Electronic certificate display method, device, equipment and storage medium

By generating one-time credentials and certificate operation information, and combining blockchain technology of SIM cards and cloud servers, the problem of identity information leakage in the display of electronic certificates is solved, achieving higher security and user experience.

CN118821088BActive Publication Date: 2025-09-19CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311542478.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-09-19
Estimated Expiration
2043-11-17

AI Technical Summary

Technical Problem

In the prior art, when electronic certificates are displayed, user identity information is easily leaked and the security is not high.

Method used

By generating one-time credentials and license operation information, using SIM cards and cloud servers combined with blockchain technology, identity authentication and license operations are performed to generate and display the target electronic license.

Benefits of technology

It improves the security of electronic certificate display, avoids identity information leakage, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118821088B_ABST
    Figure CN118821088B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of blockchain technology, and in particular to an electronic certificate display method, device, equipment and storage medium. The present invention generates a one-time pass certificate and certificate operation information according to an electronic certificate display instruction input by a user, and sends the one-time pass certificate and certificate operation information to a cloud server for identity authentication. After the verification is passed, a target electronic certificate is generated according to the certificate operation information for the queried certificate, and then the cloud server can feed the target electronic certificate back to a terminal for display. In this process, by setting a one-time certificate and operating the certificate, the identity information on the certificate is prevented from being leaked, thereby avoiding the technical problems in the prior art that identity information is easily leaked and the security is not high when the electronic certificate is displayed, thereby improving the security of the user's identity information and improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and in particular to an electronic certificate display method, device, equipment and storage medium. Background Art

[0002] In traditional electronic certificate usage scenarios, it is sometimes necessary to decode the electronic certificate into an image and display it on the user's mobile terminal interface to meet the user's usage needs. However, this display process may cause user information leakage, certificate information misuse, etc., making it difficult to ensure the security of user identity information during the electronic certificate display process.

[0003] The above content is only used to assist in understanding the technical solution of the present invention and does not constitute an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of the present invention is to provide a method, device, equipment and storage medium for displaying electronic certificates, aiming to solve the technical problems in the prior art that identity information is easily leaked and security is low when electronic certificates are displayed.

[0005] To achieve the above-mentioned object, the present invention provides an electronic certificate display method, which is applied to a terminal device and includes the following steps:

[0006] Upon receiving an electronic certificate display instruction, generating a one-time certificate and certificate operation information according to the electronic certificate display instruction;

[0007] Sending the one-time credential and the certificate operation information to a cloud server, so that the cloud server returns a target electronic certificate based on the certificate operation information and the one-time credential;

[0008] Display the target electronic certificate.

[0009] Optionally, generating a one-time credential and credential operation information according to the electronic credential display instruction includes:

[0010] In response to the electronic certificate display instruction, obtaining certificate operation information and valid timestamp information through the SIM card;

[0011] Determine the target original certificate through the preset electronic certificate list based on the certificate operation information;

[0012] A one-time credential is generated according to the valid timestamp, the target original credential and preset signature data.

[0013] In addition, to achieve the above-mentioned purpose, the present invention further provides an electronic certificate display device, which is applied to a terminal device and includes:

[0014] A generating module, configured to generate a one-time credential and credential operation information according to the electronic credential display instruction upon receiving the electronic credential display instruction;

[0015] a sending module, configured to send the one-time credential and the credential operation information to a cloud server, so that the cloud server feeds back a target electronic credential based on the credential operation information and the one-time credential;

[0016] A display module is used to display the target electronic certificate.

[0017] The present invention also provides an electronic certificate display method, which is applied to a cloud server and includes the following steps:

[0018] When receiving the target data packet sent by the terminal device, the target data packet is decrypted through the smart contract to obtain the license operation information and the one-time certificate;

[0019] authenticating based on the one-time credentials;

[0020] When the identity authentication is passed, the target electronic certificate is fed back to the terminal device according to the certificate operation information and the one-time credential, so that the terminal device displays the target electronic certificate.

[0021] Optionally, feeding back a target electronic certificate to the terminal device according to the certificate operation information and the one-time credential includes:

[0022] Read the electronic certificate data corresponding to the one-time certificate in the blockchain through a smart contract;

[0023] Convert the electronic certificate data to obtain target electronic certificate data.

[0024] Performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate;

[0025] Send the target electronic certificate to the terminal device.

