Insurance electronic document processing method and system
Patent Information
- Application Number
- CN202610838824.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-10
- Publication Date
- 2026-08-21
AI Technical Summary
[0005]本申请提供一种保险电子单证处理方法及系统,用以解决保险电子单证有被篡改、共享难度大、丢失的可能性的问题
[0016]本申请提供的保险电子单证处理方法及系统,通过在保险终端生成对称加解密密钥,采用对称加解密密钥将保险电子单证加密,得到加密单证,并采用授权信息对应的公钥将对称加解密密钥加密得到加密后密钥,将加密单证和加密后密钥发送至存证终端,使存证终端不能得到对称加解密密钥和原始保险电子单证的情况下进行存证,接单终端通过从存证终端获取加密后密钥及加密单证,采用自身的解密私钥对加密后密钥进行解密,还原对称加解密密钥,并采用对称加解密密钥对加密单证进行解密,还原保险电子单证,实现在存证终端不能知道单证内容的情况下进行文件的传递,同时如果加密后单证被篡改,则无法采用对称加解密密钥进行解密,增加了保险电子单证的篡改难度,同时实现授权前提下的可信共享流转,保障了保险电子单证的真实性。
Smart Images

Figure CN122617554A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a method and system for processing electronic insurance documents. Background Technology
[0002] With the continuous development of the economy and society, enterprises and individuals are paying increasing attention to risk protection, and insurance has become a major means of risk protection. In shipping trade, shipping insurance, including cargo insurance, marine insurance, and credit insurance, plays an important role in ensuring the security of overseas trade development.
[0003] Currently, in order to improve the convenience of policyholders signing contracts, existing technologies can be used to process insurance electronic documents online for operations such as insurance application and policy information modification.
[0004] However, the inventors have found that the existing technology has at least the following technical problems: electronic insurance documents are easily lost or tampered with after being downloaded, and it is difficult to transfer and share them among multiple entities. Summary of the Invention
[0005] This application provides a method and system for processing electronic insurance documents, which solves the problems of electronic insurance documents being tampered with, difficult to share, and potentially lost.
[0006] Firstly, this application provides a method for processing electronic insurance documents. The method is applied to an electronic insurance document processing system, which includes an insurance terminal, a certificate storage terminal, and an order receiving terminal. The method includes: the insurance terminal, in response to receiving application information and authorization information sent by a demand-side terminal, generates a symmetric encryption / decryption key; generates an electronic insurance document corresponding to the application information; encrypts the electronic insurance document using the symmetric encryption / decryption key to obtain an encrypted document; obtains a target public key corresponding to the authorization information; encrypts the symmetric encryption / decryption key using the target public key to obtain an encrypted key; determines the characteristics of the insurance document based on the electronic insurance document and the authorization information; sends the insurance document characteristics, the encrypted document, and the encrypted key to the certificate storage terminal; the certificate storage terminal sends authorization event information to the corresponding order receiving terminal based on the insurance document characteristics; the order receiving terminal obtains the encrypted key and the encrypted document from the certificate storage terminal based on the authorization event information; decrypts the encrypted key using the target private key to obtain a symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
[0007] In one possible implementation, the insurance policy features are determined based on the electronic insurance policy and authorization information, including: obtaining the policy number and the distributed digital identity in the authorization information of the electronic insurance policy; and combining the policy number and the distributed digital identity into the insurance policy features.
[0008] In one possible implementation, the insurance policy features include an authorized party identifier and a policy identifier. Accordingly, based on the insurance policy features, authorization event information is sent to the corresponding order-receiving terminal, including: reading the authorized party identifier and policy identifier from the insurance policy features; writing the policy identifier into a preset authorization event information template to obtain authorization event information; finding a preset correspondence between the authorized party identifier and the node terminal address to obtain the target order-receiving terminal address; and using the target order-receiving terminal address, sending the authorization event information to the order-receiving terminal.
[0009] In one possible implementation, the system further includes a blockchain; the method further includes: the insurance terminal calculating the feature value of the encrypted document; sending the document number and feature value of the electronic insurance document to the evidence storage terminal; and the evidence storage terminal storing the document number and feature value on the blockchain.
[0010] In one possible implementation, after the certificate storage terminal stores the certificate number and feature value in the blockchain, the method further includes: the order receiving terminal reading the stored certificate number and the stored feature value from the blockchain; calculating the target feature value of the target insurance electronic certificate, wherein the target insurance electronic certificate is the insurance electronic certificate corresponding to the stored certificate number; and outputting a prompt message if the target feature value is different from the stored feature value.
