A method for applying to transaction access path adaptive system
By using the GMSSL private dual-certificate collaborative signature channel, the problems of complex maintenance and high network risks during the access process of securities trading systems are solved, enabling automatic emergency switching and efficient emergency handling, thereby improving system security and user experience.
Patent Information
- Application Number
- CN202411868449.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-12-18
AI Technical Summary
The existing securities trading system is complex to maintain during the access process, has high network risks, long emergency switchover time, large maintenance workload, and cumbersome emergency handling.
The GMSSL private dual-certificate collaborative signing channel is adopted. Through the collaborative signing method of collaborative signing client, server, business server, centralized storage module and certificate issuance server, the number of network ports is reduced, automatic emergency switching and identity verification are realized, network risks are reduced and emergency switching efficiency is improved.
It reduced network risks, decreased maintenance workload, improved emergency response efficiency, ensured system continuity and security, and optimized user experience.
Smart Images

Figure CN119814403B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network transaction security technology, and in particular to a method applied to a transaction access path adaptive system. Background Technology
[0002] As a widely used commercial application system, securities trading systems have particularly prominent characteristics, namely, they have very high requirements for security, real-time performance, accuracy, and continuity. In particular, as an open online trading and service platform, its security plays a crucial role in the entire system. How to provide robust security and redundancy services is one of the key issues faced in establishing an online trading system.
[0003] With the development of internet technology, online securities trading has become the main trading method, providing investors with high-speed, stable real-time market data and safe and reliable order placement services. However, securities trading access is a crucial link in the trading process. As the access function of the trading system is upgraded, the number of system nodes relied upon during the access process is constantly increasing, and the risks in the access stage are also increasing exponentially.
[0004] Currently, there are two access methods for SSL one-way authentication and two-way authentication. The SSL server provides two different network connection ports. The collaborative signature client accesses RA through SSL one-way authentication service port 1 for business identity verification, completes the issuance of SSL dual certificates through the certificate issuing server cloud interface, and finally accesses the backend trading server through SSL two-way authentication service port 2 to complete securities information query and trading at the business layer.
[0005] In the existing authentication access methods, the client must maintain two sets of SSL certificates, which is difficult to maintain. The server must maintain two network ports, doubling the network risk. The server must maintain two sets of SSL certificates (one-way SSL certificate and two-way SSL certificate), which is a large workload. Maintaining the newly added RA system separately is complex. At the same time, if the key management system KMS fails, the emergency handling is troublesome and requires manual intervention to manually switch the SSL server authentication method from two-way authentication to one-way authentication access method, which takes a long time for emergency switching.
[0006] Therefore, there is an urgent need to provide a method for adaptive transaction access paths, which can improve the system's resilience and the efficiency of switching in emergency scenarios while ensuring network security. This is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0007] To overcome the shortcomings of existing technologies, this invention provides a method for an adaptive transaction access path system. This method can complete business queries and transactions through a GMSSL private dual-certificate collaborative signature channel, saving network port resources, reducing network risks, and improving the switching efficiency in emergency scenarios.
[0008] The technical solution is as follows:
[0009] A method for a transaction access path adaptive system includes a collaborative signature client, a collaborative signature server, a business server, a centralized storage module, and a certificate issuance server, wherein the collaborative signature client, collaborative signature server, business server, centralized storage module, and certificate issuance server are connected in sequence. The collaborative signature client includes a client and a collaborative signature SDK, wherein the client, collaborative signature SDK, and collaborative signature server are connected in sequence.
