is a posing system and the shared data is risk data. At this time, no further operation should be performed on the shared data, and an alarm can be issued for risk investigation personnel to handle to ensure the security of data sharing.
[0098] Refer to Figure 3 , which is the flowchart of the method for saving the boarding authentication information in the shared data and updating the authorized passenger list provided by the embodiment of the present invention, and is specifically described as follows:
[0099] S301. The authorized airport obtains the encrypted data in the shared data and calls its own private key to decrypt the encrypted data to obtain the boarding authentication information.
[0100] S302. Save the boarding authentication information and update the passenger's information to the authorized passenger list.
[0101] It should be noted that the authorized visitor list stores the information of passengers who use their own information at the authorized airport, such as the passenger's name, ID number, and gender. Exemplarily, assume there are passengers 1, 2, 3 and airport A. Passengers 1 and 2 use their own information at the authorized airport A, then the authorized visitor list of airport A contains the information of passenger 1 and passenger 2.
[0102] When saving the boarding authentication information, the structured storage is responsible for saving the basic data and authorization information of the passengers; the unstructured storage is responsible for saving the biometric information of the passengers, such as face pictures.
[0103] Preferably, after the authorized airport saves the boarding authentication information and updates the authorized visitor list, the information sharing is completed; thus, after arriving at the authorized airport, passengers can use the OneID service of the authorized airport to implement various identity authentication services at the airport without registering or uploading information; it realizes that passengers can use the OneID service to implement various identity authentication services at the airport during the process from entering the departure airport to leaving the destination airport, so that passengers do not need to rummage through documents such as ID cards when verifying their identities at the airport, shortening the time for verifying identities during the process of passengers checking in and storing luggage, providing better services for passengers, and improving the passenger experience of the airport.
[0104] In the method provided by the embodiment of the present invention, an information sharing request sent by a passenger is received, and based on the information sharing request, each candidate airport is determined; the authorized airport selected by the passenger among the candidate airports is determined; the boarding authentication information of the passenger is collected, and the boarding authentication information is encrypted using the public key of the authorized airport to obtain encrypted data; a digital signature of the boarding authentication information is generated and added to the encrypted data to obtain shared data; the shared data is uploaded to a preset blockchain, and a consensus request is sent to the authorized airport; the authorized airport is triggered to obtain the shared data in the blockchain based on the consensus request and perform signature verification on the shared data. When the shared data passes the signature verification, the boarding authentication information in the shared data is saved and the authorized passenger list is updated. In the present invention, the boarding authentication information to be shared is encrypted to obtain encrypted data, and a digital signature is added to the encrypted data to obtain shared data. The shared data is uploaded to the blockchain, and the authorized airport selected by the passenger is triggered to obtain the shared data from the blockchain and save it when the shared data passes the verification, thereby completing the information sharing; by sharing the passenger's data among airports, the passenger can use the OneID service of the airport without registering at the new airport and entering the information required for authentication, realizing the cross-airport OneID service, thus providing better services for passengers. During the data sharing process, by using blockchain technology, encryption technology, and signature technology, the shared data has the characteristics of being non-forgeable, non-fictitious, and non-tamperable, and a trusted and secure sharing environment is constructed.
[0105] Preferably, during the information sharing process, shared requests sent by passengers can also be received in batches, and then the passengers' information can be shared with the airport in batches. For example, if both passenger 1 and passenger 2 select airport B as the authorized airport, the public key of airport B can be used to encrypt the boarding authentication information of passenger 1 and passenger 2 to obtain encrypted data. After uploading the encrypted data to the blockchain, a consensus request corresponding to the encrypted data is sent to airport B. Here, the encrypted data contains the boarding authentication information of passenger 1 and passenger 2. Preferably, the public key of airport B can also be used to encrypt the boarding authentication information of passenger 1 and passenger 2 respectively, and then obtain encrypted data 1 corresponding to passenger 1 and encrypted data 2 corresponding to passenger 2. After uploading these two encrypted data to the blockchain, a consensus request corresponding to encrypted data 1 and a consensus request corresponding to encrypted data 2 are sent to airport B.
