Network certificate parser, data identification method, device and storage medium
Through the modular design of the online certificate parser, the information security issues of online certificates in the financial, tax, telecommunications and other industries are solved, cross-domain and cross-departmental online certificate parsing is realized, data security and interoperability are guaranteed, and authentication of multiple data expressions is supported.
Patent Information
- Application Number
- CN202311378764.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-23
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2043-10-23
AI Technical Summary
The information security of existing online certificates in the financial, tax, telecommunications and other industries cannot be directly connected to the Internet, resulting in the inability of counter services in these industries to support online certificates. In addition, the data format of online certificates is not unified, and there are risks in the verification of identity and identity. As a result, online certificates face data security risks and interoperability difficulties in their promotion and application across the country.
A network certificate parser is provided, which includes an internal communication module, an acquisition communication module, an external network communication module, a data security module, an instruction analysis module, a guide parsing module, a network certificate parsing module, a data scheduling module and a script management execution module. These modules are used to implement security verification of identified information, instruction analysis, access parameter generation, network certificate authentication platform determination and parsing processing, support information authentication of different types of expressions, and ensure data security.
It realizes the cross-domain and cross-departmental network certificate analysis function, ensures network and data security, prevents hacker, virus, and Trojan attacks, prevents internal personnel from stealing data, and supports the interconnection and interoperability of multiple data expressions.
Smart Images

Figure CN117675272B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of data identification technology, and in particular to a network certificate parser, a data identification method, a device, and a storage medium. Background Art
[0002] Online IDs, also known as online IDs, electronic IDs, virtual IDs, identity authentication, online ID numbers, network numbers, CTIDs, and eIDs, are a national key project. Using computers or smartphones as a medium, online IDs can serve as virtual identity credentials, reducing the need to visit business halls and running errands, truly benefiting the public. In the near future, online IDs will be available in business halls, allowing people to conduct business using online IDs without having to carry physical IDs, thus reducing the burden of carrying physical IDs.
[0003] Currently, online IDs utilize online ID resolution servers on the internet, allowing hotels, rental properties, internet cafes, and other systems to register personal identities. This allows users to check in to hotels, rent apartments, access internet cafes, and other services without having to bring their physical ID cards. However, due to the national priority of information security, industries and sectors such as finance, taxation, and telecommunications cannot be directly connected to the internet. Increasing the support for online IDs in these sectors' existing over-the-counter service systems would require a nationwide, top-down overhaul, involving numerous industries and a significant number of sectors, and the associated data security risks are also significant. Consequently, since the official launch of online IDs in 2018, over-the-counter service systems in banks, taxation, telecommunications, and other sectors have not yet supported online IDs, forcing users to bring their physical ID cards to conduct transactions.
[0004] In addition, online certificates are not uniform across China, and each province in China has its own online certificate.
[0005] Online ID cards primarily use QR codes for display and data exchange, but some also use NFC (Near Field Communication). Furthermore, their data formats are not standardized, with various data expressions including plaintext or encrypted JSON data, simple codes (no data formatting), and URLs, making interoperability more complex. Finally, the China Second Generation ID card reader, based on physical ID cards, can only verify identity through the human eye and does not support computer-based verification. Since ID cards can be valid for up to 30 years, visual verification carries certain risks. Summary of the Invention
[0006] The present invention provides a network certificate parser, data identification method, device, and storage medium that support information authentication in various formats, enabling cross-domain and cross-departmental network certificate parsing. This approach also ensures network and data security, preventing attacks from hackers, viruses, and Trojans, as well as preventing data theft by internal personnel.
[0007] In a first aspect, an embodiment of the present invention provides a network certificate parser, comprising an internal communication module, a collection communication module, an external network communication module, a data security module, an instruction analysis module, a guide parsing module, a network certificate parsing module, a data scheduling module, and a script management and execution module, wherein:
[0008] The acquisition communication module is used to collect information to be identified;
[0009] The data security module is used to perform security verification on the information to be identified;
[0010] The instruction analysis module is used to perform instruction analysis on the information to be identified and generate access parameters based on the instruction analysis result when the information to be identified passes the security verification;
[0011] The data security module is also used to perform security verification on the access parameters;
[0012] The guidance parsing module is used to determine the network certificate authentication platform of the access parameter if the access parameter security check passes;
[0013] The external network communication module is used to send the access parameters to the network certificate authentication platform, so that the network certificate authentication platform generates and sends an authentication result based on the access parameters. The external network communication module is also used to receive the authentication result sent by the network certificate authentication platform, and the authentication result includes an authentication platform identifier;
[0014] The data security module is also used to perform security verification on the authentication result;
[0015] The network certificate parsing module is used to determine the corresponding parsing script according to the authentication platform identifier when the authentication result passes the security verification;
[0016] The script management execution module is used to parse the authentication result according to the determined parsing script to obtain result data in a unified data format;
[0017] The data dispatching module is used to dispatch the result data to the internal communication module for transmitting the result data.