[0010] In scenarios without SSL private dual certificates, the collaborative signature client performs the following operations:
[0011] S1: The collaborative signature SDK, collaborative signature server, and business server sequentially receive user legitimacy verification information from the client;
[0012] S2: The client receives the verification message from the business server;
[0013] S3: The centralized storage module works with the business server to save the authentication results;
[0014] S4: The collaborative signature SDK receives certificate requests from clients and extracts terminal identification codes;
[0015] S5: The collaborative signature server receives a certificate request, collaborative signature public key, and terminal identification information from the collaborative signature SDK;
[0016] S6: The centralized storage module performs secondary verification on the information from the collaborative signature server;
[0017] S7: The collaborative signature server sends a certificate request to the certificate issuing server;
[0018] S8: The certificate issuing server responds to the collaborative signature server with a certificate;
[0019] S9: The centralized storage module stores the public key for the agreement and the terminal identification information;
[0020] S10: The centralized storage module sends a storage response message back to the collaborative signature server;
[0021] S11: The collaborative signature server requests the certificate issuing server to issue a certificate;
[0022] S12: The certificate authority server responds to the certificate issuance request;
[0023] S13: The collaborative signature server sends a certificate response message to the collaborative signature SDK;
[0024] S14: The collaborative signature SDK sends decryption certificate information back to the client;
[0025] In a scenario with dual SSL private certificates, the collaborative signature client performs the following operations:
[0026] S15: After receiving the extraction terminal identification code sent by the client, the collaborative signature SDK performs two-way authentication with the collaborative signature server using national cryptographic SSL.
[0027] S16: The centralized storage module queries the public key information of the co-signed agreement;
[0028] S17: The collaborative signature SDK interacts with the collaborative signature server to perform collaborative signature verification.
[0029] S18: The collaborative signature SDK encrypts and sends information to the collaborative signature server;
[0030] S19: The collaborative signature SDK and the collaborative signature server receive and decrypt information.
[0031] Preferably, in scenarios without SSL private dual certificates, the collaborative signature client first establishes a channel with the backend using a pre-set certificate and password to verify the legitimacy of the business layer's identity. The centralized storage module, in conjunction with the business server, saves the identity verification result. After the collaborative signature client and the collaborative signature server complete the secondary identity verification, the collaborative signature server forwards the certificate request sent by the collaborative signature client to the certificate issuing server. Finally, the collaborative signature client obtains the SM dual certificate and SSL encryption private key issued by the certificate issuing server, and then completes the collaborative signature SSL channel that meets the requirements through the private dual certificate.
[0032] Preferably, the SSL pre-built dual certificate password channel is only set up for three scenarios: application for SSL private dual certificates, renewal, and emergency situations.
[0033] Preferably, the GMSSL access server only needs to open one network port. When packaging the collaborative signature client, a 5-year SSL pre-installed dual certificate is included. Through the pre-installed SSL dual certificate password channel, the initial business layer identity verification and the issuance of the SM2 national cryptographic private dual certificate are completed. Business queries and transactions are completed through the GMSSL private dual certificate collaborative signature channel, saving network port resources and reducing network risks.
[0034] Preferably, the collaborative signature client actively detects the status of centralized storage through the SSL dual-certificate collaborative signature channel. In the event of an abnormality in centralized storage, the collaborative signature client automatically switches to the password channel with the SSL pre-set dual certificates to complete business queries and transactions. This eliminates the need for manual emergency switching and operation on the server side, as well as manual monitoring and switching operations. Compared with the manual discovery and operation required by ordinary solutions, this improves the efficiency of emergency response.
[0035] Preferably, if the certificate issuing server malfunctions, resulting in certificate issuance failure, the collaborative signature client can automatically use the current password channel as an emergency channel to continue completing business queries and transactions without requiring manual emergency switching and operation on the server side. Compared with the manual discovery and operation of ordinary solutions, this improves the efficiency of emergency response.
[0036] Preferably, the above-mentioned method for an adaptive transaction access path system further includes an emergency procedure, which addresses failures of the centralized storage module and the certificate issuance server.
[0037] Preferably, the centralized storage failure is divided into two categories: loss of the collaborative signature public key and abnormality of the centralized storage network port. The emergency procedure for loss of the collaborative signature public key is as follows:
[0038] The centralized storage system contains the collaborative signature public key data required for collaborative signature login by the collaborative signature client. Data between the master and slave of the centralized storage is automatically synchronized in real time. In extreme scenarios where the collaborative signature public key data is lost, the collaborative signature client will automatically re-run the SSL private dual certificate application process.
[0039] The emergency procedure for handling abnormal centralized storage network ports is as follows:
[0040] If a network port anomaly occurs, the centralized storage adopts a master-slave deployment mode. In the event of a complete system outage in an extreme scenario, the collaborative signature client directly switches to the SSL pre-built dual-certificate password channel to ensure business continuity.
