A rights card update platform
Through the blockchain storage and unified management of the equity card update platform, the problem of low efficiency in updating equity information is solved, and the security, consistency and efficient update of equity data are achieved.
Patent Information
- Application Number
- CN202411874710.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-12-19
AI Technical Summary
The existing equity management system lacks an integration mechanism, resulting in low efficiency in updating equity information, difficulty in ensuring data security and consistency, and a cumbersome and error-prone update process.
Through the equity card update platform, blockchain is used to store equity data. Combined with the equity sharing platform, read-write devices and card management system, unified storage and management of equity data is achieved. Equity cards are read and written through the equity read-write control system to ensure data security, consistency and non-tamperability.
It realizes the unified update of rights cards, improves the update efficiency, ensures the security and consistency of data, and avoids tedious multiple update operations.
Smart Images

Figure CN119809715B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rights and interests management, and in particular to a rights and interests card updating platform. Background Art
[0002] The current equity management system consists of multiple equity systems. These systems independently handle equity-related operations, but lack an effective integration mechanism. As equity-related businesses grow, the updating and management of equity information becomes increasingly complex. For example, different equity systems may serve different business areas or user groups. Each equity system needs to manage and update equity data. Traditionally, this management approach operates independently, without a unified, shared platform. When updating equity, users need to access different equity platforms to update their corresponding rights, which is inefficient and inconvenient.
[0003] The current equity management system lacks effective integration across various components. For example, equity data may be stored in disparate systems, making data security and consistency difficult to ensure and inefficiently updating equity data. For example, updating equity card information may require review and data processing by multiple departments, a cumbersome and error-prone process that can lead to delayed or erroneous updates. Summary of the Invention
[0004] In view of the above analysis, the embodiment of the present invention aims to provide a rights card update platform to solve the problem of low efficiency of existing rights updates.
[0005] In one aspect, an embodiment of the present invention provides a rights card update platform, comprising the following modules:
[0006] Multiple equity systems, each of which is used to initiate equity update operations to the equity sharing platform and upload the updated equity information to the equity sharing platform;
[0007] Equity sharing platform, used to store equity data using blockchain;
[0008] Reader / writer device, used to identify rights cards and read and write rights card information;
[0009] The rights and interests reading and writing control system is used to control the reading and writing device to read and write the rights and interests card; obtain the individual basic information read by the reading and writing device, and send a rights and interests card update request to the card management system; the rights and interests card update request includes the individual basic information;
[0010] The card management system is used to determine whether the individual's equity data has been updated based on the individual's basic information. If not, it returns no update data to the equity read-write control system; otherwise, it obtains the individual's equity data from the equity sharing platform and returns the equity data to the equity read-write control system;
[0011] The rights reading and writing control system writes the updated rights data of an individual into the rights card through the reading and writing device.
[0012] Based on the further improvement of the above technical solution, the equity reading and writing control system controls the reading and writing device to read and write the equity card, including:
[0013] Initialize the driver for the read and write devices;
[0014] Control the read / write device to power on and reset the equity card to obtain the dispersion factor of the equity card;
[0015] Authenticate the equity card based on its dispersion factor; after passing the authentication, authenticate the equity card;
[0016] If the rights card authentication is successful, the read-write device will be authenticated based on the dispersion factor of the rights card. After the authentication is passed, the individual basic information in the rights card will be read.
[0017] Based on the further improvement of the above technical solution, the equity card is authenticated based on the dispersion factor of the equity card, including:
[0018] The equity read-write control system sends a random number acquisition instruction to the read-write device to acquire a first random number generated by the read-write device;
[0019] The equity read-write control system sends a first encryption instruction including a first random number to the equity card, and obtains a first encrypted ciphertext obtained by the equity card executing the first encryption instruction;
[0020] The equity read-write control system sends a first authentication instruction containing a first encrypted ciphertext to the read-write device, and the read-write device performs authentication based on the dispersion factor of the equity card to obtain an equity card authentication result.
[0021] Based on a further improvement of the above technical solution, the first encrypted ciphertext obtained by the equity card executing the first encryption instruction includes:
[0022] The equity card generates a third random number, wherein the length of the third random number is the same as the length of the first random number;
[0023] Encrypting the first random number and the third random number respectively and combining the encryption results to obtain an encrypted ciphertext to be verified;
[0024] The encrypted ciphertext to be verified and the third random number are packaged to obtain a first encrypted ciphertext.
