Push message transmission method and system

By introducing biometric authentication and encryption technology in push message transmission, the problem of poor security of push messages during the Internet transmission process is solved, and the confidentiality and security of messages are guaranteed.

CN119996508AInactive Publication Date: 2025-05-13WUXI RONGKA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510361903.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, push messages are easily leaked during the Internet transmission process, resulting in poor security, especially in financial transactions such as bank APPs, which may lead to the risk of information leakage and funds being transferred.

Method used

The secure service message encryption transmission method based on biometric authentication is adopted, and biometric authentication is performed after receiving the push message. The message is encrypted and decrypted through the encryption key to ensure the confidentiality and security of the message during transmission and display.

Benefits of technology

Through biometric authentication and encryption technology, we can effectively prevent push messages from being spyed, ensure information security, and prevent the risk of information leakage and funds being transferred.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996508A_ABST
    Figure CN119996508A_ABST
Patent Text Reader

Abstract

The invention discloses a push message transmission method and system. The push message transmission method according to the embodiment of the invention comprises the following steps: receiving a push message; after the push message is received, performing biological recognition authentication; and after the biological recognition authentication is passed, displaying the push message. According to the push message transmission method and system provided by the embodiment of the invention, identity verification is performed on the receiver of the push message, so that the push message can be prevented from being snooped, and the information security of the push message is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of push message transmission, and in particular to a push message transmission method and system. Background Art

[0002] Push messages from text messages or application apps are an important means of operation for mobile products. They are increasingly valued by APP manufacturers and are widely used in financial transactions such as daily payments, identity verification, and account information reminders in the financial industry.

[0003] In the prior art, push messages are generally sent to third-party push service providers, and the third-party push service pushes the message to the user's terminal according to the mobile phone ID; or the application is connected to the operator's SMS sending platform, and accurately sent to the target user's mobile phone through the mobile phone number. Push messages are likely to be leaked during the transmission process on the Internet, and the security is poor. For bank APP's transfer transaction verification code, account change notification and other messages, if they are illegally operated, there is a high risk of information leakage and funds being transferred away.

[0004] Therefore, it is hoped that there will be a new push message transmission method and system that can overcome the above problems. Summary of the invention

[0005] In view of the above problems, the purpose of the present invention is to provide a push message transmission method and system, in particular, a method based on secure service message encryption transmission and display, thereby preventing push messages from being spied on and ensuring the information security of push messages.

[0006] According to one aspect of the present invention, there is provided a push message transmission method, comprising:

[0007] Receive push messages;

[0008] After receiving the push message, performing biometric authentication;

[0009] After the biometric authentication is passed, the push message is displayed.

[0010] Optionally, the notification message is encrypted with an encryption key to obtain the push message;

[0011] After the biometric authentication is passed, the push message is decrypted using a decryption key that matches the encryption key to obtain the notification message;

[0012] The notification message is displayed.

[0013] Optionally, the notification message is encrypted with the encryption key and then signed to obtain the push message;

[0014] After the biometric authentication is passed, the push message is signed and decrypted to obtain the notification message.

[0015] Optionally, the decryption key is stored in a secure carrier, and the secure carrier includes at least one selected from a SE environment, a TEE environment, and a system keystore.

[0016] Optionally, the push message transmission method further includes:

[0017] Calling the trusted user interface;

[0018] The notification message is displayed on the trusted user interaction interface.

[0019] Optionally, the push message transmission method further includes:

[0020] Send push identifier to application server;

[0021] receiving a push message sent by the application server,

[0022] Wherein, the push message is generated according to the push identifier;

[0023] The push identifier is bound to the identity of the user performing the biometric authentication.

[0024] Optionally, the push message transmission method further includes:

[0025] Request the remote trusted service platform to authenticate the user;

[0026] After the real person authentication is completed, receiving the identity token certificate provided by the remote trusted service platform,

[0027] Wherein, the notification message is encrypted using the identity token certificate provided by the remote trusted service platform to obtain the push message;

[0028] After the biometric authentication of the user is passed, the push message is decrypted using the private key corresponding to the identity token certificate to obtain the notification message.

