Web certificate generation, sending, verification, acquisition method, device, equipment and medium
By introducing the CMID platform to replace the CTID platform for the generation and verification of online certificates, the problem of insufficient fault tolerance in the existing technology is solved, and the reliability and stability of the generation and verification of online certificates are achieved when the CTID platform is abnormal.
Patent Information
- Application Number
- CN202310585683.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-23
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2043-05-23
AI Technical Summary
In existing technologies, the generation and verification of online certificates rely entirely on the CTID platform, resulting in poor fault tolerance. When the CTID platform fails, the generation and verification process of online certificates cannot continue and must wait for recovery.
The CMID platform is introduced to replace the CTID platform for generating and verifying online certificates. It generates online certificates by obtaining the identity information of the target user and takes over the issuance and verification tasks of online certificates when the CTID platform is abnormal.
This improves the system's fault tolerance, ensuring that the online certificate generation and verification process can still proceed normally when the CTID platform malfunctions, thus enhancing the system's reliability and stability.
Smart Images

Figure CN116566701B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet technology, and in particular to a method, apparatus, computing device, and computer-readable storage medium for generating, sending, obtaining, and verifying Internet certificates. Background Technology
[0002] "Cyber ID," also known as a cyber identity card or cyberspace trusted identifier, or CTID for short, is an electronic encrypted document independently issued by local public security organs based on the Ministry of Public Security's "Internet + Trusted Identity Authentication Platform" to promote social governance and facilitate police services.
[0003] Currently, the generation and verification of online ID cards are handled by the CTID platform launched by the First Research Institute of the Ministry of Public Security. Therefore, when a user needs to apply for or verify an online ID card, regardless of the client through which the user initiates the application or verification request, the sole and ultimate recipient of the request can only be the CTID platform, in order to trigger the CTID platform to generate or verify the online ID card.
[0004] The problem with existing technologies is that relying solely on the CTID platform to generate or verify e-ID certificates results in poor fault tolerance. For example, when the CTID platform experiences glitches or malfunctions, it can only passively wait for the platform to recover before generating or verifying e-ID certificates. Summary of the Invention
[0005] This invention provides a method and apparatus for generating online certificates, in order to solve the problem of poor fault tolerance in the related technologies that rely solely on the CTID platform for generating online certificates.
[0006] This invention also provides a method and apparatus for verifying online certificates, in order to solve the problem of poor fault tolerance in the related technologies that rely solely on the CTID platform for online certificate verification.
[0007] This invention also provides a method for obtaining a network certificate, a method for sending a network certificate, a method for sending information, an apparatus, a computing device, and a computer-readable storage medium.
[0008] The embodiments of the present invention adopt the following technical solutions:
[0009] A method for generating a network ID card, applied to a CMID (Mobile Identity Registry) platform, the method comprising:
[0010] When the condition for the CMID platform to replace the CTID platform in issuing network certificates is triggered, the CMID platform obtains the identity information of the target user.
[0011] Based on the identity information, generate the target user's online ID.
[0012] A method for sending a network certificate, applied to a CMID (Mobile Identity Registry) platform, the method comprising:
[0013] The system receives verification information sent by the target software to the CMID platform triggered by the requester for the online certificate; the verification information includes the requester's identity information provided by the requester.
[0014] Verify the verification information;
[0015] If the verification information passes the verification, the demander's identity information is encrypted to obtain encrypted demander identity information.
[0016] Send the encrypted requester's identity information to the target software to trigger the target software to send the encrypted requester's identity information to the network certificate requester;
[0017] Receive the encrypted requester's identity information sent by the requester of the online certificate;
[0018] The encrypted requester's identity information is then subjected to decryption processing corresponding to the encryption process.
[0019] If the decryption process successfully decrypts the encrypted requester's identity information, then the network certificate is sent.
[0020] A method for obtaining an online ID card, the method comprising:
[0021] Obtain the identity information of the requester;
[0022] Send the demander's identity information to the target software to trigger the target software to execute: after generating verification information based on the demander's identity information, send the verification information to the Network Mobile Identity (CMID) platform;
[0023] The system receives encrypted requester identity information sent by the target software; the encrypted requester identity information is obtained by the CMID platform after the verification information has been verified and then encrypted.
[0024] The encrypted requester's identity information is sent to the CMID platform to trigger the CMID platform to execute: after successfully decrypting the encrypted requester's identity information, the network certificate requested by the requester is sent.
[0025] A method for sending information, the method comprising:
[0026] Receive the identity information of the party requesting the online certificate;
[0027] Based on the identity information of the demander, verification information is generated;
[0028] Send the verification information to the CMID (Mobile Identity Provider) platform;
[0029] Receive the encrypted requester identity information sent by the CMID platform after the verification information has been verified.
[0030] The identity information of the party requesting the encryption is sent to the party requesting the online certificate.
[0031] A network ID verification method, applied to a CMID (Mobile Identity Registry) platform, the method comprising:
[0032] When the condition for the CMID platform to replace the CTID platform in verifying network credentials is triggered, the CMID platform obtains the network credentials of the target user.
[0033] The online certificate is verified.
[0034] An apparatus for a network mobile identity (CMID) platform, characterized in that the apparatus comprises:
[0035] The acquisition unit is used to acquire the identity information of the target user when the condition of the CMID platform replacing the CTID platform for issuing network certificates is triggered.
[0036] The generation unit is used to generate the target user's online ID based on the identity information.
[0037] An apparatus for a Network Mobile Identity (CMID) platform, the apparatus comprising:
[0038] The acquisition unit is used to acquire the target user's network certificate when the condition of the network certificate being verified by the CMID platform instead of the CTID platform in cyberspace is triggered.
[0039] The verification unit is used to verify the network certificate.
[0040] An apparatus for a Network Mobile Identity (CMID) platform, the apparatus comprising:
[0041] The verification information receiving unit is used to receive verification information sent by the target software triggered by the online certificate requester to the CMID platform; the verification information includes the requester's identity information provided by the online certificate requester.
[0042] A verification unit is used to verify the verification information;
[0043] An encryption unit is used to encrypt the demander's identity information if the verification information passes the verification, so as to obtain encrypted demander identity information.
[0044] An identity information sending unit is used to send the encrypted requester's identity information to the target software, thereby triggering the target software to send the encrypted requester's identity information to the network certificate requester.
[0045] An identity information receiving unit is used to receive the encrypted identity information of the network certificate requester sent by the network certificate requester.
[0046] The decryption unit is used to perform decryption processing on the encrypted requester's identity information corresponding to the encryption processing;
[0047] The network certificate sending unit is used to send the network certificate requested by the requesting party if the decryption process can successfully decrypt the encrypted requesting party's identity information.
[0048] A device for obtaining a network ID card, the device comprising:
[0049] The identity information acquisition unit is used to acquire the identity information of the demander;
[0050] An identity information sending unit is used to send the demander's identity information to the target software to trigger the target software to execute: after generating verification information based on the demander's identity information, send the verification information to the Network Mobile Identity Identifier (CMID) platform;
[0051] An encrypted information receiving unit is used to receive encrypted requester identity information sent by the target software; the encrypted requester identity information is obtained by the CMID platform after the verification information is verified and the requester identity information is encrypted.
[0052] The encrypted requester's identity information is sent to the CMID platform to trigger the CMID platform to execute: after successfully decrypting the encrypted requester's identity information, send the network certificate.
[0053] An information transmission device, the device comprising:
[0054] The identity information receiving unit is used to receive the identity information of the requester sent by the requester of the online certificate;
[0055] The verification information generation unit is used to generate verification information based on the identity information of the requester;
[0056] The verification information sending unit is used to send the verification information to the Network Mobile Identity (CMID) platform.
[0057] An encrypted information receiving unit is used to receive encrypted requester identity information sent by the CMID platform after the verification information has been verified.
[0058] An encrypted information sending unit is used to send the encrypted requester's identity information to the network certificate requester.
[0059] A computing device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of any of the methods described above.
[0060] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described above.
[0061] The at least one technical solution provided by the embodiments of the present invention can achieve the following technical effects:
[0062] In this embodiment of the invention, when the condition for the CMID platform to replace the CTID platform in issuing online certificates is triggered, the CMID platform can obtain the identity information of the target user and generate the target user's online certificate based on the identity information. Thus, it no longer relies solely on the CTID platform to generate online certificates, but can rely on the CMID platform to issue online certificates when it is necessary to replace the CTID platform. Therefore, it can effectively solve the problem of poor "fault tolerance" in the existing technology. Attached Figure Description
[0063] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0064] Figure 1a This is a flowchart illustrating a method for generating online certificates according to an embodiment of the present invention.
