Online passport verification method, system, terminal and medium based on secure transmission
Through the client's identification and verification of the electronic passport entity and the double verification mechanism, the problem of poor security performance of electronic passport verification is solved, and fast and authentic online passport verification is achieved.
Patent Information
- Application Number
- CN202510850691.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-06-24
AI Technical Summary
Existing electronic passport verification methods have poor security performance and are prone to data tampering, resulting in low verification efficiency.
An online passport verification method based on secure transmission is adopted to identify and verify the electronic passport entity through the client, generate electronic data, and transmit it to the document verification management end through the key communication channel. Double verification is performed in combination with dynamic verification and auxiliary verification tools to generate inspection results.
It improves the speed of verification and the authenticity of data, avoids data tampering, and enhances verification efficiency.
Smart Images

Figure CN120358102B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electronic passport verification, and in particular relates to an online passport verification method, system, terminal and medium based on secure transmission. Background Art
[0002] IDs serve as proof of identity for individuals or organizations and are fundamental to the normal operation of various social and economic activities. The current prevalence of counterfeit IDs has seriously disrupted social order, with some causing adverse social impacts and even significant economic losses. Therefore, ID authentication is essential for the normal operation of social activities and is fundamental to ensuring the validity of IDs.
[0003] However, some existing methods for verifying electronic passports have poor security performance and are prone to data tampering, resulting in low verification efficiency. Summary of the Invention
[0004] The purpose of the present invention is to provide an online passport verification method based on secure transmission to address the shortcomings of the existing technology, which can solve the technical problem of low verification efficiency in the existing technology.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] Online passport verification method based on secure transmission, including:
[0007] S1. The client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport;
[0008] S2. The client generates a verification request instruction and transmits it to the document verification management terminal;
[0009] S3. The certificate verification management terminal generates a data transmission instruction according to the inspection request instruction, and sends the data transmission instruction to the client;
[0010] S4. The client establishes a key communication channel according to the data transmission instruction; and transmits the electronic data to the certificate verification management terminal through the key communication channel;
[0011] S5. The document verification management terminal generates a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is to perform auxiliary verification processing on the electronic data by the auxiliary verification tool;
[0012] S6. Generate a verification result based on the dynamic verification operation and the verification operation of the auxiliary verification tool.
[0013] Preferably, the step of the client identifying and verifying the entity corresponding to the electronic passport to generate electronic data of the electronic passport includes:
[0014] The client triggers the NFC communication function to generate an NFC communication acquisition operation;
[0015] Identify and verify the entity corresponding to the electronic passport according to the NFC communication collection operation;
[0016] The scanning component of the client is used to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0017] Preferably, the step of the client generating a verification request instruction and transmitting it to the certificate verification management terminal includes:
[0018] The client generates a verification request instruction and generates an online verification service certificate Covs;
[0019] Send the inspection request instruction and the online verification service certificate Covs to the passport management terminal;
[0020] The passport management terminal generates a CSCA digital certificate based on the online verification service certificate Covs and the inspection request instruction, and sends the CSCA digital certificate and the online verification service certificate Covs to the document verification management terminal.
[0021] Preferably, the step of the document verification management terminal generating a data transmission instruction according to the inspection request instruction and sending the data transmission instruction to the client includes:
[0022] The certificate verification management terminal verifies the user authority of the client according to the verification request instruction;
[0023] When the user's permission is granted, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client;
[0024] The client generates an identity authentication operation for the real-time operator; and only when the identity authentication operation is passed can step S4 be executed.
[0025] Preferably, the step of the client establishing a key communication channel according to the data transmission instruction includes:
[0026] The client establishes a real-time secure channel for data transmission with the certificate verification management terminal, and converts the real-time secure channel into a temporary secure channel;
[0027] The certificate verification management terminal generates a temporary DH key pair based on the temporary secure channel; wherein the temporary DH key pair includes SKDH,Server Temporary DH key, PK DH,Server Temporary DH key, D Server Temporary DH key;
[0028] The certificate verification management terminal uses the online verification service private key SK ovs For the PK DH,Server Sign the temporary DH key; and send feedback to the PK DH,Server Temporary DH key, domain parameter D Server The temporary DH key and the signature of the completed PK DH,Server The temporary DH key is sent to the client;
[0029] The client uses Covs to verify the PK DH,Server The temporary DH key is used to sign the real-time DH key pair; wherein the real-time DH key pair includes SK DH,IC Real-time DH key, PK DH,IC The real-time DH key and D Server Real-time DH key;
[0030] The client generates and calculates K1 = KA(SK IC , PK DH,Server , D Server ) instruction; and generate the first KS based on the K1 MAC and the first KS Enc The secure channel session key;
[0031] The client sends PK DH,IC The real-time DH key is sent to the certificate verification management terminal;
[0032] The certificate verification management terminal calculates the new K2 = KA(SK Server ,PK DH,IC , D Server ) and generate a second KS MAC and the second KS Enc The secure channel session key;
[0033] According to the first KS MAC and the first KS Enc The secure channel session key and the second KS MAC and the second KS Enc The two parties negotiate the secure channel session key to build a key communication channel.
