Metering code-based data encryption method, data tampering verification method and system

By embedding the information dot matrix of encrypted data in the graphic identification of the electronic certificate, combining the local binary mode texture characteristics of the image and the Fourier transform high-frequency components, a double tamper-proof system of metrology code is built, which solves the problem of tampering with electronic certificates and achieves efficient and reliable verification and data integrity.

CN120342785AActive Publication Date: 2025-07-18ZHONGBO INFORMATION TECH RES INST CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510811958.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In the prior art, the tamper-proof technology of electronic certificates has the problem that QR codes are easily copied, digital watermarks are insufficient robustness and strong verification dependency, and it is difficult to take into account the needs of multimedia adaptability and high-precision tamper-proof.

Method used

Using a data encryption method based on metrology code, a metering code is generated by embedding the information dot matrix of encrypted data in the graphic identification of the electronic certificate, and combining the local binary mode texture characteristics of the image and the Fourier transform high-frequency components, a double tamper-proof system for physical layer and data layer is constructed, and a cloud platform is used for secure storage and verification.

Benefits of technology

It realizes the inseparability of anti-counterfeiting labels, reduces manual dependence, improves verification efficiency, ensures data integrity and verification reliability, and adapts to the high-precision tamper-proof requirements of different media.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342785A_ABST
    Figure CN120342785A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and provides a data encryption method and system based on a measurement code, and a data tampering verification method and system, and the measurement code and an image identifier of an electronic certificate are encrypted and bound, so that the inseparability of an anti-counterfeiting identifier is realized, the form limitation of a traditional two-dimensional code is broken through, the manual dependence is reduced, and the security of the electronic certificate is improved. The verification efficiency is improved; a physical layer and data layer dual tamper-proof system is constructed, cloud platform secure storage is combined, data integrity and verification reliability are ensured, and the full-life-cycle credibility of key electronic files such as measurement certificates and detection reports can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a data encryption method, a data tampering verification method and a system based on a measurement code. Background Art

[0002] With the acceleration of the digital transformation process, electronic certificates such as measurement certificates and inspection reports have been widely used in key fields of the national economy such as quality supervision and industrial certification. With the deepening of the dependence, the security issues of electronic certificates have become increasingly prominent. In particular, the tampering problem of electronic certificates is related to the integrity of enterprise information and the authenticity of data. To address this challenge, the industry has developed a variety of anti-tampering technologies.

[0003] The current mainstream anti-tampering technologies in the measurement industry mainly rely on means such as two-dimensional codes, digital watermarks and cryptographic signatures, but there are still significant defects: two-dimensional codes, as public carriers, are easy to be copied or maliciously replaced and cannot resist man-in-the-middle attacks; digital watermarks are limited by insufficient algorithm robustness and are easy to fail in scenarios such as file compression and printing; traditional digital signatures rely on third-party centralized platforms, with risks of single-point failures and key leakage; moreover, most of them are difficult to balance multi-media adaptability and high-precision anti-tampering requirements, resulting in strong manual dependence and low verification efficiency. Summary of the Invention

[0004] In order to solve the above technical problems, the present invention provides a data encryption method, a data tampering verification method and a system based on a measurement code, and solves the problems of easy tampering, poor anti-interference ability and strong verification dependence of anti-counterfeiting marks in the prior art.

[0005] The technical solution adopted by the present invention is as follows: A data encryption method based on a measurement code, used for a measurement code generation end, the method includes: S11, embedding an information dot matrix containing encrypted data in a graphic logo of an electronic certificate issuing agency to generate a measurement code corresponding to the electronic certificate, the encrypted data being the core data of the encrypted electronic certificate, and whether each information point in the information dot matrix exists represents different binary digital codes; S12, extracting the original image local binary pattern texture feature and the original Fourier transform high-frequency component of the measurement code to obtain a physical verification benchmark of the measurement code; S13, encapsulating the physical verification benchmark and the core data into a data packet, and encrypting the data packet using an asymmetric encryption algorithm and storing it on a cloud platform.

[0006] According to an embodiment of the present invention, step S11 specifically includes: S111, extracting the background area in the graphic logo of the electronic certificate issuing authority, and using the background area as the security area for embedding the information dot matrix; S112, generating binary encrypted data based on the core data of the electronic certificate according to the cryptographic hash algorithm, and generating an information dot matrix containing the encrypted data based on the binary encrypted data; S113, embedding the information dot matrix into the security area based on the Alpha blending technology to obtain a measurement code corresponding to the electronic certificate.

