Method, device, system and equipment for generating electronic certificate cancel-after-verification data
By generating and verifying dynamic passwords on the client, the problem of electronic credential verification dependent network and security risks is solved, and a high security and network-free verification process is achieved.
Patent Information
- Application Number
- CN202510111341.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, electronic credential verification has the problem of relying on the network or security risks.
The client sends an order request to the server, obtains the electronic voucher and its corresponding security key, encodes based on preset encoding rules, generates a dynamic password, and generates the verification data of the electronic voucher based on the initial data and the dynamic password. There is no network connection required on the verification end, and use the security key to verify the verification data to complete the verification.
The verification of electronic certificates that do not rely on the network is realized, which improves security. The verification data is not easy to be cracked or forged, and is suitable for more application scenarios.
Smart Images

Figure CN119995853A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a technology for generating electronic voucher verification data. Background Art
[0002] With the popularization of the Internet and the digital development and popularization of application scenarios, various electronic certificates generated, stored, transmitted and managed electronically usually exist in digital form, recording the economic activities of both parties to the transaction based on smart terminals and / or computer devices, and can effectively replace traditional paper certificates. When executing / realizing its functions or effects, electronic certificates need to be written off.
[0003] In the prior art, electronic voucher cancellation mainly includes the following situations:
[0004] 1. Online verification: During the verification process, the user end and the verification end need to be connected to the network, otherwise the verification cannot be successfully completed and it needs to rely on the network.
[0005] 2. Semi-online verification: During the verification process, the user end may not be connected to the Internet, but the verification end needs to be connected to the Internet. Although the dependence on the Internet is reduced, it is not completely independent of the Internet. Most of the existing offline payment scenarios of third-party payment are based on this situation.
[0006] 3. Offline verification: During the verification process, both the user end and the verification end may not be connected to the network, but the verification data can be easily cracked and forged, posing a security risk.
[0007] Therefore, how to provide an electronic voucher verification method that is independent of the network and has high security is an urgent problem that needs to be solved. Summary of the invention
[0008] The purpose of the present invention is to provide a method, device and equipment for generating electronic voucher verification data, so as to at least partially solve the technical problem in the prior art that electronic voucher verification exists dependence on the network or security risks.
[0009] According to one aspect of the present invention, a method for generating electronic voucher verification data is provided, which is applied to a client, wherein the method comprises:
[0010] Send an order request to the server;
[0011] Obtaining an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received order request;
[0012] Based on a preset encoding rule, the electronic certificate is encoded to obtain initial data, and based on the security key, the combined data consisting of the initial data and the timestamp is processed to obtain signature data, and a dynamic password is obtained according to the signature data;
[0013] The verification data corresponding to the electronic voucher is generated according to the initial data and the dynamic password.
[0014] Optionally, the security key is generated randomly.
[0015] Optionally, the obtaining of the electronic certificate sent by the server and its corresponding security key includes:
[0016] Receiving encrypted data sent by the server, wherein the encrypted data is obtained by the server using an asymmetric encryption algorithm to encrypt the electronic certificate and its corresponding security key;
[0017] The encrypted data is decrypted to obtain the electronic certificate and its corresponding security key.
[0018] Optionally, the processing of the combined data consisting of the initial data and the timestamp based on the security key to obtain the signature data includes:
[0019] The HMAC algorithm is adopted to sign the combined data consisting of the initial data and the timestamp through the security key to obtain the signature data.
[0020] Optionally, the HMAC algorithm includes an HMAC-SHA256 algorithm.
[0021] Optionally, obtaining a dynamic password according to the signature data includes:
[0022] Processing the signature data to obtain an initial dynamic password;
[0023] Modulus adjustment is performed on the initial dynamic password to obtain a dynamic password.
[0024] Optionally, the step of generating the verification data corresponding to the electronic voucher according to the initial data and the dynamic password includes:
[0025] Using the dynamic password to replace the corresponding data in the initial data to obtain updated data;
[0026] The update data is obfuscated to obtain the cancellation data corresponding to the electronic voucher.
[0027] Optionally, the method for generating electronic voucher write-off data further includes:
[0028] The verification data is converted into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
[0029] According to another aspect of the present invention, a method for generating electronic voucher verification data is provided, which is applied to a server, wherein the method comprises:
[0030] Receive order requests sent by users through the client;
[0031] Generate an electronic certificate and its corresponding security key according to the order request, and send the electronic certificate and its corresponding security key to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and a timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0032] A request sent by the verification end is received, and ordering data including a security key corresponding to the electronic certificate is sent to the verification end.
[0033] Optionally, the sending of the ordering data including the security key corresponding to the electronic certificate to the cancellation end includes:
[0034] Sending encrypted data to the verification end, wherein the encrypted data is obtained by using an asymmetric encryption algorithm to encrypt order data including a security key corresponding to the electronic certificate.
[0035] According to another aspect of the present invention, a method for generating electronic voucher write-off data is provided, which is applied to a write-off terminal, wherein the method comprises:
[0036] Send a request to the server;
[0037] Obtaining order data including a security key corresponding to the electronic certificate sent by the server;
[0038] When revoking an electronic voucher, obtaining revoking data corresponding to the electronic voucher in the client, wherein, at the client, based on a preset encoding rule, encoding the electronic voucher obtained from the server to obtain initial data, and based on the security key, processing the combined data consisting of the initial data and the timestamp to obtain signature data, and obtaining a dynamic password based on the signature data, and generating the revoking data corresponding to the electronic voucher based on the initial data and the dynamic password;
[0039] The security key is used to verify the cancellation data. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
[0040] Optionally, after the verification data corresponding to the electronic certificate is generated, the verification data is converted into a decimal string of a fixed length to generate a verification code corresponding to the electronic certificate.
[0041] Optionally, the step of obtaining the verification data corresponding to the electronic voucher in the client includes:
[0042] The scanning device of the cancellation terminal scans the cancellation code corresponding to the electronic certificate displayed by the client to obtain the cancellation data corresponding to the electronic certificate in the client.
[0043] According to another aspect of the present invention, there is provided a device for generating electronic voucher verification data, which is deployed on a client, wherein the device comprises:
[0044] The first module is used to send an order request to the server;
[0045] A second module is used to obtain the electronic certificate sent by the server and its corresponding security key, wherein the electronic certificate is generated by the server according to the received order request;
[0046] The third module is used to encode the electronic certificate based on a preset encoding rule to obtain initial data, and to process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and to obtain a dynamic password based on the signature data;
[0047] The fourth module is used to generate the cancellation data corresponding to the electronic voucher according to the initial data and the dynamic password.
