WO2020244235A1 - 离线图形码的处理、生成方法及装置 - Google Patents
离线图形码的处理、生成方法及装置 Download PDFInfo
- Publication number
- WO2020244235A1 WO2020244235A1 PCT/CN2020/071283 CN2020071283W WO2020244235A1 WO 2020244235 A1 WO2020244235 A1 WO 2020244235A1 CN 2020071283 W CN2020071283 W CN 2020071283W WO 2020244235 A1 WO2020244235 A1 WO 2020244235A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- code
- service
- identity information
- identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3274—Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K7/00—Methods or arrangements for sensing record carriers, e.g. for reading patterns
- G06K7/10—Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation
- G06K7/14—Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation using light without selection of wavelength, e.g. sensing reflected white light
- G06K7/1404—Methods for optical code recognition
- G06K7/1408—Methods for optical code recognition the method being specifically adapted for the type of code
- G06K7/1417—2D bar codes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/10—Services
- G06Q50/20—Education
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/30—Writer recognition; Reading and verifying signatures
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/20—Individual registration on entry or exit involving the use of a pass
- G07C9/27—Individual registration on entry or exit involving the use of a pass with central registration
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07G—REGISTERING THE RECEIPT OF CASH, VALUABLES, OR TOKENS
- G07G1/00—Cash registers
- G07G1/12—Cash registers electronically operated
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0618—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/77—Graphical identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0407—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
Definitions
- This application relates to the technical field of graphic codes, and in particular to a method and device for processing and generating offline graphic codes.
- graphic codes such as two-dimensional codes and barcodes have been widely used in various fields, such as payment and access control fields.
- offline graphic codes that can be generated offline by graphic code display devices and verified offline by scanning devices have begun to spread in various fields. application. For example, consumption scenarios such as subway entry and exit scan codes, campus canteens, convenience stores, and bathhouses.
- the purpose of the embodiments of this specification is to provide a method and device for processing and generating offline graphic codes. At least one identity information of a user and business authority information of multiple services are added to the generated offline graphic code, that is, the user uses the
- the offline graphic code can perform multiple business operations; in this way, when users need to use the offline graphic code in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether the offline graphic code is There is identity information recognized by the service acceptor of the code scanning device, and whether there is service authority information for the service supported by the code scanning device, and then based on the inspection result, it is determined whether the user has the authority to execute the corresponding service of the code scanning device; Assigning multiple service permissions to an offline graphic code avoids the need to open different offline graphic codes every time you need to use offline graphic codes to perform different services in different scenarios, which not only increases the utilization of offline graphic codes, but also It brings great convenience to users.
- the embodiment of this specification provides an offline graphic code processing method, which is applied to a code scanning device, and the method includes:
- the signature information in the scan code information obtained by scanning the user's offline graphic code is verified; wherein the scan code information includes: the signature information, at least one identity information of the user, and services of multiple services Permission information;
- the signature information is verified, it is checked whether there is identity information recognized by the service acceptor corresponding to the scanning device in the scanning information, and whether the scanning code exists in the scanning information Business authority information of the business supported by the device;
- the embodiment of this specification also provides a method for generating offline graphic codes, including:
- a code value corresponding to the offline graphic code is generated.
- the embodiment of this specification also provides an offline graphic code processing device, which is applied to a code scanning device, and the device includes:
- the verification module is used to verify the signature information in the scan code information obtained by scanning the user's offline graphic code; wherein the scan code information includes: the signature information and at least one identity information of the user, And business authority information for multiple businesses;
- the verification module is configured to, if the signature information is verified, verify whether there is identity information recognized by the service accepting party corresponding to the code scanning device in the code scanning information, and check whether the code scanning information includes There is service authority information of the service supported by the code scanning device;
- the determining module is configured to determine that the user is capable of executing the code scanning device corresponding to the identity information recognized by the service acceptor corresponding to the code scanning device and the service authority information of the service supported by the code scanning device Business authority.
- the embodiment of this specification also provides an offline graphic code generation device, the device includes:
- the obtaining module is used to obtain at least one identity information of a user and obtain business authority information of multiple services;
- the generating module is configured to generate the code value corresponding to the offline graphic code based on the at least one identity information and the service authority information of the multiple services.
- the embodiment of this specification also provides an offline graphic code processing device, which is applied to a code scanning device, including:
- a memory arranged to store computer-executable instructions which, when executed, cause the processor to:
- the signature information in the scan code information obtained by scanning the user's offline graphic code is verified; wherein the scan code information includes: the signature information, at least one identity information of the user, and services of multiple services Permission information;
- the signature information is verified, it is checked whether there is identity information recognized by the service acceptor corresponding to the scanning device in the scanning information, and whether the scanning code exists in the scanning information Business authority information of the business supported by the device;
- the embodiment of this specification also provides an offline graphic code generation device, including:
- a memory arranged to store computer-executable instructions which, when executed, cause the processor to:
- a code value corresponding to the offline graphic code is generated.
- the embodiments of this specification also provide a storage medium for storing computer-executable instructions, which, when executed, implement the following processes:
- the signature information in the scan code information obtained by scanning the user's offline graphic code is verified; wherein the scan code information includes: the signature information, at least one identity information of the user, and services of multiple services Permission information;
- the signature information is verified, it is checked whether there is identity information recognized by the service acceptor corresponding to the code scanning device in the code scanning information, and whether the code scanning information exists in the code scanning information.
- Business authority information of the supported business
- the embodiments of this specification also provide a storage medium for storing computer-executable instructions, which, when executed, implement the following processes:
- a code value corresponding to the offline graphic code is generated.
- At least one identity information of the user and service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple business operations using the offline graphic code; in this way, when When users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether there is identity information recognized by the business acceptor of the scanning device in the offline graphic code.
- FIG. 1 is one of the method flowcharts of the offline graphic code processing method provided by the embodiment of this specification
- FIG. 3 is the third method flowchart of the offline graphic code processing method provided by the embodiment of this specification.
- FIG. 5 is a schematic flowchart of a processing method for offline graphic codes provided by an embodiment of this specification
- FIG. 6 is one of the method flowcharts of the offline graphic code generation method provided by the embodiment of this specification.
- FIG. 7 is the second method flowchart of the offline graphic code generation method provided by the embodiment of this specification.
- FIG. 8 is a schematic diagram of the module composition of the offline graphic code processing device provided by the embodiment of this specification.
- FIG. 9 is a schematic diagram of the module composition of the offline graphic code generation device provided by the embodiment of the specification.
- Fig. 10 is a schematic structural diagram of an offline graphic code processing device provided by an embodiment of this specification.
- the idea of the embodiment of this specification is to add at least one identity information of the user and the service authority information of multiple services to the same offline graphic code.
- the same offline graphic code can be used, which avoids the need for users to open different offline graphic codes in different scenarios, which improves the utilization of offline graphic codes and brings great convenience to users.
- the embodiments of this specification provide an offline graphic code processing and generating method, device, equipment and storage medium. The following will introduce in detail one by one.
- the embodiment of this specification provides an offline graphic code processing method, which is applied to a code scanning device, that is, the execution body of the method is the code scanning device, specifically, the offline graphic code installed on the scanning device ⁇ Processing device.
- the offline graphic code mentioned in the embodiments of this specification generally refers to the graphic code generated by the graphic code generating device (which can be a graphic code display device) in an offline environment, and the scanning device scans the graphic code in the offline environment. Perform verification.
- the offline graphic codes mentioned in the embodiments of this specification may be offline two-dimensional codes, offline barcodes, etc., and offline two-dimensional codes such as common square two-dimensional codes and circular two-dimensional codes.
- the offline graphic code also includes other codes for displaying and scanning codes, which will not be repeated here.
- FIG. 1 is one of the method flowcharts of the offline graphics code processing method provided by the embodiment of this specification.
- the method shown in FIG. 1 at least includes the following steps:
- Step 102 Verify the signature information in the scan code information obtained by scanning the user's offline graphic code; where the scan code information includes: signature information, at least one identity information of the user, and business permissions for multiple services information.
- the user opens the offline graphic code that needs to be used currently through the graphic code display device (the graphic code display device can be a mobile phone, tablet computer, etc.), and places the opened offline graphic code in the scan code window of the scanning device Area, so that the scanning device scans the offline graphic code, so as to obtain the scanning information corresponding to the offline graphic code.
- the graphic code display device can be a mobile phone, tablet computer, etc.
- the scan code information may be information obtained by analyzing the scanned offline code graphic code, and may include signature information, at least one identity information of the user, service authority information of multiple services, etc., and may also include the time of scanning the code. Information etc.
- At least one identity information of the same user is set in an offline graphic code.
- the identity information can be the identity information of the user in different scenarios. For example, for the same user, it can be either A student of a school, an employee of a company, or even a resident of a certain community, for the user, the student identity information, company employee identity information, and community resident information can all be added to the offline graphic code.
- the user's identity information and the business authority information of the authorized service can be set in the offline graphic code according to the actual application scenario.
- one user's identity information and service authority information of multiple services can be added to the offline graphic code, and multiple identity information of the user and multiple business services can also be added to the offline graphic code. Permission information.
- the verification of the signature information in the scan information includes: verification of the issuing authority, verification of user information, verification of the validity period of the offline graphic code, etc. Wait.
- the offline graphic code can be preliminarily verified, so as to eliminate invalid graphic codes that cannot obtain the graphic code value due to expiration or mismatch with the issuing authority associated with the code scanning device.
- the offline graphic code is scanned, the scanned offline graphic code is analyzed to obtain the code value corresponding to the offline graphic code, and the offline graphic code issuing agency pre-stored in the scanning device is used.
- the public key performs the unsigned processing on the code value of the offline graphic code. If the unsigned is successful, it is determined that the offline graphic code has passed the verification and is based on the generation time information and scan of the offline graphic code obtained after unsigned
- the code time information determines whether the offline graphic code is currently within the validity period, and if so, it is determined that the validity period information of the offline graphic code passes the check. And after the code value of the offline graphic code is unsigned using the public key, all the identity information of the user stored in the offline graphic code is obtained, and the identity information is verified. After the verification is passed, the offline graphic is considered The signature information of the code is verified.
- Step 104 If the verification of the signature information is passed, check whether there is identity information recognized by the service acceptor corresponding to the scanning device in the scanning information, and check whether the scanning information is supported by the scanning device The business authority information of the business.
- the above-mentioned service acceptor is the one that accepts the service corresponding to the code scanning device.
- the service acceptor corresponding to the code scanning device can be a community property; if it is the above-mentioned code scanning device Applied to the school cafeteria, the business acceptor corresponding to the scanning device can be school logistics and so on.
- the above-mentioned code scanning device is applied to the access control of XX cell. After the code scanning device passes the verification of the signature information in the code scanning information obtained by scanning the user’s offline graphic code, then Check whether there is identity information of residents of XX cell in the scan code information (identity information recognized by the property corresponding to the scan code device), and check whether there is service authority information to enter the XX cell in the scan code information.
- Step 106 If there are identity information recognized by the service acceptor corresponding to the code scanning device and service authority information of the service supported by the code scanning device, it is determined that the user has the authority to execute the service corresponding to the code scanning device.
- At least one identity information of the user and service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification. This realizes that multiple business permissions are given to one offline graphic code, avoiding each When you need to use offline graphic codes to perform different services in different scenarios, you need to open different offline graphic codes, which increases the utilization rate of offline graphic codes and also brings great convenience to users.
- step 104 it is checked whether there is identity information recognized by the service accepting party corresponding to the code scanning device in the above code scanning information, which specifically includes the following steps 1 and 2;
- Step 1 Extract the user's identity information from the above-mentioned scan code information
- Step 2 From the extracted identity information, check whether there is identity information recognized by the business accepting party corresponding to the scanning device;
- step 104 it is checked whether there is service authority information of the service supported by the code scanning device in the above code scanning information, which specifically includes the following steps (1) and (2);
- Step (1) Extract business authority information of multiple services from the above-mentioned scan code information
- Step (2) From the extracted service authority information of multiple services, check whether there is service authority information of the service supported by the code scanning device.
- the specific implementation process of checking whether there is service authority information of the service supported by the code scanning device in the above-mentioned code scanning information please refer to the specific process of checking identity information, which will not be repeated here.
- the identity information supported by the scanning device and the business authority information of the business are stored in the scanning device.
- the scanning device supports students from XX school to perform payment operations, and the corresponding business information is XX, etc. . Therefore, in the specific implementation, after extracting the user’s identity information from the code scanning information, look for the identity information that matches the identity information stored in the code scanning device from the extracted identity information. If it exists, It is further checked whether the extracted service authority information contains the service authority information of the service supported by the code scanning device, and if it exists, it is considered that the user has the authority to execute the service corresponding to the code scanning device.
- Zhang San is both a student of a certain school and a resident of a certain apartment, and the identity information of Zhang San set in the offline graphic code is as follows:
- the business authority information of the business set in the offline graphic code is as follows:
- Authority 1 Payment-Business acceptor ID: 2088111122223333; Authority 2: Verification-Business acceptor ID: 2088111122223333; Authority 3: Verification-Business acceptor ID: 2088222233335555.
- Zhang San consumes in the school supermarket he opens the offline graphic code through the graphic code display device, and scans the offline graphic code by the scanning device set up in the school supermarket.
- the scanning device scans the offline graphic code, first The offline graphic code is analyzed to obtain the code value corresponding to the offline graphic code, and the offline graphic code is signed and verified based on the code value. After the signature verification is passed, the user is extracted from the code value corresponding to the offline graphic code Since the scanning device only supports the consumption of students, faculty and staff of the school, it is necessary to find out whether there is any identity information of the students, faculty and staff of the school in the above-mentioned various identification information, and determine the identity by searching The information contains the identity of the student of the XX school.
- the extracted identity information may contain identity information recognized by the business accepting party corresponding to the scanning device.
- the code value corresponding to the offline graphic code multiple types of authority information corresponding to the offline graphic code are extracted, and the service supported by the code scanning device and the corresponding service acceptor ( Here is the merchant) information.
