Nothing Special   »   [go: up one dir, main page]

CN105635096A - Data module access method, system and terminal - Google Patents

Data module access method, system and terminal Download PDF

Info

Publication number
CN105635096A
CN105635096A CN201510364688.6A CN201510364688A CN105635096A CN 105635096 A CN105635096 A CN 105635096A CN 201510364688 A CN201510364688 A CN 201510364688A CN 105635096 A CN105635096 A CN 105635096A
Authority
CN
China
Prior art keywords
data module
identification information
digital certificate
terminal
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201510364688.6A
Other languages
Chinese (zh)
Other versions
CN105635096B (en
Inventor
董志伟
汪万兴
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority to CN201510364688.6A priority Critical patent/CN105635096B/en
Publication of CN105635096A publication Critical patent/CN105635096A/en
Application granted granted Critical
Publication of CN105635096B publication Critical patent/CN105635096B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

The invention provides a data module access method, system and terminal. The data module access method comprises the following steps: after obtaining an encryption instruction of a data module, sending terminal identification information and identification information of the data module to a server; after the server determines a terminal group corresponding to the identification information of the data module, and when the server judges that the terminal identification information belongs to the device identification information of the terminal group, obtaining a digital certificate sent by the server; and encrypting the data module according to a public key corresponding to the digital certificate. By adopting the data module access method provided by the technical scheme of the invention, the security of an access process of the data module is guaranteed, the encryption process and the decryption process of the data module are simplified, and the user experience is improved.

