Communication terminal and communication terminal marking method
By introducing a receiving unit, a secure carrier, and a container unit into the communication terminal, the risk of telecommunications fraud caused by leakage of user identity information is resolved, the secure storage and isolation of tagged data is achieved, and the security and flexibility of user identity protection are improved.
Patent Information
- Application Number
- CN202510940058.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-10
AI Technical Summary
In the mobile Internet environment, user identity information is severely leaked, resulting in a high risk of telecommunications fraud. Existing technologies are unable to effectively solve identity tagging and data security issues.
A communication terminal is provided, comprising a receiving unit, a secure carrier and a container unit. The terminal receives tag information, verifies it using the secure carrier and generates tag data, which is stored in the container unit to ensure the security and isolation of the tag data. Access control is performed through a trusted execution environment and a secure element.
It achieves secure storage and isolation of tagged data, prevents abuse and theft, ensures the security and flexibility of tagged information, supports switching between different terminals, reduces storage space usage, and improves the protection level of user identity information.
Smart Images

Figure CN120769265A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a communication terminal and a communication terminal marking method. Background Art
[0002] With the rapid development of mobile Internet technology, more and more user groups are participating in mobile Internet services. Mobile Internet products often need to profile customer groups based on their own product evolution, promotion and marketing, user conversion and other purposes, and provide personalized services based on different groups and targeted push services to specific mobile user devices.
[0003] In today's internet environment, the existence of targeted push notification services has exacerbated the problem of identity leakage and increased the risk of users falling victim to telecom fraud. Telecom fraud has gradually become a social problem, causing huge economic losses to users.
[0004] Therefore, it is hoped that there will be a new communication terminal and a communication terminal marking method that can solve the above problems. Summary of the Invention
[0005] In view of the above problems, an object of the present invention is to provide a communication terminal and a communication terminal marking method, in particular, a universal trusted device marking method and system, so as to securely store marking data.
[0006] According to one aspect of the present invention, there is provided a communication terminal, comprising:
[0007] a receiving unit, wherein the receiving unit receives marking information;
[0008] A secure element, connected to the receiving unit to obtain the tag information; the secure element verifies the tag information using preset verification information, and generates tag data based on the tag information after passing the verification;
[0009] a container unit, the container unit receiving and storing the marking data,
[0010] The tag data is used to tag information exchanged with the outside world.
[0011] Optionally, the container unit includes:
[0012] A control information storage module, wherein the control information storage module stores a control file, wherein the control file includes at least one selected from the group consisting of information about a marking data issuing organization and information about access rights to the marking data;
[0013] A tag data storage module is used to store the tag data.
[0014] Optionally, there are multiple tag data and multiple tag data storage modules; different tag data are stored in different tag data storage modules;
[0015] The security carrier is provided with a common service container for storing common marking information, and the common marking information corresponds to a plurality of the marking data.
[0016] Optionally, the tag data is bound to user identity information;
[0017] The communication terminal further includes:
[0018] a sending unit, wherein the sending unit sends a device switching request;
[0019] The receiving unit receives the marking data bound to the user identity information fed back according to the request of the switching device.
[0020] Optionally, a general application and a management application are running on the communication terminal;
[0021] The secure carrier is provided with a trusted execution environment and / or a secure element, and a secure carrier access service program is run in the secure carrier.
[0022] The secure carrier access service program is connected to the common application and to the trusted execution environment and / or the secure element to enable the common application to access the trusted execution environment and / or the secure element;
[0023] The secure element access service program is connected to the management application and the secure element respectively, so as to enable the management application to access the secure element.
[0024] Optionally, the marking service platform generates the marking information and sends the marking information to a remote trusted service platform server;
[0025] The remote trusted service platform server sends the marking information to the receiving unit.
[0026] According to another aspect of the present invention, a communication terminal marking method is provided, comprising:
[0027] receiving marking information;
[0028] Verifying the marking information using verification information;
[0029] After verification, generating marking data according to the marking information;
[0030] storing the tag data,
[0031] The tag data is used to tag information exchanged with the outside world.
