A ukey certificate-based collaborative signature cross-channel opening method and system
By recording the binding relationship between device information and customer information in the collaborative signature system, the problem of device and customer identity binding and verification is solved, ensuring the security of the collaborative signature process, preventing attackers from impersonating customers to sign, and protecting customer assets.
Patent Information
- Application Number
- CN202410496321.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-04-24
AI Technical Summary
Existing collaborative signature systems cannot verify the binding relationship between devices and customer identities during the activation process, allowing attackers to download certificates to non-customer devices, impersonate customer identities to sign, and cause asset loss.
The system obtains authorization for customer device and customer information by signing the customer's information with a ukey certificate on the bank's client, generates an authentication message and signs it, and the collaborative signing server records the binding relationship between the device information and customer information to verify the binding relationship and ensure security.
It enables effective binding and verification of device information and customer information during the collaborative signature process, preventing attackers from impersonating customers to sign and protecting the security of customer assets.
Smart Images

Figure CN118413362B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present specification relate to the technical field of information security, and particularly relate to a method and system for opening a cross-channel based on a ukey certificate collaborative signature. BACKGROUND
[0002] As a new type of safe and convenient to use file certificate product, collaborative signature has been gradually applied to mobile banking, Internet banking, bank-enterprise direct connection and other Internet banking channels to meet the needs of users for safe transactions, electronic contract signing, message encryption and the like. Compared with the traditional ukey, collaborative signature does not require additional carrying of equipment, does not require installation of additional software, and does not require opening of the positioning, Bluetooth or audio permissions of the mobile phone system on the mobile phone side, and is convenient to use and good in customer experience.
[0003] The opening process of collaborative signature mainly involves business systems, collaborative signature products and self-CA certificate services. The business system is divided into two parts, the client and the server, such as the front desk system, mobile banking, Internet banking, bank-enterprise direct connection and the like, which can authenticate the certificate signature and electronic signature result of the collaborative signature product held by the user, and provide services such as transfer transactions and electronic contract signing. The collaborative signature product includes two parts of the client SDK and the server. The private key corresponding to the collaborative signature product certificate is split into two parts, which are generated and stored in the client SDK and the server respectively. The signature result is signed by the two private key components and synthesized, wherein the client SDK is integrated into the client of the business system, such as the mobile banking APP, the Internet banking browser side and the bank-enterprise direct connection client. The CA certificate server provides certificate management services (such as certificate application, download, cancellation, update and the like).
[0004] However, the current collaborative signature requires the client to hold the device (such as the mobile banking app client) to open and download the client certificate. The opening process includes two steps: (1) authenticating the client identity; and (2) certificate download (the client and the server generate private key components and sign, organize PKCS10 certificate signature request, and apply for a certificate).
[0005] These two steps have a certain independence.
[0006] Currently, when authenticating the client identity, the collaborative signature system only verifies the device, and the business system only verifies the client identity. Currently, the binding relationship between the device and the client identity cannot be verified. Attackers can take advantage of the independence of the opening process steps and the technical defect that the binding relationship between the device and the client identity is not authenticated throughout the process to download the certificate of the collaborative signature product to a non-client device or an unauthorized device, thereby impersonating the client identity in subsequent business processes (such as transfer transactions, electronic contract signing and the like), resulting in loss of client assets.
[0007] How to avoid the attack of the independence of the opening process steps and the technical defects of the binding relationship between the unauthenticated device and the customer identity in the whole process, and download the certificate of the co-signature product to the non-customer device or unauthorized device, thereby impersonating the customer identity to sign in the subsequent business process (such as transfer transaction, electronic contract signing, etc.), causing the loss of customer assets is a technical problem to be solved at present. SUMMARY
[0008] To solve the problem of the loss of customer assets caused by the impersonation of the customer identity to sign by the attacker due to the independence of the opening process steps of the co-signature and the binding relationship between the unauthenticated device and the customer identity in the whole process, the embodiments of the present specification provide a co-signature cross-channel opening method and system based on ukey certificate, in the opening process of co-signature, the authorization of the customer to the sending device information and customer information is obtained through the ukey certificate signing on the bank client, the device information and customer information are sent to the co-signature system, and the co-signature system records the binding relationship between the device information and the customer information, so as to verify the device information and the customer information in the co-signature process, and ensure the security of the customer assets.
[0009] In order to solve any one of the above technical problems, the specific technical solutions of the embodiments of the present specification are as follows:
[0010] On the one hand, the embodiments of the present specification provide a co-signature cross-channel opening method based on ukey certificate, comprising:
[0011] After the co-signature bank end receives the co-signature opening request sent by the bank client, an identification code is generated, and the identification code is sent to the bank client, and the co-signature opening request includes customer information;
[0012] The co-signature client sends the device information of the co-signature client to the co-signature bank end through the identification code received by the bank client;
[0013] The co-signature bank end generates an authentication message including the device information and customer information, and sends the authentication message to the bank client;
[0014] The bank client calls the authorized ukey driver interface to sign the authentication message, and sends the signed authentication message to the co-signature bank end;
[0015] After the co-signature bank end verifies the signed authentication message, the device information and customer information are sent to the co-signature service end;
[0016] The cooperative signature server stores the binding relationship of the device information and the customer information, and generates a cooperative signature certificate, so that the cooperative signature server verifies the target customer information and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service corresponding to the cooperative signature certificate, and completes the cooperative signature service after verification.