Description

The access method of data module, system and terminal
Technical field
The present invention relates to field of terminal technology, in particular to the access method of a kind of data module, the access system of a kind of data module and a kind of terminal.
Background technology
In the related, it is in the protection of the safety of the data to user, it is applied to hands machine, the data module of the other-end equipment such as computer, such as SD card (SecureDigitalMemoryCard, flash-storing card) and SIM (SubscriberIdentityModuleCard, subscriber identification module) etc., typically require and by digital certificate, data module is encrypted, user must be manually entered password could be decrypted reading to data module, cannot while protection privacy of user data, realize the automatic deciphering to data module, the use causing user is perplexed.
Therefore, the access scheme of a kind of new data module how is designed so that carrying out data module accessing easily reading the technical problem solving to become urgently to be resolved hurrily.
Summary of the invention
The present invention be based on above-mentioned technical problem at least one, propose the access scheme of a kind of new data module and a kind of terminal, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, it is provided that the access mode of a kind of data module easily.
In view of this, embodiment according to the first aspect of the invention, it is proposed that the access method of a kind of data module, including: after obtaining the instruction that described data module is encrypted, send the identification information of terminal identification information and data module to server; After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends; According to the PKI that described digital certificate is corresponding, described data module is encrypted.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, digital certificate corresponding for above-mentioned endpoint groups is sent to terminal, data module is encrypted by terminal by PKI, by private key, data module is decrypted process, additionally, terminal can also when sending data to server, by encrypted private key to realize authentication process.
Wherein, server is in the process creating endpoint groups, pre-stored can by the terminal identification information of the terminal of users to trust, the identification information of each group of terminal identification information and data module corresponds to an endpoint groups (at least including a digital certificate), but, one terminal identification information can be pre-stored in multiple endpoint groups, namely, terminal can be divided into the trusted terminal (terminal identification information is stored in endpoint groups) of multiple data module, realizes the terminal quick access process to different pieces of information module in this way.
In technique scheme, it is preferable that also include: after obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server; After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate; According to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the private key that digital certificate is corresponding, data module is decrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, sending digital certificate corresponding for above-mentioned endpoint groups to terminal, data module is encrypted by terminal by private key.
In technique scheme, it is preferable that also include: after described data module is encrypted by the PKI corresponding according to described digital certificate, described data module is write the encryption identification to be encrypted by described PKI; Store described encryption identification, store described digital certificate simultaneously.
In this technical scheme, by after data module is encrypted, data module writes encryption identification, and store encryption identification and digital certificate, what have recorded data module in being used for the terminal encrypted adds confidential information, namely after once inserting, in terminal, the data module encrypted, can judge whether to have stored corresponding digital certificate according to encryption identification, and according to the private key that digital certificate is corresponding, data module is carried out fast decryption, it is manually entered password is decrypted thus avoiding user, or the step of digital certificate is sent to server request, thus improving the efficiency that digital certificate is decrypted, decrease network load and data exchange process.
In technique scheme, it is preferable that also include: after obtaining the instruction that described data module is decrypted, it is judged that whether described data module includes described encryption identification; When whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by whether data module is included encryption identification judge, and be decrypted according to decision structure, improve the efficiency that data module is decrypted, improve the experience of user.
Embodiment according to the second aspect of the invention, propose the access system of a kind of data module, including: transmitting element, for, after obtaining the instruction that described data module is encrypted, sending the identification information of terminal identification information and data module to server; Acquiring unit, after the endpoint groups that identification information for determining described data module at described server is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends; Ciphering unit, for being encrypted described data module according to the PKI that described digital certificate is corresponding.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, digital certificate corresponding for above-mentioned endpoint groups is sent to terminal, data module is encrypted by terminal by PKI, by private key, data module is decrypted process, additionally, terminal can also when sending data to server, by encrypted private key to realize authentication process.
Wherein, server is in the process creating endpoint groups, pre-stored can by the terminal identification information of the terminal of users to trust, the identification information of each group of terminal identification information and data module corresponds to an endpoint groups (at least including a digital certificate), but, one terminal identification information can be pre-stored in multiple endpoint groups, namely, terminal can be divided into the trusted terminal (terminal identification information is stored in endpoint groups) of multiple data module, realizes the terminal quick access process to different pieces of information module in this way.
In technique scheme, it is preferable that described transmitting element is additionally operable to: after obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server; Described acquiring unit is additionally operable to: after described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate; The access system of data module also includes: decryption unit, for described data module being decrypted according to the private key that described digital certificate is corresponding.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the private key that digital certificate is corresponding, data module is decrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, sending digital certificate corresponding for above-mentioned endpoint groups to terminal, data module is encrypted by terminal by private key.
In technique scheme, it is preferable that also include: writing unit, for, after described data module is encrypted by the PKI corresponding according to described digital certificate, described data module being write the encryption identification to be encrypted by described PKI; Memory element, is used for storing described encryption identification, is simultaneously used for storing described digital certificate.