[0018] Optionally, the instruction analysis module is specifically used to:
[0019] Performing instruction analysis on the information to be identified to obtain an instruction type;
[0020] Extracting information of a preset field corresponding to the information to be identified according to the instruction type to obtain guidance information, and generating access parameters based on the guidance information.
[0021] Optionally, the instruction analysis module is specifically used to:
[0022] In a case where the guidance information is local guidance, generating local access parameters based on the guidance information;
[0023] In the case where the guidance information is a network guidance, the network address corresponding to the guidance information is queried in a recorded network address table or determined through a guidance resolution server, and an external network access parameter is generated based on the network address.
[0024] Optionally, the script management execution module is further configured to:
[0025] Before determining the corresponding parsing script according to the authentication platform identifier, configuring corresponding parsing scripts for different authentication platforms and recording the association between the authentication platform identifier and the corresponding parsing script, the configuration process includes adding, deleting, and modifying the parsing script when the script verification passes;
[0026] The script management execution module is specifically used to:
[0027] The authentication result is decrypted and the data format is changed through the parsing script.
[0028] Optionally, the data scheduling module is further configured to:
[0029] Dispatching the information to be identified to the data security module, and dispatching the information to be identified to the instruction parsing module if the information to be identified passes the security check;
[0030] If the access parameter security check passes, dispatching the access parameter to the guidance parsing module, and dispatching the access parameter and the identifier of the network certificate authentication platform to the external network communication module;
[0031] When the authentication result passes the security check, the authentication result is dispatched to the network certificate parsing module and the script management and execution module.
[0032] Optionally, the online certificate authentication platform includes an online certificate parsing service platform or a personal certificate verification service platform; the acquisition communication module is communicatively connected to the acquisition device, and the acquisition device includes any one or more of a code scanning device, a camera, an NFC device, a face information collector, a fingerprint information collector, and an iris collector; the information to be identified includes any one or more of string information, image information, and binary information; the online certificate parser and the acquisition device are an integrated device, or two separate devices.
[0033] Optionally, the internal communication module is further configured to receive a read request sent by a communication-connected host device, and feed back the result data to the host device.
[0034] Optionally, it also includes a working mode control module for setting the working mode of the network certificate parser, and the working mode includes a device setting mode, a network certificate parsing mode, a person certificate verification mode and a person code decoding mode.
[0035] In a second aspect, an embodiment of the present invention further provides a data identification method, which is applied to a network certificate parser, comprising:
[0036] Obtaining information to be identified, and performing security verification on the information to be identified;
[0037] If the security check passes, performing instruction analysis on the information to be identified and generating access parameters based on the instruction analysis result;
[0038] Performing a security check on the access parameters, and if the security check passes, determining a network authentication platform for the access parameters, and sending the access parameters to the network authentication platform, so that the network authentication platform generates and sends an authentication result based on the access parameters;
[0039] Receiving an authentication result sent by the online authentication platform, the authentication result including an authentication platform identifier;
[0040] A security check is performed on the authentication result. If the security check passes, a corresponding parsing script is determined according to the authentication platform identifier, and the authentication result is parsed by the parsing script to obtain result data in a unified data format.
[0041] Optionally, performing instruction analysis on the information to be identified and generating access parameters based on the instruction analysis result includes:
[0042] Performing instruction analysis on the information to be identified to obtain an instruction type;
[0043] Extracting information of a preset field corresponding to the information to be identified according to the instruction type to obtain guidance information, and generating access parameters based on the guidance information.
[0044] Optionally, generating access parameters based on the guidance information includes:
[0045] In a case where the guidance information is local guidance, generating local access parameters based on the guidance information;
[0046] In the case where the guidance information is a network guidance, the network address corresponding to the guidance information is queried in a recorded network address table or determined through a guidance resolution server, and an external network access parameter is generated based on the network address.
[0047] Optionally, before determining the corresponding parsing script according to the authentication platform identifier, the method further includes:
[0048] Configure corresponding parsing scripts for different authentication platforms and record the association between the authentication platform identifier and the corresponding parsing script. The configuration process includes adding, deleting, and modifying the parsing script when the script passes verification.
[0049] The parsing of the authentication result by the parsing script includes:
[0050] The authentication result is decrypted and the data format is changed through the parsing script.
