Verification Identification Generation Method, System, Electronic Device and Storage Medium
The verification identifier is generated through the cooperative signature of the server and client, which solves the problem of user identity impersonation and high cost in existing electronic documents, and improves the authenticity and security of electronic documents.
Patent Information
- Application Number
- CN202310020327.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-05
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-01-05
AI Technical Summary
The existing electronic documents have problems such as impersonation of user identity, inability to effectively identify user identity, and high costs.
The method of generating a verification identifier through a cooperative signature between the server and the client includes generating a first digital signature, a second digital signature and a third digital signature, and generating an electronic signature based on the client information to form a verification identifier.
It improves the authenticity, integrity and undeniability of electronic documents, and reduces the chances of electronic documents being tampered with and illegally impersonated.
Smart Images

Figure CN116112178B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology. Specifically, this application relates to a method, system, electronic device, and storage medium for generating verification identifiers. Background Art
[0002] With the continuous development of Internet technology, in order to solve problems such as inconvenience in carrying and easy loss, physical paper certificates have gradually been converted into electronic forms. As an example, there are mainly three common ways to implement electronic certificates:
[0003] First, unsigned electronic certificates: Unsigned electronic certificates convert electronic certificate information into electronic image information and display it on mobile intelligent terminals, such as pictures and layout files. However, there are risks of being maliciously modified, used by taking pictures, or copied and misused.
[0004] Second, authoritatively signed electronic certificates: Authoritatively signed electronic certificates are digitally signed by an electronic certificate server for the electronic certificate information in a fixed electronic document format with a page presentation effect, which can protect the authenticity, integrity, and non-repudiation of the electronic certificate. However, there is a risk of user identity being misused, and the user identity cannot be effectively identified.
[0005] Third, electronic certificates based on cryptographic hardware: Electronic certificates based on cryptographic hardware use cryptographic technology to protect electronic certificate information on the client side. The current implementation method is mainly SIMKey. As a special type of SIM card, SIMKey performs cryptographic operations using the keys inside the card when in use. The SIMKey method requires the use of a dedicated hardware medium, resulting in a relatively high cost.
[0006] In summary, existing electronic certificates have problems such as user identity being misused, the user identity not being effectively identified, and relatively high costs. Summary of the Invention
[0007] Embodiments of this application provide a method for generating verification identifiers to solve the problems in the prior art that existing electronic certificates have issues such as user identity being misused, the user identity not being effectively identified, and relatively high costs.
[0008] Correspondingly, embodiments of this application also provide a system for generating verification identifiers, an electronic device, and a storage medium to ensure the implementation and application of the above method.
[0009] To solve the above problems, embodiments of this application disclose a method for generating verification identifiers, which is applied to a server. The method includes:
[0010] When the client authentication is passed, generate a first digital signature, instruct the client to generate a second digital signature based on the first digital signature, and obtain the second digital signature;
[0011] Generate a third digital signature based on the second digital signature, and generate an electronic signature based on the third digital signature and the client information of the client;
[0012] Generate the verification identifier of the client based on the third digital signature, the electronic signature, and the client information.
[0013] An embodiment of the present application also discloses a method for generating a verification identifier, which is applied to a client. The method includes:
[0014] Send a verification identifier generation request to the server; the verification identifier generation request instructs the server to generate a first digital signature;
[0015] Generate a second digital signature and send the second digital signature to the server;
[0016] Receive the verification identifier generated by the server based on the second digital signature;
[0017] Wherein, the verification identifier is generated by the server based on a third digital signature, an electronic signature, and the client information, and the third digital signature is generated by the server based on the second digital signature; the electronic signature is generated by the server based on the third digital signature and the client information.
[0018] An embodiment of the present application also discloses a verification identifier generation system, including a server and a client;
[0019] Wherein, the client sends a verification identifier generation request to the server and obtains a verification identifier;
[0020] When the server passes the client authentication, generate a first digital signature, instruct the client to generate a second digital signature based on the first digital signature, and obtain the second digital signature;
[0021] Generate a third digital signature based on the second digital signature, and generate an electronic signature based on the third digital signature and the client information of the client;
[0022] Generate the verification identifier of the client based on the third digital signature, the electronic signature, and the client information.
[0023] An embodiment of the present application also discloses an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect of the present application is implemented.
[0024] An embodiment of the present application also discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in one or more of the embodiments of the present application is implemented.