[0065] Figure 1b This is a schematic diagram of the generated online certificate being displayed in one embodiment of the present invention;
[0066] Figure 2 This is one of the scenario illustrations of the online certificate generation method proposed in an embodiment of the present invention;
[0067] Figure 3 This is a second scenario illustration of the online certificate generation method proposed in one embodiment of the present invention;
[0068] Figure 4 This is a third scenario illustration of the online certificate generation method proposed in one embodiment of the present invention;
[0069] Figure 5 This is a fourth scenario illustration of the online certificate generation method proposed in one embodiment of the present invention;
[0070] Figure 6 This is a flowchart illustrating a network certificate verification method proposed in one embodiment of the present invention;
[0071] Figure 7 This is one of the scenario illustrations of the online certificate generation method proposed in an embodiment of the present invention;
[0072] Figure 8 This is a second scenario illustration of the online certificate generation method proposed in one embodiment of the present invention;
[0073] Figure 9 A schematic diagram of the unit composition of a CMID platform device 900 provided in an embodiment of the present invention;
[0074] Figure 10 A schematic diagram of the unit composition of a CMID platform device 1000 provided in an embodiment of the present invention;
[0075] Figure 11 This is a schematic diagram of the hardware structure of a computing device provided in one embodiment of the present invention. Detailed Implementation
[0076] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0077] Under current technology, when a user needs to apply for or verify an e-license, regardless of the client through which the user initiates the application or verification request, the sole and ultimate recipient of the request can only be the CTID platform, in order to trigger the CTID platform to generate or verify the e-license. Therefore, when the CTID platform experiences lag, malfunctions, or other anomalies, it can only passively wait for it to recover before generating or verifying the e-license. Thus, current technology suffers from poor fault tolerance in e-license generation and verification.
[0078] In order to effectively solve the problems of the prior art, the solution provided by the embodiments of the present invention uses the CMID (CyberMobile identity) platform to solve the problem of poor fault tolerance in the related technologies that rely solely on the CTID platform for generating network certificates.
[0079] The technical solutions provided by the various embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0080] Please see Figure 1a Figure 1 is a flowchart illustrating the online certificate generation method proposed in this embodiment of the invention, applied to the CMID platform. As shown in Figure 1, the method includes the following steps:
[0081] Step 101: When the condition for the CMID platform to issue online certificates instead of the CTID platform is triggered, the CMID platform obtains the target user's identity information;
[0082] The target users can refer to users who are waiting to apply for an online certificate.
[0083] The target user's identity information may include, but is not limited to, one or more of the following:
[0084] The target user's ID number;
[0085] The target user's biometric characteristics—such as, but not limited to, one or more of the target user's facial features, fingerprint features, palm print features, voiceprint features, and iris features.
[0086] Based on identity information, the target user can also refer to the user to whom the identity information obtained by the CMID platform belongs.
[0087] In one alternative implementation, the target user's identity information can be sent directly to the CMID platform by the user terminal (such as a mobile phone) used by the target user.
[0088] In one alternative implementation, the target user's identity information can be sent first to the target recipient by the user terminal (such as a mobile phone) used by the target user, and then sent by the target recipient to the CMID platform. The target recipient can be, for example, a server or service platform, or other terminals used by the target user, etc.
[0089] Step 102: Generate the target user's online ID based on the identity information.
[0090] In this embodiment of the invention, the "network ID" refers to a network identity card, also known as a cyberspace trusted identity, or CTID, which is an electronic encrypted file.
[0091] In this embodiment of the invention, in step 102, an electronic encrypted file containing part or all of the target user's identity information can be generated based on the target user's identity information, according to the file format of the online certificate and a pre-set encryption algorithm, and used as the target user's online certificate.
[0092] For example, in one alternative implementation, an electronic encrypted file containing the target user's ID card number can be generated as the target user's online ID card.
[0093] In one alternative implementation, an electronically encrypted file containing part (or all) of the target user's identity information and auxiliary information can be used as the target user's online ID, based on the target user's identity information and the obtained auxiliary information.
[0094] The auxiliary information includes, but is not limited to, one or more of the following: the network certificate number, the target user's user number, the network certificate validity period, the identifier of the network certificate issuing authority, the identifier of the network certificate application authority, the information of the network certificate application terminal device, the network certificate processing time, the random number, the check digit, and the network certificate background image, etc.
[0095] The identifier of the online certificate issuing authority may refer to the identifier of the CMID platform; the identifier of the online certificate application authority may refer to the identifier of the organization that publishes the application software (such as an instant messaging software) used by the user to send the identity information (such as the company that develops, publishes or sells the instant messaging software).
[0096] The auxiliary information mentioned above—such as the identifier of the issuing authority of the online certificate and the background image of the online certificate—can be pre-stored in the CMID platform; or it can be sent to the CMID platform by the provider of the auxiliary information—for example, the application software that sends the identity information (this application software can be an application or SDK certified by the CMID platform, collectively referred to as the target software in this application embodiment) can send the identifier of the online certificate application authority to the CMID platform; or it can be generated in real time by the CMID platform using an algorithm—for example, the CMID platform can calculate the validity period of the online certificate according to the algorithm for the validity period of the online certificate.
[0097] In one optional implementation, in step 102, the CMID platform can use the same method used by the CTID platform to generate the network certificate for the target user.
[0098] In one alternative implementation, the generated online ID card, when displayed, can be as follows: Figure 1b As shown.
[0099] In this embodiment of the invention, the CMID platform provides the function of issuing online certificates to users. Therefore, the CMID platform can replace the CTID platform in issuing online certificates. When the conditions for the CMID platform to issue online certificates in place of the CTID platform are triggered, the CMID platform can obtain the identity information of the target user for whom the online certificate needs to be issued, and issue the online certificate to the target user based on the target user's identity information.
[0100] Since it no longer relies solely on CTID as the sole platform for generating online certificates, but can instead use CMID to issue online certificates when the CMID platform is needed to replace CTID, it effectively solves the problem of poor fault tolerance in existing technologies.
[0101] In one alternative implementation, when the CTID platform is in an abnormal working state, such as when the CTID platform fails to respond to the target user's request for issuing an e-certificate for a long time or when the CTID platform malfunctions, it can be determined that the conditions for the CMID platform to issue e-certificates on behalf of the CTID platform have been triggered. At this time, the CMID platform can obtain the target user's identity information to generate the target user's e-certificate.
[0102] In one optional implementation, the CMID or a computing device that has established a communication connection with the CMID platform can monitor the operational status of the CTID platform. For example, the CMID platform (or the computing device) can obtain data representing the operational status of the CTID platform by establishing a heartbeat connection with the CTID platform. If the heartbeat connection is broken, it can be determined that the CTID platform is malfunctioning; or, if the data indicates that the CTID platform is malfunctioning, it can be determined that the CTID platform is malfunctioning. If the computing device determines that the CTID platform is malfunctioning, it can notify the CMID platform of the malfunction.
[0103] Of course, in this embodiment of the invention, other related technologies can also be used to determine whether the working status of the CTID platform is abnormal.
[0104] In one alternative implementation, when the digital identity cloud platform integrated with the CMID platform determines that the target user needs to apply for an online certificate based on the business request received from the target user, it can determine that the condition for the CMID platform to issue the online certificate on behalf of the CTID platform has been triggered. At this time, the CMID platform can obtain the target user's identity information to generate the target user's online certificate.
[0105] In one optional implementation, when the CMID platform receives a request for an online certificate from a target user, or when the CMID platform determines that the target user needs to apply for an online certificate based on the received business request from the target user, it can determine that the condition for the CMID platform to issue an online certificate on behalf of the CTID platform has been triggered. At this time, the CMID platform can obtain the target user's identity information to generate the target user's online certificate.
[0106] When a request for an online certificate is received directly from the target user to the CMID platform, it can be determined that the target user wants to apply for an online certificate issued by the CMID platform. Therefore, it can be determined that the conditions for the CMID platform to issue an online certificate instead of the CTID platform have been triggered.
[0107] In this embodiment of the invention, after obtaining the target user's identity information, the CMID platform can complete the real-name authentication of the target user based on facial recognition; alternatively, it can complete the real-name authentication based on SMS and facial recognition. After completing the real-name authentication of the target user, an online ID for the target user is generated based on the target user's identity information.
