A ukey certificate-based collaborative signature opening method and system

By using ukey certificates for signing, the binding relationship between device and customer information is recorded in the collaborative signature system. This solves the problem of insufficient verification of the binding relationship between device and customer identity in existing technologies, realizes secure verification of device and customer information, prevents attackers from impersonating customers to sign, and improves system security and convenience.

CN118473715BActive Publication Date: 2025-12-16CHINA CITIC BANK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410496319.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-24
Publication Date
2025-12-16
Estimated Expiration
2044-04-24

AI Technical Summary

Technical Problem

Existing collaborative signature systems cannot verify the binding relationship between devices and customer identities during the activation process. This allows attackers to download the certificate of the collaborative signature product to non-customer devices, impersonate the customer to sign, and cause loss of customer assets.

Method used

Authorization for obtaining device and customer information is achieved through ukey certificate signing. The collaborative signature system records the binding relationship between device and customer information and verifies it during the signing process to ensure the consistency of device and customer information.

Benefits of technology

It enables the verification of the binding relationship between device information and customer information during the collaborative signature process, preventing attackers from impersonating customers to sign, avoiding the loss of customer assets, and improving the security and convenience of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118473715B_ABST
    Figure CN118473715B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of ukey certificate-based collaborative signature opening method and system;Collaborative signature client obtains equipment information, generates collaborative signature opening request according to equipment information and customer information and sends to collaborative signature bank end;Collaborative signature bank end generates authentication message including equipment information and customer information, and sends to collaborative signature client;Collaborative signature client calls authorized ukey driver interface and signs authentication message, and sends to collaborative signature bank end;Collaborative signature bank end verifies signed authentication message, and after passing, equipment information and customer information are sent to collaborative signature service end;Collaborative signature service end stores the binding relationship of equipment information and customer information, and generates collaborative signature certificate.Through the embodiment of the present application, the binding relationship between equipment information and customer information is recorded in collaborative signature system, so that equipment information and customer information are verified in collaborative signature process, and the security of customer assets is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present specification relate to the technical field of information security, and particularly relate to a ukey certificate-based collaborative signature opening method and system. BACKGROUND

[0002] As a new type of safe and convenient-to-use file certificate product, collaborative signature has been gradually applied to mobile banking, Internet banking, bank-enterprise direct connection and other Internet banking channels to meet the needs of users for safe transaction transfer, electronic contract signing, message encryption and the like. Compared with the traditional ukey, collaborative signature does not require additional carrying of equipment, does not require installation of additional software, and does not require opening of the positioning, Bluetooth or audio permissions of the mobile phone system on the mobile phone side, and is convenient to use and good in customer experience.

[0003] The opening process of collaborative signature mainly involves business systems, collaborative signature products and self-CA certificate services. The business system is divided into two parts, a client and a server, such as a counter system, mobile banking, Internet banking, bank-enterprise direct connection and the like, which can authenticate the certificate signature and electronic signature result in the collaborative signature product held by the user and provide transfer transaction, electronic contract signing and the like. The collaborative signature product includes a client SDK and a server, and the private key corresponding to the collaborative signature product certificate is split into two parts, which are generated and stored in the client SDK and the server respectively, and the signature result is signed by the two parts of the private key and synthesized, wherein the client SDK is integrated in the client of the business system, such as the mobile banking APP, the Internet banking browser side and the bank-enterprise direct connection client, and the CA certificate server provides certificate management services (such as certificate application, download, cancellation, update and the like).

[0004] However, the current collaborative signature needs the client to hold the equipment (such as the mobile banking app client) to open and download the client certificate, and the opening process includes two steps: (1) authenticating the client identity; and (2) certificate download (the client and the server generate private key components and sign, organize PKCS10 certificate signature request, and apply for a certificate). These two steps have a certain independence. At present, when authenticating the client identity, the collaborative signature system only verifies the equipment, and the business system only verifies the client identity, and the binding relationship between the equipment and the client identity cannot be verified at present. Attackers can take advantage of the independence of the opening process steps and the technical defect that the binding relationship between the equipment and the client identity is not authenticated throughout the process to download the certificate of the collaborative signature product to a non-client equipment or an unauthorized equipment, thereby impersonating the client identity to sign in the subsequent business process (such as transfer transaction, electronic contract signing and the like), causing loss of client assets.

[0005] How to avoid the attack of opening process steps of independence and technical defects of the binding relationship between the whole process of unauthenticated device and customer identity, the certificate of the co-signature product is downloaded to the non-customer device or unauthorized device, thereby the customer identity is used to sign in the subsequent business process (such as transfer transaction, electronic contract signing, etc.), causing the loss of customer assets is a technical problem to be solved. SUMMARY

[0006] To solve the problem of the loss of customer assets caused by the attack of opening process steps of independence and technical defects of the binding relationship between the whole process of unauthenticated device and customer identity, the certificate of the co-signature product is downloaded to the non-customer device or unauthorized device, thereby the customer identity is used to sign in the subsequent business process (such as transfer transaction, electronic contract signing, etc.), the embodiment of the present specification provides a co-signature opening method and system based on ukey certificate, in the opening process of co-signature, the authorization of the customer to the sending device information and the customer information is obtained by the ukey certificate signing method, the device information and the customer information are sent to the co-signature system, the co-signature system records the binding relationship between the device information and the customer information, thereby verifying the device information and the customer information in the co-signature process, and ensuring the security of customer assets.

