Digital calibration certificate generation and verification method and system based on micro-service architecture
The digital calibration certificate generation and verification system based on a microservice architecture solves the problem that existing systems cannot meet multiple requirements, achieving high reliability, high stability and easy iteration, ensuring the compliance and credibility of certificates, supporting the FAIR principle, and meeting the information requirements of the metrology and IT industries.
Patent Information
- Application Number
- PCT/CN2024/093791
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-25
- Filing Date
- 2024-05-17
- Publication Date
- 2025-10-30
AI Technical Summary
Existing digital calibration certificate generation and verification systems are unable to simultaneously meet the information and digital security requirements of the metrology and IT industries, and are also unable to achieve FAIR (Fairness and Arbitration) of metrology data.
A digital calibration certificate generation and verification system based on a microservice architecture is adopted, which includes a user subsystem, a service subsystem, a processing subsystem, a digital security subsystem, and a storage subsystem. Digital calibration certificates are generated and verified through these subsystems. Digital signatures and trusted timestamps are used to ensure the integrity and trustworthiness of the certificates. The microservice architecture achieves high reliability and easy iteration of the system.
It achieves high reliability, high stability, and easy iteration of digital calibration certificates, meets IT requirements, ensures machine readability and operability of certificates, supports the FAIR principle, and ensures the compliance and trustworthiness of certificates.
Smart Images

Figure CN2024093791_30102025_PF_FP_ABST
Abstract
Description
A method and system for generating and verifying digital calibration certificates based on a microservice architecture Technical Field
[0001] This specification relates to the field of security protection technology, and in particular to a method and system for generating and verifying digital calibration certificates based on a microservice architecture. Background Technology
[0002] Metrology today faces the challenges of the digital age. Metrology is entering a digital era, and the SI digital framework and the FAIR (discoverable, accessible, interoperable, and reusable) of metrological data signify a global consensus on the importance of digital transformation in metrology. Calibration certificates are crucial information carriers for metrological traceability. Digital calibration certificates (DCCs) are vital information carriers for metrological traceability in the digital world; their format is unified and standardized, and they are machine-readable and machine-operable.
[0003] The German National Institute of Metrology (PTB) has done extensive pioneering work in the development of DCC metamodels and best practices, and has led four international DCC conferences, making significant contributions to the promotion and popularization of DCC worldwide. PTB developed GEMIMEG-Tool, a web-based DCC generation and verification tool, but it is still far from large-scale production application. The National Institute of Metrology (NIM) of China, drawing on the PTB-DCC metamodel, developed the bilingual (Chinese and English) NIM-DCC metamodel, as well as stand-alone NIM-DCC generation and verification software. However, neither of these can simultaneously meet the information requirements of the metrology industry, the IT industry, digital security requirements, and the FAIR principle of metrological data.
[0004] Summary of the Invention
[0005] To address the aforementioned shortcomings in existing technologies, this invention provides a digital calibration certificate generation and verification method and system based on a microservice architecture, which solves the problem that digital calibration certificates are difficult to meet standard requirements.
[0006] To achieve the aforementioned objectives, the present invention employs the following technical solution: a digital calibration certificate generation and verification system based on a microservice architecture, comprising:
[0007] The user subsystem is used to obtain digital calibration certificate content information and transmit the digital calibration certificate generation verification results to users.
[0008] The service subsystem is used to provide access services and obtain calibration business data based on the content information of the digital calibration certificate.
[0009] The processing subsystem is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp; and to verify the digital calibration certificate to obtain the digital calibration certificate generation verification result.
[0010] The digital security subsystem is used to authenticate the user subsystem through the service subsystem; and to provide digital signatures and trusted timestamps for the processing subsystem.
[0011] The storage subsystem is used to store information and data during the processing; it also provides corresponding information and data to the processing subsystem.