[0017] Further, before the cooperative signature client sends the device information of the cooperative signature client to the cooperative signature bank end through the identification code received by the bank client, the method further comprises:
[0018] The cooperative signature client logs in the cooperative signature bank end through the customer information.
[0019] Further, before the cooperative signature client sends the device information of the cooperative signature client to the cooperative signature bank end through the identification code, the method further comprises:
[0020] The cooperative signature bank end compares whether the customer information logged in by the cooperative signature client and the customer information in the cooperative signature opening request are consistent, and if consistent, allows the cooperative signature client to send the device information of the cooperative signature client to the cooperative signature bank end through the identification code.
[0021] Further, the method further comprises:
[0022] The cooperative signature client and the cooperative signature server negotiate a session key;
[0023] The cooperative signature client sends the device information of the cooperative signature client to the cooperative signature bank end through the identification code further comprises:
[0024] The cooperative signature client encrypts the device information through the negotiated session key, and sends the device information ciphertext to the cooperative signature bank end through the identification code;
[0025] The cooperative signature bank end generates an authentication message including the device information and the customer information further comprises:
[0026] The cooperative signature bank end generates the authentication message including the device information ciphertext and the customer information;
[0027] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end sends the device information and the customer information to the cooperative signature server further comprises:
[0028] The cooperative signature bank end verifies the authentication message with the signature, and sends the device information and the customer information to the cooperative signature service end after verification.
[0029] The cooperative signature service end stores the binding relationship between the device information and the customer information, and further includes:
[0030] The cooperative signature service end decrypts the device information using the session key, and stores the binding relationship between the customer information and the decrypted device information.
[0031] Further, the cooperative signature bank end generates an authentication message including the device information and the customer information, and further includes:
[0032] The cooperative signature bank end encrypts the customer information to obtain customer information ciphertext, and generates an authentication message including the device information and the customer information ciphertext.
[0033] The cooperative signature bank end verifies the authentication message with the signature, and sends the device information and the customer information to the cooperative signature bank end after verification, and further includes:
[0034] The cooperative signature bank end verifies the authentication message with the signature, and sends the device information and the customer information ciphertext to the cooperative signature service end after verification.
[0035] The cooperative signature service end stores the binding relationship between the device information and the customer information, and further includes:
[0036] The cooperative signature service end stores the binding relationship between the device information and the customer information ciphertext.
[0037] The method further includes:
[0038] When processing the cooperative signature service, the cooperative signature bank end encrypts the target customer information corresponding to the cooperative signature certificate to obtain target customer information ciphertext, and sends the cooperative signature service based on the target customer information ciphertext, so that the cooperative signature service uses the recorded binding relationship to verify the target customer information ciphertext and the target device information in the cooperative signature service when processing the cooperative signature service.
[0039] Further, the cooperative signature bank end verifies the authentication message with the signature, and the step includes:
[0040] The cooperative signature bank end compares whether the device information and the customer information in the authentication message with the signature are consistent with the device information and the customer information in the generated authentication message.
[0041] Further, before the collaborative signature client sends the device information of the collaborative signature client to the collaborative signature bank end through the identification code, the method further comprises:
[0042] The collaborative signature client calls the client SDK issued by the collaborative signature bank end to obtain the device information.
[0043] Further, after the collaborative signature bank end verifies the signed authentication message, the method further comprises:
[0044] The collaborative signature bank end saves the signed authentication message, so as to subsequently use the signed authentication message to prove the behavior of authorizing the customer to open the collaborative signature on the collaborative signature client.
[0045] On the other hand, the embodiments of the present specification also provide a collaborative signature cross-channel opening system based on a ukey certificate, the system comprising: a collaborative signature bank end, a bank client, a collaborative signature client, and a collaborative signature service end;
[0046] When the collaborative signature bank end, the bank client, the collaborative signature client, and the collaborative signature service end open the collaborative signature, the above-mentioned method is executed.
[0047] On the other hand, the embodiments of the present specification also provide a computer device, comprising a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to realize the above-mentioned method.
[0048] On the other hand, the embodiments of the present specification also provide a computer readable storage medium, the computer readable storage medium stores a computer program, and the computer program is executed by the processor to realize the above-mentioned method.
[0049] Finally, the embodiments of the present specification also provide a computer program product, the computer program product comprises a computer program, and the computer program is executed by the processor to realize the above-mentioned method.
[0050] With the embodiments of the present specification, in the face of a scenario in which a ukey cannot communicate with a co-signature client for opening a co-signature (for example, a function-limited ukey or a business-limited ukey), the embodiments of the present specification initiate a co-signature opening request to a co-signature bank end through a bank client capable of communicating with the ukey. Since opening a co-signature requires obtaining device information of the co-signature client, the co-signature bank end of the embodiments of the present specification generates an identification code for receiving the device information, sends the identification code to the bank client initiating the co-signature opening request, the bank client provides the identification code to the co-signature client requiring opening of the co-signature, and the system signature client sends its own device information to the co-signature bank end through the identification code.
[0051] The co-signature bank end generates an authentication message according to the device information and the client information in order to obtain the authorization of the client, sends the authentication message to the bank client, and after the client authorizes on the bank client, the bank client calls the authorized ukey driver interface to sign the authentication message, indicating that the client has authorized the co-signature bank end to send the device information and the client information to the co-signature service end, and finally the co-signature service end records the binding relationship between the device information and the client information, so that when processing the co-signature business, the co-signature service end can verify the binding relationship between the device information and the client information.
