Online passport verification method and system based on secure transmission, terminal and medium
Through the secure transmission and two-factor verification mechanism between the client and the certificate verification management, the problem of poor security performance in the electronic passport verification method is solved, and fast and authentic online passport verification is achieved.
Patent Information
- Application Number
- CN202510850691.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-24
AI Technical Summary
The existing electronic passport verification methods have poor security performance and are prone to data tampering, resulting in low verification efficiency.
The online passport verification method based on secure transmission is adopted, and electronic data is generated through the client's identification verification of the electronic passport entity, the client generates verification request instructions and transmits them to the certificate verification management end, and the certificate verification management end generates data transmission instructions and transmits data through the key communication channel. The two-factor verification is combined with dynamic verification and auxiliary verification tools to generate verification results.
Ensure the speed and data authenticity of online verification, avoid data tampering, and improve verification efficiency.
Smart Images

Figure CN120358102A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electronic passport verification, and particularly relates to an online passport verification method, system, terminal and medium based on secure transmission. Background Art
[0002] Certificates are the identity proofs of individuals or organizations and are the basis for the normal conduct of various social and economic activities. Currently, counterfeit certificates are rampant in society, seriously affecting social order, and some even causing adverse social impacts or significant economic losses. Therefore, the anti-counterfeiting and authentication of certificates are necessary for the normal conduct of social activities and the basis for ensuring the validity of certificates.
[0003] However, some of the existing methods for verifying electronic passports have poor security performance and are prone to phenomena such as data tampering; thus, the verification efficiency is low. Summary of the Invention
[0004] The purpose of the present invention is to provide an online passport verification method based on secure transmission, which can solve the technical problem of low verification efficiency in the existing technology in view of the deficiencies of the existing technology.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions: An online passport verification method based on secure transmission, comprising: S1. The client performs entity recognition verification on the electronic passport to generate electronic data of the electronic passport; S2. The client generates a verification request instruction and transmits it to the certificate verification management end; S3. The certificate verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client; S4. The client constructs a key communication channel according to the data transmission instruction; and transmits the electronic data through the key communication channel to the certificate verification management end; S5. The certificate verification management end generates a verification operation instruction; wherein, the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is the auxiliary verification processing of the electronic data by the auxiliary verification tool; S6. According to the dynamic verification operation and the auxiliary verification tool verification operation, a verification result is generated.
[0006] Preferably, the step of the client performing entity recognition verification on the electronic passport to generate electronic data of the electronic passport includes: The client triggers the NFC communication function to generate an NFC communication collection operation; Identify and verify the entity corresponding to the electronic passport according to the NFC communication collection operation; Use the scanning component of the client to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0007] Preferably, the step that the client generates a verification request instruction and transmits it to the certificate verification management end includes: The client generates a verification request instruction and generates an online verification service certificate Covs; Send the verification request instruction and the online verification service certificate Covs to the passport management end; The passport management end generates a CSCA digital certificate according to the online verification service certificate Covs and the verification request instruction, and sends the CSCA digital certificate, the online verification service certificate Covs and to the certificate verification management end.
[0008] Preferably, the step that the certificate verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client includes: The certificate verification management end verifies the user authority of the client according to the verification request instruction; When the user authority passes, the certificate verification management end generates a data transmission instruction and sends the data transmission instruction to the client; The client generates an authentication operation for the real-time operator; and the step of S4 can be executed only when the authentication operation passes.
[0009] Preferably, the step that the client constructs a key communication channel according to the data transmission instruction includes: The client constructs a real-time secure channel for data transmission with the certificate verification management end, and forms a temporary secure channel with the real-time secure channel; The certificate verification management end generates a temporary DH key pair according to the temporary secure channel; wherein, the temporary DH key pair includes SK DH,Server temporary DH key of, PK DH,Server temporary DH key of, D Server temporary DH key of; The certificate verification management end uses the online verification service private key SK ovs to sign the PK DH,Server temporary DH key of; and sends and feedbacks the PK DH,Server temporary DH key of, the domain parameter D Server temporary DH key of and the signed PK DH,ServerThe temporary DH key to the client; The client uses Covs to verify PK DH,Server of the temporary DH key for signature operation to generate a real-time DH key pair; wherein, the real-time DH key pair includes SK DH,IC of the real-time DH key, PK DH,IC of the real-time DH key, and D Server of the real-time DH key; The client generates an instruction to calculate K1 = KA(SK IC , PK DH,Server , D Server ); and generates the first KS MAC and the first KS Enc of the secure channel session key; The client sends the real-time DH key of PK DH,IC to the certificate verification management terminal; The certificate verification management terminal calculates a new K2 = KA(SK Server , PK DH,IC , D Server ) instruction and generates the second KS MAC and the second KS Enc of the secure channel session key; According to the secure channel session key of the first KS MAC and the first KS Enc , and the secure channel session key of the second KS MAC and the second KS Enc perform mutual negotiation operation to construct a key communication channel.
