Business processing method and device, electronic equipment and storage medium
By generating public-private key pairs in the terminal, signing and encrypting business operation information, security risks in data transmission are solved, and security of information transmission and fast identity authentication are achieved.
Patent Information
- Application Number
- CN202510403562.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-04
AI Technical Summary
During the authentication of the existing technology service platform, although the security of code and user identity authentication data is guaranteed on the cloud server side, it fails to effectively protect the security of the data during transmission, which poses security risks.
By generating public and private key pairs in the terminal, using the terminal's private key to sign the business operation information, and encrypting it with the server's public key to generate ciphertext information. After transmission to the server, the server's private key is decrypted and verified to ensure the security of information transmission.
It realizes security during information transmission, prevents non-specified servers from stealing and cracking, and improves the credibility of identity authentication and rapid authentication efficiency.
Smart Images

Figure CN120257260A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology. Specifically, this application relates to a service processing method, apparatus, electronic device, and storage medium. Background Art
[0002] In recent years, with the continuous development of the service industry, the technology service industry has become an important part of the modern service industry. Most applications such as the Internet, Internet of Things, Internet of Vehicles, medical imaging, security monitoring, finance, and telecommunications rely on interacting with users through APP programs, and the process requires users to register. Moreover, when users log in to the APP subsequently, the identity information of the users needs to be authenticated.
[0003] When the existing technology service platforms perform identity authentication, they usually load the codes used for verification and user identity authentication data into a preset loading container in the cloud server for identity verification to protect them from any software attacks. That is to say, once the codes and data are in the loader, even the operating system cannot affect the codes and data inside the loader. Using this method can ensure the security of the codes and user identity authentication data, thus ensuring the security and reliability of the identity authentication process.
[0004] However, the above solution only considers the security of identity authentication on the cloud server side during identity verification, but does not consider the security of the verification data obtained when obtaining the identity authentication data, that is, it cannot ensure the data security during the process of transmitting the verification data from the user terminal to the cloud server side. Currently, there are still certain security risks in the existing solutions. Summary of the Invention
[0005] The purpose of this application aims to solve at least one of the above technical defects. The technical solutions provided by the embodiments of this application are as follows: In a first aspect, an embodiment of this application provides a service processing method, which is applied to a terminal and includes: In response to a service operation for the terminal, generate first service operation information of the service operation, and obtain the first public key of the server; Based on the first private key of the terminal determined in advance, sign the first service operation information to obtain a first signature value; Encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information; Send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on the second public key of the terminal determined in advance and the second private key of the server, and processes the first service operation information after the decryption and signature verification pass, obtains and returns a service operation result; Receive and display the service operation result.
[0006] In a second aspect, an embodiment of the present application provides a service processing method, which is applied to a server side and includes: Receiving first ciphertext information sent by a terminal; wherein, the first ciphertext information is obtained by the terminal encrypting a first service operation information and a first signature value generated in response to a service operation for the terminal based on a first public key of the server; the first signature value is obtained by signing the first service operation information based on a first private key of the terminal; Obtaining a second public key of the terminal, and decrypting and verifying the signature of the first ciphertext information based on the second public key and a second private key of the server determined in advance to obtain a decryption and signature verification result; If the decryption and signature verification result is passed, processing the first service operation information to obtain a service operation result, and returning the service operation result to the terminal so that the terminal receives and displays the service operation result.
[0007] In a third aspect, an embodiment of the present application provides a service processing apparatus, including: An operation information acquisition module, configured to generate first service operation information of a service operation in response to a service operation for a terminal, and obtain a first public key of the server; A signature module, configured to sign the first service operation information based on a first private key of the terminal determined in advance to obtain a first signature value; An encryption module, configured to encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information; A ciphertext information sending module, configured to send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on a second public key of the terminal determined in advance and a second private key of the server, and processes the first service operation information after the decryption and signature verification is passed to obtain and return a service operation result; An operation result display module, configured to receive and display the service operation result.
[0008] In a fourth aspect, an embodiment of the present application provides a service processing apparatus, including: A ciphertext information receiving module, configured to receive first ciphertext information sent by a terminal; wherein, the first ciphertext information is obtained by the terminal encrypting a first service operation information and a first signature value generated in response to a service operation for the terminal based on a first public key of the server; the first signature value is obtained by signing the first service operation information based on a first private key of the terminal; A decryption and signature verification module, configured to obtain a second public key of the terminal, and decrypt and verify the signature of the first ciphertext information based on the second public key and a second private key of the server determined in advance to obtain a decryption and signature verification result; A service information processing module, which is configured to, if the decryption and signature verification result is passed, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal, so that the terminal receives and displays the service operation result.
[0009] In a fifth aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory; The processor executes the computer program to implement the method provided in the embodiment of the first aspect or any optional embodiment of the first aspect.
[0010] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method provided in the embodiment of the first aspect or any optional embodiment of the first aspect is implemented.
[0011] The beneficial effects brought by the technical solution provided in the embodiment of the present application are as follows: In the solution provided by the present application, when a target object initiates a service operation to a certain server through a terminal, the terminal generates first service operation information about the current service operation, and signs and encrypts the first service operation information with the private key of its own terminal and the public key of the server, so that the signed and encrypted first service operation information cannot be stolen or cracked by other terminals or servers except the server designated by the target object, thereby ensuring the security during the information transmission process.
[0012] Furthermore, in the embodiment of the present application, the identity information of the user and the device information of the terminal are bound when the user registers, so that the server can map to the corresponding user (identity) when the identity verification is passed, achieving the effect of fast identity authentication.
[0013] At the same time, during the identity authentication process, the generation and destruction of public and private keys are performed through a trusted carrier, and the PKI (Public Key Infrastructure) technology is adopted during the data transmission process, providing a security area independent of the main operating system to protect sensitive code and data from external threats, and improving the credibility during the identity authentication process. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments of the present application.
[0015] Figure 1 It is a schematic flowchart of a service processing method provided by an embodiment of the present application; Figure 2Structural flowchart of the business processing process in an example of the embodiment of the present application; Figure 3 Structural flowchart of the third-party authorization process in an example of the embodiment of the present application; Figure 4 Flowchart of a business processing method provided by the embodiment of the present application; Figure 5 Structural flowchart of the account registration process in an example of the embodiment of the present application; Figure 6 Structural flowchart of the account cancellation process in an example of the embodiment of the present application; Figure 7 Structural flowchart of the user account registration process in an example of the embodiment of the present application; Figure 8 Structural flowchart of the process for a user to conduct a transfer business in an example of the embodiment of the present application; Figure 9 Flowchart of the process for processing a business request through a third-party program in an example of the embodiment of the present application; Figure 10 Structural block diagram of a business processing device provided by the embodiment of the present application; Figure 11 Structural block diagram of a business processing device provided by the embodiment of the present application; Figure 12 Structural diagram of an electronic device provided by the embodiment of the present application. Detailed implementation manners
[0016] The embodiments of the present application will be described below with reference to the accompanying drawings in the present application. It should be understood that the embodiments described below in conjunction with the drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation to the technical solutions of the embodiments of the present application.