[0041] The preferred emergency procedure for certificate issuance server failure is as follows:
[0042] The certificate issuance server, as an SSL dual certificate issuance service, achieves high availability by attaching multiple IP addresses after the domain name. If any of these become unavailable in extreme circumstances, the collaborative signing client will automatically switch to the SSL pre-built dual certificate password channel to ensure business continuity.
[0043] A security system with adaptive transaction access path, characterized in that the system comprises:
[0044] A collaborative signature client used to initiate user authentication information and certificate requests;
[0045] The collaborative signature server is used to receive and process information from the collaborative signature client, and to send certificate requests to the certificate issuing server.
[0046] The business server is used to receive and process information from the collaborative signature server and send receipt verification information to the client.
[0047] The centralized storage module is used to store authentication results, co-signing public keys, terminal identification information, and certificate-related information, and performs secondary verification on the information;
[0048] The certificate issuing server is used to respond to certificate requests from the collaborative signature server.
[0049] Compared with the prior art, the above-described technical solutions conceived in this invention have the following advantages:
[0050] 1. Reduce network risks: The GMSSL access server only needs to open one network port, reducing the number of network ports and thus reducing the network risks caused by an increase in ports. The collaborative signature client comes pre-packaged with a 5-year SSL dual certificate, reducing the complexity of certificate management and maintenance.
[0051] 2. Improved emergency response efficiency: The collaborative signature client can automatically detect the status of centralized storage and automatically switch to the SSL pre-built dual certificate password channel in case of anomalies to complete business queries and transactions. No manual emergency switching and operation is required on the server side, and the emergency switching time is shortened to less than 1 second. In the event of a failure of the certificate issuing server or KMS, the collaborative signature client can autonomously use the current password channel as an emergency channel to continue to complete business queries and transactions, ensuring business continuity.
[0052] 3. Reduced maintenance workload: The server does not need to maintain two network ports and two sets of SSL certificates (one-way SSL certificate and two-way SSL certificate), which reduces the maintenance workload of certificates and ports. There is no need to maintain the newly added RA system separately, which reduces the complexity and maintenance cost of the system.
[0053] 4. Enhanced System Security: The system employs the GMSSL protocol for encrypted communication and data integrity assurance, supports the SSL / TSLS secure communication protocol based on SM2 commercial cryptographic dual certificates, and improves system security. It establishes a secure two-way authentication channel through the SSL pre-set dual certificate password channel and the SSL private dual certificate collaborative signature channel, thereby enhancing the system's authentication and access control.
[0054] 5. Optimize user experience: In emergency situations, the collaborative signature client can automatically switch to emergency mode without requiring manual operation from the user, thus improving the user experience. By optimizing the emergency handling process and innovative technologies, it ensures the continuity of business in abnormal situations and protects the normal transactions of users.
[0055] 6. High Availability Design: The centralized storage system contains the collaborative signature public key data required for collaborative signature client login. Data is automatically synchronized in real time between master and slave, improving the system's availability and fault tolerance. The certificate issuance server serves as an SSL dual certificate issuance service, achieving high availability by attaching multiple IP addresses after the domain name, further enhancing the system's stability and reliability.
[0056] 7. Flexibility and scalability: It provides a variety of emergency response solutions to cope with abnormal situations in different scenarios, ensuring the flexibility and scalability of the system. It is reasonably designed and easy to upgrade and maintain. Attached Figure Description
[0057] Figure 1 This is a schematic diagram of the overall process of the present invention.
[0058] Figure 2 This is a schematic diagram of the national cryptographic modification process of the present invention. Detailed Implementation
[0059] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.
[0060] Example
[0061] A method applied to an adaptive transaction access path system, such as Figure 1 As shown, it includes a collaborative signature client, a collaborative signature server, a business server, a centralized storage module, and a certificate issuance server, which are connected in sequence.
[0062] Collaborative signature client
[0063] A collaborative signature client consists of a client and a collaborative signature SDK. The client serves as the entry point for user interaction, responsible for receiving user commands and input information. The collaborative signature SDK acts as a bridge between the client and the server, handling communication and data exchange between them.
[0064] Collaborative signature server
[0065] The collaborative signature server is responsible for receiving certificate requests and authentication information from the collaborative signature client, performing secondary verification, forwarding the request to the certificate issuing server, receiving the response from the certificate issuing server, and finally sending the certificate response message back to the collaborative signature client.