[0034] Preferably, before the step of generating the verification operation instruction, the document verification management terminal further includes:
[0035] After receiving the electronic data of the electronic passport, the document verification management terminal generates a verification and identification page;
[0036] The dynamic verification operation is a step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including:
[0037] The background verification end of the certificate verification management end identifies the information data on the verification identification page, generates a data retransmission instruction at a preset time point and within a preset number of times, and transmits it to the client;
[0038] The client transmits temporary data to the certificate verification management terminal;
[0039] Generating a window of dynamic verification results based on the comparison of the temporary data with the electronic data;
[0040] The window of the dynamic verification result is hidden to the edge of the verification and identification page;
[0041] and / or, triggering the operation of the auxiliary verification tool according to the verification identification page;
[0042] The auxiliary verification tool obtains previously stored data in the data cloud platform based on the electronic data;
[0043] Comparing the electronic data with the previously stored data to generate a window of auxiliary verification results;
[0044] The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
[0045] Preferably, the step of generating a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation includes:
[0046] Compare and verify the auxiliary verification results and dynamic verification results;
[0047] When the auxiliary verification result and the dynamic verification result are the same, the auxiliary verification result window and the dynamic verification result window are closed at the same time; and a confirmation feedback of verification passing is generated;
[0048] When the auxiliary verification result and the dynamic verification result are different, the auxiliary verification result window and the dynamic verification result window are aggregated to form a data anomaly pop-up window;
[0049] The pop-up window is fully displayed on the verification and identification page in a flashing form.
[0050] The present invention also discloses an online passport verification system based on secure transmission, which is used to execute the above-mentioned online passport verification method based on secure transmission; wherein the online passport verification system based on secure transmission includes:
[0051] an identification module, the identification module being used to identify and verify the entity corresponding to the electronic passport to generate electronic data of the electronic passport;
[0052] a verification management module, the verification management module being configured to generate a verification request instruction and transmit the instruction to the document verification management terminal, and the document verification management terminal generating a data transmission instruction based on the verification request instruction and transmitting the data transmission instruction to the client;
[0053] A verification module, configured to cause the client to establish a key communication channel according to the data transmission instruction, transmit the electronic data to the document verification management terminal via the key communication channel, and generate a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation;
[0054] An analysis module is used to generate a verification result based on the dynamic verification operation and the verification operation of the auxiliary verification tool.
[0055] The present invention also discloses an online passport verification terminal based on secure transmission, comprising: a memory, a processor, and an online passport verification program based on secure transmission stored in the memory and executable on the processor. When the online passport verification program based on secure transmission is executed by the processor, the steps of the online passport verification method based on secure transmission are implemented.
[0056] The present invention also discloses a medium on which an online passport verification program based on secure transmission is stored. When the online passport verification program based on secure transmission is executed by a processor, the steps of the online passport verification method based on secure transmission are implemented.
[0057] The beneficial effect of the present invention is that the technical solution first verifies the authenticity of the entity corresponding to the electronic passport through the client to generate electronic data of the electronic passport, thereby avoiding the counterfeiting of the physical passport and causing redundant subsequent operations; then the client generates an inspection request instruction and transmits it to the document verification management end to implement the operation of the client actively requesting verification, avoiding the document verification management end collecting data from clients that do not need verification, thereby reducing the operating burden of the document verification management end and reducing data storage; then the document verification management end generates a data transmission instruction according to the inspection request instruction, and sends the data transmission instruction to the client, and the client constructs a key according to the data transmission instruction communication channel; and transmitting the electronic data to the certificate verification management end through the key communication channel, so that after the client passes the verification, the client itself creates its key communication channel, thereby reducing the number and time of running operations of the certificate verification management end, and avoiding the client from receiving forged instructions from the certificate verification management end during the transmission process; then through double verification of dynamic verification operation and auxiliary verification tool inspection operation, to avoid data tampering and affecting its authenticity; finally, based on the dynamic verification operation and auxiliary verification tool inspection operation, generate inspection results; thereby ensuring the speed of online verification and the authenticity of data, avoiding data tampering; and improving verification efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The following will refer to the attached Figures 1 to 3 To describe the features, advantages and technical effects of exemplary embodiments of the present invention.
[0059] Figure 1 Flowchart of an online passport verification method based on secure transmission according to an embodiment of the present invention;
[0060] Figure 2 This is a structural block diagram of an online passport verification system based on secure transmission according to an embodiment of the present invention;
[0061] Figure 3 This is a structural block diagram of an online passport verification terminal based on secure transmission according to an embodiment of the present invention.
[0062] In the figure: 1001 - processor; 1002 - communication bus; 1003 - user interface; 1004 - network interface; 1005 - memory. DETAILED DESCRIPTION
[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned figure descriptions are intended to cover non-exclusive inclusions.