In this technical scheme, by after data module is encrypted, data module writes encryption identification, and store encryption identification and digital certificate, what have recorded data module in being used for the terminal encrypted adds confidential information, namely after once inserting, in terminal, the data module encrypted, can judge whether to have stored corresponding digital certificate according to encryption identification, and according to the private key that digital certificate is corresponding, data module is carried out fast decryption, it is manually entered password is decrypted thus avoiding user, or the step of digital certificate is sent to server request, thus improving the efficiency that digital certificate is decrypted, decrease network load and data exchange process.
In technique scheme, it is preferable that also include: judging unit, for after obtaining the instruction that described data module is decrypted, it is judged that whether described data module includes described encryption identification; Described decryption unit is additionally operable to: when whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by whether data module is included encryption identification judge, and be decrypted according to decision structure, improve the efficiency that data module is decrypted, improve the experience of user.
Embodiment according to the third aspect of the invention we, it is proposed that a kind of terminal, including the access system of the data module as described in above-mentioned any one technical scheme.
By above technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, digital certificate corresponding for above-mentioned endpoint groups is sent to terminal, data module is encrypted by terminal by PKI, by private key, data module is decrypted process, additionally, terminal can also when sending data to server, by encrypted private key to realize authentication process.
Accompanying drawing explanation
Fig. 1 illustrates the schematic flow sheet of the access method of data module according to an embodiment of the invention;
Fig. 2 illustrates the schematic block diagram of the access system of data module according to an embodiment of the invention;
Fig. 3 illustrates the schematic block diagram of terminal according to an embodiment of the invention;
Fig. 4 illustrates the schematic diagram of endpoint groups according to an embodiment of the invention;
Fig. 5 illustrates the schematic diagram of endpoint groups according to another embodiment of the invention;
Fig. 6 illustrates the schematic diagram of the ciphering process of data module according to an embodiment of the invention;
Fig. 7 illustrates the schematic diagram of the decrypting process of data module according to an embodiment of the invention.
Detailed description of the invention
In order to be more clearly understood that the above-mentioned purpose of the present invention, feature and advantage, below in conjunction with the drawings and specific embodiments, the present invention is further described in detail. It should be noted that when not conflicting, embodiments herein and the feature in embodiment can be mutually combined.
Elaborate a lot of detail in the following description so that fully understanding the present invention; but; the present invention can also adopt other to be different from other modes described here to implement, and therefore, protection scope of the present invention is by the restriction of following public specific embodiment.
Below in conjunction with Fig. 1 to Fig. 7, the access process of data module according to an embodiment of the invention is illustrated.
As it is shown in figure 1, the access method of data module according to an embodiment of the invention, including: step 102, after obtaining the instruction that described data module is encrypted, send the identification information of terminal identification information and data module to server; Step 104, after described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends; Step 106, is encrypted described data module according to the PKI that described digital certificate is corresponding.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, digital certificate corresponding for above-mentioned endpoint groups is sent to terminal, data module is encrypted by terminal by PKI, by private key, data module is decrypted process, additionally, terminal can also when sending data to server, by encrypted private key to realize authentication process.
Wherein, server is in the process creating endpoint groups, pre-stored can by the terminal identification information of the terminal of users to trust, the identification information of each group of terminal identification information and data module corresponds to an endpoint groups (at least including a digital certificate), but, one terminal identification information can be pre-stored in multiple endpoint groups, namely, terminal can be divided into the trusted terminal (terminal identification information is stored in endpoint groups) of multiple data module, realizes the terminal quick access process to different pieces of information module in this way.
In technique scheme, it is preferable that also include: after obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server; After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate; According to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the private key that digital certificate is corresponding, data module is decrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, sending digital certificate corresponding for above-mentioned endpoint groups to terminal, data module is encrypted by terminal by private key.
In technique scheme, it is preferable that also include: after described data module is encrypted by the PKI corresponding according to described digital certificate, described data module is write the encryption identification to be encrypted by described PKI; Store described encryption identification, store described digital certificate simultaneously.
In this technical scheme, by after data module is encrypted, data module writes encryption identification, and store encryption identification and digital certificate, what have recorded data module in being used for the terminal encrypted adds confidential information, namely after once inserting, in terminal, the data module encrypted, can judge whether to have stored corresponding digital certificate according to encryption identification, and according to the private key that digital certificate is corresponding, data module is carried out fast decryption, it is manually entered password is decrypted thus avoiding user, or the step of digital certificate is sent to server request, thus improving the efficiency that digital certificate is decrypted, decrease network load and data exchange process.
In technique scheme, it is preferable that also include: after obtaining the instruction that described data module is decrypted, it is judged that whether described data module includes described encryption identification; When whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by whether data module is included encryption identification judge, and be decrypted according to decision structure, improve the efficiency that data module is decrypted, improve the experience of user.
As in figure 2 it is shown, the access system 200 of data module according to an embodiment of the invention, including: transmitting element 202, for, after obtaining the instruction that described data module is encrypted, sending the identification information of terminal identification information and data module to server; Acquiring unit 204, after the endpoint groups that identification information for determining described data module at described server is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends; Ciphering unit 206, for being encrypted described data module according to the PKI that described digital certificate is corresponding.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, digital certificate corresponding for above-mentioned endpoint groups is sent to terminal, data module is encrypted by terminal by PKI, by private key, data module is decrypted process, additionally, terminal can also when sending data to server, by encrypted private key to realize authentication process.
