Anti-counterfeiting method for electronic certificate and related device
By acquiring and processing the encrypted ID card information of the target user and verifying it using a document decryption model, the problem of poor anti-counterfeiting performance of existing document anti-counterfeiting methods is solved, and a more efficient method for judging the authenticity of documents is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-29
- Publication Date
- 2026-03-20
AI Technical Summary
Existing document anti-counterfeiting methods mainly rely on printing technology, which has poor anti-counterfeiting performance, low visual recognition reliability, and is easy to be counterfeited.
By obtaining the encrypted ID card information of the target user, user identity information is generated. The verification information is obtained using the document decryption model and compared with the pre-set user identity information to determine the authenticity of the document.
This improves the anti-counterfeiting features of the documents, enhances the reliability of identification, and reduces the risk of document forgery.
Smart Images

Figure CN118551403B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to an anti-counterfeiting method of electronic certificate and related equipment. BACKGROUND
[0002] Certificate is the identity of individuals or organizations, and is the basis for normal social and economic activities. Anti-counterfeiting of certificates is required for normal social activities and is the basis for ensuring the effectiveness of certificates. A secure certificate is usually a document that can prove the identity, experience or special value of an individual. A certificate is a document, a carrier of information, and a proof of relevant facts. For example, a passport is a typical certificate. Through the certificate, the nationality, identity and travel trajectory of entry and exit personnel can be confirmed. Because it is necessary to ensure the legality and authenticity of the information carried by such certificates, strong security measures are needed to ensure the safety of the certificate. A certificate contains a series of proof data and information, and its authenticity and validity need to be verified within a certain range and given time.
[0003] The commonly used certificate anti-counterfeiting method is mainly based on printing technology, and adds photos, signatures and seals. This method has the advantages of low cost and direct visual identification, but has poor anti-counterfeiting performance, low visual identification reliability and is easy to be imitated.
[0004] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] The purpose of the present application is to provide an anti-counterfeiting method of electronic certificate and related equipment, which at least partially overcomes the problems of the prior art. The identity certificate information of the target user after encryption processing is obtained, and the identity rough positioning information of the target user is obtained by processing. The certificate decryption model is obtained based on the identity rough positioning information. The user identity information matched with the target user is obtained based on the mapping table stored in the server. The corresponding verification information is obtained through the certificate decryption model, and the generated verification information is compared with the user identity information set in advance by the target user. The authenticity of the certificate to be identified is judged.
[0006] According to an aspect of some embodiments of the present application, there is provided a method for anti-counterfeiting of an electronic certificate, the method comprising: obtaining certificate information to be identified sent by a client, wherein the certificate information to be identified comprises identity certificate information of a target user after encryption processing; processing the certificate information to be identified to generate user identity information; obtaining an initial certificate decryption model matched with the user identity information and target user identity information matched with the user identity information, wherein the target user identity information is generated based on encryption habits of the target user and personal information on an identity certificate of the target user; training and processing the initial certificate decryption model based on a preset processing method to generate a target certificate decryption model; processing the identity information based on the target certificate decryption model to generate attribute information of the certificate information to be identified; processing the attribute information of the certificate information to be identified based on the target certificate decryption model to generate initial verification information, wherein the initial verification information is used to represent anti-counterfeiting of the certificate information to be identified; processing the initial verification information based on the target user identity information to generate a verification result; and sending the verification result to the client.
[0007] In some embodiments of the present application, the processing of the certificate information to be identified to generate user identity information comprises: processing the certificate information to be identified based on a preset processing rule to obtain a user private key set in advance by the target user, wherein the user private key is used to decrypt part of the identity certificate information of the target user after encryption processing; generating coarse positioning information of the target user based on the user private key and the certificate information to be identified, wherein the coarse positioning information of the target user is part of the identity certificate information of the target user; and generating user identity information based on the coarse positioning information of the target user.
[0008] In some embodiments of the present application, the processing of the identity information based on the target certificate decryption model to generate attribute information of the certificate information to be identified comprises: processing the identity information to generate reception time information of the certificate information to be identified, address attribution information of a real-time client, and use information of the certificate to be identified; and generating use information of the certificate information to be identified based on the reception time information of the certificate information to be identified, the address attribution information of the real-time client, and the use information of the certificate to be identified based on a preset processing rule.
[0009] In some embodiments of the present application, the processing of the identity information based on the target certificate decryption model to generate attribute information of the certificate information to be identified further comprises: obtaining identity certificate validity period information corresponding to the identity information; and processing the use information of the certificate information to be identified based on the identity certificate validity period information to generate attribute information of the certificate information to be identified.
[0010] In some embodiments of the present application, the preset processing method is used to train and process the initial certificate decryption model to generate a target certificate decryption model, including: obtaining a total sample set used to train the initial certificate decryption model; performing feature extraction on the total sample set to determine an original feature library; dividing each feature data set according to the original feature library to generate a training set and a test set; using a classifier to predict each test set divided by the original feature library to determine a prediction result; using a preset algorithm to train each training set divided by the original feature library to obtain a test set class prediction result; generating a training sample with identification information according to the prediction result and the test set class prediction result; training the initial certificate decryption model based on the training set and the test set to generate a target certificate decryption model.