- the offline graphic code is given the authority to make payment to the merchant 2088111122223333. Therefore, it is considered that the user has the ability to perform payment operations on the code scanning device to perform the corresponding payment operations.
- Zhang San when Zhang San needs to swipe his card to enter the talent apartment where he lives, he uses the graphic code display device he carries to display the offline graphic code required for verification, and scans the offline graphic through the code scanning device set in the talent apartment Code, when the scanning device scans the offline graphic code, the offline graphic code is parsed to obtain the code value corresponding to the offline graphic code, and the offline graphic code is signed and verified based on the code value. Then, extract the user’s individual identity information from the code value corresponding to the offline graphic code, and find out whether there is the identity information of the talent apartment resident in the extracted identity information.
- Zhang San is room 6265 of the talent apartment Afterwards, extract the authority information corresponding to the offline graphic code from the code value corresponding to the above-mentioned offline graphic code, and find out whether the extracted authority information has the authority to enter the talent apartment. After searching, it is found The offline graphic code has the permission to enter the talent apartment, therefore, it is believed that Zhang San has the permission to enter the talent apartment through the scanning device.
- extracting the user's identity information from the scan code information in the above step 1 specifically includes:
- the code value corresponding to the offline graphic code is generated, various information fields are correspondingly set, such as user identity information field, business authority information field, random number field, etc., and each field is generally set at a fixed position.
- the user identity information field is ranked at position 1
- the service authority information field is ranked at position 2
- the random number field is ranked at position 3, and so on. Therefore, when extracting at least one identity information of the user, the position of the identity information field can be determined based on the position information corresponding to each information field in the code value generation rule, so as to extract the user identity information field from the code value.
- the identity information field in the offline graphic code includes identity information subfield 1 and identity information subfield 2.
- Identity information subfield 1 corresponds to user A's identity 1
- identity information subfield 2 corresponds to user A's identity 2. Therefore, a specific form of the identity information field is as follows:
- Identity 1 XX school student-student number-name-school ID
- identity 2 XX community resident-building number, unit, room number-name-community ID.
- the identity information corresponding to each of the above information subfields is extracted separately as the user's identity information.
- Fig. 2 is the second method flowchart of the offline graphic code processing method provided by the embodiment of this specification.
- the method shown in Fig. 2 at least includes the following steps:
- Step 202 Verify the signature information in the scan code information obtained by scanning the user's offline graphic code.
- Step 204 If the verification of the signature information is passed, extract the identity information field in the scan code information.
- Step 206 Extract the identity information subfield from the above identity information field; wherein, one identity information subfield corresponds to one identity information of the user.
- Step 208 Check whether there is any identity information recognized by the service accepting party corresponding to the code scanning device in the above-mentioned identity information; if so, proceed to step 210, otherwise, end.
- Step 210 Extract service authority information of multiple services corresponding to the offline graphic code from the foregoing code scanning information.
- Step 212 from the multiple service authority information extracted above, it is checked whether there is service authority information of the service supported by the code scanning device; if it exists, step 214 is executed, otherwise, it ends.
- Step 214 Determine that the user has the authority to execute the service corresponding to the code scanning device.
- the embodiment corresponding to Figure 2 is only one of the specific implementations.
- the verification steps can also be performed after extracting the identity information and the business authority information of multiple services; of course, you can also follow the figure
- the step of verifying the identity information is first performed; after the identity information is verified, the business authority information is extracted, and the step of verifying the business authority information is performed; both implementation methods are available,
- the embodiments of this specification do not limit this.
- extracting the service authority information of multiple services from the code scanning information specifically includes: extracting the service authority information field from the code scanning information; and extracting multiple service authority information fields from the above code scanning information.
- Permission information subfield; among them, one permission information subfield corresponds to the business permission information of a business.
- the user can either use the offline graphic code to consume in the school cafeteria, or use the offline graphic code for identity verification to enter the student apartment. Therefore, the authority
- One possible form of the information field is as follows:
- Authority 1 Payment-business acceptor ID: 2088111122223333; authority 2: verification-business acceptor ID: 2088222233335555.
- the business acceptor identifier is used to identify the business acceptor where the offline graphic code has the ability to execute the business.
- the business acceptor may be a certain merchant, a certain residential property, a certain management department, and so on.
- the business authority information corresponding to each authority information subfield is extracted as the business authority information corresponding to the offline graphic code.
- FIG. 3 is the third method flowchart of the offline graphics code processing method provided by the embodiment of this specification.
- the method shown in FIG. 3 includes at least the following steps:
- Step 302 Verify the signature information in the scan code information obtained by scanning the user's offline graphic code.
- Step 304 If the signature information passes the verification, extract the identity information field in the scan code information.
- Step 306 Extract the identity information subfield from the above identity information field; wherein, one identity information subfield corresponds to one identity information of the user.
- Step 308 from the extracted identity information, check whether there is identity information recognized by the service accepting party corresponding to the code scanning device; if so, perform step 310; otherwise, end.
- Step 310 Extract the service authority information field in the code scanning information.
- Step 312 Extract multiple permission information subfields from the above-mentioned service permission information field; among them, one permission information subfield corresponds to service permission information of a service.
- Step 314 from the extracted service authority information of multiple services, check whether there is service authority information of the service supported by the code scanning device; if so, proceed to step 316; otherwise, end.
- Step 316 Determine that the user has the authority to execute the service corresponding to the code scanning device.
- the identity information and business authority verification can be performed, or after extracting the user’s identity information, the user’s identity information can be verified first. Then extract the business authority information, and then verify the business authority information.
- the embodiments of this specification do not limit the execution sequence of the foregoing specific processes.
- the identity information field of the offline graphic code is divided into multiple identity information subfields, and one identity information of the user is added to each identity information subfield.
- the user s multiple identity information
- the business authority information field is divided into multiple authority information subfields, and one authority information subfield corresponds to the business authority information of a business in the offline graphic code. In this way, this can be added to the offline graphic code.
- Multiple service authority information of the offline graphic code so that users can use the same offline graphic code to perform corresponding services in multiple scenarios, avoiding opening different offline graphic codes through different channels in different scenarios, which is convenient
- the user’s actions are possible to add the identity information to the offline graphic code.
- the service authority information of the above-mentioned service includes at least: the service supported by the code scanning device and the service acceptor information corresponding to the service;
- the aforementioned identity information includes at least: the user's name, identity identification information, and application scenario area information.
- the above business can be payment, verification, etc.; if the business is a payment business, the business acceptor information can be the merchant information corresponding to the payment business, and if the business is a verification business, the business acceptor information can be The unit information corresponding to the verification business, such as company information, community property information, library management department, etc.
- the service authority information of the above-mentioned service may be: payment-service acceptor identification: 2088111122223333.
- the company since there may be multiple business acceptors with the same business, for example, the company needs to set up access control to verify the identity of the personnel entering the company, and the library needs to set the access control to verify the identity of the personnel entering the library.
- the cell needs to set up access control to verify the identity of the personnel entering the cell. Therefore, in order to distinguish whether the service corresponding to the offline graphic code matches the service supported by the code scanning device, it is necessary to add the service corresponding to the service authority information Business acceptor identification.
- the aforementioned identity information may include the user's name, identity identification information, and application scenario area information.
- the application scenario area information may be the unit or activity place corresponding to the identity information, such as XX school, XX school library, XX company, XX community, etc.
- the aforementioned identity information can be identity name information or a string of identity information.
- the aforementioned identity information may be: Zhang San-student-student number-XX school.
- each part of the identity information can be coded, and a preset code can be used to replace the specific information content.
- the set encoding information is shown in Table 1.
- the above Table 1 is the code corresponding to the identification information of school students and teachers.
- the student identification information may include school name, student name, and grade information.
- the student identification information A possible format of the corresponding code may be: school name corresponds to 8 bytes, student corresponds to 4 bytes, and grade corresponds to 2 bytes, and the student identification information code can be generated based on this rule each time.
- Teacher identity information can generally include school name, teacher name, and job title.
- a possible format of the code corresponding to teacher identity information can be: school name corresponds to 8 bytes, teacher name corresponds to 4 Each byte and title correspond to 2 bytes, and the teacher identification information code can be generated based on this rule each time.
- the above code when setting the user’s identity information, can be added as the user’s identity information at a specified position in the identity information subfield, for example, at the beginning of each identity information subfield. Add identification information encoding.
- the identity information can be checked before adding the identity information to the offline graphic code. Encryption, so that the identity information is set in the offline graphic code in the form of identity ciphertext information, and during the transmission of the offline graphic code, the identity information is in the form of identity information ciphertext, ensuring the identity information Security.
- a symmetric encryption algorithm may be used to encrypt the identity information that needs to be encrypted.
- user identity information can be represented by characters.
- the original data of user identity information is 0000000100001111.
- the cipher text information obtained is 0010111100001100. If the user identity information of the user is minimal Teacher, the obtained user identity information subfield is: 000000110010111100001100.
- the code scanning device scans the offline graphic code and parses the offline graphic code to obtain the code value corresponding to the offline graphic code, if it finds the identity ciphertext information in the identity information extracted from it, then The ciphertext information of the identity is decrypted. Therefore, in the embodiment of this specification, before performing the above-mentioned extracted identity information to check whether there is identity information recognized by the service acceptor associated with the code scanning device, the method provided in the embodiment of this specification further includes:
- the key identifier used for encryption can be added to the code value corresponding to the offline graphic code.
- the code scanning device scans the offline graphic code based on The obtained key identification information determines the key information for decoding the identification information.
- the identity information field contains multiple identity information subfields, and one identity information subfield corresponds to one identity information of the user, in specific implementation, only certain identity information of the user can be encrypted.
- FIG. 4 is the fourth method flowchart of the offline graphics code processing method provided by the embodiment of this specification.
- the method shown in FIG. 4 includes at least the following steps:
- Step 402 Verify the signature information in the scan code information obtained by scanning the user's offline graphic code.
- Step 404 If the signature information is verified, extract the identity information field in the scan code information.
- Step 406 Extract the identity information subfield from the above identity information field; wherein, one identity information subfield corresponds to one identity information of the user.
- Step 408 Detect whether there is identity ciphertext information in the above-mentioned identity information; if so, proceed to step 410; otherwise, proceed to step 412.
- Step 410 Decrypt the identity ciphertext information to obtain decrypted identity information.
- Step 412 Check whether there is identity information recognized by the service accepting party associated with the code scanning device in the above-mentioned identity information; if so, proceed to step 414; otherwise, end.
- Step 414 Extract the service authority information field in the code scanning information.
- Step 416 Extract multiple permission information subfields from the above service permission information field; among them, one permission information subfield corresponds to the service permission information of a service.
- Step 418 check whether there is service permission information supported by the code scanning device in the above service permission information; if it exists, go to step 420; otherwise, end.
- Step 420 Determine that the user has the authority to execute the service corresponding to the code scanning device, and execute the service.
- one user's identity information and business authority information of multiple services can be set in the offline graphic code.
- user A is a student of XX school
- user A's student identity information can be added to the offline graphic code, and the offline graphic code is given the authority to consume in the cafeteria and enter the library.
- the following will take user A's consumption in the school cafeteria and entering the school library as an example to introduce the method provided by the embodiment of this manual.
- Fig. 5 is a schematic diagram of the processing flow of the offline graphic code provided by the embodiment of the specification.
- the code device performs the payment operation, and the code scanning device performs the corresponding payment operation; when user A needs to enter the school library, the offline graphic code display device is used to display the offline graphic code, and scan the code through the code scanning device set at the entrance of the library Offline graphic code, and perform signature verification on the offline graphic code based on the scanned code information obtained by scanning. After the signature verification is passed, the identity information in the offline graphic code is extracted, and it is determined that user A is a student of XX school. The identity recognized by the business acceptor associated with the scanning device. After that, extract the business authority information in the offline graphic code, and check whether the extracted business authority information has the authority to enter the library. If it exists, it is considered that user A has the authority to enter the library, and then prompts user A to verify identity Pass, open the door.
- multiple identity information of the user and service authority information of multiple services can also be set in the offline graphic code.
- user A is a student of XX school
- user A’s student identity information can be added to the offline graphic code
- user A is also an employee of XX company
- user A’s employee identity information can be added to the offline graphic code
- the offline graphic code is given the authority to consume in the cafeteria of XX school, enter the library of XX school, and enter XX company. The following will take user A's consumption in the XX school canteen and entering the XX company as an example to introduce the method provided by the embodiment of this specification.
- the offline graphic code display device scans the offline graphic code through the code scanning device set up in the school cafeteria, and signs the offline graphic code based on the scanned code information obtained by scanning Verification: After the signature verification is passed, the identity information in the offline graphic code is extracted to determine that user A is a student of XX school, and therefore, is the identity recognized by the merchant associated with the code scanning device. After that, extract the business authority information in the offline graphic code, and detect whether the extracted business authority information has the business authority to make payments to the XX merchant supported by the code scanning device.
- the code device performs the payment operation, and the code scanning device performs the corresponding payment operation; when user A needs to enter XX company, the offline graphic code display device displays the offline graphic code, and scans the offline code through the code scanning device set at the door of XX company Graphic code, and perform signature verification on the offline graphic code based on the scanned code information obtained by scanning. After the signature verification is passed, the identity information in the offline graphic code is extracted to determine that user A is an employee of XX company. The identity recognized by the company associated with the code device. After that, extract the business authority information in the offline graphic code, and check whether the extracted business authority information has the authority to enter the company. If it exists, it is considered that user A has the authority to enter the XX company, and the user A is prompted to pass the identity verification To open the access control.
- At least one identity information of the user and service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether the offline graphic code has the service acceptance of the scanning device
- Each service authority avoids the need to open different offline graphic codes every time you need to use offline graphic codes to perform different services in different scenarios, which increases the utilization of offline graphic codes and also brings great benefits to users. convenient.