[0011] In one possible implementation, the system further includes an evidence collection terminal; the method further includes: the evidence collection terminal reading the stored document number and the stored feature value from the blockchain; calculating the target feature value of the target insurance electronic document, wherein the target insurance electronic document is the insurance electronic document corresponding to the stored document number; and determining whether the target feature value is the same as the stored feature value.
[0012] In one possible implementation, the system further includes a blockchain; after the evidence storage terminal sends authorization event information to the corresponding order receiving terminal based on the characteristics of the insurance policy, the system further includes: the evidence storage terminal storing the authorization event information on the blockchain; the order receiving terminal reading the authorization event information from the blockchain; and obtaining the encrypted key and encrypted policy from the evidence storage terminal based on the authorization event information.
[0013] Secondly, this application provides an insurance electronic document processing system, comprising: an insurance terminal, a certificate storage terminal, and an order receiving terminal; the insurance terminal, in response to receiving application information and authorization information sent by the demand-side terminal, generates a symmetric encryption / decryption key; generates an insurance electronic document corresponding to the application information; encrypts the insurance electronic document using the symmetric encryption / decryption key to obtain an encrypted document; obtains a target public key corresponding to the authorization information; encrypts the symmetric encryption / decryption key using the target public key to obtain an encrypted key; determines the insurance document characteristics based on the insurance electronic document and authorization information; sends the insurance document characteristics, the encrypted document, and the encrypted key to the certificate storage terminal; the certificate storage terminal sends authorization event information to the corresponding order receiving terminal based on the insurance document characteristics; the order receiving terminal obtains the encrypted key and the encrypted document from the certificate storage terminal based on the authorization event information; decrypts the encrypted key using the target private key to obtain a symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the insurance electronic document.
[0014] In one possible implementation, the insurance policy features are determined based on the electronic insurance policy and authorization information, including: obtaining the policy number and the distributed digital identity in the authorization information of the electronic insurance policy; and combining the policy number and the distributed digital identity into the insurance policy features.
[0015] One possible implementation also includes: a blockchain; the insurance terminal calculates the feature value of the encrypted document; the document number and feature value of the electronic insurance document are sent to the evidence storage terminal; and the evidence storage terminal stores the document number and feature value on the blockchain.
[0016] The insurance electronic document processing method and system provided in this application generate a symmetric encryption / decryption key at the insurance terminal, encrypts the insurance electronic document using the symmetric encryption / decryption key to obtain an encrypted document, and then encrypts the symmetric encryption / decryption key again using the public key corresponding to the authorization information to obtain an encrypted key. The encrypted document and the encrypted key are then sent to the evidence storage terminal, enabling the evidence storage terminal to store documents without access to the symmetric encryption / decryption key and the original insurance electronic document. The receiving terminal obtains the encrypted key and the encrypted document from the evidence storage terminal, decrypts the encrypted key using its own decryption private key to restore the symmetric encryption / decryption key, and then decrypts the encrypted document using the symmetric encryption / decryption key to restore the insurance electronic document. This allows for file transfer without the evidence storage terminal knowing the document content. Furthermore, if the encrypted document is tampered with, it cannot be decrypted using the symmetric encryption / decryption key, increasing the difficulty of tampering with the insurance electronic document. Simultaneously, it achieves trusted sharing and circulation under authorized conditions, ensuring the authenticity of the insurance electronic document. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0018] Figure 1 A schematic diagram illustrating an application scenario of the electronic insurance document processing method provided in this application embodiment; Figure 2 A flowchart illustrating the electronic insurance document processing method provided in this application embodiment; Figure 3 A schematic diagram of the overall process of the electronic insurance document processing method provided in the embodiments of this application; Figure 4 This is a schematic diagram of the overall structure of the electronic insurance document processing system provided in this application embodiment.
[0019] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0020] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0021] In today's rapidly developing economy and society, both large enterprises and ordinary individuals are increasingly recognizing the importance of risk protection. Insurance, as one of the core means of risk protection, is receiving increasing attention. In shipping and trade, cargo insurance, marine insurance, and credit insurance play a crucial role in ensuring the security of overseas trade development.
[0022] To meet the growing demand for convenient insurance signing among policyholders and to keep pace with technological advancements, online platforms now support electronic insurance document signing. This method not only greatly simplifies the application process but also improves efficiency, allowing policyholders to conveniently and quickly complete insurance signing anytime, anywhere, and enjoy comprehensive risk protection. However, electronic insurance documents are susceptible to tampering and are not easily shared or circulated among multiple parties. To address these technical issues, the inventors propose the following technical concept: A symmetric encryption / decryption key is generated and used to encrypt the electronic insurance document, resulting in an encrypted document. The authorized party's public key is then used to encrypt the symmetric encryption / decryption key, yielding an encrypted key. The encrypted key and the encrypted document are then sent to a storage terminal for storage. The authorized party reads the encrypted key and the encrypted electronic insurance document from the storage terminal, decrypts the encrypted key using their stored private key, obtaining the aforementioned symmetric encryption / decryption key. This symmetric encryption / decryption key is then used to decrypt the encrypted document, resulting in the electronic insurance document.