[0066] Business Server
[0067] The business server is responsible for handling securities trading business logic, receiving authentication results and transaction requests from the collaborative signature server, processing the business logic, and returning the results to the client.
[0068] Centralized storage module
[0069] The centralized storage module is responsible for storing critical data such as authentication results, public keys for signatures, and terminal identification information, ensuring data integrity and security. Simultaneously, the centralized storage module also works with the business server to query and update authentication results.
[0070] Certificate Issuance Server
[0071] The certificate issuance server is responsible for issuing SSL private dual certificates, ensuring secure communication between the collaborative signature client and the collaborative signature server. Simultaneously, the certificate issuance server is also responsible for handling certificate renewal and revocation requests from the collaborative signature server.
[0072] A method for an adaptive transaction access path system, comprising the following steps:
[0073] No certificate
[0074] 1. The client sends user legitimacy verification information to the collaborative signature server through the collaborative signature SDK.
[0075] 2. After receiving the verification information, the collaborative signature server forwards it to the business server for identity verification.
[0076] 3. After verifying the user's identity, the business server returns the verification result to the collaborative signature server and saves the verification result through the centralized storage module.
[0077] 4. The collaborative signature client sends a certificate request and extracts the terminal identification code to the collaborative signature server through the collaborative signature SDK.
[0078] 5. After receiving the certificate request, the collaborative signature server forwards the request information, the collaborative signature public key, and the terminal identification information to the certificate issuing server.
[0079] 6. The centralized storage module performs secondary verification on the information from the collaborative signature server to ensure the accuracy and integrity of the information.
[0080] 7. The certificate issuing server responds to the certificate request from the collaborative signing server and issues a private dual SSL certificate.
[0081] 8. The centralized storage module stores the public key for collaborative signing and terminal identification information, and sends a storage response message back to the collaborative signing server.
[0082] 9. The collaborative signature server sends the certificate response message to the collaborative signature SDK, which then sends the decrypted certificate information back to the client.
[0083] With certificate
[0084] 1. The collaborative signature client sends a request to the collaborative signature server to extract the terminal identification code through the collaborative signature SDK.
[0085] 2. The collaborative signature SDK and the collaborative signature server perform two-way authentication using national cryptographic SSL to ensure the identity security of both parties in communication.
[0086] 3. The centralized storage module queries the public key information of the agreement to ensure the accuracy and validity of the public key.
[0087] 4. The collaborative signature SDK interacts with the collaborative signature server to verify and confirm the signature, ensuring the integrity and authenticity of the data.
[0088] 5. The collaborative signature SDK and the collaborative signature server conduct bidirectional encrypted information transmission to ensure the confidentiality and security of information.
[0089] 6. After decrypting the encrypted information, the collaborative signature server forwards it to the business server for business processing.
[0090] To further optimize the above solution, the GMSSL access server only needs to open one network port. When packaging the collaborative signature client, a pre-set SSL dual certificate password channel with a 5-year validity period is included. Through the pre-set SSL dual certificate password channel, the initial business layer identity verification, issuance of SM2 national cryptographic dual certificates, issuance of SSL private dual certificates, and business query and transaction are completed through the GMSSL private dual certificate collaborative signature channel, saving network port resources and reducing network risks.
[0091] To further optimize the above solution, the collaborative signature client actively detects the status of centralized storage through the SSL dual-certificate collaborative signature channel. In the event of an anomaly in centralized storage, the collaborative signature client automatically switches to the password channel with the SSL pre-set dual certificates to complete business queries and transactions. This eliminates the need for manual emergency switching and operation on the server side, as well as manual monitoring and switching operations. Compared to the manual discovery and operation (minute-level emergency switching) of ordinary solutions, this solution achieves automatic emergency response within 1 second, improving the efficiency of emergency handling and taking only one-thousandth of the time required for emergency response in ordinary solutions.
[0092] To further optimize the above solution, if the third-party certificate issuing server malfunctions, resulting in certificate issuance failure, the collaborative signature client will automatically use the current password channel as an emergency channel to continue completing business queries and transactions. This eliminates the need for manual emergency switching and operation on the server side. Compared to the manual discovery and operation of ordinary solutions (emergency switching at the level of 15 minutes), this solution achieves automatic emergency switching within 1 second, making it seamless for customers and improving the efficiency of emergency response. It takes only one-thousandth of the time required for emergency response in ordinary solutions.