[0029] Optionally, the push message transmission method further includes:

[0030] The ordinary application running on the device sends an activation encryption message request to the application server;

[0031] The application server forwards the activation encryption message request to the remote trusted service platform;

[0032] The remote trusted service platform responds to the activation encryption message and returns a challenge code to the application server;

[0033] The application server forwards the challenge code to the common application;

[0034] The common application requests the security carrier on the device end to activate the encrypted message user authorization signature;

[0035] The security carrier makes a user authentication request and performs biometric authentication on the user;

[0036] After the biometric authentication is passed, the security carrier generates a user authorization data packet signed with the private key of the user device certificate, and sends the user authorization data packet to the common application;

[0037] The common application sends the user authorization data packet to the remote trusted service platform server via the application server;

[0038] The remote trusted service platform server verifies the user authorization data packet, and upon successful verification, records the encrypted message function as being activated;

[0039] The remote trusted service platform server sends activation success information to the application server;

[0040] The application server records the activation status and sends a message of successful activation to the common application.

[0041] Optionally, the push message transmission method further includes:

[0042] The common application running on the device registers the push service with the message push server;

[0043] The message push server returns a push identifier to the common application;

[0044] The common application synchronizes the push identifier with the application server;

[0045] The application server records the push identifier to complete the initialization of the push channel;

[0046] The application server generates a transaction business account change notification;

[0047] The application server queries the remote trusted service platform server for a user device certificate, and receives a public key of the user device certificate returned by the remote trusted service platform server;

[0048] The application server uses the public key of the user equipment certificate as the encryption key to generate the push message, and sends the push message to the message push server;

[0049] The message push server sends the push message to the common application and returns a push success message to the application server;

[0050] Displaying a notification of the push message on the device;

[0051] The security carrier in the device side requests the biometric authentication.

[0052] Optionally, the push message transmission method further includes:

[0053] The device receives the push message sent by the application server, and after the biometric authentication is passed, sends the recognition result to the application server.

[0054] According to another aspect of the present invention, there is provided a push message transmission system, comprising:

[0055] The device side receives the push message and performs biometric authentication after receiving the push message; after the biometric authentication is passed, the device side displays the push message.

[0056] The push message transmission method and system provided by the present invention verify the identity of the receiver of the push message before displaying the content of the push message, thereby preventing the push message from being spied on and ensuring the information security of the push message.

[0057] Furthermore, the push messages are encrypted with encryption keys, which ensures the confidentiality of the push messages during network transmission, and can prevent man-in-the-middle attacks and avoid data leakage.

[0058] Furthermore, the use of secure carriers to provide hardware-level security isolation for the storage and operation of (decryption) keys can prevent the leakage of sensitive information and ensure that the storage and operation of keys are protected from external attacks and eavesdropping.

[0059] Furthermore, encryption of push messages ensures the integrity and authenticity of the messages, which can prevent push messages from being tampered with or forged, thereby ensuring the credibility and authenticity of communications.

[0060] Furthermore, the trusted user interface (TUI) is used to achieve secure display of push message content, which can prevent unauthorized screenshots and screen recording operations, ensure that sensitive information is not leaked during the display of push messages, and protect the information security of push messages.

[0061] Furthermore, the push message is generated according to the push identifier bound to the user identity, which can realize the push of the push message more accurately and specifically.

[0062] Furthermore, if biometric authentication is not passed (authentication failed or not authenticated), the message cannot be viewed, ensuring that push messages are delivered securely and effectively.

[0063] Furthermore, the user's digital identity certificate is used to construct an encrypted message digital envelope, which is signed by the RTSP-TK private key to protect the encrypted message from cloud to end. The encrypted message content is transmitted in an encrypted and signed state, ensuring the security of the push message.

