An electronic license authorization application method based on encrypted two-dimensional code

By using encrypted QR code technology and a precise authorization mechanism, the problem of privacy information leakage in the cross-industry and cross-departmental application of electronic certificates has been solved, realizing the secure transmission and precise use of electronic certificates and building a secure electronic certificate application system.

CN119442277BActive Publication Date: 2026-03-03TRAFFIC MANAGEMENT RES INST OF THE MIN OF PUBLIC SECURITY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

The use of existing electronic certificates in plaintext poses a risk of privacy breaches, and it is difficult to balance privacy protection and data needs in cross-industry and cross-departmental applications.

Method used

Electronic certificates are presented in the form of encrypted QR codes. Through the collaborative work of the electronic certificate issuance system, authorization system, and access system, precise encryption and authorization of data items are achieved. Combined with digital signatures and digital certificates for identity authentication, the secure transmission and use of electronic certificates are ensured.

Benefits of technology

It achieves privacy protection and precise authorization of electronic certificates, ensures secure transmission and use between different industries and departments, avoids privacy information leakage, and meets diverse application needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119442277B_ABST
    Figure CN119442277B_ABST
Patent Text Reader

Abstract

The application provides an electronic certificate authorization application method based on an encrypted two-dimensional code, which provides an electronic certificate in the form of an encrypted two-dimensional code, protects the privacy of the electronic certificate, and through a precise authorization mechanism, decrypts data items on demand, organically combines identity authentication and authorization decoding, and constructs a precise authorization application security system; based on an electronic certificate issuing system, an electronic certificate authorization system, an electronic certificate calling system, an electronic certificate bearing APP and an electronic certificate calling system APP, the mechanism controls the electronic certificate authorization application, realizes precise authorization decoding and application of the electronic certificate, ensures that the electronic certificate data items can be precisely authorized for use according to the needs of the use subject, and greatly improves the security of the use of the electronic certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic certificate technology, specifically to a method for authorizing electronic certificates based on encrypted QR codes. Background Technology

[0002] Electronic certificates refer to various legally valid electronic documents such as certificates, proofs, approvals, appraisal reports, and service results issued by various entities in accordance with the law. Examples include electronic versions of ID cards, marriage certificates, bank repayment statements, and business licenses. In recent years, the application areas of electronic certificates have been continuously expanding, with numerous application scenarios and diverse and complex users. Currently, most electronic certificates are used directly in plaintext, just like physical certificates. However, in practical applications, the use of these plaintext electronic certificates still presents some problems. First, in cross-industry and cross-departmental applications, different industries and departments have different requirements for electronic certificate data items. Directly providing all electronic certificate data items may lead to privacy leaks, making it difficult to balance shared applications and privacy protection. Second, if encryption and de-identification measures are not taken during the transmission and use of electronic certificates across different network environments and business systems, the risk of privacy leaks will be exacerbated. Summary of the Invention

[0003] To address the security issues arising from the direct use of electronic certificates in plaintext, just like physical certificates, in existing technologies, this invention provides an electronic certificate authorization application method based on encrypted QR codes. This method protects the privacy of electronic certificates while enabling precise authorization of electronic certificate data items according to the user's needs, thus meeting the diverse application requirements of different industries and departments.

[0004] The technical solution of this invention is as follows: a method for authorizing electronic certificates based on encrypted QR codes, characterized by comprising the following steps:

[0005] S1: System preparation;

[0006] The system includes an electronic certificate issuance system, an electronic certificate authorization system, an electronic certificate retrieval system, an electronic certificate carrier app, an electronic certificate retrieval system app, and a cryptographic device to manage and control the entire lifecycle of electronic certificates.

[0007] The electronic certificate issuance system issues and generates electronic certificates, which are presented in the form of electronic certificate QR codes.

[0008] The electronic certificate authorization system is used for decoding and authorizing electronic certificate QR codes;

[0009] The electronic certificate retrieval system is used to receive the electronic certificate QR code uploaded by the electronic certificate retrieval system APP and to call the electronic certificate authorization system to decode it;

[0010] The cryptographic machine provides cryptographic computation services for the electronic certificate issuance system, electronic certificate authorization system, and electronic certificate retrieval system.

[0011] The electronic certificate carrier APP is used to download and display electronic certificates; the electronic certificate calling system APP is used to scan and collect the QR code of the electronic certificate;

[0012] The electronic certificate issuance system generates public and private keys for issuing and adding electronic certificates, and generates an independent encryption and decryption root key for each data item; the electronic certificate authorization system and the electronic certificate retrieval system generate their respective system public and private keys and apply for digital certificates synchronously; the electronic certificate issuance system encrypts and protects the export of the encryption and decryption root key, issuance public key and adding public key for all data items, and securely imports them into the electronic certificate authorization system;

[0013] S2: Application and generation of electronic certificates;

[0014] The holder of the electronic certificate applies for the electronic certificate from the electronic certificate issuance system through the electronic certificate carrier APP; the electronic certificate issuance system uses different encryption and decryption keys to independently encrypt each data item and perform digital signature to generate a complete electronic certificate.

[0015] S3: Downloading and displaying electronic certificates and collecting QR codes;

[0016] The holder of the electronic certificate downloads the electronic certificate from the electronic certificate issuance system through the electronic certificate carrier APP and actively presents the electronic certificate QR code. The electronic certificate retrieval system APP scans and collects the QR code and uploads it to the electronic certificate retrieval system.

[0017] S4: The electronic certificate retrieval system and the electronic certificate authorization system perform two-way identity authentication;

[0018] The electronic certificate retrieval system sends an authentication request to the electronic certificate authorization system. After the electronic certificate authorization system verifies the authentication request, it sends an authentication request to the electronic certificate retrieval system. After the electronic certificate retrieval system verifies the authentication request, it completes the two-way identity authentication.