[0023] This application is applied to scenarios involving the processing of electronic insurance documents. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0024] Figure 1 This is a schematic diagram illustrating an application scenario of the electronic insurance document processing method provided in this application embodiment. For example... Figure 1 In this scenario, the following terminals are included: demand-side terminal 101, insurance terminal 102, evidence storage terminal 103, and order receiving terminal 104.
[0025] In the specific implementation process, the demand-side terminal 101 may include computers, servers, tablets, mobile phones, PDAs (personal digital assistants), and laptops, which can input data.
[0026] Insurance terminal 102, evidence storage terminal 103, and order receiving terminal can all be implemented using a single server or a cluster of multiple servers with stronger processing capabilities and higher security. Where possible, computers or laptops with strong computing power can also be used as alternatives.
[0027] The connection between the demand-side terminal 101 and the insurance terminal 102, between the insurance terminal 102 and the evidence storage terminal 103, and between the evidence storage terminal 103 and the order receiving terminal 104 can be either wired or wireless.
[0028] Demand-side terminal 101 is used to send application information and authorization information to insurance terminal 102.
[0029] Insurance terminal 102 is used to issue electronic insurance documents based on application information. It encrypts the electronic insurance documents using a symmetric encryption / decryption key to obtain an encrypted document. It also encrypts the symmetric encryption / decryption key used for encryption using the public key corresponding to the authorization information to obtain an encrypted key. The encrypted document and the encrypted key are sent to the evidence storage terminal. The evidence storage terminal saves the encrypted document and the encrypted key and sends authorization event information to the corresponding order receiving terminal 104.
[0030] Upon receiving the authorization event information, the order receiving terminal 104 obtains the encrypted key and encrypted document from the evidence storage terminal 103; decrypts the encrypted key using the target private key to obtain the symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
[0031] It is understood that the scenario architecture illustrated in the embodiments of this application does not constitute a specific limitation on the method for processing electronic insurance documents. In other feasible embodiments of this application, the above architecture may include more or fewer components than illustrated, or combine some components, or split some components, or arrange different components, which can be determined according to the actual application scenario and is not limited here. Figure 1 The scenario shown can be implemented by hardware, software, or a combination of both.
[0032] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0033] Figure 2 This is a flowchart illustrating the electronic insurance document processing method provided in this application embodiment. This application embodiment is applied to... Figure 1 The insurance electronic document processing system consists of a demand-side terminal 101, an insurance terminal 102, a certificate storage terminal 103, and an order receiving terminal 104. For example... Figure 2 As shown, the method includes: S201: Upon receiving the application and authorization information from the demand-side terminal, the insurance terminal generates a symmetric encryption / decryption key. It generates an electronic insurance document corresponding to the application information. The electronic insurance document is encrypted using the symmetric encryption / decryption key to obtain an encrypted document. The target public key corresponding to the authorization information is obtained. The symmetric encryption / decryption key is encrypted using the target public key to obtain an encrypted key. Based on the electronic insurance document and authorization information, the characteristics of the insurance document are determined. The characteristics of the insurance document, the encrypted document, and the encrypted key are sent to the evidence storage terminal.
[0034] In this step, the methods for receiving application information and authorization information may include the insurance terminal receiving data packets or messages sent by the demand-side terminal and parsing the data packets or messages, or embedding them through page redirection. The method for generating the symmetric encryption / decryption key may include calling a preset random number generation function to obtain the symmetric encryption / decryption key, or it may include calling a preset key field generation program to obtain the symmetric encryption / decryption key. The symmetric encryption / decryption key can be a string of random numbers or a symmetric key generated by an encryption algorithm. The method for generating the insurance electronic document may include inputting data of a preset type from the application information into the insurance document generation program to obtain the insurance electronic document. Obtaining the target public key corresponding to the authorization information may include finding the preset correspondence between the authorization information and the public key based on preset information (such as authorization object information or distributed digital identity information) in the authorization information to obtain the corresponding target public key. Encrypting the symmetric encryption / decryption key using the target public key to obtain the encrypted key may include inputting the target public key and the symmetric encryption / decryption key into a preset encryption program to obtain the encrypted key output by the encryption program. Based on the electronic insurance document and authorization information, the characteristics of the insurance document are determined. This may include combining information of preset types from the electronic insurance document and authorization information to obtain the characteristics of the insurance document. The method for sending the insurance document characteristics, encrypted document, and encrypted key may include writing these three types of data into a data packet or message, and sending the resulting data packet or message to the evidence storage terminal.