[0017] Those skilled in the art can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the terms "comprising" and "including" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation of other features, information, data, steps, operations, elements, components and / or their combinations supported by the technical field of the present application. It should be understood that when we say an element is "connected" or "coupled" to another element, the element can be directly connected or coupled to the other element, or it can mean that the element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein indicates at least one of the items defined by the term. For example, "A and / or B" can be implemented as "A", or implemented as "B", or implemented as "A and B".
[0018] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0019] The technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application will be described below through the description of several exemplary embodiments. It should be noted that the following embodiments can be referenced, learned from or combined with each other. For the same terms, similar features and similar implementation steps in different embodiments, they will not be described repeatedly.
[0020] Figure 1 A flowchart of a service processing method is provided for an embodiment of the present application. The execution subject of this method can be a terminal (such as a computer, a mobile phone, etc.), as Figure 1 shown, this method may include: Step S101, in response to a service operation on the terminal, generate first service operation information of the service operation, and obtain the first public key of the server.
[0021] In an embodiment of the present application, a service operation may be initiated by a target object, which may be the user who holds the terminal. The service operation may be a triggering operation on a certain service function of an application installed on the terminal. The triggering method may be to click on the service function control of the application displayed on the terminal. For example, clicking on the "transfer service" control (this click operation is a service operation) indicates triggering the transfer function. The type of the specific service function is not limited in the embodiment of the present application. The first service operation information may be a service operation presented in the form of data, which may include service data and the identification information of the terminal, and is used for subsequent processing by the terminal. The first public key may be a public key pre-set by the server pointed to by the service operation. This public key is in a publicly available state. The terminal may pre-obtain and store the first public keys of multiple servers, or may also initiate a request for acquisition to the corresponding server only when needed. The embodiment of the present application does not limit this here.
[0022] Specifically, when a user (i.e., the target object, the embodiment of the present application will take the user as an example for illustration below) needs to perform a service operation directed to a certain server, the user can first log in to the corresponding APP (Application) on the terminal. After successful login, the user can trigger the corresponding service operation through the terminal. This operation may be to click on any control in the APP displayed on the terminal. After the terminal detects the triggered service operation, it will generate and convert this service operation into the corresponding digital first service operation information, and at the same time obtain the first public key of the server pointed to by this service operation.
[0023] Step S102: Sign the first service operation information based on the first private key of the terminal determined in advance to obtain a first signature value.
[0024] In an embodiment of the present application, the first private key may be the private key in the public-private key pair pre-generated by the terminal.
[0025] Specifically, after the terminal generates the first service operation information, in order to ensure the security of the first service operation information, the terminal may perform a signature process on the first service operation information to obtain the corresponding first signature value. And the first signature value can only be confirmed as a real message after being verified by the public key corresponding to the first private key. Since the first private key is only held by the terminal, only the first signature value sent by this terminal can be successfully verified by the server, thus ensuring the authenticity of the transmission of the first service operation information.
[0026] Step S103: Encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information.
[0027] In an embodiment of the present application, the first public key may be the public key in the public-private key pair pre-generated by the server.
[0028] Specifically, to ensure the security of the user's service operations, the terminal can further encrypt the information after the above signature step. Specifically, the terminal can use the first public key of the server that has been obtained to encrypt the first service operation information and the first signature value respectively. In this way, only the server holding the corresponding private key can decrypt and read the encrypted information, ensuring the security of information transmission. Generally speaking, separate encryption will result in multiple different ciphertexts. In the embodiments of the present application, the multiple ciphertexts obtained by separate encryption are jointly used as the first ciphertext information.
[0029] Step S104: Send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on the second public key of the terminal determined in advance and the second private key of the server, and processes the first service operation information after the decryption and signature verification pass, to obtain and return the service operation result.
[0030] In the embodiments of the present application, the second public key is the public key paired with the first private key of the terminal. The second private key is the private key paired with the first public key of the server.
[0031] Specifically, after the encryption is completed, the terminal sends the encrypted first ciphertext information to the server corresponding to the current service operation. After receiving the first ciphertext information, the server can obtain the second public key of the terminal according to the terminal that sent the first ciphertext information (this obtaining process can be to obtain it from the terminal immediately, or to obtain it from the public key library pre-stored by the server, etc., and the embodiments of the present application do not limit this here), and then start the steps of decryption and signature verification. Specifically, the server can first use its own second private key to decrypt the first ciphertext information. After successful decryption, the first service operation information and the first signature value can be obtained, and then the first signature value can be verified based on the second public key of the terminal. After successful signature verification, the corresponding service operation can be processed according to the first service operation information. After the processing is completed, the service operation result corresponding to the current service operation is obtained, and this service operation result is returned to the terminal.
[0032] Step S105: Receive and display the service operation result.
[0033] Specifically, after the terminal receives the service operation result sent by the server, it can display the service operation result to the user. The service operation result can include a prompt message indicating successful service processing and the data result after successful processing, or include a prompt message indicating failed service processing and the reason for the failure, etc.
[0034] The specific interaction process can be as Figure 2As shown, the user needs to first log in to the account on the terminal. The terminal verifies this login operation. After the verification passes, the identity information of the user account is displayed. Then, the user can initiate a business operation request that needs to be performed to the server through the terminal. The terminal uploads its device information (which can be a device identifier) and the business data required for this business operation to the server (i.e., the cloud service in the figure) after signing and encrypting them with its own first private key and the first public key of the server. The server decrypts and verifies the signature of the data uploaded by the terminal according to the second public key of the terminal and its own second private key. After the decryption and signature verification pass, a business data interaction process is established with the terminal to process the business operation request sent by the terminal.
[0035] In the solution provided by this application, when the target object initiates a business operation to a certain server through the terminal, the terminal generates the first business operation information about this business operation, and signs and encrypts the first business operation information with the private key of its own terminal and the public key of the server, so that the first business operation information after signature encryption cannot be stolen or cracked by other terminals or servers except the server specified by the target object, thus ensuring the security during the information transmission process.
[0036] Based on the above various embodiments, as an optional embodiment, the first private key and the second public key are determined in the following manner: In response to the account registration operation initiated by the target object, obtain the real-time biometric information input by the target object; Compare the real-time biometric information with the pre-authenticated biometric information corresponding to the target object to obtain the matching degree; When the matching degree is not less than the preset threshold, the target object is registered, the login account information of the target object is generated, and a public-private key pair of the terminal is randomly generated; among them, the public-private key pair includes the first private key and the second public key.
[0037] In the embodiments of this application, the biometric information can also be called biometric features. The real-time biometric information can be the current real-time face information of the user, and the specific manifestation form can be a face photo. The pre-authenticated biometric information can be the authoritative certified photo of this user (such as the photo on the ID card, the photo on the driver's license), etc. The embodiments of this application do not make limitations here.
[0038] Specifically, in the embodiments of the present application, before a user logs in to the account of the APP through the terminal, the user needs to first register the account; the user can initiate an account registration operation to the terminal by clicking the "Register" control on the APP displayed on the terminal. In response, the terminal can activate the camera function so that the user can take a real-time photo of himself through the camera function and upload his real-time face image (i.e., real-time biometric information, and the real-time biometric information can also be in other forms. In the embodiments of the present application, the face image is taken as an example, and the present application embodiments do not make any limitations on other forms here), and then upload his other certified ID photos (i.e., pre-certified biometric information. If the real-time biometric information is not in the form of a face image, the pre-certified biometric information is also in other corresponding forms). The terminal can compare the features of the real-time face image with the face image on the other certified ID photos and calculate the matching degree between the two.