- the embodiment of this specification also provides an offline graphic code generation method, which can be applied to the server side or graphic code
- the display device that is, the execution subject of the method can be a server or a graphic code display device, specifically, an offline graphic code generation device installed on the server or the graphic code display device.
- Fig. 6 is one of the method flowcharts of the offline graphic code generation method provided by the embodiment of this specification. The method shown in Fig. 6 at least includes the following steps:
- Step 602 Obtain at least one identity information of the user, and obtain service authority information of multiple services.
- Step 604 Generate a code value corresponding to the offline graphic code based on the aforementioned at least one identity information and service authority information of multiple services.
- the aforementioned identity information is the identity information recognized by the service accepting party, and the aforementioned service is a service supported by the code scanning device.
- the above identity information and service authority information can be transmitted to the server by the user through the graphic code display device.
- the user can input the identity information and business authority information that need to be added to the offline graphic code through the offline graphic code generation interface displayed on the graphic code display device.
- the server sends the generated code value to the graphic code display device.
- the server may use the organization private key corresponding to the server to sign the at least one identity information, the service authority information of multiple services, and the generated random number to obtain the code value corresponding to the offline graphic code.
- the length of the code value of the generated offline graphic code can be shortened.
- the code value corresponding to the above-mentioned offline graphic code can also be generated on the graphic code display device.
- the identity information and business authority information can be transmitted to the server, so that the server can use its stored private key
- the information and service authority information are signed to obtain the corresponding signature information, and the signature information and the user public key are issued to the graphic code display device, so that the graphic code display device uses its stored user private key to sign the random number , Regard the above signature information, random number signature information and user public key as the code value corresponding to the offline graphic code.
- generating the code value corresponding to the offline graphic code specifically includes:
- the identity information field is generated based on the above identity information
- the business authority information field is generated based on the business authority information of the above business; where one identity information corresponds to an identity information subfield in the identity information field, and the business authority information of a business corresponds to the above business
- a service authority information subfield in the authority information field according to the aforementioned identity information field and the aforementioned service authority information field, a code value corresponding to the offline graphic code is generated.
- identity information there may be some sensitive information in each identity information corresponding to the user, and this information is not convenient for public disclosure. Therefore, when the identity information is added to the offline graphic code, the identity information can be checked. Encryption, so that the identity information is set in the offline graphic code in the form of identity ciphertext information, and during the transmission of the offline graphic code, the identity information is in the form of identity information ciphertext, ensuring the identity information Security.
- the method provided in the embodiment of this specification further includes:
- generating the code value corresponding to the offline graphic code specifically includes:
- the code value corresponding to the aforementioned offline graphic code is generated.
- the user can specify one or several of the identity information that needs to be encrypted, and when the code value corresponding to the offline graphic code is generated, the specified identity information is encrypted, and the obtained identity cipher text information is used , And the remaining identity information and various business authority information to generate the code value corresponding to the offline graphic code.
- the above-mentioned remaining identity information is the identity information excluding the identity information that needs to be encrypted among all the identity information that needs to be added to the offline graphic code.
- only one of the above-mentioned identity information may be encrypted.
- a symmetric encryption algorithm may be used to encrypt the identity information that needs to be encrypted.
- FIG. 7 is the second method flowchart of the offline graphic code generation method provided by the embodiment of this specification. The method shown in FIG. 7 at least includes the following steps:
- Step 702 Obtain at least one identity information of the user, and obtain service authority information of multiple services.
- Step 704 Generate an identity information field based on the above identity information, and generate a business authority information field based on the above business authority information; wherein one identity information corresponds to an identity information subfield in the identity information field, and the business authority information of a business corresponds to the business A service authority information subfield in the authority information field.
- Step 706 Detect whether there is identity information specified by the user for encryption in the obtained identity information; if so, perform step 708;
- Step 708 Encrypt the identity information specified by the user to obtain the identity ciphertext information corresponding to the identity information.
- Step 710 Generate a code value corresponding to the offline graphic code based on the above-mentioned identity ciphertext information, remaining identity information, and service authority information of multiple services.
- Step 712 Send the above code value to the graphic code display device.
- At least one identity information of the user and service authority information of multiple services are added to the generated offline graphic codes, that is, the user can perform multiple services by using the offline graphic codes. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification. This realizes that multiple business permissions are given to one offline graphic code, avoiding each When you need to use offline graphic codes to perform different services in different scenarios, you need to open different offline graphic codes, which increases the utilization rate of offline graphic codes and also brings great convenience to users.
- Fig. 8 is a schematic diagram of the module composition of an offline graphic code processing device provided by an embodiment of this specification.
- the device shown in Fig. 8 includes:
- the verification module 802 is used to verify the signature information in the scan code information obtained by scanning the user's offline graphic code; wherein the scan code information includes: signature information, at least one identity information of the user, and multiple services Business authority information;
- the verification module 804 is configured to, if the signature information is verified, verify whether there is identity information recognized by the service accepting party corresponding to the code scanning device in the code scanning information, and whether there is any identity information supported by the code scanning device in the code scanning information Business authority information of the business;
- the determining module 806 is configured to determine that the user has the authority to execute the service corresponding to the code scanning device if there are identity information recognized by the service acceptor corresponding to the code scanning device and service authority information of the service supported by the code scanning device.
- the aforementioned inspection module 804 includes:
- the first extraction unit is used to extract the user's identity information from the scan code information
- the first checking unit is used to check from the extracted identity information whether there is identity information recognized by the business accepting party corresponding to the code scanning device;
- the second extraction unit is used to extract service authority information of multiple services from the code scanning information
- the second checking unit is used to check whether there is service authority information of the service supported by the code scanning device from the extracted service authority information of multiple services.
- the aforementioned first extraction unit includes:
- the first extraction subunit is used to extract the identity information field from the code scanning information
- the second extraction subunit is used to extract the identity information subfield from the identity information field; wherein, one identity information subfield corresponds to one identity information of the user.
- the above-mentioned second extraction unit further includes:
- the third extraction subunit is used to extract the business authority information field from the code scanning information
- the fourth extraction subunit is used to extract multiple authority information subfields from the service authority information field; among them, one authority information subfield corresponds to the business authority information of one service.
- the service authority information of the above-mentioned service includes at least: the service supported by the code scanning device and the service acceptor information corresponding to the service;
- the identity information includes at least: the user's name, identity identification information, and application scenario area information.
- the above-mentioned inspection module 804 further includes:
- the decryption unit is used to decrypt the identity ciphertext information existing in the identity information to obtain the decrypted identity information.
- the offline graphic code processing device of the embodiment of this specification can also execute the method executed by the offline graphic code processing device in FIGS. 1 to 5, and realize the functions of the offline graphic code processing device in the embodiment shown in FIGS. 1 to 5 , I won’t repeat it here.
- At least one identity information of the user and the service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether the offline graphic code has the service acceptance of the scanning device
- Each service authority avoids the need to open different offline graphic codes every time you need to use offline graphic codes to perform different services in different scenarios, which increases the utilization of offline graphic codes and also brings great benefits to users. convenient.
- Fig. 9 is a schematic diagram of the module composition of the device for generating offline graphic codes provided by an embodiment of this specification.
- the device shown in Fig. 9 includes:
- the obtaining module 902 is used to obtain at least one identity information of the user and obtain business authority information of multiple services;
- the generating module 904 is configured to generate a code value corresponding to the offline graphic code based on at least one identity information and service authority information of multiple services.
- the foregoing generating module 904 includes:
- the first generating unit is used to generate the identity information field based on the identity information, and generate the business authority information field based on the business authority information of the business; wherein, one identity information corresponds to one identity information subfield in the identity information field, and one business business The authority information corresponds to a business authority information subfield in the business authority information field;
- the second generating unit is used to generate the code value corresponding to the offline graphic code according to the identity information field and the service authority information field.
- the device provided in the embodiment of this specification further includes:
- the encryption module is used to encrypt the identity information specified by the user to obtain the identity ciphertext information corresponding to the identity information;
- the aforementioned generating module 904 includes:
- the third generating unit is used to generate the code value corresponding to the offline graphic code based on the identity ciphertext information corresponding to the identity information specified by the user, the remaining identity information and the business authority information of multiple services.
- the offline graphic code generation device of the embodiment of this specification can also execute the method performed by the offline graphic code generation device in FIGS. 6-7, and realize the functions of the offline graphic code generation device in the embodiment shown in FIGS. 6-7 , I won’t repeat it here.
- the offline graphic code generation device provided by the embodiment of this specification, at least one identity information of the user and the service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification. This realizes that multiple business permissions are given to one offline graphic code, avoiding each When you need to use offline graphic codes to perform different services in different scenarios, you need to open different offline graphic codes, which increases the utilization rate of offline graphic codes and also brings great convenience to users.
- an embodiment of this specification also provides an offline graphic code processing device, which is applied to a code scanning device, as shown in FIG. 10.
- the offline graphics code processing equipment may have relatively large differences due to different configurations or performances, and may include one or more processors 1001 and a memory 1002.
- the memory 1002 may store one or more storage applications or data. Among them, the memory 1002 may be short-term storage or persistent storage.
- the application program stored in the memory 1002 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instruction information in the processing device of the offline graphic code.
- the processor 1001 may be configured to communicate with the memory 1002, and execute a series of computer-executable instruction information in the memory 1002 on an offline graphics code processing device.
- the offline graphics code processing equipment may also include one or more power supplies 1003, one or more wired or wireless network interfaces 1004, one or more input and output interfaces 1005, one or more keyboards 1006, and so on.
- the offline graphics code processing device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules , And each module may include a series of computer-executable instruction information in the processing device of the offline graphics code, and is configured to be executed by one or more processors to execute the one or more programs including the following computer executable Command information:
- the computer executable instruction information when executed, it is checked whether there is identity information recognized by the business accepting party corresponding to the code scanning device in the code scanning information, including:
- the user's identity information is extracted from the scan code information, including:
- the service authority information of multiple services is extracted from the code scanning information, including:
- the extracted identity information contains encrypted identity ciphertext information
- the method From the extracted identity information, before checking whether there is identity information recognized by the business acceptor corresponding to the scanning device, the method also includes:
- the service authority information of the service includes at least: the service supported by the code scanning device and the service acceptor information corresponding to the service;
- the identity information includes at least: the user's name, identity identification information, and application scenario area information.
- At least one identity information of the user and service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether the offline graphic code has the service acceptance of the scanning device
- Each service authority avoids the need to open different offline graphic codes every time you need to use offline graphic codes to perform different services in different scenarios, which increases the utilization of offline graphic codes and also brings great benefits to users. convenient.
- an embodiment of this specification also provides an offline graphic code generation device, and its specific structure can refer to the offline graphic code processing device shown in FIG. 10.
- the device for generating offline graphics codes includes a memory and one or more programs, one or more programs are stored in the memory, and one or more programs may include one or more modules , And each module may include a series of computer-executable instruction information in the device for generating offline graphics codes, and is configured to be executed by one or more processors.
- the one or more programs include the following computer-executable Command information:
- a code value corresponding to the offline graphic code is generated.
- the code value corresponding to the offline graphic code is generated based on at least one identity information and business authority information of multiple services, including:
- identity information fields based on identity information Generate identity information fields based on identity information, and generate business authority information fields based on business authority information; among them, one identity information corresponds to an identity information subfield in the identity information field, and business authority information for a business corresponds to business authority information Subfield
- the code value corresponding to the offline graphic code is generated.
- the following steps may be performed:
- generating the code value corresponding to the offline graphic code includes:
- the code value corresponding to the offline graphic code is generated.
- the offline graphic code generation device provided by the embodiment of this specification, at least one identity information of the user and the service authority information of multiple services are added to the generated offline graphic code, that is, the user can perform multiple services using the offline graphic code. Operation; In this way, when users need to use offline graphic codes in different scenarios, they only need to open the same offline graphic code for verification. This realizes that multiple business permissions are given to one offline graphic code, avoiding each When you need to use offline graphic codes to perform different services in different scenarios, you need to open different offline graphic codes, which increases the utilization rate of offline graphic codes and also brings great convenience to users.
- an embodiment of this specification also provides a storage medium for storing computer-executable instruction information.
- the storage medium may be U Disk, optical disk, hard disk, etc., when the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be realized:
- the computer-executable instruction information stored in the storage medium when executed by the processor, it is checked whether there is identity information recognized by the service accepting party corresponding to the code scanning device in the code scanning information, including:
- the user's identity information is extracted from the code scanning information, including:
- the service authority information of multiple services is extracted from the code scanning information, including:
- the extracted identity information contains encrypted identity ciphertext information
- the method From the extracted identity information, before checking whether there is identity information recognized by the business acceptor corresponding to the scanning device, the method also includes:
- the service authority information of the service includes at least: the service supported by the code scanning device and the service acceptor information corresponding to the service;
- the identity information includes at least: the user's name, identity identification information, and application scenario area information.
- an identity information of the user and the business authority information of multiple services are added to the generated offline graphic code, that is, the user uses the
- the offline graphic code can perform multiple business operations; in this way, when users need to use the offline graphic code in different scenarios, they only need to open the same offline graphic code for verification.
- the scanning device will check whether the offline graphic code is There is identity information recognized by the service acceptor of the code scanning device, and whether there is service authority information for the service supported by the code scanning device, and then based on the inspection result, it is determined whether the user has the authority to execute the corresponding service of the code scanning device; Assigning multiple service permissions to an offline graphic code avoids the need to open different offline graphic codes every time you need to use offline graphic codes to perform different services in different scenarios, which increases the utilization rate of offline graphic codes and also It brings great convenience to users.
- an embodiment of this specification also provides a storage medium for storing computer-executable instruction information.
- the storage medium may be U Disk, optical disk, hard disk, etc., when the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be realized:
- a code value corresponding to the offline graphic code is generated.
