Information loss reporting method and related device

CN116305051BActive Publication Date: 2026-10-09INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310348297.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2026-10-09
Estimated Expiration
2043-04-03

AI Technical Summary

Technical Problem

[0005]本申请提供一种信息挂失方法和相关设备,用以解决信息挂失的及时性较低的问题

Benefits of technology

[0031] The information loss reporting method and related equipment provided in this application receive a loss reporting message sent by a loss reporting device, determine the user identifier of the user reporting the loss message, use the user's private key associated with the user identifier to sign and verify the loss reporting message to obtain first encrypted information, then decrypt the first encrypted information to obtain a first user password and a first timestamp, and retrieve a second user password, a second timestamp, and second encrypted information associated with the user identifier from the database. If the first user password and the second user password are the same, the first timestamp and the second timestamp are the same, and the first encrypted information and the second encrypted information are the same, then the information requested by the user to report the loss is set to a lost status. In this application, when a loss reporting message is received, the user's private key is obtained through the loss reporting user's loss identifier to sign and verify the loss reporting message. This eliminates the need for the user to perform signature verification based on the digital certificate in the token device, meaning the user does not need to search for the token device to report the loss, thus saving the time spent by the user searching for the token device and improving the timeliness of information loss reporting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116305051B_ABST
    Figure CN116305051B_ABST
Patent Text Reader

Abstract

The application provides an information loss reporting method and related equipment, belonging to the technical field of information loss reporting, and the method comprises the following steps: receiving a loss reporting message sent by a loss reporting device, and determining a user identifier of a loss reporting user corresponding to the loss reporting message; using a user private key associated with the user identifier to perform signature verification on the loss reporting message to obtain first ciphertext information, and decrypting the first ciphertext information to obtain a first user password and a first timestamp; obtaining a second user password, a second timestamp and second ciphertext information associated with the user identifier from a database; when the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first ciphertext information is the same as the second ciphertext information, setting information requested to be reported as lost by the loss reporting user as a loss reporting state. In the application, the timeliness of information loss reporting is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information loss reporting technology, and in particular to an information loss reporting method and related equipment. Background Technology

[0002] If a user loses a card issued by a financial institution, they need to report the loss. This can be done by calling the financial institution's service hotline for temporary reporting or by visiting the institution in person to complete the formal loss reporting process. Whether reporting the loss by phone or in person, the user will need to provide information such as the cardholder's name and account opening document number.

[0003] With the development of information technology and users' increasing demands for faster information reporting, financial institutions provide users with token devices, which allow users to report lost information using the digital certificates of the token devices.

[0004] However, the token device is issued to users when they register and open an account. If a user needs to report the loss of information, the time between user registration and reporting the loss may be long. The user needs to spend a lot of time finding the token device to report the loss, which means that the user cannot report the loss in a timely manner, that is, the timeliness of information loss reporting is low. Summary of the Invention

[0005] This application provides a method and related equipment for reporting lost information, in order to solve the problem of low timeliness in reporting lost information.

[0006] On the one hand, this application provides a method for reporting information loss, applied to an authentication device, comprising:

[0007] Receive the loss reporting message sent by the loss reporting device, and determine the user identifier of the user who reported the loss corresponding to the loss reporting message;

[0008] The lost message is signed and verified using the user's private key associated with the user identifier to obtain the first ciphertext information, and the first ciphertext information is decrypted to obtain the first user password and the first timestamp;

[0009] Retrieve the second user password, second timestamp, and second encrypted information associated with the user identifier from the database;

[0010] When the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information, the information of the user requesting to report the loss is set to the lost status.

[0011] On the other hand, this application also provides a method for reporting information loss, applied to a loss reporting device, comprising:

[0012] Receive a loss reporting request sent by a user based on a terminal, and obtain the user identifier and first user password corresponding to the user according to the loss reporting request;

[0013] Obtain the first timestamp associated with the user identifier and the user's private key, and encrypt the first user password, the user identifier, and the first timestamp to obtain the first ciphertext information;

[0014] The first encrypted information is signed using the user's private key to obtain a lost message;

[0015] The lost message is sent to the authentication device, and the lost message is used by the authentication device to verify the user's identity.

[0016] On the other hand, this application also provides an authentication device, comprising:

[0017] The first receiving module is used to receive the loss reporting message sent by the loss reporting device and determine the user identifier of the loss reporting user corresponding to the loss reporting message;

[0018] The verification module is used to sign and verify the lost message using the user's private key associated with the user identifier to obtain the first ciphertext information, and to decrypt the first ciphertext information to obtain the first user password and the first timestamp.

