A kind of Information Authentication method, method of payment and financial intelligent payment terminal
Technical field
The present invention relates to a kind of method of Information Authentication, particularly a kind of Information Authentication method, method of payment and financial intelligent payment terminal.
Background technology
The core of carrying out Information Authentication by the Internet is how the carrying out safe transmission between the two ends that needs are verified of authorization information safety do not distorted or usurp.Many methods that are used for sensitive information is carried out safe transmission are arranged in the prior art at present, most typical is exactly at transmitting terminal sensitive information expressly to be encrypted to obtain ciphertext, then ciphertext is transferred to receiving terminal, by receiving terminal ciphertext is decrypted again and obtains plaintext.For the existing the Internet that utilizes, by import the field that sensitive information comes complete operation on webpage, as Web bank, the user need import account No. and corresponding password on webpage; If, bring great threat then can for user's property safety in case the information of being imported on webpage is obtained by other people.Emerging in an endless stream of network hacker, the safety that is endangering network day by day.A kind of means that the hacker generally adopts are to inject the key information that wooden horse comes monitoring users to object-computer.
But the electronic payment terminal of a kind of guarantee information transmission confidentiality and integrality is disclosed among the Chinese patent CN101000703 A, wherein proposed a kind of by POS KEY to the account number of user input with password is encrypted and upload server, need server that ciphertext is carried out completeness check, thereby improved the reliability of information encryption greatly.
When need not that plaintext is uploaded to the network terminal (as PC, PDA etc.), above-mentioned cipher mode can reach cipher round results preferably, yet, some information such as account No. need be presented on the network terminal in mode expressly, require the user to judge whether that with the naked eye input is correct, then can not be presented on the network terminal with form expressly for encrypted message, this situation can not adopt above-mentioned cipher mode; For this situation, what the technological means overwhelming majority of prior art adopted is that the input object type attribute on the network terminal is judged, when the input object type attribute is the password input attributes, payment terminal can be encrypted the information of input subsequently, and when the input object type attribute is non-password input attributes, as seen payment terminal then can allow the user with expressly being uploaded to the network terminal.
Yet, when the incredible network terminal (as PC, PDA etc.) is initiated false or incomplete or when the authentication of being distorted and Transaction Information, this payment terminal can not guarantee that user's key message is maintained secrecy.This is because the information that shows on the network terminal is distorted by other people, and when the input object of customer requirements input encrypted message is distorted to non-password input attributes, the user then can be under unwitting situation, Shu Ru true encrypted message as requested, this moment, this real encrypted message can send to the network terminal with line expressly, caused being stolen by other people.
Summary of the invention
For this reason, we suppose the network terminal such as PC that all are traditional, be unsafe network terminal, any information to described network terminal input is stolen by other people all can, any information from described network terminal output is false or unsafe information, therefore, technical problem to be solved by this invention is to propose a kind of financial intelligent payment terminal that has Information Authentication method and this method of employing of input attributes double verification by equipment.
For this reason, a kind of Information Authentication method of the present invention, when the user began input information by equipment in input object, described equipment was judged the type attribute of input object on the network terminal, is comprised the steps:
I. when the described type attribute of described the above input object of the network terminal is non-password input attributes
A. work as the user and do not sent described password input instruction by described equipment, described equipment receives and preserves to the information of described equipment input the user, and sends described information to the network terminal, is used for showing;
B. when the user had sent described password input instruction by described equipment, described equipment received and preserves in the information of described password input instruction input the user, and sends the character of being arranged to the described network terminal, was used for showing;
Ii. when the described type attribute of described the above input object of the network terminal is the password input attributes
C. when the user had sent described password input instruction by described equipment, described equipment received and preserves the encrypted message that the user imports after described password input instruction, and sent the character of being arranged to the described network terminal;
D. when the user had not sent described password input instruction by described equipment, described equipment was not operated or is reported an error.
Above-mentioned Information Authentication method, any one property value of being arranged in the attribute that described password input attributes is an input object; Described input object is the text input frame on the network terminal page.
A kind of method of payment that adopts above-mentioned Information Authentication method comprises:
I. the user is by the equipment input information;
Ii. described equipment obtains the information of user's input according to above-mentioned Information Authentication method, and it is kept in the described equipment;
Iii. sent when encrypt going up teletype command by described equipment as the user, described equipment carries out demonstration validation with information encryption and the upload server of preserving.