- the code value corresponding to the offline graphic code is generated based on at least one identity information and business authority information of multiple services, including:
- identity information fields based on identity information Generate identity information fields based on identity information, and generate business authority information fields based on business authority information; among them, one identity information corresponds to an identity information subfield in the identity information field, and business authority information for a business corresponds to business authority information Subfield
- the code value corresponding to the offline graphic code is generated.
- the computer executable instruction information stored in the storage medium is executed by the processor, based on at least one identity information and business authority information of multiple services, before generating the code value corresponding to the offline graphic code, the following may be executed step:
- generating the code value corresponding to the offline graphic code includes:
- the code value corresponding to the offline graphic code is generated.
- the computer executable instruction information stored in the storage medium provided by the embodiment of this specification is executed by the processor, at least one identity information of the user and the business authority information of multiple services are added to the generated offline graphic code, that is, the user uses
- the offline graphic code can perform multiple business operations; in this way, when the user needs to use the offline graphic code in different scenarios, he only needs to open the same offline graphic code for verification, thus realizing an offline graphic code assignment
- Multiple business permissions avoid the need to open different offline graphics codes every time you need to use offline graphics codes to perform different services in different scenarios, which increases the utilization of offline graphics codes and also brings great benefits to users. The convenience.
- a programmable logic device Programmable Logic Device, PLD
- FPGA Field Programmable Gate Array
- HDL Hardware Description Language
- ABEL Advanced Boolean Expression Language
- AHDL Altera Hardware Description Language
- HDCal JHDL
- Lava Lava
- Lola MyHDL
- PALASM RHDL
- VHDL Very-High-Speed Integrated Circuit Hardware Description Language
- Verilog Verilog
- the controller can be implemented in any suitable manner.
- the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program codes (such as software or firmware) executable by the (micro)processor. , Logic gates, switches, application specific integrated circuits (ASICs), programmable logic controllers and embedded microcontrollers.
- controllers include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicon Labs C8051F320, the memory controller can also be implemented as a part of the memory control logic.
- controller in addition to implementing the controller in a purely computer-readable program code manner, it is entirely possible to program the method steps to make the controller use logic gates, switches, application specific integrated circuits, programmable logic controllers and embedded The same function can be realized in the form of a microcontroller, etc. Therefore, such a controller can be regarded as a hardware component, and the devices included in it for implementing various functions can also be regarded as a structure within the hardware component. Or even, the device for realizing various functions can be regarded as both a software module for realizing the method and a structure within a hardware component.
- a typical implementation device is a computer.
- the computer may be, for example, a personal computer, a laptop computer, a cell phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or Any combination of these devices.
- the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
- a computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instruction information can also be stored in a computer-readable memory that can guide a computer or other programmable data processing equipment to work in a specific manner, so that the instruction information stored in the computer-readable memory generates a manufactured product including the instruction information device.
- the instruction information device realizes the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- These computer program instruction information can also be loaded on a computer or other programmable data processing equipment, so that a series of operation steps are executed on the computer or other programmable equipment to produce computer-implemented processing, which can be executed on the computer or other programmable equipment.
- the instruction information of provides the steps used to implement the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- the computing device includes one or more processors (CPU), input/output interfaces, network interfaces, and memory.
- processors CPU
- input/output interfaces network interfaces
- memory volatile and non-volatile memory
- the memory may include non-permanent memory in computer readable media, random access memory (RAM) and/or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer readable media.
- RAM random access memory
- ROM read-only memory
- flash RAM flash memory
- Computer-readable media include permanent and non-permanent, removable and non-removable media, and information storage can be realized by any method or technology.
- the information can be computer-readable instruction information, data structures, program modules, or other data.
- Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disc (DVD) or other optical storage, Magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media can be used to store information that can be accessed by computing devices. According to the definition in this article, computer-readable media does not include transitory media, such as modulated data signals and carrier waves.
- this application can be provided as methods, systems, or computer program products. Therefore, this application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
- computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types.
- This application can also be practiced in distributed computing environments. In these distributed computing environments, remote processing devices connected through a communication network perform tasks.
- program modules can be located in local and remote computer storage media including storage devices.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Accounting & Taxation (AREA)
- Signal Processing (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Tourism & Hospitality (AREA)
- Human Computer Interaction (AREA)
- Multimedia (AREA)
- Electromagnetism (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Artificial Intelligence (AREA)
- Toxicology (AREA)
- Economics (AREA)
- Primary Health Care (AREA)
- Marketing (AREA)
- Human Resources & Organizations (AREA)
- Educational Technology (AREA)
- Educational Administration (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Storage Device Security (AREA)
Abstract
一种离线图形码的处理、生成方法及装置,离线图形码的处理方法应用于扫码设备,具体包括:对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验,其中,该扫码信息包括:签名信息、用户的至少一个身份信息,以及多个业务的业务权限信息(102);若上述签名信息校验通过,则检验上述扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,以及,检验上述扫码信息中是否存在扫码设备所支持的业务的业务权限信息(104);若存在扫码设备对应的业务受理方所认可的身份信息以及扫码设备所支持的业务的业务权限信息,则确定该用户具备执行上述扫码设备所对应业务的权限(106)。
Description
本申请涉及图形码技术领域,尤其涉及一种离线图形码的处理、生成方法及装置。
随着信息技术的快速发展以及图形码技术的普及,二维码、条形码等图形码在各个领域都得到了广泛的应用,例如,支付领域、门禁领域等等。为了方便用户的使用,减少在进行图形码校验过程中用户的等待时间,目前,可以通过图形码展示设备离线生成、以及通过扫码设备离线校验的离线图形码也开始在各个领域开始广泛应用。例如,地铁进出站扫码、校园食堂、便利店、澡堂等消费场景。
随着用户在各种应用场景下对离线图形码的使用,如何进一步提高用户使用离线图形码的便利性,成为当前亟需解决的技术问题。
发明内容
本说明书实施例的目的是提供一种离线图形码的处理、生成方法及装置,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,既增加了离线图形码的利用率,同时还给用户带来了极大的便利。
为解决上述技术问题,本说明书实施例是这样实现的:
本说明书实施例提供了一种离线图形码的处理方法,应用于扫码设备,所述方法包括:
对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限 信息;
若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息;
若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
本说明书实施例还提供了一种离线图形码的生成方法,包括:
获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例还提供了一种离线图形码的处理装置,应用于扫码设备,所述装置包括:
校验模块,用于对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;
检验模块,用于若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息;
确定模块,用于若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
本说明书实施例还提供了一种离线图形码的生成装置,所述装置包括:
获取模块,用于获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
生成模块,用于基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例还提供了一种离线图形码的处理设备,应用于扫码设备,包括:
处理器;以及
被安排成存储计算机可执行指令的存储器,所述可执行指令在被执行时使所述处理器:
对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;
若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息;
若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
本说明书实施例还提供了一种离线图形码的生成设备,包括:
处理器;以及