[0064] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.
[0065] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0066] In the description of the embodiments of this application, the term "and / or" is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or multiple situations exist. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0067] In the description of the embodiments of the present application, unless otherwise clearly specified or limited, technical terms such as "installed," "connected," "connect," and "fixed" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be internal communication between two elements or an interaction relationship between two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to the specific circumstances.
[0068] The present invention provides an online passport verification method, system, terminal and medium based on secure transmission.
[0069] like Figure 3 As shown, Figure 3 It is a schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present invention.
[0070] The terminal of the embodiment of the present invention can be a PC, or it can be a mobile terminal device with display function such as a smart phone, a tablet computer, an e-book reader, an MP3 (Moving Picture Experts Group Audio Layer III) player, an MP4 (Moving Picture Experts Group Audio Layer IV) player, or a portable computer.
[0071] like Figure 3 As shown, the terminal may include: a processor 1001, such as a CPU, a network interface 1004, a user interface 1003, a memory 1005, and a communication bus 1002. The communication bus 1002 is used to implement communication between these components. The user interface 1003 may include a display and an input unit such as a keyboard. Optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed RAM memory or a non-volatile memory, such as a disk storage device. The memory 1005 may also be a storage device independent of the processor 1001.
[0072] Optionally, the terminal may also include a camera, RF (Radio Frequency) circuits, sensors, audio circuits, a WiFi module, and so on. These sensors include light sensors, motion sensors, and other sensors. Specifically, light sensors may include ambient light sensors and proximity sensors. The ambient light sensor can adjust the brightness of the display based on the brightness of the ambient light, and the proximity sensor can turn off the display and / or backlight when the mobile terminal is brought to the ear. A gravity accelerometer, a type of motion sensor, can monitor the magnitude of acceleration in all directions (generally three axes) and, when stationary, the magnitude and direction of gravity. This can be used for applications that recognize the mobile terminal's posture (such as switching between landscape and portrait modes, related games, and magnetometer posture calibration), vibration recognition-related functions (such as pedometers and tapping), and more. Mobile terminals may also be equipped with other sensors such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, which are not detailed here.
[0073] Those skilled in the art will understand that the terminal structure shown in the figure does not constitute a limitation to the terminal, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0074] Reference Figure 1 One embodiment of the present invention provides an online passport verification method based on secure transmission, a system, a terminal and a medium, such as Figure 1 As shown, the online passport verification method based on secure transmission includes:
[0075] S1. The client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport; the client can be a device corresponding to an application, mobile application, web page, etc.
[0076] S2. The client generates a verification request instruction and transmits it to the document verification management terminal;
[0077] S3. The certificate verification management terminal generates a data transmission instruction according to the inspection request instruction, and sends the data transmission instruction to the client;
[0078] S4. The client establishes a key communication channel according to the data transmission instruction; and transmits the electronic data to the certificate verification management terminal through the key communication channel;
[0079] S5. The document verification management terminal generates a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is to perform auxiliary verification processing on the electronic data by the auxiliary verification tool;
[0080] S6. Generate a verification result based on the dynamic verification operation and the verification operation of the auxiliary verification tool.
[0081] In this embodiment, the technical solution first verifies the authenticity of the entity corresponding to the electronic passport through the client to generate electronic data of the electronic passport, thereby avoiding the counterfeiting of the physical passport and causing redundant subsequent operations; then the client generates a verification request instruction and transmits it to the document verification management end to implement the operation of the client actively requesting verification, avoiding the document verification management end collecting data from clients that do not need verification, thereby reducing the operating burden of the document verification management end and reducing data storage; then the document verification management end generates a data transmission instruction according to the verification request instruction, and sends the data transmission instruction to the client, and the client builds a key communication according to the data transmission instruction. channel; and transmit the electronic data to the certificate verification management end through the key communication channel, so that after the client passes the verification, the client itself creates its key communication channel, thereby reducing the number and time of running operations of the certificate verification management end, and avoiding the client from receiving forged instructions from the certificate verification management end during the transmission process; then double verification is carried out through dynamic verification operation and auxiliary verification tool inspection operation to avoid data tampering and affecting its authenticity; finally, according to the dynamic verification operation and auxiliary verification tool inspection operation, a verification result is generated; thereby, the speed of online verification and the authenticity of the data can be ensured, data tampering can be avoided, and verification efficiency can be improved.
[0082] Specifically, in some embodiments, in S1, the step of the client identifying and verifying the entity corresponding to the electronic passport to generate electronic data of the electronic passport includes:
[0083] The client triggers the NFC communication function to generate an NFC communication acquisition operation;
[0084] Identify and verify the entity (chip) corresponding to the electronic passport according to the NFC communication acquisition operation;
[0085] The scanning component of the client is used to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0086] NFC is a short-range, high-frequency wireless communication technology that allows contactless, point-to-point data transmission and exchange between electronic devices. NFC (Near Field Communication) technology is a combination of radio frequency identification (RFID) and interconnect technologies. It enables communication between any two devices as long as they are in close proximity, without the need for cables.