[0012] The beneficial effects of the present invention are as follows: The digital calibration certificate generation and verification system based on microservice architecture generates and verifies digital calibration certificates using user subsystem, service subsystem, processing subsystem, digital security subsystem and storage subsystem, and obtains digital calibration certificate generation and verification results. (1) By adopting microservice architecture, the system can achieve high reliability, high stability and easy iteration; (2) By using digital calibration certificate templates and verification processes, the information of calibrators, auditors and approvers is standardized, compliant and proceduralized; (3) By using format verification processes, the generated digital calibration certificates meet IT requirements; (4) Digital certificates are provided to calibration institutions, calibrators, auditors and approvers, and digital certificates are used to digitally sign DCCs, and the content of DCCs is stamped with a trusted timestamp to ensure that the data content is complete and tamper-proof, and to ensure that the identity and data of the DCCs provided are trustworthy; (5) A certificate management unit is added, and compliant DCCs have unique DOI numbers to ensure that DCCs are discoverable and obtainable; the machine-readable and operable syntax compliance of DCCs is verified to achieve their operability and reusability, and to meet the FAIR principle.
[0013] Furthermore, the user subsystem includes:
[0014] The terminal module is used to obtain the content information of the digital calibration certificate through the terminal device;
[0015] The server module is used to transmit the content information of the digital calibration certificate to the service subsystem.
[0016] Furthermore, the service subsystem includes:
[0017] The network service module is used to provide users with access services for generating the verification system;
[0018] The digital calibration service module is used to collect calibration service data based on the content information of the digital calibration certificate through the time-frequency calibration service and the length calibration service.
[0019] Furthermore, the processing subsystem includes:
[0020] The interface module is used to configure security mechanisms and connect the service subsystem with the business module and the basic management module.
[0021] The business module is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp.
[0022] The basic management module is used to verify the digital calibration certificate and obtain the digital calibration certificate generation verification result;
[0023] The configuration module is used to configure and manage the business modules and basic modules.
[0024] Furthermore, the business module includes:
[0025] The module management unit is used to obtain the corresponding digital calibration certificate template based on the metrology standards in the professional field;
[0026] The generation unit is used to generate a digital calibration certificate based on the digital calibration certificate template, the digital calibration certificate content information, and the calibration business data;
[0027] The security management unit is used to digitally sign and timestamp digital calibration certificates to obtain securely managed digital calibration certificates.
[0028] The verification unit is used to perform format, syntax, and security verification on the digital calibration certificate of the security management system to obtain the final digital calibration certificate.
[0029] Furthermore, the basic management module includes:
[0030] The certificate management unit is used to update, query, and publish the version of the digital calibration certificate and its corresponding digital unit system based on the digital calibration certificate.
[0031] The access control unit is used to provide users in the system with registration, access control, and authentication management services.
[0032] The verification calculation unit is used to utilize verification calculation tools to provide corresponding calibration calculation functions based on metrological standards, professional terminology, and verification codes to verify the digital calibration certificate and obtain the digital calibration certificate generation verification result.
[0033] The identification management unit is used to generate an organization name identifier and a digital object identifier based on the verified digital calibration certificate, thereby enabling the registration of the digital calibration certificate;
[0034] The vocabulary management unit is used to provide metrological standards, technical terms, and verification codes to enable the generation and verification process of digital calibration certificates.
[0035] Furthermore, the configuration module includes:
[0036] The configuration unit is used to provide information configuration services for the business module and the basic management module.
[0037] The log management unit is used to manage the logs generated in the business module and the basic management module;
[0038] The registration and discovery unit is used to provide registration and discovery components for the business modules and basic management modules, and to dynamically schedule the modules based on the current application scale.
[0039] The microservice unit is used to visualize the business modules and basic management modules; and to manage the generated digital calibration certificates.
[0040] Furthermore, the digital security subsystem includes:
[0041] A digital identity module is used to provide digital identity information to the terminal module and the server module;
[0042] The digital signature module is used to generate digital signatures using cryptographic devices;
[0043] The trusted timestamp module is used to generate trusted timestamps using a timestamp server.
[0044] Furthermore, the storage subsystem includes:
[0045] The user information storage module is used to store user, authentication, and management information.
[0046] The certificate information storage module is used to store digital calibration certificate files, signatures, timestamps, process data, and management data.
[0047] The key information storage module is used to store digital signatures and their corresponding keys;
[0048] The data storage module is used to store business data, back-end service data, and process control data.