[0019] The first acquisition module is used to acquire from the database the second user password, the second timestamp, and the second encrypted information associated with the user identifier;

[0020] The setting module is used to set the information requested by the user to be reported lost to a reported lost status when the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information.

[0021] On the other hand, this application also provides a loss reporting device, comprising:

[0022] The second receiving module is used to receive a loss reporting request sent by the user based on the terminal, and to obtain the user identifier and the first user password corresponding to the user according to the loss reporting request.

[0023] The second acquisition module is used to acquire the first timestamp associated with the user identifier and the user private key, and encrypt the first user password, the user identifier and the first timestamp to obtain the first ciphertext information;

[0024] The signature module is used to sign the first ciphertext information using the user's private key to obtain the loss report message;

[0025] The sending module is used to send the lost message to the authentication device, and the lost message is used by the authentication device to verify the identity of the user.

[0026] On the other hand, this application also provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0027] The memory stores computer-executed instructions;

[0028] The processor executes the computer execution instructions stored in the memory to implement the information loss reporting method described above.

[0029] On the other hand, this application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the information loss reporting method described above.

[0030] On the other hand, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the information loss reporting method as described above.

[0031] The information loss reporting method and related equipment provided in this application receive a loss reporting message sent by a loss reporting device, determine the user identifier of the user reporting the loss message, use the user's private key associated with the user identifier to sign and verify the loss reporting message to obtain first encrypted information, then decrypt the first encrypted information to obtain a first user password and a first timestamp, and retrieve a second user password, a second timestamp, and second encrypted information associated with the user identifier from the database. If the first user password and the second user password are the same, the first timestamp and the second timestamp are the same, and the first encrypted information and the second encrypted information are the same, then the information requested by the user to report the loss is set to a lost status. In this application, when a loss reporting message is received, the user's private key is obtained through the loss reporting user's loss identifier to sign and verify the loss reporting message. This eliminates the need for the user to perform signature verification based on the digital certificate in the token device, meaning the user does not need to search for the token device to report the loss, thus saving the time spent by the user searching for the token device and improving the timeliness of information loss reporting. Attached Figure Description

[0032] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0033] Figure 1 This is a schematic diagram illustrating a scenario related to the information loss reporting method involved in this application;

[0034] Figure 2 A flowchart illustrating the first embodiment of the information loss reporting method provided in this application;

[0035] Figure 3 A flowchart illustrating a second embodiment of the information loss reporting method provided in this application;

[0036] Figure 4 A flowchart illustrating the third embodiment of the information loss reporting method provided in this application;

[0037] Figure 5 A flowchart illustrating the fourth embodiment of the information loss reporting method provided in this application;

[0038] Figure 6 A flowchart illustrating the fifth embodiment of the information loss reporting method provided in this application;

[0039] Figure 7 This is a schematic diagram of the modules of the certification device in this application;

[0040] Figure 8 This is a schematic diagram of the module of the lost device in this application;

[0041] Figure 9 This is a structural diagram of the device being certified / lost in this application.

[0042] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation

[0043] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0044] If a user loses a card issued by a financial institution, they need to report the loss. This can be done by calling the financial institution's service hotline for temporary reporting or by visiting the institution in person to complete the formal loss reporting process. Whether reporting the loss by phone or in person, the user will need to provide information such as the cardholder's name and account opening document number.

[0045] With the development of information technology and users' increasing demands for faster information reporting, financial institutions provide users with token devices, which allow users to report lost information using the digital certificates of the token devices.

[0046] The inventors of this application have discovered that token devices are issued to users when they register and open an account. If a user needs to report the loss of their information, the time between user registration and reporting the loss may be long, and the user needs to spend a lot of time finding the token device to report the loss, resulting in the user not being able to report the loss in a timely manner, that is, the timeliness of reporting the loss of information is low.

[0047] The inventors of this application therefore conceived of a method to obtain the user's private key through the user's lost token identifier when receiving a lost message, and then use this method to sign and verify the lost message. This eliminates the need for the user to sign and verify the message based on the digital certificate in the token device, thus eliminating the need for the user to search for the token device to report the loss. This saves the time spent by the user searching for the token device to report the loss and improves the timeliness of information loss reporting.