[0007] In order to solve any one of the above technical problems, the specific technical solutions of the embodiment of the present specification are as follows:

[0008] On the one hand, the embodiment of the present specification provides a co-signature opening method based on ukey certificate, comprising,

[0009] The co-signature client obtains its own device information, and generates a co-signature opening request according to the device information and the customer information;

[0010] The co-signature client sends the co-signature opening request to the co-signature bank end;

[0011] The co-signature bank end generates an authentication message including the device information and the customer information, and sends the authentication message to the co-signature client;

[0012] The co-signature client calls the authorized ukey driver interface to sign the authentication message, and sends the signed authentication message to the co-signature bank end;

[0013] After the co-signature bank end verifies the signed authentication message, the device information and the customer information are sent to the co-signature service end;

[0014] The cooperative signature server stores the binding relationship of the device information and the customer information, and generates a cooperative signature certificate, so that the cooperative signature server verifies the target customer information and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service corresponding to the cooperative signature certificate, and completes the cooperative signature service after verification.

[0015] Further, before the cooperative signature client generates the cooperative signature opening request according to the device information and the customer information, the method further comprises:

[0016] The cooperative signature client logs in the cooperative signature bank end according to the customer information;

[0017] Before the cooperative signature bank end generates the authentication message including the device information and the customer information, the method further comprises:

[0018] The cooperative signature bank end verifies whether the logged-in customer information is consistent with the customer information in the cooperative signature opening request, and if consistent, generates the authentication message including the device information and the customer information.

[0019] Further, the method further comprises:

[0020] The cooperative signature client and the cooperative signature server negotiate a session key;

[0021] After the cooperative signature client obtains the device information of the cooperative signature client, the method further comprises:

[0022] The cooperative signature client encrypts the device information by the negotiated session key, so as to generate the cooperative signature opening request according to the device information ciphertext and the customer information;

[0023] The cooperative signature bank end generates the authentication message including the device information and the customer information further comprises:

[0024] The cooperative signature bank end generates the authentication message including the device information ciphertext and the customer information;

[0025] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end further comprises:

[0026] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end further comprises:

[0027] The cooperative signature server stores the binding relationship of the device information and the customer information further comprises:

[0028] The cooperative signature server decrypts the device information ciphertext by using the session key, and stores the binding relationship between the customer information and the decrypted device information.

[0029] Further, the cooperative signature bank end generating the authentication message including the device information and the customer information further includes:

[0030] The cooperative signature bank end encrypts the customer information to obtain customer information ciphertext, and generates an authentication message including the device information and the customer information ciphertext.

[0031] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end further includes:

[0032] After the cooperative signature bank end verifies the signed authentication message, the cooperative signature bank end sends the device information and the customer information ciphertext to the cooperative signature server.

[0033] The cooperative signature server storing the binding relationship between the device information and the customer information further includes:

[0034] The cooperative signature server stores the binding relationship between the device information and the customer information ciphertext.

[0035] The method further includes:

[0036] When processing the cooperative signature service, the cooperative signature bank end encrypts the target customer information corresponding to the cooperative signature certificate to obtain target customer information ciphertext, and sends the cooperative signature service to the cooperative signature server based on the target customer information ciphertext, so that the cooperative signature server verifies the target customer information ciphertext and the target device information in the cooperative signature service by using the recorded binding relationship when processing the cooperative signature service.

[0037] Further, the step of the cooperative signature bank end verifying the signed authentication message includes:

[0038] The cooperative signature bank end compares whether the device information and the customer information in the signed authentication message are consistent with the device information and the customer information in the generated authentication message.

[0039] Further, the cooperative signature client obtaining its own device information further includes:

[0040] The cooperative signature client calls the client SDK issued by the cooperative signature server to obtain the device information.

[0041] Further, after the cooperative signature bank end verifies the authentication message with the added signature, the method further includes:

[0042] The cooperative signature bank end saves the authentication message with the added signature, so as to subsequently prove that the customer authorizes the opening of the cooperative signature on the cooperative signature client.

[0043] In another aspect, the embodiments of the present specification also provide a cooperative signature opening system based on a ukey certificate, the system including a cooperative signature bank end, a cooperative signature client, and a cooperative signature service end.

[0044] When the cooperative signature bank end, the cooperative signature client, and the cooperative signature service end open the cooperative signature, the above method is executed.

[0045] In another aspect, the embodiments of the present specification also provide a computer device including a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to implement the above method.

[0046] In another aspect, the embodiments of the present specification also provide a computer readable storage medium storing a computer program, and the computer program is executed by a processor to implement the above method.

[0047] Finally, the embodiments of the present specification also provide a computer program product including a computer program, and the computer program is executed by a processor to implement the above method.