[0064] Furthermore, the message signature is verified using the RTSP-TK public key preset in the terminal security environment to ensure that the message comes from an authoritative organization and has not been tampered with, thus ensuring that the source of the message is credible and the message is trustworthy. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] The above and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:

[0066] Figure 1 A method flow chart of a push message transmission method according to Embodiment 1 of the present invention is shown;

[0067] Figure 2 A schematic diagram of the activation process of an identity token certificate according to an embodiment of the present invention is shown;

[0068] Figure 3 A schematic diagram of an activation process according to an embodiment of the present invention is shown;

[0069] Figure 4 A method flow chart of a push message transmission method according to Embodiment 2 of the present invention is shown;

[0070] Figure 5 A schematic structural diagram of a push message transmission system according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0071] Various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In each of the accompanying drawings, identical elements are represented by identical or similar reference numerals. For the sake of clarity, the various parts in the accompanying drawings are not drawn to scale. In addition, some well-known parts may not be shown in the drawings.

[0072] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. Many specific details of the present invention, such as the structure, materials, dimensions, processing technology and techniques of the components are described below to provide a clearer understanding of the present invention. However, as those skilled in the art will appreciate, the present invention may be implemented without following these specific details.

[0073] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "on" or "over" another layer or another region, it may mean that it is directly on the other layer or another region, or that other layers or regions are included between it and the other layer or another region. Moreover, if the component is turned over, the layer or a region will be "below" or "beneath" another layer or another region.

[0074] Figure 1 FIG. 2 shows a method flow chart of a push message transmission method according to Embodiment 1 of the present invention. Figure 1 As shown, the push message transmission method according to the first embodiment of the present invention is executed by a device (smartphone, smart watch, etc.), and specifically includes the following steps:

[0075] In step S101, receiving a push message;

[0076] (Device side) receives push messages. Optionally, the device side receives push messages provided by a message push service; the message push service is a technology for the field of Web application development, which refers to the application server (server side) actively sending push messages to the device side (client side).

[0077] In step S102, after receiving the push message, biometric authentication is performed;

[0078] (Device side) After receiving the push message, request biometric authentication. For example, biometric authentication of the user is performed through fingerprint recognition, facial recognition, etc.

[0079] In step S103, after the biometric authentication is passed, the push message is displayed.

[0080] After the biometric authentication is passed, the push message is displayed (on the device side). Optionally, the device side receives and manages the transmission and display of push messages through SMS services or application APPs. Of course, the transmission and display of messages can also be achieved through the independent security management application connecting to the message push server.

[0081] In an optional embodiment of the present invention, the notification message is encrypted with an encryption key to obtain a push message (this step is performed, for example, by an application server). After the biometric authentication is passed, the push message is decrypted (on the device side) using a decryption key that matches the encryption key to obtain a notification message. After the biometric authentication is passed, the notification message is displayed (on the device side). Optionally, the application server uses the encryption key (data envelope) to encrypt, and then signs (the encrypted information), and obtains a push message after signing. After the device receives the push message, it verifies and decrypts the push message in turn to obtain a notification message. The scheme of signing after encryption further ensures the security and authority of the message, and by verifying the signature, it can be confirmed that the source of the message is authentic. In the above embodiment, the message is encrypted and signed to ensure the integrity and authenticity of the message, which can effectively prevent man-in-the-middle attacks from stealing data and tampering with data.

[0082] Optionally, the decryption key is stored in a secure carrier (on the device side), and the secure carrier includes at least one selected from a SE environment, a TEE environment, a system keystore, and the like.

[0083] Optionally, the solution of the present application can not only register the encrypted message push channel through the application APP, but also register the encrypted message push channel through the identity token management application.

[0084] In an optional embodiment of the present invention, the push message transmission method further includes:

[0085] Invoke the Trusted User Interface (TUI).

[0086] Display push messages (notification messages) in the trusted user interface. The trusted user interface (for example, in a TEE environment) provides trusted display and input for secure applications, with features such as security isolation, anti-tampering, and prevention of screenshots and screen recording. Optionally, when displaying push messages, use the Android-provided setting window.Flags to prevent users from taking screenshots or recording screens.

[0087] In an optional embodiment of the present invention, the push message transmission method further includes: (device side) sending a push identifier to an application server; wherein the push identifier is bound to (has a corresponding relationship with) the identity of the user who performs biometric authentication, and the push message is generated based on the push identifier. (Device side) receiving a push message generated based on the push identifier sent by the application server. In the above embodiment, the push message is generated based on the push identifier bound to the user identity. For the same person, targeted push messages can be pushed; for different people, different types of push messages can be pushed, which can achieve more accurate and targeted push of push messages.

[0088] In an optional embodiment of the present invention, the push message transmission method further includes:

[0089] (Device side) Request the remote trusted service platform to authenticate the user;

[0090] After the real person authentication is completed, the (device side) receives the identity token certificate provided by the remote trusted service platform.

[0091] Among them, the notification message is encrypted using the identity token certificate provided by the remote trusted service platform to obtain a push message;

[0092] After the user's biometric authentication is passed, the push message is decrypted using the private key corresponding to the identity token certificate (on the device side) to obtain the notification message.

[0093] Figure 2 FIG. 2 shows a schematic diagram of the activation process of an identity token certificate according to an embodiment of the present invention. Figure 2 As shown, in a specific embodiment, the identity token certificate activation process occurs between the user, the management application 130 , the security carrier 110 and the remote trusted service platform server 300 .

[0094] First, the terms that may be involved in the identity token activation interaction (the message transmission method described in this application) are uniformly explained:

[0095] Identity Token refers to the identity proof data used in this product to present to the authenticator.

[0096] Identity Token System is a technical system that supports the operation of identity token products.

[0097] Remote trusted service platform (RTSP), that is, remote trusted service platform server 300 .

[0098] The Certificate Authority (CA) server, which is part of RTSP, is responsible for issuing, managing, storing and revoking digital certificates.

[0099] User Device Cert (UDC), a digital certificate issued by RTSP to a user's trusted device.

[0100] User Device Identifier (UDI): RTSP is an identification number associated with both the user and the trusted device generated by the user's trusted device according to rules. The UDI of the same user on different devices is also different. The UDI is bound to the user's device certificate.

[0101] Trusted Device Key (TDK) is a trusted device authentication key deployed by the device manufacturer to the device. It can be called through the TEE interface and use TDK to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer.

[0102] The trusted device authentication server, which is part of RTSP, is responsible for verifying the data signed by TDK in the device to ensure that the data comes from a legitimate device trusted by the device manufacturer.

[0103] A unified description of the keys that may be involved in this application:

[0104] The trusted device key (TDK for short) is a trusted device authentication key deployed by the device manufacturer to the device. The TDK is used to sign the data through the TEE interface to ensure that the data comes from a legitimate device trusted by the device manufacturer. The trusted device key is generated or preset in the secure element 110. The secure element 110 holds the private key of the trusted device key, and RTSP holds the public key or certificate of the trusted device key.

[0105] The RTSP platform key (RTSP-TK for short) is created or preset by RTSP. RTSP holds the private key of the RTSP platform key, and the security element 110 presets the public key of the RTSP platform key.

[0106] The CA root key (CA-ROOT for short) is the key used by the certificate issuing server in RTSP to issue certificates. The CA root key is generated or preset by RTSP. RTSP stores the private key and certificate of the CA root key; the CA-ROOT certificate is also distributed to the authentication device 400.

[0107] The application service authentication key public key or public key certificate (ABA-PK for short) is used to verify the real person information service authorization package submitted by the general application 120 when calling the security carrier 100. The authorization package is signed by RTSP using the corresponding private key. The application service authentication key public key or public key certificate is preset by RTSP or dynamically generates an application authorization verification key pair, and the public key is preset or synchronized (stored) to the security carrier 110.

[0108] The application authorization verification key private key (ABA-SK for short) is stored in RTSP. RTSP uses this key to authorize the application's submission of real-person information services.

[0109] The token encryption master key (TEK-MK for short) is used to disperse the master key of each identity token encryption key. The token encryption master key is created or preset by RTSP and synchronized to the authentication device 400. The token encryption master key is stored in RTSP / authentication device 400.

[0110] The token encryption subkey (TEK-DK for short) is used to encrypt the identity token data on the user device. The token encryption subkey is dispersed by RTSP and transmitted (stored) to the secure element 110.

[0111] The secure channel key group (SCKs, including the encryption key SCK-ENC and the verification key SCK-HMAC) is used to establish a secure channel between the secure element 110 and the RTSP, and is created during the user device certificate activation process. The secure channel key group is randomly generated by RTSP and synchronized to the secure element 110. The secure channel key group is stored in the RTSP / secure element 110.

[0112] The user equipment certificate key pair (including the user equipment certificate private key UDC-SK and the user equipment certificate public key UDC-PK) is created and generated (randomly generated) by the security carrier 110, and the public key is exported to RTSP for issuing the user equipment certificate (UDC-PK is exported and sent to RTSP), the private key is used for service confirmation signature, and the public key is used for signature verification. The security carrier 110 stores UDC-SK and UDC issued by RTSP; RTSP stores UDC.

[0113] The identity information submission temporary asymmetric encryption key (IEK) is used to encrypt the identity information when submitting it to the application, and is generated by the application server 200 and synchronized to the security carrier 110 through RTSP authentication. The application server 200 caches or stores the private key of the identity information submission temporary asymmetric encryption key.

[0114] Specifically, the user sends a function activation request to the management application 130 (the user operates the management application 130 to activate it); the management application 130 collects identity information and on-site face from the user (takes a face photo), and the user provides the identity information to the management application 130 and takes a photo of the on-site face.

[0115] The secure element 110 obtains the face information ciphertext from the management application 130, calculates and saves the face feature template (calculates and saves the face feature data calculated using the face photo), and encrypts the identity information and the face photo using the RTSP-TK public key, where RTSP-TK is, for example, a remote trusted service platform server key. The secure element 110 sends the identity information ciphertext to the management application 130.

[0116] The management application 130 submits the real person verification to the remote trusted service platform server 300. The submitted real person verification includes the identity information ciphertext (user identity information and face ciphertext). The remote trusted service platform server 300 uses the RTSP-TK private key to decrypt the identity information and photo (user identity and face data), and performs an authority service database check (face). The remote trusted service platform server 300 returns the comparison result to the management application 130.

[0117] The management application 130 calls the secure element 110 to create an activation request. The secure element 110 performs a device status security check, creates a UDC-SK key pair (the generation of the UDC-SK key has the property of one private key and one secret key), assembles the activation request data (including at least the public key of the security key pair, the device identifier, and the self-signature), and uses the TDK (Trusted Device Key) to (secondarily) sign the activation request data. The secure element 110 requests the user to set a key PIN code (a TUI pops up for the user to set a PIN code). The secure element 110 returns the activation request data to the management application 130.

[0118] The management application 130 sends an activation request to the remote trusted service platform server 300, and the activation request includes the activation request data. The remote trusted service platform server 300 uses the TDK public key to verify the activation request data, generate UDI, issue UDC (generate user device identification UDI based on user information and issue user device certificate UDC), generate SCKs, use TEK-MK (for user device identification) to disperse the subkey TEK-DK, and use SCKs to encrypt UDC, TEK-DK, UDI and user identity information, and use UDC-PK to encrypt SCKs. The remote trusted service platform server 300 sends the activation response data (including the above data) to the management application 130.

[0119] The management application 130 imports the activation response (activation response data) to the secure element 110. The secure element 110 uses the UDC-SK to decrypt the SCKs, and then uses the SCKs to decrypt and save the UDC, UDI, TEK-DK and user identity information. The secure element 110 binds the local biometric feature. If the binding is successful, the local biometric feature verification can be used to unlock the trusted token.

[0120] Figure 3 FIG. 2 shows a schematic diagram of an activation process according to an embodiment of the present invention. Before pushing a push message, an activation process is also included. Figure 3 As shown, the activation process according to the embodiment of the present invention also includes the following steps:

[0121] Request to activate encrypted notification: The application requests the server to activate the encrypted notification function, obtains the challenge word, and then requests user authorization.

[0122] User authorization activation encrypted notification: The user passes biometric verification, authorizes the user device certificate key (UDC-SK) to sign the challenge word, and returns the user authorization package.

[0123] Activate encrypted message: Send the user authorization data packet, which is transparently transmitted to the remote trusted service platform through the application server. The platform verifies the authorization data packet and records the activation status.

[0124] Specifically:

[0125] Step 1: Activate encrypted message request. The common application running on the device sends an activation encrypted message request to the application server.

[0126] Step 1.1: Activate encrypted message request. The application server forwards the activation encrypted message request to the remote trusted service platform. Afterwards, the remote trusted service platform responds to the activation encrypted message and returns a challenge code to the application server. The application server forwards the challenge code to the common application.

[0127] Step 2: Activate the encrypted message user authorization signature. The general application requests the secure carrier on the device to activate the encrypted message user authorization signature.

[0128] Step 2.1: User authentication request: The security carrier makes a user authentication request and performs biometric authentication on the user.

[0129] Step 3: User biometric confirmation: The security carrier obtains biometric information from the user for user biometric confirmation.

[0130] Step 4: Authentication Confirmation. The security carrier is carefully confirmed.

[0131] Step 4.1: UDC-SK key signature. After the biometric authentication is passed, the secure element generates a user authorization data packet signed with the user device certificate private key (UDC-SK). Afterwards, the secure element sends the user authorization data packet to the normal application.

[0132] Step 5: Activate the encrypted message (user authorization data packet). The normal application sends the user authorization data packet to the application server.

[0133] Step 5.1: Activate the encrypted message (user authorization data packet). The application server sends the user authorization data packet to the remote trusted service platform server.

[0134] Step 5.1.1: Verify the user authorization data packet. The remote trusted service platform server verifies the user authorization data packet.

[0135] Step 5.1.2: Record the encrypted message function as activated. After successful verification, the remote trusted service platform server records the encrypted message function as activated. Afterwards, the remote trusted service platform server sends activation success information to the application server.

[0136] Step 5.2: Record activation status. The application server records the activation status. Afterwards, a successful activation message is sent to the common application.

[0137] Figure 4 FIG. 2 shows a method flow chart of a push message transmission method according to Embodiment 2 of the present invention. Figure 4 As shown, the push message transmission method according to the second embodiment of the present invention includes the following steps:

[0138] Push channel initialization: The application starts, registers the push service using the identity token SDK service, and synchronizes the user's push identifier to the server. The server records the binding relationship between the push identifier and the user, completing the push channel initialization.

[0139] Transaction business pushes encrypted messages to user terminals: User transaction business generates account change notifications, and the server pre-processes the notification message and sends it to the terminal, mainly including user device certificate query, session key generation, use of session key, UDC-PK, and notification message to build and assemble encrypted message digital envelopes, use RTSP-TK private key to sign the digital envelope, and send the encrypted message digital envelope to the user terminal through the message push server.

[0140] User identity verification and secure display of notification message: The user clicks on the notification bar message, the application 120 requests the security carrier 110 to decrypt the encrypted message, the security carrier 110 uses the preset RTSP-TK public key to verify the signature, the signature is verified by popping up the user identity authentication interface, the user biometric confirmation, unlocking the identity token key to decrypt the digital envelope, and the security carrier securely displays the notification message through the TUI.

[0141] Specifically:

[0142] Step 1: Register for push service. The normal application running on the device registers the push service with the message push server. After that, the message push server returns a push identifier to the normal application.

[0143] Step 2: Synchronize the push identifier. The common application synchronizes the push identifier to the remote trusted service platform server.

[0144] Step 2.1: Record the push identifier. The remote trusted service platform server records the push identifier.

[0145] At this point, the push channel is initialized. After initialization is complete, you can push encrypted messages.

[0146] Step 3: Transaction business account change notification. The application server generates a transaction business account change notification.

[0147] Step 4: Apply to send an encrypted message (message, identity token). The application server applies to the remote trusted service platform server to send an encrypted message.

[0148] Step 4.1: Query the digital certificate of the identity token (identity token identifier). The remote trusted service platform server queries the digital certificate of the identity token.

[0149] Step 4.2: Construct an encrypted message digital envelope. The remote trusted service platform server constructs an encrypted message digital envelope.

[0150] Step 4.3: Use the RTSP-TK private key to sign the encrypted message digital envelope. The remote trusted service platform server uses the RTSP-TK private key to sign the encrypted message digital envelope. After that, the remote trusted service platform server sends the successful application information to the application server.

[0151] Step 5: Send the encrypted message (encrypted message digital envelope (including signature), push identifier). The remote trusted service platform server sends the encrypted message to the message push server. Afterwards, the message push server sends the successfully sent message to the remote trusted service platform server.

[0152] Step 5.1: Push the encrypted message to the terminal. The message push server sends the push message to the general application.

[0153] Step 6: The notification bar on the phone displays a notification. The notification bar on the phone (device) displays a notification that a push message has been received. The push message cannot be read before the user authentication (biometric authentication) is passed.

[0154] Step 7: Click to view notification. The user clicks to view the notification.

[0155] Step 7.1: Request to decrypt message (encrypted message digital envelope (including signature)). The normal application requests to decrypt the message from the secure carrier.

[0156] Step 7.1.1: Verify the signature using the preset RTSP-TK public key. The secure element verifies the signature using the preset RTSP-TK public key.

[0157] Step 7.1.2: Request user authentication. The secure carrier requests user authentication.

[0158] Step 8: User biometric confirmation. The device performs biometric confirmation on the user.

[0159] Step 9: Authentication and confirmation: The security carrier performs authentication and confirmation of the user's identity.

[0160] Step 10: Unlock the encryption key to decrypt the envelope and display the notification message securely. The secure carrier uses the decryption key to decrypt the push message (in the form of a digital envelope), obtain the notification message, and display the notification message.

[0161] In an optional embodiment of the present invention, the push message transmission method also includes: the device receives the push message sent by the application server, and after the biometric authentication is passed, sends the identification result to the application server. In the above embodiment, if the biometric authentication is not passed (authentication failed or not authenticated), the message cannot be viewed, ensuring the safe and effective transmission of the push message. Specifically, the third-party push service is usually carried out through a reserved mobile phone number. After a period of time, the mobile phone number may not be used by the original person, and the timeliness and transmission rate of the message cannot reach 100%. The biometric identification method is used to ensure that the next push message is sent only after the previous push message is received by the person, ensuring the effective transmission of the push message.

[0162] According to another aspect of the present invention, a push message transmission system is provided. The push message transmission system according to an embodiment of the present invention is used, for example, to implement the push message transmission method described above. The push message transmission system includes a device end (smartphone, smart watch, etc.). The device end receives the push message, and after receiving the push message, performs biometric authentication; after the biometric authentication is passed, the device end displays the push message.

[0163] Figure 5 The push message transmission system according to the embodiment of the present invention is shown in FIG. . The push message transmission system according to the embodiment of the present invention is used, for example, to implement the push message transmission method described above. Figure 5 As shown, in a specific embodiment, the push message transmission system includes at least one of the following components:

[0164] The terminal device (mobile terminal / device end) 100 is a terminal device held by a user, such as a smart phone, a smart watch, etc. A security element (such as TEE or SE or both) is integrated on the terminal device 100 .

[0165] The security carrier 110 is a software and hardware module on the terminal device 100. It implements the security function interface by accessing TEE\SE internally, and provides the interface to external applications. Among them, the security carrier access service program 111 provides an entity program for the external interface of the security carrier 110, accesses TEE\SE to implement the functional interface encapsulation of the identity token, and provides external calls. TEE (Trusted Execution Environment) 112 is a security carrier, which is a logical security isolation area of ​​the system SOC and can execute security applications. SE (Secure Element) 112 is generally an independent encryption chip. Due to its independent isolation characteristics, it has a higher security level than TEE. Calling the SE interface in TEE can further ensure business security.

[0166] The general application 120 calls the secure element 110 to call the application of various functions of the identity token. The management application 130 calls the secure element 110 to perform identity token provisioning management.

[0167] The remote trusted service platform server 300 is a general term for services involved in the operation of identity token services, including but not limited to: authoritative identity authentication services, certificate issuance services, identity token verification services, activation management services, application access services, etc., and also includes terminal equipment manufacturer-related background services, etc.

[0168] The application server 200 is a background service of the common application 120 and processes authentication requests of the common application 120 .

[0169] The message push server 400 is a terminal device push channel built by a terminal device manufacturer or a push service provider, which can push messages to a designated device.

[0170] The authentication device 500 is a device used to verify and authenticate the identity token generated by the terminal device.

