Second-generation ID card online inquiry system and method based on secure network
Technical field
The present invention relates to a kind of system and method based on the China second-generation identity card information inquiry, specifically, what relate to is a kind of system and method that carries out the information inquiry relevant with identity based on secure network and electronic identity on the China second-generation identity card.
Background technology
Identity card is the legal personalized identity documents of country.Technically; used first generation resident identification card scientific and technological content for many years lower; accreditation technology is more loaded down with trivial details; it is long that system is sent out the cycle; it is relatively poor to make quality and anti-counterfeiting performance, very easily is forged, alters, and causes the problem of utilizing the false identity card and the card that claims the identity of others fraudulently to break laws and commit crime to become increasingly conspicuous; directly endanger social security and economic order, also be unfavorable for protecting simultaneously citizen's legitimate rights and interests.And first generation resident identification card belongs to traditional looking and reads certificate, generally can only be with visual verification directly perceived, be difficult to differentiate the true and false of certificate and carry out people, card establishing identity, cause examination, verification means to lag behind, also can't be used for network and real-time information monitoring and management, both be unfavorable for certificate management, and also be unfavorable for every social management, the society that has seriously restricted this legal certificate of resident identification card uses.
Based on this situation, " the residential identity demonstration " at second generation identity card passed through in the tenth Standing Committee of the National People's Congress's third session June in 2003, and arises from the formal execution in the whole nation on January 1st, 2004.Second generation resident identification card is through for many years investigation and technological demonstration, adopted ripe electronic technology, make certificate possess the possibility that machine is read check and the inquiry of computer networking real-time verification, therefore can adapt to the development trend of modernization of the country, informatization.The formal implementation of second generation identity card indicates the further perfect of resident identification card system, and modern economy social population dynamic management level is improved, simultaneously also be to residence registration system reform, replenish and perfect.
Second generation identity card has adopted electronic technology, cryptographic technique and contact type intelligent card technology comprehensively, make all information stores, checking, inquiry to carry out, provide good basis for the digitlization identity information service of omnibearing Mobile Online is provided in digitized mode.But it seems that at present the application present situation of Certification of Second Generation is but also pessimistic.Subject matter is embodied in following several aspect:
1, still can normally be distinguished by the China second-generation identity card after reporting the loss by existing identity card recognition facility, do not have supporting online database to lose efficacy or other relevant states with online verification system prompt identity card, all kinds of crimes such as financial swindling that take place because of the identity card of losing happen occasionally;
2, lack the safe mobile inquiry mechanism and support, on the airport, sensitizing ranges such as station and hotel can't bring into play the authentication and the management function of resident identification card, can't effectively carry out floating population's tracking;
3, do not have supporting database technology and online support technology, can't obtain more identity and relevant information from linked database.
Chinese patent application number is that " to share the system and method that SAM_V realizes the China second-generation identity card online reading " also be a kind of identity information verification system and method that is used for China second-generation identity card for 200510032961 patent.This patent has been set forth a kind of by the long-range deciphering identity card of networking mode enciphered message, and the technology that displays it.See also Fig. 1, be to show existing Certification of Second Generation inquiry system block diagram, its technical characterstic is as shown in the figure, the SAM_V decoder module is separated with the identity card card reader, connect SAM_V decoder module and identity card card reader by network, the crypto identity card message transmission of card reader being read by network is to the SAM_V decoder module and decode, and decoded information is returned the terminal that links to each other with card reader by network delivery and shown.This method has solved because the SAM_V volume is big, the cost of price high reading facility that cause and use limitation.But this system and method is not considered the danger of the enterprising line data transmission of network on the one hand, does not make up safety chain between SAM_V module and verification terminal, has caused huge security breaches; Only the identity information on the card is gathered and shown on the other hand, do not carry out online comparison and verify and inquire about, can't solve the handling problem after identity card is reported the loss; The 3rd, lack the support of relevant online database technology, identity information can not be combined with other information with the identity hook, can not help the inquirer to carry out comprehensive judgement.
In view of this, how to provide a kind of second-generation ID card online inquiry system and method, reduce above-mentioned drawback and become the technical problem that industry needs to be resolved hurrily based on secure network.
Summary of the invention
A purpose of the present invention is to provide a kind of second-generation ID card online inquiry system and method based on secure network, realization is to remote decoder, checking and the inquiry of China second-generation identity card information, and guarantee the reliable believable transmission of these information by secure network, solved the problem that the service of omnibearing Mobile Online is provided and uses for China second-generation identity card.