[0048] By using the embodiments of the present specification, in the case that the ukey can communicate with the cooperative signature client opening the cooperative signature (for example, a function-supported ukey or a business-supported ukey), the cooperative signature client of the embodiments of the present specification obtains the device information of itself, generates a cooperative signature opening request according to the device information and the customer information, and directly initiates the cooperative signature opening request to the cooperative signature bank end, so that the cooperative signature bank end can directly obtain the device information and the customer information. In order to obtain the customer authorization, the cooperative signature bank end generates an authentication message according to the device information and the customer information, sends the authentication message to the cooperative signature client, and after the customer authorizes on the cooperative signature client, the cooperative signature client calls the authorized ukey drive interface to add a signature to the authentication message, indicating that the customer has authorized the cooperative signature bank end to send the device information and the customer information to the cooperative signature service end, and finally the cooperative signature service end records the binding relationship between the device information and the customer information, so that when processing the cooperative signature business, the cooperative signature service end can verify the binding relationship between the device information and the customer information.

[0049] The embodiment of the present specification realizes the organic combination between the bank end of the cooperative signature only authenticating the customer identity and the service end of the cooperative signature only authenticating the device information, breaks the authentication barrier of the two, and can make the cooperative signature service end verify the binding relationship between the device information and the customer information when processing the cooperative signature business, so that even if the attacker downloads the certificate of the cooperative signature product to a non-customer device or a non-authorized device, the attacker cannot pass the binding relationship verification of the cooperative signature service end, thereby avoiding the attacker using the customer identity for signature (such as transfer transaction, electronic contract signature, etc.), and avoiding the loss of customer assets. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present specification, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.

[0051] Figure 1 An implementation system schematic diagram of a ukey certificate-based cooperative signature opening method in the embodiment of the present specification is shown.

[0052] Figure 2 A flowchart schematic diagram of a ukey certificate-based cooperative signature opening method in the embodiment of the present specification is shown.

[0053] Figure 3 A flowchart schematic diagram of the cooperative signature client logging in the cooperative signature bank end in the embodiment of the present specification is shown.

[0054] Figure 4 A processing flowchart schematic diagram of encrypting the device information in the embodiment of the present specification is shown.

[0055] Figure 5 A processing flowchart schematic diagram of encrypting the customer information in the embodiment of the present specification is shown.

[0056] Figure 6 A download flowchart schematic diagram of the cooperative signature certificate in the embodiment of the present specification is shown.

[0057] Figure 7 A use (certificate signature verification) flowchart schematic diagram of the cooperative signature certificate in the embodiment of the present specification is shown.

[0058] Figure 8 A data flow diagram of a ukey certificate-based cooperative signature opening system in the embodiment of the present specification is shown.

[0059] Figure 9Fig. 1 shows a structural schematic diagram of a computer device in the embodiments of the present specification.

[0060] [Explanation of reference signs]

[0061] 101, co-signing client;

[0062] 102, co-signing bank side;

[0063] 103, co-signing server side;

[0064] 902, computer device;

[0065] 904, processing device;

[0066] 906, storage resource;

[0067] 908, driving mechanism;

[0068] 910, input / output module;

[0069] 912, input device;

[0070] 914, output device;

[0071] 916, presentation device;

[0072] 918, graphical user interface;

[0073] 920, network interface;

[0074] 922, communication link;

[0075] 924, communication bus. DETAILED DESCRIPTION

[0076] The technical solutions in the embodiments of the present specification will be described clearly and completely below in combination with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only part of the embodiments of the present specification, rather than all the embodiments of the present specification. Based on the embodiments in the embodiments of the present specification, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the embodiments of the present specification.

[0077] It should be noted that the terms "first", "second", etc. in the description and claims of the embodiments of the present specification and the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present specification described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product or apparatus that includes a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or apparatuses.

[0078] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0079] As Figure 1 shown is an implementation system schematic diagram of a ukey certificate-based collaborative signature opening method in an embodiment of the present specification, including a collaborative signature client 101, a collaborative signature bank end 102 and a collaborative signature server end 103. The collaborative signature client 101 and the collaborative signature bank end 102 and the collaborative signature bank end 102 and the collaborative signature server end 103 can communicate through a network, which can include a local area network (Local Area Network, LAN for short), a wide area network (Wide Area Network, WAN for short), the Internet or a combination thereof, and is connected to a website, a user device (such as a computing device) and a backend system.

[0080] The collaborative signature client 101 and the collaborative signature bank end 102 perform collaborative signature, and the collaborative signature server end 103 is used to process collaborative signature business, such as generating a collaborative signature certificate, etc., and stores two parts of private key components on the collaborative signature client 101 and the collaborative signature bank end 102 respectively. The collaborative signature client 101 can be a mobile bank app client, the collaborative signature bank end 102 can be a bank business system, and the collaborative signature server end 103 can be a collaborative signature business processing system.

[0081] When the ukey can communicate with the mobile bank app client that opens the collaborative signature, the collaborative signature client 101 initiates the collaborative signature opening application, and the user authorization is performed through the ukey that directly communicates with the collaborative signature client 101.

[0082] Optionally, the co-signing bank end 102 or the co-signing service end 103 can be a node of a cloud computing system (not shown in the figure), or each server can be a separate cloud computing system, including multiple computers interconnected by a network and working as a distributed processing system.

[0083] In addition, it should be noted that, Figure 1 The shown is only an application environment provided by the embodiment of the present specification, and in actual application, the co-signing client 101 can also be a broker end or an enterprise end, etc., and the method of the embodiment of the present specification can also be applied to co-signing opening in the scenarios of brokers or enterprises, which is not limited by the present specification.