[0007] According to an embodiment of the present invention, before step S111, it further includes: performing image enhancement processing on the graphic logo, and the image enhancement processing includes grayscale conversion, denoising, and edge sharpening.

[0008] According to an embodiment of the present invention, in step S13, when storing the encrypted data packet, the digital signature and dynamic token of the issuing authority are also attached, and when the issuing authority updates the electronic certificate corresponding to the measurement code on the cloud platform, authorization authentication is also performed based on the digital signature and the dynamic token.

[0009] A data tampering verification method based on a measurement code, used for the measurement code verification end, the method includes: S21, receiving the public key sent by the measurement code generation end; S22, sending a verification request to the cloud platform based on the public key, extracting the data packet corresponding to the measurement code, and obtaining the physical verification benchmark of the measurement code and the core data of the electronic certificate, and the measurement code is generated according to step S11 in the data encryption method described above; S23, extracting the local binary pattern texture feature and the high-frequency component of the Fourier transform of the measurement code, and comparing with the physical verification benchmark for the first data tampering verification; S24, decrypting the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data, and comparing with the core data stored on the cloud platform for the second data tampering verification.

[0010] According to an embodiment of the present invention, the step of decrypting the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data specifically includes: locating the edge contour of the graphic logo in the measurement code through the Hough transform, and performing distortion correction on the measurement code based on the edge contour; locating and traversing the information dot matrix on the measurement code based on a preset security area location algorithm, and decrypting it to obtain the current core data corresponding to the encrypted data.

[0011] According to an embodiment of the present invention, it further includes hierarchical response based on the results of the first data tampering verification and the second data tampering verification, specifically including: when the measurement code passes the first data tampering verification and the second data tampering verification, a first-level response is triggered to display the traceability information of the electronic certificate; when the measurement code only shows an abnormality in the verification of the high-frequency components of the Fourier transform during the first data tampering verification but passes the second data tampering verification, a second-level response is triggered to prompt manual review; when the measurement code shows an abnormality in the verification of the local binary pattern texture features of the image or fails to pass the second data tampering verification during the first data tampering verification, a third-level response is triggered to prompt suspected tampering.

[0012] According to an embodiment of the present invention, the original certificate file of the electronic certificate is also stored on the cloud platform.

[0013] A data encryption system based on a measurement code, used for the measurement code generation end, the system includes: a generation module, the generation module is used to embed an information dot matrix containing encrypted data in the graphic logo of the electronic certificate issuing agency to generate a measurement code corresponding to the electronic certificate, the encrypted data is the core data of the encrypted electronic certificate, and whether each information point in the information dot matrix exists represents different binary codes; a first extraction module, the first extraction module is used to extract the original local binary pattern texture features and the original high-frequency components of the Fourier transform of the measurement code to obtain the physical verification benchmark of the measurement code; a storage module, the storage module is used to encapsulate the physical verification benchmark and the core data into a data packet, encrypt the data packet using an asymmetric encryption algorithm and store it on the cloud platform.

[0014] A data tampering verification system based on a measurement code, used for the measurement code verification end, the system includes: a receiving module, the receiving module is used to receive the public key sent by the measurement code generation end; a second extraction module, the second extraction module is used to send a verification request to the cloud platform based on the public key, extract the data packet corresponding to the measurement code to obtain the physical verification benchmark of the measurement code and the core data of the electronic certificate, and the measurement code is generated according to step S11 in the data encryption method described above; a first verification module, the first verification module is used to extract the local binary pattern texture features and the high-frequency components of the Fourier transform of the measurement code and compare them with the physical verification benchmark for the first data tampering verification; a second verification module, the second verification module is used to decrypt the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data and compare it with the core data stored on the cloud platform for the second data tampering verification.

[0015] The beneficial effects of the present invention: The data encryption method, data tampering verification method and system based on metering codes of the present invention encrypt and bind the metering codes with the image identification of the electronic certificate, realizing the inseparability of the anti-counterfeiting identification, breaking through the morphological limitations of traditional two-dimensional codes, reducing the manual dependence, and improving the verification efficiency; constructing a dual anti-tampering system for the physical layer and the data layer, and combining with the secure storage of the cloud platform to ensure data integrity and verification reliability, which can significantly improve the credibility of the whole life cycle of key electronic documents such as metering certificates and inspection reports. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flowchart of the data encryption method based on metering codes according to an embodiment of the present invention; Figure 2 It is a flowchart of an implementation manner of the data tampering verification method of the present invention; Figure 3 It is a flowchart of another implementation manner of the data tampering verification method of the present invention; Figure 4 It is a flowchart of the hierarchical response of the data tampering verification method according to an embodiment of the present invention; Figure 5 It is a block diagram of the data encryption system based on metering codes according to an embodiment of the present invention; Figure 6 It is a block diagram of the data tampering verification system based on metering codes according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work shall fall within the protection scope of the present invention.