[0011] In some embodiments of the present application, the feature extraction on the total sample set to determine an original feature library includes: obtaining a historical identity certificate data set; processing the historical identity certificate data set to obtain abnormal text features and correlation co-occurrence frequencies; processing the abnormal text features and the correlation co-occurrence frequencies to generate correlation matrix information; generating a plurality of text feature data based on the correlation matrix information; and generating an original feature library based on the plurality of text feature data.
[0012] In some embodiments of the present application, before the obtaining of the to-be-identified certificate information sent by the client, the method further includes: receiving digital certificate information, client unique identification information, a client random number and client key-share information sent by the client; obtaining target server random number and target server key-share information; generating a pre-master key based on the client key-share information and the target server key-share information; generating a temporary session key based on the client random number, the target server random number and the pre-master key; processing the digital certificate information and the client unique identification information based on a preset pairing rule to generate a processing result; if the processing result is that the target server is allowed to be paired and connected with the client, sending a certificate information encryption rule request to the client; receiving a preset processing rule sent by the client based on the certificate information encryption rule request, wherein the preset processing rule is used for subsequent decryption processing of the to-be-identified certificate information sent by the client.
[0013] According to another aspect of the embodiments of the present application, there is provided an anti-counterfeiting device of an electronic certificate, applied to a server, comprising: an obtaining module, configured to obtain certificate information to be identified sent by a client, wherein the certificate information to be identified comprises identity certificate information of a target user after encryption processing; an initial certificate decryption model matched with user identity information and target user identity information matched with the user identity information are obtained, wherein the target user identity information is generated based on encryption habits of the target user and personal information on an identity certificate of the target user; a processing module, configured to process the certificate information to be identified to generate user identity information; the initial certificate decryption model is processed based on a preset processing method to generate a target certificate decryption model; the identity information is processed based on the target certificate decryption model to generate attribute information of the certificate information to be identified; the attribute information of the certificate information to be identified is processed based on the target certificate decryption model to generate initial verification information, wherein the initial verification information is used to represent the anti-counterfeiting property of the certificate information to be identified; the initial verification information is processed based on the target user identity information to generate a verification result; and a sending module, configured to send the verification result to the client.
[0014] According to another aspect of the embodiments of the present application, there is provided an electronic device, comprising a computer readable storage medium storing a computer program and a processor, wherein the computer program is read and run by the processor to implement the method according to any one of the preceding aspects.
[0015] According to another aspect of the embodiments of the present application, there is provided a computer readable storage medium storing a computer program, wherein the computer program is read and run by a processor to implement the method according to any one of the preceding aspects.
[0016] According to another aspect of the embodiments of the present application, there is provided a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the method according to any one of the preceding aspects.
[0017] One of the aspects of the embodiments of the present application provides a technical solution which can include the following beneficial effects: the anti-counterfeiting method of the electronic certificate provided by the embodiments of the present application obtains identity certificate information of a target user after encryption processing, processes the identity certificate information to obtain identity rough positioning information of the target user, and obtains a certificate decryption model corresponding to the identity rough positioning information. The mapping table stored in a server is used to obtain user identity information matched with the target user, the certificate decryption model is used to obtain corresponding verification information, and the generated verification information is compared with user identity information set in advance by the target user, so that the authenticity of the certificate to be identified is determined.
[0018] Other features and advantages of the present application will be set forth in the following description, and in part will be apparent from the description, or can be learned by practice of the application. It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the application, as claimed. BRIEF DESCRIPTION OF DRAWINGS
[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0020] Figure 1 A flow chart of an anti-counterfeiting method of an electronic certificate provided by an embodiment of the present application is shown;
[0021] Figure 2 A structural schematic diagram of an anti-counterfeiting device of an electronic certificate provided by an embodiment of the present application is shown;
[0022] Figure 3 A structural schematic diagram of an electronic device provided by an embodiment of the present application is shown;
[0023] Figure 4 A schematic diagram of a storage medium provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0024] In order to make the objects, technical solutions and advantages of the present application more clear, the present application will be further described below with reference to the drawings and specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.
[0025] Those skilled in the art can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as that generally understood by those skilled in the art in the present application. It should also be understood that terms such as those defined in a general dictionary should be understood as having meanings consistent with those in the context of the prior art, and unless specifically defined as such, should not be interpreted in an idealized or overly formal sense.
[0026] As Figure 1 shown, one embodiment of the present application provides an anti-counterfeiting method of an electronic certificate, applied to a server, and in some embodiments, the method comprises:
[0027] S101, acquire the to-be-identified certificate information sent by the client.
