Multi-level cross-domain security communication system and method based on bank administration business

The multi-level cross-domain secure communication system using dynamic SSID and national cryptographic algorithms solves the problems of fragmented identity authentication and data security in government-bank business, achieving efficient cross-system authentication and encrypted transmission, and improving the efficiency and security of government affairs processing.

CN121098565APending Publication Date: 2025-12-09AGRI BANK OF CHINA CO LTD SICHUAN BRANCH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511227518.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Traditional banking and government services suffer from fragmented identity authentication, slow offline processing, inefficient manual review, and the traditional cookie mechanism is vulnerable to XSS attacks, failing to meet high security requirements.

Method used

A multi-level cross-domain secure communication system based on dynamic SSID and national cryptographic algorithms is adopted, including a trusted identity layer, an intelligent control layer, and a data security layer. Through dynamic SSID verification, national cryptographic algorithm encryption, and intelligent regional control, secure authentication and data transmission between banking and government systems are achieved.

Benefits of technology

It achieves secure inheritance of bank authentication results, prevents the risk of tampering during cross-system transmission, automatically implements regional service restrictions, enhances data security protection, reduces the number of offline processing, and meets the requirements of Level 4 Information Security Protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098565A_ABST
    Figure CN121098565A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-level cross-domain security communication system and method based on bank administration business. The system comprises an access layer, an access layer, and a credible identity layer configured with a joint authentication mechanism based on dynamic SSID and enhanced JWT and used for acquiring identity information and performing identity verification. The intelligent control layer is used for configuring multiple engines and carrying out attribute control, interaction control and regional compliance verification; and the data security layer is used for carrying out signature and encryption dual protection on service data by configuring SM3 and SM4 national cryptographic algorithms, and carrying out format verification and security filtering on the data. According to the scheme, the problems of identity authentication splitting, slow offline handling, low efficiency of manual auditing and the like in a traditional scheme are solved through three technical means of dynamic SSID visitor identity verification, national cryptographic algorithm enhanced encryption and intelligent regional control.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of government and bank communication, and in particular to a multi-level cross-domain secure communication system and method based on government and bank business. BACKGROUND

[0002] At present, through government-bank cooperation, public services are extended from government service halls to bank outlets, and high-frequency government service items such as market access are settled in bank outlet service areas, which is the improvement needed by banks and government systems. However, the traditional scheme needs to fill in and submit information repeatedly in banks and government systems, or even go to offline business handling points, resulting in cumbersome business handling and poor experience for users; in traditional business handling, banks and government systems, or even internal systems of banks, customers need to log in to different systems according to different businesses, and the systems are not associated, resulting in repeated identity authentication of customers in different systems, and customers such as public accumulation fund opening customers based on bank systems are not realized, and offline system is used to log in customer data, and bank existing customer data is not used, and the traditional Cookie mechanism is vulnerable to XSS attacks, and cannot meet the high security requirements of government and bank systems.

[0003] Therefore, how to realize the safe inheritance of bank authentication results to government systems, how to prevent tampering risks of encrypted data in the cross-system transmission process, and how to automatically implement regional service restrictions based on enterprise characteristics, are still technical problems to be solved. SUMMARY

[0004] In view of the above technical problems, the present application provides a multi-level cross-domain secure communication system and method based on government and bank business, which is suitable for the opening business scene of enterprise identity security authentication, sensitive data encrypted transmission and compliance automatic verification between bank systems and public accumulation fund centers through national secret algorithm.

[0005] The present application is realized by adopting the following technical scheme: In a first aspect, a multi-level cross-domain secure communication system based on government and bank business includes an access layer, an access layer and a three-level protection system, and the three-level protection system includes: A trusted identity layer: a joint authentication mechanism based on dynamic SSID and enhanced JWT is configured to obtain identity information and perform identity verification; An intelligent control layer: multiple engines are configured to perform attribute control, interaction control and regional compliance verification; A data security layer: SM3 and SM4 national secret algorithms are configured to perform double protection of signature and encryption on business data, and format verification and security filtering are performed on the data.

[0006] Specifically, the access layer is configured to interact with the Internet and software APP, and the access layer is connected to the gateway and load.