[0084] In view of the problems in the prior art, the embodiment of the present specification provides a co-signing opening method based on a ukey certificate. In the co-signing opening process, the authorization of a client to send device information and client information is obtained through the ukey certificate signing on the co-signing client initiating the co-signing, the device information and the client information are sent to the co-signing system, and the co-signing system records the binding relationship between the device information and the client information, so as to verify the device information and the client information in the co-signing process, and ensure the security of the client's assets.

[0085] Figure 2 The shown is a flowchart of a co-signing opening method based on a ukey certificate according to an embodiment of the present specification. In the present figure, the process of opening co-signing is described. The order of steps listed in the embodiment is only one of the many step execution orders, and does not represent the only execution order. In actual system or device product execution, the method order shown in the embodiment or the figure can be executed in sequence or in parallel. Specifically, as Figure 2 As shown, the method can include:

[0086] Step 201: The co-signing client obtains its own device information, and generates a co-signing opening request according to the device information and the client information;

[0087] Step 202: The co-signing client sends the co-signing opening request to the co-signing bank end;

[0088] Step 203: The co-signing bank end generates an authentication message including the device information and the client information, and sends the authentication message to the co-signing client;

[0089] Step 204: The co-signing client calls the authorized ukey driver interface to sign the authentication message, and sends the signed authentication message to the co-signing bank end;

[0090] Step 205: After the collaborative signature bank verifies the signed authentication message, it sends the device information and customer information to the collaborative signature server.

[0091] Step 206: The collaborative signature server stores the binding relationship between the device information and the customer information, and generates a collaborative signature certificate. This allows the collaborative signature server to verify the target customer information and target device information in the collaborative signature business using the recorded binding relationship when processing the collaborative signature business corresponding to the collaborative signature certificate. Once the verification is successful, the collaborative signature business is completed.

[0092] Using the embodiments of this specification, in scenarios where a ukey can communicate with a collaborative signature client that has enabled collaborative signature (e.g., a ukey that supports functionality or business), the collaborative signature client in the embodiments of this specification obtains its own device information, generates a collaborative signature activation request based on the device information and customer information, and directly initiates a collaborative signature activation request to the collaborative signature bank, so that the collaborative signature bank can directly obtain the device information and customer information.

[0093] To obtain customer authorization, the bank generates an authentication message based on device and customer information and sends it to the collaborative signature client. After the customer authorizes the authentication message on the collaborative signature client, the client calls the authorized ukey driver interface to sign the authentication message, indicating that the customer has authorized the bank to send the device and customer information to the collaborative signature server. Finally, the collaborative signature server records the binding relationship between the device and customer information, thus enabling the server to verify the binding relationship between device and customer information when processing collaborative signature transactions.

[0094] In the embodiments of this specification, to prevent attackers from exploiting the independence of the activation process steps and the technical flaws in the binding relationship between unauthenticated devices and customer identities throughout the process to download the certificate of the collaborative signature product to non-customer devices or unauthorized devices, and then impersonate the customer's identity to sign in subsequent business processes, the most direct method is to have the collaborative signature server verify the binding relationship between the customer's identity and device information during collaborative signing. This will prevent non-customer devices or unauthorized devices from using stolen certificates of the collaborative signature product and impersonating the customer's identity to sign.

[0095] However, the collaborative signature system and the business system are independent of each other. The current collaborative signature activation process does not send the customer's identity to the collaborative signature system. If the customer's identity is to be sent to the collaborative signature system, the customer's authorization must be obtained.

[0096] The business system obtains the authorization of the customer to send the customer identity and the device information to the collaborative signature system, which is a prerequisite for the collaborative signature system to verify the binding relationship between the customer identity and the device.

[0097] In order to obtain the authorization of the customer, the collaborative signature bank end generates an authentication message according to the device information and the customer information, sends the authentication message to the collaborative signature client, and after the customer authorizes on the collaborative signature client, the collaborative signature client calls the authorized ukey driver interface to sign the authentication message, indicating that the customer has authorized the collaborative signature bank end to send the device information and the customer information to the collaborative signature server. Finally, the collaborative signature server records the binding relationship between the device information and the customer information, so that when processing the collaborative signature business, the collaborative signature server can verify the binding relationship between the device information and the customer information.

[0098] The embodiment of the present specification realizes the organic combination between the collaborative signature bank end authenticating only the customer identity and the collaborative signature server authenticating only the device information, breaks the authentication barrier of the two, and enables the collaborative signature server to verify the binding relationship between the device information and the customer information when processing the collaborative signature business. Even if an attacker downloads the certificate of the collaborative signature product to a non-customer device or an unauthorized device, the attacker cannot pass the binding relationship verification of the collaborative signature server, thereby avoiding the attacker from using the customer identity for signature (such as transfer transaction, electronic contract signature, etc.), and avoiding the loss of customer assets.

[0099] In the embodiment of the present specification, the customer can use the existing ukey certificate to perform identity authentication and device information collection and signing on the collaborative signature client (such as a mobile bank app client) of the customer, without going to a bank branch to open a collaborative signature certificate product of the mobile bank APP client, thereby improving the convenience of the overall business of the bank and the customer experience.