[0025] Based on the further improvement of the above technical solution, the reader / writer performs authentication based on the dispersed factor of the equity card and obtains the equity card authentication result, including:
[0026] The reading and writing device splits the first encrypted ciphertext to obtain the encrypted ciphertext to be verified and the third random number;
[0027] Obtain the symmetric key based on the dispersion factor of the equity card;
[0028] The first random number and the third random number are encrypted respectively according to the obtained symmetric key and the encryption results are combined to obtain the target encrypted ciphertext, and it is determined whether the encrypted ciphertext to be verified and the target encrypted ciphertext are the same. If they are the same, the rights card authentication result is authentication passed, otherwise the authentication is failed.
[0029] Based on the further improvement of the above technical solution, the reader / writer device is authenticated based on the decentralized factor of the equity card, including:
[0030] The rights read-write control system sends a random number acquisition instruction to the rights card to acquire a second random number generated by the rights card;
[0031] The equity read-write control system sends a second encryption instruction including a second random number and a dispersion factor of the equity card to the read-write device, and obtains a second encrypted ciphertext obtained by the read-write device executing the second encryption instruction;
[0032] The rights and interests reading and writing control system sends the second authentication instruction containing the second encrypted ciphertext to the rights and interests card for authentication, and obtains the authentication result of the reading and writing device.
[0033] Based on the further improvement of the above technical solution, the equity read-write control system initializes the card reader driver, including:
[0034] Get the set of all read-write device driver paths in the root directory of the equity read-write control system;
[0035] The driver in each driver path in the read / write device driver path set is loaded in sequence, and the following steps are used to determine whether the driver is a driver that matches the read / write device:
[0036] For the current driver, call the initialization function in the driver. If the initialization is successful, the current driver is the driver that matches the read-write device. The path of the current driver is recorded as the path of the driver of the read-write device to complete the initialization of the read-write device. Otherwise, the current driver is not the driver that matches the read-write device.
[0037] Based on a further improvement of the above technical solution, the equity sharing platform includes multiple first nodes and multiple second nodes; the first nodes are used to maintain the equity ledger of the blockchain, and smart contracts are deployed on the first nodes; the second nodes are used to verify and sort submitted transactions, package the sorted transactions into blocks, and send them to each first node;
[0038] The equity system initiates an equity update operation to the equity sharing platform and uploads the updated equity information to the equity sharing platform, including:
[0039] The equity system encrypts and signs the equity update information and sends it to the corresponding first node;
[0040] The first node verifies the signature of the received encrypted and signed equity update information and decrypts it to obtain the equity update information, endorses the equity update information, encrypts and signs the endorsement result, and returns it to the equity system;
[0041] The equity system verifies and decrypts the encrypted and signed endorsement result. If the endorsement result does not fail verification, the equity update information and the endorsement result are treated as a transaction, encrypted and signed, and sent to any second node.
[0042] The second node verifies the signature of the received data and decrypts it to obtain the transaction, verifies and sorts the transactions, packages the sorted transactions into blocks, and sends them to each first node;
[0043] Each first node updates local block information according to the received blocks.
[0044] Based on the further improvement of the above technical solution, the encryption and signing includes the following process:
[0045] The sender randomly generates a symmetric key, and symmetrically encrypts the sent data based on the symmetric key to generate symmetric ciphertext data;
[0046] The sender asymmetrically encrypts the symmetric key according to the receiver's asymmetrically encrypted public key to generate an asymmetric key ciphertext;
[0047] The sender packages the symmetric ciphertext data and the asymmetric key ciphertext to generate a temporary ciphertext, and uses its own asymmetric encryption private key to digitally sign the temporary ciphertext to generate a signature value;
[0048] The sender packages the signature value and the temporary seal to obtain the final sent data.
[0049] Based on the further improvement of the above technical solution, the signature verification and decryption includes the following process:
[0050] The receiver splits the received data to obtain the signature value, asymmetric key ciphertext and ciphertext data;
[0051] The receiver verifies the signature value using the sender's asymmetrically encrypted public key. If the verification fails, a verification failure message is returned. Otherwise, the receiver decrypts the asymmetric key ciphertext using its own asymmetrically encrypted private key to obtain the symmetric key.
[0052] Use the symmetric key to decrypt the symmetric ciphertext to obtain the original data sent by the sender.
[0053] Compared to existing technologies, this invention uses a rights system to initiate rights updates to the rights-sharing platform, promptly updating the rights data on the rights-sharing platform. The rights-sharing platform uniformly stores and manages rights data, achieving unified storage of different rights, ensuring data security, consistency, and immutability. Rights cards are read and written via a rights read-write control system. The card management system determines whether there are updates. When updates are made, the corresponding rights data is retrieved from the rights-sharing platform and returned to the rights read-write control system. This allows individual rights to be uniformly updated on the rights card, eliminating the need for separate updates and improving the efficiency of rights card updates.