[0019] S5: Precise authorization of electronic certificates;

[0020] The electronic certificate retrieval system requests decoding from the electronic certificate authorization system and submits verification logs simultaneously. The electronic certificate authorization system determines the authorized electronic certificate data items according to the user's needs, calls the cryptographic machine to generate encryption and decryption keys for the authorized data items, encrypts and generates an authorization token, signs the authorization token and returns it to the electronic certificate retrieval system, and saves the verification logs.

[0021] S6: Electronic Certificate Decoding Application;

[0022] After receiving the authorization token, the electronic certificate retrieval system calls the cryptographic machine to verify and decrypt the encryption and decryption keys of all authorized data items, decrypts the ciphertext of each authorized data item, obtains the plaintext data, and then carries out subsequent related applications.

[0023] Its further features are:

[0024] In step S1, the system preparation stage, the preparation operation of the electronic certificate issuance system includes the following steps:

[0025] S11: The electronic certificate issuance system calls the cryptographic machine to randomly generate public and private keys for electronic certificate issuance and public and private keys for encryption;

[0026] S12: The electronic certificate issuance system calls the cryptographic machine to randomly generate the system root key, uses the endorsement field data item number as a dispersion factor to disperse the system root key to generate the endorsement field data item encryption and decryption root key; uses the annotation field data item number as a dispersion factor to disperse the system root key to generate the annotation field data item encryption and decryption root key.

[0027] S13: The electronic certificate authorization system calls the cryptographic machine to randomly generate the public and private keys of the electronic certificate authorization system and apply for the issuance of a digital certificate for the electronic certificate authorization system.

[0028] S14: The electronic certificate retrieval system calls the cryptographic machine to randomly generate the public and private keys of the electronic certificate retrieval system and apply for the issuance of a digital certificate for the electronic certificate retrieval system.

[0029] S15: The electronic certificate issuance system uses the public key of the electronic certificate authorization system to encrypt and protect the encryption and decryption root key, the issuance public key and the annotation public key of all data items to obtain the key ciphertext;

[0030] S16: The electronic certificate authorization system imports the key ciphertext into the electronic certificate authorization system cryptographic machine, uses the electronic certificate authorization system private key to decrypt and obtain the encryption / decryption root key, the issuance public key and the annotation public key plaintext of all data items, and then stores them securely.

[0031] S17: The electronic certificate authorization system determines the type of the user subject of this application, determines the corresponding authorization data item according to the type of the user subject, and synchronously generates an endorsement field authorization data item table; the endorsement field authorization data item table contains the number of each authorized endorsement field data item; the electronic certificate authorization system sends the endorsement field authorization data item table to the electronic certificate retrieval system;

[0032] Step S2, the process of generating the electronic certificate QR code, specifically includes the following steps:

[0033] a1: The holder of the electronic certificate applies for the electronic certificate from the electronic certificate issuance system through the electronic certificate carrier APP;

[0034] The electronic certificate data items before issuance include the QR code version number, electronic certificate number, endorsement field, and annotation field;

[0035] a2: The electronic certificate issuance system performs binary bitstream encoding on all data items of the electronic certificate before issuance;

[0036] a3: The electronic certificate issuance system uses the electronic certificate number and endorsement time as dispersion factors to disperse the root keys for encryption and decryption of the endorsement field data items to generate the encryption and decryption keys for the endorsement field data items; it also uses the electronic certificate number and endorsement time as dispersion factors to disperse the root keys for encryption and decryption of the endorsement field data items to generate the encryption and decryption keys for the endorsement field data items.

[0037] The electronic certificate issuance system encrypts all data items in the endorsement field using the corresponding endorsement field data item encryption / decryption key to obtain the ciphertext of the endorsement field.

[0038] The electronic certificate issuance system encrypts all data items in the annotation field using the same annotation field data item encryption / decryption key to obtain the annotation field ciphertext; wherein, both the annotation field ciphertext and the annotation field ciphertext are binary bit stream strings;

[0039] a4: The electronic certificate issuance system uses the electronic certificate issuance private key to digitally sign all data items of the encrypted text of the endorsement field to obtain the endorsement digital signature, and uses the electronic certificate annotation private key to digitally sign all data items of the encrypted text of the annotation field to obtain the annotation digital signature.

[0040] a5: The electronic certificate issuance system combines the QR code version number, the electronic certificate number, the encrypted text of the endorsement field, the encrypted text of the added endorsement field, the digital signature of the endorsement, and the binary bit stream of the added endorsement digital signature in sequence to obtain the issued electronic certificate binary bit stream.

[0041] a6: The electronic certificate issuance system uses a preset electronic certificate QR code encoding method to encode the binary bit stream of the issued electronic certificate to generate an electronic certificate QR code.

[0042] In step S4, the electronic certificate retrieval system and the electronic certificate authorization system perform two-way identity authentication, specifically including the following steps:

[0043] b1: Before requesting decoding authorization, the electronic certificate retrieval system first performs two-way identity authentication with the electronic certificate authorization system. The authentication adopts digital signature and digital certificate methods. The electronic certificate retrieval system calls the cryptographic machine to encapsulate and generate an identity authentication request Req1, and sends it to the electronic certificate authorization system.

[0044] b2: After receiving Req1, the electronic certificate authorization system calls the cryptographic machine to verify Req1. If the verification is successful, the system confirms that the electronic certificate calling system is legitimate, encapsulates and generates an identity authentication request Req2, and sends it to the electronic certificate calling system.

[0045] b3: After receiving Req2, the electronic certificate retrieval system calls the cryptographic machine to verify Req2. If the verification is successful, the electronic certificate authorization system is confirmed to be legitimate, and the two-way identity authentication ends.

[0046] Step S5, precise authorization of electronic certificates, specifically includes the following steps:

[0047] c1: The electronic certificate retrieval system sends the collected electronic certificate QR code to the electronic certificate authorization system, requests decoding authorization, and simultaneously submits verification information, which includes: verification time and purpose.