[0100] In the embodiment of the present specification, the ukey implementation file is securely distributed among designated users. When the file is sent, the ukey operation chip automatically encrypts and specifies the ukey ID of the file recipient. In this way, the file recipient can easily open the ukey encrypted file. At the same time, after the customer signs the authentication message through the ukey, it indicates that the customer has signed the intention to open the collaborative signature online, thereby ensuring the security of the opening process of the collaborative signature.

[0101] For example, the customer connects the ukey of the Bluetooth interface, the ukey of the WiFi interface, or the ukey of the audio interface to the mobile bank app client, and then the mobile bank app client calls the ukey driver interface inserted by the customer to sign the authentication message.

[0102] According to one embodiment of the present specification, as Figure 3As shown, before the collaborative signature client generates a collaborative signature opening request according to the device information and the customer information, the method further comprises:

[0103] Step 301: The collaborative signature client logs in the collaborative signature bank end according to the customer information;

[0104] Before the collaborative signature bank end generates an authentication message including the device information and the customer information, the method further comprises:

[0105] Step 302: The collaborative signature bank end verifies whether the customer information logged in is consistent with the customer information in the collaborative signature opening request, and if consistent, generates an authentication message including the device information and the customer information.

[0106] In the embodiments of the present specification, the customer initiating the collaborative signature opening request can be consistent with the customer corresponding to the individual signature client, for example, the customer opens the collaborative signature through the mobile phone bank app client, connects the ukey to the mobile phone bank app client, logs in the collaborative signature client (i.e. business system) through the identity information, and then the mobile phone bank app client generates a collaborative signature opening request according to the device information of the device obtained and the customer information logged in.

[0107] In the embodiments of the present specification, the collaborative signature client needs to verify whether the customer information logged in by the mobile phone bank app client is consistent with the customer information in the collaborative opening request, and if consistent, generates an authentication message including the device information and the customer information.

[0108] In the embodiments of the present specification, the collaborative signature client and the collaborative signature service end can also transmit information through ciphertext to avoid the customer information or device information being stolen in the transmission process. Specifically, according to one embodiment of the present specification, as shown in the following table, the method further comprises: Figure 4

[0109] Step 401: The collaborative signature client and the collaborative signature service end negotiate a session key;

[0110] The collaborative signature client sends the device information of the collaborative signature client to the collaborative signature bank end through the identification code further comprises:

[0111] Step 402: The collaborative signature client encrypts the device information through the negotiated session key, and sends the device information ciphertext to the collaborative signature bank end through the identification code;

[0112] The collaborative signature bank end generates an authentication message including the device information and the customer information further comprises: ​

[0113] Step 403: the co-signing bank end generates the authentication message including the device information ciphertext and the customer information;

[0114] After the co-signing bank end verifies the signed authentication message, the device information and the customer information are sent to the co-signing service end for further including:

[0115] Step 404: after the co-signing bank end verifies the signed authentication message, the device information ciphertext and the customer information are sent to the co-signing service end;

[0116] The co-signing service end stores the binding relationship of the device information and the customer information further including:

[0117] Step 405: the co-signing service end decrypts the device information ciphertext using the session key, and stores the binding relationship between the customer information and the decrypted device information.

[0118] In the embodiment of the present application, the co-signing client and the co-signing service end are end-to-end encrypted, and after the co-signing client logs in the co-signing bank end through the customer information, the co-signing client can call the client SDK issued by the co-signing service end to obtain the encrypted SDK information, generate a random number, upload the encrypted SDK information and submit a session key negotiation request, which is uploaded to the co-signing service end via the co-signing bank end. The co-signing service end verifies the SDK information, negotiates the session key, and returns the result to the co-signing client.

[0119] Then the co-signing client encrypts the device information using the negotiated session key, and sends the device information ciphertext directly to the co-signing bank end. In this step, the co-signing client can call the client SDK issued by the co-signing bank end to obtain the device information.

[0120] In the subsequent authentication message generation, signing and verification process, the device information ciphertext is used, thereby avoiding the leakage of device information. When the co-signing bank end verifies the signed authentication message, the device information ciphertext and the customer information are sent to the co-signing service end, the co-signing service end decrypts the device information ciphertext using the session key, and stores the binding relationship between the customer information and the decrypted device information.

[0121] In the subsequent co-signing business processing process, the co-signing client and the co-signing service end can still use the end-to-end encryption method to encrypt the device information, and the co-signing service end decrypts the device information ciphertext and verifies the device information and the customer information through the binding relationship.

[0122] In the embodiments of the present specification, in addition to the device information that can be encrypted, the customer information can also be encrypted to avoid leakage of customer information. Specifically, according to one embodiment of the present specification, as shown in Figure 5 The collaborative signature bank end generates the authentication message including the device information and the customer information further includes:

[0123] Step 501: The collaborative signature bank end encrypts the customer information to obtain customer information ciphertext, and generates an authentication message including the device information and the customer information ciphertext;

[0124] After the collaborative signature bank end verifies the signed authentication message, the device information and the customer information are sent to the collaborative signature service end further including:

[0125] Step 502: After the collaborative signature bank end verifies the signed authentication message, the device information and the customer information ciphertext are sent to the collaborative signature service end;

[0126] The collaborative signature service end stores the binding relationship of the device information and the customer information further including:

[0127] Step 503: The collaborative signature service end stores the binding relationship of the device information and the customer information ciphertext;

[0128] The method further includes:

[0129] Step 504: When processing the collaborative signature business, the collaborative signature bank end encrypts the target customer information corresponding to the collaborative signature certificate to obtain target customer information ciphertext, and sends the collaborative signature business to the collaborative signature service end based on the target customer information ciphertext, so that the collaborative signature service end verifies the target customer information ciphertext and the target device information in the collaborative signature business by using the recorded binding relationship when processing the collaborative signature business.