A kind of financial intelligent payment terminal that adopts above-mentioned method of payment, whether described financial intelligent payment terminal can and send password input instruction to the user and carry out double verification the type attribute of input object, comprise: Keysheet module has the button that several are used for the information input on the described Keysheet module;
Memory module is connected with described Keysheet module, is used to preserve the information to described financial intelligent payment terminal input;
Processor is connected with described memory module, and described processor is controlled all physical resources in the described financial intelligent payment terminal, and the information that is kept in the described memory module is encrypted;
Security module is connected with described processor, is used for information is encrypted;
Communication interface is used for communicating between described financial intelligent payment terminal and the server;
Described Keysheet module comprises the cryptographic key submodule, and the user sends password input instruction by described cryptographic key submodule to described financial intelligent payment terminal;
Described button also comprises uploads key, is used for sending to described financial intelligent payment terminal encrypting and last teletype command, finishes the information that is kept in the middle of the described memory module is encrypted, and ciphertext is uploaded to server confirms.
In the above-mentioned financial intelligent payment terminal, described cryptographic key submodule and described memory module independently the cryptographic key information memory cell be connected, described cryptographic key information memory cell is used to store the command information that sends from described cryptographic key submodule.
Above-mentioned financial intelligent payment terminal, the described key of uploading comprises an encryption key and a transmission key that is used to send teletype command that is used to send encrypted instruction.
Above-mentioned financial intelligent payment terminal also comprises the magnetic card module, and described magnetic card module is connected with described processor, sends the information that reads to described processor.
Above-mentioned financial intelligent payment terminal, described communication interface are USB interface, and described information storage module is the information temporary storage module in the processor.
Above-mentioned financial intelligent payment terminal, described processor has again: the packet receiver module, be connected with described memory module, be used for the reception of packet;
Processing module is connected with described packet receiver module, is connected with described security module again, be used for packet is carried out completeness check, after guaranteeing to receive complete packet,, call corresponding bottom safe function according to the safe function interface of analyzing the packet request;
The packet sending module, be connected with described usb interface module by bus, the return information of described packet sending module receiving processor, according to the usb data message format described return information is packaged, and the return results that will organize behind the bag sends to described financial intelligent payment terminal equipment in addition.
Technique scheme of the present invention has the following advantages compared to existing technology:
1, when the user begins input information, by equipment to the type attribute of input object with whether the user is sent password input instruction by described equipment carry out double verification, when the network terminal when the user provides the request of password input, as long as the user sends password input instruction to described equipment, no matter whether the type attribute of the input object on this network terminal is distorted, the encrypted message of after described equipment sends password input instruction, importing the user, will direct encrypted preservation in terminal, and it expressly no longer is sent to the network display module, is guaranteed that the plaintext of this partial information can not obtained by other people; This mode has been avoided when the input attributes of input object is distorted to non-password input attributes by other people, the user under unwitting situation with true password input, thereby stolen by other people.
2, any one property value of being arranged in the described password input attributes attribute that is input object; Described input object is the text input frame on the network terminal page; By any attribute in the text input frame type attribute being carried out the agreement of password input attributes, can avoid other people to obtain the check value of described password input attributes easily effectively.
3, by setting up cryptographic key, can allow the user send password input instruction by described cryptographic key, realize above-mentioned double verification to input object type attribute and password input instruction.
4, communication interface adopts USB interface, can allow payment terminal be suitable for the multiple network terminal with Universal USB interface, makes availability be improved.
Description of drawings
For the easier quilt of content of the present invention is clearly understood, below according to a particular embodiment of the invention and in conjunction with the accompanying drawings, the present invention is further detailed explanation.