[0048] Optionally, the device for generating electronic voucher verification data further includes:
[0049] The fifth module is used to convert the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
[0050] According to another aspect of the present invention, there is provided a device for generating electronic voucher verification data, which is deployed on a server side, wherein the device comprises:
[0051] The sixth module is used to receive an order request sent by a user through a client;
[0052] The seventh module is used to generate an electronic certificate and a corresponding security key according to the order request, and send the electronic certificate and the corresponding security key to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0053] The eighth module is used to receive a request sent by the verification end, and send order data including a security key corresponding to the electronic certificate to the verification end.
[0054] According to another aspect of the present invention, there is provided a device for generating electronic voucher cancellation data, which is deployed at a cancellation terminal, wherein the device comprises:
[0055] The ninth module is used to send a request to the server;
[0056] A tenth module is used to obtain the ordering data including the security key corresponding to the electronic certificate sent by the server;
[0057] An eleventh module is used for obtaining cancellation data corresponding to the electronic certificate in the client when canceling the electronic certificate, wherein the client encodes the electronic certificate obtained from the server based on a preset encoding rule to obtain initial data, and processes the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtains a dynamic password based on the signature data, and generates the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0058] The twelfth module is used to verify the cancellation data using the security key. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
[0059] According to another aspect of the present invention, a system for generating electronic voucher verification data is provided, wherein the system comprises:
[0060] The client is used to send a subscription request to a server, and obtain an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received subscription request, and the server encodes the electronic certificate based on a preset encoding rule to obtain initial data, and processes the combined data consisting of the initial data and a timestamp based on the security key to obtain signature data, and obtains a dynamic password based on the signature data, and generates verification data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0061] The server side is used to receive an order request sent by a user through a client side, generate an electronic certificate and its corresponding security key according to the order request, and send the electronic certificate and its corresponding security key to the client side, and receive a request sent by a cancellation side, and send order data including the security key corresponding to the electronic certificate to the cancellation side;
[0062] The verification end is used to send a request to the server and obtain the ordering data sent by the server including the security key corresponding to the electronic certificate. When the electronic certificate is verified, the verification data corresponding to the electronic certificate in the client is obtained, and the verification data is verified using the security key. If the verification is successful, the verification data corresponding to the electronic certificate is completed.
[0063] Compared with the prior art, the present invention provides a method, device, system and equipment for generating electronic certificate cancellation data, the method comprising: a client sends a subscription request to a server; obtains the electronic certificate and its corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received subscription request; based on a preset coding rule, encodes the electronic certificate to obtain initial data, and based on the security key, processes the combined data consisting of the initial data and the timestamp to obtain signature data, and obtains a dynamic password according to the signature data; generates cancellation data corresponding to the electronic certificate according to the initial data and the dynamic password. The server also receives a request sent by the cancellation end, and sends subscription data including the security key corresponding to the electronic certificate to the cancellation end; the cancellation end obtains the subscription data including the security key corresponding to the electronic certificate sent by the server; when canceling the electronic certificate, obtains the cancellation data corresponding to the electronic certificate in the client, uses the security key to verify the cancellation data, and if the verification passes, completes the cancellation of the cancellation data corresponding to the electronic certificate. The method for generating electronic voucher write-off data of the present invention uses a security key to generate a dynamic password for an electronic voucher, and obtains electronic voucher write-off data that is not easy to be cracked or forged. When the write-off end writes off the electronic voucher, both the client and the write-off end do not need to be connected to the network, and verify the electronic voucher write-off data including the dynamic password to achieve write-off. The write-off data is not easy to be cracked or forged, and has high security. In the write-off process, both the write-off parties (the client and the write-off end) do not need to rely on the network, and can be applied to more application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Other features, objects and advantages of the present invention will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings:
[0065] Figure 1 A schematic flow chart of a method for generating electronic voucher write-off data applied to a client according to one aspect of the present invention is shown;
[0066] Figure 2 A schematic flow chart of a method for generating electronic voucher write-off data applied to a server according to another aspect of the present invention is shown;
[0067] Figure 3 A schematic flow chart of a method for generating electronic voucher write-off data applied to a write-off terminal according to another aspect of the present invention is shown;
[0068] Figure 4 A schematic diagram showing a method for generating electronic voucher write-off data according to an embodiment of the present invention;
[0069] Figure 5 A schematic diagram showing a device for generating electronic voucher verification data deployed on a client according to another aspect of the present invention;
[0070] Figure 6 A schematic diagram of a device for generating electronic voucher verification data deployed on a server side according to another aspect of the present invention is shown;
[0071] Figure 7 A schematic diagram showing a device for generating electronic voucher cancellation data deployed at a cancellation terminal according to another aspect of the present invention;
[0072] Figure 8 A schematic diagram of a system for generating electronic voucher verification data according to another aspect of the present invention is shown;
[0073] The same or similar reference numerals in the drawings represent the same or similar components. DETAILED DESCRIPTION
[0074] The present invention is further described in detail below in conjunction with the accompanying drawings.
[0075] In a typical configuration of each embodiment of the present invention, the execution subject of the method, each trusted party of the system and / or each module of the device includes one or more processors (CPU), input / output interface, network interface and memory.
[0076] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0077] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include non-transitory media such as modulated data signals and carrier waves.
[0078] In the existing electronic voucher verification process, in order to ensure security, both the user end and the verification end are usually required to be connected to the network, or at least the verification end must be connected to the network, and real-time data interaction with the backend server is required during the verification process. In the offline scenario, either the verification cannot be completed, or although the method adopted can complete the verification, the electronic voucher verification data is easy to be cracked and forged, which poses a security risk.
[0079] The present invention provides a method for generating electronic certificate verification data. When a client obtains an electronic certificate from a server, it also obtains a security key corresponding to the electronic certificate, and then processes the electronic certificate and the security key to generate a dynamic password, and reproduces the electronic certificate verification data including the electronic certificate and the dynamic password. The verification end also obtains the security key from the server. When the electronic certificate is to be verified, there is no need to rely on the network. The verification end obtains the electronic certificate verification data from the client, and verifies the electronic certificate verification data according to the obtained security key. If the verification is successful, the electronic certificate verification is completed.
