Trusted business card incoming call system and method

By independently issuing digital certificates for enterprises and institutions, a trusted business card in vCard format is solved, and a low-cost and high-compatibility trusted business card system is realized, and a low-cost and high-compatibility trusted business card system is reduced, which reduces the risk of telecommunications fraud.

CN120301975AActive Publication Date: 2025-07-11GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510404027.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-11
Estimated Expiration
2045-04-01

AI Technical Summary

Technical Problem

The existing technology cannot effectively guarantee the authenticity of the work role information of incoming call business cards, and there are problems such as high service costs, complex key management, poor compatibility with existing systems and insufficient information display.

Method used

Enterprises and institutions independently issue digital certificates, and use electronic certification modules and business card issuance modules to generate trusted business cards in vCard format, and combine the operator communication network and directory servers to realize trusted business cards display and verification of terminals.

Benefits of technology

It improves the authenticity and flexibility of incoming call business cards, reduces implementation costs, enhances compatibility and user experience with existing systems, and reduces the risk of telecommunications fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301975A_ABST
    Figure CN120301975A_ABST
Patent Text Reader

Abstract

The invention discloses a trusted business card incoming call system and method, and the system comprises an electronic authentication module which is used for signing and issuing a digital certificate for an enterprise and public institution with a first user; the business card issuing module is used for editing business card information of the first user, exporting a vCard format file, signing a business card of the vCard format file of the first user by using a private key of a digital certificate to obtain a credible business card, and issuing the credible business card to a directory server for a calling terminal to download; a calling terminal and a called terminal; the directory server is used for authenticating other system structures, providing specified access authority for the calling terminal and the called terminal, and enabling the calling terminal to download the credible business card and the called terminal to verify the credible business card; and the calling terminal downloads the first user credible business card from the directory server, and the first user credible business card is transmitted to the called terminal to be displayed. The method has the advantages that enterprises and public institutions sign and issue autonomously, real work role information is guaranteed, the implementation cost is relatively low, and the method is better compatible with existing systems and applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a trusted calling card incoming call system and method. Background Art

[0002] The endless emergence of harassing, promotional, fraudulent calls, etc. has caused the called users to distrust unfamiliar incoming calls and habitually reject all unfamiliar numbers, so that the normal business operations of government departments, enterprises and institutions are hindered.

[0003] Therefore, telecom operators and third-party service providers have begun to provide incoming call card services, enabling the called users to see the identity information of the calling users to improve the business connection rate. However, most of the incoming call cards are provided with information by the calling users, without the liability endorsement of enterprises and institutions, and cannot guarantee the authenticity of the card information. In addition, most incoming call cards also lack password technology protection and cannot guarantee the immutability of their content.

[0004] Therefore, in order to solve the immutability of the caller's identity information, the existing technology has published the GB / T43779-2024 standard. Based on public key cryptography technology, a trusted credential is issued to the calling user's terminal, and the call information is electronically signed based on the trusted credential, so as to achieve the authenticity and trustworthiness of the calling user's information and the non-forgery of the call information.

[0005] Although the GB / T 43779-2024 standard well solves the problem of the trustworthiness of the calling user's personal identity technically, it is still slightly insufficient in terms of the trust problem of the calling user's work role, specifically including:

[0006] The incoming call card more needs to display the work role of the user rather than the personal identity information. Only the enterprises and institutions to which the user belongs can accurately master the work role information. At this time, the GB / T 43779-2024 standard stipulates that the trusted identity credential is issued by the identity credential issuing center. However, without the cooperation of enterprises and institutions, it is very difficult for the identity credential issuing center to confirm the work role information of the user and cannot guarantee the authenticity of the work role information in the issued identity credential;

[0007] The user may have multiple work roles, and the work role has the characteristic of volatility. According to the GB / T43779-2024 standard, the identity credential issuing center needs to issue a trusted identity credential for each work role separately, which has the disadvantages of high service cost and high key management cost;

[0008] The GB / T 43779-2024 standard requires the calling user to apply for and install a trusted identity credential, and the essence of the trusted identity credential is a public key certificate. The public and private key pairs of the public key certificate require the support of a cryptographic module product, which greatly increases the deployment and management costs;

[0009] Current mainstream mobile operating systems such as Android and IOS both support vCard format virtual cards as the import and export data of the address book. However, the identity credentials in the GB / T 43779-2024 standard are significantly incompatible with vCards, making it difficult to be compatible with existing systems and applications.

[0010] The information carried by the identity credentials in the GB / T 43779-2024 standard is not as rich as that carried by vCards, such as personal avatars, enterprise LOGOs, etc., which is not conducive to the diverse display of work roles.

[0011] Therefore, this application specifically proposes a trusted business card incoming call system and method with low implementation cost and compatibility with existing systems and applications to solve the above technical problems. Summary of the Invention

[0012] The main purpose of the present invention is to provide a trusted business card incoming call system and method to solve the technical problems raised in the background technology, which has the advantages of being independently issued by enterprises and institutions, ensuring the authenticity of work role information, relatively low implementation cost, and better compatibility with existing systems and applications.

[0013] The present invention adopts the following technical solutions to solve the above technical problems:

[0014] A trusted business card incoming call system includes:

[0015] An electronic authentication module, generally a trusted CA institution (electronic authentication service institution), is used to issue digital certificates for enterprises and institutions with a first user. This digital certificate is equivalent to the official seal of the enterprise. By signing the employee's business card with the private key of this digital certificate, a trusted incoming call business card can be obtained.