[0032] Optionally, the tag data is bound to user identity information;
[0033] The communication terminal marking method further includes:
[0034] Send a device switching request to the remote trusted service platform server;
[0035] Receive tag data bound to user identity information fed back according to the switching device request.
[0036] Optionally, the communication terminal marking method further includes:
[0037] The tagging service platform generates tags;
[0038] generating data to be signed according to the mark and the mark certificate;
[0039] Signing the data to be signed to obtain the marking information;
[0040] The security element verifies the signature of the marking information and the marking certificate using the preset information.
[0041] Optionally, the communication terminal marking method further includes:
[0042] receiving a plurality of tag information;
[0043] generating, based on the plurality of label information, a plurality of label data corresponding one-to-one to the label information and common label information corresponding to the plurality of label information;
[0044] The tag information and the public tag information are stored separately.
[0045] In the communication terminal and the communication terminal marking method provided by the present invention, the container unit specifically stores the marking data obtained after verification, thereby ensuring the security of the marking data.
[0046] Furthermore, the container unit also stores information about the issuing organization of the marking data and information about the access rights of the marking data, which can prevent the abuse and theft of the marking data.
[0047] Furthermore, the tag data released by different institutions are stored in different application containers respectively, ensuring the secure isolation of application data; the shared public tag information is stored in the public service container, avoiding duplicate storage of information and saving storage space.
[0048] Furthermore, the tag can be flexibly switched on different communication terminals and its use is not restricted by the device.
[0049] Furthermore, encryption operations are performed during the generation, push, storage and access of the marking information / marking data, thereby ensuring the security of the marking information / marking data. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] The above and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:
[0051] Figure 1 A schematic structural diagram of a communication terminal according to a first embodiment of the present invention is shown;
[0052] Figure 2 A schematic structural diagram of a container unit according to a second embodiment of the present invention is shown;
[0053] Figure 3 It shows a schematic structural diagram of a security element according to a third embodiment of the present invention;
[0054] Figure 4 A schematic structural diagram of a communication terminal according to a fourth embodiment of the present invention is shown;
[0055] Figure 5 A flowchart of a communication terminal marking method according to a fifth embodiment of the present invention is shown;
[0056] Figure 6 A flowchart of a communication terminal marking method according to a sixth embodiment of the present invention is shown;
[0057] Figure 7 An interaction diagram of a communication terminal marking method according to a seventh embodiment of the present invention is shown;
[0058] Figure 8 An interaction diagram showing a communication terminal marking method according to an eighth embodiment of the present invention is shown;
[0059] Figure 9 An interaction diagram showing a communication terminal marking method according to a ninth embodiment of the present invention is shown;
[0060] Figure 10 A schematic diagram showing the data format of tag information according to an embodiment of the present invention is shown;
[0061] Figure 11 A schematic diagram showing the data format of marking data according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0062] Various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In each of the accompanying drawings, identical elements are represented by identical or similar reference numerals. For clarity, the various parts in the accompanying drawings are not drawn to scale. In addition, certain well-known parts may not be shown in the drawings.
[0063] Specific embodiments of the present invention are described in further detail below with reference to the accompanying drawings and examples. Numerous specific details of the present invention, such as component structures, materials, dimensions, processing techniques, and technologies, are described below to facilitate a clearer understanding of the present invention. However, as those skilled in the art will appreciate, the present invention may be practiced without these specific details.
[0064] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "on" or "over" another layer or region, it may mean that it is directly on the other layer or region, or that other layers or regions are included between it and the other layer or region. Furthermore, if the component is turned over, the layer or region will be "below" or "beneath" the other layer or region.
[0065] Figure 1 FIG. 1 shows a schematic diagram of the structure of a communication terminal according to Embodiment 1 of the present invention. Figure 1 As shown, the communication terminal according to the first embodiment of the present invention includes a receiving unit 140 , a secure element 110 and a container unit 150 .
[0066] Specifically, the receiving unit 140 is configured to receive marking information.
[0067] The secure element 110 is connected to the receiving unit 140 to obtain the tag information. The secure element 110 verifies the tag information using the preset verification information, and generates tag data according to the tag information after the verification is passed.
[0068] The container unit 150 receives and stores the tag data, which is used to tag information exchanged with the outside world.