[0010] Preferably, before the step of the certificate verification management terminal generating the inspection operation instruction, it further includes: After receiving the electronic data of the electronic passport, the certificate verification management terminal generates a verification identification page; Wherein, the dynamic verification operation, which is the step of generating a dynamic verification signal and sending a data retransmission instruction to the client, includes: While the background verification terminal of the certificate verification management terminal identifies the information data of the verification identification page, it generates a data retransmission instruction at a preset time point and a preset number of times, and transmits it to the client; The client transmits temporary data to the certificate verification management terminal; According to the comparison between the temporary data and the electronic data, a window of dynamic verification result is generated; The window of the dynamic verification result is hidden at the edge of the verification identification page; And / or, trigger the operation of the auxiliary verification tool according to the verification identification page; The auxiliary verification tool obtains pre-stored data in the data cloud platform according to the electronic data; Compare the electronic data with the pre-stored data to generate a window for the auxiliary verification result; The window of the auxiliary verification result is hidden at the edge of the verification identification page.
[0011] Preferably, the step of generating an inspection result according to the dynamic verification operation and the inspection operation of the auxiliary verification tool includes: Compare and verify the auxiliary verification result and the dynamic verification result; When the auxiliary verification result and the dynamic verification result are the same, close the windows of the auxiliary verification result and the dynamic verification result at the same time; and generate a confirmation feedback for passing the verification; When the auxiliary verification result and the dynamic verification result are different, summarize the windows of the auxiliary verification result and the dynamic verification result to form a pop-up window for data abnormality; The pop-up window is fully displayed on the verification identification page in a flashing form.
[0012] The present invention also discloses an online passport verification system based on secure transmission for performing the above-mentioned online passport verification method based on secure transmission; wherein, the online passport verification system based on secure transmission includes: An identification module, which is used to perform entity identification and verification on the electronic passport to generate electronic data of the electronic passport; A verification management module, which is used to generate an inspection request instruction and transmit it to the certificate verification management end, and the certificate verification management end generates a data transmission instruction according to the inspection request instruction and sends the data transmission instruction to the client; A verification module, which is used for the client to construct a key communication channel according to the data transmission instruction; and transmit the electronic data through the key communication channel to the certificate verification management end, and generate an inspection operation instruction; wherein, the inspection operation instruction includes a dynamic verification operation and an inspection operation of an auxiliary verification tool; An analysis module, which is used to generate an inspection result according to the dynamic verification operation and the inspection operation of the auxiliary verification tool.
[0013] The present invention also discloses an online passport verification terminal based on secure transmission, comprising: a memory, a processor, and an online passport verification program based on secure transmission stored in the memory and executable on the processor, wherein the online passport verification program based on secure transmission implements the steps of the online passport verification method based on secure transmission when executed by the processor.
[0014] The present invention also discloses a medium on which an online passport verification program based on secure transmission is stored. When the online passport verification program based on secure transmission is executed by a processor, the steps of the online passport verification method based on secure transmission are implemented.
[0015] The beneficial effect of the present invention is that the technical solution first verifies the authenticity of the entity corresponding to the electronic passport through the client to generate the electronic data of the electronic passport, thereby avoiding the counterfeiting of the physical passport and causing redundant subsequent operations; then the client generates a verification request instruction and transmits it to the document verification management end to implement the operation of the client actively requesting verification, avoiding the document verification management end collecting data from clients that do not need verification, thereby reducing the operating burden of the document verification management end and reducing data storage; then the document verification management end generates a data transmission instruction according to the verification request instruction, and sends the data transmission instruction to the client, and the client constructs a key according to the data transmission instruction communication channel; and transmitting the electronic data to the certificate verification management end through the key communication channel, so that after the client passes the verification, the client itself creates its key communication channel, thereby reducing the number and time of running operations of the certificate verification management end, and avoiding the client from receiving forged instructions from the certificate verification management end during the transmission process; then double verification is carried out through dynamic verification operation and auxiliary verification tool inspection operation to avoid data tampering and affecting its authenticity; finally, based on the dynamic verification operation and auxiliary verification tool inspection operation, a verification result is generated; thereby ensuring the speed of online verification and the authenticity of data, avoiding data tampering; and improving verification efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The following will refer to the attached Figures 1 to 3 To describe the features, advantages and technical effects of exemplary embodiments of the present invention.
