Data security information processing method and device based on mobile collaborative signature
By generating the public and private key pairs of user accounts on the first device and the service platform, and generating the target public keys in combination with two public keys, for generating digital certificates and signature information, the problem of difficult data security and legality in the prior art is solved, and an efficient and secure data signature process is achieved.
Patent Information
- Application Number
- CN202411677820.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-11-22
AI Technical Summary
The prior art is difficult to effectively ensure the security and legality of data during information processing, especially in the case of multi-party collaborative signatures, where there is a risk of private key loss or tampering, resulting in a reduction in data security.
By generating a public and private key pair of the first user account on the two nodes of the first device and the service platform, the target public key is generated in combination with the two public keys, and a digital certificate is generated. The first device uses the first public and private key to digitally sign the to be processed information, and the service platform then uses the second public and private key to digitally sign the signature information to complete the signature.
It improves the security and legality of data signatures, reduces the security risks caused by the loss of a single private key, enhances the protection of to-process information, and improves the user experience.
Smart Images

Figure CN119167407B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information processing technologies, and in particular, to a data security information processing method, apparatus, electronic device, storage medium, and computer program product based on mobile collaborative signature. Background Art
[0002] With the development of technology, information processing is increasingly applied in various fields. Information can include various types, such as data. By processing the information, information that meets the user's needs is obtained. The ways of information processing can include various types, such as encryption and verification. Summary of the Invention
[0003] Embodiments of the present disclosure provide a data security information processing method, apparatus, electronic device, storage medium, and computer program product based on mobile collaborative signature.
[0004] In a first aspect, embodiments of the present disclosure provide a data security information processing method based on mobile collaborative signature, which is applied to a first device. The method includes: generating a first public-private key pair of a first user account in a service platform; where the first public-private key pair is generated by the first device; obtaining, through the service platform, a digital certificate issued by a certificate authority for the first user account; where the digital certificate is generated by the certificate authority based on a target public key sent by the service platform and information related to the first user account; the target public key is obtained according to the first public key in the first public-private key pair and the second public key in a second public-private key pair, and the second public-private key pair is generated by the service platform for the first user account; performing a digital signature on the information to be processed according to the first private key in the first public-private key pair to obtain a first signature information; where the first signature information is used for the service platform to perform a digital signature on the first signature information using the second private key in the second public-private key pair to obtain a second signature information that completes the signature of the information to be processed; and sending the information to be processed carrying the first signature information and the digital certificate to the service platform.
[0005] In an embodiment, the obtaining, through the service platform, a digital certificate issued by a certificate authority for the first user account includes: sending the first public key to the service platform; receiving the digital certificate sent by the service platform; where the digital certificate is sent by the certificate authority to the service platform after generating the digital certificate.
[0006] In one embodiment, obtaining, by the service platform, the digital certificate issued by the certificate authority for the first user account includes: receiving the second public key sent by the service platform; obtaining the target public key according to the first public key and the second public key; sending the target public key to the service platform; receiving the digital certificate sent by the service platform; wherein the digital certificate is sent by the certificate authority to the service platform after generating the digital certificate.
[0007] In one embodiment, before generating the first public-private key pair of the first user account in the service platform, the method further includes: detecting an input operation acting on the login interface; wherein the login interface is the login interface of the service platform; determining login information according to the input operation; and logging in to the first user account according to the login information.
[0008] In one embodiment, the method further includes: detecting a selection operation acting on the second user account selection interface; determining the second user account according to the selection operation; wherein the second user account is used as the account for signing the to-be-processed information with the first user account.
[0009] In a second aspect, an embodiment of the present disclosure provides a data security information processing method based on mobile collaborative signature, which is applied to a service platform. The method includes: determining a target public key; wherein the target public key is obtained according to the first public key in the first public-private key pair of the first user account in the service platform and the second public key in the second public-private key pair of the first user account; the first public-private key pair is generated by a first device, and the second public-private key pair is generated by the service platform; obtaining, based on the target public key and the information related to the first user account, the digital certificate issued by the certificate authority for the first user account; wherein the digital certificate is generated by the certificate authority based on the target public key and the information related to the first user account; sending the digital certificate to the first device; receiving the to-be-processed information carried with the first signature information and the digital certificate sent by the first device; wherein the first signature information is obtained by digitally signing the to-be-processed information by the first private key in the first public-private key pair by the first device; digitally signing the first signature information by the second private key in the second public-private key pair to obtain the second signature information, thereby completing the signature of the to-be-processed information.
[0010] In one embodiment, the determining the target public key includes: receiving the first public key sent by the first device; and obtaining the target public key according to the first public key and the second public key.
[0011] In one embodiment, the determining the target public key includes: sending the second public key to the first device; receiving the target public key sent by the first device, where the target public key is obtained by the first device according to the first public key and the second public key.
[0012] In one embodiment, the obtaining, based on the target public key and the information related to the first user account, the digital certificate issued by the certificate authority for the first user account includes: sending the target public key and the information related to the first user account to the certificate authority; receiving the authorization certificate sent by the authorization center.
[0013] In one embodiment, the method further includes: determining the second user account determined by the first device; sending a signature notice of the to-be-processed information to the second device associated with the second user account.
[0014] In one embodiment, the method further includes: performing identity authentication on the login information according to the login information input by the first device; logging in to the first user account when the login information authentication is successful.
[0015] In one embodiment, the method further includes: after verifying that the digital certificate is a digital certificate issued by a preset certificate authority, obtaining the target public key according to the digital certificate; performing signature verification on the second signature information according to the target public key; if the verification is successful, proving that the second signature information is the signature information of the first user account.
[0016] In a third aspect, an embodiment of the present disclosure provides a data security information processing device based on mobile collaborative signature, including: a generation module, configured to generate a first public-private key pair of a first user account in a service platform; wherein, the first public-private key pair is generated by the first device; a first acquisition module, configured to acquire, through the service platform, a digital certificate issued by a certificate authority for the first user account; wherein, the digital certificate is generated by the certificate authority based on a target public key sent by the service platform and information related to the first user account; the target public key is obtained according to a first public key in the first public-private key pair and a second public key in a second public-private key pair, and the second public-private key pair is generated by the service platform for the first user account; a first signature module, configured to perform a digital signature on information to be processed according to a first private key in the first public-private key pair, to obtain first signature information; wherein, the first signature information is used for the service platform to perform a digital signature on the first signature information by using a second private key in the second public-private key pair, to obtain second signature information that completes the signature of the information to be processed; a first sending module, configured to send the information to be processed carrying the first signature information and the digital certificate to the service platform.
