CN104022883B - A kind of personal information protection shopping at network technology based on logistics network - Google Patents
A kind of personal information protection shopping at network technology based on logistics network Download PDFInfo
- Publication number
- CN104022883B CN104022883B CN201410267620.1A CN201410267620A CN104022883B CN 104022883 B CN104022883 B CN 104022883B CN 201410267620 A CN201410267620 A CN 201410267620A CN 104022883 B CN104022883 B CN 104022883B
- Authority
- CN
- China
- Prior art keywords
- web
- exp
- buyer
- agent
- logistics
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 238000005516 engineering process Methods 0.000 title abstract description 7
- 238000000034 method Methods 0.000 claims abstract description 24
- 238000005303 weighing Methods 0.000 claims description 8
- 238000004806 packaging method and process Methods 0.000 claims description 7
- 238000007689 inspection Methods 0.000 claims description 3
- 238000012856 packing Methods 0.000 claims 3
- 238000004321 preservation Methods 0.000 claims 1
- 238000009826 distribution Methods 0.000 abstract description 3
- 238000011835 investigation Methods 0.000 abstract description 2
- 238000012795 verification Methods 0.000 description 5
- 238000004458 analytical method Methods 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 238000005336 cracking Methods 0.000 description 1
- 238000002716 delivery method Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000005242 forging Methods 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000003860 storage Methods 0.000 description 1
Landscapes
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
本发明涉及计算机技术领域中的网络信息安全,通过充分利用物流网络营业网点数量众多分布广泛,结合公民网络购物庞大需求,提出一种基于物流网络的公民个人信息保护网络购物技术。该技术借助于公钥密码体制实现充分保护公民在网络购物过程中的个人信息安全。本发明有助于快递物流企业进一步拓展业务范围,创造新的利润增长点,有助于更进一步推动网络商品的销售,有助于合法的特殊产品行业更好地将其销售业务融入到网络购物平台。本发明所提出的技术方案可以使得国家行政执法机构在必要时能够充分介入调查商品的销售信息与物流信息,不会对执法造成障碍,可以避免非法交易借助于网络销售平台来脱离法律监管。The invention relates to network information security in the field of computer technology. By making full use of the large number of logistics network business outlets and their wide distribution, combined with the huge demand of citizens for online shopping, a logistics network-based citizen personal information protection network shopping technology is proposed. This technology fully protects the personal information security of citizens in the online shopping process by means of the public key cryptography system. The invention helps express logistics enterprises to further expand their business scope, create new profit growth points, further promote the sales of online commodities, and help legal special product industries better integrate their sales into online shopping platform. The technical solution proposed by the invention can enable the national administrative law enforcement agency to fully intervene in the investigation of sales information and logistics information of commodities when necessary, without causing obstacles to law enforcement, and can prevent illegal transactions from being separated from legal supervision by means of online sales platforms.
Description
技术领域technical field
本发明涉及计算机技术领域中的网络信息安全,特别涉及采用信息安全技术充分利用物流网络营业网点分布广泛,结合公民网络购物庞大需求,在充分保护公民网络购物过程中个人信息安全的同时,为物流企业进一步拓展业务范围,创造新的利润增长点。The present invention relates to network information security in the field of computer technology, and in particular to the use of information security technology to make full use of the wide distribution of logistics network business outlets, combined with the huge demand of citizens for online shopping, while fully protecting the personal information security of citizens in the process of online shopping, for logistics The company further expands its business scope and creates new profit growth points.
背景技术Background technique
现有的网络购物网站(以下简称Web)要求凡是使用其网络购物平台进行商品买卖的用户,都必须在申请注册账号ID时,填写如个人姓名、家庭或者单位地址、手机号码等重要个人信息。对于合法运营的Web而言,由于受到国家法律法规的制约,它不会随意泄露注册用户的个人信息。但是当网购用户(以下简称买家)在Web某一店铺(以下简称卖家)选完商品生成购物订单并且成功付款之后,Web会将买家的姓名、电话、地址信息等显示给卖家。卖家在这一过程中收集了大量用户信息,甚至可以通过其所销售的商品分析洞察买家的个人隐私。现行的快递送货模式是当货物送达目的地之后,由快递物流企业(以下简称Exp)以电话或者短信方式通知买家取货的。卖家在发货时,Exp要求卖家将其个人信息以及买家的个人信息均填写在物流快递单上,Exp会因此收集数量庞大的买家与卖家个人信息,这些信息在某种程度上就变成了公开信息,信息的安全性和用途的合法性无法得到有效保障,公民的个人信息安全受到严重威胁,这就给非法人员利用这些信息以送快递的名义上门,或者货物含有违禁品等导致诈骗或者刑事案件的发生。Existing online shopping websites (hereinafter referred to as Web) require all users who use their online shopping platforms to buy and sell goods, to fill in important personal information such as personal name, family or work address, mobile phone number, etc. when applying for account ID registration. For a legally operating Web, due to the constraints of national laws and regulations, it will not disclose the personal information of registered users at will. However, when an online shopper (hereinafter referred to as the buyer) selects a product at a store on the Web (hereinafter referred to as the seller), generates a shopping order and pays successfully, the Web will display the buyer's name, phone number, address information, etc. to the seller. In this process, sellers collect a large amount of user information, and can even gain insight into the personal privacy of buyers through the analysis of the products they sell. The current express delivery mode is that after the goods arrive at the destination, the express logistics company (hereinafter referred to as Exp) notifies the buyer to pick up the goods by phone or text message. When the seller delivers the goods, Exp requires the seller to fill in their personal information and the buyer's personal information on the logistics express list. As a result, Exp will collect a huge amount of personal information of buyers and sellers, which will become to some extent If it becomes public information, the security of the information and the legitimacy of its use cannot be effectively guaranteed, and the security of citizens' personal information is seriously threatened. The occurrence of fraud or criminal cases.
由于这些重要个人信息的安全性与买家的切身利益密切相关,实际上很多买家除了Web以外不希望任何人知道自己的个人信息以及所购买的商品信息。这一方面会增加公民购物的心理安全负担,减少购物商品种类,限制了某些合法特殊商品的网络营销空间;另一方面也限制了安全警惕性高的人群采纳网络购物模式,从而也限制了普通合法商品通过网络平台被更广范的人群所接受。而Exp的利润直接挂钩于网购商品的订单数量,如果能够让更多的人毫无心理负担的接受网络购物模式,无疑会增加快递物流流量从而增加Exp的收入。同时如果能够帮助Exp在满足网购用户安全需求的同时,积极在现有物流网络中拓展新的业务空间,无疑将会是Web、卖家、买家和Exp多赢的局面。Because the safety of these important personal information is closely related to the vital interests of buyers, many buyers actually do not want anyone to know their personal information and the information of the purchased goods except the Web. On the one hand, this will increase the psychological security burden of citizens shopping, reduce the types of shopping products, and limit the online marketing space of some legal and special products; Ordinary legal products are accepted by a wider range of people through online platforms. The profit of Exp is directly linked to the number of orders for online shopping goods. If more people can accept the online shopping model without psychological burden, it will undoubtedly increase the flow of express logistics and increase the income of Exp. At the same time, if it can help Exp to actively expand new business space in the existing logistics network while meeting the security needs of online shopping users, it will undoubtedly be a win-win situation for the Web, sellers, buyers and Exp.
在网络购物过程中买家与卖家通常是异地的,而Exp一般拥有数量庞大、分布广泛的营业网点(以下简称Agent)。实际上Exp所拥有的众多Agent不仅仅可以从事快递物流,其营业网点的相对稳定性以及行业专业性又使其完全可以充当快递货物的代理签收角色。Web可以与国内各大快递物流公司Exp协商是否同意在其购物平台开通用户隐私保护购物模式亦即匿名购物代理签收模式,Web与Exp应在最大程度维护用户利益的原则下,签署服务质量标准,所有的货物签收、存放和领取都应做到有法可依有据可查,并且就各种可能出现的纠纷进行处理的方式和方法达成一致,同时Exp企业内部应该制定严格要求Agent代理点遵守的工作标准和服务规范。Web与Exp协商每笔成功的匿名购物代理签收费用彼此的分配比例,并且就该模式的收费标准和服务标准,以及使用该模式的买家需要遵守的服务约定在遵守国家关于快递物流行业相关法律法规规定条件下,向公众进行宣传说明。任何一个买家都可以通过咨询Exp来获取自己所希望的货物送达Agent地址信息,买家在Web购买商品之后,可以让Agent作为货物的代理签收方。In the process of online shopping, buyers and sellers are usually in different places, and Exp generally has a large number of widely distributed business outlets (hereinafter referred to as Agent). In fact, the many Agents owned by Exp can not only engage in express logistics, but the relative stability of its business outlets and industry professionalism make it fully capable of acting as an agent to sign for express goods. Web can negotiate with Exp, a major domestic express logistics company, whether to agree to open the user privacy protection shopping mode on its shopping platform, that is, the anonymous shopping agent sign-in mode. Web and Exp should sign service quality standards under the principle of maximally safeguarding the interests of users. All the signing, storage and collection of goods should be based on laws and evidence, and agreement should be reached on the methods and methods of handling various possible disputes. At the same time, Exp enterprises should formulate strict requirements for Agents to comply work standards and service specifications. Web and Exp negotiate the distribution ratio of each successful anonymous shopping agency fee, and the charging standards and service standards of this model, as well as the service agreements that buyers who use this model need to abide by, are in compliance with the relevant laws of the country on the express logistics industry Under the conditions stipulated by laws and regulations, publicity and explanations shall be made to the public. Any buyer can obtain the address information of the desired goods delivered to the Agent by consulting Exp. After the buyer purchases the goods on the Web, the Agent can be used as the agent to sign for the goods.
为了保证在互联网上进行电子交易的安全性和保密性,防范交易过程中可能出现的欺诈行为和抵赖行为等,Web和Exp必须拥有由数字证书认证中心颁发的数字证书,用于在互联网上向他人证实自己的身份。数字证书认证中心作为公正的第三方,具有权威性和可信性。数字证书是一种具有唯一性和可靠性的电子文档,通常采用公钥密码体制如RSA,椭圆曲线密码等。证书内包含用户的部分个人信息和他的公钥信息,同时还附有认证中心的签名信息。公钥密码体制的特点是数据的加密和解密需要使用两个不同的密钥,并且从其中一个密钥很难推出另外一个密钥。实际使用时只需严格保密其中之一,称之为私钥,用它进行解密和签名;另外一个则可以公开,称之为公钥,用于加密和验证签名。当发送一份秘密文件时,发送方使用接收方的公钥对数据进行加密,由于加密的信息只能被掌握私钥的真实接收方所解密,这样就实现了数据的保密传输。而当需要对一份文件或者消息进行签名时,发送方使用自己的私钥对数据进行加密,接收方则使用发送方的公钥进行解密,因为能够被成功解密的信息只能是真正掌握私钥的发送方加密的,通过这种方式发送方就实现了对数据的签名。In order to ensure the security and confidentiality of electronic transactions on the Internet, and to prevent fraud and denial that may occur during the transaction, Web and Exp must have digital certificates issued by a digital certificate certification center for sending to Others confirm their identity. As an impartial third party, the digital certificate certification center is authoritative and credible. A digital certificate is a unique and reliable electronic document, usually using a public key cryptosystem such as RSA, elliptic curve cryptography, etc. The certificate contains part of the user's personal information and his public key information, as well as the signature information of the certification authority. The characteristic of the public key cryptosystem is that data encryption and decryption need to use two different keys, and it is difficult to deduce the other key from one key. In actual use, you only need to keep one of them strictly confidential, called the private key, and use it to decrypt and sign; the other can be made public, called the public key, used to encrypt and verify the signature. When sending a secret document, the sender uses the receiver's public key to encrypt the data. Since the encrypted information can only be decrypted by the real receiver who has the private key, the confidential transmission of data is realized. When a document or message needs to be signed, the sender uses its own private key to encrypt the data, and the receiver uses the sender's public key to decrypt the data, because the information that can be successfully decrypted can only be the information that is truly mastered. It is encrypted by the sender of the key, and in this way the sender realizes the signature of the data.
发明内容Contents of the invention
本发明充分利用采用匿名购物模式时卖家、发货Exp、Agent彼此之间只掌握部分片面信息,例如卖家只知道买家的ID号,订单中所选取的商品以及买家所填写的Agent地址,除此之外对买家的其它个人信息一无所知;卖家所选取的发货Exp只知道卖家的个人信息和发货商品信息以及Agent的地址和联系方式,对买家的个人信息一无所知;Agent只知晓发货物流信息和物流单上卖家的个人信息,但是对买家的个人信息也一无所知,这些信息只需用于完成货物的运输和代理签收即可,即使他们合谋也不会形成对买家个人信息安全的侵害。The present invention makes full use of the fact that when the anonymous shopping mode is adopted, the seller, the delivery Exp, and the Agent only grasp part of one-sided information among each other, for example, the seller only knows the ID number of the buyer, the commodities selected in the order, and the Agent address filled in by the buyer. Other than that, the buyer’s other personal information is unknown; the delivery Exp selected by the seller only knows the seller’s personal information and delivery product information, as well as the Agent’s address and contact information, and has no information about the buyer’s personal information. Known; Agent only knows the delivery logistics information and the personal information of the seller on the logistics list, but does not know anything about the buyer’s personal information, which only needs to be used to complete the transportation of the goods and sign for the agent Collusion will not constitute a violation of the buyer's personal information security.
本发明提出的匿名购物模式简要流程为:买家在卖家店铺选取商品生成订单号为的订单并且付款之后,Web将进行加密和签名之后发送给Exp,用于与Exp共同见证此次匿名购物;然后卖家选取发货Exp,由发货Exp将物流单号为的货物快递至Agent;Agent代理签收之后,紧接着将物流单号为的货物到货信息上报至Exp;Exp对进行加密和签名之后发送至Web;Web通过查询匿名购物数据库可以获得与对应的以及买家信息,由于此时货物已经在Exp所属的某个Agent代理点验收签字,所以Web可以对的真伪性进行判别,从而可以识别重放攻击,若物流单号真实有效,则Web向买家手机发送物流单号为的货物到货通知,同时向买家的Web注册账号发放由其生成的取货凭证Ticket;买家在通过多重身份认证之后登录自己在Web的账号,在验证到货通知真伪的同时也可以得到Web生成的取货凭证Ticket;然后买家持到货通知和Ticket到Agent代理点付费取货;Agent将来自用户的Ticket上交至Exp;Exp通过对Ticket解密建立与之间的对应关系,Exp将Ticket转发给Web;Web通过解密Ticket可知买家已经向Agent提交Ticket并取走货物,自此成功完成此次匿名购物过程。The brief process of the anonymous shopping mode proposed by the present invention is as follows: the buyer selects the commodity in the seller’s store to generate an order number of After order and payment, Web will After encrypting and signing, send it to Exp to witness the anonymous shopping together with Exp; then the seller selects the delivery Exp, and the delivery Exp sends the logistics order number to The goods are delivered to the Agent; after the Agent signs for the receipt, the logistics order number will be The arrival information of the goods is reported to Exp; After being encrypted and signed, it is sent to the Web; the Web can obtain the relevant information by querying the anonymous shopping database. corresponding As well as the buyer's information, since the goods have been accepted and signed at an Agent point to which Exp belongs, the Web can to identify the authenticity of the data, so that replay attacks can be identified, if the logistics order number If it is true and effective, the Web will send the logistics tracking number to the buyer's mobile phone as Notification of the arrival of the goods, and at the same time, the buyer's Web registration account is issued to the buyer's Web registration account to generate the receipt certificate Ticket; after the buyer has passed the multi-identity authentication, he logs in to his account on the Web, and can verify the authenticity of the arrival notification and at the same time Get the pickup certificate Ticket generated by the Web; then the buyer takes the arrival notice and the Ticket to the Agent agency point to pay for the pickup; the Agent submits the Ticket from the user to Exp; Exp decrypts the Ticket to establish and According to the corresponding relationship between them, Exp forwards the Ticket to the Web; the Web decrypts the Ticket to know that the buyer has submitted the Ticket to the Agent and took away the goods, and the anonymous shopping process has been successfully completed since then.
在匿名购物过程中,商品的订单号在被Web用Exp的公钥加密之后再用自己的私钥进行签名,然后Web将之提交给Exp,这样做的目的在于,虽然Exp不必知晓买家的个人信息,但是为了保障Exp的权益,在出现纠纷时便于Exp了解所代理签收货物的详细商品信息,他可以使用订单号到Web的匿名购物数据库中查询该订单号除买家信息之外的详细商品信息,同时可以让Web和Exp共同见证此次匿名购物过程,防止货物被Agent私自截留以及解决其他各种可能出现的纠纷。During anonymous shopping, the order number of the item After being encrypted by Web with Exp’s public key, it is signed with its own private key, and then Web submits it to Exp. The purpose of this is that although Exp does not need to know the buyer’s personal information, in order to protect the rights and interests of Exp, In the event of a dispute, it is convenient for Exp to know the detailed commodity information of the goods signed by the agent, he can use the order number Go to the anonymous shopping database of the Web to query the detailed commodity information of the order number except for the buyer information. At the same time, the Web and Exp can jointly witness the anonymous shopping process, prevent the goods from being intercepted by the Agent privately, and solve other possible problems. dispute.
为了防止计算机黑客破解买家的账号信息,同时也为了预防手机黑客软件非法获取买家的短信信息,通知短信内容和取货凭证Ticket应分别在买家手机和买家在Web的账号内独立存放。买家必须经历账户密码、数字证书、手机验证等多重身份认证才可以登录Web账号获取由Web生成的取货凭证Ticket,买家持到货通知和Ticket到Agent付费取货,这样也可以解决现行的快递取件方式存在着取件凭证单一,检查取件人身份不严格,货物易被冒领等问题。即使黑客破解买家的账号密码获取得到货物的物流单号以及到达的Agent地址信息,但是他不能获取用户的手机就不能得到Ticket,因为买家数字证书的安装必须通过买家手机验证才可以进行。如果买家手机中的黑客软件非法窃取了买家手机短信中的物流单号,但他并不知道货物到达了那个Agent,更得不到买家的取货凭证Ticket也就无法取货。In order to prevent computer hackers from cracking the buyer's account information, and to prevent mobile phone hackers from illegally obtaining the buyer's SMS information, the content of the notification message and the receipt of the goods Ticket should be stored separately in the buyer's mobile phone and the buyer's account on the Web. . Buyers must go through multiple identity authentications such as account passwords, digital certificates, and mobile phone verifications before they can log in to their web accounts to obtain the receipt voucher generated by the web. There are problems such as a single pick-up certificate, a loose check of the identity of the pick-up person, and easy fraudulent claim of the goods in the express delivery method. Even if a hacker cracks the buyer's account password to obtain the goods' logistics order number and the arrival Agent address information, he cannot get the Ticket if he cannot obtain the user's mobile phone, because the installation of the buyer's digital certificate must be verified by the buyer's mobile phone. . If the hacker software in the buyer's mobile phone illegally steals the logistics order number in the buyer's mobile phone text message, but he does not know which Agent the goods have arrived at, and he cannot pick up the goods without getting the buyer's pick-up certificate Ticket.
为了抵御攻击者伪造取货凭证Ticket来进行货物冒领或者使用旧的取货凭证Ticket来进行重复取货,物流单号只有被Web进行了真伪性验证之后,才由Web发给买家Ticket,Ticket是由Web签名生成的,而这些签名信息是攻击者无法伪造的。Agent将买家取货凭证Ticket提交至Exp之后,Exp只有通过对Ticket进行解密才可以建立物流单号与订单号之间的对应关系,并且得到Web的签名结果,完成此次匿名购物。如果卖家与Agent合谋,Exp可以得知物流单号与订单号之间的对应关系,但是由于他无法仿冒Web的签名,也就无法私自截留货物。In order to prevent attackers from forging the delivery voucher Ticket to claim the goods or using the old delivery voucher Ticket to repeatedly pick up the goods, the logistics order number Only after being verified by the Web, the Web will send the ticket to the buyer. The Ticket is generated by the Web signature, and the signature information cannot be forged by the attacker. After the Agent submits the buyer's pick-up certificate Ticket to Exp, Exp can only create a logistics order number by decrypting the Ticket with order number The corresponding relationship between them, and get the signature result of the Web, and complete this anonymous shopping. If the seller conspires with Agent, Exp can know the tracking number with order number However, since he cannot counterfeit the signature of the Web, he cannot intercept the goods privately.
匿名购物过程中的每一步都经过相应安全技术处理,具有保密性、安全性和不可抵赖性,一旦出现纠纷,这些加密信息可以作为证据使用。在代理签收费用的付费方式上,必须是Agent代理签收以后,用户到Agent取货之后再付费用的方式。若预付费,则Agent有可能会因为已经得到了代理费用而故意拒签收货物。Every step in the anonymous shopping process is processed by corresponding security technology, which has confidentiality, security and non-repudiation. In case of disputes, these encrypted information can be used as evidence. In terms of the payment method of the agent's signing fee, it must be the way that the user pays after the agent signs for the receipt and the user picks up the goods from the agent. If it is paid in advance, the Agent may deliberately refuse to sign for the goods because it has already received the agency fee.
本发明将匿名购物模式中所有的与数据加密和签名相关的专业性很强的数据处理过程全部限制在Web与Exp之间,对于Exp的各地代理点Agent和买家而言他们感觉不到这些过程的存在,买家取货过程和普通快递取货过程几乎一致,不会给他们带来不便。在充分兼容现有网络购物模式的同时,能够让买家在购物时自主选取适合自己安全性需求的购物物流方案,有助于充分保护网购用户的个人信息安全,有助于物流企业进一步拓展业务范围,创造新的利润增长点,在此基础上有助于更进一步推动网络商品的销售,有助于合法的特殊产品行业更好地将其销售业务融入到网络购物平台。由于与订单相关的买家、卖家、商品、物流等所有信息都是记录在Web的数据库中的,所以一旦政府执法机构需要介入某项商品的销售调查,就可以从网站数据库中获取与之相关的所有详细信息,不会对执法造成任何障碍,这样可以避免非法交易借助于购物网站销售平台来脱离法律监管。The present invention limits all the highly specialized data processing processes related to data encryption and signature in the anonymous shopping mode between the Web and Exp, and for the agents and buyers of Exp everywhere, they do not feel these With the existence of the process, the buyer's pick-up process is almost the same as the ordinary express pick-up process, which will not cause inconvenience to them. While fully compatible with the existing online shopping model, it allows buyers to independently choose a shopping logistics solution that suits their own security needs when shopping, which helps to fully protect the personal information security of online shoppers and helps logistics companies to further expand their business range, creating new profit growth points, and on this basis, it will help further promote the sales of online commodities, and help the legal special product industry to better integrate its sales business into online shopping platforms. Since all information related to the order, such as buyers, sellers, commodities, and logistics, is recorded in the Web database, once government law enforcement agencies need to intervene in the sales investigation of a certain commodity, they can obtain information related to it from the website database. All the detailed information will not cause any obstacles to law enforcement, so that illegal transactions can be avoided from legal supervision by means of shopping website sales platforms.
具体实施方式detailed description
在本专利申请说明书中,符号表示某一种国家认可的商业公钥密码体制数据加密算法;数学公式 表示使用作为加密密钥,将明文加密为密文;符号和分别表示Exp的公钥和私钥,和分别表示Web的公钥和私钥;符号表示一件采用匿名购物模式的商品订单号,符号表示该订单商品的发货物流单号,符号Ticket表示买家的取货凭证;符号“”表示将其前后两个消息顺序拼接为一个新的消息。In this patent application description, the symbol Indicates a certain nationally recognized commercial public key cryptosystem data encryption algorithm; mathematical formula express use As an encryption key, the plaintext encrypted as ciphertext ;symbol with represent the public key and private key of Exp respectively, with Represents the public and private keys of the Web, respectively; the symbol Indicates the order number of a product in anonymous shopping mode, the symbol Indicates the delivery logistics tracking number of the order product, and the symbol Ticket indicates the buyer's pick-up certificate; the symbol " "Indicates that the two messages before and after it are sequentially spliced into a new message.
(1)买家在Web平台完成商品挑选并且成功付款之后订单号生效,买家可以选取匿名购物模式,然后从与Web合作的Exp中选取自己意向的一个Agent作为货物的代理签收方。买家可以要求卖家发货时必须拍下快递件的外包装图片以及称重图片并且在物流单上注明称重重量,等待卖家发货。(1) The order number after the buyer completes the product selection on the web platform and pays successfully When it takes effect, buyers can choose the anonymous shopping mode, and then choose an Agent of their own intention from the Exp that cooperates with the Web as the agent to sign for the goods. The buyer can require the seller to take pictures of the outer packaging and weighing pictures of the courier and indicate the weighing weight on the logistics bill when delivering the goods, waiting for the seller to deliver.
(2)Web使用Exp的公钥将订单号加密之后再使用自己的私钥对之进行签名生成密文,然后将密文发送给Exp。密文的作用在于由Web告知Exp有一个订单号为的货物即将发往Exp所属的某个Agent,从而Exp知道这样一件代理签收业务的存在,这样做的目的在于用于防止Agent私自将货物截留。Exp收到密文之后可以使用Web的公钥将之解密获得,然后使用自己的私钥进一步解密获得,Exp将密文反馈给Web保存,作为Exp收到来自Web的信息之后的应答信息。Exp可以使用到Web的数据库中查询该订单的商品信息,获得对即将发生的匿名购物过程的部分知情权以维护自己的权益,但是Web应阻止其查阅买家的信息。此时Exp并不知道订单号与物流单号之间的对应关系。(2) Web uses Exp's public key will order number After encryption, use your own private key Sign it to generate ciphertext , and then the ciphertext Send to Exp. ciphertext The role of is to tell Exp by the Web that there is an order number of The goods of are about to be sent to an Agent to which Exp belongs, so that Exp knows the existence of such an agency signing business, and the purpose of doing this is to prevent Agent from intercepting the goods without permission. Exp received the ciphertext The public key of the web can then be used decrypt it to get , then use your own private key further decrypted to obtain , Exp converts the ciphertext Feedback to Web Save, Receive information from the Web as an Exp subsequent response information. Exp can use Go to the Web database to query the product information of the order, and obtain part of the right to know about the upcoming anonymous shopping process to protect their own rights, but the Web should prevent them from viewing the buyer's information. At this time Exp does not know the order number and tracking number Correspondence between.
(3)卖家将订单商品妥善包装后选取发货Exp,发货Exp与买家所选择的代理签收Exp可以相同也可以不同,在发货Exp物流单上填写买家在订单中指定的Agent的地址和联系方式作为收货人信息,并在物流单上填写包装后货物的重量,对快递件包装与称重结果进行拍照。卖家应及时在Web上填写订单号为的货物的发货物流单号,同时应将发货相关照片通过购物交流软件发给买家一份复件,以便于买家对照验收货物。(3) The seller selects the delivery Exp after properly packaging the order goods. The delivery Exp and the buyer's selected agent sign-in Exp can be the same or different. Fill in the delivery Exp logistics list with the Agent specified by the buyer in the order The address and contact information are used as the consignee's information, and the weight of the packaged goods is filled in the logistics bill, and the packaging and weighing results of the express package are photographed. The seller should promptly fill in the order number on the Web as The delivery logistics order number of the goods , and at the same time, a copy of the delivery-related photos should be sent to the buyer through the shopping communication software, so that the buyer can check and accept the goods.
(4)发货Exp将货物快递至代理点Agent之后,由Agent的相关责任人根据服务标准要求检查货物外包装,并称重检查货物重量是否与物流单标明重量相差在规定范围内,拍照存档后签收,存档照片用于货物签收纠纷时仲裁用,同时Agent将物流单号为的货物到货通知发送至Exp。否则Agent拒签,拒签意味着此次匿名购物过程将得不到买家支付的代理费用,但是为买家负责也维护提升了Agent的服务信誉。(4) After the delivery Exp expresses the goods to the agent point, the relevant person in charge of the Agent will check the outer packaging of the goods according to the service standard requirements, and weigh the goods to check whether the difference between the weight of the goods and the weight indicated on the logistics list is within the specified range, and take photos for archiving After the receipt, the archived photos are used for arbitration when the goods are signed for disputes. The arrival notification of the goods is sent to Exp. Otherwise, the agent refuses the visa, which means that the anonymous shopping process will not get the agency fee paid by the buyer, but being responsible for the buyer also maintains and improves the agent's service reputation.
(5)Exp将物流单号使用Web的公开钥加密之后再用自己的私钥签名生成,将发送给Web,此时Exp尚不能确定订单号与物流单号之间的对应关系。(5) Exp will send the logistics order number Using the public key of the web After encryption, use your own private key signature generation ,Will Send to the Web, at this time Exp can not determine the order number and tracking number Correspondence between.
(6)Web收到来自Exp的消息之后,可以使用Exp的公开钥将解密获取,然后Web再使用只有自己掌握的私钥解密获取其中的内容即物流单号。Web使用作为关键字到采用匿名服务的订单数据库查找与相对应的订单号和买家注册账号ID以及电话号码,由于此时货物已经在代理点Agent签收,所以Web可以验证该的真实有效性以防止重放攻击。如果该为旧的物流单号或者无相应签收记录,Web将之返回给Exp让其重新核实。如果Web对该核实无误,则Web生成密文反馈给Exp保存,作为Web收到来自Exp的信息之后的应答信息。此时Web知晓物流单号为的货物其订单号为,已经送达Agent处,正在等待买家取货。(6) Web receives the message from Exp After that, Exp's public key can be used Will Decrypt to get , and then the Web uses the private key that only it owns decrypt Obtain the content in it, that is, the logistics order number . Web use As a key to the order database using an anonymous service lookup and corresponding order number Register the account ID and phone number with the buyer. Since the goods have been signed for by the Agent at this time, the Web can verify the real validity to prevent replay attacks. if the If it is an old tracking number or there is no corresponding receipt record, Web will return it to Exp for re-verification. If the Web should If the verification is correct, the Web generates ciphertext Feedback to Exp to save, Received information from Exp as Web subsequent response information. At this time, the Web knows that the logistics tracking number is The goods whose order number is , has been delivered to the Agent and is waiting for the buyer to pick up the goods.
(7)Web向买家手机发送物流单号为的货物到货通知,同时Web 生成,将该Ticket存放在买家的Web账号内,从方便快捷的角度来看,Ticket可以以条形码或者二维码的方式生成,用作买家到Agent的取货凭证,Web同时保存消息。(7) The Web sends the tracking number to the buyer's mobile phone as The arrival notification of the goods, and at the same time the Web generates , and store the Ticket in the buyer's Web account. From the perspective of convenience and speed, the Ticket can be generated in the form of a barcode or a QR code, which is used as a proof of delivery from the buyer to the Agent, and the Web saves the message at the same time. .
(8)买家收到来自Web的通知信息后,必须经过密码、数字证书、手机等多重身份认证才可以登录自己在Web的账号,买家可以通过检查卖家发货物流信息来辨别物流单号的真伪以防止短信欺诈,如果为真,买家同时可以得到Web生成的取货凭证Ticket。(8) After the buyer receives the notification information from the Web, he must pass multiple authentications such as password, digital certificate, and mobile phone to log in to his account on the Web. The buyer can identify the logistics order number by checking the seller's delivery logistics information To prevent SMS fraud, if it is true, the buyer can also get the ticket generated by the Web.