[0017] Figure 1 A flowchart of an online passport verification method based on secure transmission according to an embodiment of the present invention; Figure 2 It is a structural block diagram of an online passport verification system based on secure transmission according to an embodiment of the present invention; Figure 3 The structure block diagram of an online passport verification terminal based on secure transmission according to an embodiment of the present invention.
[0018] In the figure: 1001 - processor; 1002 - communication bus; 1003 - user interface; 1004 - network interface; 1005 - memory. Detailed implementation manners
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion.
[0020] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order or primary-secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "a plurality" is more than two, unless otherwise specifically defined.
[0021] Referring to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appearing in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0022] In the description of the embodiments of this application, the term "and / or" is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or there are multiple situations where A exists alone. In addition, the character " / " herein generally indicates that the associated objects before and after are in an "or" relationship.
[0023] In the description of the embodiments of this application, unless otherwise clearly specified and limited, technical terms such as "installation", "connection", "connection", "fixation" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can also be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal connection of two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of this application can be understood according to specific situations.
[0024] The present invention provides an online passport verification method, system, terminal and medium based on secure transmission.
[0025] As shown Figure 3 in the figure Figure 3 is a schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present invention.
[0026] The terminal in the embodiment of the present invention may be a PC, or may be a mobile terminal device with a display function such as a smart phone, a tablet computer, an e-book reader, an MP3 (Moving Picture Experts Group Audio Layer III) player, an MP4 (Moving Picture Experts Group Audio Layer IV) player, a portable computer, etc.
[0027] As shown Figure 3 in the figure, the terminal may include: a processor 1001, such as a CPU, a network interface 1004, a user interface 1003, a memory 1005, and a communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0028] Optionally, the terminal may further include a camera, an RF (Radio Frequency) circuit, sensors, an audio circuit, a WiFi module, etc. Among them, the sensors include, for example, a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. Among them, the ambient light sensor can adjust the brightness of the display screen according to the brightness of the ambient light, and the proximity sensor can turn off the display screen and / or the backlight when the mobile terminal moves to the ear. As a kind of motion sensor, the gravity acceleration sensor can monitor the magnitude of the acceleration in each direction (generally three axes), and can monitor the magnitude and direction of gravity when stationary, and can be used for applications that identify the posture of the mobile terminal (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as a pedometer, tapping), etc.; of course, the mobile terminal may also be configured with other sensors such as a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, etc., which will not be elaborated here.
[0029] Those skilled in the art can understand that the terminal structure shown in the figure does not limit the terminal, which may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.
[0030] Referring to Figure 1 , one embodiment of the online passport verification method, system, terminal and medium based on secure transmission of the present invention provides an online passport verification method based on secure transmission, as Figure 1 shown, the online passport verification method based on secure transmission includes: S1. The client performs entity recognition verification on the electronic passport to generate electronic data of the electronic passport; wherein, the client may be a device corresponding to an application, a mobile application, a web page, etc. S2. The client generates a verification request instruction and transmits it to the certificate verification management end. S3. The certificate verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client. S4. The client constructs a key communication channel according to the data transmission instruction; and transmits the electronic data through the key communication channel to the certificate verification management end. S5. The certificate verification management end generates a verification operation instruction; wherein, the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is the auxiliary verification processing of the electronic data by the auxiliary verification tool. S6. Generate a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation.
[0031] In this embodiment, the technical solution first verifies the authenticity of the entity corresponding to the electronic passport through the client to generate the electronic data of the electronic passport, thereby avoiding redundant subsequent operations caused by forged physical passports. Then the client generates a verification request instruction and transmits it to the certificate verification management end to implement the operation of the client actively requesting verification, avoiding the collection of the certificate verification management end from clients that do not need to be verified, thereby reducing the operation burden of the certificate verification management end and reducing data storage. Immediately afterwards, the certificate verification management end generates a data transmission instruction according to the verification request instruction, sends the data transmission instruction to the client, and the client constructs a key communication channel according to the data transmission instruction. And the electronic data is transmitted to the certificate verification management end through the key communication channel. After the client passes the verification, the client itself creates its key communication channel, thereby reducing the number and time of operation of the certificate verification management end, and avoiding the client receiving instructions from a forged certificate verification management end during the transmission process. Then, through the dual verification of the dynamic verification operation and the auxiliary verification tool inspection operation, the data is prevented from being tampered with and affecting its authenticity. Finally, according to the dynamic verification operation and the auxiliary verification tool inspection operation, a verification result is generated. Furthermore, the speed of online verification and the authenticity of data can be ensured, the data is prevented from being tampered with, and the verification efficiency is improved.