[0130] In the embodiments of the present specification, the encryption method of the customer information can be to transform the customer information into a customer ID or to calculate the hash value of the customer information, and the embodiments of the present specification are not limited.

[0131] It should be noted that in the subsequent processing process of the collaborative signature business, the customer information can also be encrypted by the collaborative signature bank end, and the collaborative signature business is sent to the collaborative signature service end based on the target customer information ciphertext, so that the collaborative signature service end verifies the target customer information ciphertext and the target device information in the collaborative signature business by using the recorded binding relationship when processing the collaborative signature business.

[0132] In actual implementation, the device information and the customer information can also be encrypted according to the above method respectively, and the embodiments of the present specification are not limited.

[0133] Specifically, the download process of the co-signature certificate can be as shown in Figure 6 , the mobile banking app client sets a certificate password, generates a co-signature client private key component, collects device information, signs PKCS10 request information, assembles and encrypts a to-be-co-signed message, and then the mobile banking app client sends the to-be-co-signed message (including the certificate password, the device information, the client private key component, the signature result, the hash result component, etc.) to the co-signature bank end; the co-signature bank end assembles a co-signature message (including a serial number, customer information (customer ID or customer information hash value), and the to-be-co-signed message), and then sends the assembled co-signature message to the co-signature service end, the co-signature service end analyzes the business message and decrypts the to-be-co-signed message, verifies the device information and the customer information, stores the certificate password, generates a service end private key component, signs the signature data, assembles a signature result certificate request PKCS10, and then is encrypted by a unified encryption platform, and then a co-signature certificate is generated and bound with the customer information, the certificate request PKCS10 is sent to the co-signature bank end, the co-signature bank end sends the customer information certificate request PKCS10 to the CA certificate service to generate a certificate, and then binds the certificate information and the customer information, and finally the certificate is sent to the mobile banking app client.

[0134] The use (certificate signature verification) process of the co-signature certificate can be as shown in Figure 7 , first, the mobile banking app client outputs a certificate password, decrypts a client private key component, signs a transaction message, collects device information, assembles and encrypts a co-signature message, and sends the to-be-co-signed message (ciphertext, including a key, device information, a client private key component result, a hash result component, etc.) to the co-signature bank end, the co-signature bank end assembles a signature business message (including a serial number, a password-free authentication identifier (optional), customer information (customer ID or customer information hash value), and the to-be-co-signed message), sends the assembled signature business message to the co-signature service end, the co-signature service end analyzes the business message and decrypts the to-be-co-signed message, verifies the device information and the customer information and the certificate password, decrypts the private key component, signs the signature data, assembles the signature result, and sends the signature result to the co-signature bank end, and the co-signature bank end verifies the signature result by using a signature verification server.

[0135] It should be noted that the co-signature certificate download and use are common knowledge in the art, and the present specification will not be repeated.

[0136] In the embodiments of the present specification, the step of verifying the signed authentication message by the co-signature bank end comprises:

[0137] The cooperative signature bank end compares the device information and the customer information in the authentication message with the device information and the customer information in the generated authentication message.

[0138] It can be understood that if the device information and the customer information in the authentication message issued by the cooperative signature bank end are inconsistent with the device information and the customer information in the authentication message signed by the ukey, it indicates that the device information or the customer information has been tampered with, and the cooperative signature client has a security risk, and the cooperative signature is stopped.

[0139] According to one embodiment of the present specification, after the cooperative signature bank end verifies the signed authentication message, the method further comprises:

[0140] The cooperative signature bank end saves the signed authentication message, so as to subsequently use the signed authentication message to prove the behavior of the customer authorized to open the cooperative signature on the cooperative signature client.

[0141] In the embodiments of the present specification, the storage period of the signed authentication message by the cooperative signature bank end can be set according to actual needs, for example, at least 5 years. The authentication message includes customer information and device information, and the certificate in the ukey has anti-repudiation for the signing result of the authentication message, which not only authenticates the customer identity, but also authenticates the authorized device, and in subsequent judicial disputes, an evidence chain can be provided to prove that the customer authorized to open the cooperative signature on the device.

[0142] Based on the same inventive concept, the embodiments of the present specification also provide a cooperative signature opening system based on a ukey certificate, which comprises a cooperative signature bank end, a cooperative signature client, and a cooperative signature service end. Figure 8 The data flow diagram of the cooperative signature cross-channel opening system based on the ukey certificate is shown, which comprises the following steps:

[0143] Step 801: The cooperative signature client submits a login request to the cooperative signature bank end.

[0144] Step 802: The cooperative signature bank end verifies the customer login information.

[0145] Step 803: The cooperative signature bank end returns a login success result to the cooperative signature client.