[0039] When the matching degree is less than the preset threshold, it can be considered that the identity information provided by the currently registering user is not true. Therefore, the current registration request of the user can be directly rejected; when the matching degree is not less than the preset threshold, it can be considered that the identity information provided by the currently registering user is relatively true, and then the account registration operation for the user can be enabled, generate the login account information about the user, and at the same time randomly generate a public-private key pair of the terminal in the preset trusted carrier of the terminal. The public-private key pair consists of the first private key and the second public key described above.
[0040] It should be noted that the trusted carrier in the solution of the present application can be a chip in the terminal (such as TEE (trusted execution environment, an area on the CPU (central processing unit) of the terminal), SE (Secure Element, security element), etc.). The trusted carrier can provide a security area independent of the main operating system to protect sensitive code and data from external threats. When the user registers successfully, the public-private key pair of the terminal can be generated in the trusted carrier to directly bind the terminal to the user, so that the subsequent connection with the server has a faster authentication speed and can improve the service processing efficiency.
[0041] Based on the above various embodiments, as an optional embodiment, registering a target object and generating the login account information of the target object specifically includes: Display at least one preset login entry type; In response to the selection operation of the target object for the target login entry type, display the login information setting interface corresponding to the target login entry type; Receive the login information input by the target object through the login information setting interface, associate the login information with the device information of the terminal, and use them together as the login account information of the target object.
[0042] In the embodiments of the present application, the preset login entry type can be used as an attribute of the login information, and can also be referred to as the account login method. The type can include but is not limited to face login type, fingerprint login type, password login type, verification code login type or other login method types. The embodiments of the present application do not make limitations here. The login information setting interface is the login information set by the user during account login; the login information corresponds to the preset login entry type. For example, the login information corresponding to the face login type is the actual face image of the user, the login information corresponding to the fingerprint login type is the fingerprint of the user, and the login information corresponding to the password login type is the password set by the user, etc.
[0043] Specifically, when the terminal registers an account for the user, it can display multiple optional account login methods (i.e., preset login entry types) to the user. The user can select a suitable account login method according to their own preferences during registration; after the user selects one of the login entry types as the target login entry type, the corresponding login information setting interface is displayed so that the user can set the login information required during login. After the user's setting is completed, the association relationship between the login information and the device information of the terminal can be bound. The bound association relationship can be uploaded to the server or stored locally on the terminal, or other methods, etc. The embodiments of the present application do not make limitations here; when the user logs in, the stored login information can be used to verify the user's login process.
[0044] It should be noted that in the embodiments of the present application, the login information can be included in the first service operation information in the service operation triggered by the user, and is used to be signed together with the first private key of the terminal. In this way, the server can obtain the login information when decrypting and verifying the signature through the second public key of the terminal in the subsequent process, that is, "obtain the login information corresponding to the user by decrypting and verifying the signature through the public key of the terminal", verify the binding relationship between the terminal and the user, and thus achieve the effect of fast authentication.
[0045] Through the solution provided in this embodiment, when a user registers, a corresponding association relationship is established and stored between the registration information input by the user and the device information of the terminal used during registration. When the user logs in subsequently, the true identity of the login person can be verified based on the identity information input by the user during login and the device information of the terminal used during login. Only when it is detected that there is a stored association relationship between the identity information input by the login person and the device information of the used terminal can the identity accuracy of the login person be confirmed, and then the initial interface of the corresponding account is displayed. (That is, an "identity authentication framework of person-terminal-user"). The advantage of the above process is that when the user logs in, the user only needs to input the identity information set by himself. After the terminal receives the identity information input by the user, the device information of the terminal itself is signed with the first private key of the terminal to obtain a corresponding signature value, and then the signature value is encrypted with the first public key of the server, and then the encrypted ciphertext information and the identity information input by the user are sent to the server together. After the server verifies the terminal device information and the user identity information corresponding to the terminal, it can confirm that the user logs in to the account with his own will and allows the user to log in successfully. Since the user's identity information and the terminal's device information are bound when the user registers, the server can map to the corresponding user (identity) when the identity verification is passed, achieving the effect of fast identity authentication.
[0046] Optionally, the login information input by the user can also be processed by an irreversible algorithm (such as hashing) first, and then only the processed login information is stored during storage. Then when the user logs in, the login information input by the user is processed by the same irreversible process again, and the processing result is compared with the stored processing result. If they are the same, the user is allowed to log in successfully; otherwise, the user is prompted that the login fails. The advantage of the above process is that even if the server or terminal storing the processed login information is attacked and leaked, the processed login information cannot be used to deduce the corresponding original login information because it has been processed by an irreversible algorithm, which can further ensure the security of the user's personal information.
[0047] Based on the above various embodiments, as an alternative embodiment, the method further specifically includes: In response to the authorization operation of the target object for a third-party program, display an authorization entry for authorizing the third-party program; In response to the interaction operation between the target object and the authorization entry, obtain the device information of the terminal and the second signature value obtained by signing the device information with the first private key; Send the device information and the second signature value to a third-party program, so that the third-party program sends a service processing request to the server based on the device information and the second signature value, and receives the processing result of the service processing request returned by the server.
[0048] In the embodiments of the present application, the third-party program may be an application program provided by other servers except the server described above. The authorization entry may be in the form of a two-dimensional code or a trigger control for verifying verification codes, etc., and the embodiments of the present application do not make limitations here.
[0049] Specifically, the embodiments of the present application also provide a method for a terminal to authorize a third-party program so that the third-party program can perform business interactions with the server. Specifically, the user can first open the authorization entry on the terminal, and then interact with the authorization entry (for example, if the authorization entry is in the form of a two-dimensional code, use the third-party program to scan the two-dimensional code). After detecting the interaction operation, the device information of the terminal can be signed with the first private key to obtain the second signature value, and then the original terminal device information and the second signature value are sent to the third-party program together (that is, the terminal device has completed the authorization of the third-party program). After receiving the second signature value and the terminal device information, the third-party program can encrypt the device information, the second signature value, and the service data required for the service processing request in a manner pre-agreed with the server, and then upload the encrypted data to the server. The server can decrypt it in a manner pre-agreed with the third-party program, and then verify the signature of the second signature value with the second public key. After the signature verification passes, the server processes the service data sent by the third-party program and directly returns the processing result to the third-party program.
[0050] The specific authorization process may be as Figure 3 shown. The user first logs in to the account on the terminal. After the terminal verifies the login operation and passes, it displays the identity information of the user account. Then, in response to the user's operation of opening the authorization entry, the terminal displays the authorization entry. The user interacts with the authorization entry through a third-party application (that is, the third-party program) (such as scanning the code, etc.), so that the third-party application obtains the device information of the terminal and the signed second signature value. After that, the third-party application encrypts the device information, the second signature value, and the service data of the service request to be performed in a manner pre-agreed with the server and uploads it to the server. The server decrypts and verifies the signature of the information uploaded by the third-party application. After the decryption and signature verification pass, the server processes the service request of the third-party application and directly returns the processing result to the third-party application.
