[go: up one dir, main page]

CN109714444A - Registration management method, system and node - Google Patents

Registration management method, system and node Download PDF

Info

Publication number
CN109714444A
CN109714444A CN201811475593.1A CN201811475593A CN109714444A CN 109714444 A CN109714444 A CN 109714444A CN 201811475593 A CN201811475593 A CN 201811475593A CN 109714444 A CN109714444 A CN 109714444A
Authority
CN
China
Prior art keywords
registration
oid
node
child node
security authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201811475593.1A
Other languages
Chinese (zh)
Inventor
马文静
韩福军
杨硕
尹国伟
康春鹏
蔺彩霞
张领先
卢宪祺
寇远涛
池程
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Electronics Standardization Institute
Original Assignee
China Electronics Standardization Institute
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Electronics Standardization Institute filed Critical China Electronics Standardization Institute
Priority to CN201811475593.1A priority Critical patent/CN109714444A/en
Publication of CN109714444A publication Critical patent/CN109714444A/en
Pending legal-status Critical Current

Links

Landscapes

  • Information Transfer Between Computers (AREA)

Abstract

A method, a system and a node for registration management comprise: after the father node authorizes and authenticates the child nodes, distributing corresponding child node identifiers for the child nodes; the child node may continue to assign (OID) the registration object for which registration is applied based on assigning the child node OID identifier. The embodiment of the invention realizes the OID distribution through the authorization node and perfects the function of OID registration management.

Description

一种注册管理的方法、系统及节点A method, system and node for registration management

技术领域technical field

本文涉及但不限于信息处理技术,尤指一种注册管理的方法、系统及节点。This article involves but is not limited to information processing technology, especially a method, system and node for registration management.

背景技术Background technique

随着信息技术的不断发展,计算机硬件设备性能得到了快速提升、网络通讯能力也在不断增强,这使得传统封闭的行业具备了“数字化”和“网络化”发展的基础条件,能够实现各类异构系统的网络互联和远程协同发展。在此阶段中,面向过程的系统开发方式逐步被面向对象的系统开发方式所取代。对象是程序设计过程中的基本元素,以“对象”为中心的设计开发方式将实现数据和操作的封装和规范化处理,保护数据、方法的可重构性和在复杂处理过程中的精确操作。典型的面向对象的程序设计语言,例如Java和C#,利用对象(封装了数据和数据处理的代码模块)模拟客观世界的对象,利用对象间的相互联系和作用模拟客观世界对象间的相互联系和作用,进而优化了信息系统开发方式,避免程序过大造成的代码混乱,降低代码维护成本,有效提高多人协同编码、异构系统之间协同工作的效率。With the continuous development of information technology, the performance of computer hardware equipment has been rapidly improved, and the network communication capabilities have also been continuously enhanced, which makes the traditional closed industries have the basic conditions for "digital" and "networked" development, and can realize various Network interconnection and remote coordinated development of heterogeneous systems. In this stage, the process-oriented system development method is gradually replaced by the object-oriented system development method. Objects are the basic elements in the program design process. The "object"-centered design and development method will realize the encapsulation and normalization of data and operations, and protect the reconfigurability of data and methods, as well as accurate operations in complex processing. Typical object-oriented programming languages, such as Java and C#, use objects (code modules that encapsulate data and data processing) to simulate objects in the objective world, and use the interrelationships and functions between objects to simulate the interrelationships and interactions between objects in the objective world. It optimizes the development method of the information system, avoids the code confusion caused by the program is too large, reduces the cost of code maintenance, and effectively improves the efficiency of multi-person collaborative coding and collaborative work between heterogeneous systems.

在此背景下,对象标识符(OID,object identifier)标识体系应运而生,OID是国际标准化组织(ISO)/国际电工委员会(IEC)、国际电信联盟(ITU)联合推动的全球化标识体系,用以标识“通信和信息处理世界中的任何事物”,为网络中各类信息处理对象提供全球唯一“标识身份证”。目前,OID标识体系发展成熟,有效地实现了异构信息系统之间的网络互联和信息互通融合。In this context, the object identifier (OID, object identifier) identification system came into being. OID is a global identification system jointly promoted by the International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) and the International Telecommunication Union (ITU). It is used to identify "anything in the world of communication and information processing", and to provide a globally unique "identification ID card" for various information processing objects in the network. At present, the OID identification system is mature, effectively realizing the network interconnection and information interoperability and integration between heterogeneous information systems.

为更好地促进OID标识体系的发展,各个国家都在研制开发本国的OID标识注册管理系统,但存在着诸多技术缺陷,难以满足当前信息技术产业对于OID标识技术的应用需求;例如、法国的一家电信公司,研制开发了OID repository注册管理系统,该系统仅能够面向各类组织机构、标准等对象提供注册管理功能。又或者,我国研制开发的CNOID注册管理系统,该系统相比于OID repository系统,增加了新闻发布、OID注册公示和发布等功能,增加了OID的审查、审批流程。In order to better promote the development of the OID identification system, various countries are developing their own OID identification registration management systems, but there are many technical defects, which make it difficult to meet the application needs of the current information technology industry for OID identification technology; A telecommunications company has developed an OID repository registration management system, which can only provide registration management functions for various organizations, standards and other objects. Or, the CNOID registration management system developed in our country, compared with the OID repository system, the system adds functions such as news release, OID registration publicity and release, and increases the OID review and approval process.

上述方案,仅能够面向各类组织机构、标准等对象提供OID注册管理功能,OID标识注册管理的相关功能依旧不够完善,不利于OID标识信息的应用发展。The above solution can only provide OID registration management functions for various organizations, standards and other objects, and the related functions of OID identification registration management are still not perfect, which is not conducive to the application and development of OID identification information.

发明内容SUMMARY OF THE INVENTION

以下是对本文详细描述的主题的概述。本概述并非是为了限制权利要求的保护范围。The following is an overview of the topics detailed in this article. This summary is not intended to limit the scope of protection of the claims.

本发明实施例提供一种注册管理的方法、系统及节点,能够完善OID注册管理的功能。The embodiments of the present invention provide a method, system and node for registration management, which can improve the function of OID registration management.

本发明实施例提供了一种注册管理的方法,包括:An embodiment of the present invention provides a method for registration management, including:

父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;After the parent node authorizes and authenticates the child nodes, it assigns the corresponding child node identifiers to each child node;

子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。The child node assigns an object identifier OID to the registered object applying for registration according to the assigned child node identifier.

可选的,所述注册对象包括以下部分或全部对象:Optionally, the registration object includes some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

可选的,所述安全认证对象包括以下一种或一种以上对象:Optionally, the security authentication object includes one or more of the following objects:

安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate.

可选的,所述子节点根据分配的子节点标识符,为申请注册的注册对象分配OID包括:Optionally, according to the assigned child node identifier, the child node assigns an OID to the registration object applying for registration, including:

所述子节点接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成对应于所述注册对象的OID;When the child node receives the registration application of the registration object, it generates an OID corresponding to the registration object according to the child node identifier assigned to itself and the object identification code determined according to the preset coding strategy;

将生成的所述OID分配给所述注册对象。The generated OID is assigned to the registration object.

可选的,所述为申请注册的注册对象分配对象标识符OID之后,所述方法还包括:Optionally, after the object identifier OID is allocated for the registration object applying for registration, the method further includes:

根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;Generate an identification code corresponding to the OID according to the OID assigned to the registered object;

根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;Obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object;

其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code.

可选的,所述方法还包括通过以下一种或一种以上方式查询所述注册对象的相关信息:Optionally, the method further includes querying the relevant information of the registered object in one or more of the following ways:

浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query.

可选的,所述相关信息包括全生命周期信息;所述全生命周期信息包括以下部分或全部信息:Optionally, the relevant information includes full life cycle information; the full life cycle information includes some or all of the following information:

制造信息、加工信息、流通信息、使用信息、维修信息、销毁信息。Manufacturing information, processing information, distribution information, usage information, maintenance information, and destruction information.

可选的,所述注册对象为元数据时,所述方法还包括通过以下一种或一种以上方式查询所述元数据:Optionally, when the registration object is metadata, the method further includes querying the metadata in one or more of the following ways:

通过所述父节点或子节点查询所述元数据;query the metadata through the parent node or child node;

通过预设的外部应用系统调用接口查询所述元数据;Query the metadata through a preset external application system call interface;

通过excel导入方式查询所述元数据;Query the metadata through excel import;

通过可扩展标记语言XML导入方式查询所述元数据。The metadata is queried by way of extensible markup language XML import.

可选的,所述注册对象为安全认证证书的注册用户时,所述方法还包括:Optionally, when the registered object is a registered user of a security authentication certificate, the method further includes:

通过预先设置的第一接口建立安全认证系统与所述父节点和/或子节点的通信连接;Establish a communication connection between the security authentication system and the parent node and/or child node through a preset first interface;

所述安全认证证书的注册用户进行注册申请时,所述父节点和/或子节点通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息;When the registered user of the security authentication certificate applies for registration, the parent node and/or the child node receives the identity information of the registered user sent by the security authentication system through the first interface; wherein, the The identity information includes the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate;

接收到所述身份信息的父节点或子节点,根据接收到的身份信息为所述注册用户分配OID。The parent node or child node that has received the identity information allocates an OID to the registered user according to the received identity information.

可选的,所述方法还包括:Optionally, the method further includes:

通过预先设置的第二接口建立所述父节点和/或子节点与安全认证系统的通信连接;Establish a communication connection between the parent node and/or the child node and the security authentication system through a preset second interface;

所述父节点和/或子节点通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The parent node and/or the child node sends the identity information of the registration object that applies for registration to the security authentication system through the second interface, so that the security authentication system can identify the registration object according to the received registration information. The registration object performs application processing for a security authentication certificate.