[0025] The beneficial effects brought by the technical solution provided by the embodiment of the present application are as follows:
[0026] In an embodiment of the present application, when the server passes the client authentication, it generates a first digital signature, instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature of the client and the client information; generates a verification identifier of the client based on the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client cooperate to sign and generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0027] The additional aspects and advantages of the embodiments of the present application will be partially given in the following description, and these will become obvious from the following description, or will be understood through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The above and / or additional aspects and advantages of the present application will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:
[0029] Figure 1 is a flowchart of the method for generating a verification identifier on the server side provided by the embodiment of the present application;
[0030] Figure 2 is a schematic diagram of the electronic certificate provided by the embodiment of the present application;
[0031] Figure 3 is a schematic diagram of the generation of the electronic certificate provided by the embodiment of the present application;
[0032] Figure 4 is a flowchart of the method for generating a verification identifier on the client side provided by the embodiment of the present application;
[0033] Figure 5 is a schematic structural diagram of the verification identifier generation system provided by the embodiment of the present application;
[0034] Figure 6 Schematic diagram of the server - side verification identifier generation device provided by the embodiment of the present application;
[0035] Figure 7 Schematic diagram of the client - side verification identifier generation device provided by the embodiment of the present application;
[0036] Figure 8 Schematic diagram of the structure of an electronic device provided by the embodiment of the present application. Detailed implementation manners
[0037] The embodiments of the present application will be described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions from beginning to end. The embodiments described below by referring to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be construed as a limitation to the present application.
[0038] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application means the presence of features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their combinations. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.
[0039] Those skilled in the art can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.
[0040] The solution provided in the embodiments of the present application can be executed by any electronic device, such as a terminal device or a server, wherein the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited to this. The terminal and the server can be directly or indirectly connected via wired or wireless communication, and this application is not limited here. For the technical problems existing in the prior art, the verification identification generation method, system, electronic device and storage medium provided by this application are intended to solve at least one of the technical problems of the prior art.
[0041] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0042] The present application embodiment provides a possible implementation method, such as Figure 1 As shown, a flowchart of a verification identification generation method is provided. The scheme can be executed by any electronic device. Optionally, it can be executed on a server or a terminal device. For the convenience of description, the method provided in the embodiment of the present application is described below using the server as the execution entity.
[0043] In the prior art, there are three main solutions for implementing electronic certificates:
[0044] The first type is an unsigned electronic certificate, which can also be called a static electronic certificate. A static electronic certificate fills the electronic certificate information into a static image or layout file style in a fixed format to generate a static electronic certificate, which is then displayed on a mobile smart terminal.
[0045] The second type is an electronic certificate with an authoritative signature. An electronic certificate with an authoritative signature performs a digital signature operation on the electronic certificate information through the server, and stamps the electronic certificate with an authoritative digital signature, making the electronic certificate legally effective.
[0046] The third type is electronic certificates based on cryptographic hardware. The main implementation method of electronic certificates based on cryptographic hardware is SIMKey. As a key information carrier, SIMKey does not require users to install any additional software and relies on dedicated SIM card hardware media. The SIMKey method opens up a special security area in the SIM card. When the electronic certificate is generated, the key in the SIM card is used to digitally sign the electronic certificate data and generate an electronic certificate for display.
[0047] The above three solutions can all implement electronic certificates. However, there are some problems, specifically:
[0048] The static electronic certificate is not encrypted and protected using password technology and is easily modified; moreover, it does not use digital signature technology for integrity and non-repudiation protection, and there are risks of malicious modification, photographing for use, and copying and misusing; it is applicable to manual verification but does not have the ability to be machine-readable and anti-counterfeiting.
[0049] The electronic certificate with a signature, that is, the electronic certificate with an authoritative signature, has limited ability to confirm the user's identity and can only be protected by means such as passwords. As long as the password is obtained, the electronic certificate can be used, and the degree of security protection is relatively low.
[0050] The electronic certificate based on password hardware relies on a dedicated hardware medium and requires the support of a dedicated SIM card and the mobile intelligent terminal itself. Users need to pay an extra fee to purchase it, and the usage cost is relatively high.
[0051] To solve the above technical problems, the present application provides a method for generating a verification identifier, as Figure 1 shown in, this method may include the following steps:
[0052] Step 101, when the authentication of the client identity is passed, generate a first digital signature, instruct the client to generate a second digital signature according to the first digital signature and obtain the second digital signature.
[0053] This embodiment can be applied to the generation of electronic certificates, and the electronic certificates include but are not limited to electronic identity cards, electronic medical insurance cards, etc. Among them, the client information may include the basic information and image information of the certificate. The basic information may include but is not limited to information such as name, gender, mobile phone number, ID number, certificate status, certificate identifier, certificate type, issuing agency, expiration date, etc. The image information may be such as a head portrait.
[0054] Among them, the server can generate a first digital signature and then send the first digital signature to the client. The client can calculate the first digital signature according to the preset client collaborative signature key, and then generate a second digital signature.
[0055] Among them, the server generates the first digital signature, including:
[0056] Generate a random number, and generate a first digital signature according to the random number and the preset signature algorithm.
[0057] In addition, the server can also perform a hash calculation on the client information, generate a hash value, and send the hash value to the client. After receiving the first digital signature and the hash value, the client can calculate the first digital signature and the hash value to generate a second digital signature.
[0058] Step 102: Generate a third digital signature based on the second digital signature, and generate an electronic signature based on the third digital signature and the client information of the client.
[0059] Specifically, the server has a preset server collaborative signature private key, and can use the server collaborative signature private key to calculate the second digital signature, and then generate the third digital signature.