[0051] In a third aspect, an embodiment of the present invention further provides a data identification device, the device comprising:
[0052] one or more processors;
[0053] a storage device for storing one or more programs,
[0054] When the one or more programs are executed by the one or more processors, the one or more processors implement the data identification method described in the embodiment of the present invention.
[0055] In a fourth aspect, an embodiment of the present invention further provides a storage medium comprising computer-executable instructions, which, when executed by a computer processor, are used to execute the data identification method described in the embodiment of the present invention.
[0056] In an embodiment of the present invention, a network certificate parser is provided, comprising an internal communication module, an acquisition communication module, an external network communication module, a data security module, an instruction analysis module, a guide parsing module, a network certificate parsing module, a data scheduling module and a script management execution module, wherein the acquisition communication module is used to acquire information to be identified; the data security module is used to perform security verification on the information to be identified; the instruction analysis module is used to perform instruction analysis on the information to be identified and generate access parameters based on the instruction analysis results if the security verification of the information to be identified passes; the data security module is also used to perform security verification on the access parameters; the guide parsing module is used to determine the network certificate authentication platform of the access parameters if the security verification of the access parameters passes; the The external network communication module is used to send the access parameters to the network certificate authentication platform, so that the network certificate authentication platform generates and sends the authentication result based on the access parameters. The external network communication module is also used to receive the authentication result sent by the network certificate authentication platform, and the authentication result includes the authentication platform identifier; the data security module is also used to perform security verification on the authentication result; the network certificate parsing module is used to determine the corresponding parsing script according to the authentication platform identifier when the authentication result security verification passes; the script management execution module is used to parse the authentication result according to the determined parsing script to obtain result data in a unified data format; the data scheduling module is used to schedule the result data to the internal communication module for transmitting the result data. The network certificate parser provided above obtains access parameters by performing instruction parsing on the identification information, and determines the corresponding network certificate authentication platform for authentication based on the access parameters. It can support information authentication of different types of expressions and realizes cross-domain and cross-departmental network certificate parsing functions. At the same time, the data reading and writing information of each link is verified through the data security module, which ensures the security of the network and data. While preventing hacker, virus and Trojan attacks, it can also prevent internal personnel from stealing data through the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 A schematic diagram of the module structure of a network certificate parser provided by an embodiment of the present invention;
[0058] Figure 2 A flowchart of a data identification method provided by an embodiment of the present invention;
[0059] Figure 3 A schematic diagram of a usage scenario of a network certificate parser provided by an embodiment of the present invention;
[0060] Figure 4 A structural diagram of a data identification device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0061] The following is a further detailed description of the embodiments of the present invention in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the embodiments of the present invention and are not intended to limit the embodiments of the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions of the embodiments of the present invention, rather than all structures.
[0062] Figure 1 A schematic diagram of the module structure of a network certificate parser provided by an embodiment of the present invention. Figure 1 The network certificate parser 10 shown includes an internal communication module 11, a collection communication module 12, an external network communication module 13, a data security module 14, an instruction analysis module 15, a guidance parsing module 16, a network certificate parsing module 17, a data scheduling module 18 and a script management execution module 19.
[0063] Among them, the acquisition communication module 12 is used to collect information to be identified. Optionally, the acquisition communication module 12 can be connected to the acquisition device for communication, such as through USB, serial port, I2C or Bluetooth, or integrated with the acquisition device as an integrated device, that is, a network certificate parser including the acquisition device. Among them, the acquisition device can be any one of a code scanning device, a camera, an NFC device, a face information collector, a fingerprint information collector and an infrared collector. Depending on the type of acquisition device used, the representation method of the information to be identified collected can be any one of string information, image information and binary information. Taking the acquisition device as a code scanning device as an example, the QR code displayed in the mobile phone app can be scanned to generate the information to be identified in the form of a string, which is transmitted to the acquisition communication module 12 for subsequent authentication. Another way to input the information to be identified is to connect the host to the code scanning device, convert the information to be identified that needs to be parsed, such as the network certificate QR code here, into the information to be identified in the form of a string and send it to the internal communication module for subsequent authentication. That is, the input information to be identified can be input into the network certificate parser 10 from the internal communication module 11 or the acquisition communication module 12 .
[0064] The data security module 14 first performs a security check on any input data to be identified. For example, if the data is in the form of a string, it is analyzed to determine if it poses a security risk. If it is deemed safe, the data is then analyzed by the instruction analysis module 15. This prevents malicious instructions that could compromise the host, network certificate parser, or intranet security, and intercepts them in advance. If the security check fails, the task execution is terminated.