Fig. 1 is the Information Authentication flow chart;
Fig. 2 is the method for payment flow chart;
Fig. 3 is the financial intelligent payment terminal schematic diagram;
Fig. 4 is the connection diagram of financial intelligent payment terminal internal module;
Fig. 5 is processor and security module connection diagram
1-housing, 2-keyboard, the 3-magnetic card mouth of swiping the card, the 4-cryptographic key, the 5-USB interface unit, 6-processor, 7-Keysheet module, the 8-communication bus, 9-uploads key, 10-magnetic card module, the 11-USB interface module, 12-memory module, 13-cryptographic key submodule, 14-cryptographic key information memory cell, 15-packet receiver module, 16-packet sending module, the 17-processing module, the non-cryptographic key information memory cell of 18-, 19 security modules;
Embodiment
Embodiment 1
Information Authentication flow chart as shown in Figure 1, when the user begins input information, at first, read input object type attribute by equipment (not marking) herein, this input object is the text input frame on the network terminal page, and the type attribute is the type attribute of being arranged in the attribute of described text input frame; Described equipment judges whether described input object type attribute is the password input attributes,
A) when described input object type attribute was non-password input attributes, whether described equipment has sent password input instruction to the user was judged,
When the user did not send password input instruction by described equipment, described equipment was accepted the information of user to described equipment input, and this information is sent to the network terminal, was used for showing;
When the user had sent password input instruction by described equipment, the information that described equipment is imported after described password input instruction the user received and preserves, and sent the character of being arranged to the described network terminal, was used for showing;
B) if when described input object type attribute is the password input attributes, whether described equipment has sent password input instruction to the user is judged,
When the user did not send described password input instruction by described equipment, prompting then reported an error; And return and continue to read first character that the user imports subsequently.
When the user has sent described password input instruction by described equipment, described equipment receives and preserves the information of the input of user after password input instruction, and sends the character of agreement to the network terminal, is used for showing.
When the user begins input information, by equipment to the type attribute of input object with whether the user is sent password input instruction by described equipment carry out double verification, when the network terminal when the user provides the request of password input, as long as the user sends password input instruction to described equipment, no matter whether the type attribute of the input object on this network terminal is distorted, the encrypted message of after described equipment sends password input instruction, importing the user, to in terminal, directly be saved, and it expressly no longer is sent to the network display module, is guaranteed that the plaintext of this partial information can not obtained by other people; This mode has been avoided when the input attributes of input object is distorted to non-password input attributes by other people, the user under unwitting situation with true password input, thereby stolen by other people.
Embodiment 2
Method of payment flow chart as shown in Figure 2, when the user begins input information, at first, read input object type attribute by equipment (not marking) herein, this input object is the text input frame on the network terminal page, and the type attribute is the type attribute of being arranged in the attribute of described text input frame; Described equipment judges whether described input object type attribute is the password input attributes,
A) when described input object type attribute was non-password input attributes, whether described equipment has sent password input instruction to the user was judged,
When the user did not send password input instruction by described equipment, described equipment was accepted the information of user to described equipment input, and this information is sent to the network terminal, was used for showing;
When the user sent password input instruction by described equipment, the information that described equipment is imported after described password input instruction the user received and preserves, and sent the character of being arranged to the described network terminal, was used for showing;
B) if when described input object type attribute is the password input attributes, whether described equipment has sent password input instruction to the user is judged,
When the user did not send described password input instruction by described equipment, prompting then reported an error; And return and continue to read first character that the user imports subsequently.
When the user has sent described password input instruction by described equipment, described equipment receives the information of the input of user after password input instruction, preserves, and sends the character of agreement to the network terminal, is used for showing.
When the user sent encrypt to go up teletype command after, the information encryption of preserving uploaded onto the server confirms.
Embodiment 3
Financial intelligent payment terminal schematic diagram as shown in Figure 3, wherein said financial intelligent payment terminal has housing 1, keyboard 2, magnetic card swipes the card mouthfuls 3, described keyboard 2 comprises a cryptographic key 4 that is used for the key feeding cipher input instruction, with one be used for uploading key 9 and the USB interface parts 5 that are used for carrying out information communication with external device with what information uploading was given server;
Financial intelligent payment terminal internal module schematic diagram as shown in Figure 4, wherein, described processor 6 has a memory module 12, described memory module 12 comprises independently a cryptographic key information memory cell 14 and a non-cryptographic key information memory cell 18, with described keyboard 2 corresponding Keysheet modules 7, with cryptographic key 4 corresponding cryptographic key submodules 13, with swipe the card mouthful 3 corresponding magnetic card modules 10 of magnetic card, with described USB interface parts 5 corresponding usb interface modules 11.