[0080] In order to further illustrate the technical means adopted by the present invention and the effects achieved, the technical scheme of the present invention is clearly and completely described below in conjunction with the accompanying drawings and various embodiments.
[0081] Figure 1 A schematic diagram of a method for generating electronic voucher verification data applied to a client according to one aspect of the present invention is shown, wherein the method of one embodiment includes:
[0082] S101 sends an order request to the server;
[0083] S102: obtaining the electronic certificate and the corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received order request;
[0084] S103: encoding the electronic certificate based on a preset encoding rule to obtain initial data, and processing the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtaining a dynamic password based on the signature data;
[0085] S104 generates cancellation data corresponding to the electronic voucher according to the initial data and the dynamic password.
[0086] The method of this embodiment is implemented by the client 100 of the system that provides electronic voucher services (such as online ticket booking for shared buses, performances, etc.). The electronic voucher service system generally includes a client (app, applet, PC client, etc.) 100, a server 200, and a verification terminal 300. The client 100 is usually installed and run on the user's smart terminal or computer device, the server 200 is usually a computer device with necessary software and hardware environment installed, and the verification terminal 300 is usually a terminal device or computer device with necessary software and hardware installed. Among them, the smart terminal includes but is not limited to smart phones, PADs, and smart wearable devices. The computer device includes but is not limited to personal computers, laptops, industrial computers, servers, network hosts, single network servers or network server clusters. Here, the smart terminal and the computer device are only examples. Other existing or future devices and / or resource platforms that may appear should also be included in the scope of protection of the present invention if they are applicable to the present invention. Here, they are included here by reference.
[0087] In this embodiment, in step S101 , the client 100 may send a subscription request to a server of the server 200 .
[0088] Among them, when the user has an online ordering or purchasing demand, for example, online ordering or purchasing shared bus tickets, movie tickets, performance tickets, etc., the user can send an order request to the server of the server end 200 of the electronic certificate service system through the client 100 of the corresponding electronic certificate service system (or online ticketing system), wherein the order request at least includes a user identifier (for example: user account information or other information that uniquely identifies the user) and specific order information.
[0089] Continuing with this embodiment, in step S102, the client 100 may obtain the electronic certificate and its corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received order request and includes at least a user identification, successful order information, etc.
[0090] When the server of the server end 200 of the electronic certificate service system receives and successfully processes the above order request, it will generate an electronic certificate corresponding to the order request, and the server will also generate a security key corresponding to the electronic certificate.
[0091] Optionally, the security key is generated randomly.
[0092] The security key corresponding to the electronic certificate can be an unordered string with a certain encoding format generated by a random function. For example, Base64 is used to encode the randomly generated data of a preset length of bytes to obtain an unordered string as the security key corresponding to the electronic certificate. The same security key can correspond to only one electronic certificate, or to the same user, or to the same batch (for example, the same bus trip, the same movie or performance, etc.), which can be determined according to the actual application scenario and the level of security requirements.
[0093] Optionally, in step S102, obtaining the electronic certificate sent by the server and its corresponding security key includes:
[0094] Receiving encrypted data sent by the server, wherein the encrypted data is obtained by the server using an asymmetric encryption algorithm to encrypt the electronic certificate and its corresponding security key;
[0095] The encrypted data is decrypted to obtain the electronic certificate and its corresponding security key.
[0096] In order to improve the security of data communication between the client 100 and the server 200, before sending the electronic certificate and its corresponding security key to the client 100, the server 200 may first use an asymmetric encryption algorithm (such as RSA encryption algorithm, national secret SM2 algorithm, etc.) and a public key corresponding to the client 100 to encrypt the electronic certificate and its corresponding security key, and then send the encrypted data to the client 100. After receiving the encrypted data, the client 100 uses the corresponding private key to decrypt the encrypted data to obtain the electronic certificate and its corresponding security key.
[0097] Continuing with this embodiment, in step S103, the client 100 may encode the electronic certificate based on a preset encoding rule to obtain initial data, and based on the security key, process the combined data consisting of the initial data and the timestamp to obtain signature data, and obtain a dynamic password based on the signature data.
[0098] Among them, after receiving the electronic certificate and its corresponding security key, the client 100 can encode the electronic certificate according to the preset encoding rules to obtain the initial data, and use the security key corresponding to the electronic certificate to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain the signature data, so that the signature data has timeliness, and also process the signature data to obtain the dynamic password, so that the dynamic password has timeliness, and the expiration period of the dynamic password can be set based on the local timestamp, such as the expiration period is set to 30 seconds, which can improve security. Among them, the preset encoding rules should ensure that the data is secure enough and concise enough to meet the requirements of various scenarios and devices. For example, the data carrying capacity of the barcode is extremely limited. In an example, in the preset encoding rules, a 64-bit long integer can be used to encode the data, including reserved bits, data bits, random bits and dynamic password bits. The 64 bits can be divided according to the actual application scenario requirements and security requirements, such as 1 bit reserved bits, 38 bit data bits, 9 bit random bits and 16 bit dynamic password bits. Among them, the reserved bit can be used as a sign bit; the data bit can be further divided in combination with the user and / or device type. For example, the 38-bit data bit can be further divided into a 32-bit first data bit and a 6-bit second data bit, wherein the 32-bit first data bit can cover 4294967296 devices or users, and the 6-bit second data bit can cover 64 types / identities (the second data bit can be used to identify different types / identities of the same user, such as bank cards, electronic certificates in different ordering scenarios, etc.); 9-bit random bits can generate 512 random numbers; 16-bit dynamic password bits can generate 65536 dynamic passwords. In actual application scenarios, if the user volume is not too large, but higher security is required, the data bits can be reduced and the random bits and password bits can be increased.
[0099] Optionally, in step S103, the processing of the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data includes:
[0100] The HMAC algorithm is adopted to sign the combined data consisting of the initial data and the timestamp through the security key to obtain the signature data.
[0101] Among them, the HMAC (Hash-based Message Authentication Code) algorithm can be used to obtain the signature data, wherein an appropriate hash function is selected, and the security key corresponding to the electronic certificate is used to fill in the combined data consisting of the initial data and the local timestamp of the client 100, and an internal key is generated based on the security key, and then the internal key is used to hash the combined data, and the hash result and the internal key can be hashed again to obtain the signature data.
[0102] Optionally, the HMAC algorithm includes an HMAC-SHA256 algorithm.