[0060] Among them, the first digital signature is calculated by the server, the second digital signature is calculated by the client based on the first digital signature, and both the server and the client participate in the digital signature process. Therefore, the third digital signature generated based on the second digital signature can authenticate the identity of the client, bind the client's own behavior, and ensure the reliability of the third digital signature.
[0061] The server can calculate the third digital signature and the client information according to the preset signature key to generate an electronic signature. The electronic signature represents that the electronic certificate is issued by an authoritative institution and is used to verify the authenticity of the electronic certificate.
[0062] Step 103: Generate a verification identifier for the client based on the third digital signature, the electronic signature, and the client information
[0063] The client information may be a certificate identifier, such as an ID number, a social security card account number, etc.
[0064] The verification identifier generated by the server includes the third digital signature, the electronic signature, and the client information,
[0065] and can determine the authenticity of the client's identity, the authenticity of the electronic certificate, and the authenticity of the certificate information through the verification identifier. At the same time, the client information can be found according to the verification identifier.
[0066] After the server generates the verification identifier for the client, it can send the verification identifier to the client, and at the same time, it can also send the client information to the client. After receiving the client information and the verification identifier, the client can display the client information and the verification identifier to generate an electronic certificate.
[0067] As a first example, as
[0068] shown, the generated electronic certificate may include an electronic certificate basic information field 201, an electronic certificate image information field 202, and an electronic certificate QR code field 203. Specifically, Figure 2
[0069] Generate an electronic certificate using the display function, such as D = display(B||M||Q), where D is the electronic certificate; B is the information in the basic information field of the electronic certificate; M is the information in the image information field of the electronic certificate; and Q is the information in the QR code field of the electronic certificate.
[0070] The process of generating an electronic identifier is as Figure 3 shown and includes: Step 301, the client initiates an electronic certificate generation request and verifies the user's identity based on the collaborative signature-based identity authentication operation.
[0071] Step 302, the server and the client perform a digital signature operation on the information B in the basic information field of the electronic certificate and the information M in the image information field of the electronic certificate. The server calculates the complete digital signature S (i.e., the third digital signature) based on the partial digital signatures of the client and the server (i.e., the first digital signature and the second digital signature).
[0072] Step 303, the server uses the server-preconfigured signature key to perform a digital signature operation on the information B in the basic information field of the electronic certificate, the information M in the image information field of the electronic certificate, and the complete digital signature S to generate the server's authoritative digital signature Sa (i.e., the electronic signature).
[0073] Step 304, the server returns relevant data to the client. The electronic certificate client assembles the data and displays it to generate the electronic certificate D = display(B||M||Q). The relevant data returned by the server includes the information B in the basic information field of the electronic certificate, the information M in the image information field of the electronic certificate, and the information Q in the QR code field of the electronic certificate. The information Q in the QR code field of the electronic certificate is generated based on the complete digital signature S, the information B in the basic information field of the electronic certificate, and the authoritative digital signature Sa.
[0074] As Figure 2 shown, the client can display the basic information in the client information in the basic information field B of the electronic certificate. For example, Name: Li*Yao; Gender: Male; Mobile Phone Number: 156****0001; ID Number: 11**************01; Certificate Status: Normal; Certificate Number: XXXX00000001; Certificate Type: XXX Certificate; Issuing Agency: XXX Agency; Expiration Date: December 31, 2022.
[0075] Optionally, the basic information in the client information can be processed through the sequence function to obtain information B in the basic information field of the electronic certificate. For example, B = sequence(b1||b2||b3||b4||b5||b6||b7||b8||b9), where b1 is the name, b2 is the gender, b3 is the mobile phone number, b4 is the ID number, b5 is the certificate status, b6 is the certificate number, b7 is the certificate type, b8 is the issuing agency, and b9 is the expiration date.
[0076] The client can display the image information in the client information in the electronic certificate image information field.
[0077] Optionally, the image information in the client information can be processed through the sequence function to obtain information M in the electronic certificate image information field. For example, M = sequence(m1), where m1 is the electronic certificate picture, such as a profile picture, etc.
[0078] The client can display the verification identifier in the electronic certificate QR code field Q. The authenticity of the electronic certificate can be verified through the verification identifier, and the certificate information of the user, such as basic information and image information, can be read through the verification identifier.
[0079] Optionally, the verification identifier can be processed through the base64 function to obtain information Q in the electronic certificate QR code field. For example, Q = base64(S||b6||Sa), where S is the third digital signature; b6 is the certificate number, that is, the client information; Sa is the electronic signature. The electronic verification identifier can be encoded and converted through the base64 function into the form of a QR code as shown in Figure 2 shown.
[0080] In the embodiment of the present application, when the server authenticates the client's identity successfully, it generates a first digital signature, instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature of the client and the client information; generates the verification identifier of the client based on the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0081] In an optional embodiment, before generating the first digital signature when the client's identity is successfully authenticated, the method further includes:
[0082] Receive a verification identity generation request from a client and verify the identity of the client.