可选的,所述为申请注册的注册对象分配OID包括:Optionally, allocating an OID to a registration object applying for registration includes:

接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;When receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule;

接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。When receiving registration applications from two or more registration objects, the corresponding OIDs are respectively allocated to the registration objects sending the registration applications according to the preset second identification distribution rule.

可选的,所述子节点通过所述父节点的授权认证后,所述方法还包括:Optionally, after the child node is authenticated by the parent node, the method further includes:

所述子节点按照预设应用范围规则,将自身设置为完全公开节点、局部区域公开节点、或私密节点。The child node sets itself as a fully public node, a local area public node, or a private node according to the preset application scope rule.

可选的,所述方法还包括:Optionally, the method further includes:

对所述父节点和/或所述子节点,与所述注册对象的通信接口,采用预设的签名加密策略进行加密。The communication interface between the parent node and/or the child node and the registered object is encrypted using a preset signature encryption strategy.

另一方面,本发明实施例还提供一种注册管理的方法,包括:On the other hand, an embodiment of the present invention also provides a method for registration management, including:

按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;According to the preset authorization policy, determine one or more sub-nodes that need to be authorized and authenticated;

对子节点进行授权认证后,为各子节点分配相应的子节点标识符;After authorizing and authenticating the sub-nodes, assign corresponding sub-node identifiers to each sub-node;

其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application.

可选的,所述注册对象包括以下部分或全部对象:Optionally, the registration object includes some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

再一方面,本发明实施例还提供一种注册管理的系统,包括:父节点和子节点;其中,In another aspect, an embodiment of the present invention also provides a system for registration management, including: a parent node and a child node; wherein,

父节点包括授权处理单元,用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The parent node includes an authorization processing unit, which is used for: assigning a corresponding child node identifier to each child node after performing authorization and authentication on the child node;

子节点包括分配处理单元,用于:根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。The child node includes an allocation processing unit, configured to: according to the allocated child node identifier, allocate an object identifier OID to the registered object applying for registration.

可选的,所述注册对象包括以下部分或全部对象:Optionally, the registration object includes some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

可选的,所述安全认证对象包括以下一种或一种以上对象:Optionally, the security authentication object includes one or more of the following objects:

安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate.

可选的,所述分配处理单元具体用于:Optionally, the allocation processing unit is specifically used for:

接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成分配给所述注册对象的OID。When the registration application of the registration object is received, the OID allocated to the registration object is generated according to the child node identifier allocated to itself and the object identification code determined according to the preset coding strategy.

可选的,所述第二节点还包括编码处理单元和所述系统还包括解析装置;其中,Optionally, the second node further includes an encoding processing unit and the system further includes a parsing device; wherein,

所述编码处理单元用于:根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;The encoding processing unit is used for: generating an identification code corresponding to the OID according to the OID assigned to the registered object;

所述解析装置用于:根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;The parsing device is configured to: obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object;

其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code.

可选的,所述系统还包括查询装置,用于通过以下一种或一种以上方式查询所述注册对象的相关信息:Optionally, the system further includes a query device for querying the relevant information of the registered object in one or more of the following ways:

浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query.

可选的,所述分配处理单元包括第一分发模块和第二分发模块;其中,Optionally, the distribution processing unit includes a first distribution module and a second distribution module; wherein,

第一分发模块用于:接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;The first distribution module is used to: when receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule;

第二分发模块用于:接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。The second distribution module is used for: when receiving registration applications of two or more registration objects, respectively assigning corresponding OIDs to the registration objects sending the registration applications according to the preset second identification distribution rules.

可选的,所述系统还包括第一接口单元,所述父节点和/或子节点还包括接收单元;其中,Optionally, the system further includes a first interface unit, and the parent node and/or child node further includes a receiving unit; wherein,

所述第一接口单元用于:通过预先设置的第一接口建立安全认证系统与所述父节点和/或子节点的通信连接;The first interface unit is configured to: establish a communication connection between the security authentication system and the parent node and/or the child node through a preset first interface;

所述接收单元用于:所述安全认证证书的注册用户进行注册申请时,通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息。The receiving unit is configured to: when the registered user of the security authentication certificate applies for registration, receive the identity information of the registered user sent by the security authentication system through the first interface; wherein, the identity information It includes the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate.

可选的,所述系统还包括第二接口单元,所述父节点和/或子节点还包括发送单元;其中,Optionally, the system further includes a second interface unit, and the parent node and/or the child node further includes a sending unit; wherein,

所述第二接口单元用于:通过预先设置的第二接口建立所述父节点和/或子节点与安全认证系统的通信连接;The second interface unit is configured to: establish a communication connection between the parent node and/or the child node and the security authentication system through a preset second interface;

所述发送单元拥有:通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The sending unit has: through the second interface, send the identity information of the registration object applying for registration to the security authentication system, so that the security authentication system can register the registration information according to the received registration information to the security authentication system. The object performs the application processing of the security authentication certificate.

还一方面,本发明实施例还提供一种节点,包括:确定单元和分配处理单元;其中,In another aspect, an embodiment of the present invention further provides a node, including: a determination unit and an allocation processing unit; wherein,

确定单元用于:按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;The determining unit is used for: determining one or more sub-nodes that need to be authorized and authenticated according to the preset authorization policy;

分配处理单元用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The assigning processing unit is used for: assigning corresponding child node identifiers to each child node after performing authorization and authentication on the child node;

其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application.

可选的,所述注册对象包括以下部分或全部对象:Optionally, the registration object includes some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

与相关技术相比,本申请技术方案包括:父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符(OID)。本发明实施例通过授权节点实现了OID分配,完善了OID注册管理的功能。Compared with the related art, the technical solution of the present application includes: after the parent node performs authorization and authentication on the child nodes, assigns a corresponding child node identifier to each child node; the child node is the registered object applying for registration according to the assigned child node identifier. Assign an Object Identifier (OID). The embodiment of the present invention realizes OID allocation through the authorization node, and improves the function of OID registration management.

本发明的其它特征和优点将在随后的说明书中阐述,并且,部分地从说明书中变得显而易见,或者通过实施本发明而了解。本发明的目的和其他优点可通过在说明书、权利要求书以及附图中所特别指出的结构来实现和获得。Other features and advantages of the present invention will be set forth in the description which follows, and in part will be apparent from the description, or may be learned by practice of the invention. The objectives and other advantages of the invention may be realized and attained by the structure particularly pointed out in the description, claims and drawings.

附图说明Description of drawings

附图用来提供对本发明技术方案的进一步理解,并且构成说明书的一部分,与本申请的实施例一起用于解释本发明的技术方案,并不构成对本发明技术方案的限制。The accompanying drawings are used to provide a further understanding of the technical solutions of the present invention, and constitute a part of the specification. They are used to explain the technical solutions of the present invention together with the embodiments of the present application, and do not limit the technical solutions of the present invention.

图1为本发明实施例注册管理的方法的流程图;1 is a flowchart of a method for registration management according to an embodiment of the present invention;

图2为本发明另一实施例注册管理的方法的流程图;2 is a flowchart of a method for registration management according to another embodiment of the present invention;

图3为本发明实施例注册管理的系统的结构框图;3 is a structural block diagram of a system for registration management according to an embodiment of the present invention;

图4为本发明实施例一种节点的结构框图;4 is a structural block diagram of a node according to an embodiment of the present invention;

图5为本发明应用示例元数据的注册管理的流程示意图。FIG. 5 is a schematic flow chart of registration management of metadata of an application example of the present invention.

具体实施方式Detailed ways

为使本发明的目的、技术方案和优点更加清楚明白,下文中将结合附图对本发明的实施例进行详细说明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互任意组合。In order to make the objectives, technical solutions and advantages of the present invention clearer, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, the embodiments in the present application and the features in the embodiments may be arbitrarily combined with each other if there is no conflict.

在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机系统中执行。并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。The steps shown in the flowcharts of the figures may be performed in a computer system, such as a set of computer-executable instructions. Also, although a logical order is shown in the flowcharts, in some cases the steps shown or described may be performed in an order different from that herein.

本申请发明人分析发现,已有的OID注册管理系统无法提供节点托管、批量赋码以及应用于RFID、二维码等众多物理载体的功能,未能从全局架构设计的角度出发,提供面向元数据、安全认证策略等其他多类对象的灵活注册管理和应用功能。The inventor of the present application found that the existing OID registration management system could not provide the functions of node hosting, batch code assignment and application to many physical carriers such as RFID and QR code, and could not provide an element-oriented solution from the perspective of global architecture design. Flexible registration management and application functions for other types of objects such as data and security authentication policies.

本发明实施例可以应用于电子医疗、信息安全等OID应用领域,还可以应用于包括农业领域在内的未建立OID标识体系的领域,为实现类重要农产品的标识编码、追溯管理等提供技术基础,满足OID标识在农业领域的应用需求。The embodiments of the present invention can be applied to OID application fields such as electronic medical care, information security, etc., and can also be applied to fields that have not established an OID identification system, including the agricultural field, and provide a technical basis for realizing identification coding and traceability management of important agricultural products. , to meet the application requirements of OID identification in the agricultural field.