[0048] c2: After receiving the electronic certificate QR code, the electronic certificate authorization system decodes it based on a preset electronic certificate QR code decoding method to obtain the issued electronic certificate binary bit stream;

[0049] c3: The electronic certificate authorization system sequentially parses the QR code version number, electronic certificate number, encrypted endorsement field, encrypted annotation field, digital signature of endorsement, and digital signature of annotation. It then verifies the digital signature of endorsement and digital signature of annotation using the issuing public key and the annotation public key, respectively. After successful verification, it uses the electronic certificate number and the annotation time in the annotation signature as a dispersion factor to disperse the encryption / decryption root key of the annotation field data item, generating an encryption / decryption key for the annotation field data item. The encrypted endorsement field is then decrypted to obtain the verification data item, which includes: the purpose and validity period of the electronic certificate QR code.

[0050] The electronic certificate authorization system verifies whether the purpose item in the QR code is consistent with the purpose item submitted in the verification information, verifies whether the verification time is within the validity period in the QR code, and authorizes after all verifications are passed.

[0051] c4: The electronic certificate authorization system distributes the root keys for encryption and decryption of all authorized endorsement field data items according to the endorsement field authorization data item table of the electronic certificate calling system, and generates a corresponding encryption and decryption key for each authorized endorsement field data item. The distribution factor is the electronic certificate number and the endorsement time in the endorsement signature.

[0052] The electronic certificate authorization system uses the public key of the electronic certificate retrieval system to encrypt the encryption and decryption keys of all authorized endorsed data items, combines the ciphertext of the encryption and decryption keys of the data items with the corresponding data item numbers, assembles all the combined data to generate an authorization token, digitally signs the authorization token using the private key of the electronic certificate authorization system, and returns the signed authorization token to the electronic certificate retrieval system; and synchronously records verification logs such as verification time and purpose items.

[0053] Step S6, the electronic certificate decoding application, specifically includes the following steps:

[0054] d1: After receiving the signed authorization token, the electronic certificate retrieval system uses the public key of the electronic certificate authorization system to verify the digital signature, uses the private key of the electronic certificate retrieval system to decrypt the key ciphertext in each combination of the authorization token, and records the encryption and decryption keys of the authorization data items and the corresponding data item numbers.

[0055] d2: The electronic certificate retrieval system decodes the electronic certificate QR code based on a preset electronic certificate QR code decoding method to obtain the issued electronic certificate binary bit stream;

[0056] The electronic certificate authorization system parses the binary bit stream of the electronic certificate sequentially to obtain the encrypted binary bit stream of the endorsement field. Based on the encryption and decryption keys of the obtained authorized data items and the corresponding data item numbers, the system decrypts the encrypted data of the data items with corresponding numbers in the endorsement field, and finally obtains the plaintext data of the authorized data items in the endorsement field for subsequent related applications.

[0057] The cryptographic machine provides digital signature verification and encryption / decryption services, and supports at least the domestic SM2, SM3 and SM4 algorithms.

[0058] The electronic certificate issuance system encodes the binary bitstream of the issued electronic certificate according to a preset electronic certificate QR code encoding method to generate an electronic certificate QR code. The electronic certificate QR code encoding method specifically includes the following steps:

[0059] The binary bit stream of the electronic certificate is padded to a length that is a multiple of 31 bits. The padded binary bit stream of the electronic certificate is divided into blocks of 31 bits in length. Each block is converted into a decimal number, and each decimal number is converted into 6 base-45 characters. All characters are concatenated in order to obtain the final electronic certificate string. Finally, an electronic certificate QR code is generated according to a preset character pattern.

[0060] The electronic certificate QR code decoding method includes the following steps:

[0061] The electronic certificate QR code is parsed according to the preset character pattern to obtain all characters. All strings are divided into groups of 6 characters each. The 6 characters in each group are converted into decimal numbers according to the preset encoding standard. The decimal numbers are converted into 31-bit binary bit streams. All 31-bit binary bit streams are concatenated in order to obtain the binary bit stream of the issued electronic certificate.

[0062] When the electronic certificate QR code is generated, all the annotation fields use the same data item number for calculation.

[0063] This application provides a method for authorizing electronic certificates based on encrypted QR codes. It provides electronic certificates to the public in the form of encrypted QR codes, protecting the privacy of electronic certificates. Through a precise authorization mechanism, it authorizes and decrypts data items on demand, while organically combining identity authentication and authorization decoding to construct a secure system for precise authorization applications. Based on the mechanism of controlling the electronic certificate authorization application through the electronic certificate issuance system, electronic certificate authorization system, electronic certificate retrieval system, electronic certificate carrier APP, and electronic certificate retrieval system APP, it achieves precise authorization decoding and application of electronic certificates, ensuring that the use of electronic certificate data items can be precisely authorized according to the needs of the user, greatly improving the security of electronic certificate use. Attached Figure Description

[0064] Figure 1 This is a schematic diagram of the electronic certificate authorization application system structure for this application;

[0065] Figure 2 A flowchart illustrating the process of applying for, generating, downloading, displaying, and collecting QR codes for electronic certificates;

[0066] Figure 3 A flowchart illustrating the authorization and decoding process for electronic certificates;

[0067] Figure 4 This is a functional diagram of the electronic certificate authorization application system;

[0068] Figure 5 The process for generating QR codes for electronic certificates;

[0069] Figure 6 For the precise authorization and decoding application process of electronic certificates. Detailed Implementation

[0070] like Figures 1-4 As shown, the present invention includes a method for authorizing electronic certificates based on encrypted QR codes, which includes the following steps.

[0071] S1: System preparation;

[0072] The system includes an electronic certificate issuance system, an electronic certificate authorization system, an electronic certificate retrieval system, an electronic certificate carrier app, an electronic certificate retrieval system app, and a cryptographic device to manage and control the entire lifecycle of electronic certificates.

[0073] The electronic certificate issuance system issues and generates electronic certificates, which are presented in the form of electronic certificate QR codes.

[0074] The electronic certificate authorization system is used for decoding and authorizing electronic certificate QR codes;

[0075] The electronic certificate retrieval system is used to receive the electronic certificate QR code uploaded by the electronic certificate retrieval system APP and to call the electronic certificate authorization system to decode it;

[0076] The cryptographic machine provides cryptographic computation services for electronic certificate issuance systems, electronic certificate authorization systems, and electronic certificate retrieval systems; the cryptographic machine provides digital signature verification and encryption / decryption services, and supports at least the domestic SM2, SM3, and SM4 algorithms.