[0065] Among them, when the security check of the information to be identified is passed, the instruction analysis module 15 performs instruction analysis on the information to be identified, and generates access parameters based on the instruction analysis results. Optionally, the parsing results are different for different forms of information to be identified, and the way to generate access parameters can be: performing instruction analysis on the information to be identified to obtain the instruction type; extracting the information of the corresponding preset field of the information to be identified according to the instruction type to obtain guidance information, and generating access parameters based on the guidance information. Among them, taking the information to be identified in the form of a string as an example, due to the differences in different platforms, different regions and specific functions, its expression methods are diverse, and the most common ones are: plaintext or ciphertext JSON data, short codes, URLs and other data expressions. Therefore, the information to be identified is analyzed to first determine its instruction type, and then the corresponding field content is extracted according to the pre-set field extraction method of different instruction types to obtain guidance information. An example is given below:
[0066] For the plain text JSON data format, the information is intuitive, such as the Guangdong Provincial Affairs Network Certificate:
[0067] "{"id":"YM001FLN3S0J1ESC6S","my":"ZU","nr":{"xm":"Zhang San","gb":"CHN111","zm":"442000199001013139","zx":"","sj":"1AD 8KH"},"qm":"MEYCIQCctcu2FD+fn5b0pVk61rQ0j4AxWbyFQkvcg0sAbe610wIhAKYlxegDe0ZVHjcuk43Tr+HqH0KIQ5i1lM1U2XJG47kV"}"
[0068] As mentioned above, the information contained in the online certificate is presented in plain text. For example, the user name of the online certificate is "Zhang San", and the ID number is "442000199001013139". The online certificate authentication platform ID of the online certificate can be extracted from the "id" field, which is "YM". At this time, the YM can be used as guidance information to generate access parameters based on this.
[0069] For short codes, it is a plain text string of network certificate information, for example:
[0070] “K9BY141VW7QP00ATYA”
[0071] The first few characters are usually the ID number of the online authentication platform to which the online authentication string belongs. In this case, the online authentication platform ID number is "K9". This online authentication string information can be used to obtain the corresponding personal information on the online authentication platform. In this case, K9 is used as guidance information to generate access parameters based on this.
[0072] For the URL, it contains the network certificate string information of the network certificate resolution URL, for example:
[0073] "https: / / qr.alipay.com / ncx08307yqqtuo4qchzz32db"
[0074] The above-mentioned network certificate string information includes the URL of the network certificate resolution server, the URL of the network certificate authentication platform is "https: / / qr.alipay.com", and the network certificate parameter is "ncx08307yqqtuo4qchzz32db". The corresponding specific URL can be used as guidance information to generate access parameters based on this.
[0075] The encrypted JSON data format is similar to the plaintext network certificate string, but the personal information is desensitized. For example:
[0076] "{"id":"YM001FLN3S0J1ESC6S","my":"ZU","nr":{"xm":"Zhang*","gb":"CHN111","zm":"44**39","zx":"","sj":" 1AD8KH"},"qm":"MEYCIQCctcu2FD+fn5b0pVk61rQ0j4AsWbyFQkvcg0sAbe612wIhAKYlxegDe0ZVHjcuk43Tr+HqH0KIQ 5i1lM1U2XJG47kV"}"
[0077] The only information from this online ID document is that the user's last name is "Zhang," the first two digits of the ID card are "44," and the last two digits are "39." The ID for this online ID verification platform is "YM," which can be used to generate access parameters. Of course, there are other data formats to be identified, such as XML and HTML, which are not discussed here.
[0078] Optionally, the instruction type can be determined based on the content of the first several characters in the information to be identified. For example, a character beginning with "{" indicates a simple code type; a character beginning with "{" indicates a plaintext or ciphertext JSON data format; a character beginning with "http: / / " or "https: / / " indicates a URL format. Then, based on the content of the preset fields corresponding to different instruction types, the navigation information can be extracted to generate access parameters.