图1为本发明实施例注册管理的方法的流程图,如图1所示,包括:FIG. 1 is a flowchart of a method for registration management according to an embodiment of the present invention, as shown in FIG. 1 , including:

步骤101、父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;Step 101: After the parent node authorizes and authenticates the child nodes, assign corresponding child node identifiers to each child node;

需要说明的是,本发明实施例子节点标识符作为分配给注册对象的OID的前缀部分,是父节点给予子节点为注册对象分配OID的标识参数。It should be noted that the example node identifier in the embodiment of the present invention is used as the prefix part of the OID allocated to the registration object, and is an identification parameter that the parent node gives the child node to allocate the OID to the registration object.

步骤102、子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。Step 102: The child node assigns an object identifier OID to the registered object applying for registration according to the assigned child node identifier.

需要说明的是,本发明实施例网络拓扑结构可以是树状分支,树状分支顶部的父节点可以认为是总运营管理机构,子节点可以认为是相关技术中已有的运营机构,运营机构获得运营管理机构的授权认证后,成为树状分支中的一个管理运营机构,管理运营机构还可以对其他运营机构进行授权认证,以构建更多的管理运营机构,管理运营机构一旦获得授权,即可对发起申请注册的注册对象进行OID分配;被分配的对象可以包括运营机构,获得OID的注册对象成为网络中一个OID节点。It should be noted that the network topology structure in this embodiment of the present invention may be a tree-like branch, the parent node at the top of the tree-like branch may be considered as a general operation management organization, and the child nodes may be considered as existing operation organizations in related technologies, and the operation organization obtains After the authorization and certification of the operation management organization, it becomes a management operation organization in the tree branch. The management operation organization can also authorize and authenticate other operation organizations to build more management operation organizations. Once the management operation organization is authorized, it can The OID is allocated to the registration object that initiates the application for registration; the allocated object may include an operating agency, and the registration object that obtains the OID becomes an OID node in the network.

另外,本发明实施例基于上述OID分配,可以参照相关技术对OID节点进行运维管理。In addition, based on the above-mentioned OID allocation, the embodiments of the present invention may refer to related technologies to perform operation and maintenance management on OID nodes.

可选的,本发明实施例注册对象包括以下部分或全部对象:Optionally, the registered objects in this embodiment of the present invention include some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

可选的,本发明实施例安全认证对象包括以下一种或一种以上对象:Optionally, the security authentication object in this embodiment of the present invention includes one or more of the following objects:

安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate.

可选的,本发明实施例子节点根据分配的子节点标识符,为申请注册的注册对象分配OID包括:Optionally, according to the allocated sub-node identifier, the instance node in this embodiment of the present invention allocates an OID to a registration object applying for registration, including:

所述子节点接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成对应于所述注册对象的OID;When the child node receives the registration application of the registration object, it generates an OID corresponding to the registration object according to the child node identifier assigned to itself and the object identification code determined according to the preset coding strategy;

将生成的所述OID分配给所述注册对象。The generated OID is assigned to the registration object.

可选的,为申请注册的注册对象分配对象标识符OID之后,本发明实施例方法还包括:Optionally, after allocating the object identifier OID to the registration object applying for registration, the method according to the embodiment of the present invention further includes:

根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;Generate an identification code corresponding to the OID according to the OID assigned to the registered object;

根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;Obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object;

其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code.

可选的,本发明实施例方法还包括通过以下一种或一种以上方式查询所述注册对象的相关信息:Optionally, the method according to the embodiment of the present invention further includes querying the relevant information of the registered object in one or more of the following ways:

浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query.

可选的,本发明实施例相关信息包括全生命周期信息;所述全生命周期信息包括以下部分或全部信息:Optionally, the information related to the embodiment of the present invention includes full life cycle information; the full life cycle information includes some or all of the following information:

制造信息、加工信息、流通信息、使用信息、维修信息、销毁信息。Manufacturing information, processing information, distribution information, usage information, maintenance information, and destruction information.

可选的,注册对象为元数据时,本发明实施例方法还包括通过以下一种或一种以上方式查询所述元数据:Optionally, when the registration object is metadata, the method according to the embodiment of the present invention further includes querying the metadata in one or more of the following ways:

通过所述父节点或子节点查询所述元数据;query the metadata through the parent node or child node;

通过预设的外部应用系统调用接口查询所述元数据;Query the metadata through a preset external application system call interface;

通过excel导入方式查询所述元数据;Query the metadata through excel import;

通过可扩展标记语言XML导入方式查询所述元数据。The metadata is queried by way of extensible markup language XML import.

可选的,注册对象为安全认证证书的注册用户时,本发明实施例方法还包括:Optionally, when the registered object is a registered user of the security authentication certificate, the method according to the embodiment of the present invention further includes:

通过预先设置的第一接口建立安全认证系统与所述父节点和/或子节点的通信连接;Establish a communication connection between the security authentication system and the parent node and/or child node through a preset first interface;

所述安全认证证书的注册用户进行注册申请时,所述父节点和/或子节点通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息;When the registered user of the security authentication certificate applies for registration, the parent node and/or the child node receives the identity information of the registered user sent by the security authentication system through the first interface; wherein, the The identity information includes the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate;

接收到所述身份信息的父节点和/或子节点,根据接收到的身份信息为所述注册用户分配OID。The parent node and/or child node that has received the identity information allocates an OID to the registered user according to the received identity information.

可选的,本发明实施例方法还包括:Optionally, the method according to the embodiment of the present invention further includes:

通过预先设置的第二接口建立所述父节点和/或子节点与安全认证系统的通信连接;Establish a communication connection between the parent node and/or the child node and the security authentication system through a preset second interface;

所述父节点和/或子节点通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The parent node and/or the child node sends the identity information of the registration object that applies for registration to the security authentication system through the second interface, so that the security authentication system can identify the registration object according to the received registration information. The registration object performs application processing for a security authentication certificate.

可选的,本发明实施例为申请注册的注册对象分配OID包括:Optionally, in this embodiment of the present invention, allocating an OID to a registration object applying for registration includes:

接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;When receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule;

接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。When receiving registration applications from two or more registration objects, the corresponding OIDs are respectively allocated to the registration objects sending the registration applications according to the preset second identification distribution rule.

可选的,子节点通过所述父节点的授权认证后,本发明实施例方法还包括:Optionally, after the child node passes the authorization and authentication of the parent node, the method according to the embodiment of the present invention further includes:

所述子节点按照预设应用范围规则,将自身设置为完全公开节点、局部区域公开节点、或私密节点。The child node sets itself as a fully public node, a local area public node, or a private node according to the preset application scope rule.

可选的,本发明实施例方法还包括:Optionally, the method according to the embodiment of the present invention further includes:

对所述父节点和/或所述子节点,与所述注册对象的通信接口,采用预设的签名加密策略进行加密。The communication interface between the parent node and/or the child node and the registered object is encrypted using a preset signature encryption strategy.

与相关技术相比,本申请技术方案包括:父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。本发明实施例通过授权节点实现了OID分配,完善了OID注册管理的功能。Compared with the related art, the technical solution of the present application includes: after the parent node performs authorization and authentication on the child nodes, assigns a corresponding child node identifier to each child node; the child node is the registered object applying for registration according to the assigned child node identifier. Assign object identifier OID. The embodiment of the present invention realizes OID allocation through the authorization node, and improves the function of OID registration management.

图2为本发明另一实施例注册管理的方法的流程图,如图2所示,包括:FIG. 2 is a flowchart of a method for registration management according to another embodiment of the present invention, as shown in FIG. 2 , including:

步骤201、按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;Step 201, according to a preset authorization policy, determine one or more sub-nodes that need to be authorized and authenticated;

步骤202、对子节点进行授权认证后,为各子节点分配相应的子节点标识符;Step 202: After performing authorization and authentication on the sub-nodes, assign corresponding sub-node identifiers to each sub-node;

其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application.

需要说明的是,本发明实施例网络拓扑结构可以是树状分支,树状分支顶部的父节点可以认为是总运营管理机构,子节点可以认为是相关技术中已有的运营机构,运营机构获得运营管理机构的授权认证后,成为树状分支中的一个管理运营机构,管理运营机构还可以对其他运营机构进行授权认证,以构建更多的管理运营机构,管理运营机构一旦获得授权,即可对发起申请注册的注册对象进行OID分配;被分配的对象可以包括运营机构。It should be noted that the network topology structure in this embodiment of the present invention may be a tree-like branch, the parent node at the top of the tree-like branch may be considered as a general operation management organization, and the child nodes may be considered as existing operation organizations in related technologies, and the operation organization obtains After the authorization and certification of the operation management organization, it becomes a management operation organization in the tree branch. The management operation organization can also authorize and authenticate other operation organizations to build more management operation organizations. Once the management operation organization is authorized, it can The OID is allocated to the registration object that initiates the application for registration; the allocated objects may include operating agencies.

可选的,本发明实施例注册对象包括以下部分或全部对象:Optionally, the registered objects in this embodiment of the present invention include some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

与相关技术相比,本申请技术方案包括:父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。本发明实施例通过授权节点实现了OID分配,完善了OID注册管理的功能。Compared with the related art, the technical solution of the present application includes: after the parent node performs authorization and authentication on the child nodes, assigns a corresponding child node identifier to each child node; the child node is the registered object applying for registration according to the assigned child node identifier. Assign object identifier OID. The embodiment of the present invention realizes OID allocation through the authorization node, and improves the function of OID registration management.