[0083] Taking the generation of an electronic certificate as an example, when a user applies for an electronic certificate, the user can send a verification identity generation request to the server through the client. After receiving the verification identity generation request, the server can verify the identity of the client. The server can determine the user's identity based on the identity authentication operation of collaborative signature. If the verification is passed, it is determined that the identity verification of the client is passed.
[0084] In an optional embodiment, the instructing the client to generate a second digital signature according to the first digital signature and obtain the second digital signature includes:
[0085] Send a second digital signature request to the client; the second digital signature request instructs the client to generate a second digital signature according to the first digital signature and obtain the second digital signature.
[0086] When the server generates the first digital signature according to the client information, it can perform a hashing calculation on the client information to generate a hash value, and then send a second digital signature request to the client. The second digital signature request may include the first digital signature and the hash value. When the client receives the second digital signature request, it can calculate the first digital signature and the hash value using the client collaborative signature key to generate a second digital signature.
[0087] Generally, when directly calculating the client information, the calculation efficiency is low. Performing a hashing calculation on the client information can compress the client information into a hash value with a shorter length. Calculating the first digital signature and the hash value using the client collaborative signature key can improve the calculation efficiency.
[0088] In this embodiment, the second digital signature is calculated by the client using the client signature key. When invoking the client signature key, the client can request the customer to input the PIN code bound to the customer, thereby determining the identity of the client, which is equivalent to binding the client's behavior and can prove the authenticity of the client sending a verification identity request to the server.
[0089] In an optional embodiment, the generating an electronic signature according to the third digital signature and the client information includes:
[0090] Perform a calculation on the third digital signature and the client information according to a preset signature key to obtain the electronic signature.
[0091] The server pre-stores a preset signature key. After calculating the third digital signature, the server can also calculate the third digital signature and the client through the preset signature key to obtain an electronic signature. The electronic signature is calculated based on the third digital signature, and the third digital signature is obtained after collaborative signature by the server and the client. Therefore, the finally obtained electronic signature can ensure the authenticity of the client's identity. And the electronic signature is issued on behalf of the authoritative agency. During the use of the electronic certificate, the verification identifier generated based on the electronic signature can verify the authenticity of the electronic certificate.
[0092] In the embodiment of the present application, when the server authenticates the client's identity, it generates a first digital signature, instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client; generates a verification identifier of the client based on the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client collaborate to sign to generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0093] The embodiment of the present application also provides a method for generating a verification identifier, which is applied to a client, as Figure 4 shown, the method includes:
[0094] Step 401, send a verification identifier generation request to the server; the verification identifier generation request instructs the server to generate a first digital signature.
[0095] After receiving the verification identifier generation request, the server first verifies the identity of the client. When the client's identity is verified, it generates a first digital signature.
[0096] This embodiment can be applied to the generation of electronic certificates, and the electronic certificates include but are not limited to electronic ID cards, electronic medical insurance cards, etc. The client information may include basic information and image information of the certificate. The basic information may include but is not limited to information such as name, gender, mobile phone number, ID number, certificate status, certificate identifier, certificate type, issuing agency, and expiration date. The image information may be an avatar.
[0097] Among them, the server generates a first digital signature, including:
[0098] Generate a random number, and generate a first digital signature based on the random number and a preset signature algorithm.
[0099] Step 402: Generate a second digital signature and send the second digital signature to the server.
[0100] After generating the first digital signature, the server may send a second digital signature request to the client. The second digital signature request includes the first digital signature. After receiving the second digital signature request, the client may generate a second digital signature based on the first digital signature.
[0101] The server may also perform a hashing calculation on the client information to generate a hash value and send the hash value to the client. After receiving the first digital signature and the hash value, the client may calculate the first digital signature and the hash value to generate a second digital signature.
[0102] Step 403: Receive the verification identifier generated by the server based on the second digital signature.
[0103] The verification identifier is generated by the server based on a third digital signature, an electronic signature, and the client information. The third digital signature is generated by the server based on the second digital signature; the electronic signature is generated by the server based on the third digital signature and the client information.
[0104] The first digital signature is calculated by the server, and the second digital signature is calculated by the client based on the first digital signature. Both the server and the client participate in the digital signature process. Therefore, the third digital signature generated based on the second digital signature can authenticate the identity of the client, bind the client's actions, and ensure the reliability of the third digital signature.
[0105] The server may calculate the third digital signature and the client information based on a preset signature key to generate an electronic signature, which represents that the electronic certificate is issued by an authoritative institution and is used to verify the authenticity of the electronic certificate.
[0106] The client information may be a certificate identifier, such as an ID number, a social security card account number, etc. The verification identifier generated by the server includes the third digital signature, the electronic signature, and the client information.
[0107] The authenticity of the client's identity, the authenticity of the electronic certificate, and the authenticity of the certificate information can be determined through the verification identifier. At the same time, the client information can be found based on the verification identifier.