[0108] In one alternative implementation, when using facial recognition-based real-name authentication to complete the real-name authentication of a target user, the CMID platform can obtain the target user's facial image and then call the identity authentication interface provided by an authoritative data source. This interface will then perform real-name authentication on the target user based on the facial image.
[0109] In one optional implementation, when using SMS and facial recognition-based real-name authentication to complete the real-name authentication of a target user, the CMID platform can first determine whether the target user is applying for an online ID card for the first time. If so, provided the CMID platform obtains the target user's mobile phone number, it can send an SMS verification code to the corresponding mobile phone. If the CMID platform subsequently receives the SMS verification code from that mobile phone and verifies it successfully, the CMID platform obtains the target user's facial image and then calls the identity authentication interface provided by the authoritative data source. This interface performs real-name authentication on the target user based on the facial image. If the target user is not applying for an online ID card for the first time, the CMID platform can obtain the target user's facial image and then call the identity authentication interface provided by the authoritative data source. This interface performs real-name authentication on the target user based on the facial image.
[0110] In one example, the above online certificate application process can be as follows: Figure 2 As shown:
[0111] Step 201: The user sends a facial image and identity information (such as an ID card number) to the CMID platform through the target software installed on their mobile phone via the digital identity cloud platform integrated with the CMID platform.
[0112] Step 202: The CMID platform determines whether the user is applying for an online license for the first time. For example, it can determine whether the user has selected the "online license not activated" or "online license cancelled" option on the target software, thereby triggering the target software to send an initial activation marker for judgment. If the option is selected, the target software is triggered to send an initial activation marker, indicating that it is the first application. If the judgment result is no, proceed to step 203; if the judgment result is yes, proceed to step 206.
[0113] Whether a user is applying for an online ID card for the first time can be determined by the digital identity cloud platform. If the determination is yes, the digital identity cloud platform can notify the CMID platform to send an online ID card application SMS.
[0114] Step 203: The CMID platform calls the facial recognition authentication capability provided by an authoritative data source (such as Megvii) to perform facial authentication on the user based on the user's facial image and identity information;
[0115] Step 204: When face authentication is successful, the CMID platform generates an online certificate and encrypts the online certificate;
[0116] Step 205: The CMID platform will issue the encrypted network certificate to the user;
[0117] Step 206: The CMID platform receives a notification from the Digital Identity Cloud Platform regarding the issuance of an online certificate application via SMS.
[0118] Step 207: The CMID platform returns the SMS serial number to the digital identity cloud platform and sends an SMS verification code to the user;
[0119] The SMS serial number, the sent facial image, and the identity information are stored in the CMID platform's cache.
[0120] Step 208: The user sends an SMS verification code to the digital identity cloud platform;
[0121] Step 209: The digital identity cloud platform sends the SMS verification code and the SMS serial number to the CMID platform;
[0122] Step 210: The CMID platform verifies the SMS verification code. After the verification is successful, it retrieves the face image and identity information corresponding to the SMS serial number from the cache. It then calls the face recognition capability provided by the authoritative data source to perform active authentication based on the face image and identity information retrieved from the cache. After the authentication is successful, it generates an online certificate based on the identity information and encrypts the online certificate.
[0123] Step 211: The CMID platform distributes the encrypted online ID to the user via the digital identity cloud platform.
[0124] In one optional implementation, when generating a target user's online ID based on identity information, a virtual ID to be encrypted can be generated based on the target user's identity information and auxiliary information for the online ID application. Then, the virtual ID to be encrypted is obtained, resulting in an encrypted virtual ID. In other words, the generated virtual ID can be an encrypted version based on the target user's identity information and auxiliary information for the online ID application. Because an encrypted virtual ID is generated, its security is guaranteed.
[0125] In one optional implementation, when generating the network certificate to be encrypted based on identity information and auxiliary information, a unique identifier for the target user with the target field length can be generated based on the identity information; then, the network certificate to be encrypted can be generated based on the unique identifier for the target user and auxiliary information.
[0126] The target field length is determined based on the size of the storage space reserved in the user terminal's super SIM card for storing the target user's unique identifier. Specifically, the target field length does not exceed the maximum field length that the storage space can support.
[0127] In this embodiment of the invention, the reason for determining the target field length of the target user unique identifier based on the size of the storage space reserved in the super SIM card of the user terminal for storing the target user unique identifier is that in some optional implementations, the digital identity cloud platform has the need to send the target user unique identifier generated by the CMID platform to the user terminal so that the user terminal can write the target user unique identifier into the super SIM card of the user terminal.
[0128] By writing the target user's unique identifier into the user terminal's super SIM card, when the user applies for an e-certificate again, the user terminal (such as the target software installed on the user terminal) can directly obtain the target user's unique identifier from the super SIM card and provide it to the CMID platform. This avoids the CMID platform repeatedly generating the target user's unique identifier, which would lead to resource consumption, and can also improve the generation efficiency of e-certificates.
[0129] When generating a unique identifier for a target user with the target field length based on identity information, a digest algorithm can be used to calculate a digest of the identity information to obtain an initial unique identifier for the target field length. Then, it is determined whether the initial unique identifier is globally unique. If it is globally unique, the initial unique identifier is determined as the unique identifier for the target user. If it is not globally unique, the process is repeated: the digest algorithm is used to calculate a digest of the concatenated identity information to obtain an updated initial unique identifier for the target field length, until the updated initial unique identifier for the target field length is globally unique. At this point, the loop ends, and the globally unique initial unique identifier is determined as the unique identifier for the target user.
[0130] Specifically, when using a digest algorithm to calculate the digest of identity information, the SM3 digest algorithm can be used to calculate the digest of user identity information, and the length of the calculated digest can be fixed at 64 bits. If the generated user unique identifier is not unique, for example, if duplicates are found after checking with a Bloom filter, the identity information is concatenated with a numeric sequence number and recalculated. The numeric sequence number defaults to 1 and increments by 1 after each recalculation until a globally unique user unique identifier is generated.
[0131] In one example, the user's unique identifier and the organization number of the CMID platform's partner organization (i.e., the online certificate application organization) are primarily used to ensure uniqueness among users. This ensures that online certificates applied for by the same user on different organization platforms are not interchangeable, and that an online certificate applied for on a particular platform can only be used on that platform. This prevents platform A from leaking user online certificate information, which could lead to insecurity in platform B's online certificate authentication service. The organization number of the CMID platform's partner organization can be 16 digits.
[0132] The generation time of the e-certificate determines the application date, facilitating the direct determination of the e-certificate's validity period during the authentication process. The generation time value can be 8 digits.
[0133] The serial number generated by the e-ID ensures that multiple applications by the same user result in different e-IDs. Each application provides unique e-ID information, guaranteeing the functionality of the lost e-ID reporting system. Users only need to reapply for an e-ID; previous e-IDs become invalid, and only the most recently applied e-ID is valid. The serial number can be up to 10 digits.
[0134] Random numbers can prevent forgery attacks on online ID information, preventing criminals from forging user online IDs after understanding their structure. The value of the random number can be 6 digits.
[0135] The checksum is used to verify whether the online certificate string is counterfeit. It uses the CMID platform's proprietary rules to verify the online certificate information and generate verification information. The checksum value can be 8 bits.
[0136] The hash value of the encrypted user device information (such as the information of the terminal device used to apply for the online certificate) can be used to verify the device used for the online certificate each time the information is used. If the device information used for the online certificate application is inconsistent with the device information obtained when using the online certificate (e.g., an online certificate applied for on phone A cannot be used on phone B, and a new online certificate needs to be applied for on phone B if you want to use it), then its use will be restricted to prevent the theft of online certificate information due to reasons such as leakage of user-bound account login information. The hash value of the encrypted user device information can be a 64-bit hash value obtained by encrypting it using the SM3 algorithm.
[0137] As can be seen from the above, the embodiments of the present invention can consider the network certificate generation process from multiple dimensions, thereby meeting the business needs of multiple scenarios.
[0138] In one alternative implementation, the process of encrypting the network ID to be encrypted to obtain the encrypted network ID can be implemented as follows:
[0139] In the case where saving the target user's user ID to the CMID platform is prohibited, the user ID is used as the interface parameter when calling the encryption machine. The encryption machine is then called to execute: using the user ID as the dispersion factor of the encryption algorithm to encrypt the network certificate to be encrypted, thereby obtaining the encrypted network certificate.