被安排成存储计算机可执行指令的存储器,所述可执行指令在被执行时使所述处理器:
获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例还提供了一种存储介质,用于存储计算机可执行指令,所述可执行指令在被执行时实现以下流程:
对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;
若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在扫码设备所支持的业务的业务权限信息;
若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
本说明书实施例还提供了一种存储介质,用于存储计算机可执行指令,所述可执行指令在被执行时实现以下流程:
获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
本实施例中的技术方案,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
为了更清楚地说明本说明书实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请中记载的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本说明书实施例提供的离线图形码的处理方法的方法流程图之一;
图2为本说明书实施例提供的离线图形码的处理方法的方法流程图之二;
图3为本说明书实施例提供的离线图形码的处理方法的方法流程图之三;
图4为本说明书实施例提供的离线图形码的处理方法的方法流程图之四;
图5为本说明书实施例提供的离线图形码的处理方法的流程示意图;
图6为本说明书实施例提供的离线图形码的生成方法的方法流程图之一;
图7为本说明书实施例提供的离线图形码的生成方法的方法流程图之二;
图8为本说明书实施例提供的离线图形码的处理装置的模块组成示意图;
图9为本说明书实施例提供的离线图形码的生成装置的模块组成示意图;
图10为本说明书实施例提供的离线图形码的处理设备的结构示意图。
为了使本技术领域的人员更好地理解本申请中的技术方案,下面将结合本说明书实施例中的附图,对本说明书实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。
本说明书实施例的思想在于,在同一种离线图形码中添加用户的至少一个身份信息和多个业务的业务权限信息,这样,用户在多种不同场景下使用离线图形码执行不同业务时,都可以采用同一种离线图形码,避免了用户需要在不同场景下打开不同的离线图形码,即提高了离线图形码的利用率,还给用户带来了极大的便利。基于此,本说明书实施例提供了一种离线图形码的处理、生成方法、装置、设备及存储介质。下述将一一详细进行介绍。
首先,本说明书实施例提供了一种离线图形码的处理方法,该方法应用于扫码设备,即该方法的执行主体为扫码设备,具体的,为安装在扫码设备上的离线图形码的处理装置。
本说明书实施例中所提及到的离线图形码一般指的是图形码的生成设备(可以为图形码展示设备)在离线环境下生成的、且扫码设备在离线环境下对扫描的图形码进行校验。
其中,本说明书实施例所提及到的离线图形码可以为离线二维码、离线条形码等,离线二维码如常见的方形二维码、圆形二维码等。此外,离线图形码也包括其他用于展示和扫码的码,在此不再赘述。
图1为本说明书实施例提供的离线图形码的处理方法的方法流程图之一,图1所示的方法至少包括如下步骤:
步骤102,对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,该扫码信息中包括:签名信息、用户的至少一个身份信息,以及多个业务的业务权限信息。
在具体实施时,用户通过图形码展示设备(该图形码展示设备可以为手机、平板电 脑等)打开当前需要使用的离线图形码,并将打开的离线图形码置于扫码设备的扫码窗口区域,以使得扫码设备扫描该离线图形码,从而得到该离线图形码所对应的扫码信息。
其中,上述扫码信息可以为对扫描到的离线码图形码进行解析得到的信息,可以包括签名信息、用户的至少一个身份信息、多个业务的业务权限信息等,还可以包括扫码的时间信息等。
在本说明书实施例中,在一个离线图形码中设置有同一个用户的至少一个身份信息,该身份信息可以是在不同场景下用户的身份信息,例如,针对同一个用户而言,既可以是某学校的学生、也可以是某公司的职员、甚至是某小区的居民,针对该用户而言,可以将其学生身份信息、公司职员身份信息以及小区居民信息均添加在该离线图形码中。
同样的,对于同一个离线图形码而言,既可以用于学校食堂消费、还可以用户图书馆门禁、小区门禁、公司打卡等,因此,可以将学校食堂消费权限、进入图书馆权限、进入小区权限以及在公司上下班签到权限等均添加至该离线图形码中。
当然,上述只是示例性说明,在具体应用时,可以根据实际应用场景在离线图形码中设置用户的身份信息和所授权的业务的业务权限信息。
其中,在本说明书实施例中,可以在离线图形码中添加用户的一个身份信息和多个业务的业务权限信息,也可以在离线图形码中添加用户的多个身份信息和多个业务的业务权限信息。
在本说明书实施例中,上述步骤102中,对扫描信息中的签名信息进行校验包括:对颁发机构进行校验、对用户信息进行校验以及对该离线图形码的有效期限进行校验等等。通过上述校验,能够对该离线图形码进行初步校验,从而排除一些由于过期,或者与扫码设备相关联的颁发机构不匹配等导致无法获取图形码码值的无效图形码。
在具体实施时,在扫描得到离线图形码后,对扫描得到的离线图形码进行解析,得到该离线图形码所对应的码值,使用扫码设备中预先存储的该离线图形码的颁发机构的公钥对该离线图形码的码值进行解签处理,若是解签成功,则确定对该离线图形码的机构校验通过,并基于解签后得到的该离线图形码的生成时间信息以及扫码时间信息确定该离线图形码当前是否处于有效期限内,若是,则确定对该离线图形码的有效期限信息校验通过。并且在使用公钥对离线图形码的码值进行解签之后,得到该离线图形码所存储的用户的所有身份信息,并对身份信息进行校验,在校验通过后,则认为该离线图形码的签名信息校验通过。
步骤104,若上述签名信息校验通过,则检验上述扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,以及,检验上述扫码信息中是否存在扫码设备所支持的业务的业务权限信息。
上述业务受理方则为受理该扫码设备所对应业务的业务方,例如,若是上述扫码设备应用于小区门禁,则该扫码设备对应的业务受理方可以为小区物业;若是上述扫码设备应用于学校食堂,则该扫码设备对应的业务受理方可以为学校后勤等等。
当用户在使用离线图形码通过扫码设备执行某项业务时,在对该离线图形码的签名信息校验通过后,则检验该离线图形码所对应的扫码信息中是否存在与该扫码设备对应的业务受理方认可的身份信息,以及,是否存在该扫码设备所支持的业务的业务权限信息。
例如,在一种具体实施方式中,上述扫码设备应用于XX小区的门禁,则扫码设备在对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验通过后,则检验该扫码信息中是否存在XX小区的居民的身份信息(该扫码设备对应的物业所认可的身份信息),以及,检验该扫码信息中是否存在进入该XX小区的业务权限信息。
步骤106,若存在扫码设备对应的业务受理方所认可的身份信息以及扫码设备所支持的业务的业务权限信息,则确定该用户具备执行该扫码设备对应业务的权限。
本说明书实施例提供的离线图形码的处理方法,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
其中,在具体实施时,上述步骤104中,检验上述扫码信息中是否存在扫码设备所对应的业务受理方所认可的身份信息,具体包括如下步骤一和步骤二;
步骤一、从上述扫码信息中提取用户的身份信息;
步骤二、从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息;
上述步骤104中,检验上述扫码信息中是否存在扫码设备所支持的业务的业务权限信息,具体包括如下步骤(1)和步骤(2);
步骤(1)、从上述扫码信息中提取多个业务的业务权限信息;
步骤(2)、从提取的多个业务的业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息。
在具体实施时,可以将扫码信息中用户的所有身份信息都提取出来,再一一检验是否存在扫码设备对应的业务受理方所认可的身份信息,也可以是每提取一个身份信息,进行一次校验的过程,直至提取出扫码设备对应的业务受理方所认可的身份信息。另外,上述检验扫码信息中是否存在扫码设备所支持业务的业务权限信息的具体实施过程可参考检验身份信息的具体过程,此处不再赘述。
一般的,在扫码设备中存储有该扫码设备所支持的身份信息和业务的业务权限信息,例如,该扫码设备支持XX学校的学生进行付款操作,所对应的商家信息为XX等等。因此,在具体实施时,在从扫码信息中提取出用户的身份信息后,从所提取的身份信息中查找是否存与该扫码设备所存储的身份信息相匹配的身份信息,若存在,进一步检验所提取的业务权限信息中是否存在该扫码设备所支持的业务的业务权限信息,若存在,则认为该用户具备执行该扫码设备所对应业务的权限。
为便于理解,下述将举例进行说明。
例如,在一种具体实施方式中,张三既为某学校的学生,又是某公寓的居民,在离线图形码中所设定的张三的身份信息如下所示:
身份1:XX学校学生-学号:0001-姓名:张三-学校标识:1111;身份2:XX公寓居民-房号6265-姓名:张三-公寓名称:人才公寓。
在离线图形码中所设定的业务的业务权限信息如下所示:
权限1:付款-业务受理方标识:2088111122223333;权限2:核身-业务受理方标识:2088111122223333;权限3:核身-业务受理方标识:2088222233335555。
当张三在学校超市进行消费时,通过图形码展示设备打开离线图形码,并由设置在学校超市的扫码设备扫描该离线图形码,当扫码设备扫描到该离线图形码后,首先对该离线图形码进行解析,得到该离线图形码所对应的码值,并基于该码值对离线图形码进行签名验证,在签名验证通过后,从该离线图形码所对应的码值中提取用户的各个身份信息,由于该扫码设备只支持该学校的学生、教职工进行消费,因此,需要查找上述各个身份信息中是否存在该学校的学生或者教职工的身份信息,通过查找,确定该身份信息中包含XX学校的学生这种身份,因此,可以所提取的身份信息中存在该扫码设备所 对应的业务受理方认可的身份信息。之后,再从该离线图形码所对应的码值中,提取该离线图形码所对应的多种权限信息,在该扫码设备中存储有该扫码设备所支持的业务和对应业务受理方(此处为商家)信息,通过查找,发现赋予了该离线图形码对商家2088111122223333进行付款的权限,因此,认为该用户具备在该扫码设备执行付款的操作,从而执行相应的付款操作。
还例如,当张三需要刷卡进入其居住的人才公寓时,使用其所携带的图形码展示设备展示进行核身所需要的离线图形码,并通过设置在人才公寓的扫码设备扫描该离线图形码,当扫码设备扫描到该离线图形码后,对该离线图形码进行解析,得到该离线图形码所对应的码值,并基于该码值对离线图形码进行签名验证,在签名验证通过后,从该离线图形码所对应的码值中提取用户的各个身份信息,并查找所提取的各个身份信息中是否存在人才公寓居民这一身份信息,经查找,发现张三为人才公寓6265房间的居民;之后,再从上述离线图形码所对应的码值中提取该离线图形码所对应的权限信息,并查找所提取的各个权限信息中是否具备进入该人才公寓的权限,经查找,发现该离线图形码具备进入人才公寓的权限,因此,认为张三具备通过该扫码设备进入人才公寓的权限。
在一种具体实施方式中,上述步骤一中从扫码信息中提取用户的身份信息,具体包括:
从上述扫码信息中提取身份信息字段;从上述身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息;
一般的,在生成离线图形码所对应的码值时,对应设置有各个信息字段,如用户身份信息字段、业务权限信息字段、随机数字段等等,并且每个字段一般设置在固定位置处,例如,用户身份信息字段排在位置1、业务权限信息字段排在位置2、随机数字段排在位置3等等。因此,在提取用户的至少一个身份信息时,可以基于码值的生成规则中各个信息字段所对应的位置信息确定身份信息字段的位置,从而从码值中提取出用户身份信息字段。
由于在离线图形码中设置有用户的至少一个身份信息,而一个身份信息子字段对应用户的一个身份信息,因此,在提取各个身份信息时,还需要分别提取每个身份信息子字段。
例如,在一种具体实施方式中,针对用户A,在离线图形码中添加有用户A的两个身份信息,即该离线图形码中的身份信息字段包括身份信息子字段1和身份信息子字段 2,身份信息子字段1对应用户A的身份1,身份信息子字段2对应用户A的身份2,因此,身份信息字段的一种具体形式如下所示:
身份1:XX学校学生-学号-姓名-学校标识;身份2:XX小区居民-楼号、单元、房号-姓名-小区标识。
在具体实施时,则分别提取上述各个信息子字段所对应的身份信息,作为用户的身份信息。
图2为本说明书实施例提供的离线图形码的处理方法的方法流程图之二,图2所示的方法至少包括如下步骤:
步骤202,对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验。
步骤204,若对上述签名信息校验通过,提取上述扫码信息中的身份信息字段。
步骤206,从上述身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
步骤208,检验上述身份信息中是否存在扫码设备对应的业务受理方所认可的身份信息;若存在,则执行步骤210,否则,结束。
步骤210,从上述扫码信息中提取该离线图形码所对应的多个业务的业务权限信息。
步骤212,从上述提取的多个业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息;若存在,则执行步骤214,否则,结束。
步骤214,确定用户具备执行扫码设备对应业务的权限。
当然,图2所对应实施例只是其中一种具体实施方式,在具体实施时,也可以在提取出身份信息和多个业务的业务权限信息之后,再执行检验的步骤;当然,也可以按照图2所示实施例中,提取出身份信息之后,先执行检验身份信息的步骤;在身份信息检验通过后,再提取业务权限信息,执行校验业务权限信息的步骤;两种实现方式均可,本说明书实施例并不对此进行限定。
具体的,在上述步骤(1)中,从扫码信息中提取多个业务的业务权限信息,具体包括:从上述扫码信息中提取业务权限信息字段;从上述业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
例如,在一种具体实施方式中,针对某个离线图形码,用户既可以使用该离线图形码在学校食堂消费,也可以使用该离线图形码进行身份核实,从而进入学生公寓, 因此,该权限信息字段的一种可能的形式如下所示:
权限1:付款-业务受理方标识:2088111122223333;权限2:核身-业务受理方标识:2088222233335555。
其中,上述业务受理方标识用于标识该离线图形码具备在哪个业务受理方执行该项业务,例如,上述业务受理方可以为某个商家、某小区物业、某管理部门等等。
在具体实施时,则分别提取各个权限信息子字段所对应的业务权限信息,作为该离线图形码所对应的业务权限信息。
图3为本说明书实施例提供的离线图形码的处理方法的方法流程图之三,图3所示的方法,至少包括如下步骤:
步骤302,对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验。
步骤304,若上述签名信息校验通过,提取上述扫码信息中的身份信息字段。
步骤306,从上述身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
步骤308,从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息;若存在,则执行步骤310,否则,结束。
步骤310,提取上述扫码信息中的业务权限信息字段。
步骤312,从上述业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
步骤314,从提取的多个业务的业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息;若存在,则执行步骤316;否则,结束。
步骤316,确定用户具备执行该扫码设备对应业务的权限。
在具体实施时,可以在提取了用户的身份信息和业务权限信息之后,再进行身份信息和业务权限的校验,也可以在提取了用户的身份信息后,先对用户的身份信息进行验证,再提取业务权限信息,然后对业务权限信息进行验证。本说明书实施例并不对上述具体过程的执行顺序进行限定。
在本说明书实施例中,通过将离线图形码的身份信息字段划分为多个身份信息子字段,在每个身份信息子字段中添加用户的一个身份信息,这样,可以实现在离线图 形码中添加用户的多个身份信息,以及,将业务权限信息字段划分为多个权限信息子字段,一个权限信息子字段对应离线图形码的一个业务的业务权限信息,这样,可以在离线图形码中添加该离线图形码的多个业务权限信息,从而便于使得用户在多种场景下都可以使用同一种离线图形码执行相应的业务,避免了在不同场景下通过不同的途径打开不同的离线图形码,方便了用户的操作。
在一种具体实施方式中,上述业务的业务权限信息至少包括:扫码设备所支持的业务和该业务所对应的业务受理方信息;
上述身份信息至少包括:用户的姓名、身份标识信息和应用场景区域信息。
其中,上述业务可以为付款、核身等;若是上述业务为付款业务,则该业务受理方信息可以为该付款业务所对应商家信息,若是上述业务为核身业务,则该业务受理方信息可以为该核身业务所对应的单位信息,如公司信息、小区物业信息、图书馆管理部门等等。
为便于理解本说明书实施例所提及到的业务的业务权限信息,下述将举例进行说明。
例如,在一种具体实施方式中,上述业务的业务权限信息可以为:付款-业务受理方标识:2088111122223333。
在本说明书实施例中,由于可能会有多种业务受理方存在相同的业务,例如公司需要设置门禁对进入公司的人员进行身份核实,图书馆需要设置门禁对进入图书馆的人员进行身份核实,小区需要设置门禁对进入小区的人员进行身份核实,因此,为了区分该离线图形码所对应的业务是否与该扫码设备所支持的业务相匹配,需要在业务权限信息中加入该业务所对应的业务受理方标识。
在一种具体应用场景下,上述身份信息可以包括用户的姓名、身份标识信息和应用场景区域信息。该应用场景区域信息可以为该身份信息所对应的单位或者活动场所,例如XX学校、XX学校图书馆、XX公司、XX小区等。上述身份标识信息可以为身份名称信息、也可以为身份标识信息字符串。
为便于理解,下述将举例进行说明。
例如,在一种具体实施方式中,上述身份信息可以为:张三-学生-学号-XX学校。
当然,在具体实施时,为了减少离线图形码所对应码值的长度,可以对身份信 息中各部分内容进行编码,使用预先设置的编码代替具体的信息内容。例如针对身份信息中的身份标识信息,所设置的编码信息如表1所示。
表1
| 身份标识信息 | 编码 |
| 标准学籍学生 | 00000000 |
| 标准教师 | 00000001 |
| 极简学籍学生 | 00000010 |
| 极简教师 | 00000011 |
| 高校定制版 | 00000100 |
其中,上述表1为针对学校学生和教师的身份标识信息所对应的编码,一般的,学生身份标识信息可以包括学校名称、学生姓名和年级信息,在一种具体实施方式中,学生身份信息所对应的编码的一种可能的格式可以为:学校名称对应8字节、学生对应4字节、年级对应2字节,每次可以基于该规则生成学生身份标识信息编码。教师身份信息一般可以包括学校名称、教师姓名和职称,在一种具体实施方式中,教师身份信息所对应的编码的一种可能的格式可以为:学校名称对应8个字节、教师姓名对应4个字节、职称对应2个字节,每次可以基于该规则生成教师身份标识信息编码。
在一种具体实施方式中,在设置用户的身份信息时,可以将上述编码作为用户身份标识信息添加在身份信息子字段的指定位置处,例如,可以在每个身份信息子字段的开始位置处添加身份标识信息编码。
在一种具体实施方式中,用户所对应的各个身份信息中可能会存在一些敏感信息,这些信息不便于对外公开,因此,在将该身份信息添加至离线图形码之前,可以对该身份信息进行加密,从而该身份信息以身份密文信息的形式设置在离线图形码中,并且在离线图形码的传输过程中,该身份信息均是以身份信息密文的形式存在的,保证了该身份信息的安全性。具体的,为了缩短所生成的离线图形码的码值的长度,可以采用对称加密算法对需要加密的身份信息进行加密。