In order to achieve the above object, the invention provides a kind of second-generation ID card online inquiry system based on secure network, comprise: at line service end, secure network link module, ID card verification and right management server and identity-related information database, wherein, describedly can operate query task at the line service end, comprise reading, encryption, and the transmission of China second-generation identity card essential information, and the obtaining and show of inquiry feedback data; Described secure network link module be described between line service end and described ID card verification and right management server, the data of transmitting on all links are encrypted, its based on network can be cable network, wireless network and, the mobile network, comprise 2G, 2.5G, 3G and later other networks and other any networks that can finish data communication function, can use SSL or VPN or other link encryption technology that link is encrypted, ensure safety of data on the link; Described ID card verification and right management server provide the checking of identity card essential information, rights management, reach the feedback data management service; Described identity-related information database refers to be used for the data message storehouse of store various types and personal identification related data, comprise a series of information databases that produce based on the social identity of individual such as public security is pursued and captured an escaped prisoner, academic diplomas, bank credit, these databases will read for described ID card verification and right management server as feedback data, can be the databases of Local or Remote.
In specific embodiment, describedly comprise: move many interfaces read module, safe encryption and decryption module, and terminating machine at the line service end, wherein, described many interfaces read module that moves can be read described China second-generation identity card essential information, and have the interface that can be connected with described terminating machine, can pass through USB, bluetooth, serial ports, SD interface, and several data communication mode such as software interface be connected with described terminating machine; Described safe encryption and decryption module can be encrypted and the authentication of basic authority the China second-generation identity card essential information, be one and have MicroSD, or MiniSD, or SD, or USB, or the safety means of other mobile terminal interfaces, this equipment may have above-mentioned one or more interface simultaneously, safe encryption and decryption module also may be a software interface module, carrying out function by the systems soft ware that moves on the terminating machine or application software interface with terminating machine is connected, safe encryption and decryption module can be independent data encrypting and deciphering and digital signature work is provided, can realize multiple symmetry and asymmetric cryptography computing; Described terminating machine can be confirmed query task, the obtaining and show of China second-generation identity card essential information transmission, inquiry feedback data, interface such as described terminating machine can move relative program, has bluetooth, serial ports, SD interface, USB or software interface can be connected with safe encryption and decryption module with mobile many interfaces read module, described terminating machine comprises mobile phone, smart mobile phone, computer, embedded device and any equipment that can initiate identity information checking query display.
Wherein, described identity-related information database is connected with ID card verification and right management server by express network, and described express network can be private line network, a kind of based in the VLL network of the Internet or other high-speed secure networks.
The present invention also provides a kind of second-generation ID card online inquiry method based on secure network, comprise step: set up the identity-related information database, this database storage has the details relevant with personal identification, comprise a series of information databases that produce based on the social identity of individual such as public security is pursued and captured an escaped prisoner, academic diplomas, bank credit, certainly, also can utilize existing Relational database in certain embodiments; The essential information of China second-generation identity card is read out from certificate, and transmit by network through encrypting the back; Confirm inquiry user's identity, information and authority; Data in network transmission process are carried out encryption and decryption; Basic personal information in the China second-generation identity card and user's authority are verified and judged, if legal, then from described identity-related information database, needed certificate details encrypted and return; After encrypting, after Network Transmission, the certificate details of returning are shown.Also comprise step: after China second-generation identity card essential information and the checking of user's authority process and judging,, then return information if illegal.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, uses many interfacings, and the assurance system can be at all kinds of terminating machines, comprise on mobile and the fixed terminal and using, expanded the scope of application of system greatly.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, introducing secure network mechanism, by user's authority being managed and the sensitive information relevant with identity being encrypted, guaranteed the fail safe of system, the information that prevented is stolen and abuses.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement is that also wide area network, local area network (LAN), industry control network or other data transmission technologies based on cable network or wireless network or mobile communications network adopted in the communication between terminating machine and ID card verification and right management server.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement is that also ID card verification and right management server can provide service to a plurality of terminating machines simultaneously, has realized multi-user's share service device simultaneously.Terminating machine and move many interfaces read module and need not built-in all functions module in this locality, checking, inquiry, the decipher function that can use ID card verification and right management server to provide by network remote.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, based on unique China second-generation identity card essential information, ID card verification and right management server can obtain other certificate details relevant with the certificate essential information from the identity-related information database, and it is sent back to terminating machine by the secure network link.