[0087] That is to say, first, the client that supports NFC communication performs chip authentication (CA) on the chip inside the entity corresponding to the electronic passport; to ensure that the applicant owns the entity corresponding to the electronic passport (the original passport); then the page information on the entity corresponding to the electronic passport (the original passport) is scanned and collected to generate the electronic data of the electronic passport; thereby ensuring that it is not attacked by replay and copying, and ensuring the adaptability of the client, thereby improving the accuracy, security and efficiency of verification.
[0088] Specifically, in some embodiments, in S2, the step of the client generating a verification request instruction and transmitting it to the document verification management terminal includes:
[0089] The client generates a verification request instruction and generates an online verification service certificate Covs (a Covs certificate is a specific type of digital certificate used to verify and confirm the identity of an entity, such as an individual, company, or server);
[0090] Send the inspection request instruction and the online verification service certificate Covs to the passport management end; wherein the passport management end includes the management end of the passport issuing center or the International Civil Aviation Organization PKD, etc.;
[0091] The passport management terminal generates a CSCA digital certificate based on the online verification service certificate Covs and the inspection request instruction, and sends the CSCA digital certificate and the online verification service certificate Covs to the document verification management terminal.
[0092] That is to say, by transmitting the inspection request instruction and the generated online verification service certificate Covs to the passport management end with transit function and stub information function, the traces of its verification operation are preserved; then the passport management end generates a CSCA digital certificate to form a re-encryption process, thereby ensuring the security of the verification process; and ensuring that business data is not eavesdropped or intercepted.
[0093] Specifically, in some embodiments, in S3, the step of the document verification management terminal generating a data transmission instruction according to the inspection request instruction and sending the data transmission instruction to the client includes:
[0094] The document verification management terminal verifies the user rights of the client according to the verification request instruction; wherein, the number of clients bound to each electronic passport (for example, three clients) and types (for example, one or all applications, mobile applications, web pages, etc.) will be entered and bound in the initial stage;
[0095] When the user's permission is granted, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client;
[0096] The client generates a real-time operator identity verification operation; and only when the identity verification operation is passed can step S4 be executed;
[0097] When the user authority is not passed, the certificate verification management terminal generates a warning message of no authority verification and sends the warning message to the client.
[0098] That is to say, when the certificate verification management terminal receives a verification request instruction, in order to avoid repeated operations, erroneous operations, and unnecessary operations, the certificate verification management terminal verifies the user authority of the client based on the information of the client previously entered, so as to avoid being held hostage or having to perform the verification request instruction operation under other unavoidable circumstances. When the user authority is passed, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client; at this time, the client also needs to verify its own identity again, that is, perform a real-time operator identity verification operation through a verification operation of biometric features such as face recognition or fingerprint recognition; and only when the identity verification operation is passed can step S4 be executed. When the user authority is not passed, the certificate verification management terminal generates a warning message of no authority verification and sends the warning message to the client; thereby preventing copying and replay: ensuring that the passport holder holds the physical original of the electronic passport, not a copy of the electronic passport.
[0099] Specifically, in some embodiments, in S4, the step of the client establishing a key communication channel according to the data transmission instruction includes:
[0100] The client establishes a real-time secure channel for data transmission with the certificate verification management terminal, and converts the real-time secure channel into a temporary secure channel;
[0101] The certificate verification management terminal generates a temporary DH key pair based on the temporary secure channel; wherein the temporary DH key pair includes SK DH,Server Temporary DH key, PK DH,Server Temporary DH key, D Server A temporary DH key is used. DH key exchange is also known as Diffie–Hellman key exchange. The temporary DH key allows the certificate verification manager and client to create a key without any prior knowledge of the other party. This ensures that even if data is being transmitted between the two parties and is being eavesdropped on, the eavesdropper cannot determine the encryption key.
[0102] The certificate verification management terminal uses the online verification service private key SK ovs For the PK DH,ServerSign the temporary DH key; and send feedback to the PK DH,Server Temporary DH key, domain parameter D Server The temporary DH key and the signature of the completed PK DH,Server The temporary DH key is sent to the client;
[0103] The client uses Covs to verify the PK DH,Server The temporary DH key is used to sign the real-time DH key pair; wherein the real-time DH key pair includes SK DH,IC Real-time DH key, PK DH,IC The real-time DH key and D Server Real-time DH key;
[0104] The client generates and calculates K1 = KA(SK IC , PK DH,Server , D Server ) instruction; and generate the first KS based on the K1 MAC and the first KS Enc The secure channel session key;
[0105] The client sends PK DH,IC The real-time DH key is sent to the certificate verification management terminal;
[0106] The certificate verification management terminal calculates the new K2 = KA(SK Server ,PK DH,IC , D Server ) and generate a second KS MAC and the second KS Enc The secure channel session key;
[0107] According to the first KS MAC and the first KS Enc The secure channel session key and the second KS MAC and the second KS Enc The two parties negotiate the secure channel session key to build a key communication channel.
