Electronic certificate management methods, equipment and storage media

By activating the identity information collection and authorization credential acquisition mechanism during SIM card loss reporting, the problem of insufficient coverage of electronic certificate management methods is solved, enabling secure and convenient use when the SIM card is unavailable and expanding application scenarios.

CN118797702BActive Publication Date: 2025-10-31CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311340430.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-16
Publication Date
2025-10-31
Estimated Expiration
2043-10-16

AI Technical Summary

Technical Problem

Existing electronic certificate management methods are insufficient to cover all application scenarios, causing inconvenience for users.

Method used

By triggering a function activation command based on a lost SIM card, the system collects the target user's identity information and uploads it to a pre-set operator platform to obtain authorization credentials. It then retrieves the target's electronic certificate from a pre-set blockchain, uses a smart contract model for identity verification and authorization, and activates authorized functions for others to broaden application scenarios.

Benefits of technology

It broadens the application scenarios of electronic certificates, improves the security and convenience of use, and ensures that electronic certificates can still be used normally when the SIM card is unavailable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118797702B_ABST
    Figure CN118797702B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of blockchain technology and discloses an electronic certificate management method, device, and storage medium. The invention activates the authorization function and completes the collection of the target user's identity information based on a function activation command issued by a preset operator platform, and uploads the collected identity information to the preset operator platform. The function activation command is triggered by a SIM card loss reporting operation command triggered by the target user. Based on the identity information, an authorization credential is obtained from the preset operator platform, and the target electronic certificate is obtained from the preset blockchain based on the authorization credential. When the SIM card of the first mobile terminal is unavailable, the preset operator platform activates the "Authorization by Others" function in the authorized user's certificate card application based on the user's loss reporting information. The "Authorization by Others" function is used to obtain and use the authorized user's electronic certificate, thus broadening the application scenarios of current electronic certificates and ensuring the security of electronic certificates in the usage scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain technology, and in particular to an electronic certificate management method, device and storage medium. Background Technology

[0002] As electronic certificates become increasingly widespread, more and more users are using them to fulfill their daily needs. However, in terms of information security, the use of electronic certificates may lead to issues such as user information leakage and misuse of certificates to conduct business. Therefore, to prevent information loss, electronic certificate data is typically uploaded to a pre-set blockchain, and multiple verification processes are added during the use of electronic certificates to improve security. However, this method of managing electronic certificates cannot cover all application scenarios, causing various inconveniences for users. Summary of the Invention

[0003] The main objective of this invention is to provide an electronic certificate management method, device, and storage medium, aiming to solve the technical problems that existing electronic certificate management methods cannot cover all application scenarios, causing various inconveniences for users.

[0004] To achieve the above objectives, the present invention provides an electronic certificate management method applied to a smart terminal, the electronic certificate management method comprising the following steps:

[0005] The function activation instruction is based on the function activation command issued by the preset operator platform to activate the authorization function and complete the collection of the target user's identity information, and upload the collected identity information to the preset operator platform. The function activation command is an instruction triggered based on the SIM card loss reporting operation command triggered by the target user.

[0006] Based on the identity information, an authorization credential is obtained from the preset operator platform, and the target electronic certificate is obtained from the preset blockchain according to the authorization credential.

[0007] Optionally, before the step of activating the authorization function based on the function activation command issued by the preset operator platform, completing the collection of the target user's identity information, and uploading the collected identity information to the preset operator platform, the method further includes:

[0008] Obtain the authorization configuration information input by the target user;

[0009] An authorization certificate is generated based on the smart terminal parameter information contained in the authorization configuration information, and the authorization certificate and the electronic certificate corresponding to the target user are uploaded to a preset blockchain.

[0010] Optionally, the step of activating the authorization function based on the function activation command issued by the preset operator platform and completing the collection of the target user's identity information, and uploading the collected identity information to the preset operator platform, includes:

[0011] The authorization function is activated based on the function activation command issued by the preset operator platform, and the target user's avatar image and ID card information are collected.

[0012] The profile picture and ID card information are uploaded to the preset operator platform.

[0013] Optionally, the step of activating the authorization function based on the function activation command issued by the preset operator platform and collecting the target user's avatar image and ID card information includes:

[0014] The authorized function is activated based on the function activation command issued by the preset operator platform, and the grayed-out state corresponding to the authorized function is canceled.

[0015] After the grayed-out state is removed, the preset camera is used to collect the target user's headshot image and ID card information.