[0052] The embodiments of the present specification realize the organic combination between the co-signature bank end only authenticating the client identity and the co-signature service end only authenticating the device information, break the authentication barrier between the two, and enable the co-signature service end to verify the binding relationship between the device information and the client information when processing the co-signature business. Even if an attacker downloads the certificate of the co-signature product to a non-client device or a non-authorized device, the attacker cannot pass the binding relationship verification of the co-signature service end, thereby avoiding the attacker from using the client identity for signing (for example, transfer transaction, electronic contract signing, etc.), and avoiding the loss of client assets. BRIEF DESCRIPTION OF DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present specification, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0054] Figure 1 An implementation system schematic diagram of a co-signature cross-channel opening method based on a ukey certificate in the embodiments of the present specification is shown;
[0055] Figure 2A flowchart of a ukey certificate-based collaborative signature cross-channel opening method is shown in the embodiment of the present specification.
[0056] Figure 3 A processing flowchart of encrypting device information is shown in the embodiment of the present specification.
[0057] Figure 4 A processing flowchart of encrypting customer information is shown in the embodiment of the present specification.
[0058] Figure 5 A download flowchart of a collaborative signature certificate is shown in the embodiment of the present specification.
[0059] Figure 6 A usage (certificate signature verification) flowchart of a collaborative signature certificate is shown in the embodiment of the present specification.
[0060] Figure 7 A data flow diagram of a ukey certificate-based collaborative signature cross-channel opening system is shown in the embodiment of the present specification.
[0061] Figure 8 A structural diagram of a computer device is shown in the embodiment of the present specification.
[0062]
Explanation of reference numerals
[0063] 101, collaborative signature client;
[0064] 102, collaborative signature bank end;
[0065] 103, bank client;
[0066] 104, collaborative signature service end;
[0067] 802, computer device;
[0068] 804, processing device;
[0069] 806, storage resource;
[0070] 808, driving mechanism;
[0071] 810, input / output module;
[0072] 812, input device;
[0073] 814, output device;
[0074] 816, presentation device;
[0075] 818, graphical user interface;
[0076] 820, network interface;
[0077] 822, a communication link;
[0078] 824, a communication bus. DETAILED DESCRIPTION
[0079] The technical solutions in the embodiments of the present specification will be described clearly and completely below in combination with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only part of the embodiments of the present specification, rather than all the embodiments. Based on the embodiments in the embodiments of the present specification, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the embodiments of the present specification.
[0080] It should be noted that the terms "first", "second" and the like in the description and claims of the embodiments of the present specification and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the embodiments of the present specification described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product or equipment including a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.
[0081] It should be noted that the acquisition, storage, use, processing and the like of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.
[0082] As Figure 1 shown is an implementation system schematic diagram of a ukey certificate-based collaborative signature cross-channel opening method in the embodiments of the present specification, including a collaborative signature client 101, a collaborative signature bank end 102, a bank client 103 and a collaborative signature service end 104. The collaborative signature client 101 and the collaborative signature bank end 102, the collaborative signature bank end 102 and the bank client 103, and the collaborative signature bank end 102 and the collaborative signature service end 104 can communicate through a network, which can include a local area network (Local Area Network, LAN for short), a wide area network (Wide Area Network, WAN for short), the Internet or a combination thereof, and be connected to a website, a user device (such as a computing device) and a backend system.
[0083] The collaborative signature client 101 and the collaborative signature bank end 102 perform collaborative signature, the collaborative signature server 104 is used for processing collaborative signature business, such as generating collaborative signature certificate, etc., and the two parts of private key components are stored on the collaborative signature client 101 and the collaborative signature bank end 102 respectively. The collaborative signature client 101 can be a mobile bank app client, the collaborative signature bank end 102 can be a bank business system, and the collaborative signature server 104 can be a collaborative signature business processing system.
[0084] The bank client 103 can be a net bank client / browser. In a cross-channel scenario, the ukey cannot communicate with the mobile bank app client of which the collaborative signature is opened, for example, the ukey does not support Bluetooth, audio function, or due to business restrictions, the ukey can only be used on the specified net bank client / browser, and cannot be used in the scenario of the mobile bank app client. In this scenario, the bank client 103 initiates the collaborative signature opening application, and the user authorization is performed through the ukey of the bank client 103.
[0085] Optionally, the collaborative signature bank end 102 or the collaborative signature server 104 can be a node (not shown in the figure) of a cloud computing system, or each server can be a separate cloud computing system, including multiple computers interconnected by a network and working as a distributed processing system.
[0086] In addition, it should be noted that, Figure 1 The shown is only one application environment provided by the embodiment of the present specification, in actual application, the collaborative signature client 101 can also be a broker end or an enterprise end, etc., and the method of the embodiment of the present specification can also be applied to the collaborative signature opening in the scenario of a broker or an enterprise, and the present specification is not limited.
[0087] In view of the problems in the prior art, the embodiment of the present specification provides a collaborative signature cross-channel opening method based on a ukey certificate, in the opening process of the collaborative signature, the authorization of the client to the sending device information and the client information is obtained through the ukey certificate signing on the bank client, the device information and the client information are sent to the collaborative signature system, and the collaborative signature system records the binding relationship between the device information and the client information, so that the device information and the client information are verified in the collaborative signature process, and the security of the client asset is ensured.