[0051] It should be noted that in some application scenarios, the processing result can also be signed based on the second private key and then encrypted based on the second public key to obtain the ciphertext of the processing result, and the ciphertext is synchronously sent to the terminal so that the terminal can record the business processing of the third-party program.
[0052] Figure 4 The following is a schematic flowchart of a business processing method provided by an embodiment of the present application. The execution subject of this method can be a server, such as Figure 4 shown, this method may include: Step S401, receiving the first ciphertext information sent by the terminal; wherein, the first ciphertext information is obtained by the terminal encrypting the first service operation information and the first signature value generated in response to the service operation for the terminal based on the first public key of the server; the first signature value is obtained by signing the first service operation information based on the first private key of the terminal.
[0053] Step S402, obtaining the second public key of the terminal, and decrypting and verifying the signature of the first ciphertext information based on the second public key and the second private key of the server determined in advance to obtain the decryption and signature verification result.
[0054] Step S403, if the decryption and signature verification result passes, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal so that the terminal can receive and display the service operation result.
[0055] In the embodiment of the present application, the service operation can be initiated by a target object. The target object can be the user who holds the terminal. The service operation can be a trigger operation for a certain service function of a certain application program installed on the terminal. The trigger method can be to click the service function control of the application program displayed on the terminal. For example, clicking the "transfer service" control (this click operation is a service operation) means triggering the transfer function. The type of the specific service function is not limited in the embodiment of the present application. The first service operation information can be a service operation presented in data form, which can include service data and the identification information of the terminal, and is used for the terminal to perform subsequent processing. The first public key can be a public key pre-set by the server pointed to by the service operation. This public key is in a publicly available state. The terminal can pre-obtain and store the first public keys of multiple servers, or can also initiate a request to obtain the corresponding server only when needed. This is not limited in the embodiment of the present application. The first private key can be the private key in the public-private key pair pre-generated by the terminal. The second public key is the public key paired with the first private key of the terminal. The second private key is the private key paired with the first public key of the server.
[0056] Specifically, when a user (i.e., the target object, and the embodiments of the present application will take the user as an example hereinafter) needs to perform a service operation directed to a certain server, the user can first log in to the corresponding APP (Application) on the terminal. After successful login, the user can trigger the corresponding service operation through the terminal. This operation can be to click on any control in the APP displayed on the terminal. After the terminal detects the triggered service operation, it will generate the service operation and convert it into corresponding digital first service operation information, and at the same time obtain the first public key of the server pointed to by the service operation.
[0057] After the terminal generates the first service operation information, to ensure the security of the first service operation information, the terminal can perform signature processing on the first service operation information to obtain the corresponding first signature value. The first signature value can only be confirmed as real information after being verified by the public key corresponding to the first private key. Since the first private key is only held by the terminal, only the first signature value sent by this terminal can be successfully verified by the server, thus ensuring the authenticity of the transmission of the first service operation information.
[0058] To ensure the security of the user's service operation, the terminal can further encrypt after the above signature step. Specifically, the terminal can use the obtained first public key of the server to encrypt the first service operation information and the first signature value respectively. In this way, the encrypted information can only be decrypted and read by the server holding the corresponding private key, ensuring the security during information transmission. Generally speaking, separate encryption will obtain multiple different ciphertexts. In the embodiments of the present application, the multiple ciphertexts obtained by separate encryption are jointly used as the first ciphertext information.
[0059] After the terminal completes the encryption, it sends the encrypted first ciphertext information to the server corresponding to this service operation. After receiving the first ciphertext information, the server can obtain the second public key of the terminal in advance according to the terminal that sent the first ciphertext information (this obtaining process can be to obtain it immediately from the terminal, or to obtain it from the public key library pre-stored by the server, etc., and the embodiments of the present application do not limit this here), and then start the steps of decryption and verification. Specifically, the server can first decrypt the first ciphertext information with its own second private key. After successful decryption, it can obtain the first service operation information and the first signature value, and then verify the first signature value based on the second public key of the terminal. After successful verification, it can perform corresponding service operation processing according to the first service operation information. After the processing is completed, it obtains the service operation result corresponding to this service operation and returns this service operation result to the terminal.
[0060] After receiving the service operation result sent by the server, the terminal can display the service operation result to the user. The service operation result may include a prompt message indicating successful service processing and the data result after successful processing, or may include a prompt message indicating failed service processing and the reason for the failure, etc.
[0061] In the solution provided by this application, when the target object initiates a service operation to a certain server through the terminal, the terminal generates first service operation information about the current service operation, and signs and encrypts the first service operation information using its own private key and the public key of the server, so that the first service operation information after signature encryption cannot be stolen or cracked by other terminals or servers except the server specified by the target object, thus ensuring the security during the information transmission process.
[0062] Based on the above various embodiments, as an optional embodiment, the first ciphertext information includes a first ciphertext and a second ciphertext; the first ciphertext is obtained by encrypting the first service operation information based on the first public key; the second ciphertext is obtained by encrypting the first signature value based on the first public key; Decrypt and verify the signature of the first ciphertext information based on the second public key and the second private key of the pre-determined server to obtain the decryption and signature verification result, including: Perform a decryption operation on the first ciphertext based on the second private key to obtain the first service operation information, and perform a decryption operation on the second ciphertext based on the second private key to obtain the first signature value; Verify the signature of the first signature value based on the second public key to obtain the second service operation information, and compare the second service operation information with the first service operation information. If the comparison result is the same, return a passed decryption and signature verification result; otherwise, return a failed decryption and signature verification result.
[0063] Specifically, after receiving the first ciphertext information sent by the terminal, the server first needs to decrypt the first ciphertext information. Since the terminal uses the server's own first public key during encryption, the server needs to use its own second private key paired with the first public key for decryption during decryption. If the decryption fails, it means that the information has been tampered with during the transmission of the terminal's uploaded information, that is, there is a security risk in this transaction, and a prompt message of "service request processing failed" can be directly returned to the terminal. After successful decryption, the first service operation information and the first signature value can be obtained respectively.
[0064] After that, the identity of the terminal that uploads the information will be verified, that is, the second service operation information (i.e., signature verification operation) will be deduced based on the second public key and the first signature value, and then the deduced second service operation information will be compared with the original first service operation information. If the comparison result is the same, it can be confirmed that the terminal that uploads the information is this terminal (since only the terminal itself holds the first private key corresponding to the second public key, so only the terminal itself can perform the signature operation), and a passed decryption and signature verification result will be returned to this terminal; if the comparison result is different, it cannot be confirmed whether the terminal that uploads the information is this terminal, and at the same time, a failed decryption and signature verification result will be returned to this terminal.
[0065] Optionally, when the terminal signs the first service information based on the first private key, it can also sign its own second public key at the same time. When the server performs signature verification, it can further verify the deduced public key, which can further improve security. At the same time, it should be noted that in actual operation, any data that needs to be signed can also be added during the signature according to actual requirements, and the embodiments of the present application do not limit this here.