[0016] Optionally, after the steps of obtaining the authorization credential from the preset operator platform based on the identity information and obtaining the target electronic certificate from the preset blockchain based on the authorization credential, the method further includes:

[0017] Based on the user-triggered certificate deletion command, retrieve the electronic certificates to be deleted from the authorized menu of others, and delete the electronic certificates.

[0018] This invention activates the authorization function and collects the target user's identity information by issuing a function activation command based on a preset operator platform. The collected identity information is then uploaded to the preset operator platform. The function activation command is triggered by the target user's SIM card loss reporting operation command. Based on the identity information, an authorization credential is obtained from the preset operator platform, and the target electronic certificate is obtained from a preset blockchain based on the authorization credential. Compared with existing electronic certificate management, which struggles to cover all application scenarios and causes various inconveniences for users, this invention relates to the user's mobile terminal, a preset operator platform, a preset blockchain, and a smart contract model within the preset operator platform. In this invention, an authorized user can generate multiple authorization credentials from others and upload them to the preset blockchain. When the SIM card is unavailable, the preset operator platform activates the "authorization by others" function in the authorized user's certificate card application based on the user's loss reporting information. After smart contract authentication, the "authorization by others" function is used to obtain and use the authorized user's electronic certificate, thus broadening the application scenarios of current electronic certificates and ensuring the security of electronic certificates in usage scenarios.

[0019] To achieve the above objectives, the present invention also provides an electronic certificate management method, applied to a pre-set operator platform, wherein the pre-set operator platform includes a smart contract model, the smart contract model being used for identity verification, and the electronic certificate management method comprising the following steps:

[0020] Receive the SIM card loss reporting operation command sent by the smart terminal, and trigger the function activation command to be sent to the smart terminal;

[0021] Receive the avatar image and identity information collected by the smart terminal based on the function activation command;

[0022] The avatar image and identity information are compared with the preset identity information in the smart contract model. Based on the comparison result, the authorization certificate corresponding to the smart terminal is obtained from the preset blockchain and the authorization certificate is sent to the smart terminal.

[0023] Optionally, the step of receiving the SIM card loss reporting instruction sent by the smart terminal and triggering the function activation instruction to be sent to the smart terminal includes:

[0024] Receive a SIM card loss reporting operation command sent by a smart terminal, and determine the smart terminal based on the specified user information in the SIM card loss reporting operation command;

[0025] The function activation command is sent to the smart terminal.

[0026] Optionally, the step of comparing the avatar image and the identity information with preset identity information in the smart contract model, obtaining the authorization certificate corresponding to the smart terminal from the preset blockchain based on the comparison result, and sending the authorization certificate to the smart terminal includes:

[0027] The user's avatar image and ID card information are obtained from the preset identity information in the smart contract model;

[0028] The profile picture is compared with the user's profile picture to obtain a first comparison result;

[0029] The ID card information is compared with the user's ID card information to obtain a second comparison result;

[0030] When both the first comparison result and the second comparison result are successful, the authorization certificate corresponding to the smart terminal is obtained from the preset blockchain and the authorization certificate is sent to the smart terminal.

[0031] In addition, to achieve the above objectives, the present invention also proposes an electronic certificate management device, which includes a memory, a processor, and an electronic certificate management program stored in the memory and executable on the processor. The electronic certificate management program is configured to implement the electronic certificate management steps described above.

[0032] In addition, to achieve the above objectives, the present invention also proposes a storage medium storing an electronic certificate management program, wherein the electronic certificate management program, when executed by a processor, implements the steps of the electronic certificate management method as described above. Attached Figure Description

[0033] Figure 1 This is a schematic diagram of the structure of the electronic certificate management device in the hardware operating environment involved in the embodiments of the present invention;

[0034] Figure 2 This is a flowchart illustrating the first embodiment of the electronic certificate management method of the present invention;

[0035] Figure 3 This is a schematic diagram of the overall architecture of the first embodiment of the electronic certificate management method of the present invention;

[0036] Figure 4 This is a schematic diagram of the certificate card application interface of the first embodiment of the electronic certificate management method of the present invention;

[0037] Figure 5 This is a schematic diagram of the secondary menu of the authorization function for others in the first embodiment of the electronic certificate management method of the present invention;

[0038] Figure 6 This is a schematic diagram of the technical solution of the first embodiment of the electronic certificate management method of the present invention;

[0039] Figure 7 This is a flowchart illustrating the second embodiment of the electronic certificate management method of the present invention.