(9)用户持Ticket到自己知道的Agent代理点,告知手机短信中的,然后将Ticket提交给Agent。Agent将来自买家的Ticket提交给Exp,Exp用Web的公钥将Ticket解密获取,用自己的私钥进一步解密可以得知订单号与物流单号之间的对应关系,Exp到自己的数据库中查询是否存在与相同的历史记录以防止重放攻击。如果全新则Exp向代理点Agent返回,由Agent验证Exp返回的与买家手机中的是否一致。Exp将Ticket存入数据库以备可能遇到的纠纷处理,同时Exp将Ticket转发给Web。由于Exp只能从买家那获取Web签名的Ticket,进而才能建立订单号与物流单号之间的对应关系,完成此次交易。如果卖家与Exp合谋,Exp从卖家处得知物流单号与订单号对应,但是由于他们均无法仿冒Web的签名,所以只能使用旧的Ticket通过重放攻击来转发给Web,当Web对Ticket进行解密并进行重放验证就可以发现Ticket的真伪。若Ticket为真,Web就可以知晓买家已经将Ticket交予Agent并且取走货物。(9) The user takes the Ticket to the Agent point he knows, and informs the , and then submit the Ticket to the Agent. Agent submits the Ticket from the buyer to Exp, and Exp uses the public key of the Web Decrypt the Ticket to get it , with your own private key Further decryption can know the order number and tracking number Correspondence between, Exp to its own database to query whether there is a relationship with Same history to prevent replay attacks. if If it is new, Exp returns to the agent point Agent , returned by the Agent verification Exp with the buyer's phone Is it consistent. Exp stores the Ticket in the database for handling possible disputes, and at the same time Exp forwards the Ticket to the Web. Since Exp can only obtain a Web-signed Ticket from the buyer, and then create an order number and tracking number The corresponding relationship between them completes the transaction. If the seller conspires with Exp, Exp will learn the tracking number from the seller with order number Correspondingly, but since none of them can counterfeit the signature of the Web, they can only use the old Ticket to forward it to the Web through a replay attack. When the Web decrypts the Ticket and performs replay verification, the authenticity of the Ticket can be found. If the Ticket is true, the Web can know that the buyer has given the Ticket to the Agent and took the goods.
(10)Agent核查买家手机中的和Exp返回的一致时,将物流单号为的货物交给买家检查,如果没有问题则买家支付费用并取走货物,此次匿名购物过程即成功完成,否则Web协商Exp就买家与Agent之间的纠纷按照服务标准和工作规范进行处理。(10) Agent checks the buyer's mobile phone and Exp returns the When consistent, the logistics order number is The goods will be handed over to the buyer for inspection. If there is no problem, the buyer will pay the fee and take the goods away. The anonymous shopping process will be completed successfully. Otherwise, the dispute between the buyer and the Agent will be negotiated according to the service standards and work specifications. deal with.
(11)退换货物时,买家首先在Web就某项订单商品点击匿名退换货申请,等待卖家同意。买家向Web支付匿名退换货代理费用之后,买家在自己所选的快递物流公司发货物流单上将由Web所提供的匿名退换货客服地址和电话填写为发货人信息,然后准确填写卖家的地址与电话作为收件人信息,并应对货物外包装和称重结果进行拍照存档。买家发货之后,应及时在Web的购物平台上填写所发货物的物流信息。由于Web知晓买家、卖家、退换货申请的订单号、物流单号等所有信息,如果货物在运输过程发生问题,它均可以及时通知到双方,此时不再需要Exp和Agent的参与。(11) When returning or exchanging goods, the buyer first clicks on the anonymous return and exchange application for an order product on the Web, and waits for the seller's approval. After the buyer pays the anonymous return agency fee to Web, the buyer fills in the anonymous return customer service address and phone number provided by Web as the consignor's information on the shipping logistics list of the express logistics company he selected, and then accurately fills in the seller's information. The address and phone number of the goods shall be used as the recipient information, and the outer packaging and weighing results of the goods shall be photographed and archived. After the buyer delivers the goods, he should fill in the logistics information of the goods sent on the Web shopping platform in time. Since the Web knows all the information about the buyer, seller, order number of the return application, logistics order number, etc., if there is a problem with the goods during transportation, it can notify both parties in time, and the participation of Exp and Agent is no longer required.