[0026] Optionally, the license operation information includes a license operation location and a license operation method;

[0027] The step of performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate includes:

[0028] When the certificate operation mode is the first operation mode, performing data parsing on the target electronic certificate data to obtain a metadata directory and template data;

[0029] When the certificate operation position is a key position, determining the certificate type and corresponding key position information of the target electronic certificate data;

[0030] determining initial character string data according to the key position information and the metadata directory;

[0031] Replace the initial character string data based on a preset replacement strategy to obtain the target identity information data;

[0032] A target electronic certificate is generated according to the target identity data and the template data.

[0033] Optionally, performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate further includes:

[0034] When the license operation mode is the second operation mode, querying the center coordinate position template corresponding to the license type;

[0035] Generate target watermark data according to the preset watermark information and the center coordinate position template;

[0036] Filling the target watermark data into the target electronic certificate data to obtain watermarked electronic certificate data;

[0037] The watermarked electronic certificate data is converted into a photo to obtain a target electronic certificate.

[0038] In addition, to achieve the above-mentioned purpose, the present invention further provides an electronic certificate display device, which is applied to a cloud server and includes:

[0039] A decryption module is used to decrypt the target data packet sent by the terminal device through the smart contract to obtain the license operation information and the one-time certificate;

[0040] a verification module, configured to perform identity authentication based on the one-time credential;

[0041] The feedback module is used to feed back the target electronic certificate to the terminal device according to the certificate operation information and the one-time credential when the identity authentication is passed, so that the terminal device displays the target electronic certificate.

[0042] In addition, to achieve the above-mentioned purpose, the present invention also provides an electronic certificate display device, which includes: a memory, a processor, and an electronic certificate display program stored in the memory and runnable on the processor. When the electronic certificate display program is executed by the processor, it implements the electronic certificate display method described above.

[0043] In addition, to achieve the above-mentioned purpose, the present invention further provides a storage medium, on which an electronic certificate display program is stored. When the electronic certificate display program is executed by a processor, the electronic certificate display method as described above is implemented.

[0044] The present invention discloses an electronic certificate display method, which is applied to a terminal device. The electronic certificate display method includes: upon receiving an electronic certificate display instruction, generating a one-time pass certificate and certificate operation information according to the electronic certificate display instruction; sending the one-time pass certificate and the certificate operation information to a cloud server, so that the cloud server feeds back a target electronic certificate according to the certificate operation information and the one-time pass certificate; and displaying the target electronic certificate. Compared with the prior art, the present invention generates a one-time pass certificate and certificate operation information according to the electronic certificate display instruction input by the user, and sends the one-time pass certificate and the certificate operation information to the cloud server for identity authentication. After the verification is passed, the target electronic certificate is generated according to the certificate operation information for the queried certificate, and then the cloud server can feed back the target electronic certificate to the terminal for display. In this process, by setting the one-time pass certificate and operating the certificate, the identity information on the certificate is prevented from being leaked, thereby avoiding the technical problems in the prior art that identity information is easily leaked and the security is not high when the electronic certificate is displayed, thereby improving the security of the user's identity information and improving the user's usage experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a flow chart of a first embodiment of a method for displaying an electronic certificate according to the present invention;

[0046] Figure 2 A schematic diagram of requesting to display an electronic certificate according to an embodiment of a method for displaying an electronic certificate of the present invention;

[0047] Figure 3 This is a simulated schematic diagram of a terminal device displaying an electronic certificate according to an embodiment of the electronic certificate display method of the present invention;

[0048] Figure 4 This is a flow chart of a second embodiment of the electronic certificate display method of the present invention;

[0049] Figure 5 This is a schematic diagram of the communication interaction sequence between a terminal device and a cloud server in an embodiment of the electronic certificate display method of the present invention;

[0050] Figure 6 This is a structural block diagram of an embodiment of an electronic certificate display device of the present invention;

[0051] Figure 7 This is a structural block diagram of another embodiment of the electronic certificate display device of the present invention.

[0052] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0053] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0054] The embodiment of the present invention provides a method for displaying an electronic certificate, referring to Figure 1 , Figure 1 This is a flow chart of a first embodiment of a method for displaying an electronic certificate according to the present invention.

[0055] In this embodiment, the electronic certificate display method includes the following steps:

[0056] Step S10: upon receiving the electronic certificate display instruction, generating a one-time certificate and certificate operation information according to the electronic certificate display instruction.

[0057] It should be noted that the execution subject of the method of this embodiment can be a terminal device, for example, a mobile terminal device such as a mobile phone or a smart watch, or other mobile devices that can achieve the same or similar functions. This embodiment does not impose specific restrictions on this. For the sake of convenience, in this embodiment and the following embodiments, a mobile phone will be used as the execution subject as an example.