[0017] In a fourth aspect, an embodiment of the present disclosure provides a data security information processing device based on mobile collaborative signature, including: a determination module, configured to determine a target public key; wherein, the target public key is obtained according to a first public key in a first public-private key pair of a first user account in the service platform and a second public key in a second public-private key pair of the first user account; the first public-private key pair is generated by a first device, and the second public-private key pair is generated by the service platform; a second acquisition module, configured to obtain, based on the target public key and information related to the first user account, a digital certificate issued by a certificate authority for the first user account; wherein, the digital certificate is generated by the certificate authority based on the target public key and information related to the first user account; a second sending module, configured to send the digital certificate to the first device; a receiving module, configured to receive the information to be processed sent by the first device and carrying first signature information and the digital certificate; wherein, the first signature information is obtained by the first device performing a digital signature on the information to be processed by using a first private key in the first public-private key pair; a second signature module, configured to perform a digital signature on the first signature information by using a second private key in the second public-private key pair, to obtain second signature information and complete the signature of the information to be processed.
[0018] In a fifth aspect, an embodiment of the present disclosure further provides an electronic device, which includes:
[0019] At least one processor; and,
[0020] A memory communicatively connected to the at least one processor; wherein,
[0021] The memory stores instructions or computer programs executable by the at least one processor, and when the instructions or computer programs are executed by the at least one processor, the at least one processor is enabled to execute the information processing method in any implementation manner of any of the foregoing first aspect or second aspect.
[0022] In a sixth aspect, an embodiment of the present disclosure further provides a non-transitory computer-readable storage medium storing a computer program or computer instructions for causing the computer to execute the information processing method in any implementation manner of any of the foregoing first aspect or second aspect.
[0023] In a seventh aspect, an embodiment of the present disclosure further provides a computer program product including a computing program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, and when the program instructions are executed by a computer, causing the computer to execute the information processing method in any implementation manner of any of the foregoing first aspect or second aspect.
[0024] Compared with the prior art, the technical solution provided by the embodiment of the present disclosure has at least the following technical effects:
[0025] By respectively generating a public-private key pair of a first user account on two different nodes of a first device and a service platform, obtaining a target public key according to the public keys in the two public-private key pairs, and the target public key is used to generate a digital certificate of the first user account. The first device signs through the first private key in the first public-private key pair to obtain first signature information, and the first signature information is used for the service platform to perform re-signature, thereby completing the signature of the information to be processed.
[0026] In the solution of this embodiment, during the process of signing the information to be processed, a part of the private key of the first user account generated by the first device and another part of the private key of the first user account generated by the service platform are combined to sign the information to be processed. When generating the digital certificate of the first user account, a part of the public key of the first user account generated by the first device and another part of the public key of the first user account generated by the service platform are also combined to generate a digital certificate of the first user account. The digital certificate includes information of the first user account, such as the target public key, which can verify the identity of the first user account and ensure the legal identity of the signing party. Signing the information to be processed with two private keys can improve the security and legality of the signed information to be processed, reduce the situation where the security of the information to be processed is reduced due to the loss of a single private key for encrypting the information to be processed, improve the security of relevant information during the signing process, reduce the situation where the information is tampered with, and thus improve the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0028] Figure 1 It is a schematic flowchart of an information processing method provided by an embodiment of the present disclosure;
[0029] Figure 2 It is a schematic flowchart of a method for obtaining a digital certificate provided by an embodiment of the present disclosure;
[0030] Figure 3 It is another schematic diagram of a method for obtaining a digital certificate provided by an embodiment of the present disclosure;
[0031] Figure 4 It is another schematic diagram of an information processing method provided by an embodiment of the present disclosure;
[0032] Figure 5 It is another schematic diagram of an information processing method provided by an embodiment of the present disclosure;
[0033] Figure 6 It is another schematic diagram of an information processing method provided by an embodiment of the present disclosure;
[0034] Figure 7 It is another schematic diagram of an information processing method provided by an embodiment of the present disclosure;
[0035] Figure 8Structural schematic diagram of an information processing device provided by an embodiment of the present disclosure;
[0036] Figure 9 Structural schematic diagram of another information processing device provided by an embodiment of the present disclosure;
[0037] Figure 10 Schematic diagram of another information processing method provided by an embodiment of the present disclosure;
[0038] Figure 11 Schematic diagram of an electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0039] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0040] The following uses specific specific examples to illustrate the implementation manners of the present disclosure. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without making creative efforts belong to the scope of protection of the present disclosure.
[0041] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device can be implemented and this method can be practiced using other structures and / or functions in addition to one or more of the aspects described herein.
[0042] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure schematically. Only the components related to the present disclosure are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be an arbitrary change, and the component layout type may also be more complex.
[0043] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0044] Embodiments of the present disclosure provide a method for processing information. The information processing method provided in this embodiment can be executed by a computing device, which can be implemented as software, or as a combination of software and hardware. The computing device can be integrally provided in a server, a terminal device, etc.
[0045] Referring to Figure 1 , a data security information processing method based on mobile collaborative signature provided by an embodiment of the present disclosure. This method can be applied to a first device, and mainly includes the following steps:
[0046] S101: Generate a first public-private key pair for the first user account in the service platform. Among them, the first public-private key pair is generated by the first device.
[0047] S102: Obtain, through the service platform, the digital certificate issued by the certificate authority for the first user account. Among them, the digital certificate is generated by the certificate authority based on the target public key sent by the service platform and the information related to the first user account; the target public key is obtained according to the first public key in the first public-private key pair and the second public key in the second public-private key pair, and the second public-private key pair is generated by the service platform for the first user account.
[0048] S103: Perform digital signature on the information to be processed according to the first private key in the first public-private key pair to obtain the first signature information. Among them, the first signature information is used for the service platform to perform digital signature on the information to be processed and / or the first signature information using the second private key in the second public-private key pair to obtain the second signature information that completes the signature of the information to be processed.
[0049] S104: Send the information to be processed carrying the first signature information and the digital certificate to the service platform.
[0050] The first device can be a mobile terminal device and a fixed terminal device. The mobile terminal device can include, but is not limited to: mobile phones, tablet computers, wearable devices, and personal computers (PCs).
[0051] The first device can log in to the service platform, and the login method is not limited, including but not limited to: web form and client form. The client can include application programs. When logging in to the service platform through the client, the client is installed in the first device.