[0007] Specifically, the identity information and identity authentication obtained by the trusted identity layer specifically include: A dynamic SSID is obtained, and the identity is verified through the SSID when the visitor requests for the first time, and the dynamic SSID includes a hash combination of a bank code, a timestamp accurate to milliseconds, an enterprise code and a random salt value; A visitor token is obtained, and the visitor identity is verified using a national secret enhanced JWT for a non-first-time request.

[0008] Specifically, the multi-engine of the intelligent control layer includes an intelligent encryption and decryption engine, an intelligent data verification engine and an intelligent regional permission control engine.

[0009] On the other hand, a multi-level cross-domain secure communication method based on bank-government business is realized based on the multi-level cross-domain secure communication system based on bank-government business, and includes the following steps: Step S1: The client initiates a request on the client side, and the request is accessed to the system intelligent control layer through the system access layer gateway; Step S2: The intelligent control layer performs visitor token authentication and dynamic SSID authentication by calling a bank SSID authentication system interface according to whether the client is a first-time request; Step S3: The intelligent control layer calls a multi-engine, and according to the visitor's regional control permission function, verifies whether the client data conforms to the corresponding rules and other business logic; Step S4: The client data is encrypted, and the client side receives the returned request; Step S5: The client browser carries the encrypted client data to jump to the government affairs center system page, the government affairs center system analyzes the encrypted client data and is directed to the corresponding government affairs page according to the analyzed client data, and the page is returned to the client side for display.

[0010] Specifically, the encryption of the client data calls the intelligent encryption and decryption engine of the intelligent control layer, and is encrypted by combining the SM3, SM4 national secret algorithm and the national secret enhanced JWT, and specifically includes: After the dynamic SSID authentication, the SM3 algorithm is used to encrypt the client device fingerprint hash, and the encrypted data and the client ID are put into the token load of the national secret enhanced JWT, the national secret enhanced JWT generates a request token, the request token is packed into the head for encryption, and the client data is put into the body for returning the request.

[0011] Specifically, the regional control permission function according to the visitor specifically includes: The intelligent regional permission control engine is called, the request token is parsed using the national secret enhanced JWT, and the client code in the head is taken out; The client code is used to query the region and authority to which the client belongs in the local library, and whether the current operation is unauthorized is checked according to the queried user region and authority; After the checking is completed, subsequent business logic is executed according to the current operation.

[0012] Specifically, the identity authentication step further comprises: The visitor token and dynamic SSID are obtained, the visitor identity is authenticated, and the client id is obtained after the authentication is passed; The visitor authority is controlled according to the region to which the visitor belongs, the function authority and data level are controlled according to the client role and level, the client data is encrypted, and the SM4 national encryption algorithm is used for client information encryption; The system client is returned, and the government affairs center page is jumped to; the government affairs system decrypts the client data using the SM4 national encryption algorithm; If the decryption is successful, the process is ended, and it is fed back that the client identity authentication is successful; if the decryption fails, the process is ended, and it is fed back that the client identity information authentication is not passed.

[0013] Specifically, the dynamic SSID is generated by accessing the bank SSID authentication system, then the system requests the bank SSID authentication system to verify the visitor identity requesting the current page through the dynamic SSID, returns the client information and marks the client state; the dynamic SSID has a preset validity period, and can only be verified successfully once.

[0014] The application has the advantages that: the application verifies the visitor identity through the dynamic SSID, enhances encryption through the national encryption algorithm, and uses the three technical means of intelligent regional control, thereby solving the problems of identity authentication fragmentation, slow offline handling, inefficient manual review and the like in the traditional scheme. The scheme reduces the number of clients who register for public accumulation fund opening through offline channels by 80%, and the data security protection strength meets the requirement of the fourth level of the network security protection, and can be extended and applied to government affairs scenes such as social security and tax. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only show some embodiments of the application, and for those skilled in the art, other drawings can also be obtained from the structures shown in the drawings without creative labor.

[0016] Fig. 1 The figure is a multi-level cross-domain secure communication system architecture based on bank-government business in the embodiment of the application; Fig. 2 The figure is a multi-level cross-domain secure communication method based on bank-government business in the embodiment of the application; Fig. 3 Figure 1 is a schematic diagram of identity authentication of a multi-level cross-domain secure communication system based on a bank-government business according to an embodiment of the present application. DETAILED DESCRIPTION

[0017] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. The components of the embodiments of the present application described and shown in the drawings can be arranged and designed in various different configurations.

[0018] It should be noted that similar reference numerals and letters represent similar items in the following drawings, and therefore, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.

[0019] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings. Figs. 1-3 Some embodiments of the present application will be described in detail. The following embodiments and features in the embodiments can be combined with each other without conflict.

[0020] The present application provides a multi-level cross-domain secure communication system and method based on a bank-government business. First, the system architecture is shown in Figure 1, which includes an access layer, an access layer and a three-level protection system. The three-level protection system includes: Fig. 1 A trusted identity layer: configure a joint authentication mechanism based on dynamic SSID and enhanced JWT, obtain identity information and perform identity verification; the identity information obtained by the trusted identity layer and the identity verification specifically include: Obtain a dynamic SSID, verify the identity through the SSID when the visitor requests for the first time, and the dynamic SSID includes a combination of bank institution code, time stamp accurate to milliseconds, enterprise code and random salt value hash; Obtain a visitor token, and use a national secret enhanced JWT to verify the visitor identity for non-first-time requests.

[0021] An intelligent control layer: configure multiple engines for attribute control, interaction control and regional compliance verification; the multiple engines include an intelligent encryption and decryption engine, an intelligent data verification engine and an intelligent regional permission control engine.

[0022] A data security layer: configure SM3 and SM4 national secret algorithms for double protection of business data signing and encryption, and perform format verification and security filtering on the data.

[0023] The access layer configures the Internet and software APP for interaction, and the access layer accesses the gateway and load.

[0024] ​The application also corresponds to propose a communication method of a multi-level cross-domain secure communication system based on bank-government business, as shown in Fig. 2 The method comprises the following steps: The client initiates a request at the client end, and accesses the system intelligent control layer through the system access layer gateway; The intelligent control layer performs visitor token authentication and dynamic SSID authentication by calling the bank SSID authentication system interface according to whether the client is a first-time request; The intelligent control layer calls a multi-engine, and according to the regional control authority function of the visitor, checks whether the client data meets the corresponding rules and other business logic; The client data is encrypted, and the client end receives the returned request; The client end browser carries the encrypted client data to jump to the government affair center system page, the government affair center system analyzes the encrypted client data and is directed to the corresponding government affair page according to the analyzed client data, and returns the page to the client end for display.

[0025] In this embodiment, the encryption of the client data calls the intelligent encryption and decryption engine of the intelligent control layer, and combines the SM3, SM4 national secret algorithm and the national secret enhanced JWT for encryption, which specifically includes: After the dynamic SSID authentication, the SM3 algorithm is used to encrypt the client device fingerprint hash, and the encrypted data and the client ID are put into the token load of the national secret enhanced JWT, the national secret enhanced JWT generates a request token, the request token is packed into the head for encryption, and the client data is put into the body for returning the request.

[0026] In this embodiment, the regional control authority function according to the visitor specifically includes: The intelligent regional authority control engine is called, the request token is parsed using the national secret enhanced JWT, and the client code in the head is taken out; The client code is used to query the client's jurisdiction and authority in the local library, and whether the current operation is unauthorized is checked according to the queried user jurisdiction and authority; After the verification is completed, the subsequent business logic is executed according to the current operation.

[0027] In one embodiment, the multi-level cross-domain secure communication system based on bank-government business further includes an identity authentication step, as shown in Fig. 3 The method specifically includes: The visitor token and dynamic SSID are obtained, the visitor identity is authenticated, and the client ID is obtained after the authentication is passed; According to the visitor's region, the visitor's authority is controlled; according to the client's role and level, the function authority and data level are controlled; the client data is encrypted, and the SM4 national secret algorithm is used for client information encryption; Returning to the system client, jumping to the government center page, the government system uses SM4 national encryption algorithm to decrypt the client data; If the decryption is successful, it is ended, and the client identity verification is fed back; if the decryption fails, it is ended, and the client identity information verification is fed back.

[0028] In this embodiment, the dynamic SSID is generated by accessing the bank SSID authentication system, and then the system requests the bank SSID authentication system to verify the identity of the visitor requesting the current page through the dynamic SSID, returns the client information and marks the client state; the dynamic SSID has a preset valid period, and can only be verified successfully once.

[0029] In one embodiment, the scheme verifies the dynamic SSID containing a timestamp and a hash check value; implements a double-layer identity authentication mechanism based on a national encryption algorithm; realizes automatic regional compliance control by analyzing enterprise identification codes; adopts SM4-CBC and SM3 joint encryption for client identity authentication management; the generation of the dynamic SSID includes a bank code, a timestamp accurate to milliseconds, an enterprise code and a random salt value hash combination. The regional compliance control includes establishing a geographic coding-government service center mapping relationship database and real-time checking the service area qualification of the requesting enterprise.

[0030] In this embodiment, the detailed principles of each part of the technology are as follows: (1) Dynamic SSID verification method: when the visitor accesses the system, an SSID generated by the bank SSID verification platform will be brought, and then the system requests the bank SSID verification platform interface to verify the identity of the visitor requesting the current page, and the verification is passed. The SSID is valid for 5 minutes, and can only be verified successfully once.

[0031] Verification process: a) get the jump SSID→b) request the bank SSID verification system interface to verify the SSID→c) return the client information→d) mark the client state of the system.

[0032] (2) National encryption algorithm enhanced JWT: on the basis of the traditional JWT, the national encryption SM3 algorithm is used to encrypt the identity information, and the national encryption SM4-CBC algorithm is used to encrypt the client data.

[0033] The implementation steps are as follows: a) Client first request for SSID verification → b) After verification, use SM3 algorithm to encrypt client device fingerprint hash → c) Put encrypted data and client ID, etc. into JWT payload → d) JWT generates token → e) Use SM4 algorithm to encrypt client data → f) Put token into head and encrypt client data into body and return request.

[0034] The JWT token payload structure is shown in Table 1: Table 1 JWT token payload structure (3) Intelligent regional control engine: Implementation steps: a) Use JWT to parse client request token → b) Take out the userId in the request head → c) Use the userId to query the client's zone and permissions in the local library → d) Check if the current operation is unauthorized according to the queried user zone and permissions → e) If the check is passed, execute the subsequent business logic according to the current operation.

[0035] In one embodiment, the silver-government business-based multi-level cross-domain secure communication system and method proposed by the present application is used for silver-government interaction. Taking the example of an enterprise user logging in to the Agricultural Bank enterprise online banking with client information to jump to the Chengdu public accumulation fund center to open a public accumulation fund account, the specific steps are as follows: Step 1: Identity verification: The client logs in to the enterprise online banking of the bank → jumps to the system page through the enterprise online banking → the system obtains the SSID carried by the client → the system calls the enterprise online banking SSID authentication interface to authenticate the identity → the enterprise online banking system authenticates successfully and feeds back the client information such as client id → generates a token based on the client information using the national secret enhanced JWT and returns it to the client → each subsequent request is based on the token for session management.

[0036] Step 2: Data encryption transmission: The user inputs information on the front end and initiates a public accumulation fund center page jump application → parses the userid through JWT → checks the user's permissions → checks the client data format → encrypts the client data using SM4-CBC → returns to the client → the client carries the encrypted client data to jump to the public accumulation fund center page.

[0037] Step 3: Public accumulation fund center verifies client data: The public accumulation fund center system decrypts the client data → displays the client data on the page → the client completes the opening registration on the public accumulation fund center page.

[0038] Step 4: Exception handling: The hierarchical policy table is shown in Table 2.

[0039] Table 2 Classification strategy table The application can be applied to the security interaction between government systems, solves the problems of identity authentication fragmentation, slow offline handling and inefficient manual review of traditional solutions through three technical means of dynamic SSID verification of visitor identity, national secret algorithm enhanced encryption and intelligent regional control. The actual measurement shows that the scheme reduces the number of customers opening and registering for provident fund through offline channels by 80%, and the data security protection strength reaches the requirement of the fourth level of network security protection, and can be extended and applied to social security, tax and other government scenarios.

[0040] For the foregoing embodiments, in order to simply describe, they are all expressed as a series of action combinations, but those skilled in the art should know that the application is not limited by the action sequence described, because according to the application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily necessary for the application.

[0041] In the above embodiments, the basic principles and main features of the application and the advantages of the application are described. Those skilled in the art should understand that the application is not limited by the above embodiments, and the above embodiments and the description in the specification are only to illustrate the principles of the application. Any modification and change made by those skilled in the art without departing from the spirit and scope of the application should be within the protection scope of the claims of the application.

Claims

1. A multi-level cross-domain secure communication system based on bank-government business, characterized in that, It includes an access layer, a connection layer, and a three-tier protection system, wherein the three-tier protection system comprises, in order: Trusted Identity Layer: Configure a joint authentication mechanism based on dynamic SSID and enhanced JWT to obtain identity information and perform identity verification; Intelligent control layer: Configured with multiple engines to perform attribute control, interaction control, and regional compliance verification; Data security layer: Configure SM3 and SM4 national cryptographic algorithms to provide dual protection for business data through signing and encryption, and perform data format verification and security filtering.

2. The multi-level cross-domain secure communication system based on bank-government business as described in claim 1, characterized in that, The access layer is configured to interact with the Internet and software APP, and the access layer connects to the gateway and load balancer.

3. The multi-level cross-domain secure communication system based on bank-government business as described in claim 1, characterized in that, The identity information and authentication obtained by the trusted identity layer specifically include: Obtain a dynamic SSID. When a visitor makes their first request, they verify their identity using the SSID. The dynamic SSID includes the bank institution code, a timestamp accurate to milliseconds, a hash combination of the enterprise code and a random salt value. Obtain the visitor token and use the national cryptographic enhanced JWT to verify the visitor's identity for requests other than the first one.

4. A multi-level cross-domain secure communication system based on bank-government business as described in claim 1, characterized in that, The intelligent control layer comprises multiple engines, including an intelligent encryption / decryption engine, an intelligent data verification engine, and an intelligent regional access control engine.

5. A multi-level cross-domain secure communication method based on banking and government business, implemented based on the multi-level cross-domain secure communication system based on banking and government business as described in any one of claims 1 to 4, characterized in that, Includes the following steps: Step S1: The client initiates a request on the client side, and the request is connected to the system intelligent control layer through the system access layer gateway; Step S2: The intelligent control layer performs visitor token authentication and dynamic SSID authentication by calling the bank's SSID authentication system interface, depending on whether the customer is making their first request. Step S3: The intelligent control layer calls multiple engines to control access permissions based on the visitor's region, and verifies whether the customer data complies with the corresponding rules and other business logic; Step S4: Encrypt customer data and return it to the client; the client receives the return request. Step S5: The client browser carries the encrypted customer data and redirects to the government affairs center system page. The government affairs center system parses the encrypted customer data and directs the user to the corresponding government affairs page based on the parsed data, and then returns the page to the client for display.

6. The multi-level cross-domain secure communication method based on bank-government business as described in claim 5, characterized in that, The encryption of the customer data invokes the intelligent encryption / decryption engine of the intelligent control layer, and combines the SM3 and SM4 national cryptographic algorithms with the national cryptographic enhanced JWT for encryption, specifically including: After dynamic SSID authentication is successful, the client device fingerprint hash is encrypted using the SM3 algorithm, and the encrypted data and the client ID are put into the token payload of the national cryptographic enhanced JWT. The national cryptographic enhanced JWT generates a request token, which is then put into the header for encryption, and the client data is put into the body to return the request.

7. The multi-level cross-domain secure communication method based on bank-government business as described in claim 6, characterized in that, The function of controlling access based on the visitor's geographical location specifically includes: The intelligent regional access control engine is invoked, and the request token is parsed using the national cryptographic enhanced JWT to extract the customer code from the header. Use the customer code to query the region and permissions of the customer in the local database, and verify whether the current operation is unauthorized based on the queryed user region and permissions; After verification is complete, execute subsequent business logic based on the current operation.

8. The multi-level cross-domain secure communication method based on bank-government business as described in claim 7, characterized in that, It also includes an identity verification process, specifically including: Obtain the visitor token and dynamic SSID, authenticate the visitor's identity, and obtain the customer ID after successful verification; Control visitor permissions based on their geographic location; control function permissions and data levels based on customer roles and levels; encrypt customer data using the SM4 national cryptographic algorithm. Returning to the system client, you are redirected to the government affairs center page. The government affairs system uses the SM4 national cryptographic algorithm to decrypt customer data. If decryption is successful, the process ends and the system displays a message indicating successful customer identity verification; if decryption fails, the process ends and the system displays a message indicating that customer identity verification failed.

9. A multi-level cross-domain secure communication method based on bank-government business as described in claim 8, characterized in that, The dynamic SSID is generated by accessing the bank's SSID authentication system. The system then requests the bank's SSID authentication system to verify the identity of the visitor requesting the current page using the dynamic SSID, returns customer information, and marks the customer's status. The dynamic SSID has a preset validity period and can only be successfully verified once.