[0146] In this step, the cooperative signature client (i.e. the mobile bank app client) logs in the cooperative signature bank end (i.e. the business system) through customer information, the cooperative signature bank end verifies the login information, and returns a login success result to the cooperative signature client.

[0147] Then the collaborative signature client and the collaborative signature server perform session key negotiation;

[0148] Step 804: The collaborative signature client reads the SDK information through the collaborative signature client SDK issued by the collaborative signature server;

[0149] Step 805: The collaborative signature client SDK organizes the SDK information in an encrypted form;

[0150] Step 806: The collaborative signature client SDK returns the SDK information ciphertext to the collaborative signature client;

[0151] In this step, the collaborative signature client reads the SDK information through the collaborative signature client SDK issued by the collaborative signature server, obtains the SDK information in ciphertext form, and forwards the SDK information in ciphertext form to the collaborative signature server through the collaborative signature bank end;

[0152] Step 807: The collaborative signature client uploads the SDK information ciphertext to the collaborative signature bank end and initiates session key negotiation;

[0153] Step 808: The collaborative signature bank end sends the SDK information ciphertext and the session key negotiation to the collaborative signature server;

[0154] Step 809: The collaborative signature server verifies the SDK information;

[0155] Step 810: The collaborative signature performs session key negotiation;

[0156] Step 811: The collaborative signature server returns the authentication and session key negotiation result to the collaborative signature bank end;

[0157] Step 812: The collaborative signature bank end returns the authentication and session key negotiation result to the collaborative signature client;

[0158] In this step, the collaborative signature server verifies the SDK information and negotiates the session key, and sends the session key to the collaborative signature client through the collaborative signature bank end; the session key is used for encrypted transmission of the device information of the collaborative signature client and the like;

[0159] Step 813: The collaborative signature client calls the collaborative signature client SDK to obtain the device information;

[0160] Step 814: The collaborative signature client SDK organizes the device information;

[0161] Step 815: The collaborative signature client SDK returns the device information ciphertext to the collaborative signature server;

[0162] Step 816: The co-signing client sends the device information to the co-signing bank end;

[0163] Step 817: The co-signing bank end organizes an authentication message according to the device information ciphertext and the customer information ciphertext;

[0164] Step 818: The co-signing bank end sends the authentication message to the co-signing client;

[0165] Step 819: The co-signing client calls the authorized ukey driver interface to sign the authentication message;

[0166] Step 820: The co-signing client sends the signed authentication message to the co-signing bank end;

[0167] Step 821: The co-signing bank end verifies the signed authentication message;

[0168] Step 822: After verification, the co-signing bank end sends the device information ciphertext and the customer information ciphertext to the co-signing service end;

[0169] Step 823: The co-signing service end decrypts the pen information ciphertext, and stores the binding relationship between the device information and the customer information;

[0170] Step 824: The co-signing service end returns the result to the co-signing bank end;

[0171] Step 825: The co-signing bank end returns the result to the co-signing client.

[0172] Since the principle of solving the problem of the above system is similar to the above method, the implementation of the above device can be referred to the implementation of the above method, and the repeated parts will not be described.

[0173] As Figure 9A structural diagram of a computer device of an embodiment of the present specification is shown. The system in the embodiment of the present specification can be the computer device in the embodiment, which executes the method of the embodiment of the present specification. The computer device 902 can include one or more processing devices 904, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads. The computer device 902 can also include any storage resources 906 for storing any kind of information, such as code, settings, data, etc. Without limitation, for example, the storage resources 906 can include any one or combination of the following: any type of RAM, any type of ROM, flash memory devices, hard disks, optical disks, etc. More generally, any storage resource can store information using any technology. Further, any storage resource can provide volatile or non-volatile retention of information. Further, any storage resource can represent a fixed or removable component of the computer device 902. In one case, the computer device 902 can perform any operation of the associated instructions when the processing device 904 executes the associated instructions stored in any storage resource or combination of storage resources. The computer device 902 also includes one or more drive mechanisms 908, such as a hard disk drive mechanism, an optical disk drive mechanism, etc., for interacting with any storage resources.

[0174] The computer device 902 can also include an input / output module 910 (I / O) for receiving various inputs (via input devices 912) and for providing various outputs (via output devices 914). One particular output mechanism can include a presentation device 916 and an associated graphical user interface (GUI) 918. In other embodiments, the input / output module 910 (I / O), the input devices 912, and the output devices 914 can also not be included, just as a computer device in a network. The computer device 902 can also include one or more network interfaces 920 for exchanging data with other devices via one or more communication links 922. One or more communication buses 924 couple the above-described components together.

[0175] The communication links 922 can be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication links 922 can include any combination of hardwired links, wireless links, routers, gateway functionality, name servers, etc., governed by any protocol or combination of protocols.

[0176] The embodiment of the present specification also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the above method.

[0177] The embodiment of the present specification further provides a computer readable instruction, wherein when the processor executes the instruction, the program therein causes the processor to execute the method.

[0178] It should be understood that the magnitude of the sequence number of each process described above does not mean the order of execution in various embodiments of the embodiment of the present specification, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present specification.

[0179] It should also be understood that in the embodiment of the present specification, the term "and / or" is only to describe the association relationship of the associated objects, which means that there can be three relationships. For example, A and / or B can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " in the embodiment of the present specification generally represents that the associated objects before and after are in an "or" relationship.