[0108] After receiving the client information and the verification identifier, the client may display the client information and the verification identifier to generate an electronic certificate.
[0109] 0 As a first example, such as Figure 2As shown, the generated electronic certificate may include an electronic certificate basic information field, an electronic certificate image information field, and an electronic certificate QR code field. Specifically, the display function is used to generate the electronic certificate, such as D = display(B||M||Q), where D is the electronic certificate; B is the information in the electronic certificate basic information field; M is the information in the electronic certificate image information field; and Q is the information in the electronic certificate QR code field.
[0110] The process of generating the electronic identifier is as Figure 3 shown and includes:
[0111] Step 301, the client initiates an electronic certificate generation request and verifies the user's identity based on the collaborative signature-based identity authentication operation.
[0112] Step 302, the server and the client perform a digital signature operation on the information B in the electronic certificate basic information field and the information M in the electronic certificate image information field. The server calculates the complete digital signature S (i.e.,
[0113] the third digital signature) based on the partial digital signatures of the client and the server 0 (i.e., the first digital signature and the second digital signature).
[0114] Step 303, the server uses the signature key preset on the server to perform a digital signature operation on the information B in the electronic certificate basic information field, the information M in the electronic certificate image information field, and the complete digital signature S to generate the server authoritative digital signature Sa (i.e., the electronic signature).
[0115] 5 Step 304, the server returns the relevant data to the client, and the electronic certificate client assembles the data
[0116] and displays it to generate the electronic certificate D = display(B||M||Q). The relevant data returned by the server includes the information B in the electronic certificate basic information field, the information M in the electronic certificate image information field, and the information Q in the electronic certificate QR code field. The information Q in the electronic certificate QR code field is generated based on the complete digital signature S, the information B in the electronic certificate basic information field, and the authoritative digital signature Sa.
[0117] As Figure 2 shown, the client can display the basic information in the client information in the electronic certificate basic information field B. For example, Name: Li*Yao; Gender: Male; Mobile Phone Number: 156****0001; ID Number: 11**************01; Certificate Status: Normal; Certificate Number: XXXX00000001; Certificate Type: XXX Certificate; Issuing Agency: XXX Agency; Expiration Date: December 31, 2022.
[0118] Optionally, the basic information in the client information can be processed through the sequence function to obtain information B in the basic information field of the electronic certificate. For example, B = sequence(b1||b2||b3||b4||b5||b6||b7||b8||b9), where b1 is the name, b2 is the gender, b3 is the mobile phone number, b4 is the ID number, b5 is the certificate status, b6 is the certificate number, b7 is the certificate type, b8 is the issuing agency, and b9 is the expiration date.
[0119] The client can display the image information in the client information in the electronic certificate image information field.
[0120] Optionally, the image information in the client information can be processed through the sequence function to obtain information M in the electronic certificate image information field. For example, M = sequence(m1), where m1 is the electronic certificate picture, such as a profile picture, etc.
[0121] The client can display the verification identifier in the electronic certificate QR code field Q. The authenticity of the electronic certificate can be verified through the verification identifier, and the certificate information of the user, such as basic information and image information, can be read through the verification identifier.
[0122] Optionally, the verification identifier can be processed through the base64 function to obtain information Q in the electronic certificate QR code field. For example, Q = base64(S||b6||Sa), where S is the third digital signature; b6 is the certificate number, that is, the client information; Sa is the electronic signature. The electronic verification identifier can be encoded and converted through the base64 function into Figure 2 the QR code form as shown.
[0123] In the embodiment of the present application, when the server authenticates the client's identity, it generates a first digital signature, instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client; generates the verification identifier of the client based on the third digital signature, the electronic signature and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0124] In an optional embodiment, the generating of the second digital signature includes:
[0125] Obtain the first digital signature and the hash value; the hash value is generated by the server through hash calculation on the client information;
[0126] Generate the second digital signature according to the first digital signature and the hash value.
[0127] Generally, when directly calculating the client information, the calculation efficiency is relatively low. By performing hash calculation on the client information, the client information can be compressed into a hash value with a shorter length. Calculating the first digital signature and the hash value using the client collaborative signature key can improve the calculation efficiency.
[0128] In an alternative embodiment, before sending a verification identifier generation request to the server, the client can verify the user's identity by inputting a PIN password or using fingerprint recognition or face recognition data bound to the PIN password, that is, establishing a binding relationship between the client and the user. When the client successfully verifies the user's identity, the user can send a verification identifier generation request to the server through the client. When the server receives the verification identifier generation request, it first verifies the identity of the client. If the client's identity verification is passed, it means that the identity verification of the user bound to the client is passed. Thus, the risk of electronic certificates being stolen or misused is greatly avoided.