[0093] A method applied to an adaptive transaction access path system, such as Figure 2 As shown, the emergency procedures are as follows:
[0094] Centralized storage failure
[0095] 1. Loss of the public key for collaborative signature
[0096] The centralized storage system contains the collaborative signature public key data required for collaborative signature login by the collaborative signature client. Data between the master and slave of the centralized storage is automatically synchronized in real time. In extreme scenarios where the collaborative signature public key data is lost, the collaborative signature client will automatically re-run the SSL private dual certificate application process.
[0097] 2. Centralized storage network port malfunction
[0098] If a network port anomaly occurs, the centralized storage adopts a master-slave deployment mode. In the event of a complete system outage in an extreme scenario, the collaborative signature client directly switches to the SSL pre-built dual-certificate password channel to ensure business continuity.
[0099] Certificate issuance server failure
[0100] The certificate issuance server, as an SSL dual certificate issuance service, achieves high availability by attaching multiple IP addresses after the domain name. If any of these become unavailable in extreme circumstances, the collaborative signing client will automatically switch to the SSL pre-built dual certificate password channel to ensure business continuity.
[0101] A security system with adaptive transaction access path, characterized in that the system comprises:
[0102] A collaborative signature client used to initiate user authentication information and certificate requests;
[0103] The collaborative signature server is used to receive and process information from the collaborative signature client, and to send certificate requests to the certificate issuing server.
[0104] The business server is used to receive and process information from the collaborative signature server and send receipt verification information to the client.
[0105] The centralized storage module is used to store authentication results, co-signing public keys, terminal identification information, and certificate-related information, and performs secondary verification on the information;
[0106] The certificate issuing server is used to respond to certificate requests from the collaborative signature server.
[0107] Although this disclosure has been shown and described with reference to specific exemplary embodiments thereof, those skilled in the art will understand that various changes in form and detail may be made to this disclosure without departing from the spirit and scope of the disclosure as defined by the appended claims and their equivalents. Therefore, the scope of this disclosure should not be limited to the above embodiments, but should be defined not only by the appended claims, but also by their equivalents.
Claims
1. A method applied to a transaction access path adaptive system, characterized in that, The system includes a collaborative signature client, a collaborative signature server, a business server, a centralized storage module, and a certificate issuance server, which are sequentially connected. The collaborative signature client includes a client and a collaborative signature SDK, which are sequentially connected. In a scenario without SSL private dual certificates, the collaborative signature client performs the following operations: S1: The collaborative signature SDK, collaborative signature server, and business server sequentially receive user legitimacy verification information from the client; S2: The client receives the verification message from the business server; S3: The centralized storage module stores the authentication results of the business server; S4: The collaborative signature SDK receives certificate requests from clients and extracts terminal identification codes; S5: The collaborative signature server receives a certificate request, collaborative signature public key, and terminal identification information from the collaborative signature SDK; S6: The centralized storage module performs secondary verification on the information from the collaborative signature server; S7: The collaborative signature server sends a certificate request to the certificate issuing server; S8: The certificate issuing server responds to the collaborative signature server with a certificate; S9: The centralized storage module stores the public key for the agreement and the terminal identification information; S10: The centralized storage module sends a storage response message back to the collaborative signature server; S11: The collaborative signature server requests the certificate issuing server to issue a certificate; S12: The certificate authority server responds to the certificate issuance request; S13: The collaborative signature server sends a certificate response message to the collaborative signature SDK; S14: The collaborative signature SDK sends decryption certificate information back to the client; In a scenario with dual SSL private certificates, the collaborative signature client performs the following operations: S15: After receiving the extraction terminal identification code sent by the client, the collaborative signature SDK performs two-way authentication with the collaborative signature server using national cryptographic SSL. S16: The centralized storage module queries the public key information of the co-signed agreement; S17: The collaborative signature SDK interacts with the collaborative signature server to perform collaborative signature verification. S18: The collaborative signature SDK encrypts and sends information to the collaborative signature server; S19: The collaborative signature SDK and the collaborative signature server receive and decrypt information; Among them, the SSL pre-built certificate and password channel are only set up for three scenarios: application and renewal of SSL private dual certificates, and emergency situations.