[0140] The user ID can be user-defined. This user ID can be sent to the CMID platform by the user through the target software, for example.
[0141] After obtaining the e-certificate document based on the target user's identity information and the auxiliary information for applying for the e-certificate, in order to ensure the security of the e-certificate being released externally, the CMID platform can encrypt the e-certificate document using the SM4 algorithm through a dedicated encryption machine. The key is stored in the encryption machine and is dedicated to this purpose. The user's user number is used as a dispersion factor. Different users have different dispersion factors. The dispersion factor is transmitted to the CMID platform as an interface parameter when the user device applies for the e-certificate. Using the dispersion factor can better ensure the security of the e-certificate.
[0142] The encryption process for generating online certificates requires a dispersion factor, but the CMID platform does not store the user ID that serves as this dispersion factor; only the user's device has the authority to generate or use it. When the encrypted online certificate stored in the CMID platform is leaked, it cannot be decrypted because the dispersion factor is unknown. Therefore, even CMID insiders cannot impersonate and use the online certificate. This ensures that user online certificate information meets security requirements at every stage, including storage, encryption, and use.
[0143] In this embodiment of the invention, after the encryption machine is invoked to encrypt the network certificate text, the network certificate text can be converted into a ciphertext of network certificate in base64 format with a length of 256 strings, and the ciphertext of network certificate can be stored.
[0144] Because this invention can invoke an encryption machine to encrypt the target user's ID as a dispersion factor for the online certificate to be encrypted, and the dispersion factor is known only to the user, even if the online certificate generation rules are leaked, user rights can still be securely protected, preventing unauthorized possession of the certificate. This invention provides certain safeguards for online certificate security, such as against external credential stuffing attacks, leakage of internal key online certificate information, and management of online certificate device information and related device information.
[0145] In one example, the process of calling the encryption machine to encrypt the network certificate can be as follows: Figure 3 As shown:
[0146] Step 301: The user sends an e-certificate application to the CMID platform; the e-certificate application carries the user's identity information, encrypted information of the device used by the user, and the user's ID number;
[0147] Step 302: The CMID platform decrypts the device information used by the user and verifies the device information after decryption.
[0148] Step 303: After the device verification is successful, the CMID platform generates a unique user identifier and uses the SM3 algorithm to encrypt and save the unique user identifier.
[0149] Step 304: The CMID platform generates a network certificate;
[0150] Step 305: The CMID platform uses the user's ID as a dispersion factor and calls the encryption machine to encrypt the network proof text.
[0151] Step 306: The CMID platform receives the encrypted network certificate sent by the encryption machine.
[0152] As shown in the above process, when applying for a network ID card, users need user information (ID card, name, and photo), network ID card application device information, and a user ID (a unique user ID defined by the user, not publicly available, used as a distribution factor). The user information is used for network ID card generation after the applicant's identity is verified. The network ID card application device information (mobile device number or unique SIM card identifier, etc.) is used to prevent unauthorized login and theft of the network ID card if the user's account password is leaked. The user ID is defined by the user and used as a distribution factor for encryption. CMID does not store the user ID at the time of network ID card activation. When a user uses the network ID card, this user ID is required as a distribution factor for decryption on the encryption device. Only after decryption can the user's network ID information be obtained normally. From a security perspective, this serves to isolate the network ID encryption and decryption keys, ensuring that each user has a unique key for each ID card. The purpose of CMID not storing the user ID is to protect the user's network ID information and prevent forgery attacks that could occur if the user ID is leaked.
[0153] Because CMID does not store the dispersion factor, but uploads it when the applicant applies for the online certificate, the security of the online certificate can be guaranteed even if the rules for generating the online certificate are leaked. Since the use of the online certificate requires the dispersion factor, this avoids the leakage of the online certificate information in the information database, which could lead to information security issues.
[0154] In this embodiment of the invention, after the e-certificate is generated on the CMID platform, the user can be notified that the e-certificate application was successful, so as to remind the user to download the e-certificate.
[0155] In this embodiment of the invention, the CMID platform can also provide partners (i.e., partner organizations) with target software authorized for use by the CMID platform. The target software can be an application or an SDK.
[0156] Based on the same inventive concept, embodiments of the present invention provide an information sending method that can be applied to target software to assist the CMID platform in verifying the legitimate identity of the party requesting the online certificate in scenarios such as when the party requesting the online certificate requests to obtain the user's online certificate.
[0157] This information sending method may include the following steps 1 through 5:
[0158] Step 1: Receive the identity information of the party requesting the online certificate;
[0159] The party requesting the online certificate may be, for example, an application (APP) of a partner organization.
[0160] In one optional implementation, the identity information of the requester may include, but is not limited to, one or more of the following: the device information of the requester of the online certificate—for example, if the requester of the online certificate is an application of a partner organization, then the device information may be the device identifier of the user terminal on which the application of the partner organization is installed; the organizational information of the requester of the online certificate—for example, if the requester of the online certificate is an application of a partner organization, then the device information may be the identifier of the partner organization.
[0161] The application from the collaborating organization and the target software can be installed on the same user terminal or on different user terminals.
[0162] Step 2: Generate verification information based on the client's identity information;
[0163] In one optional implementation, the target software can encrypt the requester's identity information based on the encryption key allocated by the CMID platform, obtaining encrypted requester identity information, which can then be used as verification information. The encryption key can be pre-allocated to the target software by the CMID platform—for example, the CMID platform can periodically generate new encryption keys and send them to the target software.
[0164] In a specific example, the encryption key may be the encryption key used by the SM4 encryption algorithm; encrypting the requester's identity information may be done by encrypting the requester's identity information using the SM4 encryption algorithm.
[0165] In an optional implementation, to further ensure information security, the target software may perform step 2 in the following manner:
[0166] Based on the encryption key allocated by the CMID platform, the identity information of the requester is encrypted to obtain the encrypted identity information of the requester (which can be referred to as the first encrypted identity information of the requester).
[0167] Based on the private key allocated to the target software by the CMID platform (such as the private key of the SM2 encryption algorithm), the obtained encryption requester identity information is signed to obtain the signed encryption requester identity information.
[0168] Based on the salt provided by the party requesting the online certificate, the obtained encrypted party identity information is salted to obtain salted encrypted party identity information, which is used as verification information.
[0169] Step 3: Send verification information to the CMID platform;
[0170] After receiving the verification information, the CMID platform verifies the information.
[0171] In one optional implementation, if the verification information received by the CMID platform is salted and encrypted requester identity information, then the CMID platform can generate the second encrypted requester identity information in the following manner:
[0172] The verification information is verified by pre-storing a salt corresponding to the requester and a public key corresponding to the private key; the salt mentioned here may be pre-sent by the requester to the CMID platform for storage.
[0173] If the signature verification is successful, the encrypted requester's identity information obtained by verifying the signature of the verification information will be decrypted based on the pre-stored encryption key—for example, the encryption key used by the SM4 encryption algorithm.
[0174] If decryption is successful, the verification information is deemed to have passed verification; if decryption fails, the verification information is deemed to have failed verification.
[0175] If the verification passes, the CMID platform can generate new encrypted requester identity information (which can be referred to as second encrypted requester identity information) according to a pre-set encryption algorithm. This encryption algorithm can be, for example, the SM4 encryption algorithm.
[0176] Step 4: Receive the encrypted requester identity information (second encrypted requester identity information) sent by the CMID platform after the verification information has been verified.
[0177] Step 5: Send the encrypted client identity information sent by the CMID platform to the client requesting the online certificate.
[0178] Subsequently, based on the received encrypted identity information, the party requesting the e-certificate can send the encrypted identity information to the CMID platform to trigger the CMID platform to execute the following: after successfully decrypting the encrypted identity information, send the e-certificate requested by the party.
[0179] Of course, if the CMID platform cannot successfully decrypt the encrypted identity information of the requester, the CMID platform will not send the online certificate to avoid the risk of information leakage.
[0180] By using steps 1 to 5 above, the target software can assist the CMID platform in verifying the legitimate identity of the party requesting the online certificate in scenarios such as when the party requesting the online certificate requests to obtain the user's online certificate.
[0181] Based on the same inventive concept, this invention provides a method for sending a network certificate, which can be applied to a CMID platform to send the network certificate in scenarios such as when a network certificate requester requests to obtain a user's network certificate.