[0077] The electronic certificate carrier app is used to download and display electronic certificates; the electronic certificate access system app is used to scan and collect the QR code of the electronic certificate.

[0078] Typically, electronic certificates serving as identity documents have a single holder. However, in practice, each type of electronic certificate has multiple users, such as individuals, commercial companies like insurance companies, and various government departments. In this method, when the certificate holder presents the electronic certificate, the electronic certificate's QR code is displayed via an accompanying app. Users then use the electronic certificate to access the system app, which collects the QR code data. Users then use the electronic certificate to conduct relevant business. The collected QR code, after encryption and precise authorization, allows users to access the corresponding electronic certificate data, ensuring that the data is not misread or maliciously collected by unrelated third parties, thus improving the security of electronic certificate use.

[0079] Specifically, during the system preparation phase, the preparation operations for the electronic certificate issuance system include the following:

[0080] S11: The electronic certificate issuance system calls the cryptographic machine to randomly generate public and private keys for electronic certificate issuance and public and private keys for encryption;

[0081] S12: The electronic certificate issuance system calls the cryptographic machine to randomly generate the system root key, uses the endorsement field data item number as a dispersion factor to disperse the system root key to generate the endorsement field data item encryption and decryption root key; uses the annotation field data item number as a dispersion factor to disperse the system root key to generate the annotation field data item encryption and decryption root key.

[0082] S13: The electronic certificate authorization system calls the cryptographic machine to randomly generate the public and private keys of the electronic certificate authorization system and apply for the issuance of a digital certificate for the electronic certificate authorization system.

[0083] S14: The electronic certificate retrieval system calls the cryptographic machine to randomly generate the public and private keys of the electronic certificate retrieval system and apply for the issuance of a digital certificate for the electronic certificate retrieval system.

[0084] S15: The electronic certificate issuance system uses the public key of the electronic certificate authorization system to encrypt and protect the encryption and decryption root key, the issuance public key and the annotation public key of all data items to obtain the key ciphertext;

[0085] S16: The electronic certificate authorization system imports the key ciphertext into the electronic certificate authorization system cryptographic machine, uses the electronic certificate authorization system private key to decrypt and obtain the encryption / decryption root key, the issuance public key and the annotation public key plaintext of all data items, and then stores them securely.

[0086] S17: The electronic certificate authorization system determines the type of the user subject of this application, determines the corresponding authorization data item according to the type of the user subject, and synchronously generates an endorsement field authorization data item table; the endorsement field authorization data item table contains the number of each authorized endorsement field data item; the electronic certificate authorization system sends the endorsement field authorization data item table to the electronic certificate retrieval system.

[0087] S2: Application and generation of electronic certificates;

[0088] The certificate holder applies for an electronic certificate from the electronic certificate issuance system through the electronic certificate carrier APP; the electronic certificate issuance system uses different encryption and decryption keys to independently encrypt each data item and perform digital signature to generate a complete electronic certificate.

[0089] Step S2, the process of generating the electronic certificate QR code, specifically includes the following steps.

[0090] a1: Electronic certificate holders apply for electronic certificates through the electronic certificate issuance system via the electronic certificate carrier APP;

[0091] The electronic certificate data items before issuance include the QR code version number, electronic certificate number, endorsement field, and annotation field;

[0092] The endorsement and annotation fields refer to the definitions of original electronic certificates and endorsed documents in the standards "GB / T 36901-2018 Overall Technical Architecture of Electronic Certificates" and "GB / T 36905-2018 Technical Requirements for Electronic Certificate Documents". The endorsement field is defined as: a field in the original electronic certificate issued by the electronic certificate issuing authority. The annotation field is defined as: fields added to the original electronic certificate for the purpose of handling related matters, such as purpose and validity period.

[0093] In this embodiment, the endorsement field consists of data items such as license plate number, vehicle type, vehicle identification number, and engine number, while the endorsement field consists of data items such as purpose and validity period.

[0094] a2: The electronic certificate issuance system encodes all data items of the electronic certificate into binary bit streams before issuance.

[0095] a3: The electronic certificate issuance system uses the electronic certificate number and endorsement time as dispersion factors to distribute the root keys for encryption and decryption of the endorsement field data items to generate the encryption and decryption keys for the endorsement field data items; it also uses the electronic certificate number and endorsement time as dispersion factors to distribute the root keys for encryption and decryption of the endorsement field data items to generate the encryption and decryption keys for the endorsement field data items.

[0096] The electronic certificate issuance system encrypts all data items in the endorsement field using the corresponding endorsement field data item encryption / decryption key to obtain the endorsement field ciphertext. Specifically, the encryption adopts the CFB mode of the SM4 algorithm.

[0097] The electronic certificate issuance system encrypts all data items in the annotation field using the same annotation field data item encryption / decryption key to obtain the annotation field ciphertext. Specifically, the encryption adopts the CFB mode of the SM4 algorithm; both the signature field ciphertext and the annotation field ciphertext are binary bit streams.

[0098] a4: The electronic certificate issuance system uses the electronic certificate issuance private key to digitally sign all data items in the ciphertext of the endorsement field to obtain the endorsement digital signature, and uses the electronic certificate annotation private key to digitally sign all data items in the ciphertext of the annotation field to obtain the annotation digital signature.

[0099] In this embodiment, the digital signature endorsement includes a 4-bit digest algorithm identifier, a 4-bit signature algorithm identifier, a 33-bit endorsement time, and a 512-bit endorsement signature value; the digital signature addition includes a 4-bit digest algorithm identifier, a 4-bit signature algorithm identifier, a 33-bit addition time, and a 512-bit addition signature value.

[0100] a5: The electronic certificate issuance system combines the QR code version number, electronic certificate number, encrypted endorsement field, encrypted additional endorsement field, digital signature of endorsement, and binary bit stream of additional endorsement in sequence to obtain the binary bit stream of the issued electronic certificate.