[0129] Based on the same principle as the method provided in the embodiments of the present application, the embodiments of the present application also provide a verification identifier generation system, as Figure 5 shown. This system includes a server 501 and a client 502;
[0130] Among them, the client sends a verification identifier generation request to the server and obtains a verification identifier;
[0131] When the server successfully authenticates the client's identity, it generates a first digital signature, instructs the client to generate a second digital signature according to the first digital signature, and obtains the second digital signature;
[0132] This embodiment can be applied to the generation of electronic certificates, and the electronic certificates include but are not limited to electronic ID cards, electronic medical insurance cards, etc. Among them, the client information may include basic information and image information of the certificate. The basic information may include but is not limited to information such as name, gender, mobile phone number, ID number, certificate status, certificate identifier, certificate type, issuing agency, and expiration date. The image information may be, for example, a profile picture.
[0133] Among them, the server can generate a random number and generate a first digital signature according to the random number and a preset signature algorithm. The server can also instruct the client to calculate the client information according to a preset client collaborative signature key, and then generate a second digital signature.
[0134] Generate a third digital signature based on the second digital signature, and generate an electronic signature based on the third digital signature and the client information of the client.
[0135] Among them, the first digital signature is calculated by the server, the second digital signature is calculated by the client based on the first digital signature, and both the server and the client participate in the digital signature process. Therefore, the third digital signature generated based on the second digital signature can authenticate the identity of the client, bind the client's actions, and ensure the reliability of the third digital signature.
[0136] The server can calculate the third digital signature and client information according to the preset signature key to generate an electronic signature, which represents that the electronic certificate is issued by an authoritative institution and is used to verify the authenticity of the electronic certificate.
[0137] Generate a verification identifier of the client based on the third digital signature, the electronic signature, and the client information.
[0138] The client information can be a certificate identifier, such as an ID number, a social security card account number, etc. The verification identifier generated by the server includes the third digital signature, the electronic signature, and the client information, and can determine the authenticity of the client's identity, the authenticity of the electronic certificate, and the authenticity of the certificate information through the verification identifier. At the same time, the client information can be found according to the verification identifier.
[0139] After the server generates the verification identifier of the client, it can send the verification identifier to the client, and at the same time, it can also send the client information to the client. After receiving the client information and the verification identifier, the client can display the client information and the verification identifier to generate an electronic certificate.
[0140] As a first example, as Figure 2 shown, the generated electronic certificate can include an electronic certificate basic information field, an electronic certificate image information field, and an electronic certificate QR code field. Specifically, use the display function to generate an electronic certificate, such as D = display(B||M||Q), where D is the electronic certificate; B is the information in the electronic certificate basic information field; M is the information in the electronic certificate image information field; Q is the information in the electronic certificate QR code field.
[0141] The process of generating the electronic identifier is as Figure 3 shown, including:
[0142] Step 301, the client initiates an electronic certificate generation request and verifies the user identity based on the identity authentication operation of collaborative signature.
[0143] Step 302, the server and the client perform digital signature operations on the information B in the basic information field of the electronic certificate and the information M in the electronic certificate image information field. The server calculates the complete digital signature S (i.e., the third digital signature) based on the partial digital signatures of the client and the server (i.e., the first digital signature and the second digital signature).
[0144] Step 303, the server uses the pre-set signature key of the server to perform digital signature operations on the information B in the basic information field of the electronic certificate, the information M in the electronic certificate image information field, and the complete digital signature S, and generates the server authoritative digital signature Sa (i.e., the electronic signature).
[0145] Step 304, the server returns the relevant data to the client. The electronic certificate client assembles the data and displays it, generating the electronic certificate D = display(B||M||Q). The relevant data returned by the server includes the information B in the basic information field of the electronic certificate, the information M in the electronic certificate image information field, and the information Q in the electronic certificate two-dimensional code field. The information Q in the electronic certificate two-dimensional code field is generated based on the complete digital signature S, the information B in the basic information field of the electronic certificate, and the authoritative digital signature Sa.
[0146] As Figure 2 shown, the client can display the basic information in the client information in the basic information field B of the electronic certificate. For example, Name: Li *yao; Gender: Male; Mobile phone number: 156****0001; ID number: 11**************01; Certificate status: Normal; Certificate number: XXXX00000001; Certificate type: XXX certificate; Issuing agency: XXX agency; Expiration date: December 31, 2022.
[0147] Optionally, the basic information in the client information can be processed through the sequence function to obtain the information B in the basic information field of the electronic certificate. For example, B = sequence(b1||b2||b3||b4||b5||b6||b7||b8||b9), where b1 is the name, b2 is the gender, b3 is the mobile phone number, b4 is the ID number, b5 is the certificate status, b6 is the certificate number, b7 is the certificate type, b8 is the issuing agency, and b9 is the expiration date.
[0148] The client can display the image information in the client information in the electronic certificate image information field.
[0149] Optionally, the image information in the client information can be processed through the sequence function to obtain the information M in the electronic certificate image information field. For example, M = sequence(m1), where m1 is the electronic certificate picture, such as a profile picture, etc.
[0150] The client can display the verification identifier in the QR code field Q of the electronic certificate. The authenticity of the electronic certificate can be verified through the verification identifier, and the certificate information of the user, such as basic information and image information, can be read through the verification identifier.