[0035] The insurance policy generation and encryption programs can be pre-written by staff. The mapping between authorization information and public keys can also be pre-set by staff and stored in file, table, or key-value pair format. Electronic insurance documents can include electronic policies, electronic endorsements, etc.
[0036] S202: The certificate storage terminal sends authorization event information to the corresponding order receiving terminal based on the characteristics of the insurance policy.
[0037] This step may include reading the Decentralized Identity (DID) and document number from the insurance policy's features; generating authorization event information based on the document number, the document's ID (Identity), and the DID; finding the correspondence between the Decentralized Identity and contact information to obtain the corresponding contact information; and sending the authorization event information to the receiving terminal using the contact information. The authorization event information may be sent in data packet or message format.
[0038] The process of generating authorization event information based on the document number may include inputting the document number into an authorization event information template to obtain the authorization event information.
[0039] S203: The receiving terminal obtains the encrypted key and encrypted document from the evidence storage terminal based on the authorized event information. It decrypts the encrypted key using the target private key to obtain the symmetric encryption / decryption key. It then decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
[0040] This step may include the order-receiving terminal generating a data retrieval request from the authorized event information, sending the data retrieval request to the evidence storage terminal, and receiving the encrypted key and encrypted document corresponding to the data retrieval request from the evidence storage terminal. The process of decrypting the encrypted key may include inputting the encrypted key and the target private key into a preset decryption program to obtain the symmetric encryption / decryption key output by the decryption program. The method for decrypting to obtain the insurance electronic document is similar to the process of obtaining the symmetric encryption / decryption key, and will not be elaborated here.
[0041] Both the target private key and the target public key can be pre-stored by the order receiving terminal.
[0042] As described in the above embodiments, this application embodiment generates a symmetric encryption / decryption key at the insurance terminal, encrypts the electronic insurance document using the symmetric encryption / decryption key to obtain an encrypted document, and encrypts the symmetric encryption / decryption key using the public key corresponding to the authorization information to obtain an encrypted key. The encrypted document and the encrypted key are then sent to the evidence storage terminal, enabling the evidence storage terminal to perform evidence storage without obtaining the symmetric encryption / decryption key and the original electronic insurance document. The receiving terminal obtains the encrypted key and the encrypted document from the evidence storage terminal, decrypts the encrypted key using its own decryption private key to restore the symmetric encryption / decryption key, and then decrypts the encrypted document using the symmetric encryption / decryption key to restore the electronic insurance document. This allows for file transfer without the evidence storage terminal knowing the document content. Furthermore, if the encrypted document is tampered with, it cannot be decrypted using the symmetric encryption / decryption key, increasing the difficulty of tampering with the electronic insurance document. Simultaneously, it achieves trusted sharing and circulation under authorized conditions, ensuring the authenticity of the electronic insurance document.
[0043] In one possible implementation, step S201 above, determining the characteristics of the insurance policy based on the electronic insurance policy and authorization information, includes: S2011: Obtain the distributed digital identity from the document number and authorization information of the electronic insurance policy.
[0044] This step may include reading the document number from the electronic insurance document and reading the distributed digital identity from the authorization information.
[0045] The reading methods for document number and distributed digital identity can include reading document number-related fields in electronic insurance documents and reading distributed digital identity-related fields in authorization information.
[0046] S2012: Combine the document number and distributed digital identity into insurance document features.
[0047] This step may include writing the document number and distributed digital identity into a preset insurance document feature template to obtain insurance document features; or it may include establishing a correspondence between the distributed digital identity and the document number, and using the correspondence as the insurance document feature.
[0048] As can be seen from the description of the above embodiments, the embodiments of this application obtain the certificate number and authorization information, and combine the certificate number and distributed digital identity into insurance certificate features, which facilitates the subsequent sending of authorization event information by the evidence storage terminal and the storage of insurance certificate features.
[0049] In one possible implementation, the insurance policy characteristics include an authorized party identifier and a policy identifier. Accordingly, in step S202 above, based on the insurance policy characteristics, authorization event information is sent to the corresponding order-receiving terminal, including: S2021: Read the authorized party identifier and document identifier in the insurance policy features.
[0050] This step may include reading the authorized party identifier and the document identifier after pre-setting fields in the insurance document features.
[0051] S2022: Write the document identifier into the preset authorization event information template to obtain the authorization event information.
[0052] In this step, the authorized event information template can be pre-set by the staff.
[0053] S2023: Based on the authorized party's identifier, find the preset correspondence between the identifier and the node terminal address to obtain the target order-receiving terminal address.