[0101] a6: The electronic certificate issuance system encodes the binary bitstream of the issued electronic certificate based on a preset electronic certificate QR code encoding method to generate an electronic certificate QR code.

[0102] S3: Downloading and displaying electronic certificates and collecting QR codes;

[0103] When an electronic certificate holder needs to provide an electronic certificate to the electronic certificate access system, the holder downloads the electronic certificate from the electronic certificate issuance system through the electronic certificate carrier APP. The electronic certificate issuance system reviews the user's download request and, upon approval, returns the final electronic certificate QR code to the electronic certificate carrier APP, which then displays the electronic certificate in the form of a QR code.

[0104] When it is necessary to read the QR code of an electronic certificate, the QR code of the electronic certificate actively presented by the certificate holder can be scanned through the electronic certificate retrieval system APP, and the data can be collected and uploaded to the electronic certificate retrieval system.

[0105] S4: Two-way identity authentication between the electronic certificate retrieval system and the electronic certificate authorization system;

[0106] The electronic certificate retrieval system sends an authentication request to the electronic certificate authorization system. After the electronic certificate authorization system verifies the authentication request and passes it, it sends an authentication request to the electronic certificate retrieval system. After the electronic certificate retrieval system verifies the authentication request and passes it, the two-way identity authentication is completed.

[0107] In step S4, the electronic certificate retrieval system and the electronic certificate authorization system perform two-way identity authentication, which specifically includes the following steps:

[0108] b1: Before requesting decoding authorization from the electronic certificate retrieval system, the system first performs two-way identity authentication with the electronic certificate authorization system. The authentication uses digital signature and digital certificate. The electronic certificate retrieval system calls the cryptographic machine to encapsulate and generate an identity authentication request Req1, which is then sent to the electronic certificate authorization system.

[0109] b2: After receiving Req1, the electronic certificate authorization system calls the cryptographic machine to verify Req1. If it passes the verification, it confirms that the electronic certificate calling system is legitimate, encapsulates and generates an identity authentication request Req2, and sends it to the electronic certificate calling system.

[0110] b3: After receiving Req2, the electronic certificate retrieval system calls the cryptographic machine to verify Req2. If the verification is successful, the electronic certificate authorization system is confirmed to be legitimate, and the two-way identity authentication ends.

[0111] S5: Precise authorization of electronic certificates;

[0112] The electronic certificate retrieval system requests decoding from the electronic certificate authorization system and submits verification logs simultaneously. The electronic certificate authorization system determines the authorized electronic certificate data items according to the user's needs, calls the cryptographic machine to generate encryption and decryption keys for the authorized data items, encrypts and generates an authorization token, signs the authorization token, and returns it to the electronic certificate retrieval system, saving the verification logs.

[0113] Before using the data items of an electronic certificate, the user requests permissions from the electronic certificate authorization system through the electronic certificate retrieval system. In this method, both the electronic certificate retrieval system and the electronic certificate authorization system predefine the data items that each user can authorize based on the type of user making the request. During authorization, precise authorization is performed according to the defined authorization scope, and data items exceeding the authorization scope are not authorized, ensuring the secure use of electronic certificate data.

[0114] Step S5, precise authorization of electronic certificates, specifically includes the following steps:

[0115] c1: The electronic certificate retrieval system sends the collected electronic certificate QR code to the electronic certificate authorization system to request decoding authorization and submit verification information simultaneously. The verification information includes: verification time and purpose.

[0116] c2: After receiving the electronic certificate QR code, the electronic certificate authorization system decodes it based on the preset electronic certificate QR code decoding method to obtain the binary bit stream of the issued electronic certificate;

[0117] c3: The electronic certificate authorization system parses the QR code version number, electronic certificate number, encrypted endorsement field, encrypted additional endorsement field, digital signature of endorsement, and digital signature of additional endorsement in sequence. It verifies the digital signature of endorsement and digital signature of additional endorsement using the issuing public key and the additional endorsement public key respectively. After verification, it uses the electronic certificate number and the endorsement time in the endorsement signature as a dispersion factor to disperse the encryption and decryption root key of the additional endorsement field data item to generate the encryption and decryption key of the additional endorsement field data item. It decrypts the encrypted endorsement field to obtain the verification data item, which includes: the purpose and validity period of the electronic certificate QR code;

[0118] The electronic certificate authorization system verifies whether the purpose of the QR code is consistent with the purpose submitted in the verification information, and verifies whether the verification time is within the validity period of the QR code. Authorization is granted after all verifications are passed.

[0119] c4: The electronic certificate authorization system calls the system's endorsement field authorization data item table based on the electronic certificate, distributes the root keys for encryption and decryption of all authorized endorsement field data items, and generates corresponding encryption and decryption keys for each authorized endorsement field data item. The distribution factor is the electronic certificate number and the endorsement time in the endorsement signature.

[0120] The electronic certificate authorization system uses the public key of the electronic certificate retrieval system to encrypt the encryption and decryption keys of all authorized endorsed data items. It then combines the ciphertext of the encryption and decryption keys of the data items with the corresponding data item numbers. All the combined data are assembled to generate an authorization token. The authorization token is digitally signed using the private key of the electronic certificate authorization system, and the signed authorization token is returned to the electronic certificate retrieval system. Simultaneously, verification logs such as verification time and purpose are recorded for subsequent supervision.

[0121] S6: Electronic Certificate Decoding Application;

[0122] After receiving the authorization token, the electronic certificate retrieval system calls the cryptographic machine to verify and decrypt the encryption and decryption keys for all authorized data items. It then decrypts the ciphertext of each authorized data item to obtain the plaintext data and proceeds with subsequent related applications.