[0052] The service platform can be a platform for processing information to be processed, or a platform dedicated to processing information to be processed. For example, the service platform can be a signature platform provided for multiple parties signing information to be processed. During the signature process, with the platform as the intermediate node, the multiple parties signing the information to be processed sign relevant information through the service platform.
[0053] Exemplarily, the service platform can include but is not limited to: a contract signing platform, a trading platform, etc.
[0054] Exemplarily, the information to be processed can include electronic contracts, transaction information, electronic tender documents for bidding, electronic certification documents, legal documents, etc.
[0055] The service platform can provide a service system, in which functions such as user account registration, account login, information storage, information download, information preview, and identity authentication can be provided for users.
[0056] For S101, the first user account is an account registered on the service platform, and the first user account can be any account that has been successfully registered on the service platform. The account registration process is not limited, and registration can be carried out through the registration process of the service platform and the relevant information required for registration.
[0057] The first device is the device required to log in to the first user account, that is, log in to the first user account through the first device. For example, by logging in to the first user account through the application program of the service platform installed in the first device, it also realizes logging in to the service platform through the first user account.
[0058] Exemplarily, the first user account is one of the accounts of multiple parties signing the information to be processed.
[0059] Exemplarily, the first user account can be a personal account or a corporate account.
[0060] The first device can generate a public-private key pair of the first user account in the first device, and record this public-private key pair as the first public-private key pair. The first public-private key pair includes a public key and a private key. The public key in the first public-private key pair can be recorded as the first public key, and the private key in the first public-private key pair can be recorded as the first private key.
[0061] The method by which the first device generates the first public-private key pair is not limited, and it can be generated by any method of generating a public-private key pair, that is, as long as the first device can generate the public-private key pair of the first user account.
[0062] Exemplarily, the service platform may also generate a public-private key pair for the first user account, record the public-private key pair as the second public-private key pair. The second public-private key pair also includes a public key and a private key. Denote the public key as the second public key and the private key as the second private key.
[0063] Exemplarily, after logging in to the first user account in the service platform through the first device, the service platform may detect that the first user account is already in the logged-in state. When the first user account is in the logged-in state, the service platform may generate a second public-private key pair for the first user account.
[0064] Exemplarily, the service platform may also generate a second public-private key pair when the first user account is in the non-logged-in state.
[0065] The first device and the service platform may respectively generate a public-private key pair for the first user account. In this way, two public-private key pairs of the first user account can be obtained, and two private keys and two public keys of the first user account can be obtained. The first public-private key pair is located in the first device, the second public-private key pair is located in the service platform. The first device has the first public-private key pair, and the service platform has the second public-private key pair.
[0066] For S102, after generating the first public-private key pair, the first device may obtain the digital certificate issued by the certificate authority for the first user account through the service platform. The Certificate Authority (CA), as the issuer of digital certificates, is responsible for reviewing and issuing digital certificates to users. The digital certificate issued by the CA can ensure identity authentication and data transmission security in network communication.
[0067] The second public-private key pair is generated by the service platform for the first user account. After obtaining the second public-private key pair, the second public key in the second public-private key pair can be obtained. The target public key is obtained based on the first public key in the first public-private key pair and the second public key in the second public-private key pair. The target public key can be obtained by the first device based on the first public key and the second public key, or can be obtained by the service platform based on the first public key and the second public key.
[0068] Exemplarily, the method of obtaining the target public key based on the first public key and the second public key is not limited, including but not limited to: performing dot multiplication or other operations on the first public key and the second public key to obtain the target public key.
[0069] Since the first user account has two public-private key pairs and thus has two public keys, after obtaining a target public key based on the first public key and the second public key, the digital certificate of the first user account can be obtained based on the target public key.
[0070] After obtaining the target public key, the service platform can send the target public key to the certificate authority, so as to facilitate the certificate authority to generate a digital certificate for the first user account according to the target public key.
[0071] The certificate authority can also generate a digital certificate for the first user account according to the information related to the first user account. The information related to the first user account may include holder information, issuer information, validity period, etc. The holder information is the account information of the first user account, including the account name of the first user account, the information of the owner of the first user account, and other information that can identify the first user account. The information of the owner of the first user account may include name, age, gender, contact information, and facial image, etc. The contact information may include email address and real-name certified mobile phone number.
[0072] Exemplarily, the information related to the first user account can be stored on the service platform. When the first user account is registered, it can be registered through the information related to the first user account. After the registration is completed, the information related to the first user account can be stored on the service platform. The service platform can obtain the information related to the first user account.
[0073] The service platform can send the target public key and the information related to the first user account to the certificate authority.
[0074] Exemplarily, the certificate authority receives the target public key and the information related to the first user account sent by the service platform.
[0075] After receiving the target public key and the information related to the first user account sent by the service platform, the certificate authority can generate a digital certificate for the first user account according to the target public key and the information related to the first user account. That is, the digital certificate is generated by the certificate authority based on the target public key sent by the service platform and the information related to the first user account. The digital certificate is issued by the certificate authority for the first user account.
[0076] The process of the certificate authority generating the digital certificate is not limited. For example, the private key of the certificate authority can be used to encrypt the target public key and the information related to the first user account to obtain the digital signature of the certificate authority. Packing the digital signature of the certificate authority, the target public key, and the information related to the first user account into one piece of information is the digital certificate.
[0077] The digital certificate can authenticate the identity of the first user account, that is, authenticate the first user account, so as to facilitate the authentication of the signatory of the information to be processed and ensure that the signatory has a legal identity.
[0078] Exemplarily, after the certificate authority generates a digital certificate, the certificate authority may send the digital certificate to the service platform.
[0079] Exemplarily, the service platform receives the digital certificate sent by the certificate authority and sends the received digital certificate to the first device.
[0080] The first device may receive the digital certificate sent by the service platform and save the digital certificate in the first device.
[0081] For example, the service platform may send the digital certificate to the first user account, and the first device may obtain the digital certificate and save the digital certificate in the first device.
[0082] Exemplarily, it may further include:
[0083] The first device sends an application for a digital certificate to the service platform.
[0084] Exemplarily, it may further include:
[0085] The service platform receives the application for the digital certificate sent by the first device and sends the application for the digital certificate to the certificate authority.
[0086] The service platform may send the application for the digital certificate, the target public key, and the information related to the first user account to the certificate authority. This can facilitate the certificate authority to issue a digital certificate for the first user account.