[0040] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0041] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0042] Reference Figure 1 , Figure 1 This is a schematic diagram of the electronic certificate management device structure of the hardware operating environment involved in the embodiments of the present invention.

[0043] like Figure 1As shown, the electronic certificate management device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen, and optionally, it may also include a standard wired interface or a wireless interface. In this invention, the wired interface of the user interface 1003 may be a USB interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be high-speed random access memory (RAM) or non-volatile memory (NVM), such as a disk storage device. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.

[0044] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on electronic certificate management equipment and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0045] like Figure 1 As shown, the memory 1005, which is identified as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an electronic certificate management program.

[0046] exist Figure 1 In the electronic certificate management device shown, the network interface 1004 is mainly used to connect to the backend server and communicate data with the backend server; the user interface 1003 is mainly used to connect to the user device; the electronic certificate management device calls the electronic certificate management program stored in the memory 1005 through the processor 1001 and executes the electronic certificate management method provided in the embodiment of the present invention.

[0047] Based on the above hardware structure, an embodiment of the electronic certificate management method of the present invention is proposed.

[0048] Reference Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the electronic certificate management method of the present invention, which presents the first embodiment of the electronic certificate management method of the present invention.

[0049] In this embodiment, the electronic certificate management method is applied to a smart terminal, and the electronic certificate management method includes the following steps:

[0050] Step S10: Activate the authorization function based on the function activation command issued by the preset operator platform and complete the collection of the target user's identity information, and upload the collected identity information to the preset operator platform. The function activation command is an instruction triggered based on the SIM card loss reporting operation command triggered by the target user.

[0051] It should be noted that the executing entity in this embodiment can be a device containing an electronic certificate management system. The electronic certificate management system has the function of electronic certificate collection and management. The device can be a smart terminal with communication and image acquisition functions, such as a computer, tablet, mobile phone, or laptop. It can also be other devices that can achieve the same or similar functions. In this embodiment and the following embodiments, a computer is used as an example to describe the electronic certificate management method of the present invention. The smart terminal can include a first mobile terminal and a second mobile terminal. The first mobile terminal and the second mobile terminal are respectively bound to a preset operator platform. In the application scenario of this solution, if user 1 loses their SIM card or the SIM card becomes invalid, they can report the loss to the operator. The loss reporting operation can be done by dialing 10086 or sending a text message, etc. The loss reporting information can include an authorized user designated by user 1. For example, if user 1 is with user 2 and wants to use the certificate card application on user 2's mobile phone, then user 2 is designated as the authorized user.

[0052] It is understood that the first mobile terminal can be a terminal device that includes a first SIM card (SIM card 1), an electronic certificate card application, and a preset blockchain card application, and the second mobile terminal can be a terminal device that includes a second SIM card (SIM card 1), an electronic certificate card application, and a preset blockchain card application. The first mobile terminal and the second mobile terminal can be the same terminal device, such as a mobile phone with dual SIM dual standby. In this solution, the first mobile terminal and the second mobile terminal can be determined based on the SIM card.

[0053] It should be understood that the electronic certificate card application is used to manage multiple electronic certificates for a user. In this solution, after the "authorization by others" function is activated, the certificate card application can retrieve, store, and manage the electronic certificates of others in a preset blockchain based on the authorization of others. The preset operating platform can be an operator service platform that includes a smart contract model and an operator TSM for managing card applications and identity verification. The operator TSM is used to manage the card applications. In this solution, based on the loss report operation of user 1, a function activation command is sent to the certificate card application of user 2 authorized by user 1, activating the "authorization by others" function of user 2's certificate card application. The smart contract model is used to authenticate the identity of user 1, and after successful authentication, it queries the authorization certificate of others and sends the certificate to user 2's certificate card application.

[0054] In this context, User 1 can refer to the user who performs the SIM card loss reporting operation on the first mobile terminal, i.e., the authorized user, and User 2 can refer to the second mobile terminal designated by the authorized user, i.e., the authorized user. The first mobile terminal sends the SIM card loss reporting operation command triggered by the user to the preset operator platform. For further explanation of this scheme, please refer to [reference needed]. Figure 3 The diagram shows the overall architecture of the solution. This solution architecture includes the mobile terminal of User 1 (authorized user), the mobile terminal of User 2 (authorized user), the operator TSM, the pre-set blockchain network, and the smart contract model. Figure 3 As shown, the user's mobile terminal acts as a preset blockchain node, used to access the preset blockchain, which stores the user's electronic credentials. The Super SIM card comes pre-installed with an electronic credential card application and a preset blockchain card application. The preset blockchain card application stores the identity verification corresponding to the user's mobile terminal as a preset blockchain node.