[0123] The electronic certificate decoding application includes the following steps:

[0124] d1: After receiving the signed authorization token, the electronic certificate retrieval system uses the public key of the electronic certificate authorization system to verify the digital signature, and uses the private key of the electronic certificate retrieval system to decrypt the key ciphertext in each combination in the authorization token, and records the encryption and decryption keys of the authorized data items and the corresponding data item numbers;

[0125] d2: The electronic certificate retrieval system decodes the electronic certificate QR code based on a preset electronic certificate QR code decoding method to obtain the binary bit stream of the issued electronic certificate;

[0126] The electronic certificate authorization system parses the binary bit stream of the electronic certificate sequentially to obtain the encrypted binary bit stream of the endorsement field. Based on the encryption / decryption key of the obtained authorized data item and the corresponding data item number, the system decrypts the encrypted data item with the corresponding number in the endorsement field, and finally obtains the plaintext data of the authorized data item in the endorsement field for subsequent related applications.

[0127] In this method, the electronic certificate issuance system encodes the binary bitstream of the issued electronic certificate according to a preset electronic certificate QR code encoding method to generate an electronic certificate QR code; the electronic certificate QR code encoding method specifically includes the following steps:

[0128] The binary bitstream of the electronic certificate is padded to a multiple of 31 bits. The padded binary bitstream is then divided into 31-bit blocks. Each block is converted to a decimal number, and each decimal number is converted into six base-45 characters. All characters are concatenated sequentially to obtain the final electronic certificate string. Finally, an electronic certificate QR code is generated according to the character pattern in GB / T 18284-2000. This method of dividing the binary bitstream into 31-bit blocks, converting to decimal numbers, and then converting each decimal number into six base-45 characters, and generating the electronic certificate QR code according to the character pattern, improves the compression rate compared to the byte pattern in GB / T 18284-2000. It allows for a larger number of characters to be stored, and the QR codes generated from the same length of electronic certificate binary bitstream are more readable, improving QR code scanning efficiency. Furthermore, it allows for direct acquisition of visible characters after scanning, improving QR code processing efficiency and software compatibility.

[0129] The specific encoding process is as follows:

[0130] Binary bit stream: 111111111111111111111111;

[0131] To fill in the remaining 31 digits: 1111111111111111111111110000000;

[0132] Converted to decimal: 16777215

[0133] Convert to base 45: 0th bit (16777215 / (45^0)) MOD 45 = 0 => '0';

[0134] The first position (16777215 / (45^1)) MOD45 = 2 =>'2';

[0135] The second position (16777215 / (45^2)) MOD45 = 5 =>'5';

[0136] The 3rd position (16777215 / (45^3)) MOD45 = 4 =>'4';

[0137] The 4th position (16777215 / (45^4)) MOD45 = 31 =>'4';

[0138] The 5th position (16777215 / (45^5)) MOD45 = 11 =>'0';

[0139] The converted data stream is: "025440".

[0140] Based on the electronic certificate QR code encoding method in this method, the binary stream is: 111001001110010001100010011000100110011101100000011001001010110001001001010010010001000000100001010101;

[0141] The converted data stream is as follows:

[0142] 8ODNH69Z97.6CIB203L00000.

[0143] Binary stream: 111111000000111111111111110010011100100011000100110001001100111011000000110010010010101100010010101100010010101111111111111111111111111111111111001000000100001010101;

[0144] The converted data stream is as follows:

[0145] $+8$ 1B+ / JD9 / EI91-VFVSB$SKXL0.

[0146] The corresponding electronic certificate QR code encoding method and the electronic certificate QR code decoding method include the following steps:

[0147] Parse the electronic certificate QR code according to the character pattern in GB / T 18284-2000 to obtain all 45 base characters, divide all strings into groups of 6 characters, convert the 6 characters of each group into decimal numbers, convert the decimal numbers into 31-bit binary bit streams, and concatenate all the 31-bit binary bit streams in order to obtain the binary bit stream of the issued electronic certificate.

[0148] In practical applications, because the annotation fields need to be provided to all types of users, to improve the efficiency of electronic certificate QR code generation, all annotation fields use the same data item number to participate in key distribution calculation for encryption and decryption keys during QR code generation. That is, all annotation fields share a single encryption and decryption key; each annotation field is not encrypted independently, but rather all annotation fields are encrypted together, and encryption is performed only once. Simultaneously, because different types of users can apply for different data items in the annotation fields, each data item in the annotation field is encrypted using a separate data item number after key distribution to generate the electronic certificate QR code, thus improving the security of the annotation field data.

[0149] By using the technical solution of this invention, electronic certificates are provided externally in the form of encrypted QR codes, protecting the privacy of electronic certificates. Simultaneously, the encrypted QR code mechanism, by independently encrypting electronic certificate data items and displaying the electronic certificate in QR code format, meets the needs of privacy protection and convenient application. The precise authorization mechanism, by authorizing decryption of data items on demand, organically combines identity authentication and authorization decoding to construct a precise authorization application security system. Through the above methods, this invention achieves encrypted protection of electronic certificate data, avoids leakage of the privacy of electronic certificate subjects, verifies the legitimacy of the identity of the electronic certificate caller, prevents unauthorized access by third-party systems, implements precise authorization decoding, realizes refined permission management of electronic certificate data information, and achieves a balance between shared applications and privacy protection. It also records verification logs for easy subsequent supervision.