[0048] Reference Figure 1 , Figure 1 This is a schematic diagram illustrating the scenario involved in the information loss reporting method of this application. The user 100 sends a loss reporting request to the loss reporting device 300 via terminal device 200. The loss reporting device 300 obtains the user identifier and the first user password provided by the user 100 based on the loss reporting request. The device 300 then obtains the first timestamp associated with the user identifier, and encrypts the first user password, the first timestamp, and the user identifier to obtain first ciphertext information. The device 300 then signs the first ciphertext information using the user's private key associated with the user identifier to obtain a loss reporting message. The loss reporting device 300 then sends the loss reporting message to the authentication device 400. The loss reporting message carries the user identifier. The authentication device 400 obtains the user's private key, the second timestamp, the second user password, and the second ciphertext information associated with the user identifier from the database. The authentication device 400 uses the user's private key to sign and verify the loss reporting message to obtain the first ciphertext information, and then decrypts the first ciphertext information to obtain the first user password and the first timestamp. The authentication device 400 then compares whether the first timestamp and the second timestamp are the same, whether the first user password and the second user password are the same, and whether the first encrypted information and the second encrypted information are the same. If they are all the same, the authentication device 400 sets the information of the user requesting to report the loss to the reported state.

[0049] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0050] In addition, the data involved in this application can be data authorized by the user or fully authorized by all parties. The collection, dissemination and use of the data comply with the requirements of relevant national laws and regulations. The implementation methods / executives disclosed herein can be combined with each other.

[0051] It should be noted that the information loss reporting method and related equipment of this application can be used in the field of information loss reporting technology, or in any field other than the field of information loss reporting technology. The application field of the information loss reporting method and related equipment of this application is not limited.

[0052] Reference Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the information loss reporting method of this application. The information loss reporting method includes the following steps:

[0053] Step S201: Receive the loss reporting message sent by the loss reporting device and determine the user identifier of the user reporting the loss corresponding to the loss reporting message.

[0054] In this embodiment, the executing entity is an authentication device. The authentication device can be a physical device of a remote authentication center for reporting lost information. The information to be reported includes the account of a financial card, a phone card, etc., and the user who reports the loss is defined as the reporting user.

[0055] When a user needs to report a lost item, they send a loss report request to the loss reporting device via their terminal. The loss reporting device can be a physical device corresponding to the key management center. The loss reporting device is used to generate the user's private key and is responsible for encrypting and signing the information requested by the user to report the loss.

[0056] When a user registers for a debit card after reporting its loss, the financial institution will assign a corresponding user password and use the registration time as a timestamp. The user can use their mobile phone number, ID number, or email address as their identification during registration. After registration, the financial institution will send the user password to the user and send the timestamp and user identifier to the card reporting device for associated storage.

[0057] When a user reports a lost item, the request includes their user identifier and password, defined as the first user password. The authentication device obtains the timestamp associated with the user identifier, defined as the first timestamp. The device encrypts the user identifier, the first user password, and the first timestamp to obtain first ciphertext information. Furthermore, the device generates a private key corresponding to the user, which is stored in association with the user identifier. The device signs the first ciphertext information using the private key to obtain a loss report, which is then sent to the verification device. Additionally, the private key generated by the device, along with the user identifier, is sent to the authentication device. That is, before receiving the loss report from the device, the authentication device receives the user identifier and corresponding private key from the device and stores them in association.

[0058] The lost item report carries the user identifier of the user who reported the loss, and the authentication device can obtain the user identifier corresponding to the user who reported the loss based on the lost item report.

[0059] Step S202: Use the user's private key associated with the user identifier to sign and verify the lost message to obtain the first ciphertext information, and decrypt the first ciphertext information to obtain the first user password and the first timestamp.

[0060] The user's private key has both signing and verification functions. The authentication device obtains the managed user's private key based on the user identifier, and then uses the user's private key to sign and verify the lost message. After successful signature verification, the first encrypted information is obtained. The authentication device then decrypts the first encrypted information to obtain the first user password and the first timestamp.

[0061] Step S203: Obtain the second user password, second timestamp, and second encrypted information associated with the user identifier from the database.

[0062] Step S204: When the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information, the information of the user requesting to report the loss is set to the lost status.

[0063] After a user successfully registers, the device generates encrypted information based on the user's identifier, timestamp, and password, and stores the user's identifier, timestamp, password, and encrypted information in the database.

[0064] The authentication device retrieves a second user password, a second timestamp, and second encrypted information from the database based on the user identifier. The device compares the first and second user passwords for consistency, the first and second timestamps for consistency, and the first and second encrypted information for consistency. The comparison between the second and first encrypted information can be a comparison of their hash values; if the hash values ​​are the same, then the first and second encrypted information are identical.