[0058] It can be understood that electronic certificates refer to various certificates, proofs, approvals, appraisal reports and service results documents issued by various units in accordance with the law and with legal effect, such as identity cards, marriage certificates, bank repayment flow certificates and business licenses, etc. This embodiment does not impose specific restrictions on this.

[0059] In traditional technology, in order to improve the security of users using electronic certificates, the solution generally adopted is to add pre-set text as a watermark to the electronic certificate and superimpose it on the display image of the electronic certificate. This method has a single display mode and only starts from the image level. The watermark is easy to remove and the security protection effect is poor.

[0060] In order to solve the above problems, this embodiment combines the mobile terminal certificate card application, SIM card, smart contracts set on the cloud server and blockchain technology to automatically display private or watermarked electronic certificates, thereby improving the security display capability of electronic certificates at the data level when the electronic certificates are issued, and avoiding security risks caused by watermark erasure.

[0061] Among them, the certificate card application is used to obtain the user's operation configuration based on the business type, and when the user displays the user's electronic certificate, the electronic certificate that has been processed by hiding, adding watermarks, etc. based on the business type is displayed; the smart contract is used to authenticate the user. After the identity authentication is passed, the electronic certificate corresponding to the one-time credentials is queried, and operations such as hiding or adding watermarks are performed according to the business type, and the processed electronic certificate data is sent to the user's certificate card application and other functions.

[0062] It should be understood that the electronic certificate display instruction refers to the control instruction generated by the user by operating the certificate card application, which is mainly used to request the cloud server to issue electronic certificates for different business scenarios through the blockchain.

[0063] In the specific implementation, refer to Figure 2 and Figure 3 , Figure 2 This is a schematic diagram of requesting and displaying an electronic certificate in this embodiment. Figure 3 A schematic diagram showing the simulation of an electronic certificate is displayed on the terminal device. The user clicks "Show" on the home page of the certificate card application, clicks "Regular Business" in the next menu, and clicks "ID Card" in the next menu. The terminal device will then display the ID card image after "hiding key positions".

[0064] It is worth noting that the one-time credential is mainly used to verify the user's identity information, and the one-time credential is a short-term valid credential information. It mainly achieves the purpose of improving the security of identity authentication by limiting the valid time and valid duration of the information in the one-time credential, and avoiding the occurrence of credential theft and the like. Among them, since the credential is combined with a valid timestamp, it can only be used once in a very short period of time, and it will become invalid after use. It is impossible to obtain the electronic certificate again through the one-time credential, which ensures the security of the electronic certificate data. The one-time credential includes the following data: original credential, application timestamp, authorization timestamp and other data information. For details, please refer to Table 1. This embodiment does not make specific restrictions on this.

[0065] Table 1

[0066]

[0067] In addition, the certificate operation information includes the certificate operation position and the certificate operation mode. The operation mode can be watermark, hidden, etc. The operation position can be any position set by the user, such as: the key position of the electronic certificate, the upper side, the lower side, the center, the left side and the right side, etc. This embodiment does not impose specific restrictions on this.

[0068] Among them, the key positions of different certificates are different. The smart contract pre-stores the coordinate position templates of various electronic certificates. For example, for the electronic ID card, the smart contract pre-stores the five position templates corresponding to the top, bottom, center, left and right sides of the electronic ID card, and pre-stores the key position information corresponding to the electronic ID card.

[0069] Furthermore, the generating of the one-time certificate and certificate operation information according to the electronic certificate display instruction includes:

[0070] In response to the electronic certificate display instruction, obtaining certificate operation information and valid timestamp information through the SIM card;

[0071] Determine the target original certificate through the preset electronic certificate list based on the certificate operation information;

[0072] A one-time credential is generated according to the valid timestamp, the target original credential and preset signature data.

[0073] It should be noted that valid timestamp information includes but is not limited to: application timestamp, authorization timestamp and other information.

[0074] In the specific implementation, the user enters the ID card application, clicks the "Display" button provided on the homepage of the ID card application, and an option box pops up. The corresponding business type is entered, and the ID card operation method and operation position corresponding to the business type are generated. The ID card application generates ID display information one by one based on the user input information, and stores the ID operation information in the SIM card of the terminal device so that it can be called in response to the electronic ID display instruction. This can not only reduce the amount of useless data storage, but also strongly associate the identity with the terminal device, thereby improving the security of the electronic ID display. Refer to Table 2, which is an example distance of ID operation.