[0087] For S103, after the first device receives the digital certificate, the first device performs a digital signature on the information to be processed according to the first private key in the first public-private key pair, obtaining the first signature information. Since the first public-private key pair is stored in the first device, the first device can use the first private key in the first public-private key pair to encrypt the information to be processed, obtaining the digital signature, that is, the first signature information.
[0088] This first signature information is used for the service platform to use the second private key in the second public-private key pair to perform a digital signature on the information to be processed and / or the first signature information, obtaining the second signature information that completes the signature of the information to be processed.
[0089] After obtaining the first signature information, this first signature information is not the final signature. It still requires the service platform to perform another encryption to obtain another digital signature, that is, the second signature information.
[0090] For S104, after encrypting the information to be processed, that is, performing a digital signature using the first private key, the information to be processed carrying the first signature information and the digital certificate is sent to the service platform.
[0091] This facilitates the service platform to use the second private key in the second public-private key pair to digitally sign the first signature information, obtaining the second signature information that completes the signature of the information to be processed.
[0092] After obtaining the second signature information, the digital signature of the information to be processed is completed.
[0093] Exemplarily, after the service platform receives the information to be processed carried with the first signature information and the digital certificate sent by the first device, it can use the second private key in the second public-private key pair to digitally sign the first signature information, obtaining the second signature information and completing the signature of the information to be processed.
[0094] In the solution of this embodiment during the process of signing the information to be processed, a part of the private key of the first user account generated by the first device and another part of the private key of the first user account generated by the service platform are combined to sign the information to be processed. When generating the digital certificate of the first user account, a part of the public key of the first user account generated by the first device and another part of the public key of the first user account generated by the service platform are also combined to generate a digital certificate of the first user account. The digital certificate includes information of the first user account, such as the target public key, which can verify the identity of the first user account and ensure the legal identity of the signing party. Signing the information to be processed with two private keys can improve the security and legality of the signature of the information to be processed, reduce the situation of reduced security of the information to be processed caused by the loss of a single private key in the case of encrypting the information to be processed with a single private key, improve the security of relevant information during the signature process, reduce the situation of information being tampered with, and thus improve the user experience.
[0095] In one embodiment, referring to Figure 2 , it is a schematic diagram of obtaining a digital certificate. Obtaining the digital certificate issued by the certificate authority for the first user account through the service platform includes:
[0096] S201, sending the first public key to the service platform.
[0097] S202, receiving the digital certificate sent by the service platform; wherein, the digital certificate is sent to the service platform by the certificate authority after generating the digital certificate.
[0098] For the first device, this embodiment provides an example of obtaining a digital certificate.
[0099] The first device can send the first public key generated by the first device to the service platform, thereby facilitating the service platform to receive the first public key and the generation of the target public key.
[0100] Under normal circumstances, information interaction can occur between the service platform and the certificate authority, and there is a trust relationship between them. The terminal device and the certificate authority need to interact with each other through the service platform, and the terminal device and the certificate authority can respectively interact with the service platform.
[0101] In this embodiment, the target public key is generated by the service platform based on the first public key and the second public key.
[0102] Exemplarily, it may further include:
[0103] The service platform receives the first public key;
[0104] The service platform generates a target public key based on the first public key and the second public key;
[0105] The service platform sends the target public key to the certificate authority;
[0106] The service platform receives the digital certificate issued by the certificate authority; this digital certificate is generated by the certificate authority based on the target public key and the relevant information of the first user account;
[0107] The service platform sends the digital certificate to the first device.
[0108] In one embodiment, referring to Figure 3 , it is another schematic diagram for obtaining a digital certificate. Obtaining the digital certificate issued by the certificate authority for the first user account through the service platform includes:
[0109] S301, receive the second public key sent by the service platform;
[0110] S302, obtain the target public key based on the first public key and the second public key;
[0111] S303, send the target public key to the service platform;
[0112] S304, receive the digital certificate sent by the service platform; wherein, the digital certificate is sent to the service platform by the certificate authority after generating the digital certificate.
[0113] In this embodiment, the solution is to generate a target public key for the first device. The service platform sends the second public key to the first device, the first device receives the second public key sent by the service platform, and the first device generates the target public key based on the first public key and the second public key. After generating the target public key, the first device sends the target public key to the service platform, so as to facilitate the service platform to send the target public key to the certificate authority and the certificate authority to generate the digital certificate.
[0114] Exemplarily, the method further includes:
[0115] The certificate authorization center receives the target public key sent by the service platform and the relevant information of the first user account;
[0116] The certificate authorization center generates a digital certificate for the first user account according to the target public key and the relevant information of the first user account.
[0117] The certificate authorization center sends the digital certificate to the service platform.
[0118] The service platform accepts the digital certificate sent by the certificate authorization center.
[0119] In one embodiment, referring to Figure 4 , it is a schematic diagram of another information processing method. Before generating the first public-private key pair of the first user account in the service platform, the method further includes:
[0120] S401, detecting the input operation on the login interface; wherein, the login interface is the login interface of the service platform.
[0121] S402, determining the login information according to the input operation.
[0122] S403, logging in to the first user account according to the login information.
[0123] This embodiment provides an example for authenticating the first user account.
[0124] The first device can display a login interface for logging in to the first user account, and this login interface can be the login interface of the service platform, and the service platform is logged in through the first user account. The display manner of the login interface and the content, format or other configuration parameters of the login interface are not limited.
[0125] Exemplarily, the login interface includes a login information input control for inputting the login information of the first user account. The login information can include an account name and a password, etc. The login information can also include information related to the first user account, such as the information of the owner of the first user account and other information that can identify the first user account. The information of the owner of the first user account can include name, age, gender, contact information and facial image, etc. The contact information can include an email address and a real-name certified mobile phone number.
[0126] After the login information is input, the login information is authenticated, and in the case of successful authentication, the first user account is logged in according to the login information.
[0127] After logging in to the first user account, the first public-private key pair of the first user account and subsequent various operations can be generated through the first device.
[0128] In one embodiment, referring toFigure 5 , which is a schematic diagram of another data security information processing method based on mobile collaborative signature. This method further includes:
[0129] S501, detecting a selection operation acting on the second user account selection interface;
[0130] S502, determining a second user account according to the selection operation; wherein, the second user account is used as the account for signing the information to be processed with the first user account.
[0131] This embodiment provides an example of determining an account that jointly processes the information to be processed with the first user account.
[0132] The second user account is not limited to one, and can also be multiple. Any account other than the first user account that jointly processes the information to be processed with the first user account can be used as the second user account.