[0103] Among them, the HMAC algorithm can usually use the HMAC-SHA1 algorithm. In order to enhance security and randomness, the HMAC algorithm can use the HMAC-SHA256 algorithm.
[0104] Optionally, in step S103, obtaining a dynamic password according to the signature data includes:
[0105] Processing the signature data to obtain an initial dynamic password;
[0106] Modulus adjustment is performed on the initial dynamic password to obtain a dynamic password.
[0107] Among them, the client 100 can process the signature data obtained in step S103 to obtain an initial dynamic password. In order to adapt to the preset coding rules, the initial dynamic password can also be adjusted modulus to obtain a dynamic password that can match the coding rules for subsequent electronic certificate verification data generation.
[0108] Continuing with this embodiment, in step S104, the client 100 may generate verification data corresponding to the electronic voucher according to the initial data and the dynamic password.
[0109] The client 100 may process the above initial data and the obtained dynamic password in combination with preset coding rules to generate verification data corresponding to the electronic voucher.
[0110] Optionally, step S104 includes:
[0111] Using the dynamic password to replace the corresponding data in the initial data to obtain updated data;
[0112] The update data is obfuscated to obtain the cancellation data corresponding to the electronic voucher.
[0113] Among them, the client 100 can replace the original filling data of the corresponding dynamic password position in the initial data with the dynamic password to obtain updated data, and then perform obfuscation processing on the updated data to obtain the verification data corresponding to the electronic certificate.
[0114] Continuing with the above example, a 64-bit long integer is used to encode the data. After obtaining the electronic certificate and its corresponding security key, the client 100 first uses the electronic certificate as data and performs encoding processing to obtain initial data (including several 64-bit data segments, each of which includes a reserved bit, a data bit, a random bit, and a dynamic password bit, wherein the dynamic password bit is 16 bits, and the initial value of each bit of the dynamic password bit is 0). Then, based on the security key corresponding to the electronic certificate, the combined data consisting of the initial data and the local timestamp of the client 100 is processed to obtain signature data, wherein the local timestamp can be updated based on a preset expiration period, so that the obtained signature data is time-effective. For example, the HMAC-SHA256 algorithm can be used, and the security key corresponding to the electronic certificate can be used to process the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data. The signature data is then processed. For example, a number of bits (for example, 4 bits) of data at a specified position of the signature data can be read to determine the offset. Then, starting from the first byte of the signature data, a preset number of bytes of data are taken to obtain an integer data as the initial dynamic password. The initial dynamic password is then modulo-adjusted to obtain a 16-bit dynamic password. The dynamic password bits in the initial data are then replaced with the dynamic password, and the replaced data is used as the verification data corresponding to the electronic certificate. The obtained verification data is not easy to copy or forge, and has high security. In order to further improve the security of the verification data, the replaced data can also be obfuscated. For example, each field can be XOR-ed, and the XOR-ed data can be used as the verification data corresponding to the electronic certificate.
[0115] Through the above-mentioned embodiments and / or optional embodiments, verification data including a dynamic password with time validity may be generated at the client 100 of the electronic certificate service system.
[0116] Optionally, the method for generating electronic voucher write-off data further includes:
[0117] S105 converts the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
[0118] Among them, after steps S101 to S104, the client 100 can generate verification data corresponding to the electronic certificate. In order to facilitate the verification operation, in an optional embodiment, in step S105, the client 100 can also convert the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic certificate, wherein the verification code can be a barcode or a QR code.
[0119] Figure 2 A schematic diagram of a method for generating electronic voucher verification data applied to a server according to another aspect of the present invention is shown, wherein the method of an embodiment includes:
[0120] S201 receives an order request sent by a user through a client;
[0121] S202: Generate an electronic certificate and a security key corresponding to the electronic certificate according to the order request, and send the electronic certificate and the security key corresponding to the electronic certificate to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0122] S203 receives the request sent by the cancellation end, and sends the ordering data including the security key corresponding to the electronic certificate to the cancellation end.
[0123] The method of this embodiment is implemented by the server side 200 of the system for providing electronic certificate services.
[0124] In this embodiment, in step S201, the server of the server end 200 may receive an order request sent by the user through the client end 100 of the electronic certificate service system. When the user has an online order or purchase demand, the user may send an order request to the server of the server end 200 of the electronic certificate service system through the client end 100, wherein the order request at least includes a user identifier and specific order information.
[0125] Continuing with this embodiment, in step S202, the server may generate a corresponding electronic certificate and a security key corresponding to the electronic certificate based on the order request after successfully processing the order request, and send the electronic certificate and its corresponding security key to the corresponding user's client 100, so that the user's client 100 can encode the electronic certificate obtained from the server of the server end 200 according to a preset encoding rule to obtain initial data, and use the security key corresponding to the electronic certificate obtained from the server to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data, and also process the signature data to obtain a dynamic password, and process the above-mentioned initial data and the obtained dynamic password to generate verification data corresponding to the electronic certificate.
[0126] Continuing with this embodiment, in step S203, the server may receive a request sent by the cancellation terminal 300 of the electronic certificate service system, and send order data including a security key corresponding to the electronic certificate to the cancellation terminal 300.
[0127] Among them, the cancellation terminal 300 can send a request to the server of the server end 200 to obtain relevant ordering data, wherein the ordering data can be an electronic certificate of a single user (for example, a certain class ticket information of a shared bus purchased by a user, one or more movie tickets / performance tickets purchased by a user, etc.) or an electronic certificate corresponding to a batch of users (for example, a certain bus of a shared bus that has been sold on that day or on that shift, a movie ticket / performance ticket sold on that day or on that show of a cinema / performance venue, etc.), and the server will send the ordering data including the security key corresponding to the electronic certificate to the cancellation terminal 300. So that when performing the cancellation operation, the cancellation terminal 300 does not need to be connected to the network, and the security key can be used to verify the cancellation data of the obtained electronic certificate, and determine whether the cancellation is successful based on the verification result. Among them, the security key corresponding to the electronic certificate can be an unordered string with a certain encoding format generated by a random function, for example, using Base64 to encode the randomly generated data of a preset length of bytes to obtain an unordered string as the security key corresponding to the electronic certificate. The same security key may correspond to only one electronic certificate, or may correspond to the same user, or to the same batch (e.g., the same bus trip, the same movie or show, etc.), which may be determined based on the actual application scenario and the level of security requirements. The security key corresponding to the electronic certificate sent by the server to the verification terminal 300 is the same as the security key corresponding to the same electronic certificate sent to the client 100.