[0079] Optionally, when the instruction analysis module 15 performs instruction parsing and generates access parameters, specifically, if the guidance information is a local guidance, local access parameters are generated based on the guidance information; if the guidance information is a network guidance, the network address corresponding to the guidance information is determined by querying the recorded network address table or through the guidance resolution server, and generating external network access parameters based on the network address. The process of generating access parameters can also be performed by the guidance resolution module 16. That is, after the instruction analysis module 15 determines the instruction type, it sends the instruction type and the information to be identified to the guidance resolution module 16. The guidance resolution module 16 determines the network address corresponding to the guidance information by querying the table or through the guidance resolution server. For example, when the network certificate string type is a URL type, the network certificate resolution URL is obtained. For example, if the network certificate resolution URL is "https: / / qr.alipay.com", the guidance resolution module queries the table to determine whether the network certificate URL is legal, preventing internal users from arbitrarily specifying network addresses and causing network access security issues. The corresponding network certificate resolution address, upload parameters, data format, and access permission code are returned as access parameters for subsequent access to the network certificate platform based on the access parameters. For example, when the network certificate string type is in plaintext or ciphertext JSON data format, obtaining the network certificate authentication platform ID (for example, if the network certificate authentication platform ID is "YM") will direct the parsing module to query the table, obtain the corresponding network certificate resolution address information, and return the corresponding network certificate resolution address, upload parameters, data format, and access permission code as access parameters for the external communication module to access the corresponding platform. Optionally, to prevent device counterfeiting or impersonation, information such as the device hardware ID and timestamp can be included when generating the access parameters.
[0080] Among them, after the access parameters pass the security verification of the data security module, the access parameters are sent to the corresponding network certificate authentication platform through the external network communication module 13. The network certificate authentication platform generates and sends the authentication result based on the access parameters. Accordingly, the external network communication module 13 receives the authentication result, and after passing the security verification of the data security module 14, the corresponding parsing script is determined according to the authentication platform identifier contained in the authentication result through the network certificate parsing module 17. The data scheduling module 18 sends the information to be identified to the script management execution module 19. The script management execution module 19 parses the authentication result according to the determined parsing script to obtain result data in a unified data format.
[0081] Among them, the script management execution module 19 maintains parsing scripts for multiple different platforms to parse the identification information to obtain parsing results. Under the scheduling of the data scheduling module 18, the result, i.e., the result data, is dispatched to the internal communication module 11 for other devices, such as the connected host to read.
[0082] The script management execution module 19 is also used to configure the corresponding parsing scripts for different authentication platforms before determining the corresponding parsing script based on the authentication platform identifier, and record the association between the authentication platform identifier and the corresponding parsing script. The configuration process includes adding, deleting, and modifying the parsing script when the script verification passes. The script management execution module 19 is specifically used to decrypt the authentication result data and change the data format through the parsing script. This includes updating the parsing scripts for each platform and verifying whether the handshake script and the parsing script contain any illegal instructions.
[0083] Optionally, the above-mentioned network certificate parser 10 also includes an encryption / decryption module 20, which is used to encrypt / decrypt data that needs to be encrypted / decrypted. After the encryption / decryption is completed, it is dispatched to a reasonable module through the data security module for storage and transmission.
[0084] As described above, the data dispatch module 18 can be used to implement data dispatch between the various modules of the network certificate parser. All dispatch steps are performed after the security check of the data security module 14 has passed. For example, the information to be identified is dispatched to the data security module. If the security check of the information to be identified has passed, the information to be identified is dispatched to the instruction parsing module. If the access parameter security check has passed, the access parameter is dispatched to the guidance parsing module, and the access parameter and the network certificate authentication platform identifier are dispatched to the external network communication module. If the authentication result security check has passed, the authentication result is dispatched to the network certificate parsing module and the script management execution module. Thus, through the configuration of the data dispatch module 18 and the data security module 14, the security of data input into the intranet and accessed into the network certificate parser is guaranteed, while the security of data output to the external network is also guaranteed.
[0085] The online certificate authentication platform accessed by the online certificate parser 10 provided in the embodiment of the present invention includes an online certificate parsing service platform or a person-certificate verification service platform, wherein it can also be a person-code verification platform in a person-code verification mode that combines the online certificate parsing mode with the person-certificate verification mode, that is, after performing online certificate parsing of the QR code, personal information is obtained by parsing, and further person-certificate verification is performed.
[0086] Optionally, the above-mentioned network certificate parser 10 also includes a working mode control module 21, which can be used to set the working mode of the network certificate parser 10, for example, including device setting mode, network certificate parsing mode, personal certificate verification mode and personal code decoding mode.
[0087] The above-mentioned external network communication module 13 can use wired network, wireless network, WIFI, 2G, 3G, 4G, 5G, 6G and other communication methods that can connect to the Internet to connect to the external network, and the internal communication module 11 can use USB, Bluetooth, serial port, Lightning, PCI-e, SATA and other communication methods to communicate.