例如,在一种具体实施方式中,若是在生成离线图形码时,用户指定对身份信息中的某种身份信息进行加密,则对该种身份信息执行加密处理。在具体实施时,用户身份信息可以使用字符进行表示,例如,用户身份信息的原始数据为0000000100001111,对该数据进行加密后,得到的密文信息为0010111100001100,若是该用户的用户身份信 息为极简教师,则所得到的用户身份信息子字段为:000000110010111100001100。
当然,上述只是示例性说明,并不构成对本说明书实施例的限定。
这样,当扫码设备在扫描了离线图形码,并对离线图形码进行解析,得到该离线图形码所对应的码值后,若是发现从中提取的身份信息中存在身份密文信息,则对该身份密文信息进行解密处理。因此,在本说明书实施例中,在执行上述从提取的身份信息中,检验是否存在与扫码设备所关联的业务受理方所认可的身份信息之前,本说明书实施例提供的方法还包括:
对上述身份信息中所存在的身份密文信息进行解密处理,得到解密后的身份信息。
在具体实施时,在对某个身份信息进行加加密后,可以将加密所使用的密钥标识添加在离线图形码所对应的码值中,扫码设备在对离线图形码进行扫描后,基于得到的密钥标识信息确定对该身份信息进行解码的密钥信息。
在本说明书实施例中,由于身份信息字段包含多个身份信息子字段,一个身份信息子字段对应用户的一个身份信息,因此,在具体实施时,可以只对用户的某个身份信息进行加密。
图4为本说明书实施例提供的离线图形码的处理方法的方法流程图之四,图4所示的方法,至少包括如下步骤:
步骤402,对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验。
步骤404,若上述签名信息校验通过,提取上述扫码信息中的身份信息字段。
步骤406,从上述身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
步骤408,检测上述身份信息中是否存在身份密文信息;若存在,则执行步骤410;否则,执行步骤412。
步骤410,对身份密文信息进行解密处理,得到解密后的身份信息。
步骤412,检验上述身份信息中是否存在扫码设备所关联的业务受理方认可的身份信息;若存在,则执行步骤414;否则,结束。
步骤414,提取上述扫码信息中的业务权限信息字段。
步骤416,从上述业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
步骤418,检验上述业务权限信息中是否存在扫码设备所支持的业务权限信息;若存在,则执行步骤420;否则,结束。
步骤420,确定用户具备执行该扫码设备对应业务的权限,并执行该业务。
需要说明的是,在本说明书实施例中,可以在离线图形码中设置用户的一个身份信息和多个业务的业务权限信息。例如,用户A为XX学校的学生,可以在离线图形码中添加用户A的学生身份信息,并赋予该离线图形码在食堂消费和进入图书馆的权限。下述将以用户A在学校食堂进行消费、以及进入学校图书馆为例,介绍本说明书实施例提供的方法。图5为本说明书实施例提供的离线图形码的处理流程示意图。
在图5所示的流程示意图中,首先用户A在学校食堂进行消费时,通过图形码展示设备展示离线图形码,通过设置在学校食堂的扫码设备扫描该离线图形码,并基于扫描得到的扫码信息对该离线图形码进行签名验证,在签名验证通过后,提取该离线图形码中的身份信息,确定用户A为XX学校的学生,因此,为该扫码设备所关联的商家认可的身份。之后,提取该离线图形码中的业务权限信息,检测所提取的业务权限信息中是否存在该扫码设备所支持的对XX商家进行付款的业务权限,若存在,则认为用户A具备在该扫码设备执行付款的操作,扫码设备执行相应的付款操作;当用户A需要进入学校图书馆时,通过离线图形码展示设备展示离线图形码,并通过设置在图书馆门口的扫码设备扫描该离线图形码,并基于扫描得到的扫码信息对该离线图形码进行签名验证,在签名验证通过后,提取该离线图形码中的身份信息,确定用户A为XX学校的学生,因此,为该扫码设备所关联的业务受理方认可的身份。之后,提取该离线图形码中的业务权限信息,检测所提取的业务权限信息是否具备进入该图书馆的权限,若存在,则认为用户A具备进入图书馆的权限,则提示用户A身份校验通过,开启门禁。
另外,在本说明书实施例中,还可以在离线图形码中设置用户的多个身份信息和多个业务的业务权限信息。例如,用户A为XX学校的学生,可以在离线图形码中添加用户A的学生身份信息,同时用户A还为XX公司的职员,可以在该离线图形码中添加用户A的职员身份信息,并赋予该离线图形码在XX学校的食堂消费、进入XX学校的图书馆以及进入XX公司的权限。下述将以用户A在XX学校食堂进行消费、以及进入XX公司为例,介绍本说明书实施例提供的方法。
首先用户A在学校食堂进行消费时,通过图形码展示设备展示离线图形码,通过设置在学校食堂的扫码设备扫描该离线图形码,并基于扫描得到的扫码信息对该离线图形码进行签名验证,在签名验证通过后,提取该离线图形码中的身份信息,确定用户A为XX学校的学生,因此,为该扫码设备所关联的商家认可的身份。之后,提取该离线图形码中的业务权限信息,检测所提取的业务权限信息中是否存在该扫码设备所支持的对XX商家进行付款的业务权限,若存在,则认为用户A具备在该扫码设备执行付款的操作,扫码设备执行相应的付款操作;当用户A需要进入XX公司时,通过离线图形码展示设备展示离线图形码,并通过设置在XX公司门口的扫码设备扫描该离线图形码,并基于扫描得到的扫码信息对该离线图形码进行签名验证,在签名验证通过后,提取该离线图形码中的身份信息,确定用户A为XX公司的职员,因此,为该扫码设备所关联的公司认可的身份。之后,提取该离线图形码中的业务权限信息,检测所提取的业务权限信息是否具备进入该公司的权限,若存在,则认为用户A具备进入XX公司的权限,则提示用户A身份校验通过,开启门禁。
本说明书实施例提供的离线图形码的处理方法,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
对应于本说明书实施例提供的离线图形码的处理方法,基于相同的思路,本说明书实施例还提供了一种离线图形码的生成方法,该方法可以应用于服务器侧,也可以应用于图形码展示设备,即该方法的执行主体可以为服务器,也可以为图形码展示设备,具体的,为安装在服务器或者图形码展示设备上的离线图形码的生成装置。图6为本说明书实施例提供的离线图形码的生成方法的方法流程图之一,图6所示的方法,至少包括如下步骤:
步骤602,获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息。
步骤604,基于上述至少一个身份信息和多个业务的业务权限信息,生成离线图 形码所对应的码值。
其中,上述身份信息为业务受理方所认可的身份信息,上述业务为扫码设备所支持的业务。
在具体实施时,若是上述方法应用于服务器侧,上述身份信息和业务权限信息可以为用户通过图形码展示设备传输给服务器的。在具体实施时,用户可以通过图形码展示设备上所展示的离线图形码生成界面输入需要添加至离线图形码中的身份信息和业务权限信息。
在服务器侧生成离线图形码的码值后,服务器将生成的码值下发给图形码展示设备。具体的,服务器可以使用该服务器所对应的机构私钥对上述至少一个身份信息、多个业务的业务权限信息和生成的随机数进行签名,得到该离线图形码所对应的码值。
具体的,在服务器侧生成离线图形码的码值,由于只需要进行一次签名即可,并且不需要携带用户公钥,因此,可以缩短所生成的离线图形码的码值的长度。
当然,也可以在图形码展示设备生成上述离线图形码所对应的码值,在具体实施时,可以将身份信息和业务权限信息传输给服务器,以使服务器利用自身存储的机构私钥对该身份信息和业务权限信息进行签名,得到相应的签名信息,并将签名信息和该用户公钥下发给图形码展示设备,以使图形码展示设备使用自身所存储的用户私钥对随机数进行签名,将上述签名信息、随机数签名信息和用户公钥作为离线图形码所对应的码值。
在一种具体实施方式中,上述步骤604中,基于上述至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,具体包括:
基于上述身份信息生成身份信息字段,以及,基于上述业务的业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应上述业务权限信息字段中的一个业务权限信息子字段;根据上述身份信息字段和上述业务权限信息字段,生成离线图形码所对应的码值。
在一种具体实施方式中,用户所对应的各个身份信息中可能会存在一些敏感信息,这些信息不便于对外公开,因此,在将该身份信息添加至离线图形码时,可以对该身份信息进行加密,从而该身份信息以身份密文信息的形式设置在离线图形码中,并且在离线图形码的传输过程中,该身份信息均是以身份信息密文的形式存在的,保证了该身份信息的安全性。
因此,在一种具体实施方式中,在执行上述步骤604之前,本说明书实施例提供的方法还包括:
对用户指定的身份信息进行加密处理,得到上述身份信息所对应的身份密文信息;
相应的,在上述步骤606中,基于上述至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,具体包括:
基于用户指定的身份信息所对应的身份密文信息、剩余的身份信息和上述多个业务的业务权限信息,生成上述离线图形码所对应的码值。
在具体实施时,可以由用户指定需要加密的其中一个或者几个身份信息,并在生成离线图形码所对应的码值时,则对指定的身份信息进行加密处理,使用得到的身份密文信息、以及剩余的身份信息和多种业务权限信息,生成离线图形码所对应的码值。
其中,上述剩余的身份信息则是需要添加至离线图形码中的所有身份信息中除需要加密的身份信息之外的身份信息。
在本说明书实施例中,可以只对上述身份信息中的某一个身份信息进行加密处理。
具体的,为了缩短所生成的离线图形码的码值的长度,可以采用对称加密算法对需要加密的身份信息进行加密。
为便于理解,下述将以在服务器侧生成离线图形码所对应的码值为例,介绍本说明书实施例提供的离线图形码的生成方法。图7为本说明书实施例提供的离线图形码的生成方法的方法流程图之二,图7所示的方法至少包括如下步骤:
步骤702,获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息。
步骤704,基于上述身份信息生成身份信息字段,以及,基于上述业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应业务权限信息字段中的一个业务权限信息子字段。
步骤706,检测所获取的身份信息中是否存在用户指定进行加密的身份信息;若存在,则执行步骤708;
步骤708,对用户指定的身份信息进行加密处理,得到该身份信息所对应的身份密文信息。
步骤710,基于上述身份密文信息、剩余的身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
步骤712,将上述码值下发给图形码展示设备。
本说明书实施例提供的离线图形码的生成方法,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
对应于本说明书实施例图1-图5所对应实施例提供的方法,基于相同的思路,本说明书实施例提供了一种离线图形码的处理装置,应用于扫码设备,用于执行本说明书实施例图1-图5所示实施例提供的方法。图8为本说明书实施例提供的离线图形码的处理装置的模块组成示意图,图8所示的装置,包括:
校验模块802,用于对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,该扫码信息包括:签名信息、用户的至少一个身份信息,以及多个业务的业务权限信息;
检验模块804,用于若签名信息校验通过,则检验扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,以及,检验扫码信息中是否存在扫码设备所支持的业务的业务权限信息;
确定模块806,用于若存在扫码设备对应的业务受理方所认可的身份信息及扫码设备所支持的业务的业务权限信息,则确定用户具备执行扫码设备对应业务的权限。
可选的,上述检验模块804,包括:
第一提取单元,用于从扫码信息中提取用户的身份信息;
第一检验单元,用于从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息;
第二提取单元,用于从扫码信息中提取多个业务的业务权限信息;
第二检验单元,用于从所提取的多个业务的业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息。
可选的,上述第一提取单元,包括:
第一提取子单元,用于从扫码信息中提取身份信息字段;
第二提取子单元,用于从身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
可选的,上述第二提取单元,还包括:
第三提取子单元,用于从扫码信息中提取业务权限信息字段;
第四提取子单元,用于从业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
可选的,在本说明书实施例中,上述业务的业务权限信息至少包括:扫码设备所支持的业务和业务所对应的业务受理方信息;
身份信息至少包括:用户的姓名、身份标识信息和应用场景区域信息。
可选的,在本说明书实施例中,所提取的身份信息中存在加密的身份密文信息;
相应的,上述检验模块804,还包括:
解密单元,用于对身份信息中所存在的身份密文信息进行解密处理,得到解密后的身份信息。
本说明书实施例的离线图形码的处理装置还可执行图1-图5中离线图形码的处理装置执行的方法,并实现离线图形码的处理装置在图1-图5所示实施例的功能,在此不再赘述。
本说明书实施例提供的离线图形码的处理装置,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
对应于本说明书实施例图6-图7所对应实施例提供的方法,基于相同的思路, 本说明书实施例提供了一种离线图形码的生成装置,即可应用于服务器,也可以应用于图形码展示设备,用于执行本说明书实施例图6-图7所示实施例提供的方法。图9为本说明书实施例提供的离线图形码的生成装置的模块组成示意图,图9所示的装置,包括:
获取模块902,用于获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
生成模块904,用于基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
可选的,上述生成模块904,包括:
第一生成单元,用于基于身份信息生成身份信息字段,以及,基于业务的业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应业务权限信息字段中的一个业务权限信息子字段;
第二生成单元,用于根据身份信息字段和业务权限信息字段,生成离线图形码所对应的码值。
可选的,本说明书实施例提供的装置,还包括:
加密模块,用于对用户指定的身份信息进行加密处理,得到身份信息所对应的身份密文信息;
相应的,上述生成模块904,包括:
第三生成单元,用于基于用户指定的身份信息所对应的身份密文信息、剩余的身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例的离线图形码的生成装置还可执行图6-图7中离线图形码的生成装置执行的方法,并实现离线图形码的生成装置在图6-图7所示实施例的功能,在此不再赘述。
本说明书实施例提供的离线图形码的生成装置,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码, 即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
进一步地,基于上述图1至图5所示的方法,本说明书实施例还提供了一种离线图形码的处理设备,应用于扫码设备,如图10所示。
离线图形码的处理设备可因配置或性能不同而产生比较大的差异,可以包括一个或一个以上的处理器1001和存储器1002,存储器1002中可以存储有一个或一个以上存储应用程序或数据。其中,存储器1002可以是短暂存储或持久存储。存储在存储器1002的应用程序可以包括一个或一个以上模块(图示未示出),每个模块可以包括对离线图形码的处理设备中的一系列计算机可执行指令信息。更进一步地,处理器1001可以设置为与存储器1002通信,在离线图形码的处理设备上执行存储器1002中的一系列计算机可执行指令信息。离线图形码的处理设备还可以包括一个或一个以上电源1003,一个或一个以上有线或无线网络接口1004,一个或一个以上输入输出接口1005,一个或一个以上键盘1006等。
在一个具体的实施例中,离线图形码的处理设备包括有存储器,以及一个或一个以上的程序,其中一个或者一个以上程序存储于存储器中,且一个或者一个以上程序可以包括一个或一个以上模块,且每个模块可以包括对离线图形码的处理设备中的一系列计算机可执行指令信息,且经配置以由一个或者一个以上处理器执行该一个或者一个以上程序包含用于进行以下计算机可执行指令信息:
对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,上述扫码信息包括:签名信息、用户的至少一个身份信息,以及多个业务的业务权限信息;
若签名信息校验通过,则检验扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,以及,检验扫码信息中是否存在扫码设备所支持的业务的业务权限信息;
若存在扫码设备对应的业务受理方所认可的身份信息以及扫码设备所支持的业务的业务权限信息,则确定用户具备执行扫码设备对应业务的权限。
可选的,计算机可执行指令信息在被执行时,检验扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,包括:
从扫码信息中提取用户的身份信息;
从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息;
检验扫码信息中是否存在扫码设备所支持业务的业务权限信息,包括:
从扫码信息中提取多个业务的业务权限信息;
从所提取的多个业务的业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息。
可选的,计算机可执行指令信息在被执行时,从扫码信息中提取用户的身份信息,包括:
从扫码信息中提取身份信息字段;
从身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
可选的,计算机可执行指令信息在被执行时,从扫码信息中提取多个业务的业务权限信息,包括:
从扫码信息中提取业务权限信息字段;
从业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
可选的,计算机可执行指令信息在被执行时,所提取的身份信息中存在加密的身份密文信息;
从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息之前,方法还包括:
对身份信息中所存在的身份密文信息进行解密处理,得到解密后的身份信息。
可选的,计算机可执行指令信息在被执行时,业务的业务权限信息至少包括:扫码设备支持的业务和业务所对应的业务受理方信息;
身份信息至少包括:用户的姓名、身份标识信息和应用场景区域信息。
本说明书实施例提供的离线图形码的处理设备,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进 而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
进一步地,基于上述图6至图7所示的方法,本说明书实施例还提供了一种离线图形码的生成设备,其具体结构可参考如图10所示的离线图形码的处理设备。
在一个具体的实施例中,离线图形码的生成设备包括有存储器,以及一个或一个以上的程序,其中一个或者一个以上程序存储于存储器中,且一个或者一个以上程序可以包括一个或一个以上模块,且每个模块可以包括对离线图形码的生成设备中的一系列计算机可执行指令信息,且经配置以由一个或者一个以上处理器执行该一个或者一个以上程序包含用于进行以下计算机可执行指令信息:
获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
可选的,计算机可执行指令信息在被执行时,基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,包括:
基于身份信息生成身份信息字段,以及,基于业务的业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应一个业务权限信息子字段;