2. The method for applying to a transaction access path adaptive system as described in claim 1, characterized in that, In scenarios without SSL private dual certificates, the collaborative signature client first establishes a channel with the backend using a pre-configured certificate and password to verify the legitimacy of the business layer's identity. The centralized storage module, in conjunction with the business server, saves the identity verification results. After the collaborative signature client and the collaborative signature server complete a secondary identity verification, the collaborative signature server forwards the certificate request sent by the collaborative signature client to the certificate issuing server. Finally, the collaborative signature client obtains the SM dual certificate and SSL encryption private key issued by the certificate issuing server, and then completes the collaborative signature SSL channel that meets the requirements using the private dual certificate.
3. The method for applying to a transaction access path adaptive system as described in claim 1, characterized in that, The GMSSL access server only needs to open one network port. The collaborative signature client is packaged with a pre-installed 5-year SSL dual certificate. Through the pre-installed SSL dual certificate password channel, the initial business layer identity verification and the issuance of the SM2 national cryptographic private dual certificate are completed. Business queries and transactions are completed through the GMSSL private dual certificate collaborative signature channel, saving network port resources and reducing network risks.
4. The method for an adaptive transaction access path system as described in claim 3, characterized in that, The collaborative signature client actively detects the status of centralized storage through the SSL dual-certificate collaborative signature channel. In the event of an abnormality in centralized storage, the collaborative signature client automatically switches to the password channel with the SSL pre-set dual certificates to complete business queries and transactions. No manual emergency switching or operation is required on the server side, and no manual monitoring or switching operation is required. Compared with the manual discovery and operation of ordinary solutions, the efficiency of emergency response is improved.
5. The method for applying to a transaction access path adaptive system as described in claim 4, characterized in that, If the certificate issuing server malfunctions, resulting in certificate issuance failure, the collaborative signature client will automatically use the current password channel as an emergency channel to continue completing business queries and transactions.
6. The method for applying to a transaction access path adaptive system as described in claim 5, characterized in that, It also includes emergency procedures for centralized storage module failures and certificate issuance server failures.
7. The method for applying to a transaction access path adaptive system as described in claim 6, characterized in that, The centralized storage failures are categorized into two types: loss of the collaborative signature public key and abnormality of the centralized storage network port. The emergency procedure for handling lost collaborative signature public keys is as follows: The centralized storage system contains the collaborative signature public key data required for collaborative signature login by the collaborative signature client. Data between the master and slave of the centralized storage is automatically synchronized in real time. In extreme scenarios where the collaborative signature public key data is lost, the collaborative signature client will automatically re-run the SSL private dual certificate application process. The emergency procedure for handling abnormal centralized storage network ports is as follows: If a network port anomaly occurs, the centralized storage adopts a master-slave deployment mode. In the event of a complete system outage in an extreme scenario, the collaborative signature client directly switches to the SSL pre-built dual-certificate password channel to ensure business continuity.
8. The method for applying to a transaction access path adaptive system as described in claim 7, characterized in that, The emergency procedure for certificate issuance server failure is as follows: As an SSL dual certificate issuance service, the certificate issuance server itself achieves high availability by attaching multiple IP addresses after the domain name. In extreme cases where multiple IP addresses become unavailable, the collaborative signing client will automatically switch to the SSL pre-built dual certificate password channel to ensure business continuity.
9. A system employing the transaction access path adaptive method according to any one of claims 1-8, characterized in that, The system includes: A collaborative signature client used to initiate user authentication information and certificate requests; The collaborative signature server is used to receive and process information from the collaborative signature client, and to send certificate requests to the certificate issuing server. The business server is used to receive and process information from the collaborative signature server and send receipt verification information to the client. The centralized storage module is used to store authentication results, co-signing public keys, terminal identification information, and certificate-related information, and performs secondary verification on the information; The certificate issuing server is used to respond to certificate requests from the collaborative signature server.
Citation Information
Patent Citations
Mobile electronic signature-based trusteeship key use method and system, computer equipment and storage medium
CN113271207A
Identity verification and application access control method and system based on multi-system interaction
CN117792802A