[0088] The network certificate parser provided in the above scheme, through the verification of the data security module at each stage, ensures that internal users cannot privately modify the access target address of the network certificate parser, prevent access to unsafe servers, prevent network attacks, virus intrusions, Trojan horse implants, and prevent internal users from stealing data and confidential information; executes the corresponding script through the script management execution module, so that the network certificate parser can communicate with different network certificate authentication platforms to achieve the effect of interconnection; ensures that the result information data is only transmitted between the network certificate parser and the network certificate resolution server, without passing through a third party, to ensure the security of the result information data; when the result information data returned by the network certificate authentication platform is received, the corresponding parsing script is executed to decrypt the result information data and adjust the data format to achieve the effect of intercommunication and compatibility; the data format can be adjusted to be consistent with the data format of the second-generation certificate reader to achieve the purpose of compatibility with the second-generation certificate reader; through the host driver reusing the communication link of the second-generation certificate reader, the second-generation certificate reader and the network certificate parser can be used simultaneously on the same computer, reducing the trouble of purchasing computer equipment and reducing the risks and troubles brought by modifying the business system; the external network communication module and the internal The communication module does not use the same communication method, which prevents data collusion from the hardware, prevents data from the network from directly entering the host, and protects the network security of the host; the data scheduling module schedules the data input from the external network to the data security module, further preventing the data from directly entering the system core, protecting the network security of the network certificate parser itself, and preventing hacker intrusion; the data scheduling module schedules the data from the system core to the internal communication module, and the data security module performs another data security check on the data to prevent data that endangers the security of the computer after decryption. The data input from the external network communication module can enter the host after two data security checks and two schedules, further strengthening the information security of the host; when the data security module receives data from the external network communication module, it will look for the corresponding request data source. If there is no corresponding request data source, it will be regarded as an illegal access and the data will be ignored. In the form of question and answer, hacker intrusion is prevented; the face information data is formatted to determine whether it is a valid image format, and the face information data is subjected to face detection to determine whether it contains face information and whether the face information is legal, preventing internal users from stealing internal confidential data.
[0089] Figure 2 A flow chart of a data identification method provided by an embodiment of the present invention is as follows: Figure 2Shown, including:
[0090] Step S201: Acquire information to be identified, and perform security verification on the information to be identified.
[0091] Step S202: If the security check passes, perform instruction analysis on the information to be identified and generate access parameters based on the instruction analysis result.
[0092] Step S203: Perform security verification on the access parameters. If the security verification passes, determine the network certificate authentication platform for the access parameters, and send the access parameters to the network certificate authentication platform, so that the network certificate authentication platform generates and sends authentication results based on the access parameters.
[0093] Step S204: Receive the authentication result sent by the online authentication platform, where the authentication result includes an authentication platform identifier.
[0094] Step S205: Perform a security check on the authentication result. If the security check passes, determine the corresponding parsing script based on the authentication platform identifier, and parse the authentication result using the parsing script to obtain result data in a unified data format.
[0095] As can be seen from the above, by obtaining the information to be identified, a security check is performed on the information to be identified; if the security check passes, the information to be identified is subjected to instruction analysis and access parameters are generated based on the instruction analysis results; the access parameters are subjected to security verification, and if the security verification passes, the network certificate authentication platform of the access parameters is determined, and the access parameters are sent to the network certificate authentication platform, for the network certificate authentication platform to generate and send authentication results based on the access parameters; the authentication result sent by the network certificate authentication platform is received, and the authentication result includes an authentication platform identifier; the authentication result is subjected to security verification, and if the security verification passes, the corresponding parsing script is determined according to the authentication platform identifier, and the authentication result is parsed and processed by the parsing script to obtain result data in a unified data format. The above scheme can support information authentication in different types of expressions, and realizes cross-domain and cross-departmental network certificate parsing functions. At the same time, it ensures network and data security, and while preventing hacker, virus, and Trojan attacks, it can also prevent internal personnel from stealing data through the present invention.