[0054] In this step, the correspondence between the identifier and the node terminal address can be pre-set by the staff or generated in advance based on the interaction with the order receiving terminal, and can be stored in a table or key-value pair format.
[0055] S2024: Use the target order receiving terminal address to send the authorization event information to the order receiving terminal.
[0056] This step includes using a preset information sending protocol or information sending command to send the authorized event information to the order receiving terminal corresponding to the target order receiving terminal address.
[0057] As can be seen from the description of the above embodiments, the embodiments of this application obtain authorization event information by reading the authorized party identifier and the document identifier, writing the document identifier into a preset authorization event information template, and sending the authorization event information to the order receiving terminal using the target order receiving terminal address, thereby informing the order receiving terminal that a new authorization event has been generated.
[0058] In one possible implementation, the system also includes a blockchain 105. The method also includes: S204: The insurance terminal calculates the feature value of the encrypted document. It then sends the document number and feature value of the electronic insurance document to the evidence storage terminal.
[0059] In this step, the feature value can include hash function values such as MD5 (Message-Digest Algorithm), SHA-2 (SecureHash Algorithm 2), and SHA-512 (Secure Hash Algorithm 512); it can also include a hash value. The method of sending the document number and feature value can include writing the document number and feature value into a data packet or message, and then sending the data packet or message to the evidence storage terminal.
[0060] S205: The certificate storage terminal stores the certificate number and feature value on the blockchain.
[0061] In this step, the certificate storage terminal can store the certificate number and feature value in the blockchain in a corresponding relationship, or write the certificate number and feature value into the same file and store it in the blockchain.
[0062] As can be seen from the description of the above embodiments, the embodiments of this application calculate the feature value of the encrypted document, send the document number and feature value to the evidence storage terminal, and the evidence storage terminal stores the document number and feature value in the blockchain, thereby realizing the security of blockchain technology, ensuring that the insurance electronic document cannot be tampered with, and also avoiding losses caused by the loss of the downloaded insurance electronic document, and facilitating the trusted sharing and circulation with other partners.
[0063] In one possible implementation, after the certificate storage terminal stores the certificate number and feature value on the blockchain in step S205 above, the method further includes: S206: The order receiving terminal reads the stored document number and stored feature value from the blockchain.
[0064] In this step, the order-receiving terminal can read the stored document number and feature value from the blockchain based on its own distributed digital identity. Alternatively, the order-receiving terminal can also read the stored document number and feature value from the blockchain based on the document number and its own distributed digital identity.
[0065] The distributed digital identity of the order-receiving terminal itself can be obtained in advance through application.
[0066] S207: Calculate the target feature value of the target insurance electronic document, where the target insurance electronic document is the insurance electronic document corresponding to the stored document number.
[0067] In this step, a preset hash function calculation program can be used to calculate the target feature value of the target insurance electronic document; alternatively, a preset hash value calculation program can be used to calculate the target feature value of the target insurance electronic document. The target insurance electronic document can be an insurance electronic document obtained by the order receiving terminal through decryption using a symmetric encryption / decryption key.
[0068] S208: If the target feature value is different from the stored feature value, output a prompt message.
[0069] This step may include calculating the cosine similarity between the target feature value and the stored feature value. If the cosine similarity is 1, they are the same; otherwise, they are different. The output prompt information may include displaying the output prompt information or sending the prompt information to a preset terminal.
[0070] As described in the above embodiments, this application embodiment reads the stored document number and stored feature value from the blockchain through the order receiving terminal, finds the decrypted insurance electronic document corresponding to the stored document number, calculates the feature value of this insurance electronic document, compares it with the feature value in the blockchain, determines that the insurance electronic document has been modified if the feature value is different, and outputs a prompt message. This achieves the effect of ensuring that the insurance electronic document is not tampered with while ensuring that the insurance electronic document is not known to third parties, and prompting a message if the insurance electronic document has been tampered with.
[0071] In one possible implementation, the system also includes an evidence-gathering terminal. The method also includes: S220: The evidence collection terminal reads the stored document number and stored feature value from the blockchain. It calculates the target feature value of the target insurance electronic document, where the target insurance electronic document is the insurance electronic document corresponding to the stored document number; and determines whether the target feature value is the same as the stored feature value.
[0072] In this step, the evidence collection terminal can read the stored document number and its corresponding stored feature value from the blockchain based on the DID and document number. The process of calculating and comparing the feature values is similar to that described in steps S207 and S208 above, and will not be repeated here.
[0073] The evidence-gathering terminal may include the terminal device of the party needing to obtain evidence. The DID and document number of the evidence-gathering terminal may be received in advance.