[0133] The first device can also display the second user account selection interface, and this second user account selection interface can be the interface after logging in to the service platform. The display content, display format, and other parameters of the second user account selection interface are not limited.
[0134] The second user account selection interface can include a selection control or an input control for the second user account. Through the selection control, the second user account can be selected from the reference accounts, and through the input control, the second user account can be input.
[0135] The first device can detect the selection operation acting on the second user account selection interface. After detecting the selection operation, the second user account can be determined according to the selection operation.
[0136] This can facilitate the first user account and the second user account to jointly complete the processing of the information to be processed.
[0137] In one embodiment, refer to Figure 6 , which is a schematic diagram of another data security information processing method based on mobile collaborative signature. This method can be applied to the service platform, and this method includes:
[0138] S601, determining a target public key; wherein, the target public key is obtained according to the first public key in the first public-private key pair of the first user account in the service platform and the second public key in the second public-private key pair of the first user account; the first public-private key pair is generated by the first device, and the second public-private key pair is generated by the service platform.
[0139] S602. Obtain the digital certificate issued by the certificate authority for the first user account based on the target public key and the information related to the first user account; wherein, the digital certificate is generated by the certificate authority based on the target public key and the information related to the first user account.
[0140] S603. Send the digital certificate to the first device.
[0141] S604. Receive the information to be processed carried with the first signature information and the digital certificate sent by the first device. Wherein, the first signature information is obtained by the first device digitally signing the information to be processed with the first private key in the first public-private key pair.
[0142] S605. Digitally sign the first signature information with the second private key in the second public-private key pair to obtain the second signature information, and complete the signature of the information to be processed.
[0143] The description of this embodiment can refer to the description of the corresponding embodiments in S101 to S104.
[0144] In one embodiment, determining the target public key includes:
[0145] Receive the first public key sent by the first device, and obtain the target public key according to the first public key and the second public key.
[0146] This embodiment is an example of the service platform generating the target public key. The first device sends the first public key generated by the first device to the service platform. The service platform receives the first public key sent by the first device, and the service platform generates the target public key according to the first public key and the second public key.
[0147] In one embodiment, determining the target public key includes:
[0148] Send the second public key to the first device, and receive the target public key sent by the first device, where the target public key is obtained by the first device according to the first public key and the second public key.
[0149] This embodiment is an example of the first device generating the target public key. The service platform sends the second public key to the first device. The first device receives the second public key sent by the service platform. The first device generates the target public key according to the first public key and the second public key. The first device sends the target public key to the service platform, and the service platform receives the target public key sent by the first device.
[0150] Exemplarily, the process of generating the target public key according to the first public key and the second public key is not limited. For example, multiplying the first public key and the second public key or other operations are used to obtain the target public key.
[0151] Exemplarily, the forms of the first public key, the second public key, and the target public key are not limited, and they can be numbers and / or letters, etc.
[0152] In one embodiment, based on the target public key and the information related to the first user account, the digital certificate issued by the certificate authority for the first user account is obtained, including:
[0153] Send the target public key and the information related to the first user account to the certificate authority, and receive the authorization certificate sent by the authorization center.
[0154] It may include the description of the corresponding embodiment in the above embodiment related to this part of the content.
[0155] In one embodiment, the method further includes:
[0156] Determine the second user account determined by the first device, and send a signature notice of the information to be processed to the second device associated with the second user account.
[0157] The second device is the device managed by the second user account, which may be the device currently logged in by the second user account, or the device used by the owner of the second user account, such as the device where the mobile phone number associated with the owner is located.
[0158] The form of the signature notice is not limited and can be determined according to business requirements, such as a short message or an email. A short message can be sent to the mobile phone number associated with the second user account. This can timely notify the owner of the second user account to perform corresponding operations, improve the processing efficiency of the information to be processed, and be able to complete the processing of the information to be processed faster, ensuring the timeliness of processing the information to be processed.
[0159] In one embodiment, the method further includes:
[0160] Authenticate the login information according to the login information input by the first device. If the login information authentication is successful, log in to the first user account.
[0161] The description of this embodiment can refer to the description of the corresponding embodiment on the first device side above.
[0162] In one embodiment, referring to Figure 7 , it is a schematic diagram of another data security information processing method based on mobile collaborative signature. The method further includes:
[0163] S701, after verifying that the digital certificate is a digital certificate issued by a preset certificate authority, obtain the target public key according to the digital certificate.
[0164] S702, perform signature verification on the second signature information according to the target public key.
[0165] S703, if the verification is successful, prove that the second signature information is the signature information of the first user account.
[0166] This embodiment provides an example of verifying signature information.
[0167] The service platform stores information of a preset certificate authority, such as a public key and a certificate chain, etc. The preset certificate authority can be the certificate authority that sends a digital certificate containing the target public key to the service platform.
[0168] The digital certificate includes the signature information of the certificate authority, the public key, the issuer information, the validity period, the information of the party to which the digital certificate belongs, etc.
[0169] It is possible to first verify whether the digital certificate is a digital certificate issued by the preset certificate authority. For example, the signature information in the digital certificate can be verified by the public key of the preset certificate authority. If the signature can be successfully decrypted, it means that the digital certificate is a digital certificate issued by the preset certificate authority.
[0170] It is also possible to verify through the certificate chain of the certificate authority in the digital certificate. If the verification through the certificate chain of the certificate authority can be passed, it proves that the digital certificate is issued by the preset certificate authority.
[0171] Exemplarily, after verifying the digital certificate through the certificate chain of the certificate authority or verifying the signature in the digital certificate by the public key of the preset certificate authority, it indicates that the digital certificate has not been tampered with, and the public key contained in the digital certificate has not been tampered with either. It means that the digital certificate is a digital certificate issued by the certificate authority to the first user account, and the public key contained in the digital certificate is the target public key.
[0172] When it is determined that the target public key is the target public key of the first user account, according to this target public key, the private key corresponding to this target public key is determined. For example, the first user account can be determined through the target public key, and then the first public key of the first user account generated by the first device and the second public key of the first user account generated by the service platform can be determined.
[0173] There is an association relationship between each user account and the secret keys generated by the first device and the service platform. The corresponding secret key can be determined according to the account.
[0174] Since the digital signature is signed according to the first private key and the second private key, the signature information is verified by the target public key obtained from the first public key and the second public key, so as to verify whether the signature information is the signature of the first account user. If the signature information verification is successful, it means that the signature information is the signature of the first account user. If the signature information verification fails, it means that the signature information is not the signature of the first account user, and there may be a security problem.