[0069] In an optional embodiment of the present invention, the container unit 150 includes a control information storage module and a tag data storage module. The control information storage module stores a control file, which includes at least one selected from tag data issuing authority information and tag data access permission information. The tag data storage module is used to store tag data.
[0070] Specifically, combined Figure 2As shown, the application container data format is the data storage format within the application container. The application container (container unit / data container) consists of shared container control information (file) and all tag data T2. The container control file primarily includes the issuing authority number (tag data issuing authority information) and authority control information (tag data access permission information). The authority control information primarily defines the application authorization and verification mechanism for tag access within the container. The application authorization and verification authority determines which applications can access the tag data within the container. Optionally, there may be multiple tag data and multiple tag data storage modules. Different tag data are stored in different tag data storage modules.
[0071] In an optional embodiment of the present invention, a common service container storing common marking information (common service container control file) is provided in the secure carrier 110. The common marking information corresponds to a plurality of marking data.
[0072] Combine Figure 3 As shown in (Overall data structure in security carrier), each security carrier 110 has only one public service container for centrally storing public tag-related content; it also contains many application containers, each corresponding to a tag issuing agency.
[0073] In an optional embodiment of the present invention, the tag data is bound to the user identity information. The communication terminal further includes a sending unit. The sending unit is configured to send a device switching request. The receiving unit receives the tag data bound to the user identity information fed back according to the device switching request.
[0074] In an optional embodiment of the present invention, a normal application and a management application are running on the communication terminal. A trusted execution environment and / or a secure element are provided in the secure carrier, and a secure carrier access service program is running in the secure carrier. The secure carrier access service program is connected to the normal application and to the trusted execution environment and / or the secure element to enable the normal application to access the trusted execution environment and / or the secure element. The secure carrier access service program is connected to the management application and the secure element respectively to enable the management application to access the secure element. Optionally, the tag service platform generates tag information and sends the tag information to the remote trusted service platform server. The remote trusted service platform server sends the tag information to the receiving unit.
[0075] Figure 4 FIG. 4 shows a schematic diagram of the structure of a communication terminal according to a fourth embodiment of the present invention. Figure 4As shown, a secure element 110 is provided on a communication terminal (terminal device) 100. A normal application 120 and a management application 130 are also running on the communication terminal 100. A TEE (trusted execution environment) 112 and a secure element (Secure Element) 113 are provided on the secure element 110. A secure element access service program 111 is also running on the secure element 110. The communication terminal 100 (the normal application 120) is connected to the application server 200 for information exchange. The communication terminal 100 (the management application 130) is connected to the remote trusted service platform server 300 for information exchange. The remote trusted service platform server 300 is also connected to the application server 200 and the tag service platform 500 for information exchange. The tag service platform 500 includes a public service platform server 501 and a tag service platform server 502.
[0076] Specifically, the terminal device 100 is a device used by users to run common applications, interact with users, display and manage application interfaces, etc.
[0077] The secure element access service program 111 acts as an intermediary service between the secure element (TEE or SE) and the application, preventing the TEE / SE interface from being directly exposed to the application. Any application accesses the TEE / SE through it. Unless otherwise specified, access to the secure element 110 is actually achieved by calling it.
[0078] The general application 120 is an application deployed on a terminal device and is used to interact with the user and perform business processing, such as transfer transactions.
[0079] The management application 130 is used to manage identity tokens, interact with security carriers, establish a push channel with RTSP (Remote Trust Service Platform), and receive warning push information.
[0080] The secure element 110 (TEE / SE) is used to securely store early warning information. In the specific application field of anti-fraud, the secure element carries risk markers during financial transactions.
[0081] The remote trusted service platform server 300 (RTSP) provides public key signature services and the issuance of identity token certificates. It should be pointed out that the remote trusted service platform server does not specify a specific server, but is a set of service systems required to complete the required business, such as encryption machines, TSM, and may need to call other authoritative institutions such as real-person verification platforms, CAs, etc.
[0082] The application server 200 interfaces with the common application 120, receives the mark in the transaction signature and performs corresponding business processing.