[0088] Figure 2 The shown is a flowchart of a collaborative signature cross-channel opening method based on a ukey certificate according to an embodiment of the present specification.
[0089] The process of opening cross-channel joint signature is described in the figure. The order of steps listed in the embodiment is only one of the many step execution orders, not the only execution order. In actual system or device product execution, it can be executed in sequence or in parallel according to the method shown in the embodiment or the figure. Specifically, as shown in Figure 2 The method can include:
[0090] Step 201: After the joint signature bank end receives the joint signature opening request sent by the bank client, the joint signature bank end generates an identification code and sends the identification code to the bank client, and the joint signature opening request includes customer information;
[0091] Step 202: The joint signature client sends the device information of the joint signature client to the joint signature bank end through the identification code received by the bank client;
[0092] Step 203: The joint signature bank end generates an authentication message including the device information and customer information, and sends the authentication message to the bank client;
[0093] Step 204: The bank client calls the authorized ukey driver interface to sign the authentication message, and sends the signed authentication message to the joint signature bank end;
[0094] Step 205: After the joint signature bank end verifies the signed authentication message, the joint signature bank end sends the device information and customer information to the joint signature service end;
[0095] Step 206: The joint signature service end stores the binding relationship of the device information and customer information, and generates a joint signature certificate, so that the joint signature service end uses the recorded binding relationship to verify the target customer information and target device information in the joint signature business when processing the joint signature business corresponding to the joint signature certificate, and completes the joint signature business after verification.
[0096] In the face of the scene that the ukey cannot communicate with the joint signature client opening joint signature (for example, function-limited ukey or business-limited ukey), the bank client capable of communicating with the ukey initiates a joint signature opening request to the joint signature bank end through the embodiment of the present specification. Since joint signature opening needs to obtain the device information of the joint signature client, the joint signature bank end of the embodiment generates an identification code for receiving device information, sends the identification code to the bank client initiating the joint signature opening request, the bank client provides the identification code to the joint signature client needing to open joint signature, and the joint signature client sends its own device information to the joint signature bank end through the identification code.
[0097] In the embodiment of the present specification, to avoid the technical defects of the independence of the opening process steps and the unbinding relationship between the unauthenticated device and the customer identity for the whole process, the certificate of the co-signing product is downloaded to a non-customer device or an unauthorized device, so that the customer identity is used to sign in the subsequent business process. The most direct method is to verify the binding relationship between the customer identity and the device information in the co-signing server during co-signing, so as to avoid the problem that the non-customer device or the unauthorized device uses the stolen certificate of the co-signing product and uses the customer identity to sign.
[0098] However, the co-signing system and the business system are independent, and the current co-signing opening process does not send the customer identity to the co-signing system. If the customer identity is to be sent to the co-signing system, the authorization of the customer should be obtained. The business system obtains the authorization of the customer to send the customer identity and the device information to the co-signing system, which is a prerequisite for the co-signing system to verify the binding relationship between the customer identity and the device.
[0099] In order to obtain the authorization of the customer, the co-signing bank side generates an authentication message according to the device information and the customer information, sends the authentication message to the bank client, and after the customer authorizes on the bank client, the bank client calls the authorized ukey driver interface to sign the authentication message, indicating that the customer has authorized the co-signing bank side to send the device information and the customer information to the co-signing server. Finally, the co-signing server records the binding relationship between the device information and the customer information, so that when processing the co-signing business, the co-signing server can verify the binding relationship between the device information and the customer information.
[0100] The embodiment of the present specification realizes the organic combination between the co-signing bank side authenticating only the customer identity and the co-signing server authenticating only the device information, breaks the authentication barrier between the two, and enables the co-signing server to verify the binding relationship between the device information and the customer information when processing the co-signing business. Even if the attacker downloads the certificate of the co-signing product to a non-customer device or an unauthorized device, it is also impossible to pass the binding relationship verification of the co-signing server, so as to avoid the problem that the attacker uses the customer identity to sign (such as transfer transaction, electronic contract signing, etc.), and avoid the loss of customer assets.
[0101] In the embodiment of the present specification, the customer can use the existing ukey certificate to perform identity authentication and device information collection and signing on the online banking client, without going to the bank branch to open the co-signing certificate product of the mobile banking APP client, thereby improving the convenience of the overall business of the bank and the customer experience.
[0102] In the embodiment of the present specification, the ukey implementation file realizes the secure distribution between the specified users. When the file is sent, the encryption is automatically performed by the ukey operation chip, and the ukey ID of the specified file receiver is specified, so that the file receiver can easily open the ukey encrypted file. At the same time, the client signs the authentication message through the ukey, which indicates that the client has signed the online collaborative signature opening intention, thereby ensuring the security of the collaborative signature opening process.
[0103] Illustratively, the client inserts the ukey of the usb interface into the specified online banking client computer, and then the online banking client / browser calls the ukey drive interface inserted by the client to sign the authentication message.
[0104] According to one embodiment of the present specification, before the collaborative signature client sends the device information of the collaborative signature client to the collaborative signature bank end through the identification code received by the bank client, the method further comprises:
[0105] The collaborative signature client logs in the collaborative signature bank end through the client information.