[0055] It should be noted that the second mobile terminal can activate the authorization function and complete the collection of the target user's identity information according to the certificate activation instruction issued by the preset operator platform, and upload the collected identity information to the preset operator platform.

[0056] It should be understood that when the preset operator service platform receives a report of loss from user 1 (the target user), it sends the loss information to the operator TSM. The operator TSM obtains the specified user information from the loss information and sends a function activation command to the specified user, such as user 2's ID card application 2. This can be done via over-the-air (OTA) download, allowing remote management of the SIM card application through the mobile communication air interface. The function activation command is used to activate the "authorization by others" function of user 2's ID card application 2. After the second mobile terminal receives the function activation command, the "authorization by others" function is unfurled and can interact with the user.

[0057] Understandably, in response to a user's click, the ID card application 2 instructs the mobile terminal 2 to collect the user 1's identity information and upload the collected identity information to the preset operator platform.

[0058] Furthermore, before step S10, the method further includes: obtaining authorization configuration information input by the target user; generating an authorization certificate based on the smart terminal parameter information contained in the authorization configuration information; and uploading the authorization certificate and the electronic certificate corresponding to the target user to a preset blockchain.

[0059] It should be noted that the authorization configuration information can be the authorized user information input by the target user (user 1) based on the first mobile terminal and the mobile terminal parameter information corresponding to the authorized user. This solution can input the configuration information of authorizing others in the certificate card application in the first mobile terminal, and generate the authorization certificate of others according to the configuration information and upload it to the preset blockchain along with the electronic certificate of the target user.

[0060] Understandably, to further illustrate the application and usage process of the certificate card in this scheme, you can refer to... Figure 4 The diagram shown illustrates the application interface of the certificate card. Figure 4 As shown, User 1 enters ID Card Application 1. ID Card Application 1 can provide option buttons on the homepage, such as adding, deleting, showing, authorizing others, and others authorizing.

[0061] The first three items are the basic functions of electronic certificate card applications, namely:

[0062] (1) Add: Store new electronic certificates;

[0063] (2) Delete: Delete the stored electronic certificates;

[0064] (3) Display: Decode the electronic certificate data and display the decoded image on the user's mobile terminal.

[0065] Additional authorization to others, as well as authorization from others, constitute new features designed for application scenarios in this solution:

[0066] (4) Authorize others: User 1 can enter the information of the authorized users under the Authorize others function menu, such as User 2, User 3, etc. These users can manage and use User 1's electronic certificates based on this authorization when User 1's certificate card application 1 is unavailable (such as when the mobile phone is lost).

[0067] (5) Authorization by others: This function is normally in a "grayed-out" state, and there is no response when the user clicks it. It is activated based on instructions, and after activation, the "grayed-out" state is removed, and the user can interact with it. After activating this function, User 2 can obtain User 1's electronic certificates and manage and use them.

[0068] In practice, when User 1 clicks the "Authorize Others" button, the ID Card Application 1 displays a corresponding option box where users can enter the authorized recipients. These recipients can be the mobile phone numbers of Users 2, 3, and 4. This indicates that User 1 allows Users 2, 3, and 4 to access, manage, and use User 1's electronic ID with their authorization. The ID Card Application 1 generates a one-to-one authorization certificate based on User 1's personal information and the information of Users 2, 3, and 4. That is, three authorization certificates are generated, each corresponding to User 2, User 3, and User 4 respectively. Then, the authorization certificates, along with User 1's electronic ID, are uploaded to the blockchain. For example, User 1 and User 2 register on a preset blockchain network through their respective mobile terminals, store their identity documents in their respective preset blockchain card applications, and upload their electronic IDs to the preset blockchain. When User 1 enables the "Authorize Others" function, the ID Card Application 1 generates authorization certificates and uploads them to the preset blockchain.

[0069] Furthermore, to illustrate the process of identity information collection, step S20 also includes: activating the authorization function based on the function activation command issued by the preset operator platform, and collecting the target user's avatar image and ID card information; and uploading the avatar image and ID card information to the preset operator platform.

[0070] It should be noted that after receiving the authorization function triggered on the second mobile terminal, the second mobile terminal completes the collection of user 1's avatar image and ID card information, and uploads the avatar image and ID card information to the preset operator platform.