[0108] In other words, the process of building a key communication channel is:
[0109] The client initiates the establishment of a secure channel;
[0110] The document verification management terminal uses the domain parameter D Server Generate a temporary DH key pair (SK DH,Server ,PK DH,Server ), and use the online verification service certificate private key SK of the certificate verification management terminal OVS PK DH,ServerSignature, PK DH,Server , domain parameter D Server and PK DH,Server The signature is returned to the client;
[0111] Client uses C OVS Public Key PK OVS Verify PK DH,Server After signing, a temporary DH key pair (SK DH,IC ,PK DH,IC ,D Server ), PK DH,IC Sent to the certificate verifier. The certificate holder uses the DH key negotiation algorithm to calculate K, K = KA (SK IC , PK DH,Server , D Server ), and then generate KS based on K MAC , KS Enc Secure channel session key;
[0112] The certificate verification management terminal receives the PK DH,IC Then calculate the new K = KA(SK IC , PK DH,Server , D Server ), and generate KS MAC , KS Enc Secure channel session key;
[0113] After the key negotiation is completed, both parties use KS Enc , KS MAC Encrypt transmitted data and use a MAC to protect transmission. KA is the name of a function or method that processes the parameters skic, pkdh, server, and dserver. In programming, the name of a function or method often indicates its function or purpose. For example, ka is an encryption algorithm, a data processing function, or a network communication function. Furthermore, it can be a symmetric encryption algorithm (for example, the DES algorithm encrypts plaintext in 64-bit blocks, generating 64-bit ciphertext for each block) or a hash function.
[0114] Furthermore, the online verification service certificate must comply with the definition in ICAO 9303-12 and have the following restrictions: 1. The online verification service key must be of ECC type; 2. Key usage, including digitalSignature, nonRepudiation, keyAgreement; 3. Key extension usage, TE certificates: OID is 2.23.136.1.1.10.xxx.
[0115] Specifically, in some embodiments, in S5, the dynamic verification operation is a step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including:
[0116] After receiving the electronic data of the electronic passport, the document verification management terminal generates a verification and identification page;
[0117] The background verification end of the certificate verification management end identifies the information data on the verification identification page, generates a data retransmission instruction at a preset time point and within a preset number of times, and transmits it to the client;
[0118] The client transmits temporary data to the certificate verification management terminal;
[0119] Generating a window of dynamic verification results based on the comparison of the temporary data with the electronic data;
[0120] The window of the dynamic verification result is hidden at the edge of the verification and identification page.
[0121] That is to say, in order to realize multiple verification operations and ensure the accuracy of verification, while the verification personnel and the background data terminal verify the information of the identification page, they also need to send a data re-transmission instruction at a certain point in time (early or late or a certain point in the middle) to avoid tampering during the transmission process; and through irregular and indefinite hidden verification, the neatness of the entire page can be ensured to avoid overly messy pages that affect the operator's operating speed and efficiency. It can also be achieved without affecting the main verification path. The re-verification operation is carried out, thereby ensuring the authenticity and accuracy of the data verification.
[0122] The auxiliary verification tool checking operation is a step of the auxiliary verification tool performing auxiliary verification processing on the electronic data, including:
[0123] After receiving the electronic data of the electronic passport, the document verification management terminal generates a verification and identification page;
[0124] triggering the operation of the auxiliary verification tool according to the verification identification page;
[0125] The auxiliary verification tool obtains previously stored data in the data cloud platform based on the electronic data;
[0126] Comparing the electronic data with the previously stored data to generate a window of auxiliary verification results;
[0127] The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
[0128] That is to say, by verifying and comparing the electronic data through the auxiliary verification tool, a window of auxiliary verification results is used, and the window of auxiliary verification results and the window of dynamic verification results are summarized and integrated into one to generate a summary window; thereby ensuring the neatness of the entire page, avoiding overly messy pages that affect the operator's operating speed and efficiency, and also achieving re-verification operations without affecting the main verification path; thus ensuring the authenticity and accuracy of data verification.
[0129] Specifically, in some embodiments, the step of generating a verification result in S6 according to the dynamic verification operation and the verification operation of the auxiliary verification tool includes:
[0130] Compare and verify the auxiliary verification results and dynamic verification results;
[0131] When the auxiliary verification result and the dynamic verification result are the same, the auxiliary verification result window and the dynamic verification result window are closed at the same time; and a confirmation feedback of verification passing is generated; this method uses the auxiliary verification tool at this location to avoid affecting the saving progress and affecting the system operation;
[0132] When the auxiliary verification result and the dynamic verification result are different, the auxiliary verification result window and the dynamic verification result window are aggregated to form a data anomaly pop-up window;
[0133] The pop-up window is fully displayed on the verification page in a flashing manner. This method displays the verification window when the verification fails, and gives different characters a prominent and jumping state to prompt an abnormal warning of inconsistent data content, thereby improving the accuracy and smoothness of operation.