Therefore, a kind of second-generation ID card online inquiry system of the present invention based on secure network, mainly have the following advantages: can realize telesecurity transmission, checking and inquiry to China second-generation identity card information, and guarantee the reliable believable transmission of these information by secure network, the problem that how provides the omnibearing Mobile Online to use for China second-generation identity card has been provided.
Description of drawings
Fig. 1 is existing China second-generation identity card inquiry system block diagram;
Fig. 2 is the second-generation ID card online inquiry system block diagram based on secure network of the present invention.
Embodiment
Below by specific instantiation explanation embodiments of the present invention, those skilled in the art can understand other advantages of the present invention and effect easily by the content that this specification disclosed.The present invention also can be implemented or used by other different instantiations, and the every details in this specification also can be based on different viewpoints and application, carries out various modifications and change under the purpose of the present invention not deviating from.
A kind of second-generation ID card online inquiry system of the present invention based on secure network, see also Fig. 2, it is the second-generation ID card online inquiry system block diagram based on secure network of the present invention, as shown in the figure, the present invention is based on the second-generation ID card online inquiry system of secure network, bag expands mobile many interfaces read module 201, safe encryption and decryption module 202, secure network link module 203, ID card verification and right management server 204 and identity-related information database 205 and terminating machine 206.
Identity card among the figure is the China second-generation identity card that adopts intelligent digital technology and radio-frequency technique to make, and is the reading object of system of the present invention.Move many interfaces read module 201 and finish reading China second-generation identity card digital information by radiofrequency signal.Simultaneously, move many interfaces read module 201, link to each other, can be USB, bluetooth, serial ports, SD interface, reach software interface etc. with terminating machine 206 according to 206 interfaces that can provide of different terminating machines; Terminating machine 206 by and the interface of safe encryption and decryption module 202 couplings link to each other with safety encryption and decryption module 202, above-mentioned three parts are combined to form that Mobile Online is professional holds 200 (or be fixed on the line service end, hereinafter with in the replacement of line service end).
Link to each other with ID card verification and right management server 204 by secure network link module 203 at line service end 200.Secure network link module 203 guarantees the fail safe of the data communication between line service end and ID card verification and right management server 204.ID card verification and right management server 204 and identity-related information database 205 link to each other by express network, and this express network should be private line network, VLL network or any network that can guarantee link safety.May there be one or a plurality of arbitrarily simultaneously in identity-related information database 205, with ID card verification and right management server 204 may be in the same place or be distributed in different zones.
Described at line service end 200, comprise and move many interfaces read module 201, safe encryption and decryption module 202 and terminating machine 206.Its effect is to finish part relevant with the operator in the practical business flow process, comprises the obtaining and show of authentication, inquiry feedback data of the encryption of reading, identity information of affirmation, the ID card information of task and transmission, identity and authority.Many interfaces read module 201 in its part is the readings that are used to finish China second-generation identity card, safe encryption and decryption module 202 is to be used to finish the encryption of identity information and identity and purview certification, terminating machine 206 is as the carrier of practical operation, the obtaining and demonstration work of the affirmation of finishing the work, the transmission of identity information, inquiry feedback data.
Described many interfaces read module 201 comprises China second-generation identity card reading submodule and interface sub-module two big parts.China second-generation identity card is read submodule and is obtained the digital information of storing on the China second-generation identity card by radio-frequency channel.Interface sub-module is a module that comprises a plurality of or single outbound data interface, is used for carrying out data communication with terminating machine 206.
Described safe encryption and decryption module 202, be one and can be used in the independently digital system of data encrypting and deciphering, it can link to each other with terminating machine by MicroSD or USB or other data-interfaces, and the while can be finished the data encrypting and deciphering and the digital certificate functionality of terminating machine requirement.
Described terminating machine 206, being one can carry out alternately the intelligence system of concurrent identity Information Authentication query requests with the user.Can be smart mobile phone, PDA, computer, notebook computer or other can be finished the embedded system of this type of function.
But embedded system mentioned above be application-centered, based on computer technology, hardware and software cutting, adapt to the dedicated computer system that application system is strict with function, reliability, cost, volume, power consumption, be software and the combining of hardware, also contain relevant mechanical auxiliary equipment.
Described secure network link module 203, consult to generate by hardware and software part that terminating machine 206 and ID card verification and right management server 204 are comprised, can encrypt the data of transmitting on all links, can adopt symmetry and asymmetric encryption techniques.Secure network link module 203 guarantee all data in transmission over networks through encryption, avoided divulging a secret of identity information.