[0096] Figure 3 A schematic diagram of a network certificate parser usage scenario provided by an embodiment of the present invention, such as Figure 3As shown, Internet 305 is the Internet, i.e., the external network; network certificate resolver 301, guided resolution server 306, network certificate resolution server 307, network certificate resolution server 308, and network certificate resolution server 309 are connected to Internet 305; computer 302 and QR code scanner 303 located on the intranet are connected to network certificate resolver 301; smartphone 304 displays the app's network certificate QR code; and network certificate resolver 301 presets network certificate resolution server 308 as the default network certificate resolution server. The guided resolution server analyzes the network certificate QR code to determine whether it is legitimate. Based on the information in the network certificate QR code, it queries the corresponding network certificate resolution server and returns the URL and access permission parameters of the relevant network certificate resolver. The network certificate resolver parses the network certificate QR code information into result information or performs identity verification and returns the corresponding result. The result information protects personal information and identity verification results. Personal information includes, but is not limited to, ID number, name, photo, gender, date of birth, address, ID validity period, phone number, online ID, employer, work ID, position, real estate information, credit history, and other data. A QR code scanner 303 scans the online certificate QR code displayed on the app on smartphone 304. When the online certificate parser 301 directly accesses a pre-set online certificate parsing server based on the online certificate QR code, it sends the QR code to the online certificate parsing server 308. The server 308 parses the QR code into result information and returns it to the parser 301. The parser 301 then sends the result information to the computer 302, completing the online certificate parsing process. When the network certificate parser 301 cannot directly access the preset network certificate resolution server based on the information of the network certificate QR code, the network certificate parser 301 sends the network certificate QR code information to the guide resolution server 306; the guide resolution server 306 queries the corresponding network certificate resolution server based on the information of the network certificate QR code, assuming it is the network certificate resolution server 309, and returns the website address and access permission parameters of the relevant network certificate resolution server 309; after the network certificate parser 301 receives the website address and access permission parameters of the website address resolution server, the network certificate parser 301 sends the network certificate QR code information to the network certificate resolution server 309, and the network certificate resolution server 309 resolves the network certificate QR code information into result information and returns it to the network certificate parser 301, and then the network certificate parser 301 sends the result information to the computer 302, thereby completing the resolution of the network certificate.
[0097] Figure 4 A structural diagram of a data identification device provided by an embodiment of the present invention is shown in FIG. Figure 4 As shown, the device includes a processor 401, a memory 402, an input device 403 and an output device 404; the number of processors 401 in the device can be one or more. Figure 4In the embodiment, a processor 401 is used as an example; the processor 401, the memory 402, the input device 403 and the output device 404 in the device can be connected by a bus or other means. Figure 4 The example of the connection via bus is taken. The memory 402, as a computer-readable storage medium, can be used to store software programs, computer executable programs and modules, such as the program instructions / modules corresponding to the game agent control method based on the directed node tree in the embodiment of the present invention. The processor 401 executes various functional applications and data processing of the device by running the software programs, instructions and modules stored in the memory 402, that is, realizes the above-mentioned game agent control method based on the directed node tree. The input device 403 can be used to receive input digital or character information, and generate key signal input related to the user settings and function control of the device. The output device 404 may include a display device such as a display screen.
[0098] An embodiment of the present invention further provides a storage medium containing computer-executable instructions, wherein the computer-executable instructions, when executed by a computer processor, are used to perform a data identification method, the method comprising:
[0099] Obtaining information to be identified, and performing security verification on the information to be identified;
[0100] If the security check passes, performing instruction analysis on the information to be identified and generating access parameters based on the instruction analysis result;
[0101] Performing a security check on the access parameters, and if the security check passes, determining a network authentication platform for the access parameters, and sending the access parameters to the network authentication platform, so that the network authentication platform generates and sends an authentication result based on the access parameters;
[0102] Receiving an authentication result sent by the online authentication platform, the authentication result including an authentication platform identifier;
[0103] A security check is performed on the authentication result. If the security check passes, a corresponding parsing script is determined according to the authentication platform identifier, and the authentication result is parsed by the parsing script to obtain result data in a unified data format.
[0104] Through the above description of the implementation methods, those skilled in the art can clearly understand that the embodiments of the present invention can be implemented with the help of software and necessary general-purpose hardware, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the embodiments of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., including a number of instructions for enabling a computer device (which can be a personal computer, service, or network device, etc.) to execute the methods described in each embodiment of the embodiments of the present invention.
[0105] It is worth noting that in the above-mentioned embodiment based on an Internet certificate resolver device supporting interconnection and interoperability, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the embodiments of the present invention.
[0106] Note that the above are only preferred embodiments of the present invention and the technical principles used. Those skilled in the art will understand that the embodiments of the present invention are not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the embodiments of the present invention. Therefore, although the embodiments of the present invention are described in more detail through the above embodiments, the embodiments of the present invention are not limited to the above embodiments. Without departing from the concept of the embodiments of the present invention, the embodiments of the present invention may also include more other equivalent embodiments, and the scope of the embodiments of the present invention is determined by the scope of the appended claims.