[0182] The method includes the following steps a to g:
[0183] Step a: Receive verification information sent by the target software to the CMID platform triggered by the online certificate requester; the verification information includes the requester's identity information provided by the online certificate requester.
[0184] In an alternative implementation, the verification information can be generated in the manner described in step 2 above, which will not be repeated here.
[0185] Step b: Verify the verification information;
[0186] Step c: If the verification information passes, the requester's identity information is encrypted to obtain encrypted requester identity information;
[0187] For details on how to implement steps b and c, please refer to the explanation of step 3 above; they will not be repeated here.
[0188] Step d: Send encrypted requester identity information to the target software to trigger the target software to send encrypted requester identity information to the network certificate requester;
[0189] Step e: Receive the encrypted identity information of the requester sent by the requester of the online certificate;
[0190] Step f: Perform decryption processing on the encrypted requester's identity information, corresponding to the encryption processing described in step c;
[0191] Step g: If the decryption process can successfully decrypt the encrypted identity information of the requester, then send the online certificate; if the decryption process cannot successfully decrypt the encrypted identity information of the requester, then do not send the online certificate.
[0192] In one alternative implementation, the CMID platform sends the network certificate, for example, by sending the network certificate to the user terminal corresponding to the requester, or by sending the network certificate to the server of the requester.
[0193] In a specific example, when the demander is an APP, the CMID platform can send the network certificate to the user terminal where the APP is installed; or, it can send the network certificate to the APP's server.
[0194] Based on the same inventive concept, this invention provides a method for obtaining a network certificate, which can be applied to applications, especially to the applications of cooperative institutions of the CMIP platform, to obtain the network certificate in scenarios such as when a network certificate requester requests to obtain a user's network certificate.
[0195] The method includes the following steps A through D:
[0196] Step A: Obtain the identity information of the requester;
[0197] The demander's identity information may include, but is not limited to, one or more of the following: the device information of the demander and the institutional information of the demander.
[0198] Step B: Send the demander's identity information to the target software to trigger the target software to execute: After generating verification information based on the demander's identity information, send the verification information to the CMID platform;
[0199] The method for generating verification information can be found in the previous description, and will not be repeated here.
[0200] Step C: Receive the encrypted requester's identity information sent by the target software;
[0201] The encrypted requester's identity information is obtained by the CMID platform encrypting the requester's identity information after the verification information has been approved. Details can be found in the previous description and will not be repeated here.
[0202] Step D: Send the encrypted requester's identity information to the CMID platform to trigger the CMID platform to execute: After successfully decrypting the encrypted requester's identity information, send the network certificate required by the requester.
[0203] In one alternative implementation, the CMID platform sends the network certificate, for example, by sending the network certificate to the user terminal corresponding to the requester, or by sending the network certificate to the server of the requester.
[0204] In a specific example, when the demander is an APP, the CMID platform can send the network certificate to the user terminal where the APP is installed; or, it can send the network certificate to the APP's server.
[0205] In a specific example, when an access device wants to apply for a network license from the CMID platform, the access device can be verified for the network license application certificate. If the verification is successful, and the condition for the CMID platform to issue a network license on behalf of the CTID platform is triggered, the CMID platform can obtain the identity information of the target user.
[0206] In this embodiment of the invention, the CMID platform authentication SDK can have a built-in encryption key. This encryption key is used to encrypt the authorization verification information of the SDK's access device. The authorization verification information includes at least one of the following: device information of the access device, key information of the access device, and network license application information of the access device (such as the mobile device number or SIM card unique identifier as shown above). When issuing a network license application certificate to the access device of the CMID platform-authenticated SDK, the CMID platform can first decrypt the encrypted authorization verification information sent by the SDK's access device to obtain the authorization verification information. Then, it verifies the authorization verification information. When the authorization verification information passes verification, it is encrypted to generate a network license application certificate. At this time, the CMID platform can issue the network license application certificate to the access device. In one example, the above process can be as follows: Figure 4 As shown.
[0207] In this embodiment of the invention, the SDK can have built-in SM2 and SM4 keys, key encryption and signing processes, which are provided to the SDK for invocation, thereby enhancing the SDK's security and preventing the SDK from being cracked and causing key leakage (even if the key is leaked, the signing key is still needed to truly crack the signing algorithm, and the key is provided to the partner offline). The generation of the online certificate authorization certificate and the encryption of request information are encrypted with a separate SM4 key, which exists in the encryption machine, ensuring the absolute security of the authorization information.
[0208] In one optional implementation, the online certificate can be a QR code online certificate. When generating the online certificate for the target user based on the identity information, the target user's QR code online certificate can be generated based on the identity information and the QR code generation rules.
[0209] In one example, such as Figure 5 As shown, users can use a mini-program or app to click on "Generate Code" and request a QR code from the digital identity cloud platform. The digital identity cloud platform can query the network certificate switching configuration. If the CTID is abnormal, it will request the generation of a CMID code. The digital identity cloud platform obtains the CMID network certificate information, calculates the generated code verification information, verifies the generated code verification information (network certificate information, device information, random number, etc.) using the CMID, and generates and returns a QR code according to the QR code rules.
[0210] In this embodiment of the invention, the CMID platform can replace the CTID platform in issuing e-ID certificates. Therefore, when the condition for issuing e-ID certificates by the CMID platform instead of the CTID platform is triggered, the CMID platform can obtain the target user's identity information and generate the target user's e-ID certificate based on the identity information. Since it no longer relies solely on the CTID platform to generate e-ID certificates, but can rely on the CMID platform to issue e-ID certificates when it is necessary to replace the CTID platform, the problem of poor fault tolerance in existing technologies can be effectively solved.
[0211] Please see Figure 6 This is a flowchart illustrating the online certificate verification method proposed in this embodiment of the invention, applied to the CMID platform. Figure 6 As shown, the method includes the following steps:
[0212] Step 601: When the condition for the CMID platform to issue network certificates instead of the CTID platform is triggered, the CMID platform obtains the network certificate of the target user.
[0213] Step 602: Verify the online certificate.
[0214] In this embodiment of the invention, the CMID platform provides a function for verifying online credentials. Therefore, the CMID platform can replace the CTID platform for verifying online credentials. When the condition for the CMID platform to replace the CTID platform in verifying online credentials is triggered, that is, when the CMID platform is required to replace the CTID platform in verifying online credentials, the CMID platform can obtain the online credentials of the target user for whom online credentials need to be issued and verify the online credentials.
[0215] Since it no longer relies solely on CTID as the sole platform for verifying online certificates, but can instead use CMID to verify online certificates when CMID is needed to replace CTID, it effectively solves the problem of poor fault tolerance in existing technologies.
[0216] In one alternative implementation, when the CTID platform is in an abnormal working state, such as when the CTID platform fails to respond to the target user's network certificate issuance request for a long time or when the CTID platform malfunctions, it can be determined that the conditions for the CMID platform to replace the CTID platform in verifying the network certificate have been triggered. At this time, the CMID platform can obtain the target user's network certificate to perform network certificate verification.
[0217] For details on how to determine whether the CTID platform is in an abnormal working state, please refer to the previous description, which will not be repeated here.
[0218] In an optional implementation, the online certificate verification method provided in this embodiment of the invention may further include: when the condition for verification of the online certificate by the CTID platform is triggered, the CTID platform calls the CTID platform to perform: the CTID platform verifies the online certificate of the target user.
[0219] Among the conditions for the CTID platform to verify the network certificate are: the CTID platform is not in an abnormal working state.
[0220] In one optional implementation, if saving the target user's user ID to the CMID platform is prohibited, and the online certificate is an encrypted online certificate, then the CMID platform verifies the online certificate, which may specifically include: decrypting the encrypted online certificate by calling the encryption machine, using the target user's user ID as the dispersion factor of the decryption algorithm, to obtain the decrypted online certificate; and verifying the decrypted online certificate.
[0221] In one optional implementation, the specific way in which the CMID platform obtains the target user's network certificate may include: receiving the network certificate sent by the digital identity cloud platform integrated with the CMID platform after verifying the identity of the sender of the network certificate.
[0222] In a specific example, when the sender includes an e-ID card reader, the sender's identity verification includes verifying the device information of the e-ID card reader (such as a gate) and the identity information of the target user. If, based on the device information of the e-ID card reader and the identity information of the target user, it is determined that the e-ID card reader is a legitimate device and the target user is a legitimate user, then the sender's identity verification passes; otherwise, it fails.