[0106] Refer to Figure 4 , which is the flowchart of the method for canceling information sharing provided by the embodiment of the present invention, and is specifically described as follows:
[0107] S401. Obtain the historical authorization list of the passenger.
[0108] The historical authorization list is the airport authorization list generated when the passenger last requested information sharing. When the historical authorization list is not empty, it contains at least one historical authorized airport. It should be noted that when the passenger first requests information sharing, the historical authorization list is empty.
[0109] S402. Based on each authorized airport and the historical authorization list, determine whether there is an airport with authorization cancelled; when it is determined that there is an airport with authorization cancelled, execute S403; when it is determined that there is no airport with authorization cancelled, execute S404.
[0110] For each historical authorized airport in the historical authorization list, determine whether there is such a historical authorized airport among the authorized airports. If there is, determine that this historical authorized airport is not an airport with authorization cancelled; if not, determine this historical authorized airport as an airport with authorization cancelled.
[0111] S403. Send an information deletion request to the airport with authorization cancelled, so that the airport with authorization cancelled deletes the passenger's information based on the information deletion request.
[0112] S404. End.
[0113] It should be noted that the airport with authorization cancelled deletes all the information about this passenger in the local area. At this point, there is no information about this passenger in this airport, and this passenger cannot use the OneID service in this airport.
[0114] Preferably, the airport with authorization cancelled can also be selected by the passenger. For example, Airport A was the airport where the passenger last authorized the use of information, but when sharing information this time, the passenger sets Airport A as the airport with authorization cancelled.
[0115] By deleting the passenger's information in the airport with authorization cancelled, the leakage of the passenger's information can be avoided, ensuring the security of the passenger's personal information.
[0116] Refer to Figure 5 , which is the scenario example diagram of information sharing provided by the embodiment of the present invention, and is specifically described as follows.
[0117] The figure includes System A of the airport where the passenger is located, System B of the authorized airport selected by the passenger, and other systems. Further, the other systems include a biometric information collection system, a passenger data supply system, and a OneID service provision system; when the passenger sends an information sharing request to System A, System A calls the biometric information collection system to collect the passenger's biometric information, and calls the passenger data supply system to collect the passenger's basic information, and determines the generated identification information and basic information as the passenger's boarding authentication information; the passenger determines each authorized airport through the authorization information management system in System A, encrypts and signs the boarding authentication information to obtain encrypted data, uploads the encrypted data to the blockchain, and sends a formula request to each authorized airport; preferably, if Airport A is the authorized airport selected by the passenger, System A can save the boarding authentication information.
[0118] After receiving the consensus request, System B of the authorized airport obtains the encrypted data from the blockchain based on the consensus request, and performs operations such as signature authentication and decryption on the encrypted data to obtain the boarding authentication information, and saves the boarding authentication information. Thus, Airport A and Airport B share the passenger's information, and the passenger can enjoy the OneID service provided by the OneID service provision system at Airport A and Airport B.
[0119] Preferably, when the system of the airport in the present invention saves the boarding authentication information, the saving methods include structured storage, unstructured storage, and caching. Structured storage is responsible for saving passenger data and authorization information; unstructured storage is responsible for saving picture information; caching is responsible for loading the data in the database into the memory in advance to improve the access speed.
[0120] Further, when the system saves the boarding authentication information, if there is no information of this passenger in the local storage, the information of the passenger is updated to the local storage; if a registered passenger modifies the authorization information and this airport is still in the authorization list, the passenger authorization information is updated. Preferably, if the passenger cancels the authorization for the airport, the airport whose authorization is cancelled needs to delete the corresponding passenger information from the local storage; preferably, the data in the local storage is used to provide the OneID service at this airport.
[0121] The present invention also provides specific scenario examples for illustration. The following assumes three passengers: Passenger 1, Passenger 2, and Passenger 3. All three passengers depart from the origin Airport A and take Flight Z to the destination Airport B. Airport A and Airport B have reached a data sharing agreement. Passenger 1 has not registered a face; Passenger 2 and Passenger 3 have registered face information at Airport A. Passenger 2 has authorized Airport A to use his biometric information, and Passenger 3 has authorized both Airport A and Airport B to use his biometric information.
[0122] Step 1: Data collection.