[0066] Based on the above various embodiments, as an optional embodiment, the method further specifically includes: Receiving an account registration request for a target object sent by the terminal; wherein, the account registration request includes at least one piece of identity information of the target object and the device information of the terminal, and the identity information is sent together when the target object inputs an identity registration instruction to the terminal; Assembling based on each piece of identity information and a preset service data template to generate service data about the target object, and combining the pre-stored root key and the device information of the terminal to generate a decentralized key about the terminal; Encrypting the service data based on the decentralized key to obtain a third ciphertext; Signing the third ciphertext and the decentralized key together based on the second private key to obtain a third signature value; Encrypting the third ciphertext, the decentralized key, and the third signature value based on the second public key to obtain second ciphertext information; Sending the second ciphertext information to the terminal, so that the terminal decrypts and verifies the second ciphertext information based on the first private key and the first public key, and stores the decentralized key and the third ciphertext after the decryption and signature verification pass. After the target object logs in to the account, the terminal decrypts the third ciphertext based on the decentralized key to obtain the service data and then displays it.
[0067] In the embodiments of the present application, the service data template may be a preset template of an application program on the terminal, and multiple account data items to be filled in may be set in the template. The split key is a symmetric key composed of a root key and a split factor. In the embodiments of the present application, the split factor may be a string of terminal device information, that is, the function of corresponding each split key to a terminal is realized.
[0068] Specifically, when a user performs identity registration, the terminal will send the identity information input by the user and the device information of the terminal itself to the server. The server can obtain the initial service data corresponding to the user according to the identity information, and assemble the initial service data with the preset service data template to obtain the actual service data of the user. At the same time, a split key for the terminal is generated. The specific generation method may be to first convert the device information of the terminal into a corresponding string form, and then combine the pre-stored root key and the string. After combination, the split key of the terminal can be obtained.
[0069] After generating the split key, the generated service data can be encrypted with the split key to generate a third ciphertext, and then the third ciphertext and the split key are signed together with the second private key to obtain a third signature value. After signing, the third ciphertext, the split key, and the third signature value are encrypted with the second public key respectively to obtain second ciphertext information, and the second ciphertext information is jointly composed of the above-mentioned ciphertexts.
[0070] After the second ciphertext information is generated, the second ciphertext information is sent to the terminal. The terminal can first decrypt the second ciphertext information based on the first private key, and then perform a signature verification operation on the third signature value based on the first public key. The decryption and signature verification process is similar to the process described above, and will not be elaborated here. After the decryption and signature verification pass, the terminal can store the split key and the third ciphertext. After the user logs in to the account, the service data of the user account after decrypting the third ciphertext with the split key is displayed on the initial interface.
[0071] It should be noted that in the embodiments of the present application, only the root key is stored on the server side, and the split key is stored separately by the corresponding terminal. The split key can also be used to encrypt data when needed, and in some scenarios, the processing efficiency is superior to the public-private key encryption method, which can improve the user experience. For the server, if it receives data encrypted with the split key from the terminal, it can obtain the corresponding string according to the terminal identification information synchronously uploaded by the terminal, and then combine the string and the root key to obtain the corresponding split key to decrypt the data.
[0072] The specific registration process can be as Figure 5As shown, when a user registers, first the user needs to upload their certified ID photo and their real-time face image to the terminal. The terminal compares the ID photo uploaded by the user with the real-time photo for person-ID verification. After the verification passes, the user can select a suitable login method for setting and enter the corresponding login information (if it is user feature login information such as fingerprint or face, it can also be called biometric feature). After the setting is completed, the trusted carrier in the terminal randomly generates a public-private key pair for the terminal (i.e., the first private key and the second public key), and then uploads the device information and its public key to the server. Subsequently, the server can generate a corresponding dispersion key based on the device information of the terminal, then encrypt the service data with the dispersion key, and then perform signature encryption processing on each required information to obtain the second ciphertext information, and return the encrypted second ciphertext information to the terminal. After receiving the second ciphertext information, the terminal performs step-by-step decryption and signature verification operations to obtain the dispersion key and the data ciphertext (i.e., the third ciphertext), and finally stores the dispersion key and the data ciphertext together in the trusted carrier.
[0073] Optionally, in the embodiment of the present application, a symmetric key for encrypting the service data of the target object can also be generated by the terminal itself. Correspondingly, when the symmetric key is generated by the terminal, since there is no dispersion key for encrypting the service data generated in the server, only the second private key of the server is used to sign the service data of the target object to obtain the corresponding sixth signature value, and the sixth signature value and the service data are encrypted based on the second public key of the terminal to obtain the fourth ciphertext information, and the fourth ciphertext information is sent to the terminal; after receiving the fourth ciphertext information, the terminal first decrypts the fourth ciphertext information based on its own first private key to obtain the sixth signature value and the service data, and then performs a signature verification operation on the sixth signature value and the service data based on the first public key of the server; after the signature verification passes, the service data is encrypted based on the symmetric key generated by the terminal itself to obtain the corresponding seventh ciphertext. Subsequently, when the target object logs in through the account, the seventh ciphertext can be directly decrypted based on the symmetric key generated by the terminal itself to obtain the service data and display it.
[0074] Based on the above various embodiments, as an optional embodiment, the method further specifically includes: Receiving an identity cancellation request sent by the terminal regarding the target object; wherein, the identity cancellation request contains the third ciphertext information, and the third ciphertext information contains the fourth ciphertext and the fifth ciphertext; the fourth ciphertext is obtained by the terminal encrypting the device information and the identity cancellation data representing the identity cancellation operation with the first public key; the fifth ciphertext is obtained by the terminal encrypting the device information and the fourth signature value obtained by signing the identity cancellation data with the first public key. Decrypt and verify the signature of the third ciphertext information based on the second private key and the second public key, and generate a signature verification passed message after the decryption and signature verification are passed; Sign the signature verification passed message based on the second private key to obtain a fifth signature value, encrypt the fifth signature value based on the second public key to obtain a sixth ciphertext, and set the second public key to invalid; Send the sixth ciphertext to the terminal so that the terminal decrypts and verifies the signature of the sixth ciphertext, and destroys the third ciphertext, the dispersion key of the terminal, the first private key, and the second public key after the decryption and signature verification are passed.
[0075] In the embodiment of the present application, the identity cancellation data may be code data regarding an identity cancellation request.
[0076] Specifically, when a user needs to cancel their account, they can initiate an identity cancellation operation through the terminal. The terminal generates a corresponding identity cancellation request according to the identity cancellation operation, and then sends the identity cancellation request to the server. The server decrypts and verifies the signatures of the various ciphertexts included in the identity cancellation request. Specifically, the fourth ciphertext can be decrypted through the second private key to obtain device information and identity cancellation data; the fifth ciphertext is decrypted through the second private key to obtain the device information and the fourth signature value of the identity cancellation data; where the fourth signature value is the terminal's signature of the device information and the identity cancellation data based on the first private key. After the decryption is completed, the server then verifies the signature of the fourth signature value based on the second public key, compares the deduced identity cancellation data with the decrypted identity cancellation data, and generates a corresponding decryption and signature verification result according to the comparison result.
[0077] After the decryption and signature verification are passed, a signature verification passed message is obtained, and then the signature verification passed message is signed based on the second private key to obtain a fifth signature value and encrypted through the second public key to obtain an encrypted sixth ciphertext. At the same time, since the server's decryption and signature verification of the terminal have passed, the server can set the second public key of the terminal stored to invalid or directly delete it to complete the identity cancellation operation process on the server side.