As shown in Figure 5, described processor 6 has the packet receiver module 15 that is connected with memory module 12 again, is used for the reception of packet;
Processing module 17 is connected with described packet receiver module 15, is connected with described security module 19 again, be used for packet is carried out completeness check, after guaranteeing to receive complete packet,, call corresponding bottom safe function according to the safe function interface of analyzing the packet request;
Packet sending module 16, be connected with described usb interface module 11 by bus, the return information of described packet sending module receiving processor, according to the usb data message format described return information is packaged, and the described return results that will organize behind the bag sends to described financial intelligent payment terminal equipment in addition.
Described Keysheet module 7 is connected with the memory module 12 of described processor 6 by communication bus 8, wherein, 14 of described encrypted message input instruction storing sub-units are connected with described cryptographic key submodule 13, simultaneously 13 of described cryptographic key submodules are connected with described cryptographic key information memory cell 14, and described cryptographic key information memory cell 14 is used to store the password input instruction information of being sent by described cryptographic key submodule 13; Described magnetic card module 10 is connected with described processor 6 by communication bus 8, and described usb interface module 11 is connected with described processor 6 by communication bus 8.
Its working method is: the user swipes the card from the magnetic card of this financial intelligent payment terminal and mouthfuls 3 brushes into magnetic card, financial intelligent payment terminal reads card information, and corresponding instruction information passed to the network terminal, this example is executed and is PC (not marking) herein, show respective page according to instruction on the described PC, when the text input frame of user on the described page begins typing information, these financial intelligent payment terminal USB interface parts read the input object type attribute, wherein, the input object of present embodiment is the text input frame on the network terminal page, and the type attribute is the type attribute in the attribute of described text input frame; Described financial intelligent payment terminal judges whether described text input frame type attribute is the password input attributes,
A) when described text input frame type attribute is non-password input attributes, if it is not that cryptographic key 4 by described financial intelligent payment terminal has sent described password input instruction that described processor is judged information in the described cryptographic key information memory cell 14, then described financial intelligent payment terminal receives and is kept in the described non-cryptographic key memory module 18 to the information of described equipment input the user, simultaneously this information is sent to the network terminal, is used for showing;
If it is that cryptographic key 4 by described financial intelligent payment terminal has sent described password input instruction that described processor is judged information in the described cryptographic key information memory cell 14, then described financial intelligent payment terminal receives and is kept in the described non-cryptographic key memory module 18 to the information of described equipment input the user, send by the agreement character to the network terminal simultaneously, be used for showing;
Whether b) when the type attribute of described text input frame is the password input attributes, described processor 6 at first reads the information in the described cryptographic key information memory cell 14, and be that the user judges by the password input instruction that described cryptographic key 4 sends to it:
If not being the cryptographic key 4 by described financial intelligent payment terminal, the information in the described cryptographic key information memory cell 14 do not sent described password input instruction, then described financial intelligent payment terminal is not accepted the information of user to described financial intelligent payment terminal input, and give wrong input prompt, and return and continue to read first character that the user imports subsequently.
If the information in the described cryptographic key information memory cell 14 has been sent described password input instruction for the cryptographic key 4 by described financial intelligent payment terminal, then described financial intelligent payment terminal receives the encrypted message of the input of user after password input instruction, and this encrypted message is stored in the non-cryptographic key information memory cell 18 of described memory module 12 of described financial intelligent payment terminal, send the character of being arranged to the network terminal again simultaneously, and be presented in the described text input frame input, be used for password input carrying out real time information feedback to the user;
The user uploads key 9 and notifies described financial intelligent payment terminal that the non-password input instruction information that is stored in the described financial intelligent payment terminal is encrypted by pressing, and the ciphertext after will encrypting is sent to server and confirms, and empties described memory module 12 simultaneously.
By setting up cryptographic key, can allow the user send password input instruction by described cryptographic key, realize above-mentioned double verification to input object type attribute and password input instruction.
Described input object type attribute can be any one property value of being arranged in the attribute of text input frame; By any attribute in the text input frame type attribute being carried out the agreement of password input attributes, can avoid other people to obtain the check value of described password input attributes easily effectively.
Obviously, the foregoing description only is for example clearly is described, and is not the qualification to execution mode.For those of ordinary skill in the field, can also make other changes in different forms according to the varying in size of equipment, interface difference on the basis of the above description.Here need not also can't give exhaustive to all execution modes.And conspicuous variation of being extended out thus or change still are among the protection range of the invention.