[0123] Data collection is performed by the system of the airport where the passenger is located, that is, by the system of Airport A. The specific process of data collection is as follows:
[0124] Step 1.1: Obtain passenger data. Obtain the basic passenger information of Passenger 1, Passenger 2, and Passenger 3 through the passenger data supply system.
[0125] Step 1.2: Obtain biometric information. Obtain the face pictures of Passenger 1, Passenger 2, and Passenger 3 through the biometric information collection system.
[0126] Step 2: Authorization information management.
[0127] Authorization information management means obtaining the authorization information provided by the passenger. The authorization information provided by the passenger can be the information of the authorized airport and the information of the airport where the authorization is cancelled. The management of the authorization information is performed by the system of the airport where the passenger is located, that is, by the system of Airport A, and is specifically described as follows:
[0128] Step 2.1: Check the data sharing agreement between airports.
[0129] Airport A checks the existing data sharing agreement between airports and determines that it can share the passenger biometric information with Airport B.
[0130] Step 2.2: Update the passenger's authorization information.
[0131] Passenger 1 performs a face registration operation. Airport A feeds back a list of authorized airports to Passenger 1. The list of authorized airports includes Airport A and Airport B. Passenger 1 authorizes both Airport A and Airport B to use his biometric information at the same time; Passenger 2 adds the authorization to use biometric information for Airport B through the check-in system; Passenger 3 cancels the authorization for Airport B to use his biometric information through the mobile APP.
[0132] So far, the information of the airports that Passenger 1, Passenger 2, and Passenger 3 have selected to authorize and the airports where the authorization is cancelled has been obtained.
[0133] Step 3: Check the passenger authorization information and add a digital signature.
[0134] Passenger 1 and Passenger 2 authorize Airport B to use biometric information, and Passenger 3 cancels the authorization for Airport B to use biometric information. Therefore, the public key of Airport B is used to encrypt the basic information, face pictures, and authorization information of the three passengers. Airport A uses a specific hash function to generate the digest of the passenger basic information, face pictures, and authorization information, and encrypts the digest with the private key of Airport A to generate a digital signature.
[0135] Step 4: Upload data to the blockchain.
[0136] Airport A uploads the encrypted information with a digital signature to the blockchain and initiates a consensus request to Airport B.
[0137] Step 5: Data storage.
[0138] Update the information of newly registered passenger 1 to the local storage. If passengers 2 and 3 have modified their authorizations and Airport A is still in the authorization list, update the authorization information of passengers 2 and 3 in the local storage. Passengers 1, 2, and 3 can enjoy the OneID service in the processes of check-in, baggage check, security check, boarding, and intelligent flight display at Airport A.
[0139] Step 6: Verify the shared data and process it.
[0140] After receiving the consensus request, Airport B decrypts the basic passenger information, face pictures, and authorization information of passengers 1, 2, and 3 using the private key of Airport B; uses the public key of Airport A to parse the digital signature to obtain the digest generated by Airport A, and uses the same hash function as Airport A to process the basic passenger information, face pictures, and authorization information to generate a digest. After verification, the digests generated by Airport A and Airport B are the same, indicating that the uploader of the shared information is indeed Airport A and the information has not been tampered with. Airport B reaches a consensus with Airport A, completes the reception of the data, and the system of Airport B executes the content of Step 7.
[0141] Step 7: Data storage.
[0142] There is no information of passengers 1 and 2 in the local storage of Airport B, so update the information of the two passengers to the local storage. Passenger 3 has cancelled the authorization for Airport B to use their biometric information, so Airport B deletes the information of passenger 3 from the local storage.
[0143] It should be noted that passengers 1 and 2 can still enjoy the OneID service after arriving at Airport B; passenger 3 has cancelled the authorization for Airport B to use their biometric information, so they cannot enjoy the OneID service after arriving at Airport B.
[0144] The present invention utilizes the asymmetric encryption technology of the blockchain and the characteristics of information being non-forgeable and non-tamperable to transmit sensitive information such as passenger biometric and authorization information. At the same time, the management process of passenger biometric information authorization is optimized. Passengers can dynamically modify the authorization scope, and airports can share passenger biometric and authorization information in real time according to the changes in passenger authorization information. After the implementation of this technical solution, it can provide a completely trusted data transmission environment between airports, effectively solve the problem of non-mutual trust of data between airports, and at the same time enable passengers to authorize biometric information across airports, so that passengers can enjoy the OneID service of multiple airports through one registration.