[0018] As Figure 1 shown, the data encryption method based on metering codes according to an embodiment of the present invention is used for the metering code generation end, and the data encryption method includes the following steps S11-S14: S11. In the graphic identification of the electronic certificate issuing agency, an information dot matrix containing encrypted data is embedded to generate a metering code corresponding to the electronic certificate. The encrypted data is the core data of the encrypted electronic certificate, and whether each information point in the information dot matrix exists represents different binary digital codes.

[0019] Optionally, the metering code generation end may be the intelligent service device of the electronic certificate issuing agency, or the intelligent service device of the metering code generation agency commissioned by the issuing agency to generate metering codes, etc. This embodiment does not limit it. In one embodiment of the present invention, step S11 specifically includes steps S111 - S113: S111, extract the background area in the graphic logo of the electronic certificate issuing authority, and use the background area as the security area for embedding the information dot matrix. Specifically, the watershed algorithm can be used to segment the Logo main body and the background area. Combining the gradient amplitude calculation, select the background area or non-critical areas with low interference at the edges as the security area for subsequent information dot matrix embedding.

[0020] In one embodiment of the present invention, to improve the image quality and thus enhance the subsequent segmentation and embedding accuracy, before step S111, it may further include: performing image enhancement processing on the graphic logo provided by the issuing authority. Among them, the image enhancement processing may include operations such as grayscale conversion, denoising, and edge sharpening. This embodiment is not limited thereto.

[0021] S112, generate binary encrypted data based on the core data of the electronic certificate according to the cryptographic hash algorithm, and generate an information dot matrix containing the encrypted data based on the binary encrypted data.

[0022] The core data of the electronic certificate may include the certificate hash value, uniqueness code, timestamp, and file storage address. The binary encrypted data generated by the cryptographic hash algorithm can be used to verify the integrity of the certificate data. Any change in the content will cause an irreversible change in the hash value; the uniqueness code is a unique identification code for each measurement certificate, ensuring the permanent non-repetitiveness of different certificates in the cloud platform; the timestamp will accurately record the certificate issuance moment; the file storage address points to the original PDF (Portable Document Format) file, facilitating quick retrieval.

[0023] Specifically, a random sequence can be generated based on the core data of the electronic certificate through the Logistic chaotic mapping algorithm, and the data bits are encrypted in combination with the private key of the issuing authority to dynamically determine the coordinate distribution of the information points in the grid, preventing the cracking of the regular characteristics of the information point distribution.

[0024] S113, embed the information dot matrix into the security area based on the Alpha blending technology to obtain the measurement code corresponding to the electronic certificate. That is, the information points and the Logo background pixels are weighted and superimposed based on the Alpha value. Specifically, in the dark area, light-colored information points with low transparency can be used, and in the light area, dark gray can be used to improve the contrast, while retaining the original color hierarchy of the image, ensuring that the embedded information points are visually naturally unified with the original Logo and avoiding abnormal human eye perception.

[0025] Specifically, by adjusting the transparency and color gradient parameters of the information points, it is ensured that the embedded area naturally blends with the original background, and then a visually lossless metacode image is output. The metacode retains the visual characteristics of the original Logo while supporting high-resolution output to meet the clarity requirements of different media. For example, each information point is set as a circle or square with a diameter not exceeding 0.5 mm, and the color difference between its color and the Logo background color is controlled within the professional color standard ΔE≤5 to ensure that the normal visual effect of the Logo is not affected.

[0026] In a specific embodiment of the present invention, the graphical logo of the issuing agency is the Logo of the issuing agency, which is presented as a circular logo with a dark blue background for the outer ring, a light gray instrument icon in the center, and the Chinese name of the agency surrounded at the bottom. When generating the metacode, the Logo can be first grayscale processed, and then the clarity of the Logo image can be optimized through denoising and edge sharpening. The dark blue background of the outer ring is separated from the central icon and text using an image segmentation algorithm, and the outer ring is selected as the safe area, avoiding the bottom text and divided into a 12×12 grid with each unit size of 0.4 mm×0.4 mm to adapt to A4 paper printing and ensure that the visual effect of the core elements of the Logo is not damaged when subsequent information points are embedded. After image preprocessing, the proportion of the background area of the outer ring is about 30%, providing a concealed and stable embedding space for encrypted data.