[0075] Table 2

[0076]

[0077] In addition, the certificate card application displays a "business type selection interface" to the user based on the user's operation of clicking the "Display" button. The interface displays: regular business, government affairs processing, and special business. After the user clicks, the business type in this display instruction is obtained. Then, the certificate card application displays the currently managed electronic certificates in the next-level menu interface. Each electronic certificate can correspond to a button. After the user clicks, the certificate card application obtains the electronic certificate list in this display instruction. Among them, the certificate card application also stores the blockchain certificate of each electronic certificate. According to the electronic certificate list obtained in the display instruction, the certificate corresponding to each electronic certificate in the electronic certificate list is searched, that is, the target original certificate, and then the valid timestamp is combined with the original certificate to generate a one-time certificate.

[0078] Step S20: Sending the one-time credential and the certificate operation information to a cloud server, so that the cloud server feeds back a target electronic certificate according to the certificate operation information and the one-time credential.

[0079] It should be noted that before the cloud server issues the electronic certificate, the Super SIM card in the terminal device has already uploaded the user's certificate data to the cloud server's blockchain for storage. The corresponding credentials for each certificate data are stored in the certificate card application. For example, T ID card, T driver's license, etc. In the actual use scenario, when the user needs to present the certificate, the certificate card application can send the credentials to the smart contract, which can access the blockchain and obtain the corresponding electronic certificate based on the credentials.

[0080] Therefore, after the cloud server receives the one-time certificate and certificate operation information sent by the terminal device, it can query the corresponding target electronic certificate data from the user certificate data stored in the blockchain and perform watermarking or hiding processing.

[0081] Furthermore, in order to improve the security of the electronic certificate display, the one-time certificate and the certificate operation information are sent to the cloud server, so that the cloud server feeds back the target electronic certificate according to the certificate operation information and the one-time certificate, including:

[0082] Encapsulating the one-time credential and the license operation information to obtain an encapsulated data packet;

[0083] Performing secondary encryption on the encapsulated data packet to obtain a target data packet;

[0084] The target data packet is sent to the cloud server, so that the cloud server decrypts the target data packet through the smart contract, obtains the certificate operation information and the one-time certificate, and feeds back the target electronic certificate based on the certificate operation information and the one-time certificate.

[0085] In a specific implementation, the certificate card application packages and encapsulates the one-time credential and the operation instructions corresponding to the operation information, which can be done by compressing the one-time credential and the operation information to obtain an encapsulated data packet; when the encapsulated data packet is encrypted twice, a combination of multiple encryption methods can be used to avoid the encapsulated data packet being intercepted when the terminal device communicates with the cloud server over the network, resulting in the leakage of user identity information.

[0086] Furthermore, the encapsulated data packet is encrypted twice to obtain a target data packet, including:

[0087] Symmetrically encrypt the encapsulated data packet based on a preset first public key to obtain a first data packet;

[0088] The first data packet is asymmetrically encrypted based on a preset second public key and a preset first private key to obtain a target data packet.

[0089] In the specific implementation, the preset first public key is a public key pre-set by the terminal device and the cloud server. A large number of encryption processes can be implemented through symmetric encryption to improve the security of data transmission. However, since the key of the symmetric encryption process is easily leaked, this embodiment adds an asymmetric encryption algorithm on the basis of symmetric encryption to further improve the security of data transmission.

[0090] Among them, the terminal device is provided with a preset first private key, which is only known to the terminal device and is not disclosed to the public. The cloud server is provided with a preset second private key, which is only known to the cloud server and is not disclosed to the public. Among them, the preset first public key and the preset second public key can be the same, thereby reducing the workload of encryption and decryption. This embodiment does not impose specific restrictions on this.

[0091] In a specific implementation, this embodiment can perform encryption by performing symmetric encryption SM4, and then use the public key stored in the SIM card to perform asymmetric encryption SM2 for signing, and this embodiment does not impose specific restrictions on this.

[0092] Step S30: Display the target electronic certificate.

[0093] This embodiment generates a one-time pass certificate and certificate operation information according to the electronic certificate display instruction input by the user, and sends the one-time pass certificate and certificate operation information to the cloud server for identity authentication. After the verification is passed, the target electronic certificate is generated according to the certificate operation information for the queried certificate, and then the cloud server can feed the target electronic certificate back to the terminal for display. In this process, by setting a one-time certificate and operating the certificate, the identity information on the certificate is prevented from being leaked, thereby avoiding the technical problems of easy leakage of identity information and low security when the electronic certificate is displayed in the existing technology, thereby improving the security of user identity information and improving the user experience.