Claims

1. An electronic certificate authorization application method based on encrypted two-dimensional code, characterized in that, It comprises the following steps: S1: system preparation; The electronic certificate issuing system, the electronic certificate authorization system, the electronic certificate calling system, the electronic certificate bearing APP, the electronic certificate calling system APP and the password machine are set up to manage and control the whole life cycle of the electronic certificate; The electronic certificate issuing system issues and generates the electronic certificate, which is presented in the form of an electronic certificate two-dimensional code; The electronic certificate authorization system is used for decoding authorization of the electronic certificate two-dimensional code; The electronic certificate calling system is used for receiving the electronic certificate two-dimensional code uploaded by the electronic certificate calling system APP and calling the electronic certificate authorization system to realize decoding; The password machine provides password operation services for the electronic certificate issuing system, the electronic certificate authorization system and the electronic certificate calling system; The electronic certificate bearing APP is used for downloading and presenting the electronic certificate; and the electronic certificate calling system APP is used for scanning and collecting the electronic certificate two-dimensional code; The electronic certificate issuing system generates electronic certificate issuing public and private keys and annotation public and private keys, and generates independent encryption and decryption root keys for each data item; the electronic certificate authorization system and the electronic certificate calling system respectively generate their own system public and private keys and apply for digital certificates synchronously; the electronic certificate issuing system encrypts and protects the encryption and decryption root keys of all data items, the issuing public key and the annotation public key, and safely imports them into the electronic certificate authorization system; S2: electronic certificate application and generation; The electronic certificate holding subject applies for an electronic certificate to the electronic certificate issuing system through the electronic certificate bearing APP; the electronic certificate issuing system independently encrypts each data item using different encryption and decryption keys and performs digital signature to generate a complete electronic certificate; S3: electronic certificate downloading and two-dimensional code collection; The electronic certificate holding subject downloads the electronic certificate from the electronic certificate issuing system through the electronic certificate bearing APP and actively presents the electronic certificate two-dimensional code, which is scanned and collected by the electronic certificate calling system APP and uploaded to the electronic certificate calling system; S4: bidirectional identity authentication between the electronic certificate calling system and the electronic certificate authorization system; The electronic certificate calling system sends an authentication request to the electronic certificate authorization system, the electronic certificate authorization system verifies the authentication request, and after the authentication request is passed, sends an authentication request to the electronic certificate calling system, the electronic certificate calling system verifies the authentication request, and after the authentication request is passed, bidirectional identity authentication is completed; S5: electronic certificate precise authorization; The electronic certificate calling system requests decoding from the electronic certificate authorization system and synchronously submits verification logs; the electronic certificate authorization system determines the allowed electronic certificate data items according to the needs of the subject, calls the password machine to generate encryption and decryption keys of the authorized data items, and generates an authorized Token after encryption, and returns the authorized Token to the electronic certificate calling system after signature, and saves the verification logs; S6: electronic certificate decoding application; The electronic certificate calling system receives the authorized Token, calls the password machine, verifies and decrypts all authorized data items to obtain the encryption and decryption keys, respectively decrypts the authorized data item ciphertext, obtains the plaintext data, and develops subsequent related applications.

2. The method of claim 1, wherein the method further comprises: receiving a request for the electronic certificate; and transmitting the electronic certificate to the requesting device. In step S1, the system preparation phase, the preparation operation of the electronic certificate issuing system, in detail, includes the following steps: S11: The electronic certificate issuing system calls the password machine to randomly generate electronic certificate issuing public and private keys and annotation public and private keys; S12: The electronic certificate issuing system calls the password machine to randomly generate a system root key, uses the annotation field data item number as a dispersion factor to disperse the system root key to generate an annotation field data item encryption and decryption root key, and uses the annotation field data item number as a dispersion factor to disperse the system root key to generate an annotation field data item encryption and decryption root key; S13: The electronic certificate authorization system calls the password machine to randomly generate electronic certificate authorization system public and private keys, and applies for issuing an electronic certificate authorization system digital certificate; S14: The electronic certificate calling system calls the password machine to randomly generate electronic certificate calling system public and private keys, and applies for issuing an electronic certificate calling system digital certificate; S15: The electronic certificate issuing system uses the electronic certificate authorization system public key to encrypt all data item encryption and decryption root keys, issuing public keys, and annotation public keys to obtain key ciphertext; S16: The electronic certificate authorization system imports the key ciphertext into the electronic certificate authorization system password machine, uses the electronic certificate authorization system private key to decrypt to obtain all data item encryption and decryption root keys, issuing public keys, and annotation public keys plaintext, and stores securely; S17: The electronic certificate authorization system determines the type of the use subject of this application, determines the corresponding authorized data item according to the type of the use subject, synchronously generates an annotation field authorized data item table; The annotation field authorized data item table contains the number of each authorized annotation field data item; The electronic certificate authorization system sends the annotation field authorized data item table to the electronic certificate calling system. 3.The electronic certificate authorization application method based on encrypted two-dimensional code according to claim 1, characterized in that: In step S2, the generation process of the electronic certificate two-dimensional code, specifically including the following steps: a1: The electronic certificate holder subject applies for an electronic certificate through the electronic certificate bearing APP to the electronic certificate issuing system; The electronic certificate data items before issuing include the two-dimensional code version number, the electronic certificate number, the annotation field, and the annotation field; a2: The electronic certificate issuing system encodes all data items of the electronic certificate before issuing in binary bit stream; a3: The electronic certificate issuing system uses the electronic certificate number and the annotation time as dispersion factors to disperse the annotation field data item encryption and decryption root key to generate the annotation field data item encryption and decryption key; uses the electronic certificate number and the annotation time as dispersion factors to disperse the annotation field data item encryption and decryption root key to generate the annotation field data item encryption and decryption key; The electronic certificate issuing system encrypts all data items of the annotation field using the corresponding annotation field data item encryption and decryption key to obtain the annotation field ciphertext; The electronic certificate issuing system encrypts all data items of the annotation field using the same annotation field data item encryption and decryption key to obtain annotation field ciphertext; wherein the annotation field ciphertext and the annotation field ciphertext are both binary bit stream strings; a4: The electronic certificate issuing system uses an electronic certificate issuing private key to digitally sign all data items of the annotation field ciphertext to obtain an annotation digital signature, and uses an electronic certificate annotation private key to digitally sign all data items of the annotation field ciphertext to obtain an annotation digital signature; a5: The electronic certificate issuing system combines the binary bit stream strings of the two-dimensional code version number, the electronic certificate certificate number, the annotation field ciphertext, the annotation field ciphertext, the annotation digital signature, and the annotation digital signature in order to obtain the electronic certificate binary bit stream after issuing; a6: The electronic certificate issuing system uses a preset electronic certificate two-dimensional code encoding method to encode the electronic certificate binary bit stream after issuing to generate an electronic certificate two-dimensional code.