[0074] As can be seen from the description of the above embodiments, the embodiments of this application read the stored document number and stored feature value from the blockchain through the evidence collection terminal, and compare them with the feature value of the existing electronic insurance document to realize the determination of the authenticity of the existing electronic insurance document by utilizing the anti-tampering characteristics of blockchain technology.
[0075] In one possible implementation, the system also includes a blockchain. After step S202, where the evidence storage terminal sends authorization event information to the corresponding order-receiving terminal based on the insurance policy characteristics, the system further includes: S209: The evidence storage terminal stores the authorization event information on the blockchain.
[0076] This step may include the evidence storage terminal converting the authorized event information into a preset format, and storing the converted authorized event information on the blockchain through a blockchain client or related development tools.
[0077] The authorization event information may include the authorized party's DID and document number, and the identifier of the electronic document.
[0078] S210: The order receiving terminal reads the authorization event information from the blockchain. Based on the authorization event information, it obtains the encrypted key and encrypted document from the evidence storage terminal.
[0079] In this step, the order-receiving terminal can continuously or periodically obtain newly added authorized event information from the blockchain. The DID and document number from the authorized event information are written into a data retrieval request, which is then sent to the evidence storage terminal. This allows the evidence storage terminal to send the encrypted key corresponding to the DID and document number, along with the encrypted document, to the order-receiving terminal.
[0080] Specifically, the order-receiving terminal can retrieve and read the authorization event information of its own DID from the blockchain.
[0081] As can be seen from the description of the above embodiments, the embodiments of this application store the authorization event information in the blockchain through the evidence storage terminal. The order receiving terminal obtains the encrypted key and encrypted document from the evidence storage terminal based on the authorization event information read from the blockchain, thereby realizing the transmission of authorization event information through the blockchain, ensuring the evidence storage and security of the authorization event information, and achieving non-repudiation.
[0082] In one possible implementation, before the insurance terminal generates a symmetric encryption / decryption key in response to receiving the application and authorization information sent by the demand-side terminal in step S201, the following method is further included: The insurance terminal receives the electronic business license signature sent by the demand-side terminal. The electronic business license signature can be obtained by the demand-side terminal signing the electronic business license or electronic ID card using its own private key. The insurance terminal verifies the signature using its public key. If the verification is successful, the above step S201 is executed.
[0083] The electronic business license signature can be completed by the demand-side terminal jumping to the insurance terminal connected to the insurance processing platform, and by scanning the code using the DID application to complete the above-mentioned process of signing the electronic business license with its own private key and verifying the signature.
[0084] Figure 3 This is a schematic diagram of the overall flow of the electronic insurance document processing method provided in the embodiments of this application. Figure 3 As shown, the overall process of the insurance electronic document processing method includes: S301: The demand-side terminal jumps to the insurance processing platform and completes the above-mentioned process of signing the electronic business license with its own private key and verifying the signature by scanning the code using the DID application. After the verification is completed, the insurance terminal generates an electronic insurance certificate. S302: The demand-side terminal sends authorization information to the insurance terminal.
[0085] This step can be achieved by having the demand-side terminal sign a notification agreement or authorization agreement. Authorization indicates agreement to authorize the storage and transfer of electronic insurance documents.
[0086] S303: The insurance terminal generates electronic insurance documents based on the authorization information; S304: The insurance terminal generates a symmetric encryption / decryption key.
[0087] S305: Encrypt the electronic insurance document using the generated symmetric encryption / decryption key to obtain the encrypted document, and calculate the hash value of the electronic insurance document.
[0088] S306: The insurance terminal will combine the encrypted document, document number, and hash value of the electronic insurance document into a set of associated information and send it to the evidence storage terminal for evidence storage.
[0089] S307: The certificate storage terminal records and stores the hash values of encrypted documents, document numbers, and electronic insurance documents, and uploads the document numbers, electronic insurance document hash value records, and status description information (such as creation, modification, and deletion) to the blockchain for storage and sharing.
[0090] S308: The insurance terminal sends the authorized party information and document number to the certificate storage center for registration and storage.
[0091] S309: The insurance terminal uses the public key corresponding to the authorized party's information to encrypt the symmetric encryption / decryption key, obtaining the encrypted key. The encrypted key is then sent to the evidence storage terminal for storage.
[0092] S310: The evidence storage terminal stores the encrypted key, the authorized party identifier, and the insurance electronic document number together, and uploads the insurance electronic document number, the authorized party's publicly available information, and status description (such as the authorized party identifier) to the blockchain storage.
[0093] S311: The evidence storage terminal sends authorization event information to the order receiving terminal (the authorized party terminal).
[0094] S312: The receiving terminal obtains the encrypted key and encrypted document from the certificate storage terminal.
[0095] S313: The order receiving terminal queries the corresponding hash value and status description information from the blockchain based on the order number.