[0151] Optionally, the verification identifier can be processed through the base64 function to obtain the information Q of the QR code field of the electronic certificate. For example, Q = base64(S||b6||Sa), where S is the third digital signature; b6 is the certificate number, that is, the client information; Sa is the electronic signature. The electronic verification identifier can be encoded and converted through the base64 function into the Figure 2 QR code form as shown.
[0152] The verification identifier generation system provided by the embodiments of the present application can implement Figures 1 to 4 each process implemented in the method embodiments. To avoid repetition, it will not be elaborated here.
[0153] In the embodiments of the present application, when the server authenticates the client's identity, it generates a first digital signature, instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client; generates the verification identifier of the client based on the third digital signature, the electronic signature and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0154] The verification identifier generation system of the embodiments of the present application can execute the verification identifier generation method provided by the embodiments of the present application, and its implementation principle is similar. The actions performed by each module and unit in the verification identifier generation system in the embodiments of the present application correspond to the steps in the verification identifier generation method in the embodiments of the present application. For the detailed function description of each module of the verification identifier generation system, reference can be specifically made to the description in the corresponding verification identifier generation method shown above, and it will not be elaborated here.
[0155] Based on the same principle as the method provided by the embodiments of the present application, the embodiments of the present application also provide a verification identifier generation device, which is applied to the server, as Figure 6 shown, the device includes:
[0156] A first signature module 601, which generates a first digital signature when the client's identity is authenticated, and instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature;
[0157] The second signature module 602 generates a third digital signature according to the second digital signature, and generates an electronic signature according to the third digital signature and the client information of the client;
[0158] The verification identifier generation module 603 generates a verification identifier of the client according to the third digital signature, the electronic signature, and the client information.
[0159] In the embodiment of the present application, when the server authenticates the client's identity, it generates a first digital signature, instructs the client to generate a second digital signature according to the first digital signature and obtain the second digital signature; generates a third digital signature according to the second digital signature, and generates an electronic signature according to the third digital signature and the client information of the client; generates a verification identifier of the client according to the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0160] Based on the same principle as the method provided in the embodiment of the present application, the embodiment of the present application also provides a verification identifier generation device, which is applied to a client, as Figure 7 shown, the device includes:
[0161] The verification identifier request module 701 sends a verification identifier generation request to the server; the verification identifier generation request instructs the server to generate a first digital signature;
[0162] The digital signature module 702 generates a second digital signature and sends the second digital signature to the server;
[0163] The verification identifier receiving module 703 receives the verification identifier generated by the server according to the second digital signature;
[0164] Wherein, the verification identifier is generated by the server according to a third digital signature, an electronic signature, and the client information, and the third digital signature is generated by the server according to the second digital signature; the electronic signature is generated by the server according to the third digital signature and the client information.
[0165] In the embodiments of the present application, when the server authenticates the client successfully, it generates a first digital signature, and instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client; generates a verification identifier of the client based on the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0166] Based on the same principle as the method shown in the embodiments of the present application, the embodiments of the present application also provide an electronic device, which may include, but is not limited to: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the verification identifier generation method shown in any optional embodiment of the present application by calling the computer program. Compared with the prior art, in the verification identifier generation method provided by the present application, when the server authenticates the client successfully, it generates a first digital signature, and instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client; generates a verification identifier of the client based on the third digital signature, the electronic signature, and the client information. When verifying the client's identity, the server and the client jointly sign to generate a verification identifier, which can effectively improve the authenticity, integrity, and non-repudiation of the electronic certificate, and reduce the probability of the electronic certificate being tampered with or illegally misused.
[0167] In an optional embodiment, an electronic device is also provided, as Figure 8 shown Figure 8 The electronic device 800 shown may be a server, including: a processor 801 and a memory 803. Among them, the processor 801 and the memory 803 are connected, such as connected through a bus 802. Optionally, the electronic device 800 may further include a transceiver 804. It should be noted that in actual applications, the transceiver 804 is not limited to one, and the structure of the electronic device 800 does not constitute a limitation to the embodiments of the present application.
[0168] The processor 801 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 801 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0169] The bus 802 may include a path for transmitting information between the above components. The bus 802 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 802 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0170] The memory 803 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or it may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0171] The memory 803 is used to store the application program code for executing the solution of this application and is controlled by the processor 801 for execution. The processor 801 is used to execute the application program code stored in the memory 803 to implement the content shown in the foregoing method embodiments.
[0172] Among them, the electronic devices include but are not limited to: mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic devices shown are merely examples and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0173] The server provided by the present application can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms. The terminal can be a smart phone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, etc., but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and the present application does not limit this here.
[0174] The embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored. When it runs on a computer, it enables the computer to execute the corresponding content in the foregoing method embodiments.
[0175] It should be understood that although the steps in the flowchart of the accompanying drawings are displayed in sequence according to the indication of the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limitation, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. Their execution order does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0176] It should be noted that the above-mentioned computer-readable storage medium in this application can also be a computer-readable signal medium or a combination of a computer-readable storage medium and a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. And in this application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0177] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; it can also exist separately without being assembled into the electronic device.