[0175] In this way, after the first private key is leaked, digital signatures cannot be made only with the first private key. If a digital signature is made only with the first private key, when the signature information is verified with the target public key in the digital certificate, the verification will fail. Through the combination of the first signature information and the second signature information, after double signing by the first device and the service platform, the signature information also needs to be verified with the target public key during verification, thereby improving the security of the information to be processed after digital signature by the first user account.
[0176] In one embodiment, referring to Figure 8 , it is a schematic diagram of a data security information processing device based on mobile collaborative signature. The device includes:
[0177] A generation module 1, configured to generate a first public-private key pair of a first user account in the service platform; wherein, the first public-private key pair is generated by the first device;
[0178] A first acquisition module 2, configured to obtain, through the service platform, a digital certificate issued by a certificate authority for the first user account; wherein, the digital certificate is generated by the certificate authority based on the target public key sent by the service platform and information related to the first user account; the target public key is obtained according to the first public key in the first public-private key pair and the second public key in the second public-private key pair, and the second public-private key pair is generated by the service platform for the first user account;
[0179] A first signature module 3, configured to perform a digital signature on the information to be processed according to the first private key in the first public-private key pair to obtain first signature information; wherein, the first signature information is used for the service platform to perform a digital signature on the first signature information with the second private key in the second public-private key pair to obtain second signature information that completes the signature of the information to be processed;
[0180] A first sending module 4, configured to send the information to be processed carrying the first signature information and the digital certificate to the service platform.
[0181] In one embodiment, referring to Figure 9 , it is a schematic diagram of another data security information processing device based on mobile collaborative signature. The device includes:
[0182] A determination module 10, configured to determine a target public key; wherein, the target public key is obtained according to the first public key in the first public-private key pair of the first user account in the service platform and the second public key in the second public-private key pair of the first user account; the first public-private key pair is generated by the first device, and the second public-private key pair is generated by the service platform;
[0183] A second acquisition module 20, configured to obtain a digital certificate issued by a certificate authority for the first user account based on the target public key and information related to the first user account; wherein, the digital certificate is generated by the certificate authority based on the target public key and information related to the first user account.
[0184] A second sending module 30, configured to send the digital certificate to the first device.
[0185] A receiving module 40, configured to receive the information to be processed carried with the first signature information and the digital certificate sent by the first device; wherein, the first signature information is obtained by the first device digitally signing the information to be processed with the first private key in the first public-private key pair.
[0186] A second signature module 50, configured to digitally sign the first signature information with the second private key in the second public-private key pair to obtain second signature information, thereby completing the signature of the information to be processed.
[0187] In one embodiment, with the popularization of the mobile Internet and the development of e-commerce technology, as the foundation and core of e-commerce, electronic contract data is increasingly used in online business activities.
[0188] Generally, the way to process electronic contract data is as follows: all parties to the contract first jointly determine the final content of the electronic contract through methods such as electronic data interchange or email reply, and then use traditional electronic signature methods to complete the signature and seal. Finally, it is transmitted to the other party through data interchange or email. This method is rather cumbersome to operate. Since there is no identity authentication and encryption processing for the electronic contract during its confirmation and transmission process, the electronic contract data is easily intercepted illegally, posing a threat to the business secrets and transaction security of all parties signing the contract, and there is a lack of security control for the management of the signed electronic contract data.
[0189] In addition, although the above-mentioned electronic signature method can guarantee the legality and non-repudiation of electronic contract data, it does not guarantee the legitimate identities of the signers of the electronic contract data, and there is a lack of timeliness in the signing process of the electronic contract by all parties.
[0190] Reference Figure 10 , is a schematic diagram of another data security information processing method based on mobile collaborative signature provided for this embodiment. The process includes the following:
[0191] S1: Register the first user account and the second user account on the service platform, including: all parties to the contract first register an account on the electronic contract management platform and use a mobile phone number authenticated by the operator as the account username.
[0192] Exemplarily, the service platform may include an electronic contract management platform.
[0193] S2: Log in to the first user account through the first device, including: after the parties to the contract log in to the electronic contract management platform on the mobile intelligent terminal, they respectively conduct identity authentication for different roles (such as personal identity authentication and enterprise real-name authentication).
[0194] S3: After the parties to the contract complete the identity authentication for their respective roles, a pair of public and private key factors are generated on the mobile intelligent terminal and the management platform respectively. After the mobile intelligent terminal sends the generated public key factor P1 to the management platform, P1 and the management platform's own public key P2 are synthesized into a public key P through operations such as dot multiplication. The first device includes the mobile intelligent terminal.
[0195] S4: After the CA center confirms the identities of the parties to the contract, it generates mobile digital certificates using the synthesized public key P and information related to the first user account, and issues their respective mobile signature digital certificates, encryption digital certificates, and encryption private keys to the parties to the contract and records them on the mobile intelligent terminal side.
[0196] S5: After the contract party A passes the identity authentication and logs in to the electronic contract management platform, it can create a contract and can select the party B or other parties whose identities have been confirmed to send an electronic contract signing SMS notification.
[0197] S6: After the parties to the contract pass the identity authentication and log in to the electronic contract management platform using the mobile intelligent terminal, they can implant a mobile collaborative electronic signature calculated using their respective mobile digital certificates and key factors on the electronic contract.
[0198] S7: After the parties to the contract pass the identity authentication and log in to the electronic contract management platform using the mobile intelligent terminal, they can preview the electronic contract data. If there is unauthorized access during the identity authentication, the preview of the electronic contract data will not be possible.
[0199] S8: After the parties to the contract pass the identity authentication and log in to the electronic contract management platform, they can download the electronic contract data. If there is unauthorized access during the identity authentication, the download of the electronic contract data will not be possible.
[0200] S9: The electronic contract management platform provides the verification function of the electronic contract data by verifying the mobile collaborative electronic signature implanted in S6. If the verification of the mobile collaborative electronic signature implanted in S6 fails, it indicates that the electronic contract data has been tampered with or is illegal, and at this time, it will be prompted that the electronic contract data is invalid.
[0201] Based on the submission of account data by all parties to the contract, identity authentication in line with the roles is achieved to safeguard the legitimate identities of the signers of electronic contract data. All parties to the contract can quickly and conveniently complete the signing process of the electronic contract, ensuring the timeliness of the electronic contract signing. Through the identity authentication of all parties to the contract, security control over the access and download of electronic contract data is guaranteed.