Wherein, server is in the process creating endpoint groups, pre-stored can by the terminal identification information of the terminal of users to trust, the identification information of each group of terminal identification information and data module corresponds to an endpoint groups (at least including a digital certificate), but, one terminal identification information can be pre-stored in multiple endpoint groups, namely, terminal can be divided into the trusted terminal (terminal identification information is stored in endpoint groups) of multiple data module, realizes the terminal quick access process to different pieces of information module in this way.
In technique scheme, it is preferable that described transmitting element 202 is additionally operable to: after obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server; Described acquiring unit 204 is additionally operable to: after described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate; The access system 200 of data module also includes: decryption unit 208, for described data module being decrypted according to the private key that described digital certificate is corresponding.
In this technical scheme, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the private key that digital certificate is corresponding, data module is decrypted, provide the access mode of a kind of data module easily, namely after server determines that terminal identification information belongs to the endpoint groups that the identification information of data module is corresponding, sending digital certificate corresponding for above-mentioned endpoint groups to terminal, data module is encrypted by terminal by private key.
In technique scheme, it is preferable that also include: writing unit 210, for, after described data module is encrypted by the PKI corresponding according to described digital certificate, described data module being write the encryption identification to be encrypted by described PKI; Memory element 212, is used for storing described encryption identification, is simultaneously used for storing described digital certificate.
In this technical scheme, by after data module is encrypted, data module writes encryption identification, and store encryption identification and digital certificate, what have recorded data module in being used for the terminal encrypted adds confidential information, namely after once inserting, in terminal, the data module encrypted, can judge whether to have stored corresponding digital certificate according to encryption identification, and according to the private key that digital certificate is corresponding, data module is carried out fast decryption, it is manually entered password is decrypted thus avoiding user, or the step of digital certificate is sent to server request, thus improving the efficiency that digital certificate is decrypted, decrease network load and data exchange process.
In technique scheme, it is preferable that also include: judging unit 214, for after obtaining the instruction that described data module is decrypted, it is judged that whether described data module includes described encryption identification; Described decryption unit 208 is additionally operable to: when whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
In this technical scheme, by whether data module is included encryption identification judge, and be decrypted according to decision structure, improve the efficiency that data module is decrypted, improve the experience of user.
As it is shown on figure 3, terminal 300 according to an embodiment of the invention, including the access system 200 of the data module as described in above-mentioned any one technical scheme.
Below in conjunction with Fig. 4 to Fig. 7, endpoint groups according to an embodiment of the invention and terminal are specifically described.
As shown in Figure 4, server side has pre-created endpoint groups, above-mentioned endpoint groups belongs to the believable group that user sets, ICCID information (IntegrateCircuitCardIdentity including a data module, integrated circuit card identification code) and the MEID information (MobileEquipmentIdentifier of multiple terminal (such as terminal A to terminal Z etc.), mobile EIC equipment identification code) or the information such as IMEI information (InternationalMobileEquipmentIdentity, international terminal recognition code).
As shown in Figure 5, server side has pre-created endpoint groups, above-mentioned endpoint groups belongs to the believable group that user sets, ICCID information (IntegrateCircuitCardIdentity including multiple data modules, integrated circuit card identification code) and the MEID information (MobileEquipmentIdentifier of multiple terminal (such as terminal A to terminal Z etc.), mobile EIC equipment identification code) or IMEI information (InternationalMobileEquipmentIdentity, international terminal recognition code) etc. information, namely multiple data module belongs to an endpoint groups, but the identification information of a pair terminal identification information and data module is only capable of corresponding to an endpoint groups, to ensure the reliability of the access process of data module.
As shown in Figures 4 to 7, ciphering process: after data module 601 is assembled in terminal, by obtaining the digital certificate that server provides, with the PKI corresponding according to digital certificate, data module is encrypted (in ciphering process such as Fig. 6 shown in 602), obtains the data module 603 through encryption, decrypting process: when terminal needs the data module 701 of encryption is decrypted (in decrypting process such as Fig. 7 shown in 702), a kind of mode is by obtaining the digital certificate that server provides, data module 701 is deciphered according to the private key in digital certificate, to obtain the data module 703 of deciphering, another way is the encryption identification by judging data module 701, namely when terminal judges storage has above-mentioned encryption identification, directly data module 701 is decrypted by the digital certificate according to pre-stored, the terminal of the second way is generally after data module 701 is encrypted, situation about again above-mentioned data module 701 being decrypted, improve the access efficiency of data module.
Describe technical scheme in detail above in association with accompanying drawing, it is contemplated that how to design a kind of easily, the technical problem of the access scheme of safer data module. Therefore, the present invention propose a kind of new easily, the access scheme of safer data module and a kind of terminal, by obtaining the server digital certificate (including one group of PKI and private key) according to terminal identification information and the identification information match of data module, and according to the PKI that digital certificate is corresponding, data module is encrypted, it is provided that the access mode of a kind of data module easily.
The foregoing is only the preferred embodiments of the present invention, be not limited to the present invention, for a person skilled in the art, the present invention can have various modifications and variations. All within the spirit and principles in the present invention, any amendment of making, equivalent replacement, improvement etc., should be included within protection scope of the present invention.