[0028] In an implementation, the to-be-identified certificate information includes the identity certificate information of the target user after encryption processing. The identity certificate information after encryption processing can be partially encrypted or fully encrypted. For example, only the user name and the first / last few digits of the ID number are not encrypted, and other information is encrypted, or all information is encrypted. The present application does not limit this, and the applicant can set it according to actual needs. The present application does not limit how to acquire the identity certificate information of the target user after encryption processing. The applicant can set it according to actual needs, for example, write the identity certificate information of the target user after encryption processing into the electronic chip of the certificate, for subsequent anti-counterfeiting detection of the to-be-identified certificate information. By encrypting the identity certificate information written in the chip, the content of the chip can be effectively prevented from being tampered with.
[0029] S102, process the to-be-identified certificate information to generate user identity information.
[0030] In an implementation, the to-be-identified certificate information is processed based on a preset processing rule to acquire the user private key set by the target user in advance, wherein the user private key is used to decrypt part of the identity certificate information of the target user after encryption processing. The preset processing rule is set by the target user based on a preset certificate information encryption rule, that is, the user private key is sent to the server by the target user in advance. Before acquiring the to-be-identified certificate information sent by the client, the identity of the client is authenticated to acquire the identity information of the client, so as to acquire the user private key of the target user based on a preset identity information mapping table.
[0031] Based on the user private key, the to-be-identified certificate information is processed to generate coarse positioning information of the target user, wherein the coarse positioning information of the target user is part of the identity certificate information of the target user; and the user identity information is generated based on the coarse positioning information of the target user. The user name and the first / last few digits of the ID number are used to preliminarily locate the personal information of the user, wherein the identity information is used to confirm the birthplace, gender, age, name, or any combination of the target user, and this part of the content is obtained after decryption processing.
[0032] S103, acquire the initial certificate decryption model matched with the user identity information and the target user identity information matched with the user identity information.
[0033] In one implementation, the target user's identity information is generated based on the target user's encryption habits and personal information on the target user's ID card. For example, some users choose a 4-digit number from their ID card as their user identity information, some choose a 5-digit number, and some choose a 6-digit number. The order of the selected numbers is preset by the user. This part of the content is preset by the target user on the target server and can be set according to the target user's needs.
[0034] S104. The initial document decryption model is trained based on a preset processing method to generate a target document decryption model.
[0035] In one implementation, a total sample set is obtained for training the initial document decryption model. Feature extraction is then performed on this total sample set to determine the original feature library. Feature extraction includes four types of features: original features, statistical features, frequency domain features, and time domain features. Commonly extracted features are described below: Original Features: Original features are obtained by preprocessing the collected data and using all information from each sample data matrix for model training. To avoid losing sample information, each curve of sample Xi is directly expanded and stretched into a row vector. Statistical Features: Statistical features consider the changing trends of all data points on the curve. By extracting statistical features, the dimensionality of the data samples can be reduced, facilitating the analysis of gene data and accelerating the convergence speed during model training. The extracted statistical features include maximum value, minimum value, mean, variance, and standard deviation. Frequency Domain Features: Wavelet transform is performed on the dataset, and the coefficients obtained from the second-order wavelet transform are used as new features to constitute the frequency domain features. Time Domain Features: Time domain features mainly focus on the time perspective to discover the changing patterns of signals and systems. Time domain features can reflect the information of curve data changing over time. This process mainly extracts the first-order forward difference of the dataset to form the first-order difference time-domain features, and uses the exponential moving average feature processing method.
[0036] According to the original feature library, each feature data set is divided to generate a training set and a test set, a classifier is used to predict each test set divided by the original feature library to determine a prediction result, a preset algorithm is used to train each training set divided by the original feature library to obtain a test set class prediction result, and a training sample with identification information is generated according to the prediction result and the test set class prediction result, wherein the identification information is used to represent that the identity certificate information of the user is abnormal. Based on the training set and the test set, the initial certificate decryption model is trained to generate a target certificate decryption model. Specifically, the data classification result corresponding to the training set is obtained, because the classification result of each training set can be determined in advance, the data can be directly obtained from the outside world. The prediction result is compared with the data classification result to determine a first comparison result; the test set class prediction result is compared with the data classification result to determine a second comparison result; and it is judged whether the second comparison result and the first comparison result meet a preset requirement. When the preset requirement is met, it indicates that the detection result of the current certificate decryption model is relatively accurate, and at this time, the current certificate decryption model can be used as the target certificate decryption model.
[0037] In one embodiment, the identity identification information is processed to generate attribute information of the to-be-identified certificate information.
[0038] In one embodiment, the identity identification information is processed to generate attribute information of the to-be-identified certificate information.
[0039] The attribute information is mainly used to assist in identifying the target user, for example, which user sends the to-be-identified certificate information, what is the purpose, the real identity certificate information of the target user, whether the current user has the permission to identify the to-be-identified certificate information, and what is the purpose of identifying the to-be-identified certificate information.