[0083] The mark service platform 500 is responsible for the generation and pushing of the user equipment mark, and can include a public service platform server and a business mark platform server.
[0084] Figure 5 A method flowchart of a communication terminal marking method according to an embodiment of the present application is shown. As shown, the communication terminal marking method according to the embodiment of the present application includes the following steps: Figure 5
[0085] In step S101, mark information is received.
[0086] The mark information is received by the communication terminal. The mark information is provided by a remote trusted service platform server / mark service platform in the outside world, for example.
[0087] In step S102, the mark information is verified using verification information.
[0088] The mark information is verified by the secure carrier of the communication terminal using verification information. The verification information can be an authentication certificate, a key, etc.
[0089] In step S103, after verification is passed, mark data is generated according to the mark information.
[0090] After verification is passed, the mark data is generated according to the mark information. The amount of information of the mark data is less than the amount of information of the mark information, for example.
[0091] In step S104, the mark data is stored.
[0092] The mark data is stored by the application container of the communication terminal. The mark data is used for marking of information interacting with the outside world.
[0093] In an optional embodiment of the present application, the communication terminal marking method further includes the following steps:
[0094] The mark service platform generates a mark.
[0095] The to-be-signed data is generated according to the mark and the mark certificate.
[0096] The to-be-signed data is signed to obtain mark information.
[0097] The secure carrier verifies the signature of the mark information and the mark certificate using preset information.
[0098] Figure 6 A method flowchart of a communication terminal marking method according to an embodiment of the present application is shown. As shown, the communication terminal marking method according to the embodiment of the present application includes the following steps: Figure 6 As shown, the communication terminal marking method according to an embodiment of the present invention involves a communication terminal (terminal device) 100, a secure element access service program 111, a secure element (TEE / SE) 110, a remote trusted service platform server 300, and a marking service platform 500. Specifically, the communication terminal marking method includes the following steps:
[0099] Step 1: The remote trusted service platform server 300 presets the platform public key certificate to the secure element 110 .
[0100] Step 2: The marking service platform 500 accesses the remote trusted service platform server 300 offline and applies to the remote trusted service platform server 300 for issuing a certificate.
[0101] Step 3: The tag service platform 500 generates a device tag (tag information).
[0102] Step 4: The marking service platform 500 pushes the marking information to the communication terminal 100 based on the secure channel.
[0103] Step 5: The communication terminal 100 calls an interface to the secure element access service program 111 to securely store the identifier (tag information).
[0104] Step 6: The secure element access service program 111 verifies the signature S1 in the tag information and generates tag data according to the tag information.
[0105] Step 7: Store the identification data T2 (marker data) into the secure element (TEE / SE) 110 .
[0106] In an optional embodiment of the present invention, the communication terminal marking method further includes:
[0107] Receive multiple tag information; for example, the multiple tag information is different tag information (function, authority, etc.) provided by an external remote trusted service platform server / tag service platform.
[0108] According to the plurality of label information, a plurality of label data corresponding to each of the label information and common label information corresponding to the plurality of label information are generated;
[0109] Individual tag information and public tag information are stored separately.
[0110] Figure 7 FIG1 shows an interaction diagram of a communication terminal marking method according to Embodiment 7 of the present invention, specifically showing the interaction process of the marking service platform 500 accessing the marking service application and preparation. Figure 7 As shown, service access occurs between the tag service platform 500, the remote trusted service platform server 300 and the secure element 110, and includes the following steps:
[0111] Step 1: The remote trusted service platform server 300 saves its own platform private key and platform certificate, and pre-installs the platform certificate into the secure carrier 110 .
[0112] Step 2: When accessing the service, the tag service platform 500 needs to generate an institutional key pair.
[0113] Step 3: The marking service platform 500 applies for access service offline to the remote trusted service platform server 300.
[0114] Step 3.1: The remote trusted service platform server 300 receives the access application, verifies the applicant, and allocates access parameters if successful.
[0115] Step 3.2: The remote trusted service platform server 300 uses the stored platform private key to issue an organization certificate for the request data containing the organization public key of the marking service platform 500, and provides the access parameters and the organization certificate to the marking service platform 500.