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410267620.1A CN104022883B (en) | 2014-06-17 | 2014-06-17 | A kind of personal information protection shopping at network technology based on logistics network |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410267620.1A CN104022883B (en) | 2014-06-17 | 2014-06-17 | A kind of personal information protection shopping at network technology based on logistics network |
Publications (2)
Publication Number | Publication Date |
---|---|
CN104022883A CN104022883A (en) | 2014-09-03 |
CN104022883B true CN104022883B (en) | 2017-03-15 |
Family
ID=51439467
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201410267620.1A Expired - Fee Related CN104022883B (en) | 2014-06-17 | 2014-06-17 | A kind of personal information protection shopping at network technology based on logistics network |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN104022883B (en) |
Families Citing this family (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP3229203B1 (en) * | 2015-02-28 | 2020-11-11 | Huawei Technologies Co., Ltd. | Information protection method, server and terminal |
CN104809156B (en) * | 2015-03-24 | 2019-02-01 | 北京锐安科技有限公司 | The method and apparatus of taking of evidence information |
CN113850610B (en) * | 2015-03-26 | 2025-05-13 | 创新先进技术有限公司 | Method, device and server for identifying false transactions based on logistics data |
DE102015110366A1 (en) * | 2015-06-26 | 2016-12-29 | Deutsche Telekom Ag | Message delivery and rating system |
CN105740747B (en) * | 2016-02-02 | 2018-05-22 | 浙江科技学院 | A kind of express delivery sort process Weight Watcher method and system based on Image Acquisition |
CN105719120B (en) * | 2016-04-25 | 2019-11-15 | 成都木马人网络科技有限公司 | A method of encryption express delivery list privacy information |
CN105956804A (en) * | 2016-04-29 | 2016-09-21 | 河南理工大学 | Safe order system based on digital certificate |
CN107609879B (en) * | 2016-07-07 | 2021-07-02 | 阿里巴巴集团控股有限公司 | Method, device and system for identifying stolen logistics information |
CN107395698A (en) * | 2017-07-06 | 2017-11-24 | 南京合荣欣业金融软件有限公司 | A kind of express delivery receiving/transmission method and system for protecting individual privacy |
CN108665207A (en) * | 2018-04-24 | 2018-10-16 | 中冶京诚工程技术有限公司 | Pipe gallery logistics operation system and method based on artificial intelligence |
CN109492427A (en) * | 2018-10-17 | 2019-03-19 | 航天信息股份有限公司 | Online shopping method and device |
CN110224989B (en) * | 2019-05-10 | 2022-01-28 | 深圳壹账通智能科技有限公司 | Information interaction method and device, computer equipment and readable storage medium |
CN110503443A (en) * | 2019-08-28 | 2019-11-26 | 深圳森林云科技有限公司 | A logistics data processing device and method |
CN112150253A (en) * | 2020-10-16 | 2020-12-29 | 郇延强 | An online purchasing method and system |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101833718A (en) * | 2009-03-13 | 2010-09-15 | 孟仁兴 | Method and system for resisting denying |
CN102044037A (en) * | 2010-12-22 | 2011-05-04 | 北京工业大学 | Method for protecting purchaser privacy information in electronic commerce |
CN102324115A (en) * | 2011-05-16 | 2012-01-18 | 黄能耿 | Computer remotely-controlled postal-parcel posting and delivering method and system |
CN102456206A (en) * | 2010-10-28 | 2012-05-16 | 阿里巴巴集团控股有限公司 | Method and system for protecting user information security and electronic commerce platform system |
CN103106611A (en) * | 2013-02-20 | 2013-05-15 | 姚丰卫 | Network platform system |
CN103810580A (en) * | 2012-11-13 | 2014-05-21 | 中兴通讯股份有限公司 | Method and device for signing for goods and wireless signing-for terminal |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2002109409A (en) * | 2000-09-29 | 2002-04-12 | Fujitsu Ltd | Electronic commerce method in electronic commerce system |
-
2014
- 2014-06-17 CN CN201410267620.1A patent/CN104022883B/en not_active Expired - Fee Related
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101833718A (en) * | 2009-03-13 | 2010-09-15 | 孟仁兴 | Method and system for resisting denying |
CN102456206A (en) * | 2010-10-28 | 2012-05-16 | 阿里巴巴集团控股有限公司 | Method and system for protecting user information security and electronic commerce platform system |
CN102044037A (en) * | 2010-12-22 | 2011-05-04 | 北京工业大学 | Method for protecting purchaser privacy information in electronic commerce |
CN102324115A (en) * | 2011-05-16 | 2012-01-18 | 黄能耿 | Computer remotely-controlled postal-parcel posting and delivering method and system |
CN103810580A (en) * | 2012-11-13 | 2014-05-21 | 中兴通讯股份有限公司 | Method and device for signing for goods and wireless signing-for terminal |
CN103106611A (en) * | 2013-02-20 | 2013-05-15 | 姚丰卫 | Network platform system |
Also Published As
Publication number | Publication date |
---|---|
CN104022883A (en) | 2014-09-03 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN104022883B (en) | A kind of personal information protection shopping at network technology based on logistics network | |
US11082234B2 (en) | Method and system for privacy-preserving social media advertising | |
US7353532B2 (en) | Secure system and method for enforcement of privacy policy and protection of confidentiality | |
US7200749B2 (en) | Method and system for using electronic communications for an electronic contract | |
CN110719176A (en) | Blockchain-based logistics privacy protection method, system and readable storage medium | |
Antoniou et al. | E-commerce: protecting purchaser privacy to enforce trust | |
CN105373955B (en) | Digital asset processing method and device based on multiple signatures | |
EP1593100B1 (en) | Method for ensuring privacy in electronic transactions with session key blocks | |
US6363365B1 (en) | Mechanism for secure tendering in an open electronic network | |
US20140372752A1 (en) | Method and database system for secure storage and communication of information | |
Ray et al. | A fair-exchange e-commerce protocol with automated dispute resolution | |
AU2001287164A1 (en) | Method and system for using electronic communications for an electronic contact | |
CN110390207A (en) | A method for protecting the privacy of personal information in online shopping and a delivery method | |
CN105956804A (en) | Safe order system based on digital certificate | |
Patro et al. | Security issues over E-commerce and their solutions | |
CN115775181A (en) | A blockchain-based fair commodity transaction privacy protection method | |
CN111369251B (en) | Block chain transaction supervision method based on user secondary identity structure | |
JP2008529186A (en) | System and method for registration control | |
JPH10105603A (en) | Information communication method and device | |
KR100733129B1 (en) | Secure payment processing system and method | |
Rattan et al. | E-Commerce Security using PKI approach | |
JP2002215935A (en) | Electronic commerce system | |
Billah | Islamic Fin-Tech: Digital Financial Products | |
CN108460662A (en) | A kind of electronic commerce transaction system | |
Sharma et al. | An approach to risk management for e-commerce |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20170315 Termination date: 20200617 |
|
CF01 | Termination of patent right due to non-payment of annual fee |