[0065] When the first user password matches the second user password, the first timestamp matches the second timestamp, and the first encrypted information matches the second encrypted information, the authentication of the user who reported the loss is successful, and the authentication device sets the user's request to report the loss to a "lost" status. The user's request to report the loss is carried in the loss report request and is sent by the loss reporting device to the authentication device. The user's request to report the loss can be a bank card or a phone card. When the status of this information is "lost," the bank card or phone card is frozen and cannot be used. Furthermore, after setting the user's request to report the loss to a "lost" status, the authentication device sends a success message to the terminal associated with the user's identifier to notify the user that the loss report was successful.

[0066] In this embodiment, a loss reporting message sent by the loss reporting device is received, and the user identifier of the user reporting the loss message is determined. The loss reporting message is signed and verified using the user's private key associated with the user identifier to obtain first encrypted information. The first encrypted information is then decrypted to obtain a first user password and a first timestamp. The second user password, second timestamp, and second encrypted information associated with the user identifier are retrieved from the database. If the first user password and the second user password are the same, the first timestamp and the second timestamp are the same, and the first encrypted information and the second encrypted information are the same, then the loss reporting information of the user is set to a lost status. In this embodiment, when a loss reporting message is received, the user's private key is obtained through the loss reporting user's loss reporting identifier to sign and verify the loss reporting message. This eliminates the need for the user to perform signature verification based on the digital certificate in the token device, meaning the user does not need to search for the token device to report the loss, thus saving the time spent by the user searching for the token device and improving the timeliness of information loss reporting.

[0067] Reference Figure 3 , Figure 3 This is a flowchart illustrating the second embodiment of the information loss reporting method of this application. Based on the first embodiment, after step S204, it further includes:

[0068] Step S301: Obtain the current time point.

[0069] In this embodiment, when a user successfully reports the loss of their information, the timestamp of the loss report verification needs to be updated, which means that the timestamp associated with the user in the database needs to be updated.

[0070] In response, the authentication device obtains the current time as the timestamp to be updated in the database.

[0071] Step S302: Encrypt the current time point, user identifier, and second user password to obtain third ciphertext information.

[0072] When the timestamp in the database is updated, the corresponding encrypted information also needs to be updated. The authentication device encrypts the current time, user identifier, and second user password to obtain the third encrypted information.

[0073] In one example, the current time point, user identifier, and second user password can all be identified by characters. The authentication device concatenates the current time point, user identifier, and second user password to obtain a string, which is the third encrypted information.

[0074] In another example, the authentication device concatenates the current time, user identifier, and second user password to obtain concatenated information, which is a string. The device divides the concatenated information into multiple sub-information groups, performs preset calculations on each sub-information group, and then concatenates the sub-information groups after the preset calculations to obtain the third encrypted information.

[0075] For example, the concatenated information is first padded. If the number of bits in the concatenated information is not a multiple of 512, it needs to be padded. Padding is done by adding a 1 and several 0s to the end of the message until the message length meets the 512-bit requirement. Additionally, a 64-bit binary number needs to be added to the end of the padded information to represent the original message length. Since the length is a 64-bit integer, it needs to be represented by two 32-bit integers, with the high-order bit first and the low-order bit last. The padded data is a multiple of 512. A 128-bit buffer is used to store the intermediate results, with a fixed initial value. The padded data is divided into multiple 512-bit sub-information, and each sub-information is processed. Processing involves performing pre-defined operations on the sub-information, such as permutation, addition, modulo operation, and bit shifting. The processed sub-information has a corresponding value in the buffer. These values ​​are then concatenated in order to form a 128-bit hash value, which is the ciphertext information.

[0076] Step S303: In the database, update the second timestamp associated with the user identifier to the current time point, and update the second encrypted information associated with the user identifier to the third encrypted information.

[0077] Step S304: Send the current time point to the loss reporting device so that the loss reporting device updates the first timestamp associated with the user identifier to the current time point.

[0078] After receiving the third encrypted information, the authentication device updates the second timestamp associated with the user identifier to the current time in the database, and also updates the second encrypted information associated with the user identifier to the third encrypted information. Additionally, the authentication device needs to send the current time to the loss reporting device, causing the loss reporting device to update the first timestamp associated with the user identifier to the current time.

[0079] It should be noted that if a user changes their user ID or password, the corresponding encrypted message also needs to be updated.

[0080] In this embodiment, after the authentication device completes the reporting of a lost user's information, it updates the timestamp and encrypted information of the reported user's information. Even if the user's reported information is leaked, it will not affect the user's subsequent reporting of lost information.