[0040] By counting the identification information sent by each client in the past, including the client IP address, the number of transmissions, the transmission time, the transmission time is introduced, the normal office time, the overtime office time and other time periods are distinguished, and different calculation weights are given. The newly received identification information is compared with the historical data, and finally it is judged whether the received identification information is a garbage request. In addition, if it is judged to be a garbage request, the client will be set to a frozen state, and the next time any identification information is sent through the client, the user must be verified before the normal use is restored. The judgment of the client address attribution increases the automatic blocking and unblocking process design of the stolen enterprise internal mailbox account, and fundamentally solves the problem of continuous malicious use of stolen enterprise internal mailbox.
[0041] In addition, the validity period information of the received identification information is also judged. If the time of receiving the identification information has exceeded the preset time, even if the identification information is correct, it will be judged as a fake content at this time.
[0042] S106, processing the attribute information of the identification information based on the target certificate decryption model, generating initial verification information.
[0043] In an embodiment, the initial verification information is used to represent the anti-fake nature of the identification information. The user identity information matched with the target user is obtained based on the mapping table stored in the server, wherein the user identity information is set based on part of the content on the target user's identity certificate information. When the certificate decryption model processes the encrypted identity certificate information, the complete identity certificate information can be obtained, and then the certificate decryption model will generate corresponding verification information based on the encryption habit set by the target server in advance. For example, the numbers 1, 4, 6, 7, 10 and 15 on the user's identity card number are selected as the encryption habit, thereby generating the corresponding verification information. The order and quantity selected by the application are not limited, and can be set according to actual needs.
[0044] S107, processing the initial verification information based on the target user identity information, generating a verification result.
[0045] In an implementation, the generated verification information is compared with the user identity information previously set by the target user, if consistent, it represents that the current encrypted identity certificate information is accurate, if inconsistent, it represents that the current encrypted identity certificate information is incorrect, thereby generating a corresponding verification result, which is used to represent whether the current to-be-identified certificate information is real certificate information. The present scheme does not limit the verification information and the user identity information previously set by the target user, and the applicant can set it according to the actual needs.
[0046] S108, send the verification result to the client.
[0047] The present application first acquires the identity certificate information of the target user after encryption processing, and then processes it to complete the rough positioning of the target user's identity, that is, to obtain part of the target user's information, such as the target user's name and birthplace, and based on the target user's name and birthplace, the corresponding initial certificate decryption model is obtained, wherein the content stored in each certificate decryption model is limited, that is, each initial certificate decryption model can be set for citizens in a province or a city, and the present scheme does not limit this, thereby avoiding that all user information can be obtained through one decryption model, and in addition, the processing efficiency of the certificate decryption model can be improved. In addition, the user identity information matched with the target user is obtained based on the mapping table stored in the server, wherein the user identity information is set based on part of the content on the target user's identity certificate information, when the certificate decryption model processes the encrypted identity certificate information, the complete identity certificate information can be obtained, and then the certificate decryption model will generate the corresponding verification information based on the encryption habit previously set by the target user, and compare the generated verification information with the user identity information previously set by the target user, if consistent, it represents that the current encrypted identity certificate information is accurate, if inconsistent, it represents that the current encrypted identity certificate information is incorrect, thereby generating a corresponding verification result, which is used to represent whether the current to-be-identified certificate information is real certificate information.
[0048] The anti-counterfeiting method of the electronic certificate provided by the embodiment of the application includes: obtaining certificate information to be identified sent by a client, wherein the certificate information to be identified includes identity certificate information of a target user after encryption processing; processing the certificate information to be identified to generate user identity information; obtaining an initial certificate decryption model matched with the user identity information and target user identity information matched with the user identity information, wherein the target user identity information is generated based on an encryption habit of the target user and personal information on an identity certificate of the target user; training and processing the initial certificate decryption model based on a preset processing method to generate a target certificate decryption model; processing the identity information based on the target certificate decryption model to generate attribute information of the certificate information to be identified; processing the attribute information of the certificate information to be identified based on the target certificate decryption model to generate initial verification information, wherein the initial verification information is used to represent the anti-counterfeiting property of the certificate information to be identified; processing the initial verification information based on the target user identity information to generate a verification result; and sending the verification result to the client. The identity rough positioning information of the target user is obtained by processing the identity certificate information of the target user after encryption processing, and the corresponding certificate decryption model is obtained based on the identity rough positioning information. The user identity information matched with the target user is obtained based on a mapping table stored in the server, the corresponding verification information is obtained through the certificate decryption model, and the generated verification information is compared with the user identity information set in advance by the target user, so that the authenticity of the certificate to be identified is determined.
[0049] Optionally, in another embodiment based on the above method of the application, the feature extraction on the total sample set to determine the original feature library comprises:
[0050] Obtaining a historical identity certificate data set;
[0051] Processing the historical identity certificate data set to obtain abnormal text features and correlation co-occurrence frequencies;
[0052] Processing the abnormal text features and the correlation co-occurrence frequencies to generate correlation matrix information;
[0053] Generating a plurality of text feature data based on the correlation matrix information;
[0054] Generating an original feature library based on the plurality of text feature data.
[0055] In an implementation, the abnormal text types and their correlations are extracted from the historical identity certificate data set in a data mining manner, the relationship between the identity certificate and the user is established, the identity information priori knowledge graph is formed, then the related department manager checks whether the correlation between the concepts is established one by one, the correlation matrix is calibrated, and the text feature data is screened.