4. The method of claim 1, wherein the method further comprises: receiving a request for the electronic certificate; and sending the electronic certificate to the requestor. In step S4, the electronic certificate calling system and the electronic certificate authorization system perform bidirectional identity authentication, specifically including the following steps: b1: Before requesting decoding authorization, the electronic certificate calling system performs bidirectional identity authentication with the electronic certificate authorization system, and the authentication adopts a digital signature and a digital certificate; the electronic certificate calling system calls a password machine, encapsulates an identity authentication request Req1, and sends it to the electronic certificate authorization system; b2: After receiving Req1, the electronic certificate authorization system calls the password machine to verify Req1, confirms that the electronic certificate calling system is legal after passing, encapsulates an identity authentication request Req2, and sends it to the electronic certificate calling system; b3: After receiving Req2, the electronic certificate calling system calls the password machine to verify Req2, confirms that the electronic certificate authorization system is legal after passing, and the bidirectional identity authentication ends.

5. The method of claim 1, wherein the method further comprises: receiving a request for a new electronic certificate; and generating a new electronic certificate based on the request. The electronic certificate precise authorization in step S5 specifically includes the following steps: c1: The electronic certificate calling system sends the collected electronic certificate two-dimensional code to the electronic certificate authorization system to request decoding authorization and synchronously submit verification information, wherein the verification information includes verification time and use items; c2: After receiving the electronic certificate two-dimensional code, the electronic certificate authorization system decodes based on a preset electronic certificate two-dimensional code decoding method to obtain the electronic certificate binary bit stream after issuing; c3: The electronic certificate authorization system sequentially parses the two-dimensional code version number, the electronic certificate certificate number, the annotation field ciphertext, the annotation field ciphertext, the annotation digital signature, and the annotation digital signature, respectively verifies the annotation digital signature and the annotation digital signature using the issuing public key and the annotation public key, and after passing the verification, uses the electronic certificate certificate number and the annotation time in the annotation signature as a dispersion factor to disperse the annotation field data item encryption and decryption root key to generate the annotation field data item encryption and decryption key, and decrypts the annotation field ciphertext to obtain the verification data item, wherein the verification data item includes the electronic certificate two-dimensional code use items and the validity period; The electronic certificate authorization system checks whether the use matter in the two-dimensional code is consistent with the use matter submitted in the verification information, and verifies whether the verification time is within the validity period in the two-dimensional code, and performs authorization after all verification passes; C4: The electronic certificate authorization system disperses the encryption and decryption root key of all authorized signature field data items according to the signature field authorization data item table of the electronic certificate calling system, generates a corresponding encryption and decryption key for each authorized signature field data item, and the dispersion factor is the electronic certificate number and the signature time in the signature signature; The electronic certificate authorization system encrypts all authorized signature data items using the electronic certificate calling system public key, and combines the data item encryption and decryption key ciphertext and the corresponding data item number, all combined data are assembled to generate an authorization Token, and the authorization Token is digitally signed using the electronic certificate authorization system private key, and the signed authorization Token is returned to the electronic certificate calling system; Synchronous record verification time, use matter and other verification logs.

6. The method of claim 1, wherein the method further comprises: receiving a request for a new electronic passport; and generating a new electronic passport based on the request. In step S6, the electronic certificate decoding application specifically includes the following steps: D1: After the electronic certificate calling system receives the signed authorization Token, the digital signature is verified using the electronic certificate authorization system public key, and the key ciphertext in each combination in the authorization Token is decrypted using the electronic certificate calling system private key, and the authorization data item encryption and decryption key and the corresponding data item number are recorded; D2: The electronic certificate calling system decodes the electronic certificate two-dimensional code based on a preset electronic certificate two-dimensional code decoding method to obtain a binary bit stream of the issued electronic certificate; The electronic certificate authorization system parses the electronic certificate binary bit stream in order to obtain the signature field ciphertext binary bit stream, decrypts the data item ciphertext corresponding to the number in the signature field according to the obtained authorization data item encryption and decryption key and the corresponding data item number, and finally obtains the plaintext data of the authorized data item in the signature field. Develop subsequent related applications.

7. The method of claim 1, wherein the method further comprises: receiving a request for a new electronic passport; and generating a new electronic passport based on the request. The cryptographic machine provides digital signature verification and encryption and decryption services, and supports at least domestic SM2, SM3 and SM4 algorithms.

8. The method of claim 3, wherein the method further comprises: receiving a request for a new electronic certificate; and generating a new electronic certificate based on the request. The electronic certificate issuing system encodes the electronic certificate binary bit stream according to a preset electronic certificate two-dimensional code encoding method to generate an electronic certificate two-dimensional code, and the electronic certificate two-dimensional code encoding method specifically includes the following steps: The electronic certificate binary bit stream is padded to an integer multiple of 31 bits; the padded electronic certificate binary bit stream is divided into blocks of 31 bits, each block is converted into a decimal number, each decimal number is converted into 6 45-bit characters, all characters are concatenated in order to obtain the final electronic certificate string, and finally an electronic certificate two-dimensional code is generated according to a preset character mode.

9. The method of claim 6, wherein the method further comprises: receiving a request for a new electronic certificate; and generating a new electronic certificate based on the request. The electronic certificate two-dimensional code decoding method includes the following steps: According to a preset character mode, all characters of the electronic certificate two-dimensional code are parsed, all character strings are divided into a group according to 6 characters, and 6 characters of each group are converted into a decimal number according to a preset encoding standard; the decimal number is converted into a 31-bit binary bit stream; all 31-bit binary bit streams are spliced in sequence to obtain the electronic certificate binary bit stream after signing.

10. The method of claim 3, wherein the method further comprises: receiving a request for a new electronic certificate; and generating a new electronic certificate based on the request. When the electronic certificate two-dimensional code is generated, all the added fields use the same data item number to participate in the calculation.

Citation Information

Patent Citations

  • Service handling method based on electronic certificate, government affair self-service terminal and storage medium

    CN111737671A

  • Method for safely obtaining electronic license through two-dimensional code

    CN118194338A