[0094] The embodiment of the present invention provides a method for displaying an electronic certificate, referring to Figure 4 , Figure 4 This is a flow chart of a first embodiment of a method for displaying an electronic certificate according to the present invention.

[0095] In this embodiment, the electronic certificate display method includes the following steps:

[0096] Step S10': When receiving the target data packet sent from the terminal device, the target data packet is decrypted through the smart contract to obtain the certificate operation information and the one-time certificate.

[0097] It should be noted that the execution entity of the method in this embodiment can be a cloud server, such as a server cluster or a virtual machine, etc., or other devices that can achieve the same or similar functions. This embodiment does not impose specific restrictions on this. For the sake of convenience, this embodiment will take the cloud server as the execution entity as an example.

[0098] Furthermore, the target data packet is decrypted by the smart contract to obtain the license operation information and the one-time certificate, including:

[0099] Decrypting the target data packet using a preset first public key to obtain a first decrypted packet; and

[0100] Decrypting the first decrypted packet based on the second private key and the second public key to obtain a second decrypted packet;

[0101] The second decrypted package is read to obtain the license operation information and the one-time certificate.

[0102] Since the target data packet sent by the terminal device undergoes a secondary encryption process, in order to successfully read the one-time certificate and license operation information in the data packet, the decryption process of this embodiment also requires a symmetric decryption and an asymmetric decryption.

[0103] To explain the asymmetric encryption and decryption process in detail, for example, for the encoded code text "photo", if the public key broadcast by the factory end is 137, its corresponding digital string is "0017 0008 0016 00200016". After encryption, the result is "232900 109600 219200 274000 219200". Taking the four-digit password item, the target translation code text group of "2900 9600 9200 40009200" is obtained. According to its mapping relationship, the local key is 73, and the target transfer code text group is calculated to obtain "211700 700800 671600292000 671600". Finally, according to the preset number corresponding to the public key, the last four digits are taken and processed to obtain "1700 0800 1600 2000". 1600" can be restored to "0017 0008 001600200016", and finally restored to the source code "photo". The above is only an example, and this embodiment does not impose any specific limitation on this.

[0104] Step S20': Perform identity authentication based on the one-time credential.

[0105] It should be noted that the user's identity information is pre-stored in the storage database of the smart contract. The received user identity information is compared with the pre-stored identity information. If the comparison is successful, it means that the current user has the right to obtain the electronic certificate data, that is, the identity verification is successful.

[0106] Step S30': When the identity authentication is passed, the target electronic certificate is fed back to the terminal device according to the certificate operation information and the one-time credential, so that the terminal device displays the target electronic certificate.

[0107] Understandably, the reference Figure 5 , Figure 5 This is a schematic diagram of the communication interaction sequence between the terminal device and the cloud server in this embodiment. After the identity authentication is passed, the encrypted data is decrypted to obtain a one-time credential, and the blockchain is accessed to obtain the electronic certificate data corresponding to the one-time credential, such as an ID card, driver's license, etc. According to the operation instructions in the certificate operation information, such as hiding the key position of the certificate, the corresponding operation is performed on the obtained ID card and driver's license data, and the operated electronic certificate data is returned to the user's certificate card application to realize the display of the electronic certificate.

[0108] Furthermore, feeding back the target electronic certificate to the terminal device based on the certificate operation information and the one-time credential includes:

[0109] Read the electronic certificate data corresponding to the one-time certificate in the blockchain through a smart contract;

[0110] Convert the electronic certificate data to obtain target electronic certificate data.

[0111] Performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate;

[0112] Send the target electronic certificate to the terminal device.

[0113] In a specific implementation, the electronic certificate data is format-converted to obtain the target electronic certificate data, which may be obtained by converting the read electronic certificate data into the target electronic certificate data of an electronic certificate OFD format file. This embodiment does not impose any specific limitation on this.

[0114] In this embodiment, the certificate operation information includes the certificate operation position and the certificate operation mode. Different certificate operation positions and certificate operation modes correspond to different certificate processing solutions. Two of the certificate operation modes, watermark and hiding, are used as examples for explanation.

[0115] Furthermore, the performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate includes:

[0116] When the certificate operation mode is the first operation mode, performing data parsing on the target electronic certificate data to obtain a metadata directory and template data;

[0117] When the certificate operation position is a key position, determining the certificate type and corresponding key position information of the target electronic certificate data;

[0118] determining initial character string data according to the key position information and the metadata directory;

[0119] Replace the initial character string data based on a preset replacement strategy to obtain the target identity information data;

[0120] A target electronic certificate is generated according to the target identity data and the template data.

[0121] In a specific implementation, when the certificate operation mode is a hidden operation mode, the metadata directory and template data can be obtained by parsing the electronic certificate OFD format file; the key position information corresponding to the electronic certificate type is searched to obtain the string of information data corresponding to the key position information; the string is replaced to obtain the replaced string, and the replaced string is used as the information data; the processed information data and template data are combined to obtain the hidden electronic certificate data.

[0122] Among them, taking the electronic ID card as an example, the metadata directory includes various attributes and fields of the ID card, such as ID card number, name, gender, date of birth, and issuing authority; the key position information corresponding to each type of electronic certificate is pre-stored in the smart contract, and the smart contract queries the key position information corresponding to the ID card, and the key position information can be the first six digits and the last four digits of the ID card number; according to the metadata directory, the string data corresponding to the ID card number is obtained, and the first six digits and the last four digits of the string data are obtained; the first six digits and the last four digits of the string data corresponding to the ID card number are replaced with X to obtain the replaced string, and the unreplaced string is spliced ​​to obtain the processed ID card number data.

[0123] The preset replacement strategy may be to replace a character with a specific character or image to hide key position information.

[0124] Furthermore, the step of performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate further includes:

[0125] When the license operation mode is the second operation mode, querying the center coordinate position template corresponding to the license type;

[0126] Generate target watermark data according to the preset watermark information and the center coordinate position template;

[0127] Filling the target watermark data into the target electronic certificate data to obtain watermarked electronic certificate data;

[0128] The watermarked electronic certificate data is converted into a photo to obtain a target electronic certificate.

[0129] In the specific implementation, when the certificate operation mode is the watermark operation mode, the center coordinate position template corresponding to the electronic certificate type can be found; the watermark information data in the operation instruction is merged with the center coordinate position template to obtain the watermark data; the watermark data is added to the electronic certificate OFD format file to obtain the electronic certificate data after the watermark operation is added.

[0130] Among them, the coordinate position templates corresponding to each type of electronic certificate are pre-stored in the smart contract. The smart contract queries the center coordinate position template corresponding to the ID card to obtain the watermark information data in the operation instruction, for example: only for business processing.

[0131] Add the watermark data to the OFD format file of the electronic ID card obtained from the blockchain, and you will get the electronic ID card data with the "for business processing only" watermark added in the "center position".

[0132] In this embodiment, a smart contract is used to hide or add a watermark to a specific location of the electronic certificate to be displayed by the user, thereby obtaining processed electronic certificate data. When the user subsequently displays the certificate, information leakage and misuse can be avoided. In addition, since the operation instructions are operation configurations corresponding to the business type, the user only needs to click the business type to realize automatic processing of the electronic certificate, which is convenient and fast.

[0133] In addition, refer to Figure 6 The present invention further provides an electronic certificate display device, which is applied to a terminal device and includes:

[0134] The generating module 10 is configured to generate a one-time certificate and certificate operation information according to the electronic certificate display instruction when receiving the electronic certificate display instruction.

[0135] The sending module 20 is used to send the one-time credential and the certificate operation information to the cloud server, so that the cloud server can feedback the target electronic certificate according to the certificate operation information and the one-time credential.

[0136] The display module 30 is used to display the target electronic certificate.

[0137] In one embodiment, the generation module 10 is further used to obtain certificate operation information and valid timestamp information through the SIM card in response to the electronic certificate display instruction; determine the target original certificate through a preset electronic certificate list based on the certificate operation information; and generate a one-time certificate based on the valid timestamp, the target original certificate and preset signature data.

[0138] In one embodiment, the sending module 20 is further used to encapsulate the one-time credential and the certificate operation information to obtain an encapsulated data packet; perform secondary encryption on the encapsulated data packet to obtain a target data packet; and send the target data packet to a cloud server so that the cloud server decrypts the target data packet through a smart contract to obtain the certificate operation information and the one-time credential, and feeds back the target electronic certificate based on the certificate operation information and the one-time credential.

[0139] In one embodiment, the sending module 20 is further used to symmetrically encrypt the encapsulated data packet based on a preset first public key to obtain a first data packet; and asymmetrically encrypt the first data packet based on a preset second public key and a preset first private key to obtain a target data packet.