[0056] In another embodiment, the method includes a calculation formula for calculating the correlation co-occurrence frequency, specifically: ; wherein, represents the concept and the concept In the report level co-occurrence times, represents the concept The total number of times, represents the concept When the concept The frequency of occurrence is based on the co-occurrence frequency The correlation matrix can be constructed .
[0057] The method also includes a calculation formula for calculating the correlation matrix, specifically ; wherein, is the co-occurrence frequency threshold, if Greater than or equal to the threshold , it is considered that the concept There is a correlation between the concept , otherwise it does not have correlation.
[0058] Optionally, in another embodiment based on the above-mentioned method of the present application, before the client sends the information of the certificate to be identified, it further includes:
[0059] Receiving digital certificate information, client unique identification information, client random number and client key-share information sent by the client;
[0060] Obtain the target server random number and the target server key-share information;
[0061] Generate a pre-master key according to the client key-share information and the target server key-share information;
[0062] Generate a temporary session key according to the client random number, the target server random number and the pre-master key;
[0063] Process the digital certificate information and the client unique identification information based on the preset pairing rule to generate a processing result;
[0064] If the processing result is to allow the target server to pair and connect with the client, send a certificate information encryption rule request to the client;
[0065] Receive the preset processing rule sent by the client based on the certificate information encryption rule request, wherein the preset processing rule is used for subsequent decryption processing of the certificate information to be identified sent by the client.
[0066] In one implementation, the client random number can be a 32-byte string generated by a secure random number generator. The client's unique identifier can be the client's MAC address. The key_share is the public key corresponding to the elliptic curve type. The specific representation of the key_share information is not described here. The key-share information includes, but is not limited to, preset parameters used to calculate the pre-master key. For example, when the client sends a request (Client Hello), the extended part carries the supported elliptic curve types, and calculates the client public key (POINT) for each supported elliptic curve type. The client public key is placed in the key-share information in the extended information. After the target server selects the elliptic curve parameters, it multiplies them by the elliptic curve's basepoint to obtain the target server public key (POINT). Then, it extracts the corresponding client public key from the key_share information in the Client Hello and calculates the pre-master key. After receiving the target server's target server public key (POINT), the client calculates the pre-master key. The client random number and client key-share information are generated by the client; the target server random number and target server key-share information are generated by the target server. The specific generation method is not limited here. By utilizing the pre-existing session key information exchanged between the client and target server during the handshake process (connection establishment), the session key can be quickly determined without affecting the handshake process (connection establishment), significantly shortening the communication time between the two ends after the handshake (connection establishment). After the connection between the client and target server is established, the client will send a preset processing rule based on the document information encryption rule request sent to the target server, i.e., the target user's encryption habits, for subsequent decryption of the document information to be identified sent by the client.
[0067] By applying the above technical solution, the server receives digital certificate information, client unique identifier information, client random number, and client key-share information sent by the client; obtains target server random number and target server key-share information; generates a pre-master key based on the client key-share information and target server key-share information; generates a temporary session key based on the client random number, target server random number, and pre-master key; processes the digital certificate information and client unique identifier information based on preset pairing rules to generate a processing result; if the processing result allows the target server and client to pair and connect, the server sends a document information encryption rule request to the client; and receives the preset processing rules sent by the client based on the document information encryption rule request, wherein the preset processing rules are used for subsequent decryption of the document information to be identified sent by the client.
[0068] The system retrieves the document information to be identified sent by the client, including the encrypted ID photo information of the target user; processes the document information based on preset processing rules to obtain the user's pre-set private key, which is used to decrypt a portion of the encrypted ID photo information; generates coarse location information of the target user based on the user's private key, which is a portion of the target user's ID photo information; generates user identity information based on the coarse location information; retrieves an initial document decryption model matching the user identity information and target user identity information matching the user identity information, where the target user identity information is generated based on the target user's encryption habits and personal information on the target user's ID document; and retrieves the decryption model used for the initial document decryption. The document decryption model is trained using the following methods: 1) Obtain a dataset of historical ID photos; 2) Process the historical ID photo dataset to obtain abnormal text features and co-occurrence frequencies of related information; 3) Process the abnormal text features and co-occurrence frequencies of related information to generate a correlation matrix; 4) Generate several text feature data based on the correlation matrix; 5) Generate an original feature library based on the text feature data; 6) Divide the original feature library into different feature datasets to generate training and test sets; 7) Use a classifier to predict the results on each test set divided by the original feature library; 8) Train the model using a pre-defined algorithm on each training set divided by the original feature library to obtain prediction results for the test set classes; 9) Generate training samples with identification information based on the prediction results and the prediction results for the test set classes; 10) Train the initial document decryption model using the training and test sets to generate the target document decryption model.