[0171] According to the push message transmission method and system of the embodiments of the present invention, based on the identity token certificate service, the encrypted message (push message) is securely pushed to the user device, the encryption key is unlocked, the message is decrypted through the user identity verification, and the notification message is securely displayed through the TUI; the identity token certificate (user digital identity certificate) is used to build an encrypted message digital envelope to protect the encrypted message from cloud to end, and the encrypted message content is transmitted in an encrypted state. The decryption of the encrypted message requires the user digital certificate owner to pass the identity verification before the encryption and decryption can be unlocked to decrypt the message, thereby protecting the user's privacy from prying eyes.

[0172] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0173] According to the embodiments of the present invention as described above, these embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and changes can be made based on the above description. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can make good use of the present invention and the modified use based on the present invention. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. A push message transmission method, comprising: Receive push messages; After receiving the push message, performing biometric authentication; After the biometric authentication is passed, the push message is displayed.

2. The push message transmission method according to claim 1, wherein: The notification message is encrypted with an encryption key to obtain the push message; After the biometric authentication is passed, the push message is decrypted using a decryption key that matches the encryption key to obtain the notification message; The notification message is displayed.

3. The push message transmission method according to claim 2, wherein: The notification message is encrypted with the encryption key and then signed to obtain the push message; After the biometric authentication is passed, the push message is signed and decrypted to obtain the notification message.

4. The push message transmission method according to claim 2, wherein: The decryption key is stored in a secure element, and the secure element includes at least one selected from a SE environment, a TEE environment, and a system keystore.

5. The push message transmission method according to claim 2, wherein: The push message transmission method further includes: Calling the trusted user interface; The notification message is displayed on the trusted user interaction interface.

6. The push message transmission method according to claim 1, wherein: The push message transmission method further includes: Send push identifier to application server; receiving a push message sent by the application server, Wherein, the push message is generated according to the push identifier; The push identifier is bound to the identity of the user performing the biometric authentication.

7. The push message transmission method according to claim 1, wherein: The push message transmission method further includes: Request the remote trusted service platform to authenticate the user; After the real person authentication is completed, receiving the identity token certificate provided by the remote trusted service platform, Wherein, the notification message is encrypted using the identity token certificate provided by the remote trusted service platform to obtain the push message; After the biometric authentication of the user is passed, the push message is decrypted using the private key corresponding to the identity token certificate to obtain the notification message.

8. The push message transmission method according to claim 1, wherein: The push message transmission method further includes: The ordinary application running on the device sends an activation encryption message request to the application server; The application server forwards the activation encryption message request to the remote trusted service platform; The remote trusted service platform responds to the activation encryption message and returns a challenge code to the application server; The application server forwards the challenge code to the common application; The common application requests the security carrier on the device end to activate the encrypted message user authorization signature; The security carrier makes a user authentication request and performs biometric authentication on the user; After the biometric authentication is passed, the security carrier generates a user authorization data packet signed by the private key of the user device certificate, and sends the user authorization data packet to the common application; The common application sends the user authorization data packet to the remote trusted service platform server via the application server; The remote trusted service platform server verifies the user authorization data packet, and upon successful verification, records the encrypted message function as being activated; The remote trusted service platform server sends activation success information to the application server; The application server records the activation status and sends a message of successful activation to the common application.

9. The push message transmission method according to claim 1, wherein: The push message transmission method further includes: The common application running on the device registers the push service with the message push server; The message push server returns a push identifier to the common application; The common application synchronizes the push identifier with the application server; The application server records the push identifier to complete the initialization of the push channel; The application server generates a transaction business account change notification; The application server queries the remote trusted service platform server for a user device certificate, and receives a public key of the user device certificate returned by the remote trusted service platform server; The application server uses the public key of the user equipment certificate as the encryption key to generate the push message, and sends the push message to the message push server; The message push server sends the push message to the common application and returns a push success message to the application server; Displaying a notification of the push message on the device; The security carrier in the device side requests the biometric authentication.

10. The push message transmission method according to claim 1, wherein: The push message transmission method further includes: The device receives the push message sent by the application server, and after the biometric authentication is passed, sends the recognition result to the application server.

11. A push message transmission system, comprising: The device side receives the push message and performs biometric authentication after receiving the push message; After the biometric authentication is passed, the device displays the push message.