[0178] The above-mentioned computer-readable medium carries one or more programs, and when the above-mentioned one or more programs are executed by the electronic device, the electronic device is caused to execute the method shown in the above-mentioned embodiments.
[0179] According to one aspect of the present application, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to execute the verification identity generation method provided in the above various alternative implementation manners.
[0180] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0181] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0182] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the module itself in some cases. For example, the search intent category determination module can also be described as the "module for determining the search intent category of a search request".
[0183] The above description is only the preferred embodiments of this application and the explanation of the technical principles applied. Those skilled in the art should understand that the scope of disclosure involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A verification identifier generation method, applied to a server, characterized in that The method includes: Receiving a verification identifier generation request from a client, determining the user identity based on the collaborative signature-based authentication operation. If the verification is passed, determining that the identity verification of the client is passed, generating a first digital signature, instructing the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; wherein, the second digital signature is calculated by the client using a signature key for the first digital signature and a hash value, and when using the signature key, the client inputs a PIN code bound to the client. Generating a third digital signature according to the second digital signature, and generating an electronic signature according to the third digital signature and the client information of the client. Generating the verification identifier of the client according to the third digital signature, the electronic signature and the client information.
2. The verification identifier generation method according to claim 1, wherein The instructing the client to generate a second digital signature based on the first digital signature and obtain the second digital signature includes: Sending a second digital signature request to the client; the second digital signature request instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature.
3. The verification identifier generation method according to claim 1, wherein The generating the electronic signature according to the third digital signature and the client information includes: Calculating the third digital signature and the client information according to a preset signature key to obtain the electronic signature.
4. A verification identifier generation method, applied to a client, characterized in that The method includes: Sending a verification identifier generation request to the server; the verification identifier generation request instructs the server to generate a first digital signature. Obtaining the first digital signature and the hash value; calculating the first digital signature and the hash value using a signature key to generate a second digital signature, and sending the second digital signature to the server; wherein, when using the signature key, the client inputs a PIN code bound to the client. Receiving the verification identifier generated by the server according to the second digital signature. Wherein, the verification identifier is generated by the server according to a third digital signature, an electronic signature and the client information of the client, and the third digital signature is generated by the server according to the second digital signature; the electronic signature is generated by the server according to the third digital signature and the client information.
5. The verification identifier generation method according to claim 4, wherein The generating the second digital signature includes: Obtaining the first digital signature and the hash value; the hash value is generated by the server through hash calculation of the client information. Generating the second digital signature according to the first digital signature and the hash value.
6. A verification identification generation system, characterized in that, Including a server and a client; Wherein, the client sends a verification identifier generation request to the server, and the verification identifier generation request instructs the server to generate a first digital signature. The server receives a verification identity generation request from a client, determines the user identity based on the authentication operation of collaborative signature, and generates a first digital signature when the client identity authentication is passed, instructing the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; wherein, the second digital signature is calculated by the client using a signature key for the first digital signature and a hash value, and when using the signature key, the client inputs a PIN code bound to the client. Generate a third digital signature based on the second digital signature, and generate an electronic signature based on the third digital signature and the client information of the client. Generate the verification identity of the client based on the third digital signature, the electronic signature, and the client information.
7. A verification identifier generation device, applied to a server, characterized in that The device includes: A first signature module that receives a verification identity generation request from a client, determines the user identity based on the authentication operation of collaborative signature, and if the verification is passed, determines that the client identity authentication is passed, generates a first digital signature, and instructs the client to generate a second digital signature based on the first digital signature and obtain the second digital signature; wherein, the second digital signature is calculated by the client using a signature key for the first digital signature and a hash value, and when using the signature key, the client inputs a PIN code bound to the client. A second signature module that generates a third digital signature based on the second digital signature, and generates an electronic signature based on the third digital signature and the client information of the client. A verification identity generation module that generates the verification identity of the client based on the third digital signature, the electronic signature, and the client information.
8. A verification identifier generation device, applied to a client, characterized in that The device includes: A verification identity request module that sends a verification identity generation request to the server; the verification identity generation request instructs the server to generate a first digital signature. A digital signature module that obtains the first digital signature and the hash value; calculates and generates a second digital signature using the signature key for the first digital signature and the hash value, and sends the second digital signature to the server; wherein, when using the signature key, the client inputs a PIN code bound to the client. A verification identity receiving module that receives the verification identity generated by the server based on the second digital signature. Wherein, the verification identity is generated by the server based on a third digital signature, an electronic signature, and the client information of the client, the third digital signature is generated by the server based on the second digital signature; the electronic signature is generated by the server based on the third digital signature and the client information.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the method according to any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, it implements the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Digital signature method and apparatus
CN108270575A
Electronic document signature method and device, storage medium and electronic equipment
CN111177801A
Electronic certificate display method, electronic certificate verification method, terminal and server
CN115378609A