[0128] Optionally, in step S203, sending the ordering data including the security key corresponding to the electronic certificate to the verification end includes:
[0129] Sending encrypted data to the verification end, wherein the encrypted data is obtained by using an asymmetric encryption algorithm to encrypt order data including a security key corresponding to the electronic certificate.
[0130] In order to improve the security of data communication between the verification end 300 and the server end 200, before sending the subscription data including the security key corresponding to the electronic certificate to the verification end 300, the server of the server end 200 may first encrypt the subscription data including the security key corresponding to the electronic certificate using the public key corresponding to the verification end 300 using an asymmetric encryption algorithm, and then send the encrypted data to the verification end 300. After receiving the encrypted data, the verification end 300 uses the corresponding private key to decrypt the encrypted data to obtain the subscription data including the security key corresponding to the electronic certificate.
[0131] Figure 3 A schematic diagram of a method for generating electronic voucher write-off data applied to a write-off terminal according to another aspect of the present invention is shown, wherein the method of one embodiment includes:
[0132] S301 sends a request to the server;
[0133] S302 obtains the ordering data including the security key corresponding to the electronic certificate sent by the server;
[0134] S303: when revoking an electronic voucher, obtaining revoking data corresponding to the electronic voucher in the client, wherein, at the client, based on a preset encoding rule, encoding the electronic voucher obtained from the server to obtain initial data, and based on the security key, processing the combined data consisting of the initial data and the timestamp to obtain signature data, and obtaining a dynamic password based on the signature data, and generating the revoking data corresponding to the electronic voucher based on the initial data and the dynamic password;
[0135] S304 uses the security key to verify the cancellation data. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
[0136] The method of this embodiment is implemented by the verification terminal 300 of the system providing electronic certificate services.
[0137] In this embodiment, in step S301, the revocation end 300 of the electronic certificate service system may send a request to the server of the server end 200 to obtain order data including a security key corresponding to the electronic certificate.
[0138] Continuing in this embodiment, in step S302, the verification end 300 obtains the order data including the security key corresponding to the electronic certificate from the service end 200. The order data can be the electronic certificate of a single user (for example, the ticket information of a certain bus trip purchased by the user, one or more movie tickets / performance tickets purchased by the user, etc.) or the electronic certificate corresponding to a batch of users (for example, the ticket information of a certain bus of the shared bus that has been sold on that day or on that day, the ticket information of the movie ticket / performance ticket sold on that day or on that day of the cinema / performance venue, etc.).
[0139] Continuing with this embodiment, in step S303, when the electronic certificate is to be revoked, the revocation terminal 300 does not need to be connected to the network, and the revocation terminal 300 can obtain the revocation data corresponding to the electronic certificate from the relevant client 100, wherein, at the relevant client 100, the electronic certificate obtained from the server of the server end 200 can be encoded according to a preset encoding rule to obtain initial data, and the security key corresponding to the electronic certificate obtained from the server is used to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data, and the signature data is also processed to obtain a dynamic password, and the above-mentioned initial data and the obtained dynamic password are processed to generate the revocation data corresponding to the electronic certificate.
[0140] Optionally, in step S303, after the client generates the verification data corresponding to the electronic certificate, the verification data is converted into a decimal string of fixed length to generate a verification code corresponding to the electronic certificate.
[0141] Among them, in order to reduce the data volume, adapt to more verification methods and verification hardware and software requirements, and facilitate verification operations, the client 100 can also convert the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic certificate, wherein the verification code can be a barcode or a QR code.
[0142] Continuing with this embodiment, in step S304, the cancellation terminal 300 may use the security key corresponding to the electronic certificate to verify the obtained cancellation data corresponding to the electronic certificate. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
[0143] Optionally, if the client can display the verification code corresponding to the electronic certificate, then in step S304, the verification code corresponding to the electronic certificate displayed by the client 100 is scanned by the scanning device of the verification terminal 300 to obtain the verification data corresponding to the electronic certificate in the client 100.
[0144] The methods of the above embodiments and / or optional embodiments are as follows Figure 4As shown, the user initiates an order request online through the client 100 to the server 200 according to the demand; after successful processing, the server 200 will generate a corresponding electronic certificate and a security key corresponding to the electronic certificate, and send the electronic certificate and its corresponding security key to the client 100; after receiving the electronic certificate and its corresponding security key, the client 100 processes the electronic certificate according to the preset encoding rules to obtain the initial data, and uses the security key to process the combined data of the initial data and the local timestamp to obtain the signature data, and then processes the signature data to obtain the dynamic password, and then determines the core code corresponding to the electronic certificate according to the initial data and the dynamic password. The cancellation data obtained is not easy to be cracked or forged, and has high security; the cancellation terminal 300 will send a request to the server 200. After successful processing, the server 200 will generate ordering data including the security key corresponding to the electronic certificate and send it to the cancellation terminal 300; after receiving the ordering data, the cancellation terminal 300 no longer needs to be connected to the network, and can perform electronic certificate cancellation in an environment without a network or a weak network. When the electronic certificate is cancelled, the cancellation terminal 300 obtains the cancellation data corresponding to the electronic certificate from the client 100, and uses the security key corresponding to the electronic certificate obtained from the server 200 for verification. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is successfully completed. During the cancellation process, the cancellation terminal 300 can successfully complete the cancellation of the electronic certificate without connecting to the network, which greatly reduces the cancellation conditions and can be applied to more application scenarios (for example, cancellation in remote locations such as tunnels where there is no network or weak network signals).
[0145] Continuing with the above example, the verification terminal 300 can obtain the verification data of the electronic certificate from the client 100 by scanning a code or other means. If the client 100 has performed an obfuscation process, the verification terminal 300 first performs a reverse obfuscation process on the verification data of the obtained electronic certificate, and then performs a decoding process according to the same encoding rules, and extracts the electronic certificate and the dynamic signature (assuming it is a dynamic password one) therefrom; the extracted electronic certificate is then used as data for encoding processing to obtain initial data, and then the security key corresponding to the electronic certificate obtained from the server 200 is used, based on the same algorithm as the client 100, to process the combined data of the initial data and the local timestamp of the verification terminal 300 to obtain the signature data, wherein the local timestamp can also be updated based on the preset expiration period, so that the obtained signature data is timely, thereby ensuring the timeliness of the verification process. The signature data is then processed to obtain a new dynamic password (assuming it is dynamic password 2). For example, the last 4 bits of the signature data can be read to determine the offset, and then 4 consecutive bytes of data are taken from the offset position of the signature data to obtain a long integer data as the initial dynamic password; then the initial dynamic password is modulo adjusted to obtain a 16-bit dynamic password 2. Then verify whether the dynamic password 2 is the same as the dynamic password 1. If they are the same, the verification is passed, and the cancellation of the cancellation data corresponding to the electronic certificate is successfully completed.
