MLPS Level 3 · Built to GB/T 22239

Qingniu DunanVisitor Management Platform

The next-generation visitor management system for smart parks. End-to-end encryption from booking and approval to access, with zero-knowledge data storage. Every visit stays secure and under control.

MLPS L3
Build Standard
Dual-Alg
Encryption
22+
Modules
Zero-K
Privacy
Alipay Mini ProgramScan with Alipay
Core Capabilities

More than visitor check-in — the security foundation of your park

A complete security loop from data collection, encrypted transport to isolated storage. The platform itself cannot decrypt visitor data — truly "data belongs to the park, platform stays zero-knowledge".

Dual-algorithm envelope encryption (national + international)

Supports both the SM2+SM4-GCM national crypto suite and the RSA-2048+AES-256-GCM international standard. Sensitive fields — name, ID, phone, face — are encrypted at the source with park-specific keys, invisible to the platform throughout.

SM2/SM3/SM4RSA-OAEPAES-256-GCMHMAC-SHA256

X.509 certificate system

Park public keys are distributed via X.509 certificates signed by the platform root CA, with SM2 signature verification and certificate revocation checking (CRL). Certificate validity is verified before every encryption to prevent man-in-the-middle attacks and key tampering.

X.509 v3Root CA verifyCRL revokeSM2 signing

Transport layer hardening

SSL Certificate Pinning + trusted-root public key verification + anti-replay. Security configuration is cached for 24h with auto refresh, ensuring authenticity and integrity of every communication.

Cert pinningTrusted rootAuto refresh

Zero-knowledge privacy

Sensitive visitor data is envelope-encrypted on the client; parks decrypt with their own keys. The platform only relays and stores ciphertext — it can never access plaintext.

Client-side encryptionPark-owned keysPlatform invisible

Native Alipay experience

Built on the native Alipay mini-program framework with the antd-mini component library, deeply integrated with Alipay authorized login, phone binding, and QR-code login to the PC admin console.

Native mini-programantd-miniAuthorized login

End-to-end anti-replay & request signing

Every API request carries Timestamp + Nonce + HMAC signature; the server validates freshness and uniqueness. Combined with token rotation, intercepted requests cannot be replayed; security configuration supports remote push and dynamic updates.

Timestamp + NonceHMAC-SHA256Auto token refreshRemote config push
Security Architecture

Dual-layer hardening, defense in depth

Transport and application layers are hardened independently, forming a defense-in-depth system. Even if one layer is breached, the other still protects the data.

01

Transport Layer Security

Transport Layer Security

  • Trusted-root public key verification
    RSA-SHA256 signature validation ensures security config comes from a trusted source
  • SSL Certificate Pinning
    Pins the server certificate fingerprint to prevent MITM proxy attacks
  • Anti-replay
    Each request carries a unique Timestamp + Nonce; server validates freshness
  • Dynamic security config management
    24h cache + auto refresh; remote push without client upgrade
02

Application Layer Security

Application Layer Security

  • System 1: RSA2 + AES-256-GCM + HMAC
    RSA-2048-OAEP wraps keys, AES-256-GCM encrypts data, HMAC-SHA256 prevents tampering
  • System 2: SM2 + SM4-GCM + HMAC
    Full national-crypto pipeline, compliant with the State Cryptography Administration
  • X.509 certificate chain validation
    Park certificates signed by the platform root CA; mini-program verifies signature + revocation status
  • Park zero-knowledge storage
    Platform stores ciphertext only; keys are held entirely by the park. Binary assets like face images are encrypted
Business Modules

Covering the full visitor lifecycle

From booking and approval to entry access, from interview registration to security scheduling — one mini-program covers every visitor management scenario in the park.

Visitor Reservation

Three-step form with envelope-encrypted submission. After host-company approval, an access QR code is generated for entry. Supports inviting visitors, reservation history, and cancellation.

Interview Registration

Companies generate an interview QR code; candidates scan to self-register. Candidate list management and status tracking — fully paperless.

Park Management

Dashboard overview + building CRUD + access-point management + device management + security scheduling. Park admins can complete all basic configuration from the mini-program.

Enterprise Management

Tenant management, enterprise profile maintenance, and park association. Enterprises can review visit records and approve visitor reservations.

Tech Stack

Reliable technology choices

Built on the native Alipay framework with antd-mini components from Ant Design, embedding both national and international encryption suites to meet financial-grade security standards.

Alipay native framework

Component2 mode

antd-mini

v2.4.0 library

National crypto suite

SM2 / SM3 / SM4

International encryption

RSA + AES-256-GCM

X.509 certificates

jsrsasign v11

HMAC anti-tamper

SHA-256 signing

Spring Boot backend

bigpeng-java

minidev build

v2.2.5

Safeguarding park security

Qingniu Dunan Visitor — built to MLPS Level 3, national-grade encryption, zero-knowledge privacy architecture