[0069] The identity information is processed to generate the receiving time information of the to-be-identified certificate information, the address attribution information of the real-time client, and the use information of the to-be-identified certificate. The receiving time information of the to-be-identified certificate information, the address attribution information of the real-time client, and the use information of the to-be-identified certificate are processed based on a preset processing rule to generate the use information of the to-be-identified certificate information. The identity certificate validity period information corresponding to the identity information is obtained. The use information of the to-be-identified certificate information is processed based on the identity certificate validity period information to generate the attribute information of the to-be-identified certificate information. The attribute information of the to-be-identified certificate information is processed based on the target certificate decryption model to generate the initial verification information, wherein the initial verification information is used to represent the anti-fake property of the to-be-identified certificate information. The initial verification information is processed based on the target user identity information to generate a verification result. The verification result is sent to the client. The identity rough positioning information of the target user is obtained by processing the identity certificate information of the target user processed by encryption. The corresponding certificate decryption model is obtained based on the identity rough positioning information. The user identity information matched with the target user is obtained based on the mapping table stored in the server. The corresponding verification information is obtained by the certificate decryption model, and the generated verification information is compared with the user identity information set in advance by the target user, so that the authenticity of the to-be-identified certificate is judged.
[0070] Reference Figure 2 Another embodiment of the present application provides an anti-fake device for an electronic certificate, applied to a server. In some embodiments, the device comprises:
[0071] The obtaining module 201 is configured to obtain to-be-identified certificate information sent by a client, wherein the to-be-identified certificate information comprises identity certificate information of a target user processed by encryption; and obtain an initial certificate decryption model matched with the user identity information and target user identity information matched with the user identity information, wherein the target user identity information is generated based on the encryption habit of the target user and personal information on the identity certificate of the target user.
[0072] The processing module 202 is configured to process the to-be-identified certificate information to generate user identity information; train and process the initial certificate decryption model based on a preset processing method to generate a target certificate decryption model; process the identity information based on the target certificate decryption model to generate attribute information of the to-be-identified certificate information; process the attribute information of the to-be-identified certificate information based on the target certificate decryption model to generate initial verification information, wherein the initial verification information is used to represent the anti-fake property of the to-be-identified certificate information; process the initial verification information based on the target user identity information to generate a verification result.
[0073] The sending module 203 is configured to send the check result to the client.
[0074] In another embodiment of the present application, the processing module 202 is configured to process the to-be-identified certificate information to generate user identity information, including:
[0075] processing the to-be-identified certificate information based on a preset processing rule to obtain a user private key set in advance by a target user, wherein the user private key is used to decrypt part of the identity certificate information of the target user after encryption processing;
[0076] generating coarse positioning information of the target user based on the user private key and the to-be-identified certificate information, wherein the coarse positioning information of the target user is part of the identity certificate information of the target user;
[0077] generating user identity information based on the coarse positioning information of the target user.
[0078] In another embodiment of the present application, the processing module 202 is configured to process the identity information based on the target certificate decryption model to generate attribute information of the to-be-identified certificate information, including:
[0079] processing the identity information to generate receiving time information of the to-be-identified certificate information, address attribution information of a real-time client, and use information of the to-be-identified certificate;
[0080] generating use information of the to-be-identified certificate information based on the receiving time information of the to-be-identified certificate information, the address attribution information of the real-time client, and the use information of the to-be-identified certificate based on a preset processing rule.
[0081] In another embodiment of the present application, the processing module 202 is configured to process the identity information based on the target certificate decryption model to generate attribute information of the to-be-identified certificate information, and further includes:
[0082] obtaining identity certificate validity period information corresponding to the identity information;
[0083] processing the use information of the to-be-identified certificate information based on the identity certificate validity period information to generate attribute information of the to-be-identified certificate information.
[0084] In another embodiment of the present application, the processing module 202 is configured to train and process the initial certificate decryption model based on a preset processing method to generate a target certificate decryption model, including:
[0085] obtaining a total sample set for training the initial certificate decryption model;
[0086] perform feature extraction on the total sample set to determine an original feature library;
[0087] divide each feature data set according to the original feature library to generate a training set and a test set;
[0088] use a classifier to predict each test set divided by the original feature library to determine a prediction result;
[0089] use a preset algorithm to train each training set divided by the original feature library to obtain a test set class prediction result;
[0090] generate a training sample with identification information according to the prediction result and the test set class prediction result;
[0091] train the initial certificate decryption model based on the training set and the test set to generate a target certificate decryption model.
[0092] In another embodiment of the present application, the processing module 202 is configured to perform feature extraction on the total sample set to determine an original feature library, including:
[0093] obtain a historical identity certificate data set;
[0094] process the historical identity certificate data set to obtain abnormal text features and correlation co-occurrence frequencies;
[0095] process the abnormal text features and the correlation co-occurrence frequencies to generate correlation matrix information;
[0096] generate a plurality of text feature data based on the correlation matrix information;
[0097] generate an original feature library based on the plurality of text feature data.