[0081] Reference Figure 4 , Figure 4 This is a flowchart illustrating the third embodiment of the information loss reporting method of this application. The information loss reporting method includes the following steps:

[0082] Step S401: Receive the user's lost card request sent by the terminal, and obtain the user's corresponding user identifier and first user password according to the lost card request.

[0083] In this embodiment, the execution entity is the loss reporting device. When a user needs to report a lost item, they send a loss reporting request to the loss reporting device via their terminal. The loss reporting device can be a physical device corresponding to the key management center. The loss reporting device is used to generate the user's private key and is responsible for encrypting and signing the information requested by the user to report the loss.

[0084] When a user registers for a debit card after reporting its loss, the financial institution will assign a corresponding user password and use the registration time as a timestamp. The user can use their mobile phone number, ID number, or email address as their identification during registration. After registration, the financial institution will send the user password to the user and send the timestamp and user identifier to the card reporting device for associated storage.

[0085] When a user reports a lost item, the request to the reporting device includes the user's identifier and password, which is defined as the first user password.

[0086] Step S402: Obtain the first timestamp associated with the user identifier and the user private key, and encrypt the first user password, user identifier and first timestamp to obtain the first ciphertext information.

[0087] The device encrypts the user identifier, the first user password, and the first timestamp to obtain the first ciphertext information. In addition, the device generates a user private key corresponding to the user who reported the loss, and the user private key is stored in association with the user identifier.

[0088] Step S403: Sign the first encrypted information using the user's private key to obtain the lost message.

[0089] Step S404: Send the lost / disappeared message to the authentication device. The lost / disappeared message is used by the authentication device to verify the user's identity.

[0090] The device that reports a lost item signs the first encrypted information using the user's private key to obtain a loss report message, which is then sent to the verification device. Additionally, the user's private key generated by the device that reports the lost item, along with the user identifier, is sent to the authentication device. That is, before receiving the loss report message from the device that reports the lost item, the authentication device receives the user identifier and the corresponding user private key from the device that reports the lost item, and stores the user identifier and user private key together.

[0091] The user's private key has both signing and verification functions. The authentication device obtains the managed user's private key based on the user identifier, and then uses the user's private key to sign and verify the lost message. After successful signature verification, the first encrypted information is obtained. The authentication device then decrypts the first encrypted information to obtain the first user password and the first timestamp.

[0092] After a user successfully registers, the device generates encrypted information based on the user's identifier, timestamp, and password, and stores the user's identifier, timestamp, password, and encrypted information in the database.

[0093] The authentication device retrieves a second user password, a second timestamp, and second encrypted information from the database based on the user identifier. The device compares the first and second user passwords for consistency, the first and second timestamps for consistency, and the first and second encrypted information for consistency. The comparison between the second and first encrypted information can be a comparison of their hash values; if the hash values ​​are the same, then the first and second encrypted information are identical.

[0094] When the first user password matches the second user password, the first timestamp matches the second timestamp, and the first encrypted information matches the second encrypted information, the authentication of the user who reported the loss is successful, and the authentication device sets the user's request to report the loss to a "lost" status. The user's request to report the loss is carried in the loss report request and is sent by the loss reporting device to the authentication device. The user's request to report the loss can be a bank card or a phone card. When the status of this information is "lost," the bank card or phone card is frozen and cannot be used. Furthermore, after setting the user's request to report the loss to a "lost" status, the authentication device sends a success message to the terminal associated with the user's identifier to notify the user that the loss report was successful.

[0095] In this embodiment, the loss reporting device sends the loss report message obtained by the user to the authentication device, so that the authentication device uses the user's private key to sign and verify the loss report message. This eliminates the need for the user to sign and verify the message based on the digital certificate in the token device, and also eliminates the need for the user to search for the token device to report the loss. This saves the time spent by the user searching for the token device to report the loss and improves the timeliness of information loss reporting.

[0096] Reference Figure 5 , Figure 5 This is the fourth embodiment of the information loss reporting method of this application. Based on the third embodiment, step S402 includes:

[0097] Step S501: The user identifier, the first user password, and the first timestamp are concatenated to obtain the concatenated information.

[0098] In this embodiment, the loss reporting device concatenates the first timestamp, the user identifier, and the first user password to obtain concatenated information, which is the string obtained by concatenating the corresponding characters of the above three.

[0099] Step S502: Divide the spliced ​​information into multiple groups of sub-information and perform preset calculations on each group of sub-information.

[0100] The lost item reporting device divides the spliced ​​information into multiple sub-information groups and performs preset calculations on each sub-information group. It should be noted that each sub-information group has the same amount of data. Therefore, the device needs to pad the spliced ​​information so that the padded data can be evenly divided into multiple sub-information groups.