[0016] A business card issuance module can be deployed on the side of enterprises and institutions or provided as a cloud service by an operating unit. It is used to edit and export the vCard format file of the first user's business card information, and then sign the business card of the first user's vCard format file with the private key of the unit's digital certificate to obtain a trusted business card, which is published to the directory server for the calling terminal to download.

[0017] The calling terminal (or calling terminal APP) bound to the first user and the called terminal (or called terminal APP) bound to the second user, where the calling terminal (or calling terminal APP) is deployed on the calling user's mobile terminal, downloads the trusted business card of this user from the directory server for business card display during a call, and the called terminal (or called terminal APP) is deployed on the called user's mobile terminal.

[0018] The operator communication network provides a VoIP voice call communication network for terminal users and supports the SIP call protocol.

[0019] A directory server, deployed by the operating unit, is used to authenticate other system structures such as CAs, enterprises and institutions, and end users, and provide specified access rights to different types of users including the calling terminal and the called terminal, for the calling terminal to download a trusted business card and the called terminal to verify the trusted business card;

[0020] The calling terminal is connected to the called terminal through a VoIP voice call communication network. The calling terminal downloads a first user trusted business card from the directory server for transmission to the called terminal for display;

[0021] The CA institution and the operator communication network belong to external systems.

[0022] Preferably, the electronic authentication module (CA institution) is used to issue enterprises and institutions that have exited or disappeared to the Certificate Revocation List (CRL), and publish the CA certificate, the issued digital certificates and the Certificate Revocation List to the directory server;

[0023] The business card issuing module issues corresponding trusted business cards and trusted business card revocation lists for employees who have left or changed their jobs according to the status of enterprises and institutions for publication to the directory server;

[0024] The business card issuing module issues corresponding trusted business cards and trusted business card revocation information for employees who have left or changed their jobs according to the employee information of enterprises and institutions for publication to the directory server;

[0025] The calling terminal and the called terminal download the CA certificate, digital certificates, Certificate Revocation List, trusted business cards and trusted business card revocation lists through the directory server for verifying and displaying the first user trusted business card.

[0026] Preferably, a method for a trusted business card incoming call, implemented based on any of the above-mentioned trusted business card incoming call systems, includes the following steps:

[0027] S1. Application for enterprise and institution digital certificates: The person in charge of the enterprise and institution submits the information of the unit to the authoritative CA institution through the electronic authentication module to apply for an organization digital certificate;

[0028] S2. Issuance of enterprise and institution digital certificates: The CA institution of the electronic authentication module issues an organization digital certificate after reviewing the information of the enterprise and institution, stores the digital certificate in a usbkey key medium for the designated person of the enterprise and institution, and regularly publishes the issued organization digital certificate, the CA certificate of the electronic authentication module and the Certificate Revocation List to the directory server;

[0029] S3. Generation of Trusted Business Cards: After enterprises and institutions enter employee information, the business card issuance module generates a vCard format file and signs it using the private key of the institution's digital certificate of the unit to ensure the integrity and non-repudiation of the vCard information, thus completing the operation of issuing trusted business cards for employees;

[0030] S4. Publication of Trusted Business Cards: Create a directory for enterprises and institutions in the directory server. The directory name is the same as the unified social credit code and unit name in the subject of the unit's digital certificate. Publish the trusted business cards issued by the enterprises and institutions to this directory, and at the same time publish the list of cancelled trusted business cards to meet the situations such as changes in employees' job positions and exits;

[0031] S5. Download of Trusted Business Cards: Employees of enterprises and institutions perform identity authentication and binding on the calling terminal, and download the CA certificate of the electronic authentication module, the institution's digital certificate of the enterprise or institution, the digital certificate cancellation list, the trusted business card, and the trusted business card cancellation list from the directory server;

[0032] S6. Installation of Trusted Business Cards: The calling terminal verifies the trusted business card according to the information of the CA certificate, the digital certificate cancellation list, the institution's digital certificate of the enterprise or institution, and the trusted business card cancellation list. After the verification passes, the trusted business card is installed;

[0033] S7. Calling Process of Trusted Business Cards: During business contact, after selecting the trusted business card to be displayed on the calling terminal and then dialing, the calling terminal transmits specified data to the called terminal as authentication information. After authentication by the directory server, the trusted business card of the calling terminal is downloaded;

[0034] S8. Preliminary Local Verification of Trusted Business Cards: The called terminal obtains the trusted business card transmitted by the calling terminal to get the mobile phone number on the trusted business card and compares it with the calling incoming number. If the comparison fails, it means the trusted business card is invalid and is displayed on the called terminal. Then, it is up to the called user to decide whether to answer. If the comparison passes, proceed to the next step;

[0035] S9. Download Verification Information of Trusted Business Cards: The called terminal downloads the CA certificate, the digital certificate cancellation list, the digital certificate of the enterprise or institution to which the trusted business card belongs, and the trusted business card cancellation list from the directory server;

[0036] S10. Verification of Trusted Business Cards: The called terminal verifies the trusted business card according to the downloaded information according to specified conditions. When all verifications pass, it means the trusted business card is valid and the specified information of the trusted business card is displayed, waiting for the called user to answer. If the verification fails, it shows that the trusted business card is invalid, and it is up to the called user to decide whether to answer.

[0037] Preferably, the directory server includes the following secondary directories:

[0038] The sub-entries of the "dc=TrustCAs" directory are the trusted electronic authentication service CA institutions in the electronic authentication module;

[0039] The sub-entries of the "dc=Organization" directory are the trusted business card issuing units in the business card issuing module. The RDN of the trusted business card issuing unit entry includes the serialNumber item and the o item. The value of the serialNumber item is the unified social credit code of the enterprise or institution, and the value of the o item is the name of the enterprise or institution. The sub-entries of the trusted business card issuing unit entry are the employees of the unit.