[0027] When embedding the information dot matrix, light gray information points (RGB: 200, 200, 200) are embedded in the dark blue outer ring area with a transparency set to 8% to make it blend naturally with the background; dark gray information points (RGB: 80, 80, 80) are embedded at the edge of the light gray icon with a transparency of 12%; at the junction of dark blue and light gray, the color gradient is synchronously adjusted to make the information points blend naturally with the background. The finally output metacode image maintains the original visual effect of the Logo while meeting the different resolution requirements of 300 dpi printing and 72 dpi screen display, ensuring that the metacode meets the concealment requirements of the information points whether printed on a paper certificate or displayed in an electronic document.

[0028] S12, extract the local binary pattern (LBP, Local Binary Pattern) texture features and the high-frequency components of the original Fourier transform of the metacode's original image to obtain the physical verification benchmark of the metacode. Among them, the local binary pattern texture features generate binary codes by analyzing the brightness difference between the pixel point and its surrounding neighborhood, mainly used to quantify the microscopic texture features of the local area of the image and focus on local detail anomalies; the high-frequency components of the Fourier transform decompose the image into different frequency components, focusing on the edges and detail information in the high-frequency band, and abnormal changes in the high-frequency energy can determine whether the overall structure of the image is damaged.

[0029] S13. Encapsulate the physical verification benchmark and core data into a data packet, encrypt the data packet using an asymmetric encryption algorithm, and store it on the cloud platform.

[0030] Based on the storage service characteristics of the cloud platform, the original data of the electronic certificate can be classified and managed. The lightweight core data associated with the measurement code is stored in the cloud database, supporting high-frequency reading and writing and fast retrieval; the original certificate file is stored in the cloud object storage service, and fast retrieval can be achieved through hash indexing. At the same time, the cloud platform audit log function is enabled to record data access behaviors and operation traces.

[0031] In an embodiment of the present invention, when storing the encrypted data packet in step S13, the digital signature and dynamic token of the issuing agency can also be attached. When the issuing agency updates the electronic certificate corresponding to the measurement code on the cloud platform, authorization authentication is also performed based on the digital signature and the dynamic token to ensure that only the authorized measurement code verification end can access the data and guarantee the legality of each sent request.

[0032] In an embodiment of the present invention, the measurement code generation end or the issuing agency can also perform role permission control on the cloud platform, that is, predefined roles are assigned operation permissions. For example, the administrator role of the measurement code generation end or the issuing agency can upload and modify the benchmark feature values, including but not limited to the physical verification benchmark of the measurement code, while the measurement code verification end can only read the data to ensure the minimumization of permissions.

[0033] When the issuing agency uploads the instrument calibration certificate, the cloud platform first verifies the dynamic token in the request to confirm the identity of the issuing agency, and then matches whether the role of the request terminal has the data upload permission. After passing the verification, data storage is allowed and the audit log is recorded; if the permission check fails, an alarm will be triggered and the access permission of the abnormal terminal will be frozen.

[0034] According to the data encryption method based on the measurement code of the present invention, by encrypting and binding the measurement code with the carrier image of the electronic certificate, that is, the graphic identifier, the inseparability of the anti-counterfeiting identifier is realized, and at the same time, the morphological limitation of the traditional two-dimensional code is broken through; by encapsulating and encrypting the physical verification benchmark and core data on the cloud platform, the data integrity and verification reliability are ensured, so that when the measurement code verification end performs data tampering verification, multi-dimensional verification can be realized through physical feature verification and digital feature verification, improving the tampering verification accuracy, reducing the manual dependence, and improving the verification efficiency; moreover, the local binary pattern texture feature of the image is sensitive to subtle tampering, and the high-frequency component of the Fourier transform can effectively identify global tampering such as image blurring, stretching deformation, or large-area coverage. The characteristics of the two complement each other, covering physical attack scenarios from micro to macro, and having strong tampering recognition ability.