[0101] The device concatenates the user identifier, the first user password, and the first timestamp to obtain the information to be processed, and then fills the information to be processed to obtain the concatenated information. The number of bits in the concatenated information is an integer multiple of a preset value, such as 512.

[0102] Step S503: Concatenate the pre-calculated sub-information to obtain the first ciphertext information.

[0103] The lost and found device can obtain the first encrypted information by splicing together the sub-information after the preset budget.

[0104] For example, the information to be processed is first padded. If the number of bits in the information to be processed is not a multiple of 512, it needs to be padded. Padding is done by adding a 1 and several 0s to the end of the information until the information length meets the 512-bit requirement. Additionally, a 64-bit binary number needs to be added to the end of the padded information to represent the original message length. Since the length is a 64-bit integer, it needs to be represented by two 32-bit integers, with the high-order bit first and the low-order bit last. The padded data is a multiple of 512. A 128-bit buffer is used to store the intermediate results, with a fixed initial value. The padded data is divided into multiple 512-bit sub-information, and each sub-information is processed. Processing involves performing preset operations on the sub-information, such as substitution, addition, modulo, and bit shifting. The processed sub-information has a corresponding value in the buffer. These values ​​are concatenated in a predetermined order to form a 128-bit hash value, which is the ciphertext information.

[0105] In this embodiment, the loss reporting device concatenates the user identifier, the first user password, and the first timestamp to obtain concatenated information, then divides the concatenated information into multiple groups of sub-information, performs preset calculations on each group of sub-information, and finally concatenates the sub-information after preset calculations to obtain the first encrypted information.

[0106] Reference Figure 6 , Figure 6The fifth embodiment of the information loss reporting method provided in this application, based on the third or fourth embodiment, includes step S402 as follows:

[0107] Step S601: Obtain the registration information of the user who reported the loss, and obtain the first timestamp and user identifier based on the registration information.

[0108] In this embodiment, after a user reports a lost item and successfully registers, the user will have corresponding registration information, including the user's identifier, first timestamp, and other information.

[0109] Step S602: Generate a random number and generate a public key based on the random number.

[0110] Step S603: Generate the user's private key based on the public key and the random number.

[0111] The loss reporting device also needs to generate a user private key associated with the user identifier. For example, the loss reporting system selects three cyclic groups G1, G2, and GT, where the order of G1, G2, and GT is a prime number N. P1 is a generator of G1, P2 is a generator of G2, and there exists a homomorphic mapping Ψ from G2 to G1 such that Ψ(P2) = P1. A bilinear pair e is a mapping from G1 × G2 to GT. The loss reporting device generates a random number ks ∈ [1, N-1] as the signature master private key and calculates the element P in G2. pub-s If [ks]P2 is used as the signature master public key, then the signature master key pair is (ks, P). pub-s (Where N, G2, and P2 are fixed values.) The loss reporting device generates a user's private key based on the public key and registration information.

[0112] For example, let hid be the function identifier; calculate t1 = H(ID||hid, q) + ks; calculate t2 = ks * t1 -1 modq; calculates D ID =t2*P1;D ID This refers to the user's private key.

[0113] Step S604: Associate and store the user's private key, user identifier, and first timestamp.

[0114] After generating the user's private key, the user's private key, user identifier, and first timestamp are associated and stored together. In addition, the loss reporting device also sends the user identifier and user's private key to the authentication device for associated storage.

[0115] In this embodiment, the device generates a random number and generates a public key based on the random number, thereby generating a user's private key based on the public key and the random number.

[0116] This application also provides an authentication device, referring to... Figure 7 The authentication device 700 includes:

[0117] The first receiving module 710 is used to receive the loss reporting message sent by the loss reporting device and determine the user identifier of the loss reporting user corresponding to the loss reporting message.

[0118] The verification module 720 is used to sign and verify the lost message using the user's private key associated with the user identifier to obtain the first ciphertext information, and to decrypt the first ciphertext information to obtain the first user password and the first timestamp.

[0119] The first acquisition module 730 is used to acquire the second user password, second timestamp, and second encrypted information associated with the user identifier from the database.

[0120] The setting module 740 is used to set the information requested by the user to be reported lost to a reported lost status when the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information.

[0121] In one embodiment, the authentication device 700 further includes:

[0122] The third acquisition module is used to acquire the current time point;

[0123] The encryption module is used to encrypt the current time point, user identifier, and second user password to obtain third ciphertext information;

[0124] The update module is used to update the second timestamp associated with the user identifier to the current time point in the database, and to update the second encrypted information associated with the user identifier to the third encrypted information.