[0223] When an e-ID is embedded in a QR code, sender identity verification includes verifying the source of the QR code. This source information can also be embedded within the QR code itself. The digital identity cloud platform determines the legitimacy of the QR code's source based on this information; if legitimate, the sender identity verification passes; otherwise, it fails. The source information can include, for example, the identifier of the e-ID issuing authority.
[0224] like Figure 7As shown, the user swipes their phone's NFC, the gate reads the user's e-ID information and unique personal identifier, and then captures the user's face. The gate's backend system requests the user information to the digital identity cloud platform for e-ID NFC authentication. The digital identity cloud platform calls the instruction unit to decrypt the e-ID unit and performs an NFC replay check. If a replay is detected, an error is reported. Then, the source of the e-ID is determined: if it is a CTID e-ID and the CTID is normal, the CTID platform is directly called for e-ID authentication; if it is a CTID e-ID and the CTID is abnormal, the user's CMID e-ID is obtained from the digital identity cloud platform and authenticated through CMID; if it is a CMID e-ID and the CTID is normal, the user's CTID e-ID is obtained from the digital identity cloud platform and authenticated through CTID; if it is a CMID e-ID and the CITD is abnormal, the CMID platform is directly called for e-ID authentication. After authentication, the authentication score is compared. If authentication is successful, the user information is dynamically returned (different merchants return different user information) and compared for consistency. If they match, the gate allows passage.
[0225] In another example, the network certificate is a QR code network certificate. When the condition for the CMID platform to verify the network certificate instead of the CTID platform is triggered, the QR code validity can be verified on the user device. When the QR code network certificate passes the validity verification, the CMID platform obtains the target user's network certificate.
[0226] like Figure 8 As shown, the verification terminal scans the QR code information for verification and captures the user's facial image. The digital identity cloud platform determines the source of the QR code and verifies it. If it is a CTID e-certificate QR code and the CTID is normal, it directly calls the CTID platform for verification. If it is a CTID e-certificate QR code and the CTID is abnormal, it obtains the user's CMID e-certificate from the digital identity cloud platform and authenticates it with the CMID. If it is a CMID e-certificate QR code and the CTID is normal, it directly calls the CMID platform for e-certificate authentication. If it is a CMID e-certificate and the CITD is abnormal, it directly calls the CMID platform for e-certificate authentication. The CMID verifies the validity of the QR code (validity period, whether it has been used, QR code rule parsing). If it is invalid, it throws an exception. If it is valid, it verifies the QR code. After verification, it calls the facial recognition capability provided by an authoritative data source for comparison. If the comparison is successful, the verification process is complete, and the verification result is returned. The digital identity cloud platform dynamically returns user information based on the verification result.
[0227] In this embodiment of the invention, the CMID platform can replace the CTID platform to verify online credentials. Therefore, when the condition for the CMID platform to replace the CTID platform in verifying online credentials is triggered, the CMID platform can obtain the target user's online credentials and verify them. Since it no longer relies solely on CTID as the sole platform for verifying online credentials, but can rely on CMID to verify them when the CTID platform malfunctions, the problem of poor fault tolerance in existing technologies can be effectively solved.
[0228] Corresponding to the above-described method for generating online certificates, this embodiment of the invention also provides an apparatus for a CMID platform. Figure 9 A schematic diagram of the unit composition of the device 900 of the CMID platform provided in an embodiment of the present invention is shown below. Figure 9 As shown, the device 900 of the CMID platform includes:
[0229] The acquisition unit 901 is used to acquire the identity information of the target user when the condition of the CMID platform replacing the CTID platform for issuing network certificates is triggered.
[0230] The generation unit 902 is used to generate the target user's online ID based on the identity information.
[0231] In one optional implementation, the acquisition unit 901 can be used to acquire the identity information of the target user when the CTID platform is in an abnormal working state.
[0232] In one optional implementation, the acquisition unit 901 can be used to acquire the identity information of the target user when the digital identity cloud platform integrating the CMID platform determines that the target user needs to apply for the network certificate based on the received business request of the target user.
[0233] In one optional implementation, the acquisition unit 901 can be used to acquire the identity information of the target user when the CMID platform receives a network certificate application request sent by the target user to the CMID platform; or, when the CMID platform determines that the target user needs to apply for the network certificate based on the received business request of the target user, the CMID platform acquires the identity information of the target user.
[0234] In an optional implementation, the CMID platform device 900 may further include: a real-name authentication unit, used to complete the real-name authentication of the target user based on a face recognition real-name authentication method before the generation unit 902 generates the target user's online ID based on the identity information; or, to complete the real-name authentication of the target user based on a real-name authentication method using SMS and face recognition.
[0235] In one optional implementation, the generation unit 902 may be specifically used to: generate an online certificate to be encrypted based on the identity information and the auxiliary information for applying for the online certificate; and encrypt the online certificate to be encrypted to obtain the encrypted online certificate.
[0236] In one optional implementation, the auxiliary information includes at least one of the following:
[0237] The information includes the e-certificate number, the target user's user ID, the e-certificate validity period, the identifier of the e-certificate issuing authority, the identifier of the e-certificate applying authority, the information of the e-certificate application terminal device, the e-certificate processing time, the random number, the check digit, and the e-certificate background image.
[0238] In an alternative implementation, the apparatus 900 of the CMID platform may further include a receiving unit. The receiving unit is used to receive the auxiliary information sent by the target software authenticated by the CMID platform.
[0239] In one optional implementation, the generation unit 902 may be specifically used to: generate a target user unique identifier with a target field length based on the identity information; wherein the target field length does not exceed the maximum field length supported by the storage space reserved in the super SIM card of the user terminal for storing the target user unique identifier;
[0240] The network certificate to be encrypted is generated based on the target user's unique identifier and the auxiliary information.
[0241] The generation unit 902 can be specifically used to: perform a digest calculation on the identity information using a digest algorithm to obtain an initial user unique identifier of the target field length;
[0242] Determine whether the initial user unique identifier is globally unique;
[0243] If so, the initial user unique identifier shall be determined as the target user unique identifier;
[0244] If not, repeat the following steps: using the digest algorithm, perform a digest calculation on the identity information with concatenated values to obtain the initial user unique identifier with the updated target field length;
[0245] The loop continues until the updated target field length's initial user unique identifier is globally unique, at which point the loop ends and the globally unique initial user unique identifier is determined as the target user unique identifier.
[0246] In an optional implementation, the generation unit 902 may be specifically used to: when it is prohibited to save the user ID of the target user to the CMID platform, use the user ID as the interface parameter used when calling the encryption machine, and call the encryption machine to execute: use the user ID as the dispersion factor of the encryption algorithm to encrypt the network certificate to be encrypted, and obtain the encrypted network certificate.
[0247] In one optional implementation, the online certificate is a QR code online certificate. Accordingly, the generation unit 902 can specifically be used to: generate the target user's QR code online certificate based on the identity information and the QR code generation rules.
[0248] Corresponding to the above-described method for generating online certificates, this embodiment of the invention also provides an apparatus for a CMID platform. Figure 10 A schematic diagram of the unit composition of the device 1000 of the CMID platform provided in this embodiment of the invention is shown below. Figure 10 As shown, the device 1000 of the CMID platform includes:
[0249] The acquisition unit 1001 is used to acquire the target user's network certificate when the condition of the network certificate being verified by the CMID platform instead of the CTID platform is triggered.
[0250] Verification unit 1002 is used to verify the network certificate.
[0251] In one optional implementation, the acquisition unit 1001 can be used to: acquire the network ID of the target user when the CTID platform is in an abnormal working state.
[0252] In an optional implementation, the verification unit 1002 can also be used to: when the condition for verifying the network certificate by the CTID platform is triggered, the CTID platform calls the CTID platform to perform: the CTID platform verifies the network certificate of the target user.
[0253] In one optional implementation, the conditions for the CTID platform to verify the network certificate include: the CTID platform is in normal working condition.
[0254] In one optional implementation, the acquisition unit 1001 may be specifically used to: receive the network certificate sent by the digital identity cloud platform integrated with the CMID platform after the identity of the sender of the network certificate has been verified.
[0255] In one optional implementation, when the sender includes a network certificate reading device, the sender identity verification includes: verifying the device information of the network certificate reading device and the identity information of the target user; when the network certificate is carried in a QR code, the sender identity verification includes: verifying the source of the QR code.