图3为本发明实施例注册管理的系统的结构框图,如图3所示,包括:父节点和子节点;其中,FIG. 3 is a structural block diagram of a system for registration management according to an embodiment of the present invention. As shown in FIG. 3 , it includes: a parent node and a child node; wherein,

父节点包括授权处理单元,用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The parent node includes an authorization processing unit, which is used for: assigning a corresponding child node identifier to each child node after performing authorization and authentication on the child node;

子节点包括分配处理单元,用于:根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。The child node includes an allocation processing unit, configured to: according to the allocated child node identifier, allocate an object identifier OID to the registered object applying for registration.

需要说明的是,本发明实施例网络拓扑结构可以是树状分支,树状分支顶部的父节点可以认为是总运营管理机构,子节点可以认为是相关技术中已有的运营机构,运营机构获得运营管理机构的授权认证后,成为树状分支中的一个管理运营机构,管理运营机构还可以对其他运营机构进行授权认证,以构建更多的管理运营机构,管理运营机构一旦获得授权,即可对发起申请注册的注册对象进行OID分配;被分配的对象可以包括运营机构。It should be noted that the network topology structure in this embodiment of the present invention may be a tree-like branch, the parent node at the top of the tree-like branch may be considered as a general operation management organization, and the child nodes may be considered as existing operation organizations in related technologies, and the operation organization obtains After the authorization and certification of the operation management organization, it becomes a management operation organization in the tree branch. The management operation organization can also authorize and authenticate other operation organizations to build more management operation organizations. Once the management operation organization is authorized, it can The OID is allocated to the registration object that initiates the application for registration; the allocated objects may include operating agencies.

可选的,本发明实施例注册对象包括以下部分或全部对象:Optionally, the registered objects in this embodiment of the present invention include some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

可选的,本发明实施例安全认证对象包括以下一种或一种以上对象:Optionally, the security authentication object in this embodiment of the present invention includes one or more of the following objects:

安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate.

可选的,本发明实施例分配处理单元具体用于:Optionally, the allocation processing unit in this embodiment of the present invention is specifically configured to:

接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成分配给所述注册对象的OID。When the registration application of the registration object is received, the OID allocated to the registration object is generated according to the child node identifier allocated to itself and the object identification code determined according to the preset coding strategy.

可选的,本发明实施例第二节点还包括编码处理单元和所述系统还包括解析装置;其中,Optionally, the second node in this embodiment of the present invention further includes an encoding processing unit, and the system further includes a parsing device; wherein,

所述编码处理单元用于:根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;The encoding processing unit is used for: generating an identification code corresponding to the OID according to the OID assigned to the registered object;

所述解析装置用于:根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;The parsing device is configured to: obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object;

其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code.

可选的,本发明实施例系统还包括查询装置,用于通过以下一种或一种以上方式查询所述注册对象的相关信息:Optionally, the system according to the embodiment of the present invention further includes a query device, configured to query the relevant information of the registered object in one or more of the following ways:

浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query.

可选的,本发明实施例相关信息包括全生命周期信息;所述全生命周期信息包括以下部分或全部信息:Optionally, the information related to the embodiment of the present invention includes full life cycle information; the full life cycle information includes some or all of the following information:

制造信息、加工信息、流通信息、使用信息、维修信息、销毁信息。Manufacturing information, processing information, distribution information, usage information, maintenance information, and destruction information.

可选的,注册对象为元数据时,本发明实施例还包括通过以下一种或一种以上方式查询所述元数据:Optionally, when the registration object is metadata, the embodiment of the present invention further includes querying the metadata in one or more of the following ways:

通过所述父节点或子节点查询所述元数据;query the metadata through the parent node or child node;

通过预设的外部应用系统调用接口查询所述元数据;Query the metadata through a preset external application system call interface;

通过excel导入方式查询所述元数据;Query the metadata through excel import;

通过可扩展标记语言XML导入方式查询所述元数据。The metadata is queried by way of extensible markup language XML import.

可选的,本发明实施例分配处理单元包括第一分发模块和第二分发模块;其中,Optionally, the distribution processing unit in this embodiment of the present invention includes a first distribution module and a second distribution module; wherein,

第一分发模块用于:接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;The first distribution module is used to: when receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule;

第二分发模块用于:接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。The second distribution module is used for: when receiving registration applications of two or more registration objects, respectively assigning corresponding OIDs to the registration objects sending the registration applications according to the preset second identification distribution rules.

可选的,本发明实施例子节点还包括应用设置单元,用于:Optionally, the example node in this embodiment of the present invention further includes an application setting unit, configured to:

按照预设应用范围规则,将自身所属节点设置为完全公开节点、局部区域公开节点、或私密节点。According to the preset application scope rules, the node to which it belongs is set as a fully public node, a local area public node, or a private node.

可选的,本发明实施例系统还包括加密处理装置,用于:Optionally, the system according to the embodiment of the present invention further includes an encryption processing device, configured to:

对所述父节点和/或所述子节点,与所述注册对象的通信接口,采用预设的签名加密策略进行加密。The communication interface between the parent node and/or the child node and the registered object is encrypted using a preset signature encryption strategy.

可选的,本发明实施例所述系统还包括第一接口单元,所述父节点和/或子节点还包括接收单元;其中,Optionally, the system in this embodiment of the present invention further includes a first interface unit, and the parent node and/or child node further includes a receiving unit; wherein,

所述第一接口单元用于:通过预先设置的第一接口建立安全认证系统与所述父节点和/或子节点的通信连接;The first interface unit is configured to: establish a communication connection between the security authentication system and the parent node and/or the child node through a preset first interface;

所述接收单元用于:所述安全认证证书的注册用户进行注册申请时,通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息。The receiving unit is configured to: when the registered user of the security authentication certificate applies for registration, receive the identity information of the registered user sent by the security authentication system through the first interface; wherein, the identity information It includes the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate.

可选的,本发明实施例系统还包括第二接口单元,所述父节点和/或子节点还包括发送单元;其中,Optionally, the system according to the embodiment of the present invention further includes a second interface unit, and the parent node and/or child node further includes a sending unit; wherein,

所述第二接口单元用于:通过预先设置的第二接口建立所述父节点和/或子节点与安全认证系统的通信连接;The second interface unit is configured to: establish a communication connection between the parent node and/or the child node and the security authentication system through a preset second interface;

所述发送单元拥有:通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The sending unit has: through the second interface, send the identity information of the registration object applying for registration to the security authentication system, so that the security authentication system can register the registration information according to the received registration information to the security authentication system. The object performs the application processing of the security authentication certificate.

图4为本发明实施例一种节点的结构框图,如图4所示,包括:确定单元和分配处理单元;其中,FIG. 4 is a structural block diagram of a node according to an embodiment of the present invention. As shown in FIG. 4 , it includes: a determination unit and an allocation processing unit; wherein,

确定单元用于:按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;The determining unit is used for: determining one or more sub-nodes that need to be authorized and authenticated according to the preset authorization policy;

分配处理单元用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The assigning processing unit is used for: assigning corresponding child node identifiers to each child node after performing authorization and authentication on the child node;

其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application.

需要说明的是,本发明实施例网络拓扑结构可以是树状分支,树状分支顶部的父节点可以认为是总运营管理机构,子节点可以认为是相关技术中已有的运营机构,运营机构获得运营管理机构的授权认证后,成为树状分支中的一个管理运营机构,管理运营机构还可以对其他运营机构进行授权认证,以构建更多的管理运营机构,管理运营机构一旦获得授权,即可对发起申请注册的注册对象进行OID分配;被分配的对象可以包括运营机构。It should be noted that the network topology structure in this embodiment of the present invention may be a tree-like branch, the parent node at the top of the tree-like branch may be considered as a general operation management organization, and the child nodes may be considered as existing operation organizations in related technologies, and the operation organization obtains After the authorization and certification of the operation management organization, it becomes a management operation organization in the tree branch. The management operation organization can also authorize and authenticate other operation organizations to build more management operation organizations. Once the management operation organization is authorized, it can The OID is allocated to the registration object that initiates the application for registration; the allocated objects may include operating agencies.

可选的,本发明实施例注册对象包括以下部分或全部对象:Optionally, the registered objects in this embodiment of the present invention include some or all of the following objects:

运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.

以下通过应用示例对本发明实施例方法进行清楚详细的说明,应用示例仅用于陈述本发明,并不用于限定本发明的保护范围。The method of the embodiments of the present invention will be described clearly and in detail below through application examples. The application examples are only used to describe the present invention, and are not used to limit the protection scope of the present invention.

应用示例Application example

相关技术OID标识的注册管理由一个综合平台实现OID标识的注册申请;本发明应用示例以综合平台作为网络拓扑的最上层结构,设置运营机构为运营管理机构;假设综合平台为第一节点,则由综合平台设置为运营管理结构的运营机构,相对于综合平台为第二节点;假设运营管理结构再次设置下级运营机构为运营管理机构,则两者的关系可以认为是第一节点和第二节点的关系,本发明应用示例第二节点获得授权认证后,与综合平台参照相关技术进行OID资源的同步,所有运营管理机构共同参与实现对注册用户的审核。The registration management of the related art OID identification is realized by an integrated platform to realize the registration application of the OID identification; the application example of the present invention uses the integrated platform as the uppermost structure of the network topology, and sets the operation organization as the operation management organization; assuming that the integrated platform is the first node, then The operation organization set by the integrated platform as the operation management structure is the second node relative to the integrated platform; if the operation management structure sets the lower-level operation organization as the operation management organization again, the relationship between the two can be considered as the first node and the second node. After the second node of the application example of the present invention obtains authorization and authentication, it synchronizes OID resources with the integrated platform with reference to related technologies, and all operation management agencies jointly participate in the verification of registered users.

相关技术的OID注册管理流程主要包括:运营机构首先登录OID注册管理系统,在提交机构相关身份信息(比如机构中英文名称、地址、联系方式、OID应用范围等)之后,提交OID注册申请;OID注册管理系统对提交的注册申请进行审核(审批)之后,赋予运营机构唯一的OID,被赋予OID的运营机构成为注册管理系统下的一个节点。The OID registration management process of related technologies mainly includes: the operating organization first logs in to the OID registration management system, and after submitting the relevant identity information of the organization (such as the organization's Chinese and English name, address, contact information, OID application scope, etc.), submit the OID registration application; OID registration application; After the registration management system reviews (approves) the submitted registration application, it gives the operating agency a unique OID, and the operating agency that is given the OID becomes a node under the registration management system.

本发明应用示例注册管理流程主要包括:运营机构在注册申请OID,成为OID节点时,可以根据需求自主选择所注册后的OID节点为完全公开节点、私密节点或者局部区域公开节点等,并将填写的注册信息提交至上级运营管理机构;上级运营管理机构收到注册申请后,依据相关的规定要求,以节点标识符作为其标识前缀,为该注册对象分配唯一的OID;运营机构获得OID后,可视为OID节点;本发明应用示例可以运营机构可以向上级运营管理机构提交自身的IP地址,自主维护与平台应用相关的数据字典和安全认证,并负责为节点下的各类注册对象分配唯一的OID;可分配给注册对象的OID资源可以根据与上级运营管理机构事先约定的分配规则进行分配。若该申请机构成功注册,获得唯一的OID,并且选择节点的性质为私密节点,则可不对外提供IP地址。The registration management process of the application example of the present invention mainly includes: when an operating organization registers and applies for an OID and becomes an OID node, it can independently select the registered OID node as a fully public node, a private node or a partial area public node according to requirements, and fill in the The registration information of the node is submitted to the higher-level operation management agency; after the higher-level operation management agency receives the registration application, it uses the node identifier as its identification prefix to assign a unique OID to the registration object; after the operation agency obtains the OID, It can be regarded as an OID node; in the application example of the present invention, the operating organization can submit its own IP address to the higher-level operation management organization, independently maintain the data dictionary and security certification related to the platform application, and be responsible for allocating unique registration objects under the node. OID; OID resources that can be allocated to registered objects can be allocated according to the allocation rules agreed with the superior operation management agency in advance. If the applicant organization successfully registers, obtains a unique OID, and selects the nature of the node as a private node, it may not provide an IP address to the outside world.

本发明应用示例注册管理的处理过程主要包括:The processing process of the application example registration management of the present invention mainly includes:

按照预设的分配策略为具备赋码的运营机构(获得授权的运营管理机构)分配相应的节点标识符,具备赋码的运营机构根据分配给自身的节点标识符,结合对象标识编码,生成分配给注册对象的OID;Assign corresponding node identifiers to operators with code assignments (authorized operation management agencies) according to a preset allocation strategy, and operators with code assignments generate assignments based on the node identifiers assigned to themselves and in combination with the object identification code. OID to the registered object;

受理下级运营机构的注册申请,为其分配唯一的OID;涵盖对申请企业或者机构的注册申请的受理、资质审查、审批、公示、发布、入库、备案等一系列注册处理事项。Accept registration applications from lower-level operating institutions and assign unique OIDs to them; cover a series of registration processing matters such as acceptance, qualification review, approval, publicity, release, storage, and filing of registration applications of the applicant company or institution.

受理系统直接连接的信息平台(系统)的注册申请,为其分配唯一的OID。注册对象可包含实体对象、元数据以及安全认证对象等。Accept the registration application of the information platform (system) directly connected to the system, and assign a unique OID to it. Registration objects can include entity objects, metadata, and security authentication objects.

本发明应用示例构建面向对象的节点服务框架,支持OID节点运维机构,通过节点授权方式,为各个节点运营机构授予OID标识符的分配权限。本发明实施例系统可以呈树状分支结构,可以根据实际应用情况逐级向下分发OID的分配权限;比如,某一组织注册OID节点,可以在该OID节点下,给所管辖的实体对象赋码,同样也可以为该组织所管辖的其他机构赋码。而其他机构也可以在所注册的OID节点下,继续为管辖的各类注册对象赋码。The application example of the present invention builds an object-oriented node service framework, supports OID node operation and maintenance organizations, and grants OID identifier allocation authority to each node operation organization through a node authorization method. The system in this embodiment of the present invention may have a tree-like branch structure, and may distribute the OID assignment authority level by level according to the actual application situation; It can also assign codes to other institutions under the jurisdiction of the organization. Other institutions can also continue to assign codes to various registered objects under their jurisdiction under the registered OID nodes.

本发明应用示例根据分配给注册对象的OID,可以生成对应于OID的识别编码;接收到预先设定的识别指令时,可以获取识别编码,并根据识别编码解析OID,以获得注册对象的相关信息;其中,识别编码包括以下一种或一种以上编码:条形码、二维码。以实体对象为注册对象为例,以下对该部分进行示例说明:实体对象进行注册申请后,获得分配给实体对象的OID;根据生成的OID本发明应用示例生成对应于OID的二维码;以农产品生产厂商为例,可以包括:农产品生产厂商调用OID接口或者在注册管理系统的节点功能,获取需标识的产品等实体对象的唯一OID;根据获取的OID生成对应的二维码。生产厂商可以打印生成的二维码,将二维码贴附于对应的实体对象;通过二维码可以访问OID注册管理系统,访问实体对象的OID。二维码如何实现OID注册管理系统地址的嵌入,访问注册管理系统,可以参照相关技术实现。The application example of the present invention can generate an identification code corresponding to the OID according to the OID assigned to the registered object; when receiving a preset identification instruction, the identification code can be obtained, and the OID can be parsed according to the identification code to obtain the relevant information of the registered object ; Wherein, the identification code includes one or more of the following codes: barcode, two-dimensional code. Taking the entity object as the registration object as an example, the following is an example to illustrate this part: after the entity object applies for registration, the OID assigned to the entity object is obtained; according to the generated OID application example of the present invention, a two-dimensional code corresponding to the OID is generated; Take the agricultural product manufacturer as an example, it may include: the agricultural product manufacturer invokes the OID interface or the node function of the registration management system to obtain the unique OID of the entity object such as the product to be identified; and generates the corresponding QR code according to the obtained OID. The manufacturer can print the generated QR code and attach the QR code to the corresponding entity object; through the QR code, the OID registration management system can be accessed, and the OID of the entity object can be accessed. How to realize the embedding of the address of the OID registration management system and access the registration management system by the QR code can be realized by referring to related technologies.

本发明应用示例可通过扫描、识读等方式解析OID;其中,RFID识别:通过射频信号识别目标对象并获取相关数据。以酒类产品追溯为例,各类酒瓶在封装处贴附RFID电子标签,支持NFC的手机,在NFC功能模式下,通过近距离感知,解析获得OID的相关信息。The application example of the present invention can analyze the OID by scanning, reading, etc.; wherein, RFID identification: identify the target object through radio frequency signals and obtain relevant data. Taking the traceability of wine products as an example, various wine bottles are attached with RFID electronic tags at the packaging, and mobile phones that support NFC, in the NFC function mode, can analyze and obtain the relevant information of OID through close-range perception.

本发明应用示例在对注册对象进行OID分配后,可以根据接收到的查询指令显示注册对象的全生命周期信息;注册对象包括但不限于:实体对象、元数据以及安全认证对象等。以实体对象为例,全生命周期信息可以包括以下部分或全部信息:注册对象的制造、加工、流通、使用、维修、销毁等信息。可选的,本发明应用示例支持以下一种或一种以上方式的查询:浏览器客户端查询、具备扫描功能的应用(例如、具有扫描功能的即时通信应用)的扫描查询、射频识别(RFID)扫描查询、万维网(WEB)页面的查询;其中,WEB页面的查询包括具备解析访问统一资源名称(URN)对应的OID标识能力的万维网(WEB)页面的查询;本发明应用示例具备解析访问URN对应的OID标识能力的WEB页面可以包括:应用于搜狗、互联网搜索(IE)、谷歌等浏览器,浏览器能够兼容URN:OID工具包,具备直接解析访问URN对应的OID的能力,支持直接解析访问可扩展标记语言(XML)文档的OID对象字段,用于各类WEB文档中OID标识对象资源的定位与索引。The application example of the present invention can display the full life cycle information of the registered object according to the received query instruction after the OID is allocated to the registered object; the registered objects include but are not limited to: entity objects, metadata and security authentication objects. Taking an entity object as an example, the whole life cycle information may include some or all of the following information: the manufacturing, processing, circulation, use, maintenance, destruction and other information of the registered object. Optionally, the application example of the present invention supports one or more of the following query methods: browser client query, scanning query of an application with scanning function (for example, an instant messaging application with scanning function), radio frequency identification (RFID) ) scan query, query of World Wide Web (WEB) page; wherein, the query of WEB page includes the query of the World Wide Web (WEB) page with the ability to parse and access the corresponding OID identification of the Uniform Resource Name (URN); the application example of the present invention has the ability to parse and access the URN The corresponding WEB pages with OID identification capabilities can include: used in browsers such as Sogou, Internet Search (IE), Google, etc. The browser is compatible with the URN:OID toolkit, has the ability to directly parse and access the OID corresponding to the URN, and supports direct parsing Access the OID object field of the Extensible Markup Language (XML) document, which is used for locating and indexing the OID identification object resource in various WEB documents.

本发明上述示例中陈述的元数据可以包括描述数据的数据,可以包括标准化基础元数据,主要包含描述数据属性的信息,用来支持指示存储位置、历史数据、资源查找、文件记录等功能;其中,标准化基础元数据,用于获取和保存各类电子文档模板数据;元数据可以认作为一种电子式目录,包含关于数据的组织、数据域及其关系的信息。元数据可体现为某一个XML文档模板或者特定编辑的组件。The metadata stated in the above examples of the present invention may include data describing data, and may include standardized basic metadata, mainly including information describing data attributes, to support functions such as indicating storage locations, historical data, resource search, file records, etc.; wherein , standardized basic metadata, used to obtain and save various types of electronic document template data; metadata can be regarded as an electronic catalog, containing information about data organization, data domains and their relationships. Metadata can be embodied as a certain XML document template or a component of a specific editing.

以下以注册对象为元数据,对本发明实施例进行示例说明,本发明应用示例为各元数据分配唯一的OID,形成元数据库;本发明应用示例将元数据库作为已完成注册并进行使用的元数据集合,是将其面向各信息系统所使用的规范数据元素定义的集合,本发明应用示例可提供可供开发人员、计算机系统访问、调用的元数据目录。元数据的OID可由注册机构进行注册申请,完成注册后写入元数据库;完成注册后通过对外提供统一的标准规范,管理人员、注册人员可查询和比对有相应查询权限的元数据和已存的元数据信息,使用人员对其所需的元数据信息进行查询、下载等操作,为其使用提供标准和规范的支撑。图5为本发明应用示例元数据的注册管理的流程示意图,如图5所示,包括:The following uses the registration object as metadata to illustrate the embodiment of the present invention. The application example of the present invention assigns a unique OID to each metadata to form a metadata database; the application example of the present invention uses the metadata database as the metadata that has been registered and used. A collection is a collection of standard data element definitions used by various information systems. The application example of the present invention can provide a metadata catalog that can be accessed and invoked by developers and computer systems. The OID of the metadata can be registered by the registration agency, and written into the metadata database after the registration is completed; after the registration is completed, the management personnel and registrants can query and compare the metadata with the corresponding query authority and the existing metadata by providing a unified standard specification to the outside world. Users can query and download the metadata information they need, and provide standard and normative support for their use. FIG. 5 is a schematic flowchart of registration management of application example metadata of the present invention, as shown in FIG. 5 , including:

步骤501、接收元数据;Step 501, receive metadata;

步骤502、对接收的元数据进行审核;Step 502, auditing the received metadata;

步骤503、将通过审核的元数据添加到元数据库;Step 503, adding the approved metadata to the metadata database;

步骤504、将新增的元数据与已存的元数据信息进行比对。Step 504: Compare the newly added metadata with the existing metadata information.

本发明应用示例可提供元数据的查询服务,包括但不限于:支持在系统内部进行的查询;通过外部应用系统调用接口、excel导入、可扩展标记语言(XML)导入等方式,实现对元数据的查询;依托Web网站建设,实现元数据的XML、excel表的查询下载。The application example of the present invention can provide the query service of metadata, including but not limited to: supporting the query carried out inside the system; realizing the query of metadata through external application system call interface, excel import, extensible markup language (XML) import, etc. Query; relying on the construction of the Web site, the query and download of XML and excel tables of metadata can be realized.

本发明应用示例可提供包括各类机械行业厂商、设备在内的元数据的注册管理功能。接收到用户填写OID时,通过对接OID系统接口校验OID是否合法,合法则进行继续OID的注册申请,不合法可以提交申请获取正确的OID。The application example of the present invention can provide the registration management function of metadata including various manufacturers and equipments in the machinery industry. When receiving the OID filled in by the user, check whether the OID is legal by connecting to the OID system interface. If it is legal, continue the OID registration application. If it is illegal, you can submit an application to obtain the correct OID.

本发明应用示例支持安全认证对象的OID的注册管理,以下对安全认证对象的定义及其注册管理进行示例说明:The application example of the present invention supports the registration management of the OID of the security authentication object, and the definition of the security authentication object and its registration management are exemplified below:

安全认证对象是基于公钥基础设施(PKI)体系研制、遵循标准化的认证技术,以电子证书为基础,通过构建一系列的信任关系来执行不同应用系统间的安全通信功能;包括通过第三方可信任机构管理用户公钥,例如、通过认证中心(CA)颁发CA证书的方式管理用户公钥,并把用户公钥和用户其他标识对象信息(名称、Email)等关联起来,在互联网环境下验证用户身份。对安全认证对象,OID标识的对象可以包括:加密算法、安全套接层(SSL)、传输层安全(TLS)服务器和客户端等。以下对安全认证对象的OID注册管理进行示例说明:The security authentication object is developed based on the public key infrastructure (PKI) system and follows the standardized authentication technology. Based on the electronic certificate, the security communication function between different application systems is performed by building a series of trust relationships; The trust organization manages the user's public key, for example, manages the user's public key by issuing a CA certificate through the certification center (CA), and associates the user's public key with the user's other identification object information (name, Email), etc., to verify in the Internet environment user ID. For the security authentication object, the objects identified by the OID may include: encryption algorithm, Secure Sockets Layer (SSL), Transport Layer Security (TLS) server and client, and the like. The following is an example of the OID registration management of the security authentication object:

用户从注册中心(RA)申请获取安全证书,成为证书持有者。安全证书持有者可以包括持有安全证书的各类用户、设备、系统等;本发明应用示例安全证书持有者可以是专用/通用设备识读客户端、各类追溯对象应用系统以及异构对接应用系统等通信实体。RA客户端/服务器作为用户与认证中心的中间渠道,主要用于获取并认证用户的身份,向CA提出证书请求。本发明应用示例用户为获得CA证书,向RA提交的申请可以通过以下方式实施:本发明应用示例建立CA认证系统与注册管理系统的连接,通过CA认证系统可以调用进行OID注册的接口,用户通过向RA提交申请或者调用安全认证接口的方式,提交用户申请CA证书时的身份信息,以进行OID的注册申请;可选的,通过CA认证系统提交身份信息、签名公钥、随机选取的一段信息以及签名,以进行OID的注册申请。申请信息格式及注册接口要求可以参照相关技术规范进行设计实现。在为用户签发CA证书时,RA需要对用户的身份信息进行确认,要求用户提交的注册申请信息与身份信息相符,并同时验证用户拥有与签名公钥相对应的签名私钥。本发明应用示例对用户的身份信息可以采用相关技术中已有的方法实现验证,包括:通过查询和调用OID注册管理系统中的OID注册信息或者查询其它的安全应用系统用户资料,进行自动信息调用和验证。可选的,包括用户希望在证书中出现包括职务、电子邮件、地址、域名等信息在内的认证,以及用户缴费情况、合同签订、犯罪记录等其它信息的验证。Users apply for a security certificate from the Registration Center (RA) and become a certificate holder. The security certificate holder may include various users, devices, systems, etc. holding the security certificate; the application example of the present invention The security certificate holder may be a dedicated/general device reading client, various traceability object application systems, and heterogeneous Connect with communication entities such as application systems. The RA client/server serves as an intermediate channel between the user and the authentication center, and is mainly used to obtain and authenticate the identity of the user, and to make a certificate request to the CA. In order to obtain a CA certificate, the user of the application example of the present invention can submit an application to the RA in the following ways: the application example of the present invention establishes the connection between the CA authentication system and the registration management system, and the CA authentication system can call the interface for OID registration, and the user passes the Submit an application to the RA or call the security authentication interface to submit the user's identity information when applying for a CA certificate to apply for OID registration; optionally, submit identity information, a signature public key, and a randomly selected piece of information through the CA authentication system and signature for registration application for OID. The application information format and registration interface requirements can be designed and implemented with reference to the relevant technical specifications. When issuing a CA certificate for a user, the RA needs to confirm the user's identity information, require that the registration application information submitted by the user is consistent with the identity information, and at the same time verify that the user has the signature private key corresponding to the signature public key. The application example of the present invention can use existing methods in the related art to verify the user's identity information, including: by querying and calling the OID registration information in the OID registration management system or querying other security application system user data, automatic information calling And verification. Optionally, it includes the authentication that the user wishes to appear in the certificate including information such as job title, email, address, domain name, etc., as well as the verification of the user's payment status, contract signing, criminal record and other information.

相关技术中OID的注册申请一般只面向组织机构,本发明应用示例进行OID的分配包含:面向单个对象的OID分配和OID的批量分发。OID registration applications in the related art are generally only oriented to organizations, and the application example of the present invention to allocate OIDs includes: OID allocation oriented to a single object and batch distribution of OIDs.

本发明应用示例OID的分发处理过程可以包括:The distribution processing process of the OID application example of the present invention may include:

根据预先设定的第一标识分发规则,在接收到OID标识申请时,为用户分配OID。通常手动分配是面向节点托管服务的用户,该用户已经完成OID注册,并且开通OID系统节点服务功能。在所注册的OID节点下,根据系统中预设的第一标识分发规则,直接进行OID分配。According to the preset first identification distribution rule, when an OID identification application is received, an OID is allocated to the user. Usually, manual allocation is for users of node hosting services who have completed OID registration and activated the OID system node service function. Under the registered OID node, the OID is directly allocated according to the first identification distribution rule preset in the system.

本发明应用示例接收到批量注册对象的注册申请时,可以对批量用户,根据预设的第二标识分发规则进行OID赋码。When an application example of the present invention receives a registration application for a batch registration object, the batch users can be assigned an OID code according to a preset second identification distribution rule.

本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序来指令相关硬件(例如处理器)完成,所述程序可以存储于计算机可读存储介质中,如只读存储器、磁盘或光盘等。可选地,上述实施例的全部或部分步骤也可以使用一个或多个集成电路来实现。相应地,上述实施例中的每个模块/单元可以采用硬件的形式实现,例如通过集成电路来实现其相应功能,也可以采用软件功能模块的形式实现,例如通过处理器执行存储于存储器中的程序/指令来实现其相应功能。本发明不限制于任何特定形式的硬件和软件的结合。Those of ordinary skill in the art can understand that all or part of the steps in the above method can be completed by instructing relevant hardware (such as a processor) through a program, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk or an optical disk Wait. Optionally, all or part of the steps in the above embodiments may also be implemented using one or more integrated circuits. Correspondingly, each module/unit in the above-mentioned embodiments can be implemented in the form of hardware, for example, an integrated circuit to implement its corresponding function, or it can be implemented in the form of a software function module, for example, a processor executes a function stored in a memory. program/instruction to achieve its corresponding function. The present invention is not limited to any particular form of combination of hardware and software.

虽然本发明所揭露的实施方式如上,但所述的内容仅为便于理解本发明而采用的实施方式,并非用以限定本发明。任何本发明所属领域内的技术人员,在不脱离本发明所揭露的精神和范围的前提下,可以在实施的形式及细节上进行任何的修改与变化,但本发明的专利保护范围,仍须以所附的权利要求书所界定的范围为准。Although the embodiments disclosed in the present invention are as above, the described contents are only the embodiments adopted to facilitate the understanding of the present invention, and are not intended to limit the present invention. Any person skilled in the art to which the present invention belongs, without departing from the spirit and scope disclosed by the present invention, can make any modifications and changes in the form and details of the implementation, but the scope of the patent protection of the present invention still needs to be The scope defined by the appended claims shall prevail.

Claims (26)

1.一种注册管理的方法,其特征在于,包括:1. a method for registration management, is characterized in that, comprises: 父节点对子节点进行授权认证后,为各子节点分配相应的子节点标识符;After the parent node authorizes and authenticates the child nodes, it assigns the corresponding child node identifiers to each child node; 子节点根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。The child node assigns an object identifier OID to the registered object applying for registration according to the assigned child node identifier. 2.根据权利要求1所述的方法,其特征在于,所述注册对象包括以下部分或全部对象:2. The method according to claim 1, wherein the registered objects include some or all of the following objects: 运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object. 3.根据权利要求2所述的方法,其特征在于,所述安全认证对象包括以下一种或一种以上对象:3. The method according to claim 2, wherein the security authentication object comprises one or more of the following objects: 安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate. 4.根据权利要求1~3任一项所述的方法,其特征在于,所述子节点根据分配的子节点标识符,为申请注册的注册对象分配OID包括:4. The method according to any one of claims 1 to 3, wherein the sub-node assigning an OID to a registration object applying for registration according to the assigned sub-node identifier comprises: 所述子节点接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成对应于所述注册对象的OID;When the child node receives the registration application of the registration object, it generates an OID corresponding to the registration object according to the child node identifier assigned to itself and the object identification code determined according to the preset coding strategy; 将生成的所述OID分配给所述注册对象。The generated OID is assigned to the registration object. 5.根据权利要求1~3任一项所述的方法,其特征在于,所述为申请注册的注册对象分配对象标识符OID之后,所述方法还包括:5. The method according to any one of claims 1 to 3, wherein after allocating an object identifier OID to a registration object applying for registration, the method further comprises: 根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;Generate an identification code corresponding to the OID according to the OID assigned to the registered object; 根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;Obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object; 其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code. 6.根据权利要求5所述的方法,其特征在于,所述方法还包括通过以下一种或一种以上方式查询所述注册对象的相关信息:6. The method according to claim 5, characterized in that, the method further comprises querying the relevant information of the registered object by one or more of the following methods: 浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query. 7.根据权利要求5所述的方法,其特征在于,所述相关信息包括全生命周期信息;所述全生命周期信息包括以下部分或全部信息:7. The method according to claim 5, wherein the related information comprises full life cycle information; and the full life cycle information comprises part or all of the following information: 制造信息、加工信息、流通信息、使用信息、维修信息、销毁信息。Manufacturing information, processing information, distribution information, usage information, maintenance information, and destruction information. 8.根据权利要求2所述的方法,其特征在于,所述注册对象为元数据时,所述方法还包括通过以下一种或一种以上方式查询所述元数据:8. The method according to claim 2, wherein when the registration object is metadata, the method further comprises querying the metadata by one or more of the following methods: 通过所述父节点或子节点查询所述元数据;query the metadata through the parent node or child node; 通过预设的外部应用系统调用接口查询所述元数据;Query the metadata through a preset external application system call interface; 通过excel导入方式查询所述元数据;Query the metadata through excel import; 通过可扩展标记语言XML导入方式查询所述元数据。The metadata is queried by way of extensible markup language XML import. 9.根据权利要求3所述的方法,其特征在于,所述注册对象为安全认证证书的注册用户时,所述方法还包括:9. The method according to claim 3, wherein when the registered object is a registered user of a security authentication certificate, the method further comprises: 通过预先设置的第一接口建立安全认证系统与所述父节点和/或子节点的通信连接;Establish a communication connection between the security authentication system and the parent node and/or child node through a preset first interface; 所述安全认证证书的注册用户进行注册申请时,所述父节点或子节点通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息;When the registered user of the security authentication certificate applies for registration, the parent node or child node receives the identity information of the registered user sent by the security authentication system through the first interface; wherein the identity information Including the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate; 接收到所述身份信息的父节点或子节点,根据接收到的身份信息为所述注册用户分配OID。The parent node or child node that has received the identity information allocates an OID to the registered user according to the received identity information. 10.根据权利要求3所述的方法,其特征在于,所述方法还包括:10. The method of claim 3, wherein the method further comprises: 通过预先设置的第二接口建立所述父节点或子节点与安全认证系统的通信连接;Establish a communication connection between the parent node or the child node and the security authentication system through a preset second interface; 所述父节点和/或子节点通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The parent node and/or the child node sends the identity information of the registration object applying for registration to the security authentication system through the second interface, so that the security authentication system can make The registration object performs application processing for a security authentication certificate. 11.根据权利要求1~3任一项所述的方法,其特征在于,所述为申请注册的注册对象分配OID包括:The method according to any one of claims 1 to 3, wherein the assigning an OID to a registration object applying for registration comprises: 接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;When receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule; 接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。When receiving registration applications from two or more registration objects, the corresponding OIDs are respectively allocated to the registration objects sending the registration applications according to the preset second identification distribution rule. 12.根据权利要求1~3任一项所述的方法,其特征在于,所述子节点通过所述父节点的授权认证后,所述方法还包括:12 . The method according to claim 1 , wherein after the child node passes the authorization and authentication of the parent node, the method further comprises: 12 . 所述子节点按照预设应用范围规则,将自身设置为完全公开节点、局部区域公开节点、或私密节点。The child node sets itself as a fully public node, a local area public node, or a private node according to the preset application scope rule. 13.根据权利要求1~3任一项所述的方法,其特征在于,所述方法还包括:13. The method according to any one of claims 1 to 3, wherein the method further comprises: 对所述父节点和/或所述子节点,与所述注册对象的通信接口,采用预设的签名加密策略进行加密。The communication interface between the parent node and/or the child node and the registered object is encrypted using a preset signature encryption strategy. 14.一种注册管理的方法,其特征在于,包括:14. A method for registration management, comprising: 按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;According to the preset authorization policy, determine one or more sub-nodes that need to be authorized and authenticated; 对子节点进行授权认证后,为各子节点分配相应的子节点标识符;After authorizing and authenticating the sub-nodes, assign corresponding sub-node identifiers to each sub-node; 其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application. 15.根据权利要求14所述的方法,其特征在于,所述注册对象包括以下部分或全部对象:15. The method according to claim 14, wherein the registration object includes some or all of the following objects: 运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object. 16.一种注册管理的系统,其特征在于,包括:父节点和子节点;其中,16. A system for registration management, comprising: a parent node and a child node; wherein, 父节点包括授权处理单元,用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The parent node includes an authorization processing unit, which is used for: assigning a corresponding child node identifier to each child node after performing authorization and authentication on the child node; 子节点包括分配处理单元,用于:根据分配的子节点标识符,为申请注册的注册对象分配对象标识符OID。The child node includes an allocation processing unit, configured to: according to the allocated child node identifier, allocate an object identifier OID to the registered object applying for registration. 17.根据权利要求16所述的系统,其特征在于,所述注册对象包括以下部分或全部对象:17. The system according to claim 16, wherein the registration object includes some or all of the following objects: 运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object. 18.根据权利要求17所述的系统,其特征在于,所述安全认证对象包括以下一种或一种以上对象:18. The system according to claim 17, wherein the security authentication object comprises one or more of the following objects: 安全认证证书的注册用户、加密算法、安全套接层、传输层安全服务器、客户端。The registered user, encryption algorithm, secure socket layer, transport layer security server and client of the security authentication certificate. 19.根据权利要求16~18任一项所述的系统,其特征在于,所述分配处理单元具体用于:19. The system according to any one of claims 16 to 18, wherein the allocation processing unit is specifically configured to: 接收到所述注册对象的注册申请时,根据分配给自身的子节点标识符及根据预设的编码策略确定的对象标识编码,生成分配给所述注册对象的OID。When the registration application of the registration object is received, the OID allocated to the registration object is generated according to the child node identifier allocated to itself and the object identification code determined according to the preset coding strategy. 20.根据权利要求16~18任一项所述的系统,其特征在于,所述第二节点还包括编码处理单元和所述系统还包括解析装置;其中,20. The system according to any one of claims 16 to 18, wherein the second node further comprises an encoding processing unit and the system further comprises a parsing device; wherein, 所述编码处理单元用于:根据分配给所述注册对象的OID,生成对应于所述OID的识别编码;The encoding processing unit is used for: generating an identification code corresponding to the OID according to the OID assigned to the registered object; 所述解析装置用于:根据接收到的识别指令获取所述识别编码,并根据所述识别编码解析所述OID,以获得所述注册对象的相关信息;The parsing device is configured to: obtain the identification code according to the received identification instruction, and parse the OID according to the identification code to obtain the relevant information of the registered object; 其中,所述识别编码包括以下一种或一种以上编码:条形码、二维码。Wherein, the identification code includes one or more of the following codes: barcode and two-dimensional code. 21.根据权利要求20所述的系统,其特征在于,所述系统还包括查询装置,用于通过以下一种或一种以上方式查询所述注册对象的相关信息:21. The system according to claim 20, wherein the system further comprises a query device for querying the relevant information of the registered object through one or more of the following methods: 浏览器客户端查询、具备扫描功能的应用的扫描查询、射频识别扫描查询、万维网页面查询。Browser client query, scan query of applications with scanning function, RFID scan query, World Wide Web page query. 22.根据权利要求16~18任一项所述的系统,其特征在于,所述分配处理单元包括第一分发模块和第二分发模块;其中,22. The system according to any one of claims 16 to 18, wherein the distribution processing unit comprises a first distribution module and a second distribution module; wherein, 第一分发模块用于:接收到一个注册对象的注册申请时,根据预先设定的第一标识分发规则为所述注册对象分配OID;The first distribution module is used to: when receiving a registration application for a registration object, allocate an OID to the registration object according to a preset first identification distribution rule; 第二分发模块用于:接收到两个或两个以上注册对象的注册申请时,根据预先设定的第二标识分发规则为发送注册申请的注册对象分别分配相应的OID。The second distribution module is used for: when receiving registration applications of two or more registration objects, respectively assigning corresponding OIDs to the registration objects sending the registration applications according to the preset second identification distribution rules. 23.根据权利要求18所述的系统,其特征在于,所述系统还包括第一接口单元,所述父节点和/或子节点还包括接收单元;其中,23. The system according to claim 18, wherein the system further comprises a first interface unit, and the parent node and/or the child node further comprises a receiving unit; wherein, 所述第一接口单元用于:通过预先设置的第一接口建立安全认证系统与所述父节点或子节点的通信连接;The first interface unit is configured to: establish a communication connection between the security authentication system and the parent node or child node through a preset first interface; 所述接收单元用于:所述安全认证证书的注册用户进行注册申请时,通过所述第一接口接收由所述安全认证系统上送的所述注册用户的身份信息;其中,所述身份信息包括所述注册用户在所述安全认证系统申请所述安全认证证书时提交的身份信息。The receiving unit is configured to: when the registered user of the security authentication certificate applies for registration, receive the identity information of the registered user sent by the security authentication system through the first interface; wherein, the identity information It includes the identity information submitted by the registered user when the security authentication system applies for the security authentication certificate. 24.根据权利要求18所述的系统,其特征在于,所述系统还包括第二接口单元,所述父节点和/或子节点还包括发送单元;其中,24. The system according to claim 18, wherein the system further comprises a second interface unit, and the parent node and/or the child node further comprises a sending unit; wherein, 所述第二接口单元用于:通过预先设置的第二接口建立所述父节点或子节点与安全认证系统的通信连接;The second interface unit is configured to: establish a communication connection between the parent node or the child node and the security authentication system through a preset second interface; 所述发送单元拥有:通过所述第二接口,向所述安全认证系统发送在自身申请注册的注册对象的身份信息,以使所述安全认证系统根据接收到的所述注册信息对所述注册对象进行安全认证证书的申请处理。The sending unit has: through the second interface, send the identity information of the registration object applying for registration to the security authentication system, so that the security authentication system can register the registration information according to the received registration information to the security authentication system. The object performs the application processing of the security authentication certificate. 25.一种节点,其特征在于,包括:确定单元和分配处理单元;其中,25. A node, comprising: a determination unit and an allocation processing unit; wherein, 确定单元用于:按照预设授权策略,确定需要进行授权认证的一个或一个以上子节点;The determining unit is used for: determining one or more sub-nodes that need to be authorized and authenticated according to the preset authorization policy; 分配处理单元用于:对子节点进行授权认证后,为各子节点分配相应的子节点标识符;The assigning processing unit is used for: assigning corresponding child node identifiers to each child node after performing authorization and authentication on the child node; 其中,所述子节点标识符用于确定分配给发起申请注册的注册对象的对象标识符OID。The child node identifier is used to determine the object identifier OID assigned to the registration object that initiates the registration application. 26.根据权利要求25所述的节点,其特征在于,所述注册对象包括以下部分或全部对象:26. The node according to claim 25, wherein the registration object includes some or all of the following objects: 运营机构、实体对象、元数据、安全认证对象。Operating agency, entity object, metadata, security authentication object.
CN201811475593.1A 2018-12-04 2018-12-04 Registration management method, system and node Pending CN109714444A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811475593.1A CN109714444A (en) 2018-12-04 2018-12-04 Registration management method, system and node

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811475593.1A CN109714444A (en) 2018-12-04 2018-12-04 Registration management method, system and node

Publications (1)

Publication Number Publication Date
CN109714444A true CN109714444A (en) 2019-05-03

Family

ID=66253994

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811475593.1A Pending CN109714444A (en) 2018-12-04 2018-12-04 Registration management method, system and node

Country Status (1)

Country Link
CN (1) CN109714444A (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1158720A2 (en) * 2000-05-25 2001-11-28 Alcatel USA Sourcing, L.P. Network node management system and method using proxy by extensible agents
CN102255983A (en) * 2011-07-26 2011-11-23 中国科学院计算机网络信息中心 Entity identifier allocation system, source tracing and authentication methods and server
CN105554169A (en) * 2014-11-04 2016-05-04 中兴通讯股份有限公司 OID configuration and analytic methods, ORS client, and OID node and database thereof
CN106657445A (en) * 2017-03-07 2017-05-10 北京鑫通运科信息技术有限公司 Chinese and English analysis method and system of Internet of Things domain names
CN108848147A (en) * 2018-06-04 2018-11-20 京信通信系统(中国)有限公司 SNMP agent method for device registration, device, computer equipment and storage medium

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1158720A2 (en) * 2000-05-25 2001-11-28 Alcatel USA Sourcing, L.P. Network node management system and method using proxy by extensible agents
CN1326280A (en) * 2000-05-25 2001-12-12 美国阿尔卡塔尔资源有限合伙公司 Network node control system and method by extendable representative use
CN102255983A (en) * 2011-07-26 2011-11-23 中国科学院计算机网络信息中心 Entity identifier allocation system, source tracing and authentication methods and server
CN105554169A (en) * 2014-11-04 2016-05-04 中兴通讯股份有限公司 OID configuration and analytic methods, ORS client, and OID node and database thereof
CN106657445A (en) * 2017-03-07 2017-05-10 北京鑫通运科信息技术有限公司 Chinese and English analysis method and system of Internet of Things domain names
CN108848147A (en) * 2018-06-04 2018-11-20 京信通信系统(中国)有限公司 SNMP agent method for device registration, device, computer equipment and storage medium

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
中华人民共和国国家质量监督检验检疫总局等: "信息技术 开放系统互连 对象标识符(OID)的国家编号体系和操作规程", 《中华人民共和国国家标准GB/T26231—2017》 *
马文静等: "物联网统一标识体系研究", 《信息技术与标准化》 *

Similar Documents

Publication Publication Date Title
EP2510466B1 (en) Delegated and restricted asset-based permissions management for co-location facilities
CN113360862A (en) Unified identity authentication system, method, electronic device and storage medium
CN102882990B (en) A kind of wireless sensor network identification analytic method
US20120159577A1 (en) Anonymous principals for policy languages
US20090320121A1 (en) System and methods for secure service oriented architectures
CN104994064B (en) A kind of authorization and authentication method and system based on client plug-in
CN106341428A (en) Cross-domain access control method and system
CN102263809A (en) A method and device for implementing service security management and control based on an enterprise service bus
CN103428700A (en) Business authentication method and device
CN101567785B (en) Method, system and entity for authenticating notes in network service
CN102420808A (en) Method for realizing single sign-on in telecom online business hall
CN114338527B (en) IPv6 active identifier processing method and system
CN112967012A (en) Design method and system of enterprise cloud platform account
CN113129008A (en) Data processing method and device, computer readable medium and electronic equipment
CN110602218B (en) Method and related device for assembling cloud service in user-defined manner
CN109714444A (en) Registration management method, system and node
Yousefnezhad et al. Authentication and access control for open messaging interface standard
CN114024692B (en) Contract method, device and system
CN116015636A (en) Authentication method, system, equipment and medium of SaaS platform
WO2015149530A1 (en) M2m application service method, device and system
Lee et al. Towards standards-compliant trust negotiation for web services
Memon Implementing Role Based Access in Healthcare Ad Hoc Networks.
Grabatin et al. Improving the scalability of identity federations through level of assurance management automation
CN116562884B (en) Data element circulation method, device, electronic equipment and storage medium
CN115102717B (en) Interconnection and intercommunication data transmission method and system based on user system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20190503