[0035] Such as Figure 2As shown, the data tampering verification method based on measurement codes according to the embodiments of the present invention is used for a measurement code verification end, and the data tampering verification method includes steps S21 - S24: S21. Receive the public key sent by the measurement code generation end. Among them, the public key can be generated by the measurement code generation end based on an asymmetric encryption algorithm when encapsulating the data packet corresponding to the measurement code, so that the measurement code verification end can perform data tampering verification through the cloud platform based on the measurement code and its corresponding public key.

[0036] Optionally, the measurement code verification end can be a mobile client application or a client system, etc., which is not limited in this embodiment. S22. Send a verification request to the cloud platform based on the public key, extract the data packet corresponding to the measurement code, and obtain the physical verification benchmark of the measurement code and the core data of the electronic certificate. The measurement code can be generated by step S11 in the above data encryption method.

[0037] S23. Extract the local binary pattern texture feature and the high-frequency component of the Fourier transform of the measurement code image, and compare them with the physical verification benchmark for the first data tampering verification.

[0038] S24. Decrypt the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data, and compare it with the core data stored on the cloud platform for the second data tampering verification.

[0039] It can be understood that the first data tampering verification and the second data tampering verification can be performed on the measurement code verification end or on the cloud platform. When the data tampering verification is performed on the cloud platform, when the measurement code verification end sends a verification request to the cloud platform, it also simultaneously sends the local binary pattern texture feature and the high-frequency component of the Fourier transform extracted from the measurement code, the feature hash value of the current core data obtained by decrypting the information dot matrix on the measurement code, and the dynamic token. The cloud platform can perform the first data tampering verification and the second data tampering verification after verifying the legality of the dynamic token, the data signature, and the hash consistency, and return the data tampering verification result.

[0040] In an embodiment of the present invention, the step of decrypting the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data specifically includes the following steps S241 - S242: S241. Locate the edge contour of the graphic identifier in the measurement code through the Hough transform, and perform distortion correction on the measurement code based on the edge contour, so as to correct the image distortion problem caused by the shooting angle, distance, etc.

[0041] S242. Locate and traverse the information dot matrix on the measurement code based on the preset security area positioning algorithm, and decrypt it to obtain the current core data corresponding to the encrypted data.

[0042] In the scenario of printing a paper measurement certificate, when the measurement code verification terminal scans the measurement code, it may also face problems such as low printing quality, dirt, or creases. At this time, the Reed-Solomon error correction code can be used to automatically repair the loss of some information points caused by ink bleeding. At the same time, the watershed algorithm is used to separate the crease area, and the information points with clear edges are preferentially parsed.

[0043] In an embodiment of the present invention, the data obtained after decryption by the measurement code verification terminal is the hash value corresponding to the current core data, that is, a binary sequence. The current core data text may not be parsed in the measurement code verification terminal. Instead, the consistency comparison can be directly performed between the hash value of the current core data and the hash value of the core data stored on the cloud platform to achieve the second data tampering verification, and this embodiment is not limited.

[0044] As Figure 3 shown, in an embodiment of the present invention, the data tampering verification method further includes: S25, performing hierarchical response based on the results of the first data tampering verification and the second data tampering verification. Step S25 may specifically include the following steps S251-S253: S251, when the measurement code passes the first data tampering verification and the second data tampering verification, trigger a first-level response to display the traceability information of the electronic certificate. Among them, the traceability information may include the authenticity status of the certificate, the information of the issuing agency, the detection instrument number, the detection / calibration time, etc.

[0045] S252, when only the high-frequency component verification of the Fourier transform is abnormal during the first data tampering verification of the measurement code, but it passes the second data tampering verification, it indicates that the measurement code image may be damaged as a whole, trigger a second-level response, and prompt for manual review.

[0046] S253, when the local binary pattern texture feature verification of the image is abnormal during the first data tampering verification of the measurement code, or it fails to pass the second data tampering verification, trigger a third-level response to prompt suspected tampering. Among them, the abnormal local binary pattern texture feature verification of the image indicates that there may be local targeted tampering, so a third-level response will be directly triggered, and at the same time, the abnormal area can be located to facilitate manual review.

[0047] As Figure 4As shown, in an embodiment of the present invention, step S25 can be carried out synchronously with step S23 and step S24. When performing the first data tampering verification in step S23, if an abnormality occurs in the verification of the local binary pattern (LBP) texture feature of the image, a third-level response can be directly triggered to indicate suspected tampering, without continuing to perform the second data tampering verification in step S24, thereby simplifying the verification process, improving the response efficiency, and avoiding resource waste. If the measurement code passes the first data tampering verification or only has an abnormality in the verification of the high-frequency components of the discrete Fourier transform, then step S24 is continued to perform the second data tampering verification. If the second data tampering verification fails, a third-level response is triggered; otherwise, based on the result of the first data tampering verification (pass at the physical layer or abnormality at the physical layer) on the basis of the second data tampering verification passing, a comprehensive determination is made, and then a first-level response or a second-level response is triggered.