[0078] After the encryption is completed, the server sends the sixth ciphertext to the terminal. The terminal can first decrypt the sixth ciphertext based on the first private key to obtain the fifth signature value, and then verify the signature of the fifth signature value based on the first public key. After the signature verification is passed, the terminal can know the result that the server has successfully cancelled. At this time, the terminal can destroy the third ciphertext, the dispersion key, and the public-private key pair of the terminal (i.e., the first private key and the second public key) previously stored in the trusted carrier, that is, complete the account cancellation operation process on the terminal side.
[0079] The specific cancellation process can be as Figure 6As shown, the user first logs in to the account on the terminal (taking the login method of verifying biometric features as an example in the figure). After the terminal verification passes, the user's account identity information is displayed. The user initiates an operation to cancel the account on the terminal. In response to the user's account cancellation operation, the terminal encrypts and uploads the device information (i.e., device identifier) and identity cancellation data (not marked in the figure) to the server after signing. The server can then decrypt the information uploaded by the terminal and perform signature verification operations. After the signature verification operation passes, the server returns an encrypted prompt message indicating that the signature verification has passed to the terminal. At the same time, the server will set the second public key of the terminal that has been obtained to invalid to complete the identity cancellation operation on the server side. After receiving the encrypted prompt message indicating that the signature verification has passed sent by the server, the terminal can delete the split key sent by the server, the public-private key pair generated by the terminal itself, and the ciphertext corresponding to the service data (i.e., the third ciphertext mentioned above) from the trusted carrier to complete the identity cancellation operation of the terminal.
[0080] Next, several specific implementation scenario provided by the solution of the present application will be introduced. Figure 7 It is a schematic diagram of the user account registration process in the solution of the present application, as Figure 7As shown in the figure, the user first uploads the authenticated ID photo and real-time face photo to the APP on the mobile phone for the verification of the unity of person and certificate. After the verification passes, the user can select a suitable login method. Taking the fingerprint login method as an example, the user can enter their own fingerprint as the login information in the login information setting interface, and can also enter their identity information. Then, the SDK (Software Development Kit) of the mobile phone sends the identity information and the device information of the mobile phone itself to the trusted carrier TEE of the mobile phone. The TEE creates a public-private key pair for the mobile phone based on the identity information and device information, and signs the identity information, device information, and public key (i.e., the second public key) with the private key (i.e., the first private key). Then, the generated public key and signature value are returned to the APP of the mobile phone. The mobile phone APP then obtains the public key (i.e., the first public key) on the server side to encrypt the device information, identity information, mobile phone public key, signature value, etc., and sends the obtained ciphertext to the server. The server decrypts and verifies the signature of the ciphertext based on its own private key (i.e., the second private key) and the public key of the mobile phone to verify the identity information. After the verification passes, the business data of the user is assembled based on the identity information. At the same time, a corresponding dispersion key is generated according to the device information of the mobile phone, and then the business data is encrypted with the dispersion key. Then, the dispersion key and the encrypted business data are signed with its own private key and further encrypted with the public key of the mobile phone, and the obtained ciphertext is returned to the mobile phone. The mobile phone APP decrypts with the private key of the mobile phone itself and verifies the signature with the public key of the server. After the signature verification passes, the dispersion key and the business data ciphertext are stored in its own trusted carrier TEE for subsequent users to directly decrypt the business data ciphertext with the stored dispersion key to obtain the business data and display it when logging in, without establishing a data transmission connection with the server.
[0081] Figure 8 It is a schematic flow diagram for the user in the solution of this application to conduct a transfer business, as Figure 8As shown, the user first logs in to their account on the mobile phone APP using their fingerprint. After successful login, the user initiates a transfer operation through the mobile phone APP. The mobile phone converts this operation into a corresponding transfer request and sends it to its own trusted execution environment (TEE). The TEE signs the transfer request and device information using the mobile phone's own private key and returns the obtained signature value to the mobile phone APP. The mobile phone APP encrypts its own device information, transfer request, and signature value using the server's public key and then sends the ciphertext to the server side. After receiving the ciphertext, the server decrypts and verifies the signature (the decryption and signature verification process is similar to that during registration and will not be elaborated here). After successful decryption and signature verification, the server processes the transfer request. After the processing is completed, the server signs the processing result and then returns the processing result and signature value to the mobile phone APP. The mobile phone APP decrypts and verifies the signature. After successful decryption and signature verification, it enters a state of waiting for the next service operation instruction.
[0082] Figure 9 This is a schematic diagram of the business request processing flow through a third-party program in the solution of this application. As Figure 9 shown, the user first logs in to their account on the mobile phone APP using their fingerprint. After successful login, the terminal displays a QR code for authorizing the third-party program (i.e., the authorization entry). The third-party program (i.e., the third-party APP / background in the figure) performs an operation of scanning the QR code (i.e., an interaction operation with the authorization entry), receives the device information of the mobile phone from the mobile phone APP, and then signs and encrypts the device information and business data required for the business request using a pre-agreed signature encryption method with the server to obtain ciphertext, and sends the ciphertext to the server. The server decrypts and verifies the signature according to the pre-agreed signature encryption method. After successful decryption and signature verification, the server processes the business data to obtain a processing result. For the processing result, it can be encrypted using the encryption method of the third-party program to obtain the ciphertext returned to the third-party program, and signed and encrypted using the encryption and signature method used when interacting with the terminal as described above to obtain the ciphertext returned to the mobile phone side, and then the obtained ciphertexts are respectively returned to the third-party program and the mobile phone side.
[0083] Figure 10 This is a structural block diagram of a service processing device provided by an embodiment of this application. As Figure 10 shown, the service processing device 1000 may include: an operation information acquisition module 1001, a signature module 1002, an encryption module 1003, a ciphertext information sending module 1004, and an operation result display module 1005. Among them, The operation information acquisition module 1001 is configured to generate first service operation information of a service operation in response to a service operation on the terminal and acquire a first public key of the server; The signature module 1002 is used to sign the first service operation information based on the first private key of the predetermined terminal to obtain a first signature value; The encryption module 1003 is used to encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information; The ciphertext information sending module 1004 is used to send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on the second public key of the predetermined terminal and the second private key of the server, and processes the first service operation information after the decryption and signature verification pass, to obtain and return a service operation result; The operation result display module 1005 is used to receive and display the service operation result.
[0084] In the solution provided by this application, when the target object initiates a service operation to a certain server through the terminal, the terminal generates first service operation information about this service operation, and signs and encrypts the first service operation information with its own private key and the public key of the server, so that the first service operation information after signature and encryption cannot be stolen or cracked by other terminals or servers except the server designated by the target object, thus ensuring the security during the information transmission process.
[0085] Based on the above various embodiments, as an optional embodiment, the device further includes a public-private key pair determination module, which is specifically used for: In response to an account registration operation initiated by the target object, obtain the real-time biometric information input by the target object; Compare the real-time biometric information with the pre-authenticated biometric information corresponding to the target object to obtain a matching degree; When the matching degree is not less than a preset threshold, register the target object, generate login account information of the target object, and randomly generate a public-private key pair of the terminal; where the public-private key pair includes a first private key and a second public key.
[0086] Based on the above various embodiments, as an optional embodiment, the public-private key pair determination module is further used for: Display at least one preset login entry type; In response to a selection operation of the target object for the target login entry type, display a login information setting interface corresponding to the target login entry type; Receive the login information input by the target object through the login information setting interface, associate the login information with the device information of the terminal, and jointly use them as the login account information of the target object.