[0106] In the embodiment of the present specification, the client initiating the collaborative signature opening request can be consistent with the client corresponding to the collaborative signature client. For example, the company opens the collaborative signature for the mobile banking app client of the employee, and then logs in the collaborative signature bank end (i.e. business system) through the identity information of the employee on the online banking client / browser specified by the company, sends a collaborative signature opening request to the collaborative signature bank end, and at the same time, the employee logs in the business system through his own identity information on his own mobile banking app client.
[0107] In some other embodiments of the present specification, the client initiating the collaborative signature opening request can also be inconsistent with the client corresponding to the collaborative signature client. For example, the company opens the collaborative signature for the mobile banking app client of the employee, and then logs in the collaborative signature bank end (i.e. business system) through the identity information of the company administrator on the online banking client / browser specified by the company, sends a collaborative signature opening request to the collaborative signature bank end and attaches the identity information of the employee, and at the same time, the employee logs in the business system through his own identity information on his own mobile banking app client.
[0108] However, it should be noted that in the cross-channel scenario of the embodiment of the present specification, the collaborative signature client needs to verify whether the client information logged in by the mobile banking app client is consistent with the client information in the collaborative opening request, regardless of the above-mentioned manner. Specifically, according to one embodiment of the present specification, before the collaborative signature client sends the device information of the collaborative signature client to the collaborative signature bank end through the identification code, the method further comprises:
[0109] The collaborative signature bank end compares whether the customer information logged in by the collaborative signature client and the customer information in the collaborative signature opening request are consistent, and if consistent, allows the collaborative signature client to send the device information of the collaborative signature client to the collaborative signature bank end through the identification code.
[0110] In the embodiments of the present specification, the collaborative signature bank end can only proceed with the subsequent opening of the collaborative signature when verifying that the customer information logged in by the collaborative signature client and the customer information in the collaborative signature opening request are consistent, thereby avoiding that the corresponding customer of the collaborative signature client system is maliciously lured, and a criminal uses a public account to log in to the collaborative signature bank end on the online banking client / browser to open the collaborative signature of the lured customer, causing property loss of the lured customer.
[0111] In the embodiments of the present specification, the identification code can be a two-dimensional code or a bar code, and the embodiments of the present specification are not limited thereto.
[0112] In the embodiments of the present specification, the collaborative signature client and the collaborative signature server can also transmit information through ciphertext to avoid that the customer information or the device information is stolen in the transmission process. Specifically, according to one embodiment of the present specification, as shown in Figure 3 The method further includes:
[0113] Step 301: The collaborative signature client and the collaborative signature server negotiate a session key;
[0114] The collaborative signature client sends the device information of the collaborative signature client to the collaborative signature bank end through the identification code further includes:
[0115] Step 302: The collaborative signature client encrypts the device information through the negotiated session key, and sends the device information ciphertext to the collaborative signature bank end through the identification code;
[0116] The collaborative signature bank end generates an authentication message including the device information and the customer information further includes:
[0117] Step 303: The collaborative signature bank end generates the authentication message including the device information ciphertext and the customer information;
[0118] The collaborative signature bank end sends the device information and the customer information to the collaborative signature server after verifying the signed authentication message further includes:
[0119] Step 304: The collaborative signature bank end sends the device information ciphertext and the customer information to the collaborative signature server after verifying the signed authentication message.
[0120] The cooperative signature server stores the binding relationship between the device information and the customer information further comprising:
[0121] Step 305: The cooperative signature server decrypts the device information ciphertext using the session key, and stores the binding relationship between the customer information and the decrypted device information.
[0122] In the embodiment of the present specification, the cooperative signature client and the cooperative signature server are end-to-end encryption. After the cooperative signature client logs in the cooperative signature bank end through the customer information, the cooperative signature client can call the client SDK issued by the cooperative signature server to obtain the SDK information in encrypted form, generate a random number, upload the SDK information in encrypted form and submit a session key negotiation request, and then send the request to the cooperative signature server through the cooperative signature bank end. The cooperative signature server verifies the SDK information, negotiates the session key, and returns the result to the cooperative signature client.
[0123] Then the cooperative signature client encrypts the device information through the negotiated session key, and sends the device information ciphertext to the cooperative signature bank end through the identification code. In this step, the cooperative signature client can call the client SDK issued by the cooperative signature bank end to obtain the device information.
[0124] In the subsequent authentication message generation, signing and verification process, the device information ciphertext is used, so as to avoid the leakage of the device information. When the cooperative signature bank end verifies the signed authentication message, the device information ciphertext and the customer information are sent to the cooperative signature server. The cooperative signature server decrypts the device information ciphertext using the session key, and stores the binding relationship between the customer information and the decrypted device information.
[0125] In the subsequent cooperative signature business processing process, the cooperative signature client and the cooperative signature server can still use the end-to-end encryption method to encrypt the device information. The cooperative signature server decrypts the device information ciphertext and verifies the device information and the customer information through the binding relationship.
[0126] In the embodiment of the present specification, in addition to the device information, the customer information can also be encrypted, so as to avoid the leakage of the customer information.
[0127] Specifically, according to one embodiment of the present specification, as shown in Figure 4 The cooperative signature bank end generates an authentication message including the device information and the customer information further comprising:
[0128] Step 401: The cooperative signature bank end encrypts the client information to obtain client information ciphertext, and generates an authentication message including the device information and the client information ciphertext;
[0129] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end sends the device information and the client information to the cooperative signature service end for further processing, and the method further includes:
[0130] Step 402: After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end sends the device information and the client information ciphertext to the cooperative signature service end;
[0131] The cooperative signature service end stores the binding relationship between the device information and the client information, and the method further includes:
[0132] Step 403: The cooperative signature service end stores the binding relationship between the device information and the client information ciphertext.