[0116] Step 4: The tagging service platform 500 saves the organization certificate, access parameters and organization private key.
[0117] Figure 8 The figure shows an interaction diagram of the communication terminal marking method according to the eighth embodiment of the present invention, specifically showing the interaction process of the marking service platform publishing or updating the device marking (marking / marking information / marking data). Figure 8 As shown, issuing or updating a device tag occurs between the tag service platform 500, the communication terminal 100, the secure element access program 111, and the secure element 110, and includes the following steps:
[0118] Step 1: The tagging service platform 500 generates tagging data T2 according to business requirements.
[0119] Step 2: The marking service platform 500 assembles the data to be signed = T2 | the institution certificate; and uses the institution private key to sign the data to be signed S1.
[0120] Step 3: The marking service platform 500 constructs marking data T1=T2|organization certificate|signature S1.
[0121] Step 4: The tag service platform 500 pushes the tag data T1 to the device end through a secure push channel.
[0122] Step 4.1: The terminal device 100 calls the secure carrier access program 111 to perform tag storage.
[0123] Step 4.1.1: The secure element access program 111 calls the secure element 110 to perform tag storage.
[0124] Step 4.1.1.1: The secure element 110 first uses the preset platform certificate to verify the organization certificate in the tag data T1.
[0125] Step 4.1.1.2: The signature S1 in the tag data T1 is then verified using the authority certificate.
[0126] Step 4.1.1.3: After the above verification is passed, the tag data T2 is stored or updated in the security element 110.
[0127] In an optional embodiment of the present invention, the marking data is bound to the user identity information. The communication terminal marking method further includes: sending a device switching request to a remote trusted service platform server; and receiving the marking data bound to the user identity information fed back according to the device switching request.
[0128] Figure 9 The figure shows an interaction diagram of the communication terminal marking method according to the ninth embodiment of the present invention, specifically showing the interaction process of marking synchronization (when the user changes to a new device, the original marking can be automatically synchronized in the new device). Figure 9 As shown, tag synchronization occurs between the communication terminal 100, the secure element access program 111, the secure element 110, the remote trusted service platform server 300 and the tag service platform 500, and includes the following steps:
[0129] Step 1: The user replaces the device with a new one;
[0130] Step 1.1: The user activates an identity token on a new device.
[0131] Step 1.2: Then the user needs to switch the device on the new device, that is, set the device as the personal identity device.
[0132] Step 1.2.1: The terminal device 100 sends a device switching request to the remote trusted service platform server 300.
[0133] Step 1.2.2: The remote trusted service platform server 300 sets the new device as the target device.
[0134] Step 2: The remote trusted service platform server 300 synchronously marks the data to the terminal device in an asynchronous manner.
[0135] Step 2.1: First query the valid tag list corresponding to the user identity.
[0136] Step 2.2: Then, according to the corresponding tag issuing agency and tag synchronization service address on the tag list, the tag service platform 500 of the tag issuing agency is cyclically called to synchronize personal tags.
[0137] Step 2.2.1: The tag service platform 500 first searches for valid tags of individuals under the organization;
[0138] Step 2.2.2: Continue Figure 8 The process shown stores the token in the secure carrier 110 of the new device.
[0139] Figure 10 FIG. 1 shows a schematic diagram of the data format of the tag information according to an embodiment of the present invention. Figure 10 As shown, the tag information according to an embodiment of the present invention (tag format T1 in the generated state) includes a tag number, a tag type, a service tag, a tag issuing agency number, a tag content, a validity period, application control information, user control information, a tag issuing agency certificate, and a tag signature S1.
[0140] The tag data T1 is the initial data structure when the tag service platform 500 publishes the tag, and is pushed to the terminal device 100 through a secure push channel; the secure push channel between the tag service platform 500 and the terminal device 100 can be, but is not limited to, the operator's SMS channel, the mobile phone manufacturer's push channel, the push alliance's push channel or other end-to-end information communication channel.
[0141] The tag data T1 includes a digital signature S1, which can be verified by the security element 110 to ensure the integrity and legitimacy of the tag data. The data in the tag data T1 is defined as follows:
[0142] Tag number: a unique identifier of a tag, which must remain unique within the tag service platform 500.