[0180] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the disclosed embodiments in the embodiment of the present specification can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiment of the present specification.

[0181] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here.

[0182] In several embodiments provided by the embodiment of the present specification, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic, and the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed mutual objects can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other forms of connection.

[0183] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present specification.

[0184] In addition, each functional unit in each embodiment of the present specification can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0185] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present specification essentially or say the part of the prior art that contributes, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in each embodiment of the present specification. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0186] The principles and implementation manners of the embodiments of the present specification are described in the specific embodiments in the present specification, and the above embodiment description is only used to help understand the method and its core idea of the present specification; meanwhile, for those skilled in the art, according to the idea of the present specification, the specific implementation manner and application range will be changed, and the above description should not be understood as a limitation of the present specification.

Claims

1. A collaborative signature activation method based on a ukey certificate, characterized in that, The method includes: The collaborative signature client obtains its own device information and generates a collaborative signature activation request based on the device information and customer information; The collaborative signature client sends the collaborative signature activation request to the collaborative signature bank. The collaborative signature bank generates an authentication message including the device information and customer information, and sends the authentication message to the collaborative signature client; The collaborative signature client calls the authorized ukey driver interface to sign the authentication message and sends the signed authentication message to the collaborative signature bank. After the collaborative signature bank verifies the signed authentication message, it sends the device information and customer information to the collaborative signature server. The collaborative signature server stores the binding relationship between the device information and the customer information, and generates a collaborative signature certificate. When processing the collaborative signature business corresponding to the collaborative signature certificate, the collaborative signature server uses the recorded binding relationship to verify the target customer information and target device information in the collaborative signature business. After successful verification, the collaborative signature business is completed.

2. The method according to claim 1, characterized in that, Before the collaborative signature client generates a collaborative signature activation request based on the device information and customer information, the method further includes: The collaborative signature client logs into the collaborative signature bank terminal based on the customer information; Before the collaborative signature bank generates the authentication message including the device information and customer information, the method further includes: The bank verifies whether the customer information logged in through the collaborative signature is consistent with the customer information in the collaborative signature activation request. If they are consistent, an authentication message including the device information and the customer information is generated.

3. The method according to claim 1, characterized in that, The method further includes: The collaborative signature client and the collaborative signature server negotiate the session key; After the collaborative signature client obtains the device information of the collaborative signature client, the method further includes: The collaborative signature client encrypts the device information using the negotiated session key, so as to generate the collaborative signature activation request based on the encrypted device information and the client information; The authentication message generated by the collaborative signature bank, which includes the device information and customer information, further includes: The collaborative signature bank generates the authentication message, which includes encrypted device information and customer information. After the collaborative signature bank verifies the signed authentication message, it sends the device information and customer information to the collaborative signature server, which further includes: After the collaborative signature bank verifies the signed authentication message, it sends the encrypted device information and customer information to the collaborative signature server. The collaborative signature server storing the binding relationship between the device information and the customer information further includes: The collaborative signature server uses the session key to decrypt the encrypted device information and stores the binding relationship between the client information and the decrypted device information.

4. The method according to claim 1 or 3, characterized in that, The authentication message generated by the collaborative signature bank, which includes the device information and customer information, further includes: The collaborative signature bank encrypts the customer information to obtain encrypted customer information, and generates an authentication message that includes the device information and the encrypted customer information. After the collaborative signature bank verifies the signed authentication message, it sends the device information and customer information to the collaborative signature server, which further includes: After the collaborative signature bank verifies the signed authentication message, it sends the encrypted device information and customer information to the collaborative signature server. The collaborative signature server storing the binding relationship between the device information and the customer information further includes: The collaborative signature server stores the binding relationship between the encrypted device information and the customer information; The method further includes: When the collaborative signature bank processes the collaborative signature business, it encrypts the target customer information corresponding to the collaborative signature certificate to obtain the target customer information ciphertext, and sends the collaborative signature business to the collaborative signature server based on the target customer information ciphertext, so that the collaborative signature server can use the recorded binding relationship to verify the target customer information ciphertext and target device information in the collaborative signature business when processing the collaborative signature business.

5. The method according to claim 1, characterized in that, The steps for the collaborative signature bank to verify the signed authentication message include: The collaborative signature bank compares whether the device information and customer information in the signed authentication message are consistent with the device information and customer information in the generated authentication message.

6. The method according to claim 1, characterized in that, The collaborative signature client obtains its own device information, which further includes: The collaborative signature client calls the client SDK issued by the collaborative signature server to obtain the device information.

7. The method according to claim 1, characterized in that, After the collaborative signature bank verifies the signed authentication message, the method further includes: The collaborative signature bank saves the signed authentication message so that it can be used later to prove that the customer authorized the activation of collaborative signature on the collaborative signature client.

8. A collaborative signature activation system based on ukey certificates, characterized in that, The system includes a collaborative signature bank terminal, a collaborative signature client terminal, and a collaborative signature server terminal; When the collaborative signature bank, collaborative signature client, and collaborative signature server enable collaborative signature, the method described in any one of claims 1-7 shall be executed.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 7.

11. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Identity authentication method based on collaborative signature and computer readable storage medium

    CN112651036A

  • Collaborative signature security opening method and system based on client device matching

    CN117749384A