[0133] The method further includes:
[0134] Step 404: When processing the cooperative signature service, the cooperative signature bank end encrypts the target client information corresponding to the cooperative signature certificate to obtain target client information ciphertext, and sends the cooperative signature service to the cooperative signature service end based on the target client information ciphertext, so that the cooperative signature service end verifies the target client information ciphertext and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service.
[0135] In the embodiments of the present specification, the encryption method of the client information can be transforming the client information into a client ID or calculating a hash value of the client information, and the embodiments of the present specification are not limited thereto.
[0136] It should be noted that in the subsequent processing process of the cooperative signature service, the client information can also be encrypted by the cooperative signature bank end, and the cooperative signature service is sent to the cooperative signature service end based on the target client information ciphertext, so that the cooperative signature service end verifies the target client information ciphertext and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service.
[0137] In actual implementation, the device information and the client information can also be encrypted according to the above method respectively, and the embodiments of the present specification are not limited thereto.
[0138] Specifically, the download process of the cooperative signature certificate can be as follows Figure 5As shown, the mobile banking app client sets a certificate password, generates a co-signing client private key component, collects device information, signs a PKCS10 request information, assembles and encrypts a to-be-co-signed message;
[0139] Then the mobile banking app client sends the to-be-co-signed message (including the certificate password, device information, client private key component, signature result, hash result component, etc.) to the co-signing bank end; the co-signing bank end assembles a co-signing message (including a serial number, client information (client ID or client information hash value), to-be-co-signed message, etc.);
[0140] Then the assembled co-signing message is sent to the co-signing service end, which parses the business message and decrypts the to-be-co-signed message, verifies the device information and client information, stores the certificate password, generates a service end private key component, signs the signature data, assembles a signature result certificate request PKCS10, and then is encrypted by a unified encryption platform;
[0141] Then a co-signing certificate is generated and bound with the client information, the certificate request PKCS10 is sent to the co-signing bank end, the co-signing bank end sends the client information certificate request PKCS10 to the CA certificate service to generate a certificate, then binds the certificate information and client information, and finally sends the certificate to the mobile banking app client.
[0142] The use (certificate signature verification) process of the co-signing certificate can be as shown in Figure 6 First, the mobile banking app client outputs a certificate password, decrypts a client private key component, signs a transaction message, collects device information, assembles and encrypts a co-signing message, and sends the to-be-co-signed message (ciphertext, including a key, device information, client private key component result, hash result component, etc.) to the co-signing bank end, the co-signing bank end assembles a signature business message (including a serial number, a password-free authentication identifier (optional), client information (client ID or client information hash value), to-be-co-signed message, etc.), sends the assembled signature business message to the co-signing service end, the co-signing service end parses the business message and decrypts the to-be-co-signed message, verifies the device information and client information and the certificate password, decrypts the private key component, signs the signature data, assembles the signature result, and sends the signature result to the co-signing bank end, which verifies the signature result by using a signature verification server.
[0143] It should be noted that the co-signing certificate download and use are common knowledge in the art, and will not be described in detail in this specification.
[0144] In the embodiments of the present specification, the step of verifying the signed authentication message by the co-signing bank end comprises:
[0145] The cooperative signature bank end compares the device information and the customer information in the authentication message with the device information and the customer information in the generated authentication message.
[0146] It can be understood that if the device information and the customer information in the authentication message issued by the cooperative signature bank end are inconsistent with the device information and the customer information in the authentication message signed by the ukey, it indicates that the device information or the customer information has been tampered with, and the bank client has a security risk, and the cooperative signature is stopped.
[0147] According to one embodiment of the present specification, after the cooperative signature bank end verifies the signed authentication message, the method further comprises:
[0148] The cooperative signature bank end saves the signed authentication message, so as to subsequently use the signed authentication message to prove the behavior of the customer authorizing the opening of the cooperative signature on the cooperative signature client.
[0149] In the embodiments of the present specification, the storage period of the signed authentication message of the cooperative signature bank end can be set according to actual needs, for example, at least 5 years. The authentication message includes customer information and device information, and the certificate in the ukey has anti-repudiation for the signing result of the authentication message, which not only authenticates the customer identity, but also authenticates the authorized device, and in subsequent judicial disputes, an evidence chain can be provided to prove that the customer authorizes the opening of the cooperative signature on the device.
[0150] Based on the same inventive concept, the embodiments of the present specification also provide a ukey certificate-based cooperative signature cross-channel opening system, which comprises a cooperative signature bank end, a bank client, a cooperative signature client and a cooperative signature server. Figure 7 The data flow diagram of the ukey certificate-based cooperative signature cross-channel opening system is shown, which can include the following steps:
[0151] Step 701: The bank client submits a login request to the cooperative signature bank end;
[0152] Step 702: The cooperative signature bank end verifies the customer login information;
[0153] Step 703: The cooperative signature bank end returns a login success result to the bank client;
[0154] Step 704: The bank client submits a cooperative signature opening request to the cooperative signature bank end;
[0155] Step 705: The cooperative signature bank end organizes two-dimensional code data for collecting mobile device feature information;
[0156] Step 706: The cooperative signature bank end returns the two-dimensional code data to the bank client;
[0157] Step 707: The bank client displays the two-dimensional code;
[0158] Step 708: The co-signing client submits a login request to the co-signing bank end;
[0159] Step 709: The co-signing bank end verifies the client login information;
[0160] Step 710: The co-signing bank end returns a login success result to the co-signing client;
[0161] In this step, the client information of the co-signing client needs to be consistent with the client information in the co-signing request.