Claims
1. A network certificate parser, characterized in that: It includes internal communication module, acquisition communication module, external network communication module, data security module, instruction analysis module, guidance parsing module, network certificate parsing module, data scheduling module and script management execution module, among which, The acquisition communication module is used to collect information to be identified; The data security module is used to perform security verification on the information to be identified; The instruction analysis module is used to, if the information to be identified passes the security check, perform instruction analysis on the information to be identified to obtain an instruction type, extract information of a corresponding preset field of the information to be identified according to the instruction type to obtain guidance information, generate local access parameters based on the guidance information if the guidance information is local guidance, and query the recorded network address table or determine the network address corresponding to the guidance information through a guidance resolution server if the guidance information is network guidance, and generate external network access parameters based on the network address; The data security module is also used to perform security verification on the access parameters; The guidance parsing module is used to determine the network certificate authentication platform of the access parameter if the access parameter security check passes; The external network communication module is used to send the access parameters to the network certificate authentication platform, so that the network certificate authentication platform generates and sends an authentication result based on the access parameters. The external network communication module is also used to receive the authentication result sent by the network certificate authentication platform, and the authentication result includes an authentication platform identifier; The data security module is also used to perform security verification on the authentication result; The network certificate parsing module is used to determine the corresponding parsing script according to the authentication platform identifier when the authentication result passes the security verification; The script management execution module is used to parse the authentication result according to the determined parsing script to obtain result data in a unified data format; The data dispatching module is used to dispatch the result data to the internal communication module for transmitting the result data.
2. The network certificate parser according to claim 1, characterized in that: The script management execution module is also used to: Before determining the corresponding parsing script according to the authentication platform identifier, configuring corresponding parsing scripts for different authentication platforms and recording the association between the authentication platform identifier and the corresponding parsing script, the configuration process includes adding, deleting, and modifying the parsing script when the script verification passes; The script management execution module is specifically used to: The authentication result is decrypted and the data format is changed through the parsing script.
3. The network certificate parser according to any one of claims 1-2, characterized in that: The data scheduling module is also used for: Dispatching the information to be identified to the data security module, and dispatching the information to be identified to the instruction analysis module if the information to be identified passes the security check; If the access parameter security check passes, dispatching the access parameter to the guidance parsing module, and dispatching the access parameter and the identifier of the network certificate authentication platform to the external network communication module; When the authentication result passes the security check, the authentication result is dispatched to the network certificate parsing module and the script management and execution module.
4. The network certificate parser according to any one of claims 1-2, characterized in that: The online certificate authentication platform includes an online certificate parsing service platform or a person-certificate verification service platform; the acquisition communication module is communicatively connected to the acquisition device, and the acquisition device includes any one or more of a code scanning device, a camera, an NFC device, a face information collector, a fingerprint information collector, and an iris collector; the information to be identified includes any one or more of string information, image information, and binary information; the online certificate parser and the acquisition device are an integrated integrated device, or two separate devices.
5. The network certificate parser according to any one of claims 1-2, characterized in that: The internal communication module is further configured to receive a read request sent by a communication-connected host device and feed back the result data to the host device.
6. The network certificate parser according to any one of claims 1-2, characterized in that: It also includes a working mode control module for setting the working mode of the network certificate parser, and the working mode includes a device setting mode, a network certificate parsing mode, a person certificate verification mode and a person code decoding mode.
7. A data identification method, applied to a network certificate parser, characterized in that: include: Obtaining information to be identified, and performing security verification on the information to be identified; If the security check passes, the information to be identified is subjected to instruction analysis to obtain an instruction type, and information of a corresponding preset field of the information to be identified is extracted according to the instruction type to obtain guidance information. If the guidance information is local guidance, local access parameters are generated based on the guidance information. If the guidance information is network guidance, the network address corresponding to the guidance information is determined by querying a recorded network address table or using a guidance resolution server, and external network access parameters are generated based on the network address. Performing a security check on the access parameters, and if the security check passes, determining a network authentication platform for the access parameters, and sending the access parameters to the network authentication platform, so that the network authentication platform generates and sends an authentication result based on the access parameters; Receiving an authentication result sent by the online authentication platform, the authentication result including an authentication platform identifier; A security check is performed on the authentication result. If the security check passes, a corresponding parsing script is determined according to the authentication platform identifier, and the authentication result is parsed by the parsing script to obtain result data in a unified data format.
8. The data identification method according to claim 7, characterized in that: Before determining the corresponding parsing script according to the authentication platform identifier, the method further includes: Configure corresponding parsing scripts for different authentication platforms and record the association between the authentication platform identifier and the corresponding parsing script. The configuration process includes adding, deleting, and modifying the parsing script when the script passes verification. The parsing of the authentication result by the parsing script includes: The authentication result is decrypted and the data format is changed through the parsing script.
9. A data identification device, comprising: one or more processors; A storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, enables the one or more processors to implement the data identification method according to any one of claims 7-8.
10. A storage medium comprising computer-executable instructions, wherein the computer-executable instructions are used to perform the data identification method according to any one of claims 7 to 8 when executed by a computer processor.
Citation Information
Patent Citations
Identity authentication platform and method fusing multi-platform identity information
CN116915482A