[0096] S314: The receiving terminal uses its own private key to decrypt the encrypted key and obtains a decrypted random number (if the encrypted key has not been modified, the symmetric encryption and decryption key mentioned above will be obtained).
[0097] S315: The order receiving terminal uses a decrypted random number to decrypt the encrypted document, obtaining the decrypted electronic insurance document (if the electronic insurance document has not been tampered with, it is the aforementioned electronic insurance document).
[0098] S316: The receiving terminal calculates the hash value of the decrypted insurance electronic document and compares it with the hash value obtained from the blockchain. If they are the same, the document has not been tampered with; if they are different, the document has been tampered with.
[0099] Figure 4 This is a schematic diagram of the overall structure of the electronic insurance document processing system provided in this application embodiment. Figure 4 As shown, the insurance electronic document processing system 100 includes: an insurance terminal 102, a certificate storage terminal 103, an order receiving terminal 104, and a blockchain 105. The demand-side terminal 101 and the order receiving terminal 104 can be the same terminal or different terminals.
[0100] In response to receiving the application information and authorization information sent by the demand-side terminal 101, the insurance terminal 102 generates a symmetric encryption / decryption key; generates an electronic insurance document corresponding to the application information; encrypts the electronic insurance document using the symmetric encryption / decryption key to obtain an encrypted document; obtains the target public key corresponding to the authorization information; encrypts the symmetric encryption / decryption key using the target public key to obtain an encrypted key; determines the characteristics of the insurance document based on the electronic insurance document and authorization information; and sends the characteristics of the insurance document, the encrypted document, and the encrypted key to the evidence storage terminal. Based on the characteristics of the insurance policy, the evidence storage terminal 103 sends authorization event information to the corresponding order receiving terminal 104; Based on the authorization event information, the order receiving terminal 104 obtains the encrypted key and encrypted document from the evidence storage terminal; decrypts the encrypted key using the target private key to obtain the symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
[0101] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0102] In one possible implementation, the insurance policy features are determined based on the electronic insurance policy and authorization information, including: obtaining the policy number and the distributed digital identity in the authorization information of the electronic insurance policy; and combining the policy number and the distributed digital identity into the insurance policy features.
[0103] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0104] In one possible implementation, the insurance terminal calculates the feature value of the encrypted document; sends the document number and feature value of the electronic insurance document to the evidence storage terminal; and the evidence storage terminal stores the document number and feature value on the blockchain.
[0105] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0106] In one possible implementation, the insurance policy features include an authorized party identifier and a policy identifier. Accordingly, based on the insurance policy features, authorization event information is sent to the corresponding order-receiving terminal, including: reading the authorized party identifier and policy identifier from the insurance policy features; writing the policy identifier into a preset authorization event information template to obtain authorization event information; finding a preset correspondence between the authorized party identifier and the node terminal address to obtain the target order-receiving terminal address; and using the target order-receiving terminal address, sending the authorization event information to the order-receiving terminal.
[0107] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0108] In one possible implementation, after the certificate storage terminal stores the certificate number and feature value in the blockchain, the method further includes: the order receiving terminal reading the stored certificate number and the stored feature value from the blockchain; calculating the target feature value of the target insurance electronic certificate, wherein the target insurance electronic certificate is the insurance electronic certificate corresponding to the stored certificate number; and outputting a prompt message if the target feature value is different from the stored feature value.
[0109] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0110] In one possible implementation, the system further includes an evidence collection terminal 106; the method further includes: the evidence collection terminal reading the stored document number and the stored feature value from the blockchain; calculating the target feature value of the target insurance electronic document, wherein the target insurance electronic document is the insurance electronic document corresponding to the stored document number; and determining whether the target feature value is the same as the stored feature value.
[0111] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0112] In one possible implementation, the system further includes a blockchain. After the evidence storage terminal sends authorization event information to the corresponding order-receiving terminal based on the characteristics of the insurance policy, the system also includes: the evidence storage terminal storing the authorization event information on the blockchain; the order-receiving terminal reading the authorization event information from the blockchain; and the terminal obtaining the encrypted key and encrypted policy from the evidence storage terminal based on the authorization event information. The aforementioned symmetric encryption algorithm can use the SM4 national cryptographic symmetric algorithm, etc., and the public and private key pair associated with the DID can be generated using the SM2 asymmetric national cryptographic algorithm, etc.
[0113] The system provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0114] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.