Claims (9)

1. the access method of a data module, it is characterised in that including:
After obtaining the instruction that described data module is encrypted, send the identification information of terminal identification information and data module to server;
After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends;
According to the PKI that described digital certificate is corresponding, described data module is encrypted.
2. the access method of data module according to claim 1, it is characterised in that also include:
After obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server;
After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate;
According to the private key that described digital certificate is corresponding, described data module is decrypted.
3. the access method of data module according to claim 2, it is characterised in that also include:
After described data module is encrypted by the PKI corresponding according to described digital certificate, described data module is write the encryption identification to be encrypted by described PKI;
Store described encryption identification, store described digital certificate simultaneously.
4. the access method of data module according to claim 3, it is characterised in that also include:
After obtaining the instruction that described data module is decrypted, it is judged that whether described data module includes described encryption identification;
When whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
5. the access system of a data module, it is characterised in that including:
Transmitting element, for, after obtaining the instruction that described data module is encrypted, sending the identification information of terminal identification information and data module to server;
Acquiring unit, after the endpoint groups that identification information for determining described data module at described server is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain the digital certificate that described server sends;
Ciphering unit, for being encrypted described data module according to the PKI that described digital certificate is corresponding.
6. the access system of data module according to claim 5, it is characterised in that
Described transmitting element is additionally operable to:
After obtaining the instruction that described data module is decrypted, send the identification information of terminal identification information and described data module to server;
Described acquiring unit is additionally operable to:
After described server determines the endpoint groups that the identification information of described data module is corresponding, and when described server judges that described terminal identification information belongs to the equipment identification information that described endpoint groups includes, obtain described digital certificate;
The access system of data module also includes:
Decryption unit, for being decrypted described data module according to the private key that described digital certificate is corresponding.
7. the access system of data module according to claim 6, it is characterised in that also include:
Writing unit, for, after described data module is encrypted by the PKI corresponding according to described digital certificate, writing the encryption identification to be encrypted by described PKI in described data module;
Memory element, is used for storing described encryption identification, is simultaneously used for storing described digital certificate.
8. the access system of data module according to claim 7, it is characterised in that also include:
Judging unit, for after obtaining the instruction that described data module is decrypted, it is judged that whether include described encryption identification in described data module;
Described decryption unit is additionally operable to:
When whether including described encryption identification in judging described data module, according to the private key that described digital certificate is corresponding, described data module is decrypted.
9. a terminal, it is characterised in that including: the access system of the data module as according to any one of claim 5 to 8.
CN201510364688.6A 2015-06-26 2015-06-26 Access method, system and the terminal of data module Active CN105635096B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510364688.6A CN105635096B (en) 2015-06-26 2015-06-26 Access method, system and the terminal of data module

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510364688.6A CN105635096B (en) 2015-06-26 2015-06-26 Access method, system and the terminal of data module

Publications (2)

Publication Number Publication Date
CN105635096A true CN105635096A (en) 2016-06-01
CN105635096B CN105635096B (en) 2018-09-14

Family

ID=56049592

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510364688.6A Active CN105635096B (en) 2015-06-26 2015-06-26 Access method, system and the terminal of data module

Country Status (1)

Country Link
CN (1) CN105635096B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113449337A (en) * 2021-06-22 2021-09-28 广州市资拓科技有限公司 Server hosting information processing method and system
CN113647080A (en) * 2019-04-15 2021-11-12 西门子股份公司 Providing digital certificates in a cryptographically secured manner