[0054] In the present invention, the above-mentioned technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of the present invention will be described in the following description, and some advantages will become apparent from the description or be learned through practice of the present invention. The objectives and other advantages of the present invention can be realized and obtained through the contents particularly pointed out in the description and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] The accompanying drawings are only used for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. Throughout the drawings, the same reference symbols denote the same components.
[0056] Figure 1 This is a block diagram of a rights card update platform according to an embodiment of the present invention. DETAILED DESCRIPTION
[0057] The preferred embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, and are not used to limit the scope of the present invention.
[0058] A specific embodiment of the present invention discloses a rights card update platform, such as Figure 1 As shown, it includes the following modules:
[0059] Multiple equity systems, each of which is used to initiate equity update operations to the equity sharing platform and upload the updated equity information to the equity sharing platform;
[0060] Equity sharing platform, used to store equity data using blockchain;
[0061] Reader / writer device, used to identify rights cards and read and write rights card information;
[0062] The rights and interests reading and writing control system is used to control the reading and writing device to read and write the rights and interests card; obtain the individual basic information read by the reading and writing device, and send a rights and interests card update request to the card management system; the rights and interests card update request includes the individual basic information;
[0063] The card management system is used to determine whether the individual's equity data has been updated based on the individual's basic information. If not, it returns no update data to the equity read-write control system; otherwise, it obtains the individual's equity data from the equity sharing platform and returns the equity data to the equity read-write control system;
[0064] The rights and interests reading and writing control system writes individual rights and interests data into the rights and interests card through a reading and writing device.
[0065] It should be noted that the rights-sharing platform is a rights-chain platform built by acquiring rights data from various rights-sharing systems. The comprehensive rights-sharing management system includes multiple rights-sharing systems. Examples of rights-sharing systems include the Civil Affairs Management System, the Transportation Management System, and the Student Rights Management System, which are related to people's livelihoods. Rights-sharing data includes individual transportation discount types and student identity types. Rights-sharing systems initiate rights-sharing updates to the rights-sharing platform. Rights-sharing updates include adding new rights-sharing data and modifying rights-sharing data.
[0066] Compared to existing technologies, this invention uses a rights system to initiate rights updates to the rights-sharing platform, promptly updating the rights data on the rights-sharing platform. The rights-sharing platform uniformly stores and manages rights data, achieving unified storage of different rights, ensuring data security, consistency, and immutability. Rights cards are read and written via a rights read-write control system. The card management system determines whether there are updates. When updates are made, the corresponding rights data is retrieved from the rights-sharing platform and returned to the rights read-write control system. This allows individual rights to be uniformly updated on the rights card, eliminating the need for separate updates and improving the efficiency of rights card updates.
[0067] The rights card stores the individual's rights data at the time of issuance. The rights card is a smart card that includes an operating system. When rights are updated, the rights system initiates a rights update operation to the rights sharing platform and uploads the updated rights data to the rights sharing platform.
[0068] Specifically, the equity sharing platform includes multiple first nodes and multiple second nodes; the first nodes are used to maintain the equity ledger of the blockchain, and smart contracts are deployed on the first nodes; the second nodes are used to verify and sort submitted transactions, package the sorted transactions into blocks, and send them to each first node.
[0069] The equity sharing platform uses blockchain to store equity data. During implementation, the constructed equity sharing platform includes multiple first nodes (peer nodes) and multiple second nodes. The first nodes are used to maintain the blockchain's equity ledger, that is, to endorse transactions and update the blockchain.
[0070] A second node network is constructed, comprising at least four second nodes (orderer nodes). These second nodes are responsible for verifying and sorting transactions, packaging sorted transactions into blocks, and sending them to each first node, enabling the first node to update the blocks and state database. Message synchronization is performed between multiple second nodes. A smart contract is deployed on the first node, which reads and writes the first node's equity chain and state data. The smart contract's endorsement policy allows for arbitrary node endorsement, meaning that any endorsement by a first node validates the result. To prevent tampering with the smart contract, a policy with endorsement by more than two first nodes is also possible. To ensure data security and secure access, the blockchain of the equity-sharing platform is a consortium chain. All first and second nodes join the same channel, share and manage the equity ledger within the channel, enabling secure sharing and management of equity data.
[0071] During implementation, each first node stores equity data, that is, each update information of the equity data is saved on the blockchain of the first node (obtaining the equity ledger), and the state database of the first node stores the latest state data obtained based on the latest update.
[0072] During implementation, each equity system establishes a connection with the corresponding first node (peer node) through the https protocol.
[0073] When there is an update to the equity, the equity system initiates an equity update operation to the equity sharing platform and uploads the updated equity information to the equity sharing platform. Specifically, it includes:
[0074] S11. The equity system encrypts and signs the equity modification information and sends it to the corresponding first node;
[0075] S12. The first node verifies the signature of the received encrypted and signed equity update information, decrypts it, obtains the equity update information, endorses the equity update information, encrypts and signs the endorsement result, and returns it to the equity system.
[0076] S13. The equity system verifies and decrypts the encrypted and signed endorsement result. If the endorsement result does not fail verification, the equity update information and the endorsement result are treated as a transaction, encrypted and signed, and then sent to any second node.
[0077] S14. The second node verifies the signature of the received data and decrypts it to obtain transactions, sorts the transactions, packages the sorted transactions into blocks, and sends them to each first node.
[0078] S15. Each first node updates local block information according to the received blocks.
[0079] During implementation, the equity update information includes: update type (new / modified), updated data, and the equity system encrypts and signs the equity update information and sends it to the corresponding first node.
[0080] It should be noted that each first node stores the blockchain (ledger copy) and status data in the channel. The status data is the latest status data obtained based on the latest transaction data, thereby forming a distributed ledger and achieving decentralization.
[0081] After receiving the encrypted and signed equity update information, the first node first verifies and decodes the signature, and then endorses the equity update information.
[0082] The first node endorses the equity update information, encrypts and signs the endorsement result, and returns it to the equity system, including:
[0083] S121. Call the smart contract to check whether the rights update is legal; if not, the endorsement result is verification failure;
[0084] S122. If the transaction is legal, the equity update information is used as the input of the smart contract, and the smart contract is called to simulate the transaction execution to obtain the simulated execution result; the simulated execution result is signed as the endorsement result.
[0085] During implementation, the following methods are used to determine whether the rights update is legal:
[0086] If the equity update type is to add new equity data, the query function of the smart contract is called with the ID of the newly added equity data as the index to check whether the ID of the equity data exists in the state database of the first node. If it exists, the transaction is illegal;
[0087] If the equity update type is to modify equity data, the smart contract's query function is called with the ID of the modified equity data as the index to check whether the equity data ID exists in the first node's state database. If not, the transaction is invalid. In practice, the equity data ID is a unique identifier consisting of the individual's ID type, ID number, and name. If the equity update type is to add equity data, but the individual's data already exists in the first node's state database, the transaction is invalid. If the equity update type is to modify equity data, but the individual's data does not exist in the first node's state database, the transaction is also invalid.
[0088] If the transaction is legal, the smart contract is called to simulate the execution of the rights and interests update based on the state database of the first node, and the simulated execution result is obtained. The simulated execution result is signed as the endorsement result.
[0089] It should be noted that the simulation execution result includes a read set and a write set, which correspond to the state data before the simulation transaction is executed and the state data after the simulation transaction is executed.
[0090] For example, if the equity update type is to modify the equity data, the state data is obtained, and the corresponding equity data modification is performed on it to obtain the simulation execution result.
[0091] The equity system verifies and decrypts the encrypted and signed endorsement result received. If the endorsement result fails the verification, the next step will not be performed.
[0092] If the endorsement result is not verification failure, after the equity system receives the required endorsement result according to the endorsement policy, it encrypts and signs the equity update information and endorsement result as a transaction and sends it to any second node.
[0093] The second node verifies the signature of the received data and decrypts it to obtain the transaction, and then sorts and packages it into blocks.
[0094] It should be noted that there is a consensus mechanism among multiple second nodes. When implemented, an existing formula algorithm, such as the fast Byzantine algorithm, is used to reach a consensus and determine which second node will sort the transactions and package the blocks.
[0095] Specifically, the second node verifies and sorts the transactions, packages the sorted transactions into blocks, and sends them to each first node, including:
[0096] The second node verifies the validity of the transaction; if the transaction is invalid, it returns a transaction failure message to the equity system;
[0097] The second node sends valid transactions to the buffer for sorting according to the time sequence of transaction requests;
[0098] If the block time is reached, or the number of transactions in the buffer reaches the specified number, the transactions in the buffer are packaged into a block, signed, and sent to each first node.
[0099] During implementation, the second node verifies the validity of the transaction including:
[0100] Determine whether the number of endorsement results of the transaction meets the endorsement policy requirements. If not, the transaction is invalid;
[0101] If the endorsement policy is that there is more than one endorsement node, then determine whether the simulated execution results of all endorsement results of the transaction are the same. If there are different simulated execution results, the transaction is invalid.
[0102] For valid transactions, the second blockchain node sends the transactions to the buffer for sorting in the order of the transaction requests.
[0103] When implemented, the time of the transaction request is the timestamp when the equity system sends the equity update information to the equity sharing platform.
[0104] When the block generation conditions are met, the transactions in the buffer are packaged into blocks and signed, and sent to each first node to update the blockchain and status database.
[0105] After receiving the block, the first node verifies whether the signature is valid. If it is valid, it updates the local block information based on the received block. Specifically, it includes:
[0106] Add the received block to the Ontology blockchain;
[0107] Update the local state database based on the received blocks.
[0108] During implementation, the first node adds the block to the local blockchain and updates the local state data based on the transaction information in the received block.
[0109] During implementation, the card management system and each equity system subscribe to events on the blockchain of the equity sharing platform through the message mechanism. When the blockchain is updated, messages corresponding to the events are sent to the card management system and each equity system, so that the card management system and each equity system can monitor changes in equity status in a timely manner.
[0110] After the rights are updated, the rights card is updated through the read-write device and the rights read-write control system. Users only need to update once to uniformly update the rights data of different rights systems without having to update them separately, which improves the efficiency of the update.
[0111] During implementation, the equity read-write control system is used to control the read-write device to read and write equity cards, specifically including:
[0112] S21, initialize the driver of the read / write device;
[0113] S22. Control the read / write device to power on and reset the equity card to obtain the dispersion factor of the equity card;
[0114] S23. Authenticate the equity card based on the dispersion factor of the equity card; after the authentication is passed, authenticate the equity card;
[0115] S24. If the rights card authentication is successful, the read / write device is authenticated based on the dispersion factor of the rights card. After the authentication is passed, the individual basic information in the rights card is read.
[0116] During implementation, since there are many different card reading devices, in order to perform unified card reading and writing, it is first necessary to initialize the driver of the reading and writing device.
[0117] Specifically, the equity read-write control system initializes the driver of the read-write device, including:
[0118] Get the set of all read-write device driver paths in the root directory of the equity read-write control system;
[0119] The driver in each driver path in the read / write device driver path set is loaded in sequence, and the following steps are used to determine whether the driver is a driver that matches the read / write device:
[0120] For the current driver, call the initialization function in the driver. If the initialization is successful, the current driver is the driver that matches the read-write device. The path of the current driver is recorded as the path of the driver of the read-write device to complete the initialization of the read-write device. Otherwise, the current driver is not the driver that matches the read-write device.
[0121] During implementation, the driver of the read-write device connected to the equity read-write control system is found by polling the read-write device drivers of various manufacturers.
[0122] For each loaded driver, the initialization function is called and the result returned by the function is used to determine whether the initialization is successful. If the initialization is successful, it is considered that the driver matching the read / write device is found and its path is written to the local cache, so that the driver function can be called directly through the driver path recorded in the cache during subsequent card read / write operations.
[0123] After initializing the driver of the read / write device, a power-on command is sent to the corresponding port of the read / write device to control the read / write device to power on and reset the equity card, and the dispersion factor of the equity card is obtained according to the reset response information, that is, the reset response information of the equity card contains the dispersion factor of the equity card.
[0124] It should be noted that because each equity card has a different key, the reader / writer must be able to authenticate with each equity card. Therefore, the reader / writer stores the parent key of the symmetric keys on all equity cards. This parent key is then dispersed using a dispersion algorithm to obtain the symmetric key and corresponding dispersion factor for each equity card. Therefore, the reader / writer can obtain the symmetric key on each equity card using the parent key and the dispersion factor of the equity card.
[0125] In order to prevent data tampering and effectively identify counterfeit equity cards, equity cards need to be authenticated. Specifically, the reader / writer device is authenticated based on the equity card's dispersion factor, including:
[0126] S231, the equity read-write control system sends a random number acquisition instruction to the read-write device to acquire a first random number R1 generated by the read-write device;
[0127] S232: The equity read-write control system sends a first encryption instruction including a first random number R1 to the equity card, and obtains a first encrypted ciphertext E1 obtained by the equity card executing the first encryption instruction.
[0128] S233. The rights and interests reading and writing control system sends a first authentication instruction including a first encrypted ciphertext to the reading and writing device. The reading and writing device performs authentication based on the dispersion factor of the rights and interests card to obtain a rights and interests card authentication result.
[0129] During implementation, the equity read / write control system sends a random number acquisition instruction to the read / write device to obtain the first random number R1 generated by the read / write device. The equity read / write control system sends a first encryption instruction containing the first random number R1 to the equity card, and then obtains the first encrypted ciphertext E1 generated by the equity card executing the first encryption instruction.
[0130] During implementation, to prevent the encryption key from being exposed, the first encrypted ciphertext E1 obtained by the equity card executing the first encryption instruction includes:
[0131] S2321. The equity card generates a third random number R3, where the length of the third random number is the same as that of the first random number;
[0132] S2322. Encrypt the first random number R1 and the third random number R3 respectively and combine the encryption results to obtain the encrypted ciphertext to be verified;
[0133] S2323. Pack the encrypted ciphertext to be verified and the third random number to obtain a first encrypted ciphertext E1.
[0134] After receiving the first encryption instruction, the equity card first generates a third random number R3, and the length of the third random number R3 is the same as that of the first random number R1.
[0135] During implementation, the equity card encrypts the first random number and the third random number using a symmetric key, and combines the two encryption results to obtain the encrypted ciphertext to be verified. During implementation, the two encryption results can be spliced or added together to obtain the encrypted ciphertext to be verified.
[0136] Then, the encrypted ciphertext to be verified and the third random number are packaged to obtain the first encrypted ciphertext E1.
[0137] The rights card sends the first encrypted ciphertext to the rights read-write control system, and the rights read-write control system sends a first authentication instruction to the read-write device, where the first authentication instruction includes the first encrypted ciphertext.
[0138] Specifically, the reader / writer performs authentication based on the dispersed factor of the equity card and obtains the equity card authentication result, including:
[0139] The reading and writing device splits the first encrypted ciphertext to obtain the encrypted ciphertext to be verified and the third random number R3;
[0140] Obtain the symmetric key based on the dispersion factor of the equity card;
[0141] The first random number R1 and the third random number R3 are encrypted according to the obtained symmetric key respectively, and the encryption results are combined to obtain the target encrypted ciphertext, and it is determined whether the encrypted ciphertext to be verified and the target encrypted ciphertext are the same. If they are the same, the rights card authentication result is authentication passed, otherwise the authentication is failed.
[0142] During implementation, since the third random number and the first random number have the same length, the reader / writer can split the first encrypted ciphertext to obtain the encrypted ciphertext to be verified and the third random number R3. During implementation, according to the key dispersion algorithm, the corresponding symmetric key can be obtained from the dispersion factor of the equity card.
[0143] The reader / writer encrypts the first random number R1 and the third random number obtained by splitting using the obtained symmetric key, and combines the two encryption results to obtain the target encrypted ciphertext. It then determines whether the encrypted ciphertext to be verified and the target encrypted ciphertext are identical. If they are, the first authentication result is authentication passed; otherwise, authentication failed. The merging method can be concatenation or addition, which is the same as the method used for the equity card.
[0144] After the rights card is authenticated, rights card authorization is required to determine whether the card's service status is valid. During implementation, the rights read-write control system reads the card number and sends the card authorization information to the card management system to determine whether the card's service status is valid. If invalid, subsequent operations are discontinued and the device is shut down. If valid, the card information is read again.
[0145] During implementation, if the rights card authentication is successful, the reading and writing device will be authenticated based on the dispersion factor of the rights card. After the authentication is passed, the individual basic information in the rights card will be read.
[0146] During implementation, in order to prevent data tampering, improve security, and effectively identify counterfeit equity cards, the reader / writer device needs to be authenticated before reading the personal information in the card. Specifically, the following steps are required:
[0147] S234: The rights read-write control system sends a random number acquisition instruction to the rights card to acquire a second random number R2 generated by the rights card;
[0148] S235. The equity read-write control system sends a second encryption instruction including a second random number and a dispersion factor of the equity card to the read-write device, and obtains a second encrypted ciphertext E2 obtained by the read-write device executing the second encryption instruction.
[0149] S236. The rights read-write control system sends the second authentication instruction containing the second encrypted ciphertext to the rights card for authentication, and obtains the read-write device result.
[0150] During implementation, both the equity card and the reader / writer device have authentication and encryption modules. The reader / writer's authentication and encryption module can be an internally installed PSAM card or an externally connected encryption device. The reader / writer device obtains the corresponding symmetric key based on the equity card's dispersion factor and executes the second encryption instruction based on the obtained symmetric key.
[0151] The process of steps S234 to S236 is the same as that of steps S231 to S233, except that the roles of the rights card and the read-write device are swapped. Steps S231 to S233 are the read-write device authenticating the rights card, and steps S234 to S236 are the rights card authenticating the read-write device.
[0152] After the read-write device is authenticated, the equity read-write control system can perform subsequent read-write operations.
[0153] During implementation, the card reader function is called to read the basic individual information in the rights card, including the evidence type, evidence number, and name, and then a rights card update request is sent to the card management system. The rights card update request includes the basic individual information.
[0154] Because the card management system subscribes to the block update events of the equity sharing platform, it stores the update information. The card management system determines whether the individual's equity data has been updated based on the individual's basic information. If not, it returns no update information. If so, it obtains the individual's updated equity data from the equity sharing platform.
[0155] Specifically, the card management system obtains individual rights and interests data from the rights and interests sharing platform, including:
[0156] S31. The card management system encrypts and signs the rights query information and sends it to the corresponding first node;
[0157] S32. The first node verifies the signature of the received encrypted and signed rights query information, decrypts it, and obtains the rights query information. The first node endorses the rights query information, encrypts and signs the endorsement result, and returns it to the card management system.
[0158] S33. The card management system verifies and decrypts the encrypted and signed endorsement result. If the endorsement result fails verification, the card management system returns a transaction verification failure to the equity read-write control system. Otherwise, the equity data is obtained from the endorsement result.
[0159] During implementation, the process of steps S31 to S32 is the same as that of steps S11 to S12, except for the difference in determining whether it is legal or not in step S121. When obtaining individual rights and interests data from the rights and interests sharing platform, the following method is used to determine whether the rights and interests query information is legal or not:
[0160] The query function of the smart contract is called with the ID of the queried equity data as the index to query whether the ID of the equity data exists in the state database of the first node. If not, the transaction is illegal.
[0161] In step S33, the card management system verifies and decrypts the encrypted and signed endorsement result, obtaining the endorsement result. If the endorsement result does not indicate a verification failure, the queried equity data is obtained based on the simulated execution result in the endorsement result. The card management system returns the acquired equity data to the equity read-write control system, which calls the card write function to write the equity data to the equity card.
[0162] To improve data transmission security and eliminate the risk of data leakage or tampering, data exchange between systems is encrypted. For example, each equity system and equity sharing platform uniformly issues asymmetric key pairs, and both parties exchange asymmetric public keys. Data transmission between the two parties is encrypted and signed, thereby enhancing security.
[0163] Specifically, the encryption and signing process includes the following steps:
[0164] The sender randomly generates a symmetric key, and symmetrically encrypts the sent data based on the symmetric key to generate symmetric ciphertext data;
[0165] The sender asymmetrically encrypts the symmetric key according to the receiver's asymmetrically encrypted public key to generate an asymmetric key ciphertext;
[0166] The sender packages the symmetric ciphertext data and the asymmetric key ciphertext to generate a temporary ciphertext, and uses its own asymmetric encryption private key to digitally sign the temporary ciphertext to generate a signature value;
[0167] The sender packages the signature value and the temporary seal to obtain the final sent data.
[0168] Specifically, the signature verification and decryption process includes:
[0169] The receiver splits the received data to obtain the signature value, asymmetric key ciphertext and ciphertext data;
[0170] The receiver verifies the signature value using the sender's asymmetrically encrypted public key. If the verification fails, a verification failure message is returned. Otherwise, the receiver decrypts the asymmetric key ciphertext using its own asymmetrically encrypted private key to obtain the symmetric key.
[0171] Use the symmetric key to decrypt the symmetric ciphertext to obtain the original data sent by the sender.
[0172] Encryption and signing are achieved by combining symmetric encryption, asymmetric encryption and digital signatures, which greatly improves the security of data transmission.
[0173] Those skilled in the art will appreciate that all or part of the process steps of the above-described embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium, such as a magnetic disk, an optical disk, a read-only memory, or a random access memory.
[0174] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any technician familiar with this technical field within the technical scope disclosed by the present invention should be covered by the scope of protection of the present invention.
Claims
1. A rights card update platform, characterized in that: Includes the following modules: Multiple rights and interests systems, each of which is used to initiate a rights and interests update operation to the rights and interests sharing platform and upload the updated rights and interests information to the rights and interests sharing platform; the rights and interests are people's livelihood related rights and interests; Equity sharing platform, used to store equity data using blockchain; Reader / writer device, used to identify rights cards and read and write rights card information; The rights and interests reading and writing control system is used to control the reading and writing device to read and write the rights and interests card; obtain the individual basic information read by the reading and writing device, and send a rights and interests card update request to the card management system; the rights and interests card update request includes the individual basic information; The card management system is used to determine whether the individual's equity data has been updated based on the individual's basic information. If not, it returns no updated data to the equity read and write control system; Otherwise, the individual's equity data is obtained from the equity sharing platform and returned to the equity read-write control system; The rights reading and writing control system writes the updated rights data of the individual into the rights card through the reading and writing device; The rights reading and writing control system controls the reading and writing equipment to read and write rights cards, including: Initialize the driver for the read and write devices; Control the read / write device to power on and reset the equity card to obtain the dispersion factor of the equity card; Authenticate the equity card based on its dispersion factor; after passing the authentication, authenticate the equity card; If the equity card authentication is successful, the reader / writer will be authenticated based on the equity card's dispersion factor. After the authentication is passed, the individual's basic information in the equity card will be read; Authenticate the equity card based on its dispersion factor, including: The equity read-write control system sends a random number acquisition instruction to the read-write device to acquire a first random number generated by the read-write device; The equity read-write control system sends a first encryption instruction including a first random number to the equity card, and obtains a first encrypted ciphertext obtained by the equity card executing the first encryption instruction; The equity read-write control system sends a first authentication instruction containing a first encrypted ciphertext to the read-write device, and the read-write device performs authentication based on the dispersion factor of the equity card to obtain an equity card authentication result; The first encrypted ciphertext obtained by the equity card executing the first encryption instruction includes: The equity card generates a third random number, wherein the length of the third random number is the same as the length of the first random number; Encrypting the first random number and the third random number respectively and combining the encryption results to obtain an encrypted ciphertext to be verified; Packing the encrypted ciphertext to be verified and the third random number to obtain a first encrypted ciphertext; The reader / writer performs authentication based on the decentralized factor of the equity card and obtains the equity card authentication result, including: The reading and writing device splits the first encrypted ciphertext to obtain the encrypted ciphertext to be verified and the third random number; Obtain the symmetric key based on the dispersion factor of the equity card; The first random number and the third random number are encrypted respectively according to the obtained symmetric key and the encryption results are combined to obtain the target encrypted ciphertext, and it is determined whether the encrypted ciphertext to be verified and the target encrypted ciphertext are the same. If they are the same, the rights card authentication result is authentication passed, otherwise the authentication is failed.