[0098] In another embodiment of the present application, the processing module 202, before being configured to obtain the identification certificate information sent by the client, further includes:
[0099] receive digital certificate information, client unique identification information, client random number and client key-share information sent by the client;
[0100] obtain target server random number and target server key-share information;
[0101] generate a pre-master key according to the client key-share information and the target server key-share information;
[0102] generating a temporary session key according to the client random number, the target server random number and the pre-master key;
[0103] processing the digital certificate information and the client unique identification information based on preset pairing rules to generate a processing result;
[0104] if the processing result is that the target server is allowed to pair and connect with the client, sending a certificate information encryption rule request to the client;
[0105] receiving a preset processing rule sent by the client based on the certificate information encryption rule request, wherein the preset processing rule is used for subsequent decryption processing of to-be-identified certificate information sent by the client.
[0106] According to another aspect of the embodiments of the present application, an electronic device is provided, including a computer readable storage medium storing a computer program and a processor, and the computer program is read and run by the processor to implement the method of any one of the above.
[0107] The embodiments of the present application provide an electronic device, as shown in the figure, Figure 3 The electronic device 3 includes a first processor 300, a memory 301, a bus 302 and a communication interface 303, the first processor 300, the communication interface 303 and the memory 301 are connected through the bus 302; the memory 301 stores a computer program which can be run on the first processor 300, and the first processor 300 runs the computer program to execute the anti-counterfeiting method of the electronic certificate provided by any one of the preceding embodiments of the present application.
[0108] The memory 301 can include a high-speed random access memory (RAM) and can also include a non-volatile memory such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 303 (which can be wired or wireless), and the Internet, a wide area network, a local network, a metropolitan area network, etc. can be used.
[0109] The bus 302 can be an ISA bus, a PCI bus or an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 301 is used to store programs, and the first processor 300 executes the programs after receiving execution instructions. The anti-counterfeiting method of the electronic certificate disclosed in any one of the preceding embodiments of the present application can be applied to the first processor 300 or implemented by the first processor 300.
[0110] The first processor 300 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the first processor 300 or by instructions in software form. The first processor 300 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be implemented by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 301. The first processor 300 reads the information in memory 301 and, in conjunction with its hardware, completes the steps of the above method.
[0111] The electronic devices provided in the above embodiments of this application and the anti-counterfeiting methods for electronic certificates provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.
[0112] This application provides a computer-readable storage medium, such as... Figure 4 As shown, the computer-readable storage medium 401 stores a computer program, which is read and executed by the second processor 402 to implement the anti-counterfeiting method for electronic certificates as described above.
[0113] The technical solutions of this application embodiment, in essence, or the part that contributes to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device (which may be an air conditioner, refrigeration unit, personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the method described in the embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0114] The computer readable storage medium provided by the above-mentioned embodiments of the present application has the same beneficial effects as the anti-counterfeiting method of the electronic certificate provided by the embodiments of the present application, and the same beneficial effects as the method adopted, run or implemented by the application program stored therein.
[0115] The embodiments of the present application provide a computer program product comprising a computer program, which is executed by a third processor to implement the method as described above.
[0116] The computer program product provided by the above-mentioned embodiments of the present application has the same beneficial effects as the anti-counterfeiting method of the electronic certificate provided by the embodiments of the present application, and the same beneficial effects as the method adopted, run or implemented by the application program stored therein.
[0117] It should be noted that, in the present application, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.
[0118] Each of the embodiments in the present application is described in a relevant manner, and the same or similar parts of each of the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the anti-counterfeiting method of evaluating an electronic certificate, the electronic device, the electronic equipment, and the readable storage medium, since they are basically similar to the anti-counterfeiting method of the electronic certificate described above, the description is relatively simple, and the relevant parts can be referred to the part of the description of the anti-counterfeiting method of the electronic certificate described above.
[0119] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various modifications and changes without departing from the spirit and scope of the present application, and therefore the protection scope of the present application should be subject to the scope defined by the claims.
[0120] It should be noted that:
[0121] The term "module" is not intended to be limited to a particular physical form. A module can be implemented as hardware, firmware, software, and / or combinations thereof depending on the particular application. Further, different modules can share a common component or even be implemented by the same component. There can or can not be a clear line of demarcation between different modules. The structure required to construct such an apparatus is apparent from the above description. Moreover, the present application is not directed to any particular programming language. It will be appreciated that a variety of programming languages could be used to implement the teachings of the present application described herein, and any references to a particular language are supplied for disclosure of the best mode of practicing the present application.
[0122] It should be understood that although the steps in the flowcharts of the drawings are shown in a sequential order, the steps are not necessarily performed in the order shown. Unless explicitly stated, the steps can be performed in any order, and the steps can be performed in parallel. Further, at least some of the steps in the flowcharts of the drawings can include multiple sub-steps or multiple stages, which are not necessarily performed at the same time, but can be performed at different times, and the order of the execution of the sub-steps or stages is not necessarily sequential, but can be round-robin or alternating with other steps or sub-steps or stages of other steps.