[0146] Figure 5 A device for generating electronic voucher verification data deployed on a client according to another aspect of the present invention is shown, wherein the device in one embodiment includes:
[0147] The first module 510 is used to send a subscription request to a server;
[0148] A second module 520 is configured to obtain an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received order request;
[0149] The third module 530 is used to encode the electronic certificate based on a preset encoding rule to obtain initial data, and to process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and to obtain a dynamic password based on the signature data;
[0150] The fourth module 540 is used to generate the cancellation data corresponding to the electronic voucher according to the initial data and the dynamic password.
[0151] The device of this embodiment is integrated in the client 100 .
[0152] In this embodiment, through the first module 510 of the device, an order request can be sent to the server of the server end 200. When a user has an online order or purchase demand, such as online ordering or purchasing shared bus tickets, movie tickets, performance tickets, etc., the user can send an order request to the server of the server end 200 of the electronic voucher service system through the first module 510 of the device integrated in the client 100 of the corresponding electronic voucher service system (or online ticketing system), wherein the order request at least includes a user identifier (e.g., user account information or other information that uniquely identifies the user) and specific order information.
[0153] When the server of the server end 200 of the electronic certificate service system receives and successfully processes the above order request, it will generate an electronic certificate corresponding to the order request, and the server will also generate a security key corresponding to the electronic certificate.
[0154] Continuing with this embodiment, the electronic certificate sent by the server and its corresponding security key can be obtained through the second module 520 of the device, wherein the electronic certificate is generated by the server according to the received order request and includes at least a user identification, successful order information, etc.
[0155] Continuing in this embodiment, the third module 530 of the device can encode the electronic certificate based on the preset encoding rules to obtain initial data, and based on the security key, process the combined data consisting of the initial data and the timestamp to obtain signature data, and obtain the dynamic password according to the signature data. After the electronic certificate and its corresponding security key are received by the second module 520 of the device, the third module 530 of the device can encode the electronic certificate according to the preset encoding rules to obtain initial data, and use the security key corresponding to the electronic certificate to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data, so that the signature data has time validity, and also process the signature data to obtain the dynamic password, so that the dynamic password has time validity, and the expiration period of the dynamic password can be set based on the local timestamp, such as the expiration period is set to 30 seconds, which can improve security. The preset encoding rules should ensure that the data is sufficiently secure and concise to meet the requirements of various scenarios and devices, such as the data carrying capacity of the barcode is extremely limited.
[0156] Continuing with this embodiment, through the fourth module 540 of the device, the cancellation data corresponding to the electronic certificate can be generated according to the initial data and the dynamic password.
[0157] Optionally, the device further comprises:
[0158] The fifth module 550 is used to convert the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
[0159] Through the first module 510 to the fourth module 540 of the device, verification data corresponding to the electronic certificate can be generated. In order to facilitate the verification operation, the fifth module 550 of the device can also be used to convert the verification data into a decimal string of a fixed length to generate a verification code corresponding to the electronic certificate, wherein the verification code can be a barcode or a QR code.
[0160] Figure 6 A device for generating electronic voucher verification data deployed on a server side according to another aspect of the present invention is shown, wherein the device of one embodiment includes:
[0161] The sixth module 610 is used to receive an order request sent by a user through a client;
[0162] The seventh module 620 is used to generate an electronic certificate and a corresponding security key according to the order request, and send the electronic certificate and the corresponding security key to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0163] The eighth module 630 is used to receive a request sent by the cancellation end, and send order data including a security key corresponding to the electronic certificate to the cancellation end.
[0164] The device of this embodiment is integrated into the server of the server end 200 .
[0165] In this embodiment, the sixth module 610 of the device can receive an order request sent by the user through the client 100 of the electronic certificate service system. When the user has an online order or purchase demand, the user can send an order request to the server of the server end 200 of the electronic certificate service system through the client 100, wherein the order request at least includes a user identifier and specific order information.
[0166] Continuing with this embodiment, through the seventh module 620 of the device, according to the order request, after successfully processing the order request, a corresponding electronic certificate and a security key corresponding to the electronic certificate can be generated, and the electronic certificate and its corresponding security key can be sent to the corresponding user's client 100, so that on the user's client 100, the electronic certificate obtained from the server of the server end 200 can be encoded according to a preset encoding rule to obtain initial data, and the security key corresponding to the electronic certificate obtained from the server is used to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data, and the signature data is also processed to obtain a dynamic password, and the above-mentioned initial data and the obtained dynamic password are processed to generate verification data corresponding to the electronic certificate.
[0167] The cancellation terminal 300 of the electronic certificate service system can send a request to the server of the server terminal 200 to obtain relevant ordering data. Continuing in this embodiment, the eighth module 630 of the device can receive the request sent by the cancellation terminal 300 and send ordering data including the security key corresponding to the electronic certificate to the cancellation terminal 300.
[0168] Figure 7 A device for generating electronic voucher cancellation data deployed at a cancellation terminal according to another aspect of the present invention is shown, wherein the device in one embodiment includes:
[0169] The ninth module 710 is used to send a request to the server;
[0170] A tenth module 720 is used to obtain the ordering data including the security key corresponding to the electronic certificate sent by the server;
[0171] The eleventh module 730 is used to obtain the cancellation data corresponding to the electronic certificate in the client when canceling the electronic certificate, wherein the client encodes the electronic certificate obtained from the server based on a preset encoding rule to obtain initial data, and processes the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtains a dynamic password based on the signature data, and generates the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password;
[0172] The twelfth module 740 is used to verify the cancellation data using the security key. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
[0173] The device of this embodiment is integrated in the verification and cancellation terminal 200 .
[0174] In this embodiment, through the ninth module 710 of the device, a request can be sent to the server of the server end 200 to obtain the ordering data including the security key corresponding to the electronic certificate.
[0175] Continuing with this embodiment, through the tenth module 720 of the device, the ordering data including the security key corresponding to the electronic certificate can be obtained from the service end 200.