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030204720A1 (en) * 2002-04-26 2003-10-30 Isadore Schoen Secure instant messaging system using instant messaging group policy certificates
CN1925681A (en) * 2006-09-20 2007-03-07 北京太极联合实验室科技有限公司 End-to-end encrypting method and system based on mobile communication network
CN101025977A (en) * 2006-02-06 2007-08-29 索尼株式会社 Information processing apparatus and method, information recording medium and its manufacturing apparatus and method
CN101136742A (en) * 2007-04-09 2008-03-05 中兴通讯股份有限公司 Packet key synchronization, updating, and calibration method
CN103259651A (en) * 2013-05-30 2013-08-21 成都欣知科技有限公司 Encryption and decryption method and system of terminal data
CN104660567A (en) * 2013-11-22 2015-05-27 中国联合网络通信集团有限公司 D2D terminal access authentication method as well as D2D terminal and server

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030204720A1 (en) * 2002-04-26 2003-10-30 Isadore Schoen Secure instant messaging system using instant messaging group policy certificates
CN101025977A (en) * 2006-02-06 2007-08-29 索尼株式会社 Information processing apparatus and method, information recording medium and its manufacturing apparatus and method
CN1925681A (en) * 2006-09-20 2007-03-07 北京太极联合实验室科技有限公司 End-to-end encrypting method and system based on mobile communication network
CN101136742A (en) * 2007-04-09 2008-03-05 中兴通讯股份有限公司 Packet key synchronization, updating, and calibration method
CN103259651A (en) * 2013-05-30 2013-08-21 成都欣知科技有限公司 Encryption and decryption method and system of terminal data
CN104660567A (en) * 2013-11-22 2015-05-27 中国联合网络通信集团有限公司 D2D terminal access authentication method as well as D2D terminal and server

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113647080A (en) * 2019-04-15 2021-11-12 西门子股份公司 Providing digital certificates in a cryptographically secured manner
CN113647080B (en) * 2019-04-15 2024-02-20 西门子股份公司 Providing digital certificates in a cryptographically secure manner
US12088578B2 (en) 2019-04-15 2024-09-10 Siemens Aktiengesellschaft Cryptographically protected provision of a digital certificate
CN113449337A (en) * 2021-06-22 2021-09-28 广州市资拓科技有限公司 Server hosting information processing method and system

Also Published As

Publication number Publication date
CN105635096B (en) 2018-09-14

Similar Documents

Publication Publication Date Title
US7912224B2 (en) Wireless network system and communication method for external device to temporarily access wireless network
CN103201998B (en) For the protection of the data processing of the local resource in mobile device
US20050235143A1 (en) Mobile network authentication for protection stored content
US10009760B2 (en) Providing network credentials
US9730060B2 (en) Method and system for transfering profiles of authentication module
EP2879421B1 (en) Terminal identity verification and service authentication method, system, and terminal
CN101282218B (en) Method for ciphering and deciphering host computer and pickaback plane of split type terminal
CN101917710A (en) Method, system and related device for mobile internet encryption communication
CN104244237A (en) Data transmitting and receiving method, receiving and transmitting terminal and data transmitter-receiver set
CN102867157B (en) Mobile terminal and data guard method
CN101621794A (en) Method for realizing safe authentication of wireless application service system
EP2693784A1 (en) A method for accessing a service, corresponding first device, second device and system
CN103108327A (en) Method, device and system of verification of safety association between terminal equipment and user card
CN102866960A (en) Method for realizing encryption in storage card, decrypting method and device
CN104318286A (en) NFC label data management method and system and terminal
CN110856170B (en) Data transmission method and device and communication system of Internet of things
CN104660567A (en) D2D terminal access authentication method as well as D2D terminal and server
CN105187369B (en) A kind of data access method and device
CN105812334A (en) Network authentication method
CN104955029A (en) Address book protection method, address book protection device and communication system
KR101680536B1 (en) Method for Service Security of Mobile Business Data for Enterprise and System thereof
CN103577763A (en) Mobile terminal device with data protection function and data protection method
CN105635096A (en) Data module access method, system and terminal
CN104994498B (en) The method and system that a kind of terminal applies are interacted with mobile phone card application
KR101329789B1 (en) Encryption Method of Database of Mobile Communication Device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant