Terminal security protection method based on digital certificate UKEY technology

By using digital certificate UKEY technology in the monitoring system for terminal security protection, the problems of weak security awareness and backward technical means in the monitoring system are solved, high-strength encryption and secure storage of user data are achieved, and security risks and costs are reduced.

CN120200753APending Publication Date: 2025-06-24国网河北省电力有限公司营销服务中心 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411781320.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing monitoring system has weak security awareness and backward technical means, which leads to high data security risks, and the traditional transformation methods are costly and difficult to implement.

Method used

The terminal security protection method based on the digital certificate UKEY is adopted to ensure the security of user data during transmission and storage through client and server identity authentication, data encryption and key management.

Benefits of technology

It realizes high-strength encryption and secure storage of user data, avoids data leakage and illegal access, and reduces security awareness and technical costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200753A_ABST
    Figure CN120200753A_ABST
Patent Text Reader

Abstract

The invention discloses a terminal security protection method based on a digital certificate UKEY technology, and the method comprises the steps: enabling a client to monitor whether a digital certificate UKEY is inserted or not when a user opens the client; if yes, the client verifies whether the identity recognition information of the user is correct or not; if the digital certificate UKEY is correct, public key query and CRL query are carried out on the server side, and validity verification is carried out on the digital certificate of the digital certificate UKEY; if verification succeeds, the client requests the digital certificate UKEY to generate a corresponding service key, and the service key is encrypted and protected through a master key; generating a storage directory of the user; and the client encrypts user data generated in the process of using the client by the user by using the service key to generate a user data ciphertext, and stores the user data ciphertext in a storage directory of the user. According to the invention, identity authentication of the client and the server is realized through the digital certificate UKEY, and the security of system data is effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security, and particularly relates to a terminal security protection method based on digital certificate UKEY technology. Background Art

[0002] With the booming development of the Internet, the network has become an indispensable basic condition in people's life and work. During the process of using the network, users will generate various types of user data, and many of these data are very sensitive and core to users, such as account passwords, access records, bookmarks, Cookies, etc. Due to the openness of network implementation and existing security problems, there are already some hacker tools on the market that can illegally read, collect, tamper with, and transmit user data, posing a serious threat to users' privacy, property security, etc.

[0003] Most systems include servers and various terminals, and the terminals are interconnected with the backend server through the IP network. For various software systems built on the network, they also face a large number of attacks, such as: illegally obtaining information or providing false information, illegally obtaining surveillance images, infringing on personal privacy, etc. An intruder may access the video surveillance system by forging front-end devices and backend monitoring management platforms and illegally steal the system content. Therefore, it is necessary to perform two-way identity authentication between the front-end device and the backend monitoring management platform, as well as between the monitoring management user and the monitoring management platform to ensure that the identities of both parties are not forged; on the other hand, when transmitting data between the system front-end device and the management platform, between management platforms, and between the management platform and the user terminal, it is relatively easy to be intercepted, resulting in the leakage of key or sensitive content.

[0004] And cryptography is a feasible technical option to solve the above security requirements. Relying on the cryptography technology system, means such as digital certificates, digital signatures, and data encryption can be adopted to prevent illegal access of devices and users, prevent signaling and video data from being illegally tampered with, repudiated, and stolen. However, existing monitoring systems, whether it is the front-end device, the backend monitoring management platform, or the user terminal, still mainly focus on the monitoring function, and the consideration of security awareness and technical means is not sufficient, which is reflected in: only relying on setting login passwords, weak security awareness, believing that the "private network" is a secure network and will not be attacked, manually recording forms to manage monitoring devices, etc.

[0005] Precisely because of the weak security awareness and backward technical means, large data information security hazards have emerged in the monitoring system. To solve the security problem, the traditional approach is to completely transform the existing large number of deployed monitoring devices, which will face huge costs and implementation difficulties. There is a need for a system and method that breaks new ground to control costs and implementation difficulties and enables security technologies to be effectively implemented. Summary of the Invention

[0006] In view of this, the present invention provides a terminal security protection method based on digital certificate UKEY technology, aiming to solve the problems of weak security awareness and backward technical means in the prior art, which have caused great potential data information security hazards in the monitoring system.

[0007] To solve the above technical problems, the technical solutions adopted by the present invention are as follows.

[0008] A terminal security protection method based on digital certificate UKEY technology, the method is implemented based on a security protection system; specifically includes the following steps:

[0009] A. When the user opens the client, the client listens for whether the digital certificate UKEY is inserted;

[0010] B. If so, the client verifies whether the user's identity identification information is correct;

[0011] C. If it is correct, based on the digital certificate of the digital certificate UKEY, a public key query and a CRL query are performed on the server side, and the digital certificate of the digital certificate UKEY is subjected to a legality check;

[0012] D. If the verification is successful, the client requests the digital certificate UKEY to generate a corresponding service key, and the service key is encrypted and protected by the master key;

[0013] E. Generate a storage directory for this user;

[0014] F. The client encrypts the user data generated during the user's use of the client with the service key to generate a user data ciphertext, and stores the user data ciphertext in the storage directory of this user.

[0015] The above terminal security protection method based on digital certificate UKEY technology, the security protection system includes a digital certificate UKEY, a client and a server side, the client is pre-installed on the terminal device and can communicate with the server side; the digital certificate UKEY is plugged into the terminal device for providing hardware password security services for the client;

[0016] The digital certificate UKEY is pre-set with a digital certificate, a public-private key pair and a master key, generates a corresponding service key according to the requirements of the client, and encrypts and protects the service key with the master key;

[0017] The client includes: a hardware monitoring module responsible for monitoring the working status of the digital certificate UKEY; an identity authentication module for verifying the user's identity identification information and the digital certificate of the digital certificate UKEY; a key management module for receiving the service key encrypted and protected by the master key and responsible for the secure use of the service key by the user; an encryption / decryption module for encrypting and decrypting the data generated by the user using the client with the service key; a local storage module for storing and managing the data encrypted by the encryption / decryption module.

[0018] The server side includes: a PKI service module for issuing or revoking digital certificates for the digital certificate UKEY and providing public key query and CRL query services for the identity authentication module.

[0019] The method specifically includes the following steps:

[0020] When the user opens the client, the hardware monitoring module of the client monitors whether the digital certificate UKEY is inserted;

[0021] If so, the identity authentication module of the client verifies whether the user's identity identification information is correct;

[0022] If it is correct, the identity authentication module performs a public key query and a CRL query on the PKI service module of the server side based on the digital certificate of the digital certificate UKEY, and performs a legality verification on the digital certificate of the digital certificate UKEY;

[0023] If the verification is successful, the key management module of the client requests the digital certificate UKEY to generate a corresponding service key, and places the service key encrypted and protected by the master key in the key management module;

[0024] The local storage module generates a storage directory for the user;

[0025] The encryption / decryption module of the client encrypts the user data generated by the user during the use of the client with the service key to generate a user data ciphertext, and stores the user data ciphertext in the storage directory of the user.

[0026] For the above terminal security protection method based on the digital certificate UKEY technology, the security protection system further includes an authentication and authorization module for authenticating and authorizing the service requests of the client; during the authentication and authorization process, the digital certificate UKEY uses its own private key to encrypt and sign the challenge value to generate signature information; the authentication and authorization module uses the public key of the digital certificate UKEY to decrypt and verify the signature information.

[0027] The above-mentioned terminal security protection method based on digital certificate UKEY technology, the security protection system further includes a cloud storage module, and the cloud storage module is used to manage and store the ciphertext of user data uploaded by the client, and provide functions of uploading, deleting, querying, and downloading externally; the client further includes a data synchronization module, and the data synchronization module is responsible for uploading the ciphertext of user data to the cloud storage module on the server side, or downloading and obtaining the ciphertext of user data from the cloud storage module on the server side.

[0028] The above-mentioned terminal security protection method based on digital certificate UKEY technology, the security protection system further includes a display module, and the display module is responsible for providing a user interface display interface for the digital certificate UKEY and other modules of the client.

[0029] The above-mentioned terminal security protection method based on digital certificate UKEY technology, the client further includes a digital certificate UKEY call library, and the digital certificate UKEY call library encapsulates the software interface and driver of the digital certificate UKEY for other modules of the client to call.

[0030] The above-mentioned terminal security protection method based on digital certificate UKEY technology, the server side further includes a hardware asset management module, and the hardware asset management module is responsible for managing the asset information of all delivered and used digital certificate UKEYs, and the asset information includes the ID of the digital certificate UKEY and the public key information of the signature.

[0031] The above-mentioned terminal security protection method based on digital certificate UKEY technology, after generating the ciphertext of user data in step F, the client requests the server side to obtain a challenge value; the server side generates a challenge value and returns it to the client; the client calls the digital certificate UKEY and encrypts and signs the challenge value with its own private key to generate signature information; the client sends a signature verification request to the server side based on the signature information; the server side receives the signature information and decrypts and verifies the signature with the public key of the digital certificate UKEY, and after the verification is successful, generates voucher information and returns it to the client; the client sends a service request to the server side, and the service request at least includes service content and the voucher information; the server side processes the service content according to the voucher information.

[0032] The above-mentioned terminal security protection method based on digital certificate UKEY technology, after generating the voucher information and returning it to the client, the client sends an upload data request to the server side, and the upload data request at least includes the ciphertext of user data and the voucher information; the server side stores the received ciphertext of user data in the user storage directory of the cloud storage module according to the voucher information.

[0033] After generating the credential information and returning it to the client, the above terminal security protection method based on digital certificate UKEY technology further includes: the client sends a download data request to the server, and the download data request includes at least a download data range and the credential information; the server pushes the corresponding user data ciphertext to the client according to the credential information and the download data range, and stores it in the user storage directory of the local storage module.

[0034] Due to the adoption of the above technical solutions, the technical progress achieved by the present invention is as follows.

[0035] The present invention realizes the identity authentication of the client and the server through the digital certificate UKEY, realizes account-free login, and only needs to insert an authorized digital certificate UKEY to use the client. For the server, it also realizes high-strength identity authentication based on the digital certificate UKEY. The data is encrypted by the digital certificate UKEY, and the encryption key cannot leave the hardware. Whether on the terminal or the server, it can ensure that the user data cannot be cracked; the server provides the function of persistent storage of user data, including uploading, downloading, querying, etc., and the data of different users is isolated from each other. The data generated during the user's use of the system can be uploaded to the server for persistent storage, or the data can be downloaded to the terminal device for local storage and use. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 It is a flowchart of the implementation of the terminal security protection method based on digital certificate UKEY technology provided by the embodiments of the present invention. Detailed Embodiments

[0038] In the following description, specific details such as specific system structures and technologies are proposed for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present invention. However, those skilled in the art should clearly understand that the present invention can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present invention.

[0039] A terminal security protection method based on digital certificate UKEY technology, the process of which is as Figure 1As shown, the method is implemented based on a security protection system.

[0040] The security protection system includes a digital certificate UKEY, a client, and a server. The client is pre-installed on a terminal device and can communicate with the server. The digital certificate UKEY is plugged into the terminal device to provide hardware password security services for the client.

[0041] The digital certificate UKEY is pre-set with a digital certificate, a public-private key pair, and a master key. It generates corresponding service keys according to the requirements of the client and encrypts and protects the service keys using the master key.

[0042] The client includes: a hardware monitoring module, an identity authentication module, a key management module, an encryption and decryption module, and a local storage module. The hardware monitoring module is responsible for monitoring the working status of the digital certificate UKEY. The identity authentication module is used to verify the user's identity identification information and the digital certificate of the digital certificate UKEY. The key management module is used to receive the service keys encrypted and protected by the master key and is responsible for the secure use of the service keys by the user. The encryption and decryption module encrypts and decrypts the data generated by the user using the client using the service keys. The local storage module is used to store and manage the data encrypted by the encryption and decryption module.

[0043] The server includes a PKI service module, which is used to issue or revoke digital certificates for the digital certificate UKEY and provide public key query and CRL query services for the identity authentication module.