2. The rights card update platform according to claim 1, characterized in that: Authentication of read / write devices based on the decentralized factors of the equity card, including: The rights read-write control system sends a random number acquisition instruction to the rights card to acquire a second random number generated by the rights card; The equity read-write control system sends a second encryption instruction including a second random number and a dispersion factor of the equity card to the read-write device, and obtains a second encrypted ciphertext obtained by the read-write device executing the second encryption instruction; The rights and interests reading and writing control system sends the second authentication instruction containing the second encrypted ciphertext to the rights and interests card for authentication, and obtains the authentication result of the reading and writing device.
3. The rights card update platform according to claim 1, characterized in that: The equity read-write control system initializes the card reader driver, including: Get the set of all read-write device driver paths in the root directory of the equity read-write control system; The driver in each driver path in the read / write device driver path set is loaded in sequence, and the following steps are used to determine whether the driver is a driver that matches the read / write device: For the current driver, call the initialization function in the driver. If the initialization is successful, the current driver is the driver that matches the read-write device. The path of the current driver is recorded as the path of the driver of the read-write device to complete the initialization of the read-write device. Otherwise, the current driver is not the driver that matches the read-write device.
4. The rights card update platform according to claim 1, characterized in that: The equity sharing platform includes multiple first nodes and multiple second nodes; the first nodes are used to maintain the equity ledger of the blockchain, and smart contracts are deployed on the first nodes; the second nodes are used to verify and sort submitted transactions, package the sorted transactions into blocks, and send them to each first node; The equity system initiates an equity update operation to the equity sharing platform and uploads the updated equity information to the equity sharing platform, including: The equity system encrypts and signs the equity update information and sends it to the corresponding first node; The first node verifies the signature of the received encrypted and signed equity update information and decrypts it to obtain the equity update information, endorses the equity update information, encrypts and signs the endorsement result, and returns it to the equity system; The equity system verifies and decrypts the encrypted and signed endorsement result. If the endorsement result does not fail verification, the equity update information and the endorsement result are treated as a transaction, encrypted and signed, and sent to any second node. The second node verifies the signature of the received data and decrypts it to obtain the transaction, verifies and sorts the transactions, packages the sorted transactions into blocks, and sends them to each first node; Each first node updates local block information according to the received blocks.
5. The rights card update platform according to claim 4, characterized in that: The encryption and signing process includes the following steps: The sender randomly generates a symmetric key, and symmetrically encrypts the sent data based on the symmetric key to generate symmetric ciphertext data; The sender asymmetrically encrypts the symmetric key according to the receiver's asymmetrically encrypted public key to generate an asymmetric key ciphertext; The sender packages the symmetric ciphertext data and the asymmetric key ciphertext to generate a temporary ciphertext, and uses its own asymmetric encryption private key to digitally sign the temporary ciphertext to generate a signature value; The sender packages the signature value and temporary ciphertext to obtain the final sent data.
6. The rights card update platform according to claim 4, characterized in that: The signature verification and decryption process includes the following steps: The receiver splits the received data to obtain the signature value, asymmetric key ciphertext and ciphertext data; The receiver verifies the signature value using the sender's asymmetrically encrypted public key. If the verification fails, a verification failure message is returned. Otherwise, the receiver decrypts the asymmetric key ciphertext using its own asymmetrically encrypted private key to obtain the symmetric key. Use the symmetric key to decrypt the symmetric ciphertext to obtain the original data sent by the sender.
Citation Information
Patent Citations
RFID bidirectional authentication method
CN106792686A
Block chain-based rights and interests issuing method and device, electronic device and storage medium
CN110148017A
Payment processing method and device based on near field communication
CN117933987A