[0145] Furthermore, the present invention also allows passengers to change the authorization status of biometric information in real time, and determines which airports need to update this changed information in real time according to the authorization list, encrypts the information with the corresponding private key and transmits it. Thus, the information changed by the passengers can be synchronized to all nodes that need to participate in the data change in real time, so that there is no time delay problem in information synchronization.
[0146] Corresponding to Figure 1 the method shown, the present invention also provides an information sharing device, which is used to support Figure 1 the specific implementation of the method shown, and this device can be applied to the processing system of the airport.
[0147] Referring to Figure 6 , which is a schematic structural diagram of an information sharing device provided by an embodiment of the present invention, and is specifically described as follows:
[0148] A receiving unit 501, configured to receive an information sharing request sent by a passenger, and determine each candidate airport based on the information sharing request;
[0149] A determining unit 502, configured to determine the authorized airports selected by the passenger among the candidate airports;
[0150] An acquisition unit 503, configured to acquire the boarding authentication information of the passenger, and encrypt the boarding authentication information with the public key of the authorized airport to obtain encrypted data;
[0151] A generating unit 504, configured to generate a digital signature of the boarding authentication information, and add the digital signature to the encrypted data to obtain shared data;
[0152] A sending unit 505, configured to upload the shared data to a preset blockchain, and send a consensus request to the authorized airport;
[0153] A triggering unit 506, configured to trigger the authorized airport to obtain the shared data in the blockchain based on the consensus request, and perform signature verification on the shared data. When the shared data passes the signature verification, save the boarding authentication information in the shared data and update the authorized visitor list.
[0154] In another device provided by an embodiment of the present invention, the receiving unit 501 of this device includes:
[0155] A first acquisition subunit, configured to parse a preset airport data sharing protocol to obtain the signing information in the airport data sharing protocol;
[0156] A first determination subunit, configured to determine each participating airport that has signed the airport data sharing protocol based on the signing information;
[0157] A second determination subunit, configured to determine each of the participating airports as an alternative airport.
[0158] In another device provided by an embodiment of the present invention, the generating unit 504 of the device includes:
[0159] A third determination subunit, configured to determine the private key of the airport where the passenger is located, and use the private key to perform a signature process on the boarding authentication information to obtain a digital signature.
[0160] In another device provided by an embodiment of the present invention, the triggering unit 506 of the device includes:
[0161] An invocation subunit, configured to enable the authorized airport to obtain the encrypted data in the shared data, and invoke its own private key to decrypt the encrypted data to obtain the boarding authentication information;
[0162] A saving subunit, configured to save the boarding authentication information, and update the information of the passenger to the authorized visitor list.
[0163] In another device provided by an embodiment of the present invention, the device further includes:
[0164] A second acquisition subunit, configured to acquire the historical authorization list of the passenger;
[0165] A judgment subunit, configured to judge whether there is an airport with authorization cancellation based on each of the authorized airports and the historical authorization list;
[0166] A deletion subunit, configured to, when it is determined that there is an airport with authorization cancellation, send an information deletion request to the airport with authorization cancellation, so that the airport with authorization cancellation deletes the information of the passenger based on the information deletion request.
[0167] An embodiment of the present invention further provides a storage medium, where the storage medium includes stored instructions, and when the instructions run, the device where the storage medium is located is controlled to execute the above information sharing method.
[0168] An embodiment of the present invention further provides an electronic device, the structural schematic diagram of which is as Figure 7 shown, specifically including a memory 601, and one or more instructions 602, where one or more instructions 602 are stored in the memory 601 and are configured to be executed by one or more processors 603 to execute the above information sharing method.
[0169] The specific implementation processes and their derivative methods of the above various embodiments are all within the protection scope of the present invention.
[0170] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for a system or system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the description of the method embodiment. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.