[0040] Preferably, the directory server performs SMS authentication on the calling terminal, and the specific authentication process includes:

[0041] a1. The user enters the unit name and mobile phone number, obtains the first data request and sends it through the client;

[0042] a2. The server queries the corresponding entry from the directory server directory according to the unit name and mobile phone number in the first data request:

[0043] If it does not exist, the process ends and an authentication failure response is directly returned to the client;

[0044] If an entry exists, send an SMS authentication code to the mobile phone number of the entry, and then return a waiting for continued authentication response to the client;

[0045] a3. After the user receives the SMS verification code, combines the unit name and mobile phone number, and sends a second data request through the client again;

[0046] a4. The server queries the entry from the directory according to the unit name and mobile phone number in the second data request:

[0047] If it does not exist, the process ends and an authentication failure response is returned to the client;

[0048] If an entry exists, compare the SMS authentication code. If the comparison of the SMS authentication code fails, the process ends and an authentication failure data response is returned to the client. If the comparison of the SMS authentication code is successful, the authentication is successful and a corresponding authentication success data response is returned to the client.

[0049] Preferably, the steps for obtaining and generating the trusted business card in step S3 include:

[0050] Based on the attribute certificate, extend the attribute data through vCardEx, write the vCard format data, and finally generate the trusted business card. The signature value of the attribute certificate is obtained by signing the attribute certificate with the private key of the enterprise or institution digital certificate.

[0051] Preferably, the trusted business card transfers data based on a serial number. The specific process includes:

[0052] b1. The calling terminal reads out the serial number of the trusted business card to be transferred, and adds a first parameter to the Call-Info header field of the INVITE message. The first parameter contains the mobile phone number, the unit name, and the HEX encoding of the trusted business card serial number.

[0053] b2. The called terminal obtains the first parameter from the INVITE message, uses the mobile phone number and unit name in the first parameter as the user name data, and uses the HEX encoding of the trusted business card serial number in the first parameter as the password data to input for authentication by the directory server.

[0054] b3. The directory server queries the trusted business card of the calling terminal user according to the user name data, reads out its serial number, and uses it to compare with the password data of the called terminal. If they are the same, it returns the trusted business card; if they are different, it returns an invalidCredentials error.

[0055] b4. If the called terminal receives an invalidCredentials error returned by the directory server, it prompts that the acquisition of the trusted business card fails. If the called terminal receives the trusted business card returned by the directory server, the process proceeds to the next step.

[0056] Preferably, the specific verification method for the called terminal to verify the validity of the trusted business card includes:

[0057] c1. Obtain its validity period from the trusted business card. If the current time is not within its validity period, the verification fails.

[0058] If it is within its validity period, further obtain the vCard from the vCardExt extension item of the trusted business card, obtain the mobile phone number and unit name from the attributes of the vCard, and compare the mobile phone number in the vCard attribute with the mobile phone number of the incoming call and the unit name in the vCard attribute with the issuer name in the trusted business card in turn. If any comparison result is inconsistent, the verification fails.

[0059] c2. According to the unified social credit code and unit name in the trusted business card, download the unit's signature certificate and the trusted business card revocation list from the directory server.

[0060] Read the CA certificate and the digital certificate revocation list from the cache or download them from the directory server according to the issuer of the unit signature certificate.

[0061] And verify whether the downloaded CA certificate is issued by the trust root preset by the called terminal. If not, the verification fails.

[0062] c3. Verify the signature certificate of the entity based on the specified public key certificate verification criteria, using the CA certificate and the digital certificate revocation list. If all requirements cannot be met, the verification fails.

[0063] c4. Verify the trusted business card based on the attribute certificate verification criteria, using the entity signature certificate and the trusted business card revocation list. If all requirements cannot be met, the verification fails.

[0064] c5. After all the above verifications pass, display the specified information of the caller's trusted business card according to the vCard information, and wait for the callee to answer the call.

[0065] As can be seen from the above technical solutions, the present invention provides a trusted business card incoming call system and method.

[0066] Compared with the prior art, the present invention has the following advantages:

[0067] 1. By setting up an independent issuance mechanism for enterprises and institutions in the trusted business card issuance system, the present invention can dynamically adjust employee information in a timely manner, ensuring the authenticity of incoming call business cards, thus having better autonomy and flexibility, and being able to enhance the reliability of trusted business cards and the liability traceability ability of enterprises and institutions.

[0068] 2. By setting up a digital certificate signature endorsement mechanism in the CA institution, with the signature endorsement of enterprises and institutions, the present invention can provide legal effect for the signatures of enterprises and institutions, play a role in ensuring liability traceability, achieve the effect of enhancing anti-fraud ability, and thus effectively reduce the risk of telecommunications fraud.

[0069] 3. By setting up a key-free storage design in the terminal APP, the calling and called terminals do not need to store the public and private key pairs and can avoid deploying a password module, thus avoiding the complexity of terminal users managing keys, reducing implementation and maintenance costs, and at the same time being able to simplify the system architecture and further improve the convenience of user use.

[0070] 4. By using the vCard standard format to generate business cards in the generation of trusted business cards, the present invention can be seamlessly compatible with existing applications on mobile terminals, can be directly exported and imported from the address book, and can directly call the APIs of Android and iOS to process vCards, thus improving the user experience and enhancing the adaptability of the system to the terminal ecosystem.