[0143] Mark type: According to the applicability of the mark, it is divided into public marks, commercial marks and self-use marks, etc.
[0144] Public tag type tags are issued by national authoritative agencies and provided to all applications on terminal devices. For example, the anti-fraud center can mark user devices with high fraud risks and provide them to various financial apps for risk identification and risk control. Public tags will be stored in a unified public service container in the security carrier 110 and can be accessed without verification.
[0145] Commercial tag type tags are issued by various commercial organizations and provided to authorized applications for use. For example, an e-commerce alliance defines user portraits based on the industry and provides them to authorized members of the alliance for use in corresponding business development. Commercial tags will be stored in the application container corresponding to the issuing organization in the security carrier 110 and accessed by verifying the authorization credentials. The commercial tag publishing process can support offline authorization methods as well as publishing and subscription methods on the platform.
[0146] Tags of the self-use tag type are published and used by application services and are not developed for use by other applications. Self-use tags are stored in the application container corresponding to the issuing organization, similar to commercial tags.
[0147] Business Tag: The business alias of the tag, used for tag filtering during tag usage.
[0148] Marking agency: The issuing agency of the mark. The mark of each issuing agency will be stored in the application container of the corresponding agency in the secure carrier; the issuing agencies of public service marks share one container.
[0149] Tag content: The tagged content supports text, pictures, videos, binary data blocks, etc. The tagging organization can customize the data structure in the tagged content.
[0150] Validity period: The validity period of the mark. After the validity period, the mark will become invalid and cleared.
[0151] Application control information: used to define whether tag access requires application authorization verification.
[0152] User control information: used to define whether tag access requires user authorization.
[0153] Organization certificate: a digital certificate issued by an issuing organization through the remote trusted service platform server 300.
[0154] Tag signature S1: the signature value of the tag data T1 (excluding tag signature S1); there are two methods, one is the "self-signed method", the trusted service platform server 300 issues a certificate to the tag issuing agency, and the tag issuing agency uses its own private key to complete the signature of the tag data. In this method, the tag issuing agency sets the tag issuing agency number and the tag issuing agency certificate, and uses its own private key to complete the signature of the tag data. When sending the tag data, the trusted service platform server 300 needs to verify the tag issuing agency number and the certificate. The second is the "platform signature method", the tag issuing agency does not sign, and sends the tag number, tag type, business tag, and tag content in the tag data to the trusted service platform server 300, and the trusted service platform server 300 sets the tag issuing agency number, assembles the identification data, and signs the identification data.
[0155] Figure 11 FIG. 1 shows a schematic diagram of the data format of the marking data according to an embodiment of the present invention. Figure 11 As shown, the tag data (tag format T2 in storage state) according to an embodiment of the present invention includes a tag number, a tag type, a service tag, a tag issuing agency number, a tag content, a validity period, application control information, and user control information.
[0156] The format of the tag data T1 when it is stored in the secure element 110 after being delivered to the communication terminal 100 via the secure push channel.
[0157] The security carrier 110 verifies the institutional certificate in the tag data T1 through the platform certificate of the preset remote trusted service platform server, and then verifies the integrity and legitimacy of the tag data T1 by verifying the tag signature S1 through the institutional certificate; then the tag data T1 is stripped of the authentication-related institutional certificate and tag signature S1 to form tag data T2 which is stored in the application container.
[0158] According to the communication terminal and communication terminal tagging method of the embodiments of the present invention, digital certificate signature algorithms can be used during the generation, push, storage, and access of tag information / tag data, ensuring the trustworthiness of the information source and information. User identity information and tag data can be stored in a secure hardware environment, and transaction signature verification and confirmation reminders are performed in a secure environment, making them tamper-proof and attack-proof. If attempts are made to use other devices for multiple logins to bypass the depositor and steal assets, these devices cannot authenticate the signature and conduct transfers because they lack the chip-level identity token digital certificate (user identity information) that has undergone real-name verification (requiring direct NFC reading of a physical ID card via a mobile phone). If attempts are made to remotely control a user's mobile phone and steal assets without the depositor's knowledge, the chip-level identity token digital certificate requires the depositor to verify the signature using a fingerprint or PIN code stored in the secure environment of the mobile phone chip (which cannot be stolen). This prevents circumvention and enables secure chip-level storage and computation. Tags are bound to user identity information. Once issued, they can be provided to different applications based on the tag's definition. Both tag data and control information are stored on the device side (communication terminal), providing support for expanding offline service scenarios and end-to-end business expansion through near-field communication.