[0202] By providing an electronic contract data verification platform, ex post verification of the legality of electronic contract data is guaranteed. The data processing method based on mobile collaborative signature of the present invention can be applied not only to the scenario of electronic contract signing, but also to electronic documents involving multi-party cooperation signing, such as: legal document signing, customer documents of financial institutions such as banks and insurance companies, electronic guarantee letter signing, tender documents for electronic bidding, and proof document signing scenarios.
[0203] This embodiment adopts a CA mobile digital certificate and combines digital signature and identity recognition technology to improve the timeliness of the electronic contract signing process and the security and confidentiality of electronic contract data processing.
[0204] See Figure 11 , this embodiment of the disclosure also provides an electronic device 60, which includes:
[0205] At least one processor; and,
[0206] A memory communicatively connected to the at least one processor; wherein,
[0207] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the information processing method in the foregoing method embodiment.
[0208] This embodiment of the disclosure also provides a non-transitory computer-readable storage medium, which stores computer instructions for causing the computer to execute the foregoing method embodiment.
[0209] This embodiment of the disclosure also provides a computer program product, which includes a computing program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer is enabled to execute the information processing method in the foregoing method embodiment.
[0210] Refer to Figure 11, which shows a schematic structural diagram of an electronic device 60 suitable for implementing the embodiments of the present disclosure. The electronic devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), vehicle terminals (such as vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 11 The electronic device shown is only an example and should not impose any limitations on the functions and scope of use of the embodiments of the present disclosure.
[0211] As Figure 11 shown, the electronic device 60 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 602 or the programs loaded from the storage device 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 60 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0212] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 60 to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device 60 having various devices, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be implemented or had alternatively.
[0213] Specifically, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.
[0214] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0215] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; it can also exist separately without being assembled into the electronic device.
[0216] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device is caused to: obtain at least two Internet protocol addresses; send a node evaluation request including the at least two Internet protocol addresses to a node evaluation device, where the node evaluation device selects an Internet protocol address from the at least two Internet protocol addresses and returns it; receive the Internet protocol address returned by the node evaluation device; where the obtained Internet protocol addresses indicate edge nodes in a content distribution network.
[0217] Alternatively, the above computer-readable medium carries one or more programs which, when executed by the electronic device, cause the electronic device to: receive a node evaluation request including at least two Internet Protocol addresses; select an Internet Protocol address from the at least two Internet Protocol addresses; return the selected Internet Protocol address; wherein the received Internet Protocol address indicates an edge node in a content delivery network.
[0218] Computer program code for carrying out operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0219] The flowcharts and block diagrams in the figures illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the figures. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0220] The units described in the embodiments of the present disclosure may be implemented in software or in hardware. Wherein, the name of the unit does not constitute a limitation to the unit itself in some cases. For example, the first acquisition unit may also be described as "the unit for acquiring at least two Internet Protocol addresses".
[0221] It should be understood that the various parts of the present disclosure may be implemented in hardware, software, firmware, or a combination thereof.
[0222] As described above, it is only the specific implementation manner of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present disclosure should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure shall be subject to the protection scope of the claims.
Claims
1. A data security information processing method based on mobile collaborative signature, characterized in that: Applied to a first device, the method includes: Detecting an input operation on a login interface; wherein the login interface is a login interface of a service platform; determining login information of a first user account in the service platform according to the input operation, and logging in to the first user account according to the login information; Generate a first public-private key pair for the first user account in the service platform; wherein the first public-private key pair is generated by the first device; the service platform is a platform that provides signature and identity authentication functions for multiple parties that sign the information to be processed; the first device is a device for logging into the first user account; the first user account is an account registered on the service platform, and is one of the multiple accounts that sign the information to be processed; Obtaining, through the service platform, a digital certificate issued by a certificate authority for the first user account; wherein, the digital certificate is generated by the certificate authority based on a target public key sent by the service platform and information related to the first user account; the target public key is obtained based on a first public key in the first public-private key pair and a second public-private key pair, and the second public-private key pair is generated by the service platform for the first user account whether the first user account is in a logged-in state or in a non-logged-in state; the first user account is in the logged-in state after logging in to the service platform through the first device; wherein, the first device and the service platform respectively generate a public-private key pair for the first user account, the first device has the first public-private key pair, and the service platform has the second public-private key pair; Digitally signing the information to be processed according to the first private key in the first public-private key pair to obtain first signature information; wherein the first signature information is used for the service platform to digitally sign the first signature information using the second private key in the second public-private key pair to obtain second signature information that completes the signature of the information to be processed; Sending the information to be processed carrying the first signature information and the digital certificate to the service platform; Detecting a selection operation on a second user account selection interface; determining a second user account according to the selection operation; wherein the second user account is used as an account for signing the information to be processed with the first user account; the second user account is used by the service platform to send a signature notification of the information to be processed to a second device associated with the second user account; Among them, the digital certificate is used by the service platform to obtain the target public key based on the digital certificate after verifying that the digital certificate is a digital certificate issued by a preset certificate authority; and to perform signature verification on the second signature information based on the target public key; if the verification is successful, it proves that the second signature information is the signature information of the first user account.
2. The method according to claim 1, characterized in that: The step of obtaining, through the service platform, a digital certificate issued by a certificate authority for the first user account includes: Sending the first public key to the service platform; Receive the digital certificate sent by the service platform; wherein the digital certificate is sent to the service platform by the certificate authority after generating the digital certificate.
3. The method according to claim 1, characterized in that The step of obtaining, through the service platform, a digital certificate issued by a certificate authority for the first user account includes: Receiving the second public key sent by the service platform; Obtain the target public key according to the first public key and the second public key; Sending the target public key to the service platform; Receive the digital certificate sent by the service platform; wherein the digital certificate is sent to the service platform by the certificate authority after generating the digital certificate.