[0071] 5. Based on attribute certificates, public key certificates, and LDAP directory servers, by integrating LDAP and X.509 standard technologies in the directory server, the present invention can reuse existing mature technology systems, reduce the development difficulty, thus shortening the R & D cycle and reducing the technical implementation cost.

[0072] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. Of course, any product implementing the present invention does not necessarily need to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] The accompanying drawings forming a part of this application are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0074] Figure 1 is a block diagram of the system structure of the present invention;

[0075] Figure 2 is a schematic diagram of the overall method flow of the present invention;

[0076] Figure 3 is a schematic diagram of the directory structure organization of the present invention;

[0077] Figure 4 is a schematic diagram of the trusted business card data format of the present invention;

[0078] Figure 5 is a schematic diagram of the SIP protocol INVITE message packet of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0079] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0080] In the embodiment, refer in detail to Figures 1 to 5 .

[0081] A trusted business card incoming call system proposed in an embodiment of the present invention is composed of a directory server, a trusted business card issuing system, a calling terminal APP, a called terminal APP, a CA institution, and an operator communication network, as Figure 1 shown, and specifically includes:

[0082] (1) CA Institution: An electronic certification service institution that issues digital certificates to enterprises and institutions. This digital certificate is equivalent to the official seal of an enterprise. By using the private key of this digital certificate to sign an employee's business card, a trustworthy incoming call business card can be obtained. The CA institution also issues the digital certificates of enterprises and institutions that have withdrawn or ceased to exist to the Certificate Revocation List (CRL) and publishes it on the directory server for mobile terminals to download.

[0083] (2) Trusted Business Card Issuance System: It can be deployed on the side of enterprises and institutions or provided as a cloud service by the operating unit. It can edit employee business card information, and finally export a vCard file and use the private key of the unit's digital certificate to sign the employee's business card to form a trusted business card, which is then published on the directory server for mobile terminals to download. For employees who have left the company or changed their job positions, a trusted business card revocation list is issued and published on the directory server for mobile terminals to download.

[0084] (3) Directory Server: Deployed by the operating unit, it authenticates CA institutions, enterprises and institutions, end users, etc., and provides different access permissions to different types of users. It stores CA institution certificates and CRLs for users to download. It stores the trusted business cards and trusted business card revocation lists published by enterprises and institutions for users to download.

[0085] (4) Operator Communication Network: Provides a VoIP voice call communication network for end users and supports the SIP call protocol.

[0086] (5) Calling Terminal APP: Deployed on the calling user's mobile terminal, it downloads the user's trusted business card from the directory server for business card display during calls.

[0087] (6) Called Terminal APP: Deployed on the called user's mobile terminal, it downloads digital certificates, CRLs, trusted business card revocation information, etc. from the directory server for verifying and displaying the calling user's trusted business card.

[0088] In summary, the trusted business cards of this system are independently issued by enterprises and institutions, can timely adjust the departure of employees and job changes, and can better ensure the authenticity of incoming call business cards, with better autonomy and flexibility. In addition, through the signature endorsement of enterprises and institutions, when liability events such as telecom fraud occur, it is easier to hold someone accountable.

[0089] On the other hand, the present invention also discloses a method for incoming calls with trusted business cards, as Figure 2 shown, including the following steps:

[0090] L1. Application for an enterprise or institution digital certificate: The person in charge of the enterprise or institution submits the unit's information to an authoritative CA institution to apply for an organization digital certificate.

[0091] Issuance of digital certificates for enterprises and institutions: After the CA institution reviews the information of enterprises and institutions, it issues organizational digital certificates, which can be stored in the usbkey key medium and given to the handling personnel of enterprises and institutions. The CA institution also regularly publishes the cancelled organizational digital certificates to the directory server to meet the situations such as the withdrawal and extinction of enterprises and institutions.

[0092] Specifically, the directory organization of the directory server is as Figure 3 shown. The directory server is based on LDAP technology (IETF RFC4511 standard), and its directory includes two secondary directories:

[0093] The sub-entries of the "dc=TrustCAs" directory are each trusted CA institution. The RDN of the CA institution entry should be the same as the subject of the CA certificate. The value of the cACertificate attribute of the CA institution entry is the CA certificate, and the value of the certificateRevocationList attribute of the CA institution entry is the CRL issued by the CA.

[0094] The sub-entries of the "dc=Organization" directory are each trusted business card issuing unit. The RDN of the trusted business card issuing unit entry includes the serialNumber item and the o item. The value of the serialNumber item is the unified social credit code of the enterprise or institution, and the value of the o item is the name of the enterprise or institution. The value of the userCertificate attribute of the trusted business card issuing unit entry is the public key certificate for signature of the enterprise or institution. The value of the attributeCertificateRevocationList attribute of the trusted business card issuing unit entry is the cancellation list of trusted business cards issued by the enterprise or institution (i.e., the cancellation list of attribute certificates). Additionally, the sub-entries of the trusted business card issuing unit entry are the employees of the unit. The RDN of the unit employee entry includes the telephoneNumber item, and its value is the mobile phone number of the employee. The value of the attributeCertificate attribute of the unit employee entry is their trusted business card. There can be multiple attributeCertificate attributes for storing multiple trusted business cards of the same employee to meet the situation of an employee having multiple work roles.

[0095] The directory organization is summarized in the following table:

[0096]

[0097]

[0098] The user roles of the directory server include: system administrator, CA institution, enterprise or institution, calling user, and called user.