[0140] This embodiment generates a one-time pass certificate and certificate operation information according to the electronic certificate display instruction input by the user, and sends the one-time pass certificate and certificate operation information to the cloud server for identity authentication. After the verification is passed, the target electronic certificate is generated according to the certificate operation information for the queried certificate, and then the cloud server can feed the target electronic certificate back to the terminal for display. In this process, by setting a one-time certificate and operating the certificate, the identity information on the certificate is prevented from being leaked, thereby avoiding the technical problems of easy leakage of identity information and low security when the electronic certificate is displayed in the existing technology, thereby improving the security of user identity information and improving the user experience.

[0141] In addition, refer to Figure 7 The present invention further provides an electronic certificate display device, which is applied to a cloud server and includes:

[0142] The decryption module 10' is used to decrypt the target data packet sent by the terminal device through the smart contract to obtain the certificate operation information and the one-time certificate.

[0143] The verification module 20' is configured to perform identity authentication based on the one-time credential.

[0144] The feedback module 30' is used to feedback the target electronic certificate to the terminal device according to the certificate operation information and the one-time credential when the identity authentication is passed, so that the terminal device displays the target electronic certificate.

[0145] In one embodiment, the feedback module 30' is further used to read the electronic certificate data corresponding to the one-time certificate in the blockchain through a smart contract; convert the format of the electronic certificate data to obtain target electronic certificate data; perform certificate processing on the target electronic certificate data according to the certificate operation information to obtain a target electronic certificate; and send the target electronic certificate to the terminal device.

[0146] In one embodiment, the feedback module 30' is further used to perform data parsing on the target electronic certificate data to obtain metadata directory and template data when the certificate operation mode is the first operation mode; determine the certificate type and corresponding key position information of the target electronic certificate data when the certificate operation position is a key position; determine initial string data based on the key position information and the metadata directory; replace the initial string data based on a preset replacement strategy to obtain target identity information data; and generate a target electronic certificate based on the target identity data and the template data.

[0147] In one embodiment, the feedback module 30' is also used to query the center coordinate position template corresponding to the certificate type when the certificate operation mode is the second operation mode; generate target watermark data based on preset watermark information and the center coordinate position template; fill the target watermark data into the target electronic certificate data to obtain watermarked electronic certificate data; and convert the watermarked electronic certificate data into a photo to obtain the target electronic certificate.

[0148] In one embodiment, the decryption module 10' is further used to decrypt the target data packet using a preset first public key to obtain a first decrypted package; and decrypt the first decrypted package based on a second private key and the second public key to obtain a second decrypted package; and read the second decrypted package to obtain certificate operation information and a one-time certificate.

[0149] In this embodiment, a smart contract is used to hide or add a watermark to a specific location of the electronic certificate to be displayed by the user, thereby obtaining processed electronic certificate data. When the user subsequently displays the certificate, information leakage and misuse can be avoided. In addition, since the operation instructions are operation configurations corresponding to the business type, the user only needs to click the business type to realize automatic processing of the electronic certificate, which is convenient and fast.

[0150] In addition, to achieve the above-mentioned purpose, the present invention further provides a storage medium, on which an electronic certificate display program is stored. When the electronic certificate display program is executed by a processor, the electronic certificate display method as described above is implemented.

[0151] It should be understood that, although the various steps in the flowchart in the embodiment of the present application are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and they can be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and their execution order is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.

[0152] It should be understood that the above is only an example and does not constitute any limitation to the technical solution of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any limitation on this.

[0153] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of the present invention. In practical applications, technicians in this field can select part or all of it according to actual needs to achieve the purpose of the embodiment scheme, and no limitation is made here.

[0154] In addition, for technical details not fully described in this embodiment, please refer to the electronic certificate display method provided in any embodiment of the present invention, and will not be repeated here.

[0155] In addition, it should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0156] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0157] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, or of course by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as a read-only memory (ROM) / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.

[0158] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A method for displaying an electronic certificate, characterized in that: The electronic certificate display method is applied to a terminal device, and the electronic certificate display method includes: Upon receiving an electronic certificate display instruction, generating a one-time credential and certificate operation information according to the electronic certificate display instruction, the certificate operation information including a certificate operation position and a certificate operation method, the certificate operation position and the certificate operation method corresponding to the business type; Sending the one-time credential and the credential operation information to a cloud server, so that the cloud server reads the electronic credential data corresponding to the one-time credential in the blockchain through a smart contract; converting the electronic credential data to obtain target electronic credential data; performing credential processing on the target electronic credential data according to the credential operation information to obtain a target electronic credential; and sending the target electronic credential to the terminal device; Display the target electronic certificate.