Described ID card verification and right management server 204 are the servers that are used for identity information checking and rights management.The request that ID card verification and right management server 204 are responsible for terminating machine 206 is sended over responds, and after confirming identity and authority, finishes decoding and checking to relevant identity information.If desired other identity and personal information are inquired about, then carry out data with identity-related information database 205 and link up by ID card verification and right management server 204.All terminating machine 206 needed data all will be sent to terminating machine by secure network link module 203.
Described identity-related information database 205 is used to store or obtains identity several people information data.Identity-related information database 205 is connected with ID card verification and right management server 204 by express network.This express network should be private line network, VLL network or any network that can guarantee link safety.When ID card verification and right management server 204 transmission identity and personal information request of data, 205 pairs of requests of identity-related information database respond, and send the data to ID card verification and right management server 204.
The application of native system is contained from ID card information and is read, to the obtaining of identity associated encryption data, return, show, function such as reading, realized the information inquiry of Mobile Online's remote live and obtained.
The said system of just utilizing present embodiment realizes online query method of the present invention, comprises the steps:
Set up identity-related information database 205, this database storage has the details relevant with personal identification, comprise a series of information databases that produce based on the social identity of individual such as public security is pursued and captured an escaped prisoner, academic diplomas, bank credit, certainly, also can utilize the existing Relational database of having set up in certain embodiments.With terminating machine 206 and move many interfaces read module 201 and safe encryption and decryption module 202 is formed can have one or a plurality of arbitrarily simultaneously at line service end 200.These can be in same position with ID card verification and right management server 204 at the line service end, also can be in diverse position.These are in being connected with ID card verification and right management server 204 by data link such as 3G network, cable network, wireless networks at the line service end of diverse location.When under the operation of line service end 200 the operator, finished after the reading of China second-generation identity card essential information, information will be encrypted by safety encryption and decryption module 202, and be transferred to ID card verification and right management server 204 by secure network link module 203, during carry out encrypted transmission.Simultaneously, ID card verification and right management server 204 will be verified and judge user identity, authority, ID card information, finally, if it is legal to operate, then Xiang Guan details are with encrypted processing and return to terminating machine 206, and display result or finish other follow-up feature operation as requested; If illegal, then return information.
May there be one or a plurality of arbitrarily simultaneously in identity-related information database 205, and they are connected with ID card verification and right management server 204 by express network.This express network should be private line network, VLL network or any network that can guarantee link safety.When ID card verification and right management server 204 have been finished authentication, and when obtaining relevant identity and personal information data according to user side request needs, identity-related information database 205 is the request of response server end, and gives server end with relevant feedback information.Server end returns to terminating machine 206 by safety chain module 203 with corresponding information.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, uses many interfacings, and the assurance system can be at all kinds of terminating machines, comprise on mobile and the fixed terminal and using, expanded the scope of application of system greatly.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, introducing secure network mechanism, by the China second-generation identity card authority being managed and the sensitive information relevant with China second-generation identity card being encrypted, guaranteed the fail safe of system, the information that prevented is stolen and abuses.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement is that also wide area network, local area network (LAN), industry control network or other data transmission technologies based on cable network or wireless network or mobile communications network adopted in the communication between terminating machine and ID card verification and right management server.
In sum, a kind of second-generation ID card online inquiry system of the present invention based on secure network, be included in the line service end, the secure network link module, ID card verification and right management server, and identity-related information database, between line service end and checking of card prison and right management server, set up secure network described by the secure network link module, can realize remote decoder to China second-generation identity card information, inquiry and checking, and guarantee the reliable believable transmission of these information by secure network, the problem that how provides the omnibearing Mobile Online to use for China second-generation identity card has been provided.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement is that also ID card verification and right management server can provide service to a plurality of terminating machines simultaneously, has realized multi-user's share service device simultaneously.Terminating machine and move many interfaces read module and need not built-in all functions module in this locality, checking, inquiry, the decipher function that can use ID card verification and right management server to provide by network remote.
The present invention is based on the China second-generation identity card online information inquiry system and the method for secure network, its further improvement also is, based on unique China second-generation identity card essential information, ID card verification and right management server can obtain other China second-generation identity card details relevant with the China second-generation identity card essential information from the identity-related information database, and it is sent back to terminating machine by the secure network link.
The above-mentioned description to embodiment is can understand and use the present invention for ease of those skilled in the art.The person skilled in the art obviously can make various modifications to these embodiment soon, and needn't pass through performing creative labour being applied in the General Principle of this explanation among other embodiment.Therefore, the invention is not restricted to the embodiment here, those skilled in the art should be within protection scope of the present invention for improvement and modification that the present invention makes according to announcement of the present invention.