[0071] In practice, when user 1 or user 2 clicks the "Authorize Others" function button on user 2's ID card application 2, the ID card application 2 instructs the mobile terminal 2 to collect headshot data. At this time, the collection interface can display "Collect user 1's headshot". Subsequently, the obtained headshot of user 1 and ID card information are sent to the preset operator platform.

[0072] Furthermore, the step of activating the authorization function based on the function activation command issued by the preset operator platform and collecting the target user's avatar image and ID card information includes: activating the authorization function based on the function activation command issued by the preset operator platform and canceling the grayed-out state corresponding to the authorization function; after canceling the grayed-out state, calling the preset camera to collect the target user's avatar image and ID card information.

[0073] It should be noted that collecting user 1's photo and ID card information through the second mobile terminal requires calling the camera device of mobile terminal 2. The purpose of collecting user 1's photo is that the photo data is biometric information. If the matching is successful, it means that user 1 is using user 2's ID card application 2, ensuring the security of the subsequent use of electronic certificates.

[0074] Understandably, in this solution, after receiving the certificate activation instruction issued by the preset operator platform, the second mobile terminal activates the "authorization by others" function of the certificate card application 2, cancels the grayed-out state corresponding to the "authorization by others" function, and calls the preset camera of the mobile terminal 2 to collect the portrait image and ID card information of user 1.

[0075] Step S20: Obtain an authorization credential from the preset operator platform based on the identity information, and obtain the target electronic certificate from the preset blockchain according to the authorization credential.

[0076] It should be noted that User 2's (second mobile terminal's) ID card application 2 calls the blockchain card application 2 in the SIM card 2 of the second mobile terminal to obtain identity verification for accessing the blockchain, and accesses blockchain data based on this identity verification. According to the authorization certificate issued by the smart contract model in the preset operator platform, the electronic ID of User 1 corresponding to the certificate is retrieved from the preset blockchain.

[0077] Furthermore, after step S20, the method further includes: obtaining the electronic certificate to be deleted from the authorization menu of others according to the certificate deletion instruction triggered by the user, and deleting the electronic certificate.

[0078] It should be noted that the certificate card application 2 can store and manage user 1's electronic certificates, and delete the corresponding electronic certificates according to the deletion command.

[0079] Understandably, the ID card application 2 stores User 1's electronic ID in a separate storage space, which can only be managed through the menu under the "Authorize Others" button. User 1's electronic ID is not displayed in the basic function management.

[0080] It should be understood that, to further explain the secondary menu function for authorization by others corresponding to the second mobile terminal in this solution, please refer to... Figure 5 The diagram shown illustrates the second-level menu for the "Authorize Others" function. Figure 5 As shown, the secondary menu for "Authorization by Others" includes basic functions such as deletion and presentation. Users can use and manage the stored electronic certificates of User 1 by clicking the corresponding function buttons.

[0081] In practice, when User 1 finishes using their electronic certificate, they can click the delete button to remove it from User 2's certificate card application 2. This ensures the security of the electronic certificate data. Subsequently, User 1 can apply for a new SIM card and manage their electronic certificates again through the pre-installed certificate card application on the new SIM card. For further explanation of the implementation process in this solution, please refer to [link / reference]. Figure 6 The illustrated technical solution flowchart shows that in this solution, users can use a certificate card application to generate multiple authorization credentials for others based on their own authorization and upload them to the blockchain. When the SIM card is unavailable, the operator, based on the user's lost card information, activates the "authorization of others" function in the certificate card application of the authorized user and verifies the identity of the current user. When it is confirmed that it is the user, the "authorization credentials for others" in the blockchain are sent to the certificate card application. The "authorization of others" function is used to obtain the electronic certificate uploaded to the blockchain by the user and use it, thus broadening the application scenarios of the current electronic certificate. After the operator TSM activates the "authorization of others" function of the authorized user's certificate card application and combines it with smart contract identity authentication, the security of electronic certificate use is improved while enriching the application scenarios.

[0082] This embodiment activates the authorization function and collects the target user's identity information by issuing a function activation command based on a preset operator platform. The collected identity information is then uploaded to the preset operator platform. The function activation command is triggered by the SIM card loss reporting operation command triggered by the target user. Based on the identity information, an authorization credential is obtained from the preset operator platform, and the target electronic certificate is obtained from the preset blockchain based on the authorization credential. Compared with existing electronic certificate management, which is difficult to cover all application scenarios and causes various inconveniences for users, this embodiment involves the user's mobile terminal, the preset operator platform, the preset blockchain, and the smart contract model in the preset operator platform. In this invention, the authorized user can generate multiple authorization credentials from others and upload them to the preset blockchain. When the SIM card is unavailable, the preset operator platform activates the "authorization by others" function in the authorized user's certificate card application based on the user's loss reporting information. After smart contract authentication, the "authorization by others" function is used to obtain and use the authorized user's electronic certificate, thus broadening the application scenarios of current electronic certificates and ensuring the security of electronic certificates in the usage scenarios.