[0125] The sending module is used to send the current time to the lost device so that the lost device can update the first timestamp associated with the user identifier to the current time.

[0126] In one embodiment, the authentication device 700 further includes:

[0127] The third receiving module is used to receive the user identifier and the corresponding user private key sent by the lost device;

[0128] The storage module is used to associate and store user identifiers and user private keys.

[0129] This application also provides a device for reporting a lost item, as described above. Figure 8 The loss reporting device 800 includes:

[0130] The second receiving module 810 is used to receive the loss reporting request sent by the user based on the terminal, and to obtain the user's corresponding user identifier and first user password according to the loss reporting request;

[0131] The second acquisition module 820 is used to acquire the first timestamp associated with the user identifier and the user private key, and to encrypt the first user password, user identifier and first timestamp to obtain the first ciphertext information;

[0132] The signature module 830 is used to sign the first ciphertext information using the user's private key to obtain the lost message;

[0133] The sending module 840 is used to send the lost and found message to the authentication device. The lost and found message is used by the authentication device to verify the user's identity.

[0134] In one embodiment, the second acquisition module 820 includes:

[0135] The first splicing unit splices the user identifier, the first user password, and the first timestamp to obtain spliced ​​information;

[0136] The processing unit is used to divide the spliced ​​information into multiple groups of sub-information and perform preset calculations on each group of sub-information;

[0137] The second splicing unit is used to splice the pre-calculated sub-information to obtain the first ciphertext information.

[0138] In one embodiment, the first splicing unit includes:

[0139] The splicing subunit is used to splice the user identifier, the first user password, and the first timestamp to obtain the information to be processed;

[0140] The filler sub-unit is used to fill the information to be processed to obtain the spliced ​​information. The number of bits in the spliced ​​information is an integer multiple of the preset value.

[0141] In one embodiment, the second acquisition module 820:

[0142] The acquisition unit is used to acquire the registration information of the user who reported the loss, and to obtain the first timestamp and user identifier based on the registration information;

[0143] The generation unit is used to generate random numbers and generate a public key based on the random numbers;

[0144] The generation unit is also used to generate a user's private key based on the public key and a random number;

[0145] The storage unit is used to associate and store the user's private key, user identifier, and first timestamp.

[0146] Figure 9 This is a hardware structure diagram of an authentication device / loss reporting device according to an exemplary embodiment.

[0147] The authentication device 900 / loss reporting device 900 may include: a processor 91, such as a CPU, a memory 92, and a transceiver 93. Those skilled in the art will understand that... Figure 9 The structure shown does not constitute a limitation on the authentication / loss reporting device and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. Memory 92 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0148] The processor 91 can call the computer program stored in the memory 92 or execute the computer execution instructions to complete all or part of the steps of the above-mentioned information loss reporting method.

[0149] Transceiver 93 is used to receive information sent by external devices and to send information to external devices.

[0150] An electronic device includes: a processor, and a memory communicatively connected to the processor;

[0151] The memory stores the instructions that the computer executes;

[0152] The processor executes computer execution instructions stored in memory to implement the information loss reporting method as described in any of the above embodiments.

[0153] A non-transitory computer-readable storage medium, wherein when the instructions (computer-executable instructions) in the storage medium are executed by the processor of an authentication device or a loss-reporting device, the authentication device is able to perform the aforementioned information loss reporting method, or the loss-reporting device is able to perform the aforementioned information loss reporting method.

[0154] A computer program product includes a computer program that, when executed by a processor of an authentication device, enables the authentication device to perform the aforementioned information loss reporting method.

[0155] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0156] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A method for reporting lost information, characterized in that, Applied to authentication devices, including: The system receives a loss reporting message sent by the loss reporting device and determines the user identifier of the user reporting the loss corresponding to the loss reporting message; wherein, the user private key and the first timestamp associated with the user identifier are generated and stored in association based on the registration information during the user registration stage, the registration information includes the user identifier and the first timestamp, and the user private key is generated based on a random number and a public key; the public key is generated based on the random number. The first ciphertext information is obtained by signing and verifying the lost message using the user's private key associated with the user identifier. The first ciphertext information is generated by encrypting the first user password, the user identifier, and the first timestamp. The first encrypted information is decrypted to obtain the first user password and the first timestamp; The second user password, second timestamp, and second encrypted information associated with the user identifier are retrieved from the database, wherein the second user password, second timestamp, and second encrypted information are stored during the user registration phase; When the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information, the information of the user requesting to report the loss is set to the lost status.