[0171] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0172] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An information sharing method, characterized in that, Including: Receiving an information sharing request sent by a passenger, and determining each candidate airport based on the information sharing request; Determining an authorized airport selected by the passenger from among the candidate airports; Collecting the boarding authentication information of the passenger, and encrypting the boarding authentication information using the public key of the authorized airport to obtain encrypted data; wherein, the boarding authentication information at least includes the biometric information, basic information and authorization information of the passenger; Generating a digital signature of the boarding authentication information, and adding the digital signature to the encrypted data to obtain shared data; Uploading the shared data to a preset blockchain, and sending a consensus request to the authorized airport; wherein, the consensus request is used to trigger the authorized airport to obtain the information shared by the passenger, and the consensus request contains the identification code of the shared data uploaded to the blockchain; Triggering the authorized airport to obtain the shared data in the blockchain based on the consensus request, and performing signature verification on the shared data. When the shared data passes the signature verification, saving the boarding authentication information in the shared data and updating the authorized passenger list.
2. The method according to claim 1, characterized in that, The determining each candidate airport based on the information sharing request includes: Parsing a preset airport data sharing protocol to obtain the signing information in the airport data sharing protocol; Determining each participating airport that has signed the airport data sharing protocol based on the signing information; Determining each of the participating airports as a candidate airport.
3. The method according to claim 1, characterized in that, The generating a digital signature of the boarding authentication information includes: Determining the private key of the airport where the passenger is located, and using the private key to sign the boarding authentication information to obtain a digital signature.
4. The method according to claim 1, characterized in that, The saving the boarding authentication information in the shared data and updating the authorized passenger list includes: The authorized airport obtains the encrypted data in the shared data, and decrypts the encrypted data by invoking its own private key to obtain the boarding authentication information; Saving the boarding authentication information, and updating the information of the passenger to the authorized passenger list.
5. The method according to claim 1, characterized in that, After determining the authorized airport selected by the passenger from among the candidate airports, it further includes: Obtaining the historical authorization list of the passenger; Based on each of the authorized airports and the historical authorization list, determining whether there is an airport with authorization cancelled; When it is determined that there is an airport with authorization cancelled, sending an information deletion request to the airport with authorization cancelled, so that the airport with authorization cancelled deletes the information of the passenger based on the information deletion request.
6. An information sharing device, characterized in that, Including: A receiving unit, configured to receive an information sharing request sent by a passenger, and determine each candidate airport based on the information sharing request; A determining unit, configured to determine the authorized airport selected by the passenger from among the candidate airports; A collecting unit, configured to collect the boarding authentication information of the passenger, and encrypt the boarding authentication information using the public key of the authorized airport to obtain encrypted data; wherein, the boarding authentication information at least includes the biometric information, basic information and authorization information of the passenger; A generating unit, configured to generate a digital signature of the boarding authentication information and add the digital signature to the encrypted data to obtain shared data; A sending unit, configured to upload the shared data to a preset blockchain and send a consensus request to the authorized airport; wherein, the consensus request is used to trigger the authorized airport to obtain the information shared by the passenger, and the identification code of the shared data uploaded to the blockchain is included in the consensus request; A triggering unit, configured to trigger the authorized airport to obtain the shared data in the blockchain based on the consensus request and perform signature verification on the shared data. When the shared data passes the signature verification, the boarding authentication information in the shared data is saved and the authorized passenger list is updated.
7. The device according to claim 6, characterized in that, The receiving unit includes: A first obtaining subunit, configured to parse a preset airport data sharing protocol and obtain the signing information in the airport data sharing protocol; A first determining subunit, configured to determine each participating airport that has signed the airport data sharing protocol based on the signing information; A second determining subunit, configured to determine each of the participating airports as an alternative airport.
8. The device according to claim 6, characterized in that, The generating unit includes: A third determining subunit, configured to determine the private key of the airport where the passenger is located and use the private key to sign the boarding authentication information to obtain a digital signature.
9. A storage medium, characterized in that, The storage medium includes stored instructions, wherein when the instructions run, the device where the storage medium is located is controlled to execute the information sharing method according to any one of claims 1-5.
10. An electronic device, characterized in that, It includes a memory and one or more instructions, wherein one or more instructions are stored in the memory and are configured to be executed by one or more processors to execute the information sharing method according to any one of claims 1-5.
Citation Information
Patent Citations
Electronic certificate management method and related equipment
CN107231351A