[0176] Continuing with this embodiment, when an electronic certificate is to be revoked, the revocation terminal 300 does not need to be connected to the network, and the revocation data corresponding to the electronic certificate can be obtained from the relevant client 100 through the eleventh module 730 of the device, wherein, at the relevant client 100, the electronic certificate obtained from the server of the server end 200 can be encoded according to a preset encoding rule to obtain initial data, and the security key corresponding to the electronic certificate obtained from the server is used to sign the combined data consisting of the initial data and the local timestamp of the client 100 to obtain signature data, and the signature data is also processed to obtain a dynamic password, and the above-mentioned initial data and the obtained dynamic password are processed to generate the revocation data corresponding to the electronic certificate.
[0177] Continuing with this embodiment, through the twelfth module 740 of the device, the security key corresponding to the electronic certificate can be used to verify the verification data corresponding to the electronic certificate. If the verification is successful, the verification data corresponding to the electronic certificate is completed.
[0178] Figure 8 A system for generating electronic voucher verification data according to another aspect of the present invention is shown, wherein the system of one embodiment includes:
[0179] The client 100 is used to send a subscription request to a server of the server end 200, and obtain an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received subscription request, and the electronic certificate is encoded based on a preset encoding rule to obtain initial data, and the combined data consisting of the initial data and a timestamp is processed based on the security key to obtain signature data, and a dynamic password is obtained based on the signature data, and the cancellation data corresponding to the electronic certificate is generated based on the initial data and the dynamic password;
[0180] The server end 200 is used to receive an order request sent by a user through the client end 100, generate an electronic certificate and its corresponding security key according to the order request, and send the electronic certificate and its corresponding security key to the client end 100, and receive a request sent by the cancellation end 300, and send order data including the security key corresponding to the electronic certificate to the cancellation end 300;
[0181] The verification terminal 300 is used to send a request to the server of the server end 200, and obtain the ordering data sent by the server including the security key corresponding to the electronic certificate. When the electronic certificate is verified, the verification data corresponding to the electronic certificate in the client 100 is obtained, and the verification data is verified using the security key. If the verification is successful, the verification data corresponding to the electronic certificate is completed.
[0182] In this embodiment, the system (or electronic certificate service system) may include a client 100, a server 200 and a verification terminal 300. First, when a user has an online order or purchase demand, the user may send an order request to the server of the server 200 through the client 100 of the system (or online ticketing system), wherein the order request at least includes a user identifier (e.g., user account information or other information that uniquely identifies the user) and specific order information. After successfully processing the order request, the server will generate a corresponding electronic certificate, and will also generate a security key corresponding to the electronic certificate, and send the electronic certificate and its corresponding security key to the client 100, wherein the electronic certificate at least includes the user identifier, successful order information, etc. After receiving the electronic certificate and its corresponding security key, the client 100 processes the electronic certificate according to the preset encoding rules to obtain initial data, and uses the security key to process the combined data of the initial data and the local timestamp to obtain signature data, and then processes the signature data to obtain a dynamic password, and then determines the verification data corresponding to the electronic certificate according to the initial data and the dynamic password, and the verification data obtained is not easy to be cracked or forged, and has high security. At the appropriate time, the verification end 300 will send a request to the server of the server end 200. After successful processing, the server will generate order data including the security key corresponding to the electronic certificate and send it to the verification end 300. After the verification end 300 receives the order data, if the order data does not need to be updated, there is no need to connect to the network again, and the electronic certificate can be verified in an environment without a network or a weak network.
[0183] When the electronic certificate is cancelled, the cancellation terminal 300 obtains the cancellation data corresponding to the electronic certificate from the client 100, and uses the security key corresponding to the electronic certificate obtained from the server 200 for verification. If the verification is successful, the cancellation data corresponding to the electronic certificate is cancelled. During the cancellation process, the cancellation terminal 300 can successfully complete the cancellation of the electronic certificate without connecting to the network, which greatly reduces the cancellation conditions and can be applied to more application scenarios.
[0184] In the various embodiments and / or optional embodiments of the above-mentioned system, the matters not mentioned in the method steps executed by each module are the same as those of the aforementioned related method embodiments and / or optional embodiments, and will not be repeated here.
[0185] According to yet another aspect of the present invention, a computer-readable medium is provided, wherein the computer-readable medium stores computer-readable instructions, and the computer-readable instructions can be executed by a processor to implement part or all of the above method.
[0186] It should be noted that each method embodiment and / or optional embodiment of the present invention may be partially or completely implemented in software and / or a combination of software and hardware. The software program involved in the present invention may be executed by a processor to implement some or all of the steps or functions of the above-mentioned embodiments and / or optional embodiments. Similarly, the software program of the present invention (including related data structures) may be stored in a computer-readable recording medium.
[0187] In addition, a part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide part or all of the method and / or technical solution according to the present invention through the operation of the computer. The program instruction for calling the method of the present invention may be stored in a fixed or removable recording medium, and / or transmitted through a data stream in a broadcast or other signal-bearing medium, and / or stored in a working memory of a computer device that runs according to the program instruction.
[0188] According to another aspect of the present invention, a device for generating electronic voucher verification data is provided, wherein the device comprises: a memory for storing computer program instructions and a processor for executing the program instructions, wherein when the computer program instructions are executed by the processor, the device is triggered to execute part or all of the methods and / or technical solutions of the aforementioned embodiments and / or optional embodiments.
[0189] It is obvious to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments and / or optional embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential features of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive, and the scope of the present invention is defined by the appended claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention. Any figure mark in the claims should not be regarded as limiting the claims involved. In addition, it is obvious that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the device claim can also be implemented by one unit or device through software and / or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.
Claims
1. A method for generating electronic voucher write-off data, applied to a client, characterized in that: The method comprises: Send an order request to the server; Obtaining an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received order request; Based on a preset encoding rule, the electronic certificate is encoded to obtain initial data, and based on the security key, the combined data consisting of the initial data and the timestamp is processed to obtain signature data, and a dynamic password is obtained according to the signature data; The verification data corresponding to the electronic voucher is generated according to the initial data and the dynamic password.
2. The method according to claim 1, characterized in that: The security key is generated randomly.
3. The method according to claim 1, characterized in that The obtaining of the electronic certificate sent by the server and its corresponding security key includes: Receiving encrypted data sent by the server, wherein the encrypted data is obtained by the server using an asymmetric encryption algorithm to encrypt the electronic certificate and its corresponding security key; The encrypted data is decrypted to obtain the electronic certificate and its corresponding security key.