[0115] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0116] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for processing electronic insurance documents, characterized in that, The method is applied to an insurance electronic document processing system, which includes an insurance terminal, a document storage terminal, and an order receiving terminal; the method includes: The insurance terminal, upon receiving application and authorization information from the demand-side terminal, generates a symmetric encryption / decryption key; generates an electronic insurance document corresponding to the application information; encrypts the electronic insurance document using the symmetric encryption / decryption key to obtain an encrypted document; obtains the target public key corresponding to the authorization information; encrypts the symmetric encryption / decryption key using the target public key to obtain an encrypted key; determines the insurance document characteristics based on the electronic insurance document and the authorization information; and sends the insurance document characteristics, the encrypted document, and the encrypted key to the evidence storage terminal. The evidence storage terminal sends authorization event information to the corresponding order receiving terminal based on the characteristics of the insurance policy. The order receiving terminal obtains the encrypted key and the encrypted document from the evidence storage terminal based on the authorization event information; decrypts the encrypted key using the target private key to obtain the symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
2. The method according to claim 1, characterized in that, The step of determining the insurance policy characteristics based on the electronic insurance policy and the authorization information includes: Obtain the document number of the electronic insurance policy and the distributed digital identity from the authorization information; The document number and the distributed digital identity are combined to form the insurance document features.
3. The method according to claim 1, characterized in that, The insurance policy document features include an authorized party identifier and a document identifier; correspondingly, the step of sending authorization event information to the corresponding order-receiving terminal based on the insurance policy document features includes: Read the authorized party identifier and the document identifier from the insurance policy features; The document identifier is written into a preset authorization event information template to obtain the authorization event information; Based on the authorized party identifier, find the preset correspondence between the identifier and the node terminal address to obtain the target order receiving terminal address; The authorization event information is sent to the order receiving terminal using the target order receiving terminal address.
4. The method according to claim 1, characterized in that, The system further includes a blockchain; the method further includes: The insurance terminal calculates the feature value of the encrypted document; and sends the document number of the electronic insurance document and the feature value to the evidence storage terminal. The certificate storage terminal stores the certificate number and the feature value in the blockchain.
5. The method according to claim 4, characterized in that, After the evidence storage terminal stores the certificate number and the feature value in the blockchain, the method further includes: The order receiving terminal reads the stored certificate number and stored feature value from the blockchain; Calculate the target feature value of the target electronic insurance document, wherein the target electronic insurance document is the electronic insurance document corresponding to the stored document number; If the target feature value is different from the stored feature value, a prompt message will be output.
6. The method according to claim 5, characterized in that, The system further includes an evidence-gathering terminal; the method further includes: The evidence collection terminal reads the stored document number and stored feature value from the blockchain; calculates the target feature value of the target insurance electronic document, wherein the target insurance electronic document is the insurance electronic document corresponding to the stored document number; and determines whether the target feature value is the same as the stored feature value.
7. The method according to any one of claims 1 to 5, characterized in that, The system further includes a blockchain; after the evidence storage terminal sends authorization event information to the corresponding order receiving terminal based on the characteristics of the insurance policy, it also includes: The evidence storage terminal stores the authorization event information in the blockchain; The order-receiving terminal reads the authorization event information from the blockchain; based on the authorization event information, it obtains the encrypted key and the encrypted document from the evidence storage terminal.
8. An electronic insurance document processing system, characterized in that, include: Insurance terminals, evidence storage terminals, and order receiving terminals; The insurance terminal, upon receiving application and authorization information from the demand-side terminal, generates a symmetric encryption / decryption key; generates an electronic insurance document corresponding to the application information; encrypts the electronic insurance document using the symmetric encryption / decryption key to obtain an encrypted document; obtains the target public key corresponding to the authorization information; and encrypts the symmetric encryption / decryption key using the target public key to obtain an encrypted key. Based on the aforementioned electronic insurance document and the aforementioned authorization information, the characteristics of the insurance document are determined; The insurance policy features, the encrypted policy, and the encrypted key are sent to the evidence storage terminal. The evidence storage terminal sends authorization event information to the corresponding order receiving terminal based on the characteristics of the insurance policy. The order receiving terminal obtains the encrypted key and the encrypted document from the evidence storage terminal based on the authorization event information; decrypts the encrypted key using the target private key to obtain the symmetric encryption / decryption key; and decrypts the encrypted document using the symmetric encryption / decryption key to obtain the electronic insurance document.
9. The system according to claim 8, characterized in that, The step of determining the insurance policy characteristics based on the electronic insurance policy and the authorization information includes: Obtain the document number of the electronic insurance policy and the distributed digital identity from the authorization information; The document number and the distributed digital identity are combined to form the insurance document features.
10. The system according to claim 8, characterized in that, Also includes: Blockchain; The insurance terminal calculates the feature value of the encrypted document; The document number and the feature value of the electronic insurance document are sent to the evidence storage terminal; The certificate storage terminal stores the certificate number and the feature value in the blockchain.