[0134] The present invention also provides an online passport verification system based on secure transmission.
[0135] Specifically, if Figure 2 As shown, the online passport verification system based on secure transmission includes:
[0136] an identification module 630 for identifying and verifying the entity corresponding to the electronic passport to generate electronic data of the electronic passport;
[0137] A verification management module 620 is configured to generate a verification request instruction and transmit it to the document verification management terminal, and the document verification management terminal generates a data transmission instruction based on the verification request instruction and transmits the data transmission instruction to the client;
[0138] Verification module 610, configured to cause the client to establish a key communication channel according to the data transmission instruction, transmit the electronic data to the document verification management terminal via the key communication channel, and generate a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation;
[0139] The analysis module 640 is used to generate a verification result based on the dynamic verification operation and the auxiliary verification tool verification operation.
[0140] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a secure transmission-based online passport verification program is stored. When the secure transmission-based online passport verification program is executed by a processor, the following operations are implemented:
[0141] The client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport;
[0142] The client generates a verification request instruction and transmits it to the certificate verification management terminal;
[0143] The certificate verification management terminal generates a data transmission instruction according to the inspection request instruction, and sends the data transmission instruction to the client;
[0144] The client establishes a key communication channel according to the data transmission instruction; and transmits the electronic data to the certificate verification management terminal through the key communication channel;
[0145] The document verification management terminal generates a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is to perform auxiliary verification processing on the electronic data by the auxiliary verification tool;
[0146] Generate a verification result based on the dynamic verification operation and the auxiliary verification tool verification operation.
[0147] Furthermore, the client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport, including:
[0148] The client triggers the NFC communication function to generate an NFC communication acquisition operation;
[0149] Identify and verify the entity corresponding to the electronic passport according to the NFC communication collection operation;
[0150] The scanning component of the client is used to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
[0151] Furthermore, the step of the client generating a verification request instruction and transmitting it to the document verification management terminal includes:
[0152] The client generates a verification request instruction and generates an online verification service certificate Covs;
[0153] Send the inspection request instruction and the online verification service certificate Covs to the passport management terminal;
[0154] The passport management terminal generates a CSCA digital certificate based on the online verification service certificate Covs and the inspection request instruction, and sends the CSCA digital certificate and the online verification service certificate Covs to the document verification management terminal.
[0155] Furthermore, the step of the document verification management terminal generating a data transmission instruction according to the inspection request instruction and sending the data transmission instruction to the client includes:
[0156] The certificate verification management terminal verifies the user authority of the client according to the verification request instruction;
[0157] When the user's permission is granted, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client;
[0158] The client generates an identity verification operation for the real-time operator; and only when the identity verification operation is passed can the next step be executed.
[0159] Furthermore, the step of the client establishing a key communication channel according to the data transmission instruction includes:
[0160] The client establishes a real-time secure channel for data transmission with the certificate verification management terminal, and converts the real-time secure channel into a temporary secure channel;
[0161] The certificate verification management terminal generates a temporary DH key pair based on the temporary secure channel; wherein the temporary DH key pair includes SK DH,Server Temporary DH key, PK DH,Server Temporary DH key, D Server Temporary DH key;
[0162] The certificate verification management terminal uses the online verification service private key SK ovs For the PK DH,Server Sign the temporary DH key; and send feedback to the PK DH,ServerTemporary DH key, domain parameter D Server The temporary DH key and the signature of the completed PK DH,Server The temporary DH key is sent to the client;
[0163] The client uses Covs to verify the PK DH,Server The temporary DH key is used to sign the real-time DH key pair; wherein the real-time DH key pair includes SK DH,IC Real-time DH key, PK DH,IC The real-time DH key and D Server Real-time DH key;
[0164] The client generates and calculates K1 = KA(SK IC , PK DH,Server , D Server ) instruction; and generate the first KS based on the K1 MAC and the first KS Enc The secure channel session key;
[0165] The client sends PK DH,IC The real-time DH key is sent to the certificate verification management terminal;
[0166] The certificate verification management terminal calculates the new K2 = KA(SK Server ,PK DH,IC , D Server ) and generate a second KS MAC and the second KS Enc The secure channel session key;
[0167] According to the first KS MAC and the first KS Enc The secure channel session key and the second KS MAC and the second KS Enc The two parties negotiate the secure channel session key to build a key communication channel.