[0099] Its directory access permissions are shown in the following table:

[0100]

[0101]

[0102] Among them: S: Search to search for and read this entry; A: Add to add this entry; D: Delete to delete this entry; M: Modify to modify the attributes of this entry.

[0103] L3. Generation of trusted business cards: The operators of enterprises and institutions enter employee information into the trusted business card issuance system to generate a vCard, and call the private key of the institution's digital certificate to sign it to ensure the integrity and non-repudiation of the vCard information. The signed vCard is as Figure 4 shown, and a custom critical extension vCardExt is added to the attribute certificate (abbreviation "AC", X.509 standard) to store the vCard information.

[0104] Furthermore, as Figure 4 shown, the trusted business card is an attribute certificate (X.509 standard) issued by the private key of the enterprise or institution's signature certificate. The holder of the attribute certificate selects entityName, and the name is like the RDN of the unit employee entry in the directory server, which is "telephoneNumber = mobile phone number". The issuer of the attribute certificate selects issuerName, and the format is like the RDN of the trusted business card issuing unit entry, which is "serialNumber = unified social credit code, o = unit name". The signature algorithm of the attribute certificate is set according to the key pair algorithm of the unit's signature certificate. For the serialNumber of the attribute certificate, this method uses a 20-byte random number and ensures uniqueness within the same unit. The validity period of the attribute certificate is set by the unit's operator according to the possible working period of the employee. The optional attributes of the attribute certificate are empty.

[0105] The trusted business card is mainly formed by adding a vCardExt extension based on the above attribute certificate. The object identifier OID of vCardExt can be applied to INNA. As a critical extension, the value of vCardExt consists of vCard (IETF RFC6350 standard). The NICKNAME attribute of vCard places the caller's name, the PHOTO attribute places the caller's avatar, the TEL attribute places the caller's mobile phone number, the TITLE attribute places the caller's job role (such as "General Manager", "Sales Consultant", etc.), multiple job roles can be written, the LOGO attribute places the unit logo, the ORG attribute places the unit name, etc. Enterprises and institutions can add or delete attributes according to needs when issuing trusted business cards.

[0106] Finally, the signature value of the attribute certificate is calculated according to the attribute certificate standard.

[0107] In summary, by adopting the vCard standard format to generate standard business cards in the generation of trusted business cards, it can better be compatible with existing applications on mobile terminals, can be directly exported and imported from the address book, and can directly call the APIs of Android and iOS to process vCards, thereby improving the user experience and enhancing the adaptability of the system to the terminal ecosystem.

[0108] L4. Publication of trusted business cards: The trusted business card issuing system creates the directory of this unit on the directory server. The directory name is the same as the unified social credit code and the unit name in the subject of the digital certificate of this unit. The issued trusted business cards are published under this directory. The trusted business card issuing system also publishes the list of revoked trusted business cards (attribute certificate revocation list, X.509 standard) to the directory server to meet the situations such as changes in employees' job positions and exits.

[0109] L5. Download of trusted business cards: The calling user opens the APP, enters the name of the enterprise or institution or the unified social credit code and the user's mobile phone number on the interface, conducts SMS authentication, and downloads information such as the CA certificate, the institutional digital certificate of the enterprise or institution, the trusted business card corresponding to this mobile phone number, and the CRL from the directory server.

[0110] The authentication methods for each user role of the directory server are shown in the following table:

[0111]

[0112] Anonymous or account password authentication can adopt LDAP Simple authentication. Considering the security of password transmission, StartTLS or LDAPS can be started for secure transmission. Digital certificate authentication can adopt the client certificate authentication of StartTLS or LDAPS.

[0113] For mobile SMS authentication, the SASL (Simple Authentication Security Layer, IETF RFC 4422) authentication extension of LDAP can be adopted. Here, a "SASL-SMS" authentication mechanism is designed, and the authentication process is as follows:

[0114] (a1) The user inputs the unit name and mobile phone number, and sends a BindRequest through the client. The name field is "telephoneNumber = mobile phone number, o = unit name", the authentication field selects sasl, the mechanism field of sasl is the "SASL-SMS" mechanism, and the sasl does not carry the credentials field.

[0115] (a2) The server checks the entry from the directory according to the unit name and mobile phone number sent by the client. If it does not exist, it returns a BindResponse to the client, and the resultCode is the noSuchObject error, and the process ends. If the entry exists, it sends a short message authentication code and returns a BindResponse to the client, and the resultCode is saslBindInProgress.

[0116] (a3) The user receives the short message verification code and sends a BindRequest through the client. The name field is "telephoneNumber = mobile phone number, o = unit name", the authentication field selects sasl, the mechanism field of sasl is the "SASL-SMS" mechanism, and the credentials of sasl are the short message verification code input by the user.

[0117] (a4) The server checks the entry from the directory according to the unit name and mobile phone number sent by the client. If it does not exist, it returns a BindResponse to the client, and the resultCode is the noSuchObject error, and the process ends. If the entry exists, it compares the short message authentication code. If the comparison fails, it returns a BindResponse to the client, and the resultCode is invalidCredentials, and the process ends. If the short message authentication code comparison is successful, the resultCode is success, and the authentication is successful.

[0118] The above process authenticates the calling terminal, enabling it to only download the trusted business cards of the calling user and not other trusted business cards, effectively protecting the sensitive information of enterprises, institutions and other users.

[0119] L6. Installation of trusted business cards: The calling terminal APP verifies the trusted business cards according to the CA certificate, enterprise and institution digital certificate, CRL information, etc., and installs them on this terminal after passing the verification.