[0044] In practical applications, the hardware monitoring module is mainly responsible for monitoring events such as the insertion, removal, and timeout of the digital certificate UKEY. When an insertion event occurs, the user is prompted to perform identity authentication. When a removal event occurs, some functions of the client will be frozen. When a timeout event occurs, the client is frozen and the user is required to re-perform identity authentication. In addition, when these events occur, the hardware monitoring module is also responsible for notifying other modules of the client so that other modules can obtain the working status of the digital certificate UKEY in real time.

[0045] Among them, the identity authentication module authenticates the users of the client, including the verification of user identity information, digital certificate verification, etc. Only when the identity authentication is passed can the user use the functions of the client. Specifically, the verification content of the digital certificate includes the certificate issuing authority, the certificate validity period, whether the certificate has been revoked, etc.; the identity identification information may include a personal identification number (PIN), user biometric information, etc. Further, the user biometric information may be a face, iris, fingerprint, gait, etc.

[0046] The key management module can call the interface of the digital certificate UKEY to generate service keys, and protect the service keys with the master key in the digital certificate UKEY. The master key is sealed in the key storage area of the digital certificate UKEY. The master key cannot leave the digital certificate UKEY, and the outside world cannot read it from the digital certificate UKEY, which can ensure the security of user data on the terminal device. Specifically, after the service key is generated by the digital certificate UKEY, it is encrypted with the master key to generate a service key ciphertext, and the key management module stores the service key ciphertext; when the user needs to use the service key to encrypt and decrypt data, the key management module can call the digital certificate UKEY to decrypt the service key ciphertext; specifically, the key management module can send the service key ciphertext to be decrypted to the digital certificate UKEY, and the digital certificate UKEY decrypts it according to the master key to obtain the service key. If the digital certificate UKEY is unplugged, the service key ciphertext stored in the key management module cannot be decrypted because there is no master key, thus preventing the user from using the service key normally.

[0047] The encryption and decryption module can provide software interfaces such as encryption, decryption, signature, signature verification, and hash calculation. The local storage module is responsible for local storage and management of the data generated during the user's use of the client. The user data stored in the local storage module has been encrypted by the encryption and decryption module.

[0048] The local storage module can build corresponding storage directories based on different digital certificate UKEYs. Based on the storage directories, the user data generated during the use of different digital certificate UKEYs is isolated from each other, effectively preventing the cross of different user data and ensuring the privacy of user data.

[0049] The digital certificate USB Key contains public key information. The client obtains the public key information of the digital certificate USB Key and traverses the PKI service module according to the public key information to query whether there is a matching public key. If there is, it indicates that the digital certificate is issued by the certificate authority CA of the PKI service module. If not, it indicates that the digital certificate is not issued by the certificate authority CA of the PKI service module. After determining that the digital certificate is issued by the certificate authority CA of the PKI service module, traverse the certificate revocation list according to the digital certificate to query whether there is a matching revoked certificate. If not, verify that the digital certificate is legal and valid. If there is, it indicates that the digital certificate has expired.

[0050] Figure 1 It is the implementation flowchart of the terminal security protection method based on the digital certificate USB Key technology provided by the embodiments of the present invention. As Figure 1 shown, the method based on the security protection system specifically includes the following steps:

[0051] A. When the user opens the client, the hardware monitoring module of the client monitors whether the digital certificate USB Key is inserted.

[0052] B. If so, the identity authentication module of the client verifies whether the user's identity identification information is correct.

[0053] C. If it is correct, the identity authentication module queries the public key and CRL from the PKI service module of the server side based on the digital certificate of the digital certificate USB Key, and performs a legality check on the digital certificate of the digital certificate USB Key.

[0054] D. If the verification is successful, the key management module of the client requests the digital certificate USB Key to generate a corresponding service key, and encrypts and protects the service key with the master key and then places it in the key management module.

[0055] E. The local storage module generates a storage directory for this user.

[0056] F. The encryption and decryption module of the client encrypts the user data generated during the user's use of the client with the service key to generate user data ciphertext, and stores the user data ciphertext in the storage directory of this user.