[0032] Specifically, in some embodiments, in S1, the step of the client performing entity recognition verification on the entity corresponding to the electronic passport to generate the electronic data of the electronic passport includes: The client triggers the NFC communication function to generate an NFC communication collection operation; Perform entity (chip in it) recognition verification on the entity corresponding to the electronic passport according to the NFC communication collection operation; Use the scanning component of the client to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0033] Among them, NFC communication is a short-range high-frequency wireless communication technology that allows non-contact point-to-point data transmission and data exchange between electronic devices. NFC (Near Field Communication) technology is developed on the basis of the integration of radio frequency identification technology (RFID) and interconnect technology. As long as any two devices are close to each other without the need for cable plugging, communication between them can be achieved.
[0034] That is to say, first, the client supporting NFC communication performs chip authentication (CA) on the physical chip corresponding to the e-passport to ensure that the applicant has the entity corresponding to the e-passport (the original passport). Then, the page information on the entity (the original passport) corresponding to the e-passport is scanned and collected to generate the electronic data of the e-passport, thereby ensuring protection against replay attacks and copy attacks and ensuring the adaptability of the client, and further improving the accuracy, security, and efficiency of verification.
[0035] Specifically, in some embodiments, in S2, the step in which the client generates a verification request instruction and transmits it to the certificate verification management terminal includes: The client generates a verification request instruction and generates an online verification service certificate Covs (the Covs certificate is a specific type of digital certificate used to verify and confirm the identity of an entity such as an individual, company, or server, etc.). The verification request instruction and the online verification service certificate Covs are sent to the passport management terminal; where the passport management terminal includes the management terminal of the passport issuance center or the International Civil Aviation Organization PKD, etc. The passport management terminal generates a CSCA digital certificate based on the online verification service certificate Covs and the verification request instruction, and sends the CSCA digital certificate, the online verification service certificate Covs, and [the relevant content] to the certificate verification management terminal.
[0036] That is to say, by transmitting the verification request instruction and generating the online verification service certificate Covs to the passport management terminal with a transfer function and stub information function to save the traces of its verification operations; then the passport management terminal generates a CSCA digital certificate to form a re-encryption process, thereby ensuring the security of the verification process and ensuring that business data is not eavesdropped or intercepted.
[0037] Specifically, in some embodiments, in S3, the step in which the certificate verification management terminal generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client includes: The certificate verification management terminal verifies the user permissions of the client according to the verification request instruction; where the number of clients (such as three clients, etc.) and types (such as one or all of application programs, mobile applications, web pages, etc.) bound to each e-passport will be entered and bound in the initial stage. When the user permissions are passed, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client. The client generates an authentication operation for the identity of the real-time operator; and only when the authentication operation is passed can the steps of S4 be executed. When the user permission fails, the certificate verification management terminal generates a warning message for unauthorized verification and sends the warning message to the client.
[0038] That is to say, when the certificate verification management terminal receives a verification request instruction, in order to avoid phenomena such as repeated operations, incorrect operations, and unfounded operations, the certificate verification management terminal verifies the user permission of the client according to the information of the client previously entered, so as to avoid operations on the verification request instruction in cases of being held hostage or other inevitable situations. When the user permission passes, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client; at this time, the client also needs to conduct a re-verification of its own identity, that is, to verify the identity of the real-time operator through biometric verification operations such as face recognition or fingerprint recognition; and only when the identity verification operation passes can the steps of S4 be executed. When the user permission fails, the certificate verification management terminal generates a warning message for unauthorized verification and sends the warning message to the client; furthermore, it can prevent replication and replay: ensure that the passport holder holds the original physical electronic passport instead of a copy of the electronic passport.
[0039] Specifically, in some embodiments, in S4, the step of the client constructing a key communication channel according to the data transmission instruction includes: The client constructs a real-time secure channel for data transmission with the certificate verification management terminal and forms a temporary secure channel with the real-time secure channel; The certificate verification management terminal generates a temporary DH key pair according to the temporary secure channel; wherein, the temporary DH key pair includes the temporary DH key of SK DH,Server of, the temporary DH key of PK DH,Server of, the temporary DH key of D Server ; The DH key exchange is also known as the Diffie–Hellman key exchange, Diffie–Hellman key exchange; and through the temporary DH key, both the certificate verification management terminal and the client can create a key under the condition of having no prior information about each other at all. In order for both parties to send data to each other, even if the whole process is spied on by others, the spy cannot know what the key to the encrypted information is; The certificate verification management terminal uses the online verification service private key SK ovs to sign the temporary DH key of the PK DH,Server ; and sends and feedbacks the temporary DH key of the PK DH,Server , the temporary DH key of the domain parameter D Server , and the signed temporary DH key of the PK DH,Server to the client; The client uses Covs to verify PK DH,Server to sign the temporary DH key of DH,IC to generate a real-time DH key pair; where the real-time DH key pair includes the real-time DH key of SK DH,IC , the real-time DH key of PK Server and the real-time DH key of D The client generates an instruction to calculate K1 = KA(SK IC , PK DH,Server , D Server ); and generates the first KS MAC and the security channel session key of the first KS Enc ; The client sends the real-time DH key of PK DH,IC to the certificate verification management end; The certificate verification management end calculates a new instruction of K2 = KA(SK Server ,PK DH,IC , D Server ) and generates the second KS MAC and the security channel session key of the second KS Enc ; According to the security channel session key of the first KS MAC and the first KS Enc , and the security channel session key of the second KS MAC and the second KS Enc , mutual negotiation operation is performed to build a key communication channel.
[0040] That is to say, the process of building a key communication channel is: The client initiates to establish a security channel; The certificate verification management end uses the domain parameter D Server to generate a temporary DH key pair (SK DH,Server ,PK DH,Server ), and uses the private key SK OVS of the online verification service certificate of the certificate verification management end to sign PK DH,Server , and returns PK DH,Server , the domain parameter D Server and the signature of PK DH,Server to the client; After the client uses the public key PK OVS in C OVS to verify the signature of PK DH,Server , it generates a temporary DH key pair (SK DH,IC ,PK DH,IC ,D Server ), and sends PKDH,IC Send to the document verification party. The document holder uses the DH key negotiation algorithm to calculate K, where K = KA(SK IC , PK DH,Server , D Server ), and then generates KS MAC 、KS Enc Secure channel session key; After the document verification management terminal receives PK DH,IC , it calculates the new K = KA(SK IC , PK DH,Server , D Server ), and at the same time generates KS MAC 、KS Enc Secure channel session key; After the process key negotiation is completed, both parties use KS Enc 、KS MAC to encrypt the transmitted data and protect the transmission with MAC. Among them, KA is the name of a function or method used to process parameters such as skic, pkdh, server, and dserver. In programming, the name of a function or method usually indicates its function or purpose. For example, ka is an encryption algorithm, a data processing function, or a network communication function. Further, it can be a symmetric encryption algorithm (for example, the DES algorithm groups the plaintext by 64 bits for encryption, and each group generates a ciphertext of 64 bits), a hash function, etc.
[0041] Furthermore, the online verification service certificate needs to comply with the definition in ICAO 9303-12 and has the following restrictions: 1. The online verification service key must be of the ECC type; 2. Key usage, including digitalSignature, nonRepudiation, keyAgreement; 3. Key extension usage, TE certificates: OID is 2.23.136.1.1.10.xxx.
[0042] Specifically, in some embodiments, in S5, the dynamic verification operation of generating a dynamic verification signal and sending a data retransmission instruction to the client includes: After the document verification management terminal receives the electronic data of the electronic passport, it generates a verification identification page; While the background verification terminal of the document verification management terminal identifies the information data of the verification identification page, it generates a data retransmission instruction at a preset time point and a preset number of times, and transmits it to the client; The client transmits temporary data to the document verification management terminal; Generate a window for the dynamic verification result based on the comparison between the temporary data and the electronic data; The window of the dynamic verification result is hidden at the edge of the verification and identification page.
[0043] That is to say, to implement multiple verification operations and ensure the accuracy of verification, while the verifier and the background data terminal verify the information on the verification and identification page, it is also necessary to send a data retransmission instruction at a certain time point (at the beginning or end or a certain time point in the middle) to avoid phenomena such as tampering during the transmission process; and through hidden verification at irregular times and irregular frequencies, to ensure the neatness of the entire page, avoid an overly messy page from affecting the operation speed and efficiency of the operator, and can also perform a re-verification operation without affecting the main verification path; thereby ensuring the authenticity and accuracy of data verification.
[0044] The operation of the auxiliary verification tool for inspection is the step of the auxiliary verification tool for the auxiliary verification processing of electronic data, including: After the document verification management terminal receives the electronic data of the electronic passport, it generates a verification and identification page; Trigger the operation of the auxiliary verification tool according to the verification and identification page; The auxiliary verification tool obtains the previously stored data in the data cloud platform according to the electronic data; Generate a window for the auxiliary verification result based on the comparison between the electronic data and the previously stored data; The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
[0045] That is to say, through the verification and comparison of the electronic data by the auxiliary verification tool, to obtain a window for the auxiliary verification result, and integrate the window of the auxiliary verification result and the window of the dynamic verification result into one, a summary window is generated; thereby ensuring the neatness of the entire page, avoiding an overly messy page from affecting the operation speed and efficiency of the operator, and can also perform a re-verification operation without affecting the main verification path; thus ensuring the authenticity and accuracy of data verification.
[0046] Specifically, in some embodiments, in step S6, the step of generating an inspection result according to the dynamic verification operation and the operation of the auxiliary verification tool for inspection includes: Compare and verify the auxiliary verification result and the dynamic verification result; When the auxiliary verification result and the dynamic verification result are the same, close the window of the auxiliary verification result and the window of the dynamic verification result at the same time; and generate a confirmation feedback for passing the verification; this method avoids affecting the saving progress and thus affecting the system operation through the auxiliary verification tool at this position; When the auxiliary verification result and the dynamic verification result are different, summarize the window of the auxiliary verification result and the window of the dynamic verification result to form a pop-up window for data anomalies; The pop-up window is fully displayed on the verification recognition page in a flashing form. In this way, when the verification fails, the verification window is displayed, and at the same time, different characters are given a prominent and jumping state to prompt the abnormal warning of inconsistent data content; thereby improving the accuracy and fluency of the operation.
[0047] The present invention also provides an online passport verification system based on secure transmission.
[0048] Specifically, as Figure 2 shown, the online passport verification system based on secure transmission includes: An identification module 630, which is used to perform entity identification verification on the electronic passport to generate electronic data of the electronic passport; A verification management module 620, which is used to generate a verification request instruction and transmit it to the document verification management end, and the document verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client; A verification module 610, which is used for the client to construct a key communication channel according to the data transmission instruction; and transmit the electronic data through the key communication channel to the document verification management end, and generate a verification operation instruction; wherein, the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; An analysis module 640, which is used to generate a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation.
[0049] In addition, an embodiment of the present invention also proposes a computer-readable storage medium, on which an online passport verification program based on secure transmission is stored. When the online passport verification program based on secure transmission is executed by a processor, the following operations are implemented: The client performs entity identification verification on the electronic passport to generate electronic data of the electronic passport; The client generates a verification request instruction and transmits it to the document verification management end; The document verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client; The client constructs a key communication channel according to the data transmission instruction; and transmits the electronic data through the key communication channel to the document verification management end; The certificate verification management terminal generates a verification operation instruction; wherein, the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is the auxiliary verification processing of the electronic data by the auxiliary verification tool; Generate a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation.
[0050] Further, the step of the client performing entity recognition verification on the electronic passport to generate electronic data of the electronic passport includes: The client triggers the NFC communication function to generate an NFC communication collection operation; Perform entity recognition verification on the entity corresponding to the electronic passport according to the NFC communication collection operation; Use the scanning component of the client to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0051] Further, the step of the client generating a verification request instruction and transmitting it to the certificate verification management terminal includes: The client generates a verification request instruction and generates an online verification service certificate Covs; Send the verification request instruction and the online verification service certificate Covs to the passport management terminal; The passport management terminal generates a CSCA digital certificate according to the online verification service certificate Covs and the verification request instruction, and sends the CSCA digital certificate, the online verification service certificate Covs to the certificate verification management terminal.
[0052] Further, the step of the certificate verification management terminal generating a data transmission instruction according to the verification request instruction and sending the data transmission instruction to the client includes: The certificate verification management terminal verifies the user authority of the client according to the verification request instruction; When the user authority passes, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client; The client generates an authentication operation of the real-time operator; and the next step can only be executed when the authentication operation passes.
[0053] Further, the step of the client constructing a key communication channel according to the data transmission instruction includes: The client constructs a real-time secure channel for data transmission with the certificate verification management terminal, and forms a temporary secure channel with the real-time secure channel; The certificate verification management terminal generates a temporary DH key pair according to the temporary security channel; wherein, the temporary DH key pair includes the SK DH,Server temporary DH key of, PK DH,Server temporary DH key of, D Server temporary DH key of; The certificate verification management terminal uses the online verification service private key SK ovs to sign the PK DH,Server temporary DH key of; and sends feedback on the PK DH,Server temporary DH key of, the domain parameter D Server temporary DH key of, and the signed PK DH,Server temporary DH key of to the client; The client uses Covs verification to sign the PK DH,Server temporary DH key of to generate a real-time DH key pair; wherein, the real-time DH key pair includes the SK DH,IC real-time DH key of, PK DH,IC real-time DH key of, and D Server real-time DH key of; The client generates an instruction to calculate K1 = KA(SK IC , PK DH,Server , D Server ); and generates the first KS MAC and the first KS Enc security channel session key of; The client sends the PK DH,IC real-time DH key of to the certificate verification management terminal; The certificate verification management terminal calculates a new instruction of K2 = KA(SK Server ,PK DH,IC , D Server ) and generates the second KS MAC and the second KS Enc security channel session key of; According to the security channel session key of the first KS MAC and the first KS Enc and the security channel session key of the second KS MAC and the second KS Enc a mutual negotiation operation is performed to construct a key communication channel.
[0054] Furthermore, before the step of the certificate verification management terminal generating an inspection operation instruction, it further includes: After receiving the electronic data of the electronic passport, the certificate verification management terminal generates a verification and identification page; Among them, the dynamic verification operation is the step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including: While the background verification end of the document verification management end identifies the information data of the verification and identification page, it generates a data retransmission instruction at a preset time point and within a preset number of times, and transmits it to the client; The client transmits temporary data to the document verification management end; According to the comparison between the temporary data and the electronic data, a window for generating a dynamic verification result is formed; The window of the dynamic verification result is hidden at the edge of the verification and identification page; And / or, according to the verification and identification page, trigger the operation of the auxiliary verification tool; The auxiliary verification tool obtains previously stored data in the data cloud platform according to the electronic data; According to the comparison between the electronic data and the previously stored data, a window for generating an auxiliary verification result is formed; The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
[0055] Furthermore, the step of generating an inspection result according to the dynamic verification operation and the inspection operation of the auxiliary verification tool includes: Compare and verify the auxiliary verification result and the dynamic verification result; When the auxiliary verification result and the dynamic verification result are the same, close the windows of the auxiliary verification result and the dynamic verification result at the same time; and generate a confirmation feedback of verification passed; When the auxiliary verification result and the dynamic verification result are different, summarize the windows of the auxiliary verification result and the dynamic verification result to form a pop-up window for data anomaly; The pop-up window is fully displayed on the verification and identification page in a flashing form.
[0056] In addition, it should be understood that although this specification is described according to embodiments, not each embodiment only contains an independent technical solution. This narrative way of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
[0057] Based on the disclosure and teachings of the above specification, those skilled in the art to which the present invention pertains are also able to make changes and modifications to the above embodiments. Therefore, the present invention is not limited to the above specific embodiments, and any obvious improvements, substitutions, or variations made by those skilled in the art based on the present invention fall within the protection scope of the present invention. In addition, although some specific terms are used in this specification, these terms are only for convenience of description and do not constitute any limitation to the present invention.
Claims
1. An online passport verification method based on secure transmission, characterized in that: Including: S1. The client conducts entity recognition and verification on the electronic passport to generate electronic data of the electronic passport; S2. The client generates a verification request instruction and transmits it to the document verification management end; S3. The document verification management end generates a data transmission instruction according to the verification request instruction and sends the data transmission instruction to the client; S4. The client constructs a key communication channel according to the data transmission instruction; and transmits the electronic data through the key communication channel to the document verification management end; S5. The document verification management end generates a verification operation instruction; wherein, the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data re-transmission instruction to the client; the auxiliary verification tool verification operation is the auxiliary verification processing of the electronic data by the auxiliary verification tool; S6. Generate a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation.
2. The online passport verification method based on secure transmission according to claim 1, wherein: The step of the client conducting entity recognition and verification on the electronic passport to generate electronic data of the electronic passport includes: The client triggers the NFC communication function to generate an NFC communication collection operation; Conduct entity recognition and verification on the entity corresponding to the electronic passport according to the NFC communication collection operation; Use the scanning component of the client to collect the view information of the entity corresponding to the electronic passport to generate electronic data of the electronic passport.
3. The online passport verification method based on secure transmission according to claim 1, wherein: The step of the client generating a verification request instruction and transmitting it to the document verification management end includes: The client generates a verification request instruction and generates an online verification service certificate Covs; Transmit the verification request instruction and the online verification service certificate Covs to the passport management end; The passport management end generates a CSCA digital certificate according to the online verification service certificate Covs and the verification request instruction, and sends the CSCA digital certificate, the online verification service certificate Covs to the document verification management end.
4. The online passport verification method based on secure transmission according to claim 1, characterized in that: The step of the document verification management end generating a data transmission instruction according to the verification request instruction and sending the data transmission instruction to the client includes: The document verification management end verifies the user authority of the client according to the verification request instruction; When the user authority passes, the document verification management end generates a data transmission instruction and sends the data transmission instruction to the client; The client generates an identity verification operation of the real-time operator; and the step of S4 can be executed only when the identity verification operation passes.
5. The online passport verification method based on secure transmission according to claim 1, characterized in that: The step of the client constructing a key communication channel according to the data transmission instruction includes: The client constructs a real-time secure channel for data transmission with the document verification management end, and forms a temporary secure channel with the real-time secure channel; The certificate verification management terminal generates a temporary DH key pair according to the temporary security channel; wherein, the temporary DH key pair includes the temporary DH key of SK DH,Server , the temporary DH key of PK DH,Server , and the temporary DH key of D Server ; The certificate verification management terminal uses the online verification service private key SK ovs to sign the temporary DH key of the PK DH,Server ; and sends feedback on the temporary DH key of the PK DH,Server , the domain parameter D Server , the temporary DH key of the PK DH,Server and the signed temporary DH key of the PK to the client; The client uses Covs authentication to sign the temporary DH key of PK DH,Server to generate a real-time DH key pair; wherein, the real-time DH key pair includes the real-time DH key of SK DH,IC , the real-time DH key of PK DH,IC , and the real-time DH key of D Server ; The client generates an instruction to calculate K1 = KA(SK IC , PK DH,Server , D Server ); and generates the first KS MAC and the first session key of the secure channel for KS Enc ; The client sends the real-time DH key of PK DH,IC to the certificate verification management terminal; The certificate verification management terminal calculates a new K2 = KA(SK Server , PK DH,IC , D Server ) instruction and generates a second KS MAC and a second KS Enc for the secure channel session key; According to the first KS MAC and the first KS Enc for the secure channel session key, and the second KS MAC and the second KS Enc perform mutual negotiation operations on the secure channel session key to build a key communication channel.
6. The online passport verification method based on secure transmission according to claim 1, wherein: Before the step that the document verification management end generates a verification operation instruction, it further includes: After receiving the electronic data of the electronic passport, the document verification management end generates a verification identification page; Among them, the dynamic verification operation is the step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including: While the background verification end of the certificate verification management end identifies the information data of the verification identification page, it generates a data retransmission instruction at a preset time point and a preset number of times, and transmits it to the client; The client transmits temporary data to the certificate verification management end; According to the comparison between the temporary data and the electronic data, a window for generating a dynamic verification result is formed; The window of the dynamic verification result is hidden at the edge of the verification identification page; And / or, according to the verification identification page, trigger the operation of the auxiliary verification tool; The auxiliary verification tool obtains the previously stored data in the data cloud platform according to the electronic data; According to the comparison between the electronic data and the previously stored data, a window for generating an auxiliary verification result is formed; The window of the auxiliary verification result is hidden at the edge of the verification identification page.
7. The online passport verification method based on secure transmission according to claim 6, wherein: The step of generating an inspection result according to the dynamic verification operation and the inspection operation of the auxiliary verification tool includes: Compare and verify the auxiliary verification result and the dynamic verification result; When the auxiliary verification result and the dynamic verification result are the same, close the windows of the auxiliary verification result and the dynamic verification result at the same time; and generate a confirmation feedback of successful verification; When the auxiliary verification result and the dynamic verification result are different, summarize the windows of the auxiliary verification result and the dynamic verification result to form a pop-up window for data anomalies; The pop-up window is fully displayed on the verification identification page in a flashing form.
8. An online passport verification system based on secure transmission, characterized in that: For implementing the online passport verification method based on secure transmission according to any one of claims 1 to 7 above; among them, the online passport verification system based on secure transmission includes: An identification module, which is used to identify and verify the entity corresponding to the electronic passport to generate electronic data of the electronic passport; A verification management module, which is used to generate an inspection request instruction and transmit it to the certificate verification management end, and the certificate verification management end generates a data transmission instruction according to the inspection request instruction and sends the data transmission instruction to the client; A verification module, which is used for the client to construct a key communication channel according to the data transmission instruction; and transmit the electronic data through the key communication channel to the certificate verification management end, and generate an inspection operation instruction; among them, the inspection operation instruction includes a dynamic verification operation and an inspection operation of an auxiliary verification tool; An analysis module, which is used to generate an inspection result according to the dynamic verification operation and the inspection operation of the auxiliary verification tool.
9. An online passport verification terminal based on secure transmission, characterized in that: Including: A memory, a processor, and an online passport verification program based on secure transmission stored on the memory and executable on the processor. When the online passport verification program based on secure transmission is executed by the processor, it implements the steps of the online passport verification method based on secure transmission according to any one of claims 1 to 7.
10. A medium, characterized in that: An online passport verification program based on secure transmission is stored on the medium. When the online passport verification program based on secure transmission is executed by a processor, the steps of the online passport verification method based on secure transmission as described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Method and system for reading resident document card information and device for reading resident document card
CN106372547A
Anti-counterfeit verification system of electronic certificate
CN106709534A
Authentication method and system based on block chain
CN109359691A
Electronic passport authentication method and device and computer readable storage medium
CN112465527A
Identity verification method and device, storage medium and electronic equipment
CN119211938A