[0120] L7. Call process of the trusted vCard: When making a business contact, the calling user selects the trusted vCard to be displayed on the APP and makes a call. The calling terminal APP adds the TrustedVCard parameter to the Call-Info header field of the SIP protocol INVITE message, and writes the Base64-encoded trusted vCard to the value of this parameter. If the SIP protocol of the telecom operator does not support such a large header, only the trusted vCard serial number can be transmitted, and the TrustedVCardSN parameter is passed through the SIP header to the called terminal as authentication information. After the called terminal APP authenticates on the directory server, the trusted vCard of the calling terminal is downloaded.

[0121] Specifically, the transmission process based on the trusted vCard serial number includes:

[0122] (b1) The calling terminal reads out the serial number of the trusted vCard to be transmitted, and then adds these parameters in the Call-Info header field of the INVITE message in the format shown: "telephoneNumber = mobile phone number, o = company name, TrustedVCardSN = HEX encoding of the trusted vCard serial number;". Figure 5

[0123] (b2) The called terminal APP obtains "telephoneNumber = mobile phone number, o = company name, TrustedVCardSN = HEX encoding of the trusted vCard serial number" from the INVITE message, and uses "telephoneNumber = mobile phone number, o = company name" as the user name and the HEX encoding of the trusted vCard serial number as the password to authenticate on the directory server.

[0124] (b3) The directory server queries the trusted vCard (i.e., the attribute certificate) of the calling user according to "telephoneNumber = mobile phone number, o = company name", reads its serial number, and compares it with the password of the called terminal. If they are the same, the trusted vCard is returned. If they are different, an invalidCredentials error is returned.

[0125] (b4) If the called terminal APP receives the invalidCredentials error returned by the directory server, it prompts that the acquisition of the trusted vCard fails and prompts the user whether to answer the call. If the called terminal APP receives the trusted vCard returned by the directory server, the process proceeds to the next step.

[0126] It should be noted at this time that the transmission process of the trusted vCard serial number authenticates the called terminal, enabling it to only download the trusted vCard of the calling user and not other trusted vCards, effectively protecting the sensitive information of enterprises, institutions and other users.

[0127] ​L8. Initial local verification of the trusted business card: The called terminal APP obtains the trusted business card passed by the calling terminal APP, with the format as Figure 4 shown. The mobile phone number of the calling terminal can be obtained from the trusted business card, and then compared with the calling number in the SIP call. If the comparison fails, it means the trusted business card is invalid, and the called terminal APP displays that the trusted business card is invalid, and it is up to the called user to decide whether to answer. If the comparison passes, proceed to the next step.

[0128] L9. Download verification information of the trusted business card: The called terminal APP downloads information such as the CA certificate, CRL, digital certificate of the enterprise or institution to which the trusted business card belongs, and trusted business card revocation list from the directory server.

[0129] L10. Verification of the trusted business card: The called terminal APP verifies the validity period of the trusted business card, the validity of the enterprise or institution signature, the validity of the enterprise or institution organization certificate, whether the CA institution is in the APP trust root (or issued by the trust root), etc. through the trusted business card verification information downloaded in the above steps. When all verifications pass, it means the trusted business card is valid, and the avatar, enterprise logo, enterprise name, personal title, job position, etc. of the trusted business card are displayed, waiting for the called user to answer. If the verification fails, the trusted business card is displayed as invalid, and it is up to the called user to decide whether to answer.

[0130] Specifically, after the called terminal receives the trusted business card of the calling user from the SIP call or downloads it from the directory server during the verification process, the following steps are required to verify the validity of the trusted business card:

[0131] (c1) Initial local verification: Obtain its validity period from the trusted business card (i.e., the attribute certificate). If the current time is not within its validity period, the verification fails. Obtain the vCard from the vCardExt extension item of the attribute certificate, obtain the calling mobile phone number from the TEL attribute of the vCard, and then compare it with the calling number of the SIP call and the mobile phone number of the holder in the attribute certificate. If they are inconsistent, the verification fails. Check whether the ORG attribute of the vCard is consistent with the unit name of the issuer in the attribute certificate. If they are inconsistent, the verification fails.

[0132] (c2) Download verification information such as the certificate chain and revocation list: According to the unified social credit code and unit name of the issuer in the attribute certificate, download the signature certificate of the unit and the trusted business card revocation list (attribute certificate revocation list) from the directory server. Read the CA certificate and CRL from the cache or download them from the directory server according to the issuer of the unit signature certificate. And verify whether the downloaded CA certificate is issued by the trust root preset in the called terminal APP. If not, the verification fails.

[0133] (c3)Signature certificate verification for enterprises and institutions: Based on the X.509 public key certificate verification standard, verify the unit's signature certificate according to the CA certificate, CRL, etc. If all requirements cannot be met, the verification fails.

[0134] (c4)Trusted business card (attribute certificate) verification: Based on the X.509 attribute certificate verification standard, verify the attribute certificate according to the unit signature certificate, trusted business card revocation list (attribute certificate revocation list), etc. If all requirements cannot be met, the verification fails.

[0135] (c5)Display of trusted business card: After all the above verifications pass, according to the vCard information, display the avatar, enterprise logo, enterprise name, personal title, job position, etc. of the calling user's trusted business card, and wait for the called user to answer.

[0136] In summary, for the method of this application, the calling and called terminals do not need to store the public and private key pairs, and do not need to deploy a password module, so the implementation and management costs are relatively low. At the same time, based on attribute certificates, public key certificates, and LDAP directory servers, it can make better use of existing products, test tools, and open source code, reducing the development cost.