[0087] Based on the above various embodiments, as an optional embodiment, the device further includes a login information setting module, which is specifically used for: In response to an authorization operation for a third-party program initiated by a target object, an authorization entry for authorizing the third-party program is displayed; In response to an interaction operation between the target object and the authorization entry, device information of the terminal and a second signature value obtained by signing the device information with a first private key are acquired; The device information and the second signature value are sent to the third-party program, so that the third-party program sends a service processing request to the server based on the device information and the second signature value, and receives a processing result of the service processing request returned by the server.
[0088] Figure 11 The block diagram of a service processing device provided by an embodiment of the present application is as Figure 11 shown. The service processing device 1100 may include: a ciphertext information receiving module 1101, a decryption and signature verification module 1102, and a service information processing module 1103, where The ciphertext information receiving module 1101 is configured to receive first ciphertext information sent by the terminal; wherein, the first ciphertext information is obtained by the terminal encrypting a first service operation information and a first signature value generated in response to a service operation for the terminal based on a first public key of the server; the first signature value is obtained by signing the first service operation information based on a first private key of the terminal; The decryption and signature verification module 1102 is configured to obtain a second public key of the terminal, and perform decryption and signature verification on the first ciphertext information based on the second public key and a second private key of the server determined in advance to obtain a decryption and signature verification result; The service information processing module 1103 is configured to, if the decryption and signature verification result is passed, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal, so that the terminal receives and displays the service operation result.
[0089] Based on the above various embodiments, as an optional embodiment, the decryption and signature verification module is specifically configured to: Perform a decryption operation on the first ciphertext based on the second private key to obtain the first service operation information, and perform a decryption operation on the second ciphertext based on the second private key to obtain the first signature value; Perform signature verification on the first signature value based on the second public key to obtain a second service operation information, and compare the second service operation information with the first service operation information. If the comparison result is the same, return a passed decryption and signature verification result; otherwise, return a failed decryption and signature verification result.
[0090] Based on the above various embodiments, as an optional embodiment, the device further includes an account registration module, which is specifically configured to: Receive an account registration request for a target object sent by a receiving terminal; wherein, the account registration request includes at least one piece of identity information of the target object and device information of the terminal, and the identity information is sent together when the target object inputs an identity registration instruction to the terminal; Assemble based on each piece of identity information and a preset business data template to generate business data about the target object, and combine a pre-stored root key and the device information of the terminal to generate a decentralized key about the terminal; Encrypt the business data based on the decentralized key to obtain a third ciphertext; Sign the third ciphertext and the decentralized key together based on a second private key to obtain a third signature value; Encrypt the third ciphertext, the decentralized key, and the third signature value based on a second public key to obtain a second ciphertext information; Send the second ciphertext information to the terminal, so that the terminal decrypts and verifies the signature of the second ciphertext information based on a first private key and a first public key, and stores the decentralized key and the third ciphertext after the decryption and signature verification pass. After the target object logs in to the account, the terminal decrypts the third ciphertext based on the decentralized key to obtain the business data and then displays it.
[0091] Based on the above various embodiments, as an alternative embodiment, the device further includes an identity cancellation module, specifically used for: Receive an identity cancellation request for a target object sent by a terminal; wherein, the identity cancellation request includes third ciphertext information, and the third ciphertext information includes a fourth ciphertext and a fifth ciphertext; the fourth ciphertext is obtained by the terminal encrypting device information and identity cancellation data representing the identity cancellation operation through a first public key; the fifth ciphertext is obtained by the terminal encrypting the device information and a fourth signature value obtained by signing the identity cancellation data through a first public key; Decrypt and verify the signature of the third ciphertext information based on a second private key and a second public key, and generate a signature verification passed information after the decryption and signature verification pass; Sign the signature verification passed information based on a second private key to obtain a fifth signature value, encrypt the fifth signature value based on a second public key to obtain a sixth ciphertext, and set the second public key to invalid; Send the sixth ciphertext to the terminal, so that the terminal decrypts and verifies the signature of the sixth ciphertext, and destroys the third ciphertext, the decentralized key of the terminal, the first private key, and the second public key after the decryption and signature verification pass.
[0092] Next, refer to Figure 12 , which shows an electronic device suitable for implementing the embodiments of the present application (for example, executing Figure 1Schematic diagram of the structure of a terminal device or server (1200) of the method shown. The electronic device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), vehicle terminals (such as in-vehicle navigation terminals), wearable devices, etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 12 The electronic device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.
[0093] The electronic device includes: a memory and a processor. The memory is used to store programs for executing the methods described in the above various method embodiments; the processor is configured to execute the programs stored in the memory. Here, the processor may be referred to as the processing device 1201 described below, and the memory may include at least one of the read-only memory (ROM) 1202, random access memory (RAM) 1203, and storage device 1208 described below, as shown specifically: As Figure 12 shown, the electronic device 1200 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 1201, which may perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 1202 or the programs loaded from the storage device 1208 into the random access memory (RAM) 1203. In the RAM 1203, various programs and data required for the operation of the electronic device 1200 are also stored. The processing device 1201, ROM 1202, and RAM 1203 are connected to each other through a bus 1204. The input / output (I / O) interface 1205 is also connected to the bus 1204.
[0094] Generally, the following devices may be connected to the I / O interface 1205: an input device 1206 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 1207 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1208 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1209. The communication device 1209 may allow the electronic device 1200 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 12 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be implemented or had alternatively.
[0095] In particular, according to an embodiment of the present application, the processes described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 1209, or installed from the storage device 1208, or installed from the ROM 1202. When the computer program is executed by the processing device 1201, the above functions defined in the method of the embodiment of the present application are executed.
[0096] It should be noted that the above computer-readable storage medium of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program codes. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program codes contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0097] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0098] The above computer-readable medium can be included in the above electronic device; or it can exist separately without being assembled into the electronic device.
[0099] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: In response to a service operation for the terminal, generate first service operation information of the service operation, and obtain the first public key of the server; based on the first private key of the terminal determined in advance, sign the first service operation information to obtain a first signature value; encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information; send the first ciphertext information to the server so that the server decrypts and verifies the signature of the first ciphertext information based on the second public key of the terminal determined in advance and the second private key of the server, and processes the first service operation information after the decryption and signature verification pass to obtain and return a service operation result; receive and display the service operation result.
[0100] Or, Receive the first ciphertext information sent by the terminal; wherein the first ciphertext information is obtained by the terminal encrypting the first service operation information and the first signature value generated in response to the service operation for the terminal based on the first public key of the server; the first signature value is obtained by signing the first service operation information based on the first private key of the terminal; obtain the second public key of the terminal, decrypt and verify the signature of the first ciphertext information based on the second public key and the second private key of the server determined in advance to obtain a decryption and signature verification result; if the decryption and signature verification result is passed, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal so that the terminal receives and displays the service operation result.
[0101] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0102] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0103] The modules or units involved in the embodiments described in this application can be implemented in software or in hardware. Among them, the name of the module or unit does not constitute a limitation on the unit itself in some cases. For example, the first constraint acquisition module can also be described as "the module for acquiring the first constraint".
[0104] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, the exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip (SOC), complex programmable logic devices (CPLD), and so on.