4. The method according to claim 1, characterized in that The processing of the combined data consisting of the initial data and the timestamp based on the security key to obtain the signature data includes: The HMAC algorithm is adopted to sign the combined data consisting of the initial data and the timestamp through the security key to obtain the signature data.
5. The method according to claim 4, characterized in that The HMAC algorithm includes the HMAC-SHA256 algorithm.
6. The method according to claim 1, characterized in that The step of obtaining a dynamic password according to the signature data comprises: Processing the signature data to obtain an initial dynamic password; Modulus adjustment is performed on the initial dynamic password to obtain a dynamic password.
7. The method according to claim 1, characterized in that The generating, according to the initial data and the dynamic password, the verification data corresponding to the electronic voucher comprises: Using the dynamic password to replace the corresponding data in the initial data to obtain updated data; The update data is obfuscated to obtain the cancellation data corresponding to the electronic voucher.
8. The method according to claim 1, characterized in that The method further comprises: The verification data is converted into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
9. A method for generating electronic voucher verification data, applied to a server, characterized in that: The method comprises: Receive order requests sent by users through the client; Generate an electronic certificate and its corresponding security key according to the order request, and send the electronic certificate and its corresponding security key to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and a timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password; A request sent by the verification end is received, and ordering data including a security key corresponding to the electronic certificate is sent to the verification end.
10. The method according to claim 9, characterized in that The sending of the ordering data including the security key corresponding to the electronic certificate to the verification end includes: Sending encrypted data to the verification end, wherein the encrypted data is obtained by using an asymmetric encryption algorithm to encrypt order data including a security key corresponding to the electronic certificate.
11. A method for generating electronic voucher write-off data, applied to a write-off terminal, characterized in that: The method comprises: Send a request to the server; Obtaining order data including a security key corresponding to the electronic certificate sent by the server; When revoking an electronic voucher, obtaining revoking data corresponding to the electronic voucher in the client, wherein, at the client, based on a preset encoding rule, encoding the electronic voucher obtained from the server to obtain initial data, and based on the security key, processing the combined data consisting of the initial data and the timestamp to obtain signature data, and obtaining a dynamic password based on the signature data, and generating the revoking data corresponding to the electronic voucher based on the initial data and the dynamic password; The security key is used to verify the cancellation data. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
12. The method according to claim 11, characterized in that After the verification data corresponding to the electronic voucher is generated, the verification data is converted into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
13. The method according to claim 12, characterized in that The obtaining of the write-off data corresponding to the electronic voucher in the client includes: The scanning device of the cancellation terminal scans the cancellation code corresponding to the electronic certificate displayed by the client to obtain the cancellation data corresponding to the electronic certificate in the client.
14. A device for generating electronic voucher verification data, deployed on a client, characterized in that: The device comprises: The first module is used to send an order request to the server; A second module is used to obtain the electronic certificate sent by the server and its corresponding security key, wherein the electronic certificate is generated by the server according to the received order request; The third module is used to encode the electronic certificate based on a preset encoding rule to obtain initial data, and to process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and to obtain a dynamic password based on the signature data; The fourth module is used to generate the cancellation data corresponding to the electronic voucher according to the initial data and the dynamic password.
15. The device according to claim 14, characterized in that The device also includes: The fifth module is used to convert the verification data into a decimal string of fixed length to generate a verification code corresponding to the electronic voucher.
16. A device for generating electronic voucher verification data, deployed on a server, characterized in that: The device comprises: The sixth module is used to receive an order request sent by a user through a client; The seventh module is used to generate an electronic certificate and a corresponding security key according to the order request, and send the electronic certificate and the corresponding security key to the client, so that the client can encode the electronic certificate based on a preset encoding rule to obtain initial data, and process the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtain a dynamic password based on the signature data, and generate the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password; The eighth module is used to receive a request sent by the verification end, and send order data including a security key corresponding to the electronic certificate to the verification end.
17. A device for generating electronic voucher cancellation data, deployed at a cancellation terminal, characterized in that: The device comprises: The ninth module is used to send a request to the server; A tenth module is used to obtain the ordering data including the security key corresponding to the electronic certificate sent by the server; An eleventh module is used for obtaining cancellation data corresponding to the electronic certificate in the client when canceling the electronic certificate, wherein the client encodes the electronic certificate obtained from the server based on a preset encoding rule to obtain initial data, and processes the combined data consisting of the initial data and the timestamp based on the security key to obtain signature data, and obtains a dynamic password based on the signature data, and generates the cancellation data corresponding to the electronic certificate based on the initial data and the dynamic password; The twelfth module is used to verify the cancellation data using the security key. If the verification is successful, the cancellation of the cancellation data corresponding to the electronic certificate is completed.
18. A system for generating electronic voucher write-off data, characterized in that: The system comprises: The client is used to send a subscription request to a server, and obtain an electronic certificate and a corresponding security key sent by the server, wherein the electronic certificate is generated by the server according to the received subscription request, and the server encodes the electronic certificate based on a preset encoding rule to obtain initial data, and processes the combined data consisting of the initial data and a timestamp based on the security key to obtain signature data, and obtains a dynamic password based on the signature data, and generates verification data corresponding to the electronic certificate based on the initial data and the dynamic password; The server side is used to receive an order request sent by a user through a client side, generate an electronic certificate and its corresponding security key according to the order request, and send the electronic certificate and its corresponding security key to the client side, and receive a request sent by a cancellation side, and send order data including the security key corresponding to the electronic certificate to the cancellation side; The verification end is used to send a request to the server and obtain the ordering data sent by the server including the security key corresponding to the electronic certificate. When the electronic certificate is verified, the verification data corresponding to the electronic certificate in the client is obtained, and the verification data is verified using the security key. If the verification is successful, the verification data corresponding to the electronic certificate is completed.
19. A computer-readable medium having computer-readable instructions stored thereon, wherein the computer-readable instructions can be executed by a processor to implement part or all of the method according to any one of claims 1 to 13.
20. A device for generating electronic voucher write-off data, characterized in that: The device comprises: one or more processors; and A memory storing computer-readable instructions, wherein when the computer-readable instructions are executed, the processor is caused to perform part or all of the operations of the method according to any one of claims 1 to 13.