[0049] A method for generating and verifying digital calibration certificates based on a microservice architecture includes:
[0050] Obtain the digital calibration certificate information;
[0051] Based on the information contained in the digital calibration certificate, calibration business data is obtained;
[0052] Generate digital signatures and trusted timestamps;
[0053] A digital calibration certificate is generated based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp; the digital calibration certificate is verified to obtain the digital calibration certificate generation verification result. Attached Figure Description
[0054] This specification will be further described by way of exemplary embodiments, which will be described in detail with reference to the accompanying drawings. These embodiments are not limiting; in these embodiments, the same reference numerals denote the same structures, wherein:
[0055] Figure 1 is a schematic diagram of an application scenario of a digital calibration certificate generation and verification system based on a microservice architecture, according to some embodiments of this specification.
[0056] Figure 2 is an exemplary flowchart of a digital calibration certificate generation and verification method based on a microservice architecture, according to some embodiments of this specification. Detailed Implementation
[0057] The specific embodiments of the present invention are described below to enable those skilled in the art to understand the present invention. However, it should be understood that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, various changes are obvious as long as they are within the spirit and scope of the present invention as defined and determined by the appended claims. All inventions utilizing the concept of the present invention are protected.
[0058] Example 1
[0059] Figure 1 is a schematic diagram of a digital calibration certificate generation and verification system based on a microservice architecture, according to some embodiments of this specification.
[0060] In some embodiments, the microservice-based digital calibration certificate generation and verification system may include a user subsystem, a service subsystem, a processing subsystem, a digital security subsystem, and a storage subsystem.
[0061] The user subsystem is used to obtain information about the digital calibration certificate content and to transmit the digital calibration certificate generation and verification results to the user.
[0062] The content information of a digital calibration certificate describes the calibration process. For example, the content information of a digital calibration certificate may include the calibration object, calibration time, administrative data, calibration organization, calibration environment, calibration method, calibration instrument, and calibration result data.
[0063] In some embodiments, the user subsystem may include a terminal module and a server module.
[0064] The terminal module is used to obtain the content information of the digital calibration certificate through the terminal device.
[0065] Terminal devices may include computers, tablets, calibration instruments, and other similar devices.
[0066] In some embodiments, the terminal module can use the terminal device to upload the original data of the calibration certificate and obtain the content information of the digital calibration certificate.
[0067] The server module is used to transmit the raw calibration certificate data of the user subsystem to the service subsystem and transmit the content information of the digital calibration certificate to the terminal module.
[0068] In some embodiments, the authorized user subsystem can transmit digital calibration certificate content information from the service subsystem to the user subsystem via the Internet. For example, the server can authorize the user subsystem using a USB smart key.
[0069] The verification result of digital calibration certificate generation reflects whether the generated format of the digital calibration certificate and the calibration results conform to the standard. For example, the verification result of digital calibration certificate generation may include the generated format of the digital calibration certificate, whether the calibration results conform to the standard, the specific generation time of the certificate, and the digital signature information in the certificate (calibrator, auditor, approver, organization), etc.
[0070] The service subsystem is used to provide access services and obtain calibration business data based on the content information of the digital calibration certificate.
[0071] In some embodiments, the service subsystem can provide users with visual access services.
[0072] Calibration operational data refers to data related to specific calibration operational processes. For example, calibration operational data may include time and frequency calibration operational data and length calibration operational data.
[0073] In some embodiments, the service subsystem may include a network service module and a digital calibration service module.
[0074] The network service module is used to provide users with access services for generating the verification system.
[0075] In some embodiments, the network service module may utilize a web server deployed at the front end to provide users with a visual access via a web page, helping users select digital calibration certificate generation and calibration services.
[0076] The digital calibration service module is used to collect calibration service data based on the content information of the digital calibration certificate through the time-frequency calibration service and the length calibration service.
[0077] The time and frequency calibration service is a service that calibrates time and frequency. By calculating the data of the GNSS receiver being calibrated and the reference GNSS receiver, the time difference and uncertainty between the calibrated receiver and the reference receiver are obtained. The "processing subsystem" generates a digital calibration certificate and sends it back to the receiver being calibrated. The receiver being calibrated verifies the certificate based on the received digital calibration certificate, parses the calibration result in the digital calibration certificate, and completes the calibration of the receiver.
[0078] The length calibration service generates digital calibration certificates based on length calibration results. The calibration laboratory measures the object to be calibrated under specified experimental conditions according to metrological calibration specifications, obtains the raw measurement data, and calculates the average deviation and uncertainty. This service generates the corresponding digital calibration certificate based on calibration specifications, calibration environment, calibration results, and other relevant information, and provides it to the end user.
[0079] In some embodiments, the digital calibration service module can collect corresponding service data from the digital security subsystem and the storage subsystem based on the time-frequency calibration service and the length calibration service.
[0080] The processing subsystem is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp; and to verify the digital calibration certificate to obtain the digital calibration certificate generation verification result.
[0081] A Digital Calibration Certificate (DCC) is a certificate that uses calibration information to ensure the accuracy and traceability of measuring equipment.
[0082] In some embodiments, the processing subsystem may use the digital calibration certificate content information and calibration business data to generate a corresponding digital calibration certificate.
[0083] In some embodiments, the processing subsystem may include an interface module, a business module, a basic management module, and a configuration module.
[0084] The interface module is used to configure security mechanisms and connect the service subsystem with the business module and the basic management module.
[0085] Security mechanisms are mechanisms that control secure address interactions. For example, security mechanisms may include setting address whitelists, setting address blacklists, rate limiting, and circuit breaking.
[0086] In some embodiments, the interface module can utilize security mechanisms to connect the service subsystem with the business module and the basic management module, and transmit digital calibration certificate content information and calibration business data to the business module and the basic management module.
[0087] The business module is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp.
[0088] In some embodiments, a business module may include a module management unit, a generation unit, a security management unit, and a verification unit.
[0089] The module management unit is used to obtain the corresponding digital calibration certificate template based on the metrology standards in the professional field.
[0090] Metrological standards are those with lower accuracy than metrological references. They are used to verify other metrological standards or working measuring instruments. Different professional fields have corresponding metrological standards.
[0091] In some embodiments, the module management unit can determine the corresponding metrological standard by searching the professional field of the digital calibration certificate.
[0092] A digital calibration certificate template is a template used to retrieve information about the content of a digital calibration certificate. For example, a digital calibration certificate template may include areas for the calibration object, calibration organization, calibration environment, calibration process, and calibration results.
[0093] In some embodiments, the user subsystem can divide the digital calibration certificate template into a calibration object area, a calibration institution area, a calibration environment area, a calibration process area, and a calibration result area, and use a terminal device to obtain the corresponding digital calibration certificate content information. For example, the calibration object area can obtain the calibration object company name, address, and calibration time; the calibration institution area can obtain the calibration institution name and responsible person information; the calibration environment area can obtain the calibration environmental conditions and location; the calibration process area can obtain the measurement methods and measuring instruments used in the calibration; and the calibration result area can obtain the calibration result data, etc.
[0094] The generation unit is used to generate a digital calibration certificate based on the digital calibration certificate template, the digital calibration certificate content information, and the calibration business data.
[0095] In some embodiments, the generation unit can arrange the digital calibration certificate content information according to the digital calibration certificate template to obtain a digital calibration certificate.
[0096] The security management unit is used to digitally sign and timestamp digital calibration certificates to obtain securely managed digital calibration certificates.
[0097] In some embodiments, the security management unit can obtain the corresponding digital signature and valid timestamp in the digital security subsystem based on the digital calibration certificate, and digitally sign and timestamp the digital calibration certificate.
[0098] In some embodiments, the security management unit can generate an organization name identifier (PID) and a category identifier for the digital calibration certificate according to the naming standard of DOI, and bind the PID to the content of the digital calibration certificate.
[0099] In some embodiments, the security management unit can perform procedural CA endorsements (such as calibrator, auditor, approver, organization) and corresponding timestamp endorsements on the digital calibration certificate, and encapsulate the relevant CA signature and timestamp endorsement data blocks / files accordingly to obtain a security-managed digital calibration certificate.
[0100] The verification unit is used to perform format, syntax, and security verification on the digital calibration certificate of the security management system to obtain the final digital calibration certificate.
[0101] In some embodiments, the verification unit can use calibration business data to verify the file format, syntax and semantics, digital signature and timestamp of the digital calibration certificate to obtain the final digital calibration certificate.
[0102] The basic management module is used to verify the digital calibration certificate and obtain the digital calibration certificate generation verification result.
[0103] In some embodiments, the basic management module may include a certificate management module, a permission management module, a verification calculation module, an identifier management module, and a vocabulary management module.
[0104] The certificate management unit is used to update and query the version of the digital calibration certificate and digital unit system based on the digital calibration certificate.
[0105] In some embodiments, the certificate management unit can use the generated XSD file to query for new versions and publish them based on the digital calibration certificate.
[0106] The access control unit is used to provide users in the system with registration, access control, and authentication management services.
[0107] In some embodiments, the permission management unit can manage user permissions, provide corresponding registration services and assign corresponding roles to different types of users (certificate-providing users, verification users, etc.), assign permissions based on different users, and perform authentication management.
[0108] The verification calculation unit is used to utilize verification calculation tools to provide corresponding calibration calculation functions based on metrological standards, professional terminology, and verification codes to verify the digital calibration certificate and obtain the digital calibration certificate generation verification result.
[0109] Verification calculation tools are methods and tools used to calibrate and verify digital calibration certificates.
[0110] In some embodiments, the verification calculation unit can perform verification using targeted verification calculation tools based on the professional field and corresponding metrological standards of the digital calibration certificate, and obtain the verification result of the digital calibration certificate generation.
[0111] In some embodiments, the verification calculation unit can use the digital calibration certificate and the corresponding timestamp annotation data, and calculate the hash value of the digital calibration certificate file using the hash algorithm declared in the timestamp annotation data. The hash value of the digital calibration certificate stored in the timestamp annotation data is compared with the hash value of the digital calibration certificate. The unit determines the validity of the hash by comparing the hash value with the hash value of the digital calibration certificate stored in the timestamp annotation data, and verifies the hash signature value of the digital calibration certificate in the timestamp annotation data using the public key of the timestamp certificate in the timestamp annotation data.
[0112] In some embodiments, the verification calculation unit may use the digital calibration certificate file and the corresponding signature result data to verify the legality of the corresponding signature information, such as the signatures of the calibrator, verifier, approver, or organization, based on the CA certificate number (matching the CA certificate) or certificate verification in the signature data.
[0113] In some embodiments, the verification calculation unit can read the corresponding version of the digital calibration certificate file and use the corresponding version's metamodel definition (xsd) file to perform syntactic and semantic verification on the digital calibration certificate file. For example, the verification calculation unit can verify the completeness of the elements and nodes contained in the digital calibration certificate, the legality of element names and data types, the completeness and legality of the descriptions of each data node, the legality of numerical values, and the legality of the unit system, etc., based on technical terms and verification codes.
[0114] The identification management unit is used to generate an organization name identifier and a digital object identifier based on the verified digital calibration certificate, thereby enabling the registration of the digital calibration certificate.
[0115] The Institution Name Identifier (PID) is an identifier generated by the system during the verification process of digital calibration certificates.
[0116] A Digital Object Identifier (DOI) is a network identifier generated after a digital calibration certificate has been verified.
[0117] In some embodiments, the identification management unit may use the verification process of the digital calibration certificate to obtain the corresponding organization name identification number and digital object identifier, and register the digital object identifier.
[0118] The vocabulary management unit is used to provide metrological standards, technical terms, and verification codes to enable the generation and verification process of digital calibration certificates.
[0119] Technical terms are the terms used in the specific field corresponding to the calibration method. For example, technical terms may include units, quantities, values, measurement principles, measurement methods, measuring instruments, measuring devices, uncertainty, and other metrological terms defined in VIM (Vocabulary of Measurement).
[0120] The verification code is data used to verify digital calibration certificates.
[0121] In some embodiments, the vocabulary management unit can provide references and verification data for the metrological standards, technical terms, and other relevant information used in the generation and verification of digital calibration certificates.
[0122] The configuration module is used to configure and manage the business modules and basic modules.
[0123] In some embodiments, the configuration module may include a configuration unit, a log management unit, a registration and discovery unit, and a microservice unit.
[0124] Microservices are various services within a system that users can access and select. For example, microservices may include query services, digital calibration certificate generation services, and verification services.
[0125] The configuration unit is used to provide information configuration services for the business module and the basic management module.
[0126] In some embodiments, the configuration unit can act as a configuration service center in microservice management, providing unified configuration for all microservices. For example, the configuration unit can configure service ports, database connection URLs, log levels, etc.
[0127] The log management unit is used to manage the logs generated in the business module and the basic management module.
[0128] In some embodiments, the log management unit can provide centralized log management functionality for all microservices. For example, the log management unit can perform log collection, log storage, log retrieval, and log querying for all microservices.
[0129] The registration and discovery unit is used to provide registration and discovery components for the business modules and basic management modules, and to dynamically schedule the modules based on the current application scale.
[0130] The registration-discovery component is used to reflect the relationship between the number of microservices and users.
[0131] In some embodiments, the registration and discovery unit can utilize the registration-discovery component to provide dynamic scheduling capabilities for internal microservices, dynamically increasing and decreasing the number of services based on the current application scale, and providing load balancing support.
[0132] The microservice unit is used to visualize the business modules and basic management modules; and to manage the generated digital calibration certificates.
[0133] In some embodiments, a microservice unit can transfer microservice items to a service subsystem for users to access visually.
[0134] In some embodiments, the microservice unit can manage the generated digital calibration certificates using methods such as storage and scheduling.
[0135] The digital security subsystem is used to authenticate the user subsystem through the service subsystem and to provide digital signatures and trusted timestamps for the processing subsystem.
[0136] A digital signature is a signature that proves the authenticity of information.
[0137] A trusted timestamp is data that reflects the time of content with credibility.
[0138] In some embodiments, the digital security subsystem may include a digital identity module, a digital signature module, and a trusted timestamp module.
[0139] The digital identity module is used to provide digital identity information to the terminal module and the server module.
[0140] In some embodiments, the digital identity module can provide digital identity services (e.g., CA certificate services) for various terminals and distribute certificates through commercial cryptographic devices (e.g., USBKey, TF cryptographic card, etc.) to provide digital identity for terminals.
[0141] The digital signature module is used to generate digital signatures using cryptographic devices.
[0142] Cryptographic devices are devices used to provide signature services and are capable of generating random numbers that conform to the "Random Number Detection Specification".
[0143] In some embodiments, the cryptographic device may have built-in RSA or SM2 signature algorithms, enabling secure key storage and physical mechanisms to prevent the key from being read.
[0144] In some embodiments, the digital signature module can use a secure hardware cryptographic card of a cryptographic device to sign and generate a digital signature through cryptographic commercial device authentication.
[0145] The trusted timestamp module is used to generate trusted timestamps using a timestamp server.
[0146] A timestamp server is a server that provides trusted timestamp signatures. For example, a timestamp server may include TSA hardware products developed based on PKI technology, employing a precise time source, high-strength, high-standard security mechanisms, and capable of providing users with accurate and non-repudiable timestamp services. The service interface requests timestamps that strictly adhere to the international standard RFC3161 timestamp protocol via the HTTP protocol, using standard RFC3161 timestamp request, timestamp response, and timestamp encoding formats.
[0147] In some embodiments, the trusted timestamp module can utilize a timestamp server to authenticate via a cryptographic commercial device and generate a trusted timestamp using a metrology-grade time source with a valid trusted calibration certificate.
[0148] The storage subsystem is used to store information and data during the processing; it also provides corresponding information and data to the processing subsystem.
[0149] The information and data used in the processing are those required for the generation and verification of digital calibration certificates. For example, the information and data used in the processing may include user data, certificate data, key data, and business data.
[0150] In some embodiments, the storage subsystem may provide the processing subsystem with information and data during the processing.
[0151] In some embodiments, the storage subsystem may include a user information storage module, a certificate information storage module, a key information storage module, and a data information storage module.
[0152] The user information storage module is used to store user, authentication, and management information.
[0153] User information is the information required when a user registers. For example, user information may include the user's address, name, and other information.
[0154] Authentication information is information related to user authentication. For example, authentication information may include a list of permissions a user has, the user's login password, the user's login public key, API session information, etc.
[0155] Management information refers to information related to user management. For example, management information may include the relationships between users and calibration institutions, calibration groups, personnel roles, and review processes.
[0156] In some embodiments, the user information storage module can obtain and store user, authentication, and management information through the user subsystem.
[0157] The certificate information storage module is used to store digital calibration certificate files, signatures, timestamps, process data, and management data.
[0158] Process data refers to data related to the generation and verification processes of digital calibration certificates. For example, process data may include initial records of the certificate, signature records of the inspector, signature records of the auditor, signature records of the approver, signature records of the organization, verification records, etc.
[0159] Management data refers to data related to the management of digital calibration certificates. For example, management data may include the certificate's issuing authority, the calibration group to which the certificate belongs, the personnel associated with the certificate, and the certificate's audit logs.
[0160] In some embodiments, the certificate information storage module may use the service subsystem, processing subsystem, and digital security subsystem to acquire and store digital calibration certificate files, signatures, timestamps, process data, and management data.
[0161] The key information storage module is used to store digital signatures and their corresponding keys.
[0162] A key is a key used to encrypt and decrypt numbers. For example, the key can include RSA and Chinese national standard SM2.
[0163] In some embodiments, the key information storage module can acquire and store digital signatures and corresponding keys through the digital security subsystem.
[0164] The data storage module is used to store business data, back-end service data, and process control data.
[0165] Business data refers to data related to specific processing tasks. For example, business data may include time and frequency calibration business data, length calibration business data, etc.
[0166] Backend service data refers to data generated during backend processing and transmission. For example, backend service data may include digital calibration certificate data, calibration organization data, calibration group data, audit log data, and calibration personnel data.
[0167] Process control data refers to data used to control the processing procedures. For example, process control data may include audit process data, calibrator signature records, auditor signature records, approver signature records, and organization signature records.
[0168] In some embodiments, the data information storage module can utilize the service subsystem and the processing subsystem to acquire and store business data, back-end service data, and process control data.
[0169] In some embodiments of this specification, the digital calibration certificate generation and verification system based on a microservice architecture uses a user subsystem, a service subsystem, a processing subsystem, a digital security subsystem, and a storage subsystem to generate and verify digital calibration certificates, and obtain the digital calibration certificate generation and verification results. (1) By adopting a microservice architecture, the system can achieve high reliability, high stability, and easy iteration; (2) By using digital calibration certificate templates and verification processes, the information of calibrators, auditors, and approvers is standardized, compliant, and proceduralized; (3) By using a format verification process, the generated digital calibration certificate meets IT requirements; (4) Digital certificates are provided to calibration institutions, calibrators, auditors, and approvers, and digital certificates are used to digitally sign DCCs, and a trusted timestamp is added to the content of DCCs to ensure that the data content is complete and tamper-proof, and to ensure that the identity and data of the DCCs provided are trustworthy; (5) A certificate management unit is added, and compliant DCCs all have a unique DOI number to ensure that DCCs are discoverable and obtainable; the machine-readable and operable syntax compliance of DCCs is verified to achieve their operability and reusability, and to meet the FAIR principle.
[0170] Example 2
[0171] Figure 2 is an exemplary flowchart of a digital calibration certificate generation and verification method based on a microservices architecture, according to some embodiments of this specification. As shown in Figure 2, the process includes the following steps. In some embodiments, the process may be executed by a processor.
[0172] S1, Obtain the digital calibration certificate content information. More details regarding the digital calibration certificate content information can be found in Figure 1 and its related description.
[0173] S2, Based on the information in the digital calibration certificate, obtain calibration business data. More details regarding the calibration business data can be found in Figure 1 and its related description.
[0174] S3 generates a digital signature and a trusted timestamp. More details about the digital signature and trusted timestamp can be found in Figure 1 and its related description.
[0175] S4. Based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp, a digital calibration certificate is generated; the digital calibration certificate is verified to obtain the digital calibration certificate generation verification result. More details regarding the digital calibration certificate generation verification result can be found in Figure 1 and its related description.
Claims
1. A digital calibration certificate generation and verification system based on a microservice architecture, characterized in that, include: The user subsystem is used to obtain information about the digital calibration certificate content. Transmit digital calibration certificates to users and generate verification results; The service subsystem is used to provide access services; Based on the information contained in the digital calibration certificate, calibration business data is obtained; The processing subsystem is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp. The digital calibration certificate is verified to obtain the digital calibration certificate generation verification result; A digital security subsystem is used to authenticate the user subsystem through the service subsystem; Provide digital signatures and trusted timestamps for the processing subsystem; The storage subsystem is used to store information and data during the processing. Provide corresponding information and data for the processing subsystem.
2. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 1, characterized in that, The user subsystem includes: The terminal module is used to obtain the content information of the digital calibration certificate through the terminal device; The server module is used to transmit the content information of the digital calibration certificate to the service subsystem.
3. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 1, characterized in that, The service subsystem includes: The network service module is used to provide users with access services for generating the verification system; The digital calibration service module is used to collect calibration service data based on the content information of the digital calibration certificate through the time-frequency calibration service and the length calibration service.
4. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 1, characterized in that, The processing subsystem includes: The interface module is used to configure security mechanisms and connect the service subsystem with the business module and the basic management module. The business module is used to generate a digital calibration certificate based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp. The basic management module is used to verify the digital calibration certificate and obtain the digital calibration certificate generation verification result; The configuration module is used to configure and manage the business modules and basic modules.
5. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 4, characterized in that, The business module includes: The module management unit is used to obtain the corresponding digital calibration certificate template based on the metrology standards in the professional field; The generation unit is used to generate a digital calibration certificate based on the digital calibration certificate template, the digital calibration certificate content information, and the calibration business data; The security management unit is used to digitally sign and timestamp digital calibration certificates to obtain securely managed digital calibration certificates. The verification unit is used to perform format, syntax, and security verification on the digital calibration certificate of the security management system to obtain the final digital calibration certificate.
6. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 4, characterized in that, The basic management module includes: The certificate management unit is used to update, query, and publish the version of the digital calibration certificate and its corresponding digital unit system based on the digital calibration certificate. The access control unit is used to provide users in the system with registration, access control, and authentication management services. The verification calculation unit is used to utilize verification calculation tools, based on metrological standards, professional terminology, and verification codes, to provide corresponding calibration calculation functions, verify the digital calibration certificate, and obtain the digital calibration result. Certificate verification results generated; The identification management unit is used to generate an organization name identifier and a digital object identifier based on the verified digital calibration certificate, thereby enabling the registration of the digital calibration certificate; The vocabulary management unit is used to provide metrological standards, technical terms, and verification codes to enable the generation and verification process of digital calibration certificates.
7. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 4, characterized in that, The configuration module includes: The configuration unit is used to provide information configuration services for the business module and the basic management module. The log management unit is used to manage the logs generated in the business module and the basic management module; The registration and discovery unit is used to provide registration and discovery components for the business modules and basic management modules, and to dynamically schedule the modules based on the current application scale. The microservice unit is used to visualize the business modules and basic management modules; and to manage the generated digital calibration certificates.
8. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 2, characterized in that, The digital security subsystem includes: A digital identity module is used to provide digital identity information to the terminal module and the server module; The digital signature module is used to generate digital signatures using cryptographic devices; The trusted timestamp module is used to generate trusted timestamps using a timestamp server.
9. The digital calibration certificate generation and verification system based on a microservice architecture according to claim 1, characterized in that, The storage subsystem includes: The user information storage module is used to store user, authentication, and management information. The certificate information storage module is used to store digital calibration certificate files, signatures, timestamps, and process numbers. According to and managing data; The key information storage module is used to store digital signatures and their corresponding keys; The data storage module is used to store business data, back-end service data, and process control data.
10. A method for generating and verifying digital calibration certificates based on a microservice architecture, used to execute the digital calibration certificate generation and verification system based on a microservice architecture as described in claims 1-9, characterized in that, include: Obtain the digital calibration certificate information; Based on the information contained in the digital calibration certificate, calibration business data is obtained; Generate digital signatures and trusted timestamps; A digital calibration certificate is generated based on the content information of the digital calibration certificate, the calibration business data, the digital signature, and the trusted timestamp. The digital calibration certificate is verified to obtain the digital calibration certificate generation verification result.
Citation Information
Patent Citations
Big data acquisition and transaction system based on block chain and trusted computing platform
CN109325331A
Credible alliance block chain digital calibration certificate system and operation method thereof
CN111352998A
Service system of multiple digital certificate authentication mechanisms
CN111831996A
Digital certificate generation method, identity authentication method, quantum CA authentication center and quantum CA authentication system
CN114254284A
Trusted time network calibration system and trusted time digital service
CN115766236A