[0048] By grading the responses to different data tampering verification results, the reliability of the verification can be effectively ensured, the credibility of the entire life cycle of the measurement certificate can be improved, and a traceable and non-repudiable digital certificate can be provided for scenarios such as quality supervision and judicial evidence collection.

[0049] In an embodiment of the present invention, the original certificate file of the electronic certificate is also stored on the cloud platform. When the first-level response is triggered, the user can also read the original certificate file of the electronic certificate from the cloud platform through the measurement code verification terminal.

[0050] According to the data tampering verification method based on the measurement code of the present invention, the data tampering verification is respectively carried out on the measurement code based on the physical verification benchmark and the core data stored on the cloud platform, forming a multi-level verification architecture of "physical characteristics - encrypted data - cloud storage evidence", solving the core contradiction of the coexistence of carrier vulnerability and verification dependence, and meeting the requirements of long-term storage of electronic certificates, high anti-tampering and cross-media verification; moreover, the local binary pattern texture feature of the image is sensitive to subtle tampering, and the high-frequency components of the Fourier transform can effectively identify global tampering such as image blurring, stretching deformation or large-area coverage. The characteristics of the two complement each other, and can cover physical attack scenarios from micro to macro, with strong tampering recognition ability.

[0051] Corresponding to the above-mentioned data encryption method based on the measurement code, the present invention also proposes a data encryption system based on the measurement code for the measurement code generation end.

[0052] As Figure 5As shown in the figure, the data encryption system of the embodiment of the present invention includes: a generation module 11, a first extraction module 12, and a storage module 13. Among them, the generation module 11 is used to embed an information dot matrix containing encrypted data in the graphic logo of the electronic certificate issuing authority to generate a measurement code corresponding to the electronic certificate. The encrypted data is the core data of the encrypted electronic certificate, and whether each information point in the information dot matrix exists represents different binary codes; the first extraction module 12 is used to extract the original image local binary pattern texture features and the original Fourier transform high-frequency components of the measurement code to obtain the physical verification benchmark of the measurement code; the storage module 13 is used to encapsulate the physical verification benchmark and the core data into a data packet, encrypt the data packet using an asymmetric encryption algorithm, and store it on the cloud platform.

[0053] In an embodiment of the present invention, the generation module 11 is specifically used for: extracting the background area in the graphic logo of the electronic certificate issuing authority, and using the background area as the security area for embedding the information dot matrix; generating binary encrypted data based on the core data of the electronic certificate according to the encryption hash algorithm, and generating an information dot matrix containing the encrypted data based on the binary encrypted data; embedding the information dot matrix into the security area based on the Alpha blending technology to obtain the measurement code corresponding to the electronic certificate.

[0054] In an embodiment of the present invention, the data encryption system further includes an image enhancement module for performing image enhancement processing on the graphic logo. The image enhancement processing includes grayscale conversion, denoising, and edge sharpening.

[0055] In an embodiment of the present invention, when the storage module 13 stores the encrypted data packet, it also attaches the digital signature and dynamic token of the issuing authority. When the issuing authority updates the electronic certificate corresponding to the measurement code on the cloud platform, it also performs authorization authentication based on the digital signature and dynamic token.

[0056] According to the data encryption system based on the measurement code of the present invention, by encrypting and binding the measurement code with the carrier image of the electronic certificate, that is, the graphic logo, it not only realizes the inseparability of the anti-counterfeiting logo but also breaks through the morphological limitations of traditional two-dimensional codes; by encapsulating and encrypting the physical verification benchmark and the core data on the cloud platform, it ensures data integrity and verification reliability, enabling the measurement code verification end to perform multi-dimensional verification through physical feature verification and digital feature verification when performing data tampering verification, improving the tampering verification accuracy, reducing the dependence on manual work, and improving the verification efficiency; moreover, the image local binary pattern texture features are sensitive to subtle tampering, while the Fourier transform high-frequency components can effectively identify global tampering such as image blurring, stretching deformation, or large-area coverage. The characteristics of the two complement each other, can cover physical attack scenarios from micro to macro, and have strong tampering recognition ability.