Claims
1. A method for preventing counterfeiting of electronic certificates, characterized in that, The method includes: Obtain the identification document information sent by the client, which includes the encrypted ID card information of the target user; The information on the identification document to be identified is processed to generate user identity information; Obtain an initial document decryption model that matches the user's identity information and target user identity information that matches the user's identity information, wherein the target user identity information is generated based on the target user's encryption habits and personal information on the target user's identity document; The initial document decryption model is trained based on a preset processing method to generate the target document decryption model; The identity information is processed based on the target document decryption model to generate attribute information of the document to be identified, including: processing the identity information to generate the reception time information, real-time client address information, and document usage information; generating the purpose information of the document to be identified based on the reception time information, real-time client address information, and document usage information; obtaining the validity period information of the ID card corresponding to the identity information; and processing the purpose information of the document to be identified based on the validity period information to generate attribute information of the document to be identified, which is used to assist in identifying the target user's information. By statistically analyzing the document information sent by each client within a certain period of time, the newly received document information is compared with the statistically analyzed historical data to determine whether the received document information is a spam request. If it is determined to be a spam request, the client will be frozen. The next time any document information is sent through this client, the user's identity must be verified before normal use can be restored. The attribute information of the document to be identified is processed based on the target document decryption model to generate initial verification information, which is used to characterize the anti-counterfeiting properties of the document to be identified. The initial verification information is processed based on the target user's identity information to generate a verification result. This includes comparing the generated verification information with the user's pre-set identity information. If they match, it means that the encrypted ID card information is accurate. If they do not match, it means that the encrypted ID card information is incorrect. The corresponding verification result is generated to indicate whether the current ID card information to be identified is genuine. Send the verification result to the client.
2. The method according to claim 1, characterized in that, The process of processing the document information to be identified to generate user identity information includes: The information of the document to be identified is processed based on preset processing rules to obtain the user's private key set in advance. The user's private key is used to decrypt part of the encrypted ID card information of the target user. Based on the user's private key and the identification document information to be identified, a coarse location information of the target user is generated, wherein the coarse location information of the target user is part of the target user's ID card information; User identification information is generated based on the coarse location information of the target user.
3. The method according to claim 1, characterized in that, The step of training the initial document decryption model based on a preset processing method to generate a target document decryption model includes: Obtain the total sample set used to train the initial document decryption model; Feature extraction is performed on the total sample set to determine the original feature library; Based on the original feature library, divide each feature dataset to generate training and test sets; The classifier is used to predict the results of each test set divided by the original feature library. The preset algorithm is used to train on each training set divided by the original feature library to obtain the test set class prediction results. Based on the prediction results and the test set class prediction results, generate training samples with labeling information; The initial document decryption model is trained based on the training set and the test set to generate the target document decryption model.
4. The method according to claim 3, characterized in that, The step of extracting features from the total sample set to determine the original feature library includes: Obtain historical ID card photo dataset; The historical ID photo dataset is processed to obtain abnormal text features and related co-occurrence frequencies; The abnormal text features and the co-occurrence frequency of the correlation are processed to generate correlation matrix information; Several text feature data are generated based on the correlation matrix information; An original feature library is generated based on the aforementioned text feature data.
5. The method according to claim 1, characterized in that, Before obtaining the document information to be identified sent by the client, the process also includes: Receive digital certificate information, client unique identifier information, client random number, and client key-share information sent by the client; Obtain the target server's random number and target server key-share information; A pre-master key is generated based on the client key-share information and the target server key-share information; A temporary session key is generated based on the client random number, the target server random number, and the pre-master key; The digital certificate information and the client's unique identifier information are processed based on preset pairing rules to generate a processing result; If the processing result allows the target server to pair and connect with the client, then a request for document information encryption rules is sent to the client. The system receives a preset processing rule sent by the client based on the document information encryption rule request, wherein the preset processing rule is used to decrypt the document information to be identified sent by the client in subsequent processing.
6. An anti-counterfeiting device for electronic certificates, characterized in that, The apparatus for implementing the method of claim 1 includes: The acquisition module is used to acquire the identification document information sent by the client, wherein the identification document information includes the encrypted ID card information of the target user; acquire the initial document decryption model matching the user identification information and the target user identity information matching the user identification information, wherein the target user identity information is generated based on the target user's encryption habits and the personal information on the target user's ID card; The processing module is used to process the document information to be identified to generate user identity information; train the initial document decryption model based on a preset processing method to generate a target document decryption model; process the identity information based on the target document decryption model to generate attribute information of the document information to be identified; process the attribute information of the document information to be identified based on the target document decryption model to generate initial verification information, wherein the initial verification information is used to characterize the anti-counterfeiting properties of the document information to be identified; and process the initial verification information based on the target user identity information to generate a verification result. The sending module is used to send the verification result to the client.
7. An electronic device, characterized in that, The method includes a computer-readable storage medium storing a computer program, which is read and executed by the processor to implement the method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that is read and executed by a processor to implement the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Method and device for processing user request, electronic equipment and storage medium
CN112308236A
QUIC connection establishment method, system and device, electronic equipment and storage medium
CN116566612A
Lung cancer postoperative rehabilitation method and related equipment
CN117877663A