[0057] The security protection system further includes an authentication and authorization module for authenticating and authorizing the service requests of the client. During the authentication and authorization process, the digital certificate USB Key encrypts and signs the challenge value with its own private key to generate signature information. The authentication and authorization module decrypts and verifies the signature information with the public key of the digital certificate USB Key.

[0058] The security protection system further includes a cloud storage module, which is used to manage and store the ciphertext of user data uploaded by the client, and provide functions of uploading, deleting, querying, and downloading externally; the client further includes a data synchronization module, and the data synchronization module is responsible for uploading the ciphertext of user data to the cloud storage module on the server side, or downloading and obtaining the ciphertext of user data from the cloud storage module on the server side.

[0059] The security protection system further includes a display module, and the display module is responsible for providing a user interface display interface for the digital certificate UKEY and other modules of the client.

[0060] The client further includes a digital certificate UKEY call library, and the digital certificate UKEY call library encapsulates the software interface and driver of the digital certificate UKEY for other modules of the client to call.

[0061] The server side further includes a hardware asset management module, and the hardware asset management module is responsible for managing the asset information of all delivered and used digital certificate UKEYs. The asset information includes the ID of the digital certificate UKEY and the public key information of the signature.

[0062] After the user data ciphertext is generated in step F of the present invention, the client requests the server side to obtain a challenge value; the server side generates a challenge value and returns it to the client; the client calls the digital certificate UKEY and encrypts and signs the challenge value with its own private key to generate signature information; the client sends a signature verification request to the server side based on the signature information; the server side receives the signature information and decrypts and verifies it with the public key of the digital certificate UKEY. After the verification is successful, it generates voucher information and returns it to the client; the client sends a service request to the server side, and the service request includes at least service content and the voucher information; the server side processes the service content according to the voucher information.

[0063] After generating the voucher information and returning it to the client, the client sends an upload data request to the server side, and the upload data request includes at least the ciphertext of user data and the voucher information; the server side stores the received ciphertext of user data in the user storage directory of the cloud storage module according to the voucher information.

[0064] After generating voucher information and returning it to the client, the method further includes: the client sending a download data request to the server, where the download data request includes at least a download data range and the voucher information; the server pushing corresponding encrypted user data to the client according to the voucher information and the download data range, and storing it in a user storage directory in a local storage module.

[0065] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0066] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described terminal and unit can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0067] In several embodiments provided in the present application, it should be understood that the disclosed terminal and method can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection to each other can be an indirect coupling or communication connection through some interfaces, devices or units, and can also be in an electrical, mechanical or other form of connection.

[0068] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.

[0069] In addition, the functional units in various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-integrated units can be implemented in the form of hardware or in the form of software functional units.

[0070] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A terminal security protection method based on digital certificate UKEY technology, characterized in that: The method is implemented based on a safety protection system and specifically comprises the following steps: A. When the user opens the client, the client listens to whether the digital certificate UKEY is inserted; B. If so, the client verifies whether the user's identity information is correct; C. If correct, based on the digital certificate of the digital certificate UKEY, the client performs public key query and CRL query on the server, and verifies the legitimacy of the digital certificate of the digital certificate UKEY; D. If the verification is successful, the client requests the digital certificate UKEY to generate the corresponding business key, and encrypts and protects the business key via the master key; E. Generates the storage directory of the user; F. The client uses the business key to encrypt the user data generated by the user during the use of the client, generates user data ciphertext, and stores the user data ciphertext in the user's storage directory.