4. A data security information processing method based on mobile collaborative signature, characterized in that: Applied to a service platform, the method comprises: Performing identity authentication on the login information of the first user account in the service platform input by the first device; if the authentication is successful, the first device logs in to the first user account; the service platform is a platform that provides signature and identity authentication functions for multiple parties who sign the information to be processed; the first device is a device that logs in to the first user account; the first user account is an account registered on the service platform, and is one of the multiple accounts that sign the information to be processed; Determine a target public key; wherein the target public key is obtained according to the first public key in the first public-private key pair of the first user account in the service platform, and the second public key in the second public-private key pair of the first user account; the first public-private key pair is generated by the first device, and the second public-private key pair is generated by the service platform for the first user account whether the first user account is in a logged-in state or in a non-logged-in state; the first user account is in the logged-in state after logging in to the service platform through the first device; wherein the first device and the service platform respectively generate the public-private key pair of the first user account, the first device has the first public-private key pair, and the service platform has the second public-private key pair; Based on the target public key and the information related to the first user account, obtain a digital certificate issued by a certificate authority for the first user account; wherein the digital certificate is generated by the certificate authority based on the target public key and the information related to the first user account; Sending the digital certificate to the first device; Receiving information to be processed that carries first signature information and the digital certificate and is sent by the first device; wherein the first signature information is obtained by the first device digitally signing the information to be processed using the first private key in the first public-private key pair; Digitally sign the first signature information using the second private key in the second public-private key pair to obtain second signature information, thereby completing the signing of the information to be processed; After verifying that the digital certificate is a digital certificate issued by a preset certificate authority, obtaining the target public key according to the digital certificate; Performing signature verification on the second signature information according to the target public key; If the verification is successful, it proves that the second signature information is the signature information of the first user account; Determine a second user account determined by the first device; and send a signature notification of the information to be processed to a second device associated with the second user account.
5. The method according to claim 4, characterized in that The determining of the target public key comprises: receiving the first public key sent by the first device; The target public key is obtained according to the first public key and the second public key.
6. The method according to claim 4, characterized in that The determining of the target public key comprises: sending the second public key to the first device; Receive the target public key sent by the first device, wherein the target public key is obtained by the first device according to the first public key and the second public key.
7. The method according to claim 4, characterized in that The obtaining, based on the target public key and the information related to the first user account, a digital certificate issued by a certificate authority for the first user account, comprises: Sending the target public key and information related to the first user account to the certificate authority; Receive the authorization digital certificate sent by the authorization center.
8. A data security information processing device based on mobile collaborative signature, characterized in that: include: a detection module, configured to detect an input operation on a login interface; wherein the login interface is a login interface of a service platform; determine login information of a first user account in the service platform according to the input operation, and log in to the first user account according to the login information; A generation module, configured to generate a first public-private key pair for the first user account in the service platform; wherein the first public-private key pair is generated by a first device; the service platform is a platform that provides signature and identity authentication functions for multiple parties that sign the information to be processed; the first device is a device for logging into the first user account; the first user account is an account registered on the service platform, and is one of the multiple accounts that sign the information to be processed; a first acquisition module, configured to acquire, through the service platform, a digital certificate issued by a certificate authority for the first user account; wherein the digital certificate is generated by the certificate authority based on a target public key sent by the service platform and information related to the first user account; the target public key is obtained based on a first public key in the first public-private key pair and a second public key in a second public-private key pair, the second public-private key pair being generated by the service platform for the first user account whether the first user account is in a logged-in state or in a non-logged-in state; the first user account is in the logged-in state after logging in to the service platform through the first device; wherein the first device and the service platform respectively generate a public-private key pair for the first user account, the first device has the first public-private key pair, and the service platform has the second public-private key pair; A first signature module, configured to digitally sign the information to be processed according to the first private key in the first public-private key pair to obtain first signature information; wherein the first signature information is used by the service platform to digitally sign the first signature information using the second private key in the second public-private key pair to obtain second signature information that completes the signature of the information to be processed; A first sending module, used for sending the information to be processed carrying the first signature information and the digital certificate to the service platform; The detection module is further used to detect a selection operation on a second user account selection interface; determine a second user account according to the selection operation; wherein the second user account is used as an account for signing the information to be processed with the first user account; the second user account is used by the service platform to send a signature notification of the information to be processed to the second device associated with the second user account; Among them, the digital certificate is used by the service platform to obtain the target public key based on the digital certificate after verifying that the digital certificate is a digital certificate issued by a preset certificate authority; and to perform signature verification on the second signature information based on the target public key; if the verification is successful, it proves that the second signature information is the signature information of the first user account.
9. A data security information processing device based on mobile collaborative signature, characterized in that: include: An authentication module, used to authenticate the login information of the first user account in the service platform input by the first device; If the authentication is successful, the first device logs in to the first user account; The service platform is a platform that provides signature and identity authentication functions for multiple parties who sign the information to be processed; The first device is a device for logging into the first user account; The first user account is an account registered on the service platform and is one of the multiple accounts that sign the information to be processed; A determination module, used to determine a target public key; wherein the target public key is obtained according to the first public key in the first public-private key pair of the first user account in the service platform, and the second public key in the second public-private key pair of the first user account; the first public-private key pair is generated by the first device, and the second public-private key pair is generated by the service platform for the first user account whether the first user account is in a logged-in state or in a non-logged-in state; the first user account is in the logged-in state after logging in to the service platform through the first device; wherein the first device and the service platform respectively generate the public-private key pair of the first user account, the first device has the first public-private key pair, and the service platform has the second public-private key pair; A second acquisition module is used to obtain a digital certificate issued by a certificate authority for the first user account based on the target public key and the information related to the first user account; wherein the digital certificate is generated by the certificate authority based on the target public key and the information related to the first user account; A second sending module, configured to send the digital certificate to the first device; a receiving module, configured to receive information to be processed and sent by the first device, the information carrying the first signature information and the digital certificate; wherein the first signature information is obtained by the first device digitally signing the information to be processed using the first private key in the first public-private key pair; A second signature module is configured to digitally sign the first signature information using the second private key in the second public-private key pair to obtain second signature information, thereby completing the signing of the information to be processed; after verifying that the digital certificate is a digital certificate issued by a preset certificate authority, obtain the target public key according to the digital certificate; perform signature verification on the second signature information according to the target public key; if the verification is successful, it is proved that the second signature information is the signature information of the first user account; The determination module is further used to determine the second user account determined by the first device; A third sending module is used to send a signature notification of the information to be processed to a second device associated with the second user account.
10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions or computer programs executable by the at least one processor, wherein the instructions or computer programs are executed by the at least one processor so as to enable the at least one processor to perform the method of any one of claims 1 to 3 or 4 to 7.
11. A non-transitory computer-readable storage medium storing a computer program or computer instructions, wherein the computer program or computer instructions are used to cause the computer to execute the method of any one of claims 1 to 3 or 4 to 7.
12. A computer program product, comprising a computer program or executable instructions, characterized in that: When the computer program or executable instructions are executed by a processor, the method according to any one of claims 1 to 3 or 4 to 7 is implemented.
Citation Information
Patent Citations
Collaborative digital signature system and method
CN104618116A
Identity authentication method based on collaborative signature and computer readable storage medium
CN112651036A