[0083] Based on the above Figure 2 The first embodiment shown illustrates a second embodiment of the electronic certificate management method of the present invention, which is described below. Figure 7 , Figure 7 This is a flowchart illustrating the second embodiment of the electronic certificate management method of the present invention.

[0084] In this embodiment, the electronic certificate management method is applied to a preset operator platform; the preset operator platform includes a smart contract model, which is used for identity verification, and the electronic certificate management method includes the following steps:

[0085] Step S100: Receive the SIM card loss reporting operation command sent by the smart terminal, and trigger the function activation command to be sent to the smart terminal.

[0086] It should be noted that the execution entity in this embodiment can be a preset operator service platform, which includes the operator TSM and a smart contract model. The smart terminal includes a first mobile terminal and a second mobile terminal, which are respectively bound to the preset operator platform. In the application scenario of this solution, user 1 reports the loss of their SIM card to the operator due to loss or SIM card failure. The reporting operation can be done by dialing 10086 or sending an SMS. The reporting information can include an authorized user designated by user 1. For example, if user 1 is with user 2 and wants to use the ID card application on user 2's phone, then user 2 is designated as the authorized user. The first mobile terminal can be a terminal device containing a first SIM card (SIM card 1), an electronic ID card application, and a preset blockchain card application. The second mobile terminal can be a terminal device containing a second SIM card (SIM card 1), an electronic ID card application, and a preset blockchain card application. The first mobile terminal and the second mobile terminal can be the same terminal device, such as a mobile phone with dual SIM dual standby. In this solution, the first mobile terminal and the second mobile terminal can be determined based on the SIM card.

[0087] Understandably, after receiving a SIM card loss reporting request from the first mobile terminal, the pre-set operator service platform sends a function activation instruction to the specified user based on the specified user information in the loss reporting information corresponding to the SIM card loss reporting operation instruction. The specified user can be the second mobile terminal bound to the first mobile terminal.

[0088] Furthermore, step S100 also includes: receiving a SIM card loss reporting operation instruction sent by a smart terminal, determining the smart terminal based on the specified user information in the SIM card loss reporting operation instruction, and sending a function activation instruction to the smart terminal.

[0089] In practice, the operator's TSM in the pre-set operator service platform obtains the specified user information from the lost card information and sends a function activation command to the specified user, such as user 2's ID card application 2. This can be done through over-the-air (OTA) download, which allows for remote management of the SIM card application via the mobile communication air interface.

[0090] Step S200: Receive the avatar image and identity information collected by the smart terminal based on the function activation command.

[0091] It should be noted that, in response to the user's click operation, the ID card application 2 instructs the mobile terminal 2 to collect the user 1's avatar and send the user 1's avatar and identity information to the smart contract model for later identity verification.

[0092] In practice, when either User 1 or User 2 clicks the "Authorize Others" button on User 2's ID card application 2, the ID card application 2 instructs Mobile Terminal 2 to collect facial image data. At this time, the collection interface displays "Collecting User 1's Facial Image." Subsequently, the obtained facial image and identity information of User 1 are sent to the smart contract. This step requires calling the camera device of Mobile Terminal 2. The purpose of collecting User 1's facial image is that this facial image data is biometric information. If a successful match is subsequently found, it indicates that User 1 is using User 2's ID card application 2, ensuring the security of subsequent electronic certificate usage.

[0093] Step S300: Compare the avatar image and the identity information with the preset identity information in the smart contract model, obtain the authorization certificate corresponding to the smart terminal from the preset blockchain according to the comparison result, and send the authorization certificate to the smart terminal.

[0094] It should be noted that the smart contract model will compare the received avatar and identity information of user 1 with the pre-stored identity information. After the comparison is successful, it will access the blockchain to query whether there is a certificate corresponding to user 2 in the authorization certificate uploaded by user 1. If there is, the authorization certificate corresponding to user 2 will be sent to the certificate card application 2.

[0095] It should be understood that the smart contract's storage database pre-stores user identity information. The received user avatar and identity information are compared with the pre-stored information. If the comparison is successful, it indicates that user 1 is using user 2's ID card application 2, which is a security consideration. Then, the smart contract accesses the blockchain data.