[0159] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0160] While embodiments of the present invention have been described above, these embodiments do not exhaustively describe all details and do not limit the invention to the specific embodiments described. Obviously, many modifications and variations are possible based on the above description. These embodiments are selected and described in detail in this specification in order to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better utilize the present invention and its modifications. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A communication terminal, comprising: a receiving unit, wherein the receiving unit receives marking information; a secure element connected to the receiving unit to obtain the marking information; The security element verifies the marking information using preset verification information, and generates marking data based on the marking information after the verification is passed; a container unit, the container unit receiving and storing the marking data, The tag data is used to tag information exchanged with the outside world.
2. The communication terminal according to claim 1, wherein The container unit comprises: A control information storage module, wherein the control information storage module stores a control file, wherein the control file includes at least one selected from the group consisting of information about a marking data issuing organization and information about access rights to the marking data; A tag data storage module is used to store the tag data.
3. The communication terminal according to claim 2, wherein: There are multiple tag data and multiple tag data storage modules; different tag data are stored in different tag data storage modules; The security carrier is provided with a common service container for storing common marking information, and the common marking information corresponds to a plurality of the marking data. The communication terminal according to claim 1 , wherein: The tag data is bound to the user identity information; The communication terminal further includes: a sending unit, wherein the sending unit sends a device switching request; The receiving unit receives the marking data bound to the user identity information fed back according to the request of the switching device. The communication terminal according to claim 1 , wherein: The communication terminal runs a common application and a management application; The secure carrier is provided with a trusted execution environment and / or a secure element, and a secure carrier access service program is run in the secure carrier. The secure element access service program is connected to the common application and to the trusted execution environment and / or the secure element, so as to enable the common application to access the trusted execution environment and / or the secure element; The secure element access service program is connected to the management application and the secure element respectively, so as to enable the management application to access the secure element. The communication terminal according to claim 5 , wherein: The marking service platform generates the marking information and sends the marking information to the remote trusted service platform server; The remote trusted service platform server sends the marking information to the receiving unit.
7. A communication terminal marking method, comprising: receiving marking information; Verifying the marking information using verification information; After verification, generating marking data according to the marking information; storing the tag data, The tag data is used to tag information exchanged with the outside world.
8. The communication terminal marking method according to claim 7, wherein: The tag data is bound to the user identity information; The communication terminal marking method further includes: Send a device switching request to the remote trusted service platform server; Receive tag data bound to user identity information fed back according to the switching device request.
9. The communication terminal marking method according to claim 7, wherein: The communication terminal marking method further includes: The tagging service platform generates tags; generating data to be signed according to the mark and the mark certificate; Signing the data to be signed to obtain the marking information; The security element verifies the signature of the marking information and the marking certificate using the preset information.
10. The communication terminal marking method according to claim 7, wherein: The communication terminal marking method further includes: receiving a plurality of tag information; generating, based on the plurality of label information, a plurality of label data corresponding one-to-one to the label information and common label information corresponding to the plurality of label information; The tag information and the public tag information are stored separately.
Citation Information
Patent Citations
Method for managing application based on cloud server and terminal
CN106209998A
Method and terminal for verifying authenticity of communication information source
CN106888098A
Server, blockchain-based defrauding client information sharing method and medium
CN109347789A
Encryption method of call handling strategy
CN110830999A
Financial anti-fraud service database construction method and financial anti-fraud service system
CN113837885A
Cited By
Marking application method and communication terminal
CN120768602A
Passenger information autonomous closed-loop method and system based on cryptographic marking, medium and hardware
CN121167789A
Zero terminal and TEE combined data labeling method and system, storage medium and product
CN121547288A
Data labeling method and system combined with zero terminal and TEE, storage medium and product
CN121547288B