2. According to claim 1, the terminal security protection method based on digital certificate UKEY technology is characterized in that: The security protection system includes a digital certificate UKEY, a client and a server. The client is pre-installed on the terminal device and can communicate with the server. The digital certificate UKEY is plugged into the terminal device and is used to provide hardware password security services for the client. The digital certificate UKEY is pre-set with a digital certificate, a public-private key pair and a master key, generates a corresponding business key according to the needs of the client, and uses the master key to encrypt and protect the business key; The client comprises: A hardware monitoring module is responsible for monitoring the working status of the digital certificate UKEY; An identity authentication module is used to verify the user's identity information and the digital certificate of the digital certificate UKEY; A key management module, used for receiving a service key encrypted and protected by the master key, and responsible for the safe use of the service key by the user; An encryption and decryption module, using the business key to encrypt and decrypt data generated by the user using the client; A local storage module, used to store and manage the data encrypted by the encryption and decryption module; The server side includes: A PKI service module, used to issue or revoke the digital certificate UKEY, and provide public key query and CRL query services for the identity authentication module; The method specifically comprises the following steps: When the user opens the client, the hardware monitoring module of the client monitors whether the digital certificate UKEY is inserted; If yes, the identity authentication module of the client verifies whether the user's identity information is correct; If it is correct, the identity authentication module performs a public key query and a CRL query to the PKI service module on the server side based on the digital certificate of the digital certificate UKEY, and performs a legitimacy check on the digital certificate of the digital certificate UKEY; If the verification is successful, the key management module of the client requests the digital certificate UKEY to generate a corresponding business key, and encrypts the business key with the master key and places it in the key management module; The local storage module generates a storage directory for the user; The encryption and decryption module of the client uses the business key to encrypt the user data generated during the user's use of the client, generate user data ciphertext, and store the user data ciphertext in the storage directory of the user.

3. According to claim 2, the terminal security protection method based on digital certificate UKEY technology is characterized in that: The security protection system also includes an authentication module, which is used to authenticate the service request of the client; During the authentication process, the digital certificate UKEY uses its own private key to encrypt and sign the challenge value to generate signature information; The authentication module uses the public key of the digital certificate UKEY to decrypt and verify the signature information.

4. The terminal security protection method based on digital certificate UKEY technology according to claim 2 is characterized in that: The security protection system also includes a cloud storage module, which is used to manage and store the user data ciphertext uploaded by the client, and provide upload, deletion, query and download functions to the outside world; the client also includes a data synchronization module, which is responsible for uploading the user data ciphertext to the cloud storage module on the server side, or downloading and obtaining the user data ciphertext from the cloud storage module on the server side.

5. According to claim 2, the terminal security protection method based on digital certificate UKEY technology is characterized in that: The security protection system also includes a display module, which is responsible for providing a user interface display interface for the digital certificate UKEY and other modules of the client.

6. The terminal security protection method based on digital certificate UKEY technology according to claim 2 is characterized in that: The client also includes a digital certificate UKEY calling library, which encapsulates the software interface and driver of the digital certificate UKEY for calling by other modules of the client.

7. The terminal security protection method based on digital certificate UKEY technology according to claim 2 is characterized in that: The server side also includes a hardware asset management module, which is responsible for managing the asset information of all digital certificates UKEY delivered for use, and the asset information includes the ID of the digital certificate UKEY and the signed public key information.

8. The terminal security protection method based on digital certificate UKEY technology according to claim 2 is characterized in that: After generating the user data ciphertext in step F, the client requests the server to obtain a challenge value; the server generates the challenge value and returns it to the client; The client calls the digital certificate UKEY and uses its own private key to encrypt and sign the challenge value to generate signature information; The client sends a signature verification request to the server based on the signature information; The server receives the signature information and uses the public key of the digital certificate UKEY to decrypt and verify the signature. After the verification is successful, the credential information is generated and returned to the client; the client sends a service request to the server, and the service request includes at least the service content and the credential information; the server processes the service content according to the credential information.

9. The terminal security protection method based on digital certificate UKEY technology according to claim 8 is characterized in that: After generating the credential information and returning it to the client, the client sends a data upload request to the server, and the data upload request includes at least the user data ciphertext and the credential information; the server stores the received user data ciphertext in the user storage directory of the cloud storage module according to the credential information.

10. The terminal security protection method based on digital certificate UKEY technology according to claim 8 is characterized in that: After generating the credential information and returning it to the client, the method also includes: the client sends a download data request to the server, and the download data request includes at least a download data range and the credential information; the server pushes the corresponding user data ciphertext to the client based on the credential information and the download data range, and stores it in the user storage directory in the local storage module.