[0096] Understandably, as mentioned earlier, User 1 has sent the authorization certificate for others along with the electronic certificate to the blockchain. The smart contract queries the authorization certificates uploaded by User 1 to see if a certificate corresponding to User 2 exists. In the example above, User 1 uploaded three authorization certificates, corresponding to User 2, User 3, and User 4 respectively. Therefore, after the query, a certificate corresponding to User 2 exists, and the smart contract sends the found authorization certificate to the certificate card application 2 corresponding to User 2.

[0097] Furthermore, step S300 further includes: obtaining a user avatar image and user ID card information from the preset identity information in the smart contract model; comparing the avatar image with the user avatar image to obtain a first comparison result; comparing the ID card information with the user ID card information to obtain a second comparison result; when both the first comparison result and the second comparison result are successful, obtaining the authorization certificate corresponding to the smart terminal from the preset blockchain, and sending the authorization certificate to the smart terminal.

[0098] It should be noted that the user's avatar image and user's ID card information are obtained from the preset identity information in the smart contract model; the avatar image is compared with the user's avatar image to obtain a first comparison result; the ID card information is compared with the user's ID card information to obtain a second comparison result; when both the first comparison result and the second comparison result are successful, the authorization certificate corresponding to the first terminal is obtained from the preset blockchain, and the authorization certificate is sent to the second mobile terminal.

[0099] For a more detailed explanation of the implementation process in this solution, please refer to [link / reference]. Figure 6 The illustrated technical solution flowchart shows that in this solution, users can use a certificate card application to generate multiple authorization credentials for others based on their own authorization and upload them to the blockchain. When the SIM card is unavailable, the operator, based on the user's lost card information, activates the "authorization of others" function in the certificate card application of the authorized user and verifies the identity of the current user. When it is confirmed that it is the user, the "authorization credentials for others" in the blockchain are sent to the certificate card application. The "authorization of others" function is used to obtain the electronic certificate uploaded to the blockchain by the user and use it, thus broadening the application scenarios of the current electronic certificate. After the operator TSM activates the "authorization of others" function of the authorized user's certificate card application and combines it with smart contract identity authentication, the security of electronic certificate use is improved while enriching the application scenarios.

[0100] This embodiment receives a SIM card loss reporting instruction from a smart terminal and triggers a function activation instruction to be sent to the smart terminal; it receives a profile picture and identity information collected by the smart terminal based on the function activation instruction; it compares the profile picture and identity information with preset identity information in the smart contract model, and obtains the corresponding authorization certificate for the smart terminal from the preset blockchain based on the comparison result and sends the authorization certificate to the smart terminal. Compared with existing electronic certificate management, which is difficult to cover all application scenarios and causes various inconveniences for users, this embodiment involves the user's mobile terminal, a preset operator platform, a preset blockchain, and a smart contract model in the preset operator platform. In this invention, the authorized user can generate multiple authorization certificates for others and upload them to the preset blockchain. When the SIM card is unavailable, the preset operator platform activates the "authorization of others" function in the authorized user's certificate card application based on the user's loss reporting information. After smart contract authentication, the "authorization of others" function is used to obtain and use the authorized user's electronic certificate, thus broadening the application scenarios of current electronic certificates and ensuring the security of electronic certificates in the usage scenarios.

[0101] In addition, to achieve the above objectives, the present invention also proposes a storage medium storing an electronic certificate management program, wherein the electronic certificate management program, when executed by a processor, implements the steps of the electronic certificate management method as described above.

[0102] It should be understood that the above are merely illustrative examples and do not constitute any limitation on the technical solutions of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any restrictions on this.

[0103] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this invention. In practical applications, those skilled in the art can select some or all of the workflow to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.

[0104] In addition, for technical details not described in detail in this embodiment, please refer to the electronic certificate management method provided in any embodiment of the present invention, which will not be repeated here.

[0105] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0106] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments. In the unit claims listing several devices, several of these devices may be embodied by the same hardware item. The use of the terms first, second, and third, etc., does not indicate any order and can be interpreted as names.