根据身份信息字段和业务权限信息字段,生成离线图形码所对应的码值。
可选的,计算机可执行指令信息在被执行时,基于至少一个身份信息和多个业务的业务权限信息,生成待生成离线图形码所对应的码值之前,还可执行如下步骤:
对用户指定的身份信息进行加密处理,得到身份信息所对应的身份密文信息;
相应的,基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,包括:
基于用户指定的身份信息所对应的身份密文信息、剩余的身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例提供的离线图形码的生成设备,在所生成的离线图形码中添加 有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
进一步地,基于上述图1至图5所示的方法,本说明书实施例还提供了一种存储介质,用于存储计算机可执行指令信息,一种具体的实施例中,该存储介质可以为U盘、光盘、硬盘等,该存储介质存储的计算机可执行指令信息在被处理器执行时,能实现以下流程:
对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,上述扫码信息包括:签名信息、用户的至少一个身份信息,以及多个业务的业务权限信息;
若签名信息校验通过,则检验扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,以及,检验扫码信息中是否存在扫码设备所支持的业务的业务权限信息;
若存在扫码设备对应的业务受理方所认可的身份信息以及扫码设备所支持的业务的业务权限信息,则确定用户具备执行扫码设备对应业务的权限。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,检验扫码信息中是否存在扫码设备对应的业务受理方所认可的身份信息,包括:
从扫码信息中提取用户的身份信息;
从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息;
检验扫码信息中是否存在扫码设备所支持业务的业务权限信息,包括:
从扫码信息中提取多个业务的业务权限信息;
从所提取的多个业务的业务权限信息中,检验是否存在扫码设备所支持的业务的业务权限信息。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,从扫码信息中提取用户的身份信息,包括:
从扫码信息中提取身份信息字段;
从身份信息字段中提取身份信息子字段;其中,一个身份信息子字段对应用户的一个身份信息。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,从扫码信息中提取多个业务的业务权限信息,包括:
从扫码信息中提取业务权限信息字段;
从业务权限信息字段中提取多个权限信息子字段;其中,一个权限信息子字段对应一个业务的业务权限信息。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,所提取的身份信息中存在加密的身份密文信息;
从提取的身份信息中,检验是否存在扫码设备对应的业务受理方所认可的身份信息之前,方法还包括:
对身份信息中所存在的身份密文信息进行解密处理,得到解密后的身份信息。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,业务的业务权限信息至少包括:扫码设备支持的业务和业务所对应的业务受理方信息;
身份信息至少包括:用户的姓名、身份标识信息和应用场景区域信息。
本说明书实施例提供的存储介质存储的计算机可执行指令信息在被处理器执行时,在所生成的离线图形码中添加有用户的一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,该扫码设备会检验离线图形码中是否存在该扫码设备的业务受理方认可的身份信息,以及是否存在扫码设备所支持的业务的业务权限信息,进而依据检验结果判断用户是否具备执行该扫码设备对应业务的权限;从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
进一步地,基于上述图6至图7所示的方法,本说明书实施例还提供了一种存储介质,用于存储计算机可执行指令信息,一种具体的实施例中,该存储介质可以为U盘、光盘、硬盘等,该存储介质存储的计算机可执行指令信息在被处理器执行时,能实现以下流程:
获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;
基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,包括:
基于身份信息生成身份信息字段,以及,基于业务的业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应一个业务权限信息子字段;
根据身份信息字段和业务权限信息字段,生成离线图形码所对应的码值。
可选的,该存储介质存储的计算机可执行指令信息在被处理器执行时,基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值之前,还可执行如下步骤:
对用户指定的身份信息进行加密处理,得到身份信息所对应的身份密文信息;
相应的,基于至少一个身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值,包括:
基于用户指定的身份信息所对应的身份密文信息、剩余的身份信息和多个业务的业务权限信息,生成离线图形码所对应的码值。
本说明书实施例提供的存储介质存储的计算机可执行指令信息在被处理器执行时,在所生成的离线图形码中添加有用户的至少一个身份信息和多个业务的业务权限信息,即用户使用该离线图形码可以执行多个业务操作;这样,当用户在不同场景下需要使用离线图形码时,只需要打开同一种离线图形码进行校验即可,从而实现了为一种离线图形码赋予多个业务权限,避免了每次在不同场景下需要使用离线图形码执行不同业务时,需要打开不同的离线图形码,即增加了离线图形码的利用率,同时还给用户带来了极大的便利。
在20世纪90年代,对于一个技术的改进可以很明显地区分是硬件上的改进(例如,对二极管、晶体管、开关等电路结构的改进)还是软件上的改进(对于方法流程的改进)。然而,随着技术的发展,当今的很多方法流程的改进已经可以视为硬件电路结构的直接改进。设计人员几乎都通过将改进的方法流程编程到硬件电路中来得到相应的 硬件电路结构。因此,不能说一个方法流程的改进就不能用硬件实体模块来实现。例如,可编程逻辑器件(Programmable Logic Device,PLD)(例如现场可编程门阵列(Field Programmable Gate Array,FPGA))就是这样一种集成电路,其逻辑功能由用户对器件编程来确定。由设计人员自行编程来把一个数字系统“集成”在一片PLD上,而不需要请芯片制造厂商来设计和制作专用的集成电路芯片。而且,如今,取代手工地制作集成电路芯片,这种编程也多半改用“逻辑编译器(logic compiler)”软件来实现,它与程序开发撰写时所用的软件编译器相类似,而要编译之前的原始代码也得用特定的编程语言来撰写,此称之为硬件描述语言(Hardware Description Language,HDL),而HDL也并非仅有一种,而是有许多种,如ABEL(Advanced Boolean Expression Language)、AHDL(Altera Hardware Description Language)、Confluence、CUPL(Cornell University Programming Language)、HDCal、JHDL(Java Hardware Description Language)、Lava、Lola、MyHDL、PALASM、RHDL(Ruby Hardware Description Language)等,目前最普遍使用的是VHDL(Very-High-Speed Integrated Circuit Hardware Description Language)与Verilog。本领域技术人员也应该清楚,只需要将方法流程用上述几种硬件描述语言稍作逻辑编程并编程到集成电路中,就可以很容易得到实现该逻辑方法流程的硬件电路。
控制器可以按任何适当的方式实现,例如,控制器可以采取例如微处理器或处理器以及存储可由该(微)处理器执行的计算机可读程序代码(例如软件或固件)的计算机可读介质、逻辑门、开关、专用集成电路(Application Specific Integrated Circuit,ASIC)、可编程逻辑控制器和嵌入微控制器的形式,控制器的例子包括但不限于以下微控制器:ARC 625D、Atmel AT91SAM、Microchip PIC18F26K20以及Silicone Labs C8051F320,存储器控制器还可以被实现为存储器的控制逻辑的一部分。本领域技术人员也知道,除了以纯计算机可读程序代码方式实现控制器以外,完全可以通过将方法步骤进行逻辑编程来使得控制器以逻辑门、开关、专用集成电路、可编程逻辑控制器和嵌入微控制器等的形式来实现相同功能。因此这种控制器可以被认为是一种硬件部件,而对其内包括的用于实现各种功能的装置也可以视为硬件部件内的结构。或者甚至,可以将用于实现各种功能的装置视为既可以是实现方法的软件模块又可以是硬件部件内的结构。
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机。具体的,计算机例如可以为个人计算机、膝上型计算机、蜂窝电话、相机电话、智能电话、个人数字助理、媒体播放器、导航设备、电子邮件设备、游戏控制台、平板计算机、可穿戴设备 或者这些设备中的任何设备的组合。
为了描述的方便,描述以上装置时以功能分为各种单元分别描述。当然,在实施本申请时可以把各单元的功能在同一个或多个软件和/或硬件中实现。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本说明书实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令信息实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令信息到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令信息产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令信息也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令信息产生包括指令信息装置的制造品,该指令信息装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令信息也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令信息提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方 法或技术来实现信息存储。信息可以是计算机可读指令信息、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。
本领域技术人员应明白,本申请的实施例可提供为方法、系统或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本申请可以在由计算机执行的计算机可执行指令信息的一般上下文中描述,例如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的例程、程序、对象、组件、数据结构等等。也可以在分布式计算环境中实践本申请,在这些分布式计算环境中,由通过通信网络而被连接的远程处理设备来执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地和远程计算机存储介质中。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
以上所述仅为本申请的实施例而已,并不用于限制本申请。对于本领域技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本申请的权利要求范围之内。
Claims (18)
- 一种离线图形码的处理方法,应用于扫码设备,所述方法包括:对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息;若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
- 如权利要求1所述的方法,所述检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,包括:从所述扫码信息中提取所述用户的身份信息;从提取的所述身份信息中,检验是否存在所述扫码设备对应的业务受理方所认可的身份信息;所述检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息,包括:从所述扫码信息中提取所述多个业务的业务权限信息;从所提取的所述多个业务的业务权限信息中,检验是否存在所述扫码设备所支持的业务的业务权限信息。
- 如权利要求2所述的方法,所述从所述扫码信息中提取所述用户的身份信息,包括:从所述扫码信息中提取身份信息字段;从所述身份信息字段中提取身份信息子字段;其中,一个所述身份信息子字段对应所述用户的一个身份信息。
- 如权利要求2所述的方法,所述从所述扫码信息中提取所述多个业务的业务权限信息,包括:从所述扫码信息中提取业务权限信息字段;从所述业务权限信息字段中提取多个权限信息子字段;其中,一个所述权限信息子字段对应一个业务的业务权限信息。
- 如权利要求2所述的方法,所提取的所述身份信息中存在加密的身份密文信息;所述从提取的所述身份信息中,检验是否存在所述扫码设备对应的业务受理方所认可的身份信息之前,所述方法还包括:对所述身份信息中所存在的身份密文信息进行解密处理,得到解密后的身份信息。
- 如权利要求1-5任一项所述的方法,所述业务的业务权限信息至少包括:所述扫码设备所支持的业务和所述业务所对应的业务受理方信息;所述身份信息至少包括:所述用户的姓名、身份标识信息和应用场景区域信息。
- 一种离线图形码的生成方法,所述方法包括:获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
- 如权利要求7所述的方法,所述基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值,包括:基于所述身份信息生成身份信息字段,以及,基于所述业务的业务权限信息生成业务权限信息字段;其中,一个身份信息对应身份信息字段中的一个身份信息子字段,一个业务的业务权限信息对应一个业务权限信息子字段;根据所述身份信息字段和所述业务权限信息字段,生成所述离线图形码所对应的码值。
- 如权利要求7或8所述的方法,所述基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值之前,所述方法还包括:对所述用户指定的所述身份信息进行加密处理,得到所述身份信息所对应的身份密文信息;相应的,所述基于所述至少一个身份信息和所述多种业务的业务权限信息,生成离线图形码所对应的码值,包括:基于所述用户指定的所述身份信息所对应的所述身份密文信息、剩余的身份信息和所述多个业务的业务权限信息,生成所述离线图形码所对应的码值。
- 一种离线图形码的处理装置,应用于扫码设备,所述装置包括:校验模块,用于对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;检验模块,用于若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述 扫码设备所支持的业务的业务权限信息;确定模块,用于若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
- 如权利要求10所述的装置,所述检验模块,包括:第一提取单元,用于从所述扫码信息中提取所述用户的身份信息;第一检验单元,用于从提取的所述身份信息中,检验是否存在所述扫码设备对应的业务受理方所认可的身份信息;第二提取单元,用于从所述扫码信息中提取所述多个业务的业务权限信息;第二检验单元,用于从所提取的所述多个业务的业务权限信息中,检验是否存在所述扫码设备所支持的业务的业务权限信息。
- 如权利要求11所述的装置,所述第一提取单元,包括:第一提取子单元,用于从所述扫码信息中提取身份信息字段;第二提取子单元,用于从所述身份信息字段中提取身份信息子字段;其中,一个所述身份信息子字段对应所述用户的一个身份信息。
- 如权利要求11所述的装置,所述第二提取单元,包括:第三提取子单元,用于从所述扫码信息中提取业务权限信息字段;第四提取子单元,用于从所述业务权限信息字段中提取多个权限信息子字段;其中,一个所述权限信息子字段对应一个业务的业务权限信息。
- 一种离线图形码的生成装置,所述装置包括:获取模块,用于获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;生成模块,用于基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
- 一种离线图形码的处理设备,应用于扫码设备,包括:处理器;以及被安排成存储计算机可执行指令的存储器,所述可执行指令在被执行时使所述处理器:对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在所述扫码设备所支持的业务的业务权限信息;若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
- 一种离线图形码的生成设备,包括:处理器;以及被安排成存储计算机可执行指令的存储器,所述可执行指令在被执行时使所述处理器:获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
- 一种存储介质,用于存储计算机可执行指令,所述可执行指令在被执行时实现以下流程:对扫描用户的离线图形码所得到的扫码信息中的签名信息进行校验;其中,所述扫码信息包括:所述签名信息、所述用户的至少一个身份信息,以及多个业务的业务权限信息;若所述签名信息校验通过,则检验所述扫码信息中是否存在所述扫码设备对应的业务受理方所认可的身份信息,以及,检验所述扫码信息中是否存在扫码设备所支持的业务的业务权限信息;若存在所述扫码设备对应的业务受理方所认可的身份信息及所述扫码设备所支持的业务的业务权限信息,则确定所述用户具备执行所述扫码设备对应业务的权限。
- 一种存储介质,用于存储计算机可执行指令,所述可执行指令在被执行时实现以下流程:获取用户的至少一个身份信息,以及,获取多个业务的业务权限信息;基于所述至少一个身份信息和所述多个业务的业务权限信息,生成离线图形码所对应的码值。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/888,410 US10943087B2 (en) | 2019-06-03 | 2020-05-29 | Method and apparatus for processing and generating offline graphic code |
| US17/170,014 US11176352B2 (en) | 2019-06-03 | 2021-02-08 | Method and apparatus for processing and generating offline graphic code |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910478641.0 | 2019-06-03 | ||
| CN201910478641.0A CN110335036B (zh) | 2019-06-03 | 2019-06-03 | 离线图形码的处理、生成方法及装置 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/888,410 Continuation US10943087B2 (en) | 2019-06-03 | 2020-05-29 | Method and apparatus for processing and generating offline graphic code |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020244235A1 true WO2020244235A1 (zh) | 2020-12-10 |