2. The electronic certificate display method according to claim 1, wherein: The generating of the one-time certificate and certificate operation information according to the electronic certificate display instruction includes: In response to the electronic certificate display instruction, obtaining certificate operation information and valid timestamp information through the SIM card; Determine the target original certificate through the preset electronic certificate list based on the certificate operation information; A one-time credential is generated according to the valid timestamp, the target original credential and preset signature data.

3. A method for displaying an electronic certificate, characterized in that: The electronic certificate display method is applied to a cloud server, and the electronic certificate display method includes: Upon receiving a target data packet sent from a terminal device, the target data packet is decrypted through a smart contract to obtain license operation information and a one-time certificate. The license operation information includes a license operation location and a license operation method, and the license operation location and license operation method correspond to the business type. authenticating based on the one-time credentials; When the identity verification is passed, the electronic certificate data corresponding to the one-time certificate in the blockchain is read through the smart contract; Convert the electronic certificate data to obtain target electronic certificate data. Performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate; The target electronic certificate is sent to the terminal device so that the terminal device displays the target electronic certificate.

4. The electronic certificate display method according to claim 3, wherein: The license operation information includes the license operation position and license operation method; The step of performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate includes: When the certificate operation mode is the first operation mode, performing data parsing on the target electronic certificate data to obtain a metadata directory and template data; When the certificate operation position is a key position, determining the certificate type and corresponding key position information of the target electronic certificate data; determining initial character string data according to the key position information and the metadata directory; Replace the initial character string data based on a preset replacement strategy to obtain the target identity information data; A target electronic certificate is generated according to the target identity information data and the template data.

5. The electronic certificate display method according to claim 4, wherein: The step of performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate further includes: When the license operation mode is the second operation mode, querying the center coordinate position template corresponding to the license type; Generate target watermark data according to the preset watermark information and the center coordinate position template; Filling the target watermark data into the target electronic certificate data to obtain watermarked electronic certificate data; The watermarked electronic certificate data is converted into a photo to obtain a target electronic certificate.

6. An electronic certificate display device, characterized in that: The electronic certificate display device is applied to a terminal device, and the electronic certificate display device includes: a generating module configured to generate a one-time voucher and certificate operation information according to the electronic certificate display instruction upon receiving the electronic certificate display instruction, wherein the certificate operation information includes a certificate operation position and a certificate operation mode, wherein the certificate operation position and the certificate operation mode correspond to the business type; a sending module configured to send the one-time credential and the credential operation information to a cloud server, so that the cloud server reads the electronic credential data corresponding to the one-time credential in the blockchain through a smart contract; converts the format of the electronic credential data to obtain target electronic credential data; performs credential processing on the target electronic credential data according to the credential operation information to obtain a target electronic credential; and sends the target electronic credential to the terminal device; A display module is used to display the target electronic certificate.

7. An electronic certificate display device, characterized in that: The electronic certificate display device is applied to a cloud server, and the electronic certificate display device includes: A decryption module, configured to decrypt a target data packet sent from a terminal device through a smart contract upon receiving the target data packet, and obtain credential operation information and a one-time credential. The credential operation information includes a credential operation location and a credential operation method, and the credential operation location and the credential operation method correspond to the service type. a verification module, configured to perform identity authentication based on the one-time credential; A feedback module, configured to read the electronic certificate data corresponding to the one-time credential in the blockchain through a smart contract when the identity verification is passed; Convert the electronic certificate data to obtain target electronic certificate data. Performing certificate processing on the target electronic certificate data according to the certificate operation information to obtain the target electronic certificate; The target electronic certificate is sent to the terminal device so that the terminal device displays the target electronic certificate.

8. An electronic certificate display device, characterized in that: The electronic certificate display device includes: a memory, a processor, and an electronic certificate display program stored in the memory and executable on the processor. When the electronic certificate display program is executed by the processor, the electronic certificate display method according to any one of claims 1 or 2 or any one of claims 3 to 5 is implemented.

9. A storage medium, characterized in that: The storage medium stores an electronic certificate display program, which, when executed by a processor, implements the electronic certificate display method according to any one of claims 1 or 2 or any one of claims 3 to 5.

Citation Information

Patent Citations

  • Electronic license certificate issuing system

    CN107146186A

  • Electronic license library management system and method based on block chain

    CN116720824A