[0107] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as a read-only memory image (ROM) / random access memory (RAM), magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0108] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for managing electronic certificates, characterized in that, The electronic certificate management method, applied to smart terminals, includes the following steps: The function activation instruction is based on the function activation command issued by the preset operator platform to activate the authorization function and complete the collection of the target user's identity information, and upload the collected identity information to the preset operator platform. The function activation command is an instruction triggered by the SIM card loss reporting operation command triggered by the target user. Based on the identity information, an authorization credential is obtained from the preset operator platform, and the target electronic certificate is obtained from the preset blockchain according to the authorization credential; The steps of activating the authorization function and collecting the target user's identity information based on the function activation command issued by the preset operator platform include: The authorized function is activated based on the function activation command issued by the preset operator platform, and the grayed-out state corresponding to the authorized function is canceled. After the grayed-out state is removed, the target user's identity information is collected.

2. The electronic certificate management method as described in claim 1, characterized in that, Before the step of activating the authorization function based on the function activation command issued by the preset operator platform, completing the collection of the target user's identity information, and uploading the collected identity information to the preset operator platform, the method further includes: Obtain the authorization configuration information input by the target user; An authorization certificate is generated based on the smart terminal parameter information contained in the authorization configuration information, and the authorization certificate and the electronic certificate corresponding to the target user are uploaded to a preset blockchain.

3. The electronic certificate management method as described in claim 1, characterized in that, The steps of activating the authorization function based on the function activation command issued by the preset operator platform, completing the collection of the target user's identity information, and uploading the collected identity information to the preset operator platform include: The authorization function is activated based on the function activation command issued by the preset operator platform, and the target user's avatar image and ID card information are collected. The profile picture and ID card information are uploaded to the preset operator platform.

4. The electronic certificate management method as described in claim 3, characterized in that, The steps of activating the authorization function based on the function activation command issued by the preset operator platform and collecting the target user's profile picture and ID card information include: The authorized function is activated based on the function activation command issued by the preset operator platform, and the grayed-out state corresponding to the authorized function is canceled. After the grayed-out state is removed, the preset camera is used to collect the target user's headshot image and ID card information.

5. The electronic certificate management method as described in claim 1, characterized in that, After the steps of obtaining the authorization credential from the preset operator platform based on the identity information and obtaining the target electronic certificate from the preset blockchain based on the authorization credential, the method further includes: Based on the user-triggered certificate deletion command, retrieve the electronic certificates to be deleted from the authorized menu of others, and delete the electronic certificates.

6. A method for managing electronic certificates, characterized in that, Applied to a pre-defined operator platform, the pre-defined operator platform includes a smart contract model, which is used for identity verification. The electronic certificate management method includes the following steps: Receive the SIM card loss reporting operation command sent by the smart terminal, and trigger the function activation command to be sent to the smart terminal; Receive the avatar image and identity information collected by the smart terminal based on the function activation command; The avatar image and identity information are compared with the preset identity information in the smart contract model. Based on the comparison result, the authorization certificate corresponding to the smart terminal is obtained from the preset blockchain and the authorization certificate is sent to the smart terminal so that the smart terminal can obtain the target electronic certificate from the preset blockchain based on the authorization certificate.

7. The electronic certificate management method as described in claim 6, characterized in that, The step of receiving the SIM card loss reporting instruction sent by the smart terminal and triggering the function activation instruction to be sent to the smart terminal includes: Receive a SIM card loss reporting operation command sent by a smart terminal, and determine the smart terminal based on the specified user information in the SIM card loss reporting operation command; The function activation command is sent to the smart terminal.

8. The electronic certificate management method as described in claim 6, characterized in that, The step of comparing the avatar image and the identity information with the preset identity information in the smart contract model, obtaining the authorization certificate corresponding to the smart terminal from the preset blockchain based on the comparison result, and sending the authorization certificate to the smart terminal includes: The user's avatar image and ID card information are obtained from the preset identity information in the smart contract model; The profile picture is compared with the user's profile picture to obtain a first comparison result; The ID card information is compared with the user's ID card information to obtain a second comparison result; When both the first comparison result and the second comparison result are successful, the authorization certificate corresponding to the smart terminal is obtained from the preset blockchain and the authorization certificate is sent to the smart terminal.

9. An electronic certificate management device, characterized in that, The electronic certificate management device includes: a memory, a processor, and an electronic certificate management program stored in the memory and executable on the processor. When the electronic certificate management program is executed by the processor, it implements the electronic certificate management method as described in any one of claims 1-5 or 6-8.

10. A storage medium, characterized in that, The storage medium stores an electronic certificate management program, which, when executed by a processor, implements the electronic certificate management method as described in any one of claims 1-5 or 6-8.

Citation Information

Patent Citations

  • Stand-in authorization method and electronic equipment

    CN104348687A

  • Electronic license certificate issuing system

    CN107146186A