Family
ID=68140256
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/071283 Ceased WO2020244235A1 (zh) | 2019-06-03 | 2020-01-10 | 离线图形码的处理、生成方法及装置 |
Country Status (3)
| Country | Link |
|---|---|
| US (2) | US10943087B2 (zh) |
| CN (2) | CN112488697A (zh) |
| WO (1) | WO2020244235A1 (zh) |
Families Citing this family (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112488697A (zh) * | 2019-06-03 | 2021-03-12 | 创新先进技术有限公司 | 离线图形码的处理、生成方法及装置 |
| US11245537B2 (en) * | 2019-06-07 | 2022-02-08 | Open Text Corporation | System and method for a local server with self-signed certificates |
| CN112862466A (zh) * | 2019-12-17 | 2021-05-28 | 中国银联股份有限公司 | 一种资源转移的方法及结账终端、服务器节点 |
| CN111461725B (zh) * | 2020-01-02 | 2023-11-14 | 中国银联股份有限公司 | 一种基于二维码支付的身份识别方法以及身份识别系统 |
| CN111540093A (zh) * | 2020-04-29 | 2020-08-14 | 三仟(杭州)数字科技有限公司 | 一种门禁控制系统及其控制方法 |
| US12457097B2 (en) * | 2021-02-16 | 2025-10-28 | Cloudflare, Inc. | Zero trust authentication |
| TWI764616B (zh) * | 2021-03-11 | 2022-05-11 | 第一商業銀行股份有限公司 | 身分驗證及產品權限獲得方法、用於身分驗證的設備端和用於獲得產品權限的使用端 |
| CN113313224B (zh) * | 2021-06-02 | 2022-06-28 | 哈尔滨华泽数码科技有限公司 | 一种用于政务服务的办件码的生成系统及生成方法 |
| CN113470237A (zh) * | 2021-07-02 | 2021-10-01 | 厦门悦讯信息科技股份有限公司 | 一种校园门禁智慧管理系统及方法 |
| CN117787310A (zh) * | 2022-09-06 | 2024-03-29 | 博泰车联网(南京)有限公司 | 图片的操作方法、电子设备及存储介质 |
| CN116204691A (zh) * | 2023-03-17 | 2023-06-02 | 蚂蚁区块链科技(上海)有限公司 | 码数据的存储方法及装置 |
| CN116633697A (zh) * | 2023-07-25 | 2023-08-22 | 苏州万店掌网络科技有限公司 | 一种设备入网方法、装置、设备及可读存储介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104050567A (zh) * | 2014-05-30 | 2014-09-17 | 深圳天珑无线科技有限公司 | 离线模式下的数据交互方法、终端以及服务器 |
| US20170068953A1 (en) * | 2015-09-09 | 2017-03-09 | Samsung Electronics Co., Ltd. | Method and apparatus for performing payment |
| CN108737394A (zh) * | 2018-05-08 | 2018-11-02 | 腾讯科技(深圳)有限公司 | 离线验证系统、扫码设备和服务器 |
| CN108900302A (zh) * | 2018-06-19 | 2018-11-27 | 广州佳都数据服务有限公司 | 二维码生成、认证方法、生成终端及认证设备 |
| CN110335036A (zh) * | 2019-06-03 | 2019-10-15 | 阿里巴巴集团控股有限公司 | 离线图形码的处理、生成方法及装置 |
Family Cites Families (32)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5640002A (en) * | 1995-08-15 | 1997-06-17 | Ruppert; Jonathan Paul | Portable RF ID tag and barcode reader |
| US7028902B2 (en) * | 2002-10-03 | 2006-04-18 | Hewlett-Packard Development Company, L.P. | Barcode having enhanced visual quality and systems and methods thereof |
| US7168614B2 (en) * | 2004-12-10 | 2007-01-30 | Mitek Systems, Inc. | System and method for check fraud detection using signature validation |
| US7140541B2 (en) * | 2005-04-22 | 2006-11-28 | Troy Stelzer | Data processing method for image lift wet signature capture within retail transaction |
| US9002944B2 (en) * | 2007-04-04 | 2015-04-07 | Pathfinders International, Llc | Virtual badge, device and method |
| US8595503B2 (en) * | 2008-06-30 | 2013-11-26 | Konica Minolta Laboratory U.S.A., Inc. | Method of self-authenticating a document while preserving critical content in authentication data |
| US8632000B2 (en) | 2010-12-23 | 2014-01-21 | Paydiant, Inc. | Mobile phone ATM processing methods and systems |
| US20110258058A1 (en) | 2010-04-14 | 2011-10-20 | Restaurant Technology, Inc. | System and method for generating a restaurant order on a wireless mobile personal computer |
| US8528820B2 (en) * | 2011-06-29 | 2013-09-10 | Symbol Technologies, Inc. | Object identification using barcode reader |
| US8924712B2 (en) | 2011-11-14 | 2014-12-30 | Ca, Inc. | Using QR codes for authenticating users to ATMs and other secure machines for cardless transactions |
| US8639619B1 (en) | 2012-07-13 | 2014-01-28 | Scvngr, Inc. | Secure payment method and system |
| US9083531B2 (en) * | 2012-10-16 | 2015-07-14 | Symantec Corporation | Performing client authentication using certificate store on mobile device |
| US20140279469A1 (en) | 2013-03-12 | 2014-09-18 | Carta Worldwide Inc. | System and method for mobile transaction payments |
| JP6505732B2 (ja) * | 2013-11-07 | 2019-04-24 | スキャントラスト・エスエイScanTrust SA | 2次元バーコードおよびそのようなバーコードの認証方法 |
| US9219723B1 (en) * | 2013-12-20 | 2015-12-22 | Certify Global Inc. | Source device for systems and methods of verifying an authentication using dynamic scoring |
| KR101450013B1 (ko) | 2013-12-20 | 2014-10-13 | 주식회사 시큐브 | 빠른 응답 코드를 이용한 인증 시스템 및 방법 |
| CN104751332A (zh) * | 2013-12-26 | 2015-07-01 | 腾讯科技(深圳)有限公司 | 一种信息登记方法、终端、服务器及其系统 |
| CN104751334B (zh) * | 2013-12-31 | 2022-04-26 | 腾讯科技(深圳)有限公司 | 一种业务处理方法、装置及系统 |
| US20170302641A1 (en) * | 2014-03-28 | 2017-10-19 | Confia Systems, Inc. | Secure and Anonymized Authentication |
| BR112016026270B1 (pt) | 2014-05-09 | 2023-12-12 | Diebold Nixdorf, Incorporated | Método para realizar uma transação bancária pré-criada em um caixa eletrônico |
| KR101652625B1 (ko) | 2015-02-11 | 2016-08-30 | 주식회사 이베이코리아 | 온라인 웹사이트의 회원 로그인을 위한 보안인증 시스템 및 그 방법 |
| WO2017087981A2 (en) | 2015-11-20 | 2017-05-26 | Payeazy, Inc. | Systems and methods for authenticating users of a computer system |
| US20170161729A1 (en) | 2015-12-07 | 2017-06-08 | Leadot Innovation, Inc. | Method of Exchanging Currencies Using an Offline Point of Sale Third Party Payment System and Internet-connected Mobile Computing Device |
| US20170249660A1 (en) | 2016-02-29 | 2017-08-31 | Patricia Ann Smith | Methods and Apparatuses for Electronic Verification |
| WO2017152150A1 (en) | 2016-03-04 | 2017-09-08 | ShoCard, Inc. | Method and system for authenticated login using static or dynamic codes |
| CN107016420B (zh) | 2016-12-08 | 2022-01-28 | 创新先进技术有限公司 | 一种业务处理方法及装置 |
| US10476862B2 (en) | 2017-03-31 | 2019-11-12 | Mastercard International Incorporated | Systems and methods for providing digital identity records to verify identities of users |
| CN108154211B (zh) * | 2017-11-22 | 2020-08-28 | 阿里巴巴集团控股有限公司 | 二维码生成、业务处理方法、装置和设备以及二维码 |
| CN111860020B (zh) * | 2018-04-25 | 2024-10-01 | 创新先进技术有限公司 | 业务处理方法、装置以及设备 |
| CN109636411B (zh) * | 2018-11-16 | 2020-06-09 | 阿里巴巴集团控股有限公司 | 提供和获取安全身份信息的方法及装置 |
| CN109523254B (zh) * | 2018-11-29 | 2023-04-28 | 湖北云雷信息技术有限公司 | 一种基于手机app通过双离线扫码的多种支付方法 |
| US10949636B2 (en) * | 2019-07-30 | 2021-03-16 | Tetrus Corp. | Consent management apparatus and system |
-
2019
- 2019-06-03 CN CN202011476115.XA patent/CN112488697A/zh active Pending
- 2019-06-03 CN CN201910478641.0A patent/CN110335036B/zh active Active
-
2020
- 2020-01-10 WO PCT/CN2020/071283 patent/WO2020244235A1/zh not_active Ceased
- 2020-05-29 US US16/888,410 patent/US10943087B2/en active Active
-
2021
- 2021-02-08 US US17/170,014 patent/US11176352B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104050567A (zh) * | 2014-05-30 | 2014-09-17 | 深圳天珑无线科技有限公司 | 离线模式下的数据交互方法、终端以及服务器 |
| US20170068953A1 (en) * | 2015-09-09 | 2017-03-09 | Samsung Electronics Co., Ltd. | Method and apparatus for performing payment |
| CN108737394A (zh) * | 2018-05-08 | 2018-11-02 | 腾讯科技(深圳)有限公司 | 离线验证系统、扫码设备和服务器 |
| CN108900302A (zh) * | 2018-06-19 | 2018-11-27 | 广州佳都数据服务有限公司 | 二维码生成、认证方法、生成终端及认证设备 |
| CN110335036A (zh) * | 2019-06-03 | 2019-10-15 | 阿里巴巴集团控股有限公司 | 离线图形码的处理、生成方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN110335036A (zh) | 2019-10-15 |
| US11176352B2 (en) | 2021-11-16 |
| CN110335036B (zh) | 2020-11-06 |
| US20210165995A1 (en) | 2021-06-03 |
| US10943087B2 (en) | 2021-03-09 |
| US20200293749A1 (en) | 2020-09-17 |
| CN112488697A (zh) | 2021-03-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN110335036B (zh) | 离线图形码的处理、生成方法及装置 | |
| WO2021227966A1 (zh) | 绑定处理 | |
| WO2021068636A1 (zh) | 基于区块链的可验证声明的创建方法、装置、设备及系统 | |
| US20180293580A1 (en) | Systems and methods for processing an access request | |
| WO2021114937A1 (zh) | 一种基于区块链的业务处理方法、装置及设备 | |
| CN110532165B (zh) | 应用程序安装包特性检测方法、装置、设备及存储介质 | |
| TW201822049A (zh) | 業務處理方法及裝置 | |
| US10164777B2 (en) | Privacy control using unique identifiers associated with sensitive data elements of a group | |
| TWI697854B (zh) | 支付乘車費的方法、裝置及設備 | |
| CN110933117B (zh) | 数字身份信息的派生、验证方法、装置及设备 | |
| CN113127516B (zh) | 一种区块链数据的处理方法、装置及设备 | |
| TW201909041A (zh) | 基於伺服器推薦的驗票方案進行驗票的方法、系統及設備 | |
| WO2021174997A1 (zh) | 跨境支付方法、装置、设备及系统 | |
| CN111737686A (zh) | 一种区块链数据的处理方法、装置及设备 | |
| US9576124B2 (en) | Multi-level password authorization | |
| CN111415143A (zh) | 支付设备及其支付方法和装置 | |
| WO2024046121A1 (zh) | 服务处理的方法及装置 | |
| US12339996B2 (en) | Retrieving hidden digital identifier | |
| CN113591040A (zh) | 加密方法及其装置、解密方法及其装置、电子设备和介质 | |
| CN110321752B (zh) | 离线图形码的校验方法及装置 | |
| Rai et al. | Security and Auditing of Smart Devices: Managing Proliferation of Confidential Data on Corporate and BYOD Devices | |
| HK40046900A (zh) | 离线图形码的处理、生成方法及装置 | |
| HK40016182B (zh) | 离线图形码的处理、生成方法及装置 | |
| HK40016182A (zh) | 离线图形码的处理、生成方法及装置 | |
| CN108255823A (zh) | 读取发票信息的方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20818272 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20818272 Country of ref document: EP Kind code of ref document: A1 |