[0256] In one optional implementation, verifying the online ID includes:
[0257] When saving the target user's user ID to the CMID platform is prohibited, and the network certificate is an encrypted network certificate, the encryption machine is invoked to perform the following: using the user ID as the dispersion factor of the decryption algorithm to decrypt the encrypted network certificate to obtain the decrypted network certificate.
[0258] The decrypted online ID is then verified.
[0259] This application also provides an apparatus for a CMID platform, comprising:
[0260] The verification information receiving unit is used to receive verification information sent by the target software triggered by the online certificate requester to the CMID platform; the verification information includes the requester's identity information provided by the online certificate requester.
[0261] A verification unit is used to verify the verification information;
[0262] An encryption unit is used to encrypt the demander's identity information if the verification information passes the verification, so as to obtain encrypted demander identity information.
[0263] An identity information sending unit is used to send the encrypted requester's identity information to the target software, thereby triggering the target software to send the encrypted requester's identity information to the network certificate requester.
[0264] An identity information receiving unit is used to receive the encrypted identity information of the network certificate requester sent by the network certificate requester.
[0265] The decryption unit is used to perform decryption processing on the encrypted requester's identity information corresponding to the encryption processing;
[0266] The online certificate sending unit is used to send the online certificate requested by the online certificate requester if the decryption process can successfully decrypt the encrypted identity information of the requester.
[0267] In one optional implementation, the verification information is generated by the target software in the following manner:
[0268] Based on the encryption key allocated by the CMID platform, the identity information of the requester sent by the network certificate requester to the target software is encrypted to obtain the encrypted identity information of the requester.
[0269] Based on the private key allocated to the target software by the CMID platform, the obtained encrypted requester identity information is signed to obtain the signed encrypted requester identity information.
[0270] Based on the salt provided by the network certificate requester, the obtained encrypted requester identity information is salted to obtain salted encrypted requester identity information, which is used as the verification information.
[0271] In one optional implementation, the demander identity information includes at least one of the following:
[0272] The device information of the party requesting the online certificate;
[0273] The information of the organization requesting the online certificate.
[0274] In one alternative implementation, the verification unit may specifically be used for:
[0275] The verification information is verified based on the pre-stored salt and the public key corresponding to the private key;
[0276] If the signature verification is successful, the encrypted requester identity information obtained by verifying the signature of the verification information is decrypted based on the pre-stored encryption key.
[0277] If decryption is successful, the verification information is deemed to have passed verification.
[0278] This application embodiment also provides a network certificate acquisition device, including:
[0279] The identity information acquisition unit is used to acquire the identity information of the demander;
[0280] An identity information sending unit is used to send the demander's identity information to the target software to trigger the target software to execute: after generating verification information based on the demander's identity information, send the verification information to the CMID platform;
[0281] An encrypted information receiving unit is used to receive encrypted requester identity information sent by the target software; the encrypted requester identity information is obtained by the CMID platform after the verification information is verified and the requester identity information is encrypted.
[0282] The encrypted requester's identity information is sent to the CMID platform to trigger the CMID platform to execute: after successfully decrypting the encrypted requester's identity information, send the network certificate.
[0283] This application embodiment also provides an information sending device, including:
[0284] The identity information receiving unit is used to receive the identity information of the requester sent by the requester of the online certificate;
[0285] The verification information generation unit is used to generate verification information based on the identity information of the requester;
[0286] The verification information sending unit is used to send the verification information to the CMID platform.
[0287] An encrypted information receiving unit is used to receive encrypted requester identity information sent by the CMID platform after the verification information has been verified.
[0288] An encrypted information sending unit is used to send the encrypted requester's identity information to the network certificate requester.
[0289] Based on the same inventive concept as the foregoing embodiments of this application, this application also provides a computing device.
[0290] like Figure 11 As shown, the computing device includes a memory 111 and a processor 112. The memory 111 can be configured to store various other data to support operation on the electronic device. Examples of such data include instructions for any application or method used to operate on the electronic device. The memory 111 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0291] The processor 112, coupled to the memory 111, is used to execute a computer program stored in the memory 111 for performing the session quality detection method described in the embodiments of this application.
[0292] When the processor 112 executes the computer program in the memory 111, in addition to the functions described above, it can also perform other functions, as detailed in the descriptions of the preceding embodiments.
[0293] Furthermore, such as Figure 11 As shown, the computing device also includes other components such as a display 114, a communication component 113, a power supply component 115, and an audio component 116. Figure 11 The diagram only shows some components and does not mean that the computing device includes only these components. Figure 11 The components shown.
[0294] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a computer, can implement the methods provided in the above embodiments.
[0295] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0296] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0297] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A method of transmitting a web ticket, characterized by, The method is applied to a network mobile identity platform CMID, and comprises the following steps: receiving verification information sent by target software triggered by a network certificate demander to the CMID platform, wherein the verification information contains demander identity information provided by the network certificate demander; verifying the verification information; if the verification information is verified successfully, performing encryption processing on the demander identity information to obtain encrypted demander identity information; sending the encrypted demander identity information to the target software to trigger the target software to send the encrypted demander identity information to the network certificate demander; receiving the encrypted demander identity information sent by the network certificate demander; performing decryption processing corresponding to the encryption processing on the encrypted demander identity information; if the decryption processing can successfully decrypt the encrypted demander identity information, sending a network certificate required by the network certificate demander.
2. The method of claim 1, wherein, The verification information is generated by the target software in the following manner: performing encryption processing on the demander identity information sent by the network certificate demander to the target software based on an encryption key allocated by the CMID platform to obtain encrypted demander identity information; performing signature processing on the obtained encrypted demander identity information based on a private key allocated by the CMID platform to the target software to obtain signed encrypted demander identity information; performing salt processing on the obtained encrypted demander identity information based on a salt provided by the network certificate demander to obtain salted encrypted demander identity information as the verification information.
3. The method of claim 2, wherein, The demander identity information comprises at least one of the following: device information of the network certificate demander; institution information of the network certificate demander.
4. The method according to claim 2 or 3, characterized in that, The verification processing on the verification information comprises the following steps: performing signature verification on the verification information based on a pre-stored salt and a public key corresponding to the private key; if the signature verification is passed, performing decryption processing on the encrypted demander identity information obtained by performing signature verification on the verification information based on a pre-stored encryption key; if the decryption is successful, determining that the verification information is verified successfully.
5. A web attestation generation method characterized by comprising: The method is applied to a network mobile identity platform CMID, and comprises the following steps: when a condition that a network space trusted identity CTID platform is replaced by the CMID platform to issue a network certificate is triggered, the CMID platform acquires identity information of a target user; generating a network certificate of the target user according to the identity information; the network certificate is generated by the method in any one of claims 1-4.
6. The method of claim 5, wherein, When the condition is triggered, the CMID platform acquires identity information of a target user, comprising the following steps: when a working state of the CTID platform is abnormal, the CMID platform acquires the identity information of the target user.
7. The method of claim 5, wherein, When the condition is triggered, the CMID platform acquires identity information of a target user, comprising the following steps: when a digital identity cloud platform integrated with the CMID platform judges that the target user needs to apply for the network certificate based on a received service request of the target user, the CMID platform acquires the identity information of the target user.
8. The method of claim 5, wherein, When the condition is triggered, the CMID platform acquires identity information of a target user, comprising the following steps: The CMID platform acquires the identity information of the target user when receiving a network certificate application request sent by the target user to the CMID platform; or The CMID platform acquires the identity information of the target user when judging that the target user needs to apply for the network certificate based on the received service request of the target user.
9. The method of claim 5, wherein, Before generating the network certificate of the target user according to the identity information, the method further comprises: completing real-name authentication of the target user based on a real-name authentication mode of face recognition; or completing real-name authentication of the target user based on a real-name authentication mode of short message and face recognition.
10. The method of claim 5, wherein, Generating the network certificate of the target user according to the identity information comprises: generating a network certificate to be encrypted according to the identity information and auxiliary information of network certificate application; and encrypting the network certificate to be encrypted to obtain an encrypted network certificate.
11. The method of claim 10, wherein, The auxiliary information comprises at least one of the following information: a network certificate number, a user number of the target user, a network certificate validity period, an identifier of a network certificate issuing authority, an identifier of a network certificate application authority, information of a network certificate application terminal device, a network certificate handling time, a random number, a check digit, and a network certificate background image.