[0057] Corresponding to the above-mentioned data tampering verification method based on measurement codes, the present invention also proposes a data tampering verification system based on measurement codes for the measurement code verification end.

[0058] As Figure 6 shown, the data tampering verification system according to an embodiment of the present invention includes: a receiving module 21, a second extraction module 22, a first verification module 23, and a second verification module 24. Among them, the receiving module 21 is used to receive the public key sent by the measurement code generation end; the second extraction module 22 is used to send a verification request to the cloud platform based on the public key, extract the data packet corresponding to the measurement code, and obtain the physical verification benchmark of the measurement code and the core data of the electronic certificate. The measurement code is generated according to step S11 in the data encryption method described above; the first verification module 23 is used to extract the local binary pattern texture feature and the high-frequency component of the Fourier transform of the measurement code, and compare them with the physical verification benchmark for the first data tampering verification; the second verification module 24 is used to decrypt the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data, and compare it with the core data stored on the cloud platform for the second data tampering verification.

[0059] In an embodiment of the present invention, the step in which the second verification module 24 decrypts the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data specifically includes: positioning the edge contour of the graphic identifier in the measurement code through the Hough transform, and performing distortion correction on the measurement code based on the edge contour; positioning and traversing the information dot matrix on the measurement code based on a preset security area positioning algorithm, and decrypting it to obtain the current core data corresponding to the encrypted data.

[0060] In an embodiment of the present invention, the data tampering verification system further includes a response module. The response module performs hierarchical responses based on the results of the first data tampering verification and the second data tampering verification, specifically including: when the measurement code passes the first data tampering verification and the second data tampering verification, triggering a first-level response and displaying the traceability information of the electronic certificate; when only the high-frequency component verification of the Fourier transform is abnormal during the first data tampering verification of the measurement code, but it passes the second data tampering verification, triggering a second-level response and prompting for manual review; when the local binary pattern texture feature verification of the image is abnormal during the first data tampering verification of the measurement code, or it fails to pass the second data tampering verification, triggering a third-level response and prompting for suspected tampering.

[0061] In an embodiment of the present invention, the original certificate file of the electronic certificate is also stored on the cloud platform. When the first-level response is triggered, the user can also read the original certificate file of the electronic certificate from the cloud platform through the measurement code verification end.

[0062] According to the data tampering verification system of the embodiments of the present invention, data tampering verification is respectively performed on the metering codes based on the physical verification benchmarks and core data stored on the cloud platform, forming a multi-level verification architecture of "physical characteristics - encrypted data - cloud evidence storage", solving the core contradiction of the coexistence of carrier vulnerability and verification dependence, and meeting the requirements of long-term evidence storage, high anti-tampering and cross-media verification of electronic certificates; moreover, the local binary pattern texture features of the image are sensitive to subtle tampering, and the high-frequency components of the Fourier transform can effectively identify global tampering such as image blurring, stretching deformation or large-area coverage. The characteristics of the two complement each other, can cover physical attack scenarios from micro to macro, and have strong tampering recognition ability.

[0063] In the description of the present invention, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The meaning of "a plurality" is two or more, unless otherwise specifically defined.

[0064] In the description of this specification, the description with reference to the terms "an embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not have to be directed to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art of the present invention can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0065] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where the functions may be executed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art of the embodiments of the present invention.

[0066] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definable sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other appropriate processing as necessary, and then stored in a computer memory.

[0067] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0068] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0069] In addition, each functional unit in various embodiments of the present invention may be integrated into a processing module, or each unit may exist physically alone, or two or more units may be integrated into one module. The above integrated module may be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0070] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A data encryption method based on measurement codes, used for the measurement code generation end, characterized in that, The method includes: S11. Embed an information dot matrix containing encrypted data into the graphic logo of the electronic certificate issuing authority to generate a measurement code corresponding to the electronic certificate. The encrypted data is the core data of the encrypted electronic certificate, and the presence or absence of each information point in the information dot matrix represents different binary digits; S12. Extract the original image local binary pattern texture features and the original Fourier transform high-frequency components of the measurement code to obtain the physical verification benchmark of the measurement code; S13. Package the physical verification benchmark and the core data into a data packet, encrypt the data packet using an asymmetric encryption algorithm, and store it on the cloud platform.

2. The data encryption method according to claim 1, wherein Step S11 specifically includes: S111. Extract the background area in the graphic logo of the electronic certificate issuing authority, and use the background area as the security area for embedding the information dot matrix; S112. Generate binary encrypted data based on the core data of the electronic certificate according to the encrypted hash algorithm, and generate an information dot matrix containing the encrypted data based on the binary encrypted data; S113. Embed the information dot matrix into the security area based on the Alpha blending technique to obtain a measurement code corresponding to the electronic certificate.

3. The data encryption method according to claim 2, wherein Before step S111, it also includes: performing image enhancement processing on the graphic logo, and the image enhancement processing includes grayscale conversion, denoising, and edge sharpening.

4. The data encryption method according to claim 1, wherein In step S13, when storing the encrypted data packet, also append the digital signature and dynamic token of the issuing authority. When the issuing authority updates the electronic certificate corresponding to the measurement code on the cloud platform, also perform authorization authentication based on the digital signature and the dynamic token.

5. A data tampering verification method based on a metering code, which is used for a metering code verification end, and is characterized in that, The method includes: S21. Receive the public key sent by the measurement code generation end; S22. Send a verification request to the cloud platform based on the public key, extract the data packet corresponding to the measurement code, and obtain the physical verification benchmark of the measurement code and the core data of the electronic certificate; S23. Extract the image local binary pattern texture features and the Fourier transform high-frequency components of the measurement code, and compare them with the physical verification benchmark for the first data tampering verification; S24. Decrypt the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data, and compare it with the core data stored on the cloud platform for the second data tampering verification.

6. The data tampering verification method according to claim 5, wherein The step of decrypting the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data specifically includes: Locate the edge contour of the graphic logo in the measurement code through the Hough transform, and perform distortion correction on the measurement code based on the edge contour; Locate and traverse the information dot matrix on the measurement code based on a preset security area location algorithm, and decrypt it to obtain the current core data corresponding to the encrypted data.

7. The data tampering verification method according to claim 5, wherein It also includes performing hierarchical responses based on the results of the first data tampering verification and the second data tampering verification, specifically including: When the measurement code passes the first data tampering verification and the second data tampering verification, trigger a first-level response and display the traceability information of the electronic certificate; When only the high-frequency component verification of the Fourier transform is abnormal during the first data tampering verification of the measurement code, but the second-level response is triggered and manual review is prompted when the second data tampering verification is passed; When the local binary pattern texture feature verification of the image is abnormal during the first data tampering verification of the measurement code, or the third-level response is triggered and tampering is prompted when the second data tampering verification fails.

8. The data tampering verification method according to claim 5, wherein The original certificate file of the electronic certificate is also stored on the cloud platform.

9. A data encryption system based on measurement codes, for the measurement code generation end, characterized in that, The system includes: A generation module, which is used to embed an information dot matrix containing encrypted data in the graphic logo of the electronic certificate issuing agency to generate a measurement code corresponding to the electronic certificate. The encrypted data is the core data of the encrypted electronic certificate, and the presence or absence of each information point in the information dot matrix represents different binary codes; A first extraction module, which is used to extract the original local binary pattern texture feature and the original high-frequency component of the Fourier transform of the measurement code to obtain the physical verification benchmark of the measurement code; A storage module, which is used to encapsulate the physical verification benchmark and the core data into a data packet, encrypt the data packet using an asymmetric encryption algorithm, and store it on the cloud platform.

10. A data tampering verification system based on a measurement code, for a measurement code verification end, characterized in that, The system includes: A receiving module, which is used to receive the public key sent by the measurement code generation end; A second extraction module, which is used to send a verification request to the cloud platform based on the public key, extract the data packet corresponding to the measurement code, and obtain the physical verification benchmark of the measurement code and the core data of the electronic certificate; A first verification module, which is used to extract the local binary pattern texture feature and the high-frequency component of the Fourier transform of the measurement code, and compare them with the physical verification benchmark for the first data tampering verification; A second verification module, which is used to decrypt the information dot matrix on the measurement code to obtain the current core data corresponding to the encrypted data, and compare it with the core data stored on the cloud platform for the second data tampering verification.

Citation Information

Patent Citations

  • Efficient information lattice image and its generation and decoding method

    CN101086761A

  • Implement method for embedding large amount of information on printing media

    CN101127089A

  • Digital product content protection system and method based on digital water mark

    CN101165699A

  • Method and apparatus for binding data in combined anti-counterfeit label

    CN104883383A

  • File tamper-proofing method and system, terminal and trusted cloud platform

    CN107995148A