[0168] Furthermore, before the step of generating the verification operation instruction, the document verification management terminal further includes:
[0169] After receiving the electronic data of the electronic passport, the document verification management terminal generates a verification and identification page;
[0170] The dynamic verification operation is a step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including:
[0171] The background verification end of the certificate verification management end identifies the information data on the verification identification page, generates a data retransmission instruction at a preset time point and within a preset number of times, and transmits it to the client;
[0172] The client transmits temporary data to the certificate verification management terminal;
[0173] Generating a window of dynamic verification results based on the comparison of the temporary data with the electronic data;
[0174] The window of the dynamic verification result is hidden to the edge of the verification and identification page;
[0175] and / or, triggering the operation of the auxiliary verification tool according to the verification identification page;
[0176] The auxiliary verification tool obtains previously stored data in the data cloud platform based on the electronic data;
[0177] Comparing the electronic data with the previously stored data to generate a window of auxiliary verification results;
[0178] The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
[0179] Furthermore, the step of generating a verification result according to the dynamic verification operation and the verification operation of the auxiliary verification tool includes:
[0180] Compare and verify the auxiliary verification results and dynamic verification results;
[0181] When the auxiliary verification result and the dynamic verification result are the same, the auxiliary verification result window and the dynamic verification result window are closed at the same time; and a confirmation feedback of verification passing is generated;
[0182] When the auxiliary verification result and the dynamic verification result are different, the auxiliary verification result window and the dynamic verification result window are aggregated to form a data anomaly pop-up window;
[0183] The pop-up window is fully displayed on the verification and identification page in a flashing form.
[0184] In addition, it should be understood that although this specification is described in terms of implementation methods, not every implementation method contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.
[0185] Based on the disclosure and teachings of the above description, those skilled in the art will be able to make changes and modifications to the above embodiments. Therefore, the present invention is not limited to the above specific embodiments. Any obvious improvements, substitutions, or modifications made by those skilled in the art based on the present invention fall within the scope of protection of the present invention. In addition, although certain specific terms are used in this description, these terms are only for convenience of description and do not constitute any limitation to the present invention.
Claims
1. An online passport verification method based on secure transmission, characterized by: include: S1. The client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport; S2. The client generates a verification request instruction and transmits it to the document verification management terminal; S3. The certificate verification management terminal generates a data transmission instruction according to the inspection request instruction, and sends the data transmission instruction to the client; S4. The client establishes a key communication channel according to the data transmission instruction; and transmits the electronic data to the certificate verification management terminal through the key communication channel; S5. The document verification management terminal generates a verification operation instruction; wherein the verification operation instruction includes a dynamic verification operation and an auxiliary verification tool verification operation; the dynamic verification operation is to generate a dynamic verification signal and send a data retransmission instruction to the client; the auxiliary verification tool verification operation is to perform auxiliary verification processing on the electronic data by the auxiliary verification tool; S6. Generate a verification result based on the dynamic verification operation and the verification operation of the auxiliary verification tool; The step of the client establishing a key communication channel according to the data transmission instruction includes: The client establishes a real-time secure channel for data transmission with the certificate verification management terminal, and converts the real-time secure channel into a temporary secure channel; The certificate verification management terminal generates a temporary DH key pair based on the temporary secure channel; wherein the temporary DH key pair includes SK DH,Server Temporary DH key, PK DH,Server Temporary DH key, D Server Temporary DH key; The certificate verification management terminal uses the online verification service private key SK ovs For the PK DH,Server Sign the temporary DH key; and send feedback to the PK DH,Server Temporary DH key, domain parameter D Server The temporary DH key and the signature of the completed PK DH,Server The temporary DH key is sent to the client; The client uses Covs to verify the PK DH,Server The temporary DH key is used to sign the real-time DH key pair; wherein the real-time DH key pair includes SK DH,IC Real-time DH key, PK DH,IC The real-time DH key and D Server Real-time DH key; The client generates and calculates K1 = KA(SK IC , PK DH,Server , D Server ) instruction; and generate the first KS based on the K1 MAC and the first KS Enc The secure channel session key; The client sends PK DH,IC The real-time DH key is sent to the certificate verification management terminal; The certificate verification management terminal calculates the new K2 = KA(SK Server ,PK DH,IC , D Server ) and generate a second KS MAC and the second KS Enc The secure channel session key; According to the first KS MAC and the first KS Enc The secure channel session key and the second KS MAC and the second KS Enc The secure channel session key is negotiated with each other to build a key communication channel.
2. The online passport verification method based on secure transmission according to claim 1, characterized in that: The client verifies the entity corresponding to the electronic passport to generate electronic data of the electronic passport, including: The client triggers the NFC communication function to generate an NFC communication acquisition operation; Identify and verify the entity corresponding to the electronic passport according to the NFC communication collection operation; The scanning component of the client is used to collect the view information of the entity corresponding to the electronic passport to generate the electronic data of the electronic passport.
3. The online passport verification method based on secure transmission according to claim 1, characterized in that: The step of the client generating a verification request instruction and transmitting it to the certificate verification management terminal includes: The client generates a verification request instruction and generates an online verification service certificate Covs; Send the inspection request instruction and the online verification service certificate Covs to the passport management terminal; The passport management terminal generates a CSCA digital certificate based on the online verification service certificate Covs and the inspection request instruction, and sends the CSCA digital certificate and the online verification service certificate Covs to the document verification management terminal.