12. The method of claim 11, wherein, The method further comprises: The CMID platform receives the auxiliary information sent by the target software authenticated by the CMID platform.
13. The method of any one of claims 10-12, wherein, Generating the network certificate to be encrypted according to the identity information and the auxiliary information comprises: generating a target user unique identifier with a target field length according to the identity information; wherein the target field length does not exceed the maximum field length supported by the storage space reserved in the super SIM card of the user terminal for storing the target user unique identifier; and generating the network certificate to be encrypted according to the target user unique identifier and the auxiliary information.
14. The method of claim 13, wherein, Generating the target user unique identifier with the target field length according to the identity information comprises: performing digest calculation on the identity information by using a digest algorithm to obtain an initial user unique identifier with the target field length; judging whether the initial user unique identifier is globally unique; if yes, determining the initial user unique identifier as the target user unique identifier; if no, performing the following operations in a loop: performing digest calculation on the identity information spliced with a value by using the digest algorithm to obtain an updated initial user unique identifier with the target field length; and terminating the loop when the updated initial user unique identifier with the target field length is globally unique, and determining the globally unique initial user unique identifier as the target user unique identifier.
15. The method of claim 14, wherein, Encrypting the network certificate to be encrypted to obtain the encrypted network certificate comprises: in the case where the user number of the target user is prohibited from being saved to the CMID platform, using the user number as an interface parameter used when calling an encryption machine, and calling the encryption machine to perform the following operation: using the user number as a dispersion factor of an encryption algorithm to encrypt the network certificate to be encrypted to obtain the encrypted network certificate.
16. The method of claim 5, wherein, The network certificate is a two-dimensional code network certificate; and generating the network certificate of the target user according to the identity information comprises: According to the identity information and a two-dimensional code generation rule, a two-dimensional code network certificate of the target user is generated.
17. A web authentication method, characterized by, The method comprises: obtaining demander identity information; sending the demander identity information to a target software to trigger the target software to perform: after generating verification information based on the demander identity information, sending the verification information to a network mobile identity platform (CMID); receiving encrypted demander identity information sent by the target software; the encrypted demander identity information is obtained by encrypting the demander identity information by the CMID after the verification information is verified to be correct; sending the encrypted demander identity information to the CMID to trigger the CMID to perform: after successfully decrypting the encrypted demander identity information, sending a network certificate required by the demander.
18. An information transmission method characterized by comprising: The method applied to a target software comprises: receiving demander identity information sent by a network certificate demander; generating verification information based on the demander identity information; sending the verification information to a network mobile identity platform (CMID); receiving encrypted demander identity information sent by the CMID after the verification information is verified to be correct; sending the encrypted demander identity information to the network certificate demander, so that the network certificate demander sends the encrypted demander identity information to the CMID to trigger the CMID to perform: after successfully decrypting the encrypted demander identity information, sending a network certificate required by the demander.
19. The method of claim 18, wherein, Generating verification information based on the demander identity information comprises: encrypting the demander identity information based on an encryption key assigned by the CMID to obtain encrypted demander identity information; signing the obtained encrypted demander identity information based on a private key assigned by the CMID to the target software to obtain signed encrypted demander identity information; salting the obtained encrypted demander identity information based on a salt provided by the network certificate demander to obtain salted encrypted demander identity information as the verification information.
20. The method of claim 19, wherein, The demander identity information comprises at least one of: device information of the network certificate demander; institutional information of the network certificate demander.
21. A web attestation method, characterized by, The method applied to a network mobile identity platform (CMID) comprises: when a condition that a network space trusted identity (CTID) platform is replaced by the CMID to verify a network certificate is triggered, the CMID obtains a network certificate of a target user; the network certificate is obtained by the method of any one of claims 1-4; verifying the network certificate.
22. The method of claim 21, wherein, When the condition is triggered, the CMID obtains the network certificate of the target user, comprising: when a working state of the CTID platform is abnormal, the CMID obtains the network certificate of the target user.
23. The method of claim 21, wherein, The method further comprises: when a condition that a network space trusted identity (CTID) platform is replaced by the CMID to verify a network certificate is triggered, the CMID calls the CTID platform to perform: verifying the network certificate of the target user by the CTID platform.
24. The method of claim 23, wherein, The condition that the CTID platform verifies the network certificate comprises: The CTID platform working state is normal.
25. The method of claim 21, wherein, The CMID platform obtains the network certificate of the target user, comprising: After the sender identity verification of the network certificate is passed, the digital identity cloud platform integrated with the CMID platform sends the network certificate.
26. The method of claim 25, wherein: When the sender comprises a network certificate reading device, the sender identity verification comprises verifying the device information of the network certificate reading device and the identity information of the target user; When the network certificate is carried in a two-dimensional code, the sender identity verification comprises verifying the source of the two-dimensional code.
27. The method of claim 21, wherein, The verification of the network certificate comprises: In the case that the user number of the target user is prohibited to be saved to the CMID platform, when the network certificate is an encrypted network certificate, the user number is used as a dispersion factor of a decryption algorithm to decrypt the encrypted network certificate to obtain a decrypted network certificate by calling an encryption machine; The decrypted network certificate is verified.
28. An apparatus of a network mobile identity (CMID) platform, the apparatus characterized by: The device comprises: A verification information receiving unit configured to receive verification information sent by a network certificate demander to a target software via the CMID platform, wherein the verification information comprises demander identity information provided by the network certificate demander; A verification unit configured to verify the verification information; An encryption unit configured to, if the verification information is verified, encrypt the demander identity information to obtain encrypted demander identity information; An identity information sending unit configured to send the encrypted demander identity information to the target software to trigger the target software to send the encrypted demander identity information to the network certificate demander; An identity information receiving unit configured to receive the encrypted demander identity information sent by the network certificate demander; A decryption unit configured to decrypt the encrypted demander identity information by a decryption process corresponding to the encryption process; A network certificate sending unit configured to, if the encrypted demander identity information can be successfully decrypted by the decryption process, send a network certificate demanded by the demander.
29. An apparatus of a network mobile identity (CMID) platform, the apparatus characterized by: The device comprises: An obtaining unit configured to obtain identity information of a target user when a condition that a network space trusted identity (CTID) platform is replaced by the CMID platform to issue a network certificate is triggered; A generating unit configured to generate a network certificate of the target user according to the identity information, wherein the network certificate is generated by the method of any one of claims 1-4.
30. An apparatus of a network mobile identity (CMID) platform, the apparatus characterized by: The device comprises: An obtaining unit configured to obtain a network certificate of a target user when a condition that a network space trusted identity (CTID) platform is replaced by the CMID platform to verify the network certificate is triggered, wherein the network certificate is generated by the method of any one of claims 1-4; A verification unit configured to verify the network certificate.
31. A web certificate obtaining apparatus characterized by comprising: The device comprises: An identity information obtaining unit configured to obtain demander identity information; An identity information sending unit configured to send the demander identity information to a target software to trigger the target software to generate verification information based on the demander identity information and send the verification information to a network mobile identity (CMID) platform. The encryption information receiving unit is configured to receive encrypted demander identity information sent by the target software, wherein the encrypted demander identity information is obtained by encrypting the demander identity information by the CMID platform after the verification information is verified to be correct. The encrypted demander identity information is sent to the CMID platform to trigger the CMID platform to send a network certificate after successfully decrypting the encrypted demander identity information.
32. An information transmitting apparatus, characterized by comprising: The device is applied to target software and includes: An identity information receiving unit configured to receive demander identity information sent by a network certificate demander; A verification information generating unit configured to generate verification information based on the demander identity information; A verification information sending unit configured to send the verification information to a network mobile identity (CMID) platform; An encryption information receiving unit configured to receive encrypted demander identity information sent by the CMID platform after the verification information is verified to be correct; An encryption information sending unit configured to send the encrypted demander identity information to the network certificate demander, so that the network certificate demander sends the encrypted demander identity information to the CMID platform to trigger the CMID platform to send a network certificate demanded by the demander after successfully decrypting the encrypted demander identity information.
33. A computing device, comprising: The device includes: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is executed by the processor to implement the steps of the method according to any one of claims 1-27.
34. A computer-readable storage medium, characterized in that, A computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the method according to any one of claims 1-27.
Citation Information
Patent Citations
User identity real-name authentication method of an electronic payment system
CN109829722A
Disaster recovery method and device of business management platform and storage medium
CN114253774A