[0162] Step 711: The co-signing client reads the SDK information through the co-signing client SDK issued by the co-signing system;
[0163] Step 712: The co-signing client SDK organizes the SDK information ciphertext;
[0164] Step 713: The co-signing client SDK returns the SDK information ciphertext to the co-signing client;
[0165] Step 714: The co-signing client uploads the SDK information in ciphertext form to the co-signing bank end;
[0166] Step 715: The co-signing bank end sends the SDK information ciphertext to the co-signing service end;
[0167] Step 716: The co-signing service end verifies the SDK information;
[0168] Step 717: The co-signing service end negotiates the session key;
[0169] Step 718: The co-signing service end returns the authentication and session key negotiation result to the co-signing bank end;
[0170] Step 719: The co-signing bank end returns the authentication and session key negotiation result to the co-signing client;
[0171] The session key is used for encrypted transmission of the device information of the co-signing client, etc.
[0172] Step 720: The co-signing client scans the two-dimensional code of the bank client;
[0173] Step 721: The co-signing client calls the co-signing client SDK to obtain device information;
[0174] Step 722: The co-signing client SDK organizes the device information;
[0175] Step 723: The co-signature client SDK returns the device information ciphertext to the co-signature client;
[0176] Step 724: The co-signature client sends the device information plaintext to the co-signature bank end and submits a device authentication application;
[0177] Step 725: The co-signature bank end organizes an authentication message according to the device information ciphertext and the client information ciphertext;
[0178] Step 726: The co-signature bank end returns the authentication message to the bank client;
[0179] Step 727: The bank client calls the authorized ukey driver interface to sign the authentication message;
[0180] Step 728: The bank client sends the signed authentication message to the co-signature bank end;
[0181] Step 729: The co-signature bank end verifies the signed authentication message;
[0182] Step 730: After verification, the co-signature bank end sends the device information ciphertext and the client information ciphertext to the co-signature service end;
[0183] Step 731: The co-signature service end decrypts the device information and stores the binding relationship between the device information and the client information;
[0184] Step 732: The co-signature service end returns the authentication result to the co-signature bank end;
[0185] Step 733: The co-signature bank end returns the authentication result to the co-signature client.
[0186] Since the principle of solving the problem of the above system is similar to the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described.
[0187] As Figure 8 The structure schematic diagram of the computer device of the embodiment of the present specification is shown, the system in the present application can be the computer device in the present embodiment, and the method of the present application is executed. The computer device 802 can include one or more processing devices 804, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads.
[0188] The computer device 802 can also include any storage resource 806 for storing any kind of information such as code, settings, data, etc.
[0189] Without limitation, for example, the storage resources 806 can include any one or combination of: any type of RAM, any type of ROM, a flash device, a hard disk, an optical disk, etc.
[0190] More generally, any storage resource can store information using any technology.
[0191] Further, any storage resource can provide volatile or non-volatile retention of information.
[0192] Further, any storage resource can represent a fixed or removable component of the computer device 802.
[0193] In one case, the computer device 802 can perform any of the operations associated with the instructions stored in any storage resource or combination of storage resources when the processing device 804 executes the associated instructions. The computer device 802 also includes one or more drive mechanisms 808, such as a hard drive mechanism, an optical disk drive mechanism, etc., for interacting with any storage resource.
[0194] The computer device 802 can further include an input / output module 810 (I / O) for receiving various inputs (via input devices 812) and for providing various outputs (via output devices 814). One particular output mechanism can include a presentation device 816 and an associated graphical user interface (GUI) 818. In other embodiments, the input / output module 810 (I / O), the input devices 812, and the output devices 814 can not be included, and the computer device 802 can merely be a computer device in a network. The computer device 802 can also include one or more network interfaces 820 for exchanging data with other devices via one or more communication links 822. One or more communication buses 824 couple the above-described components together.
[0195] The communication links 822 can be implemented in any manner, such as through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication links 822 can include any combination of hardwired links, wireless links, routers, gateway functionality, name servers, etc., governed by any protocol or combination of protocols.
[0196] The embodiments of the present specification also provide a computer readable storage medium, the computer readable storage medium stores a computer program, the computer program is executed by a processor to implement the above method.
[0197] The embodiments of the present specification also provide a computer readable instruction, wherein when the processor executes the instruction, the program in the processor makes the processor execute the above method.
[0198] It should be understood that the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0199] It should also be understood that in the embodiments of the present application, the term "and / or" only describes the association relationship of the associated objects, and means that there can be three relationships. For example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in the embodiments of the present application generally represents that the front and rear associated objects are in an "or" relationship.
[0200] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present application can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been described in the above description.
[0201] Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present application.
[0202] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0203] In several embodiments provided by the embodiments of the present application, it should be understood that the disclosed system, device and method can be implemented in other ways.
[0204] For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0205] In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other form of connection.
[0206] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units.
[0207] Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present specification.
[0208] In addition, each functional unit in each embodiment of the present specification can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0209] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium.
[0210] Based on this understanding, the technical solutions of the embodiments of the present specification or the entire or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product, which is stored in a storage medium and includes instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in each embodiment of the present specification.
[0211] And the aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0212] The principles and implementation manners of the embodiments of the present specification are described in the specific embodiments in the present specification, and the above embodiment descriptions are only used to help understand the method and its core idea of the present specification; at the same time, for those skilled in the art, according to the idea of the present specification, the specific implementation manner and application range will be changed, and the above description should not be understood as a limitation of the present specification.
Claims
1. A ukey certificate-based collaborative signature cross-channel opening method, characterized in that, The method comprises: After receiving the co-signing opening request sent by the bank client, the co-signing bank end generates an identification code and sends the identification code to the bank client, wherein the co-signing opening request comprises customer information; The co-signing client sends the device information of the co-signing client to the co-signing bank end through the identification code received by the bank client; The co-signing bank end generates an authentication message comprising the device information and the customer information, and sends the authentication message to the bank client; The bank client calls the authorized ukey driver interface to sign the authentication message, and sends the signed authentication message to the co-signing bank end; After verifying the signed authentication message, the co-signing bank end sends the device information and the customer information to the co-signing service end; The co-signing service end stores the binding relationship between the device information and the customer information, and generates a co-signing certificate, so that when processing the co-signing business corresponding to the co-signing certificate, the co-signing service end verifies the target customer information and the target device information in the co-signing business by using the recorded binding relationship, and completes the co-signing business after verification.
2. The method of claim 1, wherein, Before the co-signing client sends the device information of the co-signing client to the co-signing bank end through the identification code received by the bank client, the method further comprises: The co-signing client logs in the co-signing bank end through the customer information.
3. The method of claim 2, wherein, Before the co-signing client sends the device information of the co-signing client to the co-signing bank end through the identification code, the method further comprises: The co-signing bank end compares whether the customer information logged in by the co-signing client and the customer information in the co-signing opening request are consistent, and if consistent, allows the co-signing client to send the device information of the co-signing client to the co-signing bank end through the identification code.
4. The method of claim 1, wherein, The method further comprises: The co-signing client and the co-signing service end negotiate a session key; The co-signing client sends the device information of the co-signing client to the co-signing bank end through the identification code further comprises: The co-signing client encrypts the device information through the negotiated session key, and sends the device information ciphertext to the co-signing bank end through the identification code; The co-signing bank end generates an authentication message comprising the device information and the customer information further comprises: The co-signing bank end generates the authentication message comprising the device information ciphertext and the customer information; After verifying the signed authentication message, the co-signing bank end sends the device information and the customer information to the co-signing service end further comprises: After verifying the signed authentication message, the co-signing bank end sends the device information ciphertext and the customer information to the co-signing service end; The cooperative signature server further stores the binding relationship between the device information and the customer information. The cooperative signature server decrypts the device information ciphertext by using the session key, and stores the binding relationship between the customer information and the decrypted device information.
5. The method according to claim 1 or 4, characterized in that, The cooperative signature bank end further generates the authentication message including the device information and the customer information. The cooperative signature bank end encrypts the customer information to obtain customer information ciphertext, and generates the authentication message including the device information and the customer information ciphertext. The cooperative signature bank end further sends the device information and the customer information to the cooperative signature bank end after the verification of the signed authentication message. The cooperative signature bank end further sends the device information and the customer information ciphertext to the cooperative signature server after the verification of the signed authentication message. The cooperative signature server further stores the binding relationship between the device information and the customer information. The cooperative signature server further stores the binding relationship between the device information and the customer information ciphertext. The method further includes: When processing the cooperative signature service, the cooperative signature bank end encrypts the target customer information corresponding to the cooperative signature certificate to obtain target customer information ciphertext, and sends the cooperative signature service to the cooperative signature server based on the target customer information ciphertext, so that the cooperative signature server verifies the target customer information ciphertext and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service.
6. The method of claim 1, wherein, The step of verifying the signed authentication message by the cooperative signature bank end includes: The cooperative signature bank end compares whether the device information and the customer information in the signed authentication message are consistent with the device information and the customer information in the generated authentication message.
7. The method of claim 1, wherein, The method further includes: The cooperative signature client calls the client SDK issued by the cooperative signature bank end to obtain the device information.
8. The method of claim 1, wherein, The method further includes: The cooperative signature bank end saves the signed authentication message, so as to subsequently use the signed authentication message to prove the behavior of authorizing the customer to open the cooperative signature on the cooperative signature client. 9.A ukey certificate based co-signature cross-channel onboarding system, characterized in that, The system includes a cooperative signature bank end, a bank client, a cooperative signature client, and a cooperative signature server. When the cooperative signature bank end, the bank client, the cooperative signature client, and the cooperative signature server open the cooperative signature, the method of any one of claims 1-8 is executed.
10. A computer device comprising a memory, a processor, and a computer program stored on the memory, wherein, The processor executes the computer program to implement the method of any one of claims 1-8.
11. A computer readable storage medium characterized by, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method of any one of claims 1-8. The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method of any one of claims 1-8.
12. A computer program product, characterised in that, The computer program product comprises a computer program which, when executed by a processor, implements the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Secure login method and device of terminal equipment and nonvolatile storage medium
CN115883104A
Collaborative signature enhanced authentication method and enhanced authentication system
CN117544318A