4. The online passport verification method based on secure transmission according to claim 1, characterized in that: The step of the document verification management terminal generating a data transmission instruction according to the inspection request instruction and sending the data transmission instruction to the client includes: The certificate verification management terminal verifies the user authority of the client according to the verification request instruction; When the user's permission is granted, the certificate verification management terminal generates a data transmission instruction and sends the data transmission instruction to the client; The client generates an identity authentication operation for the real-time operator; and only when the identity authentication operation is passed can step S4 be executed.
5. The online passport verification method based on secure transmission according to claim 1, characterized in that: Before the step of generating the verification operation instruction by the certificate verification management terminal, the method further includes: After receiving the electronic data of the electronic passport, the document verification management terminal generates a verification and identification page; The dynamic verification operation is a step of generating a dynamic verification signal and sending a data retransmission instruction to the client, including: The background verification end of the certificate verification management end identifies the information data on the verification identification page, generates a data retransmission instruction at a preset time point and within a preset number of times, and transmits it to the client; The client transmits temporary data to the certificate verification management terminal; Generating a window of dynamic verification results based on the comparison of the temporary data with the electronic data; The window of the dynamic verification result is hidden to the edge of the verification and identification page; and / or, triggering the operation of the auxiliary verification tool according to the verification identification page; The auxiliary verification tool obtains previously stored data in the data cloud platform based on the electronic data; Comparing the electronic data with the previously stored data to generate a window of auxiliary verification results; The window of the auxiliary verification result is hidden at the edge of the verification and identification page.
6. The online passport verification method based on secure transmission according to claim 5, characterized in that: The step of generating a verification result according to the dynamic verification operation and the auxiliary verification tool verification operation includes: Compare and verify the auxiliary verification results and dynamic verification results; When the auxiliary verification result and the dynamic verification result are the same, the auxiliary verification result window and the dynamic verification result window are closed at the same time; and a confirmation feedback of verification passing is generated; When the auxiliary verification result and the dynamic verification result are different, the auxiliary verification result window and the dynamic verification result window are aggregated to form a data anomaly pop-up window; The pop-up window is fully displayed on the verification and identification page in a flashing form.
7. An online passport verification system based on secure transmission, characterized by: Used to perform the online passport verification method based on secure transmission according to any one of claims 1 to 6 above; wherein the online passport verification system based on secure transmission comprises: an identification module, the identification module being used to identify and verify the entity corresponding to the electronic passport to generate electronic data of the electronic passport; a verification management module, the verification management module being configured to generate a verification request instruction and transmit the instruction to the document verification management terminal, and the document verification management terminal generating a data transmission instruction based on the verification request instruction and transmitting the data transmission instruction to the client; The verification module is used for the client to build a key communication channel according to the data transmission instruction; and transmit the electronic data to the certificate verification management end through the key communication channel, and generate an inspection operation instruction; wherein the inspection operation instruction includes a dynamic verification operation and an auxiliary verification tool inspection operation; and the step of the client building a key communication channel according to the data transmission instruction includes: the client building a real-time secure channel for data transmission between the client and the certificate verification management end, and using the real-time secure channel to form a temporary secure channel; the certificate verification management end generates a temporary DH key pair according to the temporary secure channel; wherein the temporary DH key pair includes SK DH,Server Temporary DH key, PK DH,Server Temporary DH key, D Server The certificate verification management terminal uses the online verification service private key SK ovs For the PK DH,Server Sign the temporary DH key; and send feedback to the PK DH,Server Temporary DH key, domain parameter D Server The temporary DH key and the signature of the completed PK DH,Server The client uses Covs to verify the temporary DH key of PK DH,Server The temporary DH key is used to sign the real-time DH key pair; wherein the real-time DH key pair includes SK DH,IC Real-time DH key, PK DH,IC The real-time DH key and D Server The client generates and calculates K1=KA(SK IC , PK DH,Server , D Server ) instruction; and generate the first KS based on the K1 MAC and the first KS Enc The client sends the secure channel session key PK DH,IC The real-time DH key is sent to the certificate verification management terminal; the certificate verification management terminal calculates a new K2 = KA (SK Server ,PK DH,IC , D Server ) and generate a second KS MAC and the second KS Enc The secure channel session key; according to the first KS MAC and the first KS Enc The secure channel session key and the second KS MAC and the second KS Enc The secure channel session key is negotiated with each other to build a key communication channel; An analysis module is used to generate a verification result based on the dynamic verification operation and the verification operation of the auxiliary verification tool.
8. An online passport verification terminal based on secure transmission, characterized by: include: A memory, a processor, and an online passport verification program based on secure transmission stored in the memory and executable on the processor, wherein the online passport verification program based on secure transmission, when executed by the processor, implements the steps of the online passport verification method based on secure transmission according to any one of claims 1 to 6.
9. A medium, characterized in that: The medium stores an online passport verification program based on secure transmission, which, when executed by a processor, implements the steps of the online passport verification method based on secure transmission according to any one of claims 1 to 6.
Citation Information
Patent Citations
Anti-counterfeit verification system of electronic certificate
CN106709534A