[0105] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0106] It should be understood that although the steps in the flowchart of the accompanying drawings are shown sequentially as indicated by the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order limitation for the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0107] The above are only some embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A service processing method, characterized in that, Applied to a terminal, including: In response to a service operation for the terminal, generate first service operation information of the service operation, and obtain a first public key of the server; Based on a pre-determined first private key of the terminal, sign the first service operation information to obtain a first signature value; Based on the first public key, encrypt the first service operation information and the first signature value to obtain first ciphertext information; Send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on a pre-determined second public key of the terminal and a second private key of the server, and processes the first service operation information after the decryption and signature verification pass, to obtain and return a service operation result; Receive and display the service operation result.
2. The method according to claim 1, characterized in that, The first private key and the second public key are pre-determined in the following manner: In response to an account registration operation initiated by a target object, obtain real-time biometric information input by the target object; Compare the real-time biometric information with pre-authenticated biometric information corresponding to the target object to obtain a matching degree; When the matching degree is not less than a preset threshold, register the target object, generate login account information of the target object, and randomly generate a public-private key pair of the terminal; wherein, the public-private key pair includes the first private key and the second public key.
3. The method according to claim 2, wherein The registering of the target object to generate the login account information of the target object includes: Display at least one preset login entry type; In response to a selection operation of the target object for a target login entry type, display a login information setting interface corresponding to the target login entry type; Receive login information input by the target object through the login information setting interface, associate the login information with device information of the terminal, and jointly use them as the login account information of the target object.
4. The method according to claim 1, characterized in that, The method further includes: In response to an authorization operation initiated by a target object for a third-party program, display an authorization entry for authorizing the third-party program; In response to an interaction operation between the target object and the authorization entry, obtain device information of the terminal and a second signature value obtained by signing the device information with the first private key; Send the device information and the second signature value to the third-party program, so that the third-party program sends a service processing request to the server based on the device information and the second signature value, and receives a processing result of the server for the service processing request.
5. A service processing method, characterized in that, Applied to a server, including: Receive first ciphertext information sent by a terminal; wherein, the first ciphertext information is obtained by the terminal encrypting first service operation information and a first signature value generated in response to a service operation for the terminal based on a first public key of the server; the first signature value is obtained by signing the first service operation information based on a first private key of the terminal; Obtain the second public key of the terminal, and decrypt and verify the signature of the first ciphertext information based on the second public key and the second private key of the server determined in advance to obtain a decryption and signature verification result; If the decryption and signature verification result is passed, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal so that the terminal receives and displays the service operation result.
6. The method according to claim 5, wherein The first ciphertext information includes a first ciphertext and a second ciphertext; the first ciphertext is obtained by encrypting the first service operation information based on the first public key; The second ciphertext is obtained by encrypting the first signature value based on the first public key; The decrypting and verifying the signature of the first ciphertext information based on the second public key and the second private key of the server determined in advance to obtain a decryption and signature verification result includes: Perform a decryption operation on the first ciphertext based on the second private key to obtain the first service operation information, and perform a decryption operation on the second ciphertext based on the second private key to obtain the first signature value; Verify the signature of the first signature value based on the second public key to obtain second service operation information, and compare the second service operation information with the first service operation information. If the comparison result is the same, return a passed decryption and signature verification result; otherwise, return a failed decryption and signature verification result.
7. The method according to claim 5, wherein The method further includes: Receive an account registration request for a target object sent by the terminal; wherein, the account registration request includes at least one piece of identity information of the target object and device information of the terminal, and the identity information is sent together with an identity registration instruction input by the target object to the terminal; Assemble based on each piece of identity information and a preset service data template to generate service data about the target object, and combine the root key stored in advance and the device information of the terminal to generate a decentralized key about the terminal; Encrypt the service data based on the decentralized key to obtain a third ciphertext; Sign the third ciphertext and the decentralized key together based on the second private key to obtain a third signature value; Encrypt the third ciphertext, the decentralized key, and the third signature value based on the second public key to obtain second ciphertext information; Send the second ciphertext information to the terminal so that the terminal decrypts and verifies the signature of the second ciphertext information based on the first private key and the first public key, and stores the decentralized key and the third ciphertext after the decryption and signature verification pass. After the target object logs in through the account, the terminal decrypts the third ciphertext based on the decentralized key to obtain the service data and then displays it.
8. The method according to claim 7, wherein The method further includes: Receive an identity cancellation request for the target object sent by the terminal; wherein, the identity cancellation request includes third ciphertext information, and the third ciphertext information includes a fourth ciphertext and a fifth ciphertext; the fourth ciphertext is obtained by the terminal encrypting the device information and identity cancellation data representing the identity cancellation operation with the first public key; the fifth ciphertext is obtained by the terminal encrypting the device information and the fourth signature value obtained by signing the identity cancellation data with the first public key with the first public key. Decrypt and verify the signature of the third ciphertext information based on the second private key and the second public key, and generate information indicating successful signature verification after successful decryption and signature verification. Sign the information indicating successful signature verification with the second private key to obtain a fifth signature value, encrypt the fifth signature value with the second public key to obtain a sixth ciphertext, and invalidate the second public key. Send the sixth ciphertext to the terminal, so that the terminal decrypts and verifies the signature of the sixth ciphertext, and destroys the third ciphertext, the dispersion key of the terminal, the first private key, and the second public key after successful decryption and signature verification.
9. A service processing device, characterized in that, Comprises: An operation information acquisition module, configured to generate first service operation information of the service operation in response to a service operation for the terminal, and acquire the first public key of the server. A signature module, configured to sign the first service operation information based on the first private key of the terminal determined in advance to obtain a first signature value. An encryption module, configured to encrypt the first service operation information and the first signature value based on the first public key to obtain first ciphertext information. A ciphertext information sending module, configured to send the first ciphertext information to the server, so that the server decrypts and verifies the signature of the first ciphertext information based on the second public key of the terminal determined in advance and the second private key of the server, and processes the first service operation information after successful decryption and signature verification to obtain and return a service operation result. An operation result display module, configured to receive and display the service operation result.
10. A service processing device, characterized in that, Comprises: A ciphertext information receiving module, configured to receive first ciphertext information sent by the terminal; wherein, the first ciphertext information is obtained by the terminal encrypting the first service operation information and the first signature value generated in response to a service operation for the terminal with the first public key of the server; the first signature value is obtained by signing the first service operation information based on the first private key of the terminal. A decryption and signature verification module, configured to acquire the second public key of the terminal, and decrypt and verify the signature of the first ciphertext information based on the second public key and the second private key of the server determined in advance to obtain a decryption and signature verification result. A service information processing module, configured to, if the decryption and signature verification result is passed, process the first service operation information to obtain a service operation result, and return the service operation result to the terminal, so that the terminal receives and displays the service operation result.
11. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1-8.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1-8 are implemented.
Citation Information
Patent Citations
Application program communication processing system, an application program communication processing device, an application program communication processing apparatus and an application program communication processing method
CN105915342A
Terminal identity verification method and system based on dispersed key encryption
CN107508791A
Identity authentication method, apparatus, computer readable storage medium and device
CN109150535A
Identity verification method and device, terminal, server and readable storage medium
CN111414599A
Business processing method, device and equipment and computer readable storage medium
CN116204857A