[0137] On the other hand, the present invention also discloses a computer-readable storage medium storing a computer program, which when executed by a processor causes the processor to execute the specified module system of any trusted business card incoming call system in the above embodiments or some steps in any trusted business card incoming call method in the above embodiments.

[0138] On yet another hand, the present invention also discloses a computer device including a memory and a processor, where the memory stores a computer program, and when the computer program is executed by the processor, it causes the processor to execute the specified module system of any trusted business card incoming call system in the above embodiments or some steps in any trusted business card incoming call method in the above embodiments.

[0139] In yet another embodiment provided by this application, there is also provided a computer program product containing instructions, which when running on a computer causes the computer to execute the specified module system of any trusted business card incoming call system in the above embodiments or some steps in any trusted business card incoming call method in the above embodiments.

[0140] It can be understood that the system provided by the embodiments of the present invention corresponds to the method provided by the embodiments of the present invention. The explanations, examples, and beneficial effects of the relevant content can refer to the corresponding parts in the above method.

[0141] The communication bus mentioned in the above electronic device can be a peripheral component interconnect standard bus or an extended industry standard architecture bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0142] The communication interface is used for communication between the above-mentioned electronic device and other devices.

[0143] The memory may include a random access memory, or may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0144] The aforementioned processor may be a general-purpose processor, including a central processing unit, a network processor, etc.; it may also be a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0145] It should also be noted that the electronic device further includes a terminal device, which may also be referred to as a terminal, a user equipment, a mobile station, a mobile terminal, etc. The terminal device may be a mobile phone, a smart TV, a wearable device, a tablet computer, a computer with wireless transceiver function, a virtual reality terminal device, an augmented reality terminal device, a wireless terminal in industrial control, a wireless terminal in driverless, a wireless terminal in remote surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, and so on. The specific technologies and specific device forms adopted by the terminal device in the embodiments of the present application are not limited.

[0146] In the above embodiments, it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (or wireless) manner. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium, etc.

[0147] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

[0148] In addition, it should be noted that if there are directional indications in the embodiments of the present invention, the directional indications are only used to explain the relative positional relationship and movement conditions between components in a specific posture. If the specific posture changes, the directional indications will also change accordingly.

[0149] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present invention, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the meaning of "and / or" appearing throughout the text includes three parallel scenarios. Taking "A and / or B" as an example, it includes Scenario A, or Scenario B, or the scenario where both A and B are satisfied simultaneously. In addition, in the embodiments of the present invention, "a plurality of" means two or more. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

Claims

1. A trustworthy business card incoming call system, characterized in that, Including: An electronic authentication module, which is used to issue digital certificates for enterprises and institutions with a first user; A business card issuing module, which is used to edit the business card information of the first user and export a vCard format file, and then use the private key of the digital certificate to sign the business card of the first user's vCard format file to obtain a trusted business card, and publish it to the directory server for the calling terminal to download; A calling terminal bound to the first user and a called terminal bound to the second user; A directory server, which is used to authenticate other system structures and provide specified access permissions to the calling terminal and the called terminal, and is used for the calling terminal to download the trusted business card and the called terminal to verify the trusted business card; The calling terminal is connected to the called terminal through a VoIP voice call communication network. The calling terminal downloads the trusted business card of the first user from the directory server for transmission to the called terminal for display.

2. The trustworthy business card incoming call system according to claim 1, characterized in that The electronic authentication module is used to publish the CA certificate, the issued digital certificate and the digital certificate revocation list to the directory server; The business card issuing module issues a trusted business card and a trusted business card revocation list according to the employee information of the enterprise or institution for publishing to the directory server; The calling terminal and the called terminal download the CA certificate, the digital certificate, the digital certificate revocation list, the trusted business card and the trusted business card revocation list through the directory server for verifying the trusted business card of the first user.

3. A trustworthy calling method for business cards, implemented based on the trustworthy calling system for business cards described in any one of the above claims 1-2, characterized in that, Including the following steps: S1. Enterprises and institutions apply for organization digital certificates through the electronic authentication module; S2. After the electronic authentication module audits the information of enterprises and institutions, it issues organization digital certificates, stores the digital certificates in a usbkey key medium for designated personnel of enterprises and institutions, and regularly publishes the issued organization digital certificates, the CA certificate of the electronic authentication module and the digital certificate revocation list to the directory server; S3. After the enterprise or institution enters the employee information, the business card issuing module generates a vCard format file and calls the private key of the digital certificate for signature to issue a trusted business card for the employee; S4. The directory server creates an enterprise or institution directory, publishes the trusted business cards issued by the enterprise or institution to this directory, and publishes the list of revoked trusted business cards at the same time; S5. The employees of the enterprise or institution perform identity authentication and binding on the calling terminal, and download the CA certificate of the electronic authentication module, the organization digital certificate of the enterprise or institution, the digital certificate revocation list, the trusted business card and the trusted business card revocation list from the directory server; S6. The calling terminal verifies the trusted business card according to the information of the CA certificate, the digital certificate revocation list, the organization digital certificate of the enterprise or institution and the trusted business card revocation list. After the verification is passed, the trusted business card is installed; S7. When making business contacts, select the trusted business card to be displayed on the calling terminal and then dial. The calling terminal transmits specified data to the called terminal as authentication information, and downloads the trusted business card of the calling terminal after authentication by the directory server; S8. The called terminal obtains the trusted business card passed from the calling terminal to obtain the mobile phone number on the trusted business card, and compares it with the calling incoming call number. If the comparison fails, it means the trusted business card is invalid and is displayed on the called terminal. Then, it is up to the called user to decide whether to answer the call. If the comparison passes, proceed to the next step; S9. The called terminal downloads the CA certificate, digital certificate revocation list, digital certificate of the enterprise or institution to which the trusted business card belongs, and the trusted business card revocation list from the directory server; S10. The called terminal verifies the trusted business card according to the specified conditions through the downloaded information. When all verifications pass, it means the trusted business card is valid and the specified information of the trusted business card is displayed, waiting for the called user to answer the call. If the verification fails, it displays that the trusted business card is invalid, and it is up to the called user to decide whether to answer the call.

4. The trustworthy calling method for business cards according to claim 3, characterized in that, The directory server includes the following secondary directories: The "dc=TrustCAs" directory, and the sub-entries are each trusted electronic authentication service CA institution in the electronic authentication module; The "dc=Organization" directory, and the sub-entries are each trusted business card issuing unit in the business card issuing module. The RDN of the trusted business card issuing unit entry includes the serialNumber item and the o item. The value of the serialNumber item is the unified social credit code of the enterprise or institution, and the value of the o item is the name of the enterprise or institution. The sub-entries of the trusted business card issuing unit entry are the employees of this unit.

5. The trusted business card incoming call method according to claim 3, characterized in that, The directory server performs SMS authentication on the calling terminal. The specific authentication process includes: a1. The user enters the unit name and mobile phone number, obtains the first data request and sends it through the client; a2. The server queries the corresponding entry from the directory server directory according to the unit name and mobile phone number in the first data request: If it does not exist, the process ends, and an authentication failure response is directly returned to the client; If an entry exists, an SMS authentication code is sent to the mobile phone number of this entry, and then a waiting for continued authentication response is returned to the client; a3. After the user receives the SMS verification code, combines the unit name and mobile phone number, and sends the second data request through the client again; a4. The server queries the entry from the directory according to the unit name and mobile phone number in the second data request: If it does not exist, the process ends, and an authentication failure response is returned to the client; If an entry exists, compare the SMS authentication code. If the comparison of the SMS authentication code fails, the process ends, and an authentication failure data response is returned to the client. If the comparison of the SMS authentication code is successful, the authentication is successful, and a corresponding authentication success data response is returned to the client.

6. The trustworthy calling method for business cards according to claim 3, wherein The acquisition and generation steps of the trusted business card in step S3 include: Based on the attribute certificate, expand the attribute data through vCardEx, write the vCard format data, and finally generate the trusted business card. The signature value of the attribute certificate is obtained by signing the attribute certificate with the private key of the enterprise or institution digital certificate.

7. The trustworthy calling method for business cards according to claim 3, wherein The trusted business card performs data transfer based on the serial number. The specific process includes: b1. The calling terminal reads out the serial number of the trusted business card to be transmitted, and adds a first parameter to the Call-Info header field of the INVITE message. The first parameter contains the mobile phone number, the company name, and the HEX encoding of the serial number of the trusted business card. b2. The called terminal obtains the first parameter from the INVITE message, uses the mobile phone number and the company name in the first parameter as the user name data, and inputs the HEX encoding of the serial number of the trusted business card in the first parameter as the password data to the directory server for authentication. b3. The directory server queries the trusted business card of the calling terminal user according to the user name data, reads out its serial number, and uses it to compare with the password data of the called terminal. If they are the same, the trusted business card is returned; if not, an "invalidCredentials" error is returned. b4. If the called terminal receives the "invalidCredentials" error returned by the directory server, it prompts that the acquisition of the trusted business card fails. If the called terminal receives the trusted business card returned by the directory server, the process proceeds to the next step.

8. The trustworthy calling method for business cards according to claim 3, wherein The specific verification method for the called terminal to verify the validity of the trusted business card includes: c1. Obtain its expiration date from the trusted business card. If the current time is not within its expiration date, the verification fails. If it is within the expiration date, further obtain the vCard from the vCardExt extension item of the trusted business card, and obtain the mobile phone number and the company name from the attributes of the vCard. Compare the mobile phone number in the vCard attribute with the mobile phone number of the incoming call and the company name in the vCard attribute with the issuer name in the trusted business card in turn. If any of the comparison results is inconsistent, the verification fails. c2. According to the unified social credit code and the company name in the trusted business card, download the signature certificate of the company and the trusted business card revocation list from the directory server. Read the CA certificate and the digital certificate revocation list from the cache or download them from the directory server according to the issuer of the company signature certificate. And verify whether the downloaded CA certificate is issued by the trust root preset by the called terminal. If not, the verification fails. c3. Based on the specified public key certificate verification standard, verify the company's signature certificate according to the CA certificate and the digital certificate revocation list. If all requirements cannot be met, the verification fails. c4. Based on the attribute certificate verification standard, verify the trusted business card according to the company signature certificate and the trusted business card revocation list. If all requirements cannot be met, the verification fails. c5. After all the above verifications pass, display the specified information of the calling user's trusted business card according to the information of the vCard, and wait for the called user to answer the call.

Citation Information

Patent Citations

  • Calling subscriber identity display method, terminal and system based on super SIM (Subscriber Identity Module) card

    CN114900577A

  • Call processing method, related equipment and storage medium

    CN115915112A

  • Business card digital certificate authentication method, terminal, system and equipment

    CN116827550A

  • Identity display method based on trusted communication, terminal and server

    CN116866473A

  • Identity selectable display method, terminal and system based on trusted communication

    CN117478356A