2. The method for reporting lost information according to claim 1, characterized in that, After the step of setting the information requested by the user to be reported lost to a reported lost status, the method further includes: Get the current time point; The current time point, the user identifier, and the second user password are encrypted to obtain the third ciphertext information; In the database, the second timestamp associated with the user identifier is updated to the current time point, and the second encrypted information associated with the user identifier is updated to the third encrypted information; The current time point is sent to the loss reporting device so that the loss reporting device updates the first timestamp associated with the user identifier to the current time point.

3. The method for reporting lost information according to claim 2, characterized in that, Before receiving the loss reporting message sent by the loss reporting device, the method further includes: Receive the user identifier and corresponding user private key sent by the loss reporting device; The user identifier and the user private key are stored together.

4. A method for reporting lost information, characterized in that, Applied to loss reporting devices, including: The system receives a loss reporting request sent by a user via a terminal, and obtains the user identifier and first user password corresponding to the user based on the loss reporting request; wherein, the user private key associated with the user identifier and the first timestamp are generated and stored in association based on the registration information during the user registration stage, the registration information includes the user identifier and the first timestamp, and the user private key is generated based on a random number and a public key, the public key being generated based on the random number; Obtain the first timestamp associated with the user identifier and the user's private key, and encrypt the first user password, the user identifier, and the first timestamp to obtain the first ciphertext information; The first encrypted information is signed using the user's private key to obtain a lost message; The lost message is sent to the authentication device, and the lost message is used by the authentication device to verify the user's identity.

5. The method for reporting lost information according to claim 4, characterized in that, The step of encrypting the first user password, the user identifier, and the first timestamp to obtain the first ciphertext information includes: The user identifier, the first user password, and the first timestamp are concatenated to obtain the concatenated information; The spliced ​​information is divided into multiple groups of sub-information, and a preset operation is performed on each group of sub-information; The first ciphertext information is obtained by concatenating the sub-information after the preset calculation.

6. The method for reporting lost information according to claim 5, characterized in that, The step of concatenating the user identifier, the first user password, and the first timestamp to obtain the concatenated information includes: The user identifier, the first user password, and the first timestamp are concatenated to obtain the information to be processed; The spliced ​​information is obtained by filling in the information to be processed, and the number of digits of the spliced ​​information is an integer multiple of a preset value.

7. An authentication device, characterized in that, include: The first receiving module is used to receive a loss reporting message sent by the loss reporting device and determine the user identifier of the user reporting the loss corresponding to the loss reporting message; wherein, the user private key associated with the user identifier and the first timestamp are generated and associated with the user registration information during the user registration stage, the registration information includes the user identifier and the first timestamp, the user private key is generated based on a random number and a public key; the public key is generated based on the random number; The verification module is used to sign and verify the lost message using the user's private key associated with the user identifier to obtain first ciphertext information, wherein the first ciphertext information is generated by encrypting the first user password, the user identifier, and the first timestamp; and the first ciphertext information is decrypted to obtain the first user password and the first timestamp. The first acquisition module is used to acquire the second user password, the second timestamp, and the second encrypted information associated with the user identifier from the database, wherein the second user password, the second timestamp, and the second encrypted information are stored during the user registration stage; The setting module is used to set the information requested by the user to be reported lost to a reported lost status when the first user password is the same as the second user password, the first timestamp is the same as the second timestamp, and the first encrypted information is the same as the second encrypted information.

8. A device for reporting lost items, characterized in that, include: The second receiving module is used to receive a loss reporting request sent by the user based on the terminal, and to obtain the user identifier and the first user password corresponding to the user according to the loss reporting request; wherein, the user private key associated with the user identifier and the first timestamp are generated and associated with the user registration information during the user registration stage, the registration information includes the user identifier and the first timestamp, and the user private key is generated based on a random number and a public key, the public key being generated based on the random number; The second acquisition module is used to acquire the first timestamp associated with the user identifier and the user private key, and to encrypt the first user password, the user identifier and the first timestamp to obtain the first ciphertext information; The signature module is used to sign the first ciphertext information using the user's private key to obtain the loss report message; The sending module is used to send the lost message to the authentication device, and the lost message is used by the authentication device to verify the identity of the user.

9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the information loss reporting method as described in any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the information loss reporting method as described in any one of claims 1-6.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the information loss reporting method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Communication system and method based on certificateless signcryption in intelligent medical environment

    CN109981290A

  • SM2 homomorphic signature method for private key multiplication encryption based on SOTP technology

    CN110971411A