CN102025738A - Method, equipment and system for processing transaction message - Google Patents

Method, equipment and system for processing transaction message Download PDF

Info

Publication number
CN102025738A
CN102025738A CN2010105808967A CN201010580896A CN102025738A CN 102025738 A CN102025738 A CN 102025738A CN 2010105808967 A CN2010105808967 A CN 2010105808967A CN 201010580896 A CN201010580896 A CN 201010580896A CN 102025738 A CN102025738 A CN 102025738A
Authority
CN
China
Prior art keywords
transaction message
message section
show
client host
needs
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2010105808967A
Other languages
Chinese (zh)
Other versions
CN102025738B (en
Inventor
陆舟
于华章
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Feitian Technologies Co Ltd
Original Assignee
Beijing Feitian Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=43866592&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=CN102025738(A) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by Beijing Feitian Technologies Co Ltd filed Critical Beijing Feitian Technologies Co Ltd
Priority to CN201010580896.7A priority Critical patent/CN102025738B/en
Publication of CN102025738A publication Critical patent/CN102025738A/en
Application granted granted Critical
Publication of CN102025738B publication Critical patent/CN102025738B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention provides a method, equipment and a system for processing a transaction message and belongs to the field of information security. The method comprises the steps of: generating the transaction message by a client host according to transaction information, dividing the transaction message into a plurality of sections based on the fact whether the content in the transaction message needs to be displayed, sending the divided transaction message to intelligent secret key equipment and simultaneously marking the transaction message needing to be displayed, receiving the divided transaction message sections by the intelligent secret key equipment, operating the transaction message sections and judging whether the transaction message sections need to be displayed, if yes, storing the transaction message sections needing to be displayed in a display cache area, displaying the transaction message sections stored in the display cache area after receiving a signature instruction, performing signature operation, and then feeding back the signature result to the client host, if no, directly displaying the transaction message sections stored in the display cache area after receiving the signature instruction, performing the signature operation, and feeding back the signature result to the client host.

Description

A kind of processing method of transaction message, equipment and system
Technical field
The present invention relates to information security field, particularly a kind of processing method of transaction message, equipment and system.
Background technology
At present, the transmission of network file, internet bank trade have become people's life or part of work, so the fail safe of network just becomes the focus that people pay close attention to more.
Can digital signature technology not appearred by people's malicious modification in order to ensure network data in transmission course.Digital signature technology promptly carries out the technology of authentication.Along with the development and the application of this technology, especially on the net in the process that bank concludes the business, the signature process of data has been developed into and can carry out in a kind of intelligent cipher key equipment.The process that the signature of data is carried out in intelligent cipher key equipment mainly comprises: client host is before mailing to server with data, earlier data are sent to intelligent cipher key equipment inside, finish signature process again in intelligent cipher key equipment inside, guarantee the fail safe of data message with this to data.
In the prior art, in order to guarantee the fail safe of digital signature, normally according to default rule transaction message is resolved in intelligent cipher key equipment inside, the content that parsing is obtained is signed then, but because the resource-constrained of intelligent cipher key equipment, in intelligent cipher key equipment inside complicated or long transaction message resolved with regard to difficult and therefore also to be difficult to handle the rule of more complicated, can not handle long transaction message to realize.
Summary of the invention
In order to solve deficiency of the prior art, the invention provides a kind of processing method, equipment and system of transaction message, guaranteed the fail safe of signature, improved flexibility, accelerated treatment effeciency to transaction message.
A kind of processing method of transaction message, described method comprises:
Client host and intelligent cipher key equipment connect, and generate transaction message according to Transaction Information;
Whether described client host needs to show according to the content in the described transaction message is divided into plurality of sections with described transaction message;
The transaction message section of described client host after with described cutting apart issued described intelligent cipher key equipment successively, and the transaction message section that needs are shown is carried out mark simultaneously;
Described intelligent cipher key equipment receives the transaction message section after described cutting apart, and described transaction message section is carried out computing, and judge whether described transaction message section needs to show;
If need, then the described transaction message section that needs to show is deposited in the display buffer district, and after receiving signature command, show the transaction message section that is stored in the display buffer district, carry out signature operation, the result that will sign returns to described client host;
If do not need, then directly after receiving signature command, show the transaction message section that is stored in the display buffer district, and carry out signature operation that the result that will sign returns to described client host.
A kind of client host, described client host is connected with intelligent cipher key equipment, comprising:
Interface module is used for being connected with described intelligent cipher key equipment;
Communication module is used for carrying out communication with described intelligent cipher key equipment;
Input module is used for importing relationship trading information for the user;
Generation module is used for generating transaction message according to the described Transaction Information of user's input;
Judge module is used for judging whether the content of described transaction message needs to show;
Cut apart module, be used for judging the content of the described transaction message that obtains whether needs show described transaction message is divided into plurality of sections according to described judge module;
Mark module, the transaction message section that is used for described needs are shown is carried out mark.
A kind of intelligent cipher key equipment, described intelligent cipher key equipment is connected with client host, comprising:
Interface module is used for being connected with described client host;
Communication module is used for carrying out communication with described client host, specifically is used to receive the transaction message section after cutting apart that described client host sends;
Computing module is used for described transaction message section is carried out computing;
Judge module is used to judge whether described transaction message section needs to show;
Memory module is used to store the transaction message section that described judge module judges that the needs that obtain show;
Display module is used for the transaction message section that shows that described memory module is stored;
Signature blocks is used to carry out signature operation.
A kind of treatment system of transaction message, described system comprises client host and intelligent cipher key equipment, described intelligent cipher key equipment is connected with described client host;
Described client host, be used for connecting with described intelligent cipher key equipment, generate transaction message according to Transaction Information, described transaction message is resolved, whether need to show according to the content in the described transaction message described transaction message is divided into plurality of sections, transaction message section after described cutting apart is sent to described intelligent cipher key equipment, and the transaction message section that needs are shown is carried out mark simultaneously;
Described intelligent cipher key equipment, be used to receive the transaction message section after cutting apart that described client host sends, described transaction message section is carried out computing, judge whether described transaction message section needs to show, if need, then described transaction message section is deposited in the display buffer district, and after receiving signature command, show the described transaction message section that is stored in the display buffer district, carry out signature operation, and the result that will sign returns to described client host, if do not need, then directly shows the described transaction message section that is stored in the display buffer district after receiving signature command, carry out signature operation, and the result that will sign returns to described client host.
Beneficial effect of the present invention is: the invention provides the method, apparatus and system that a kind of transaction message is handled, by method, apparatus and system provided by the invention, transaction message can be resolved at client host, need not to resolve in intelligent cipher key equipment inside, and guaranteed the safety that intelligent cipher key equipment is signed to the information of needs signature, improved flexibility, accelerated treatment effeciency transaction message.
Description of drawings
The flow chart of the processing method of a kind of transaction message that Fig. 1 provides for present embodiment;
The structure chart of the treatment facility of a kind of transaction message that Fig. 2 provides for present embodiment;
The treatment system figure of a kind of transaction message that Fig. 3 provides for present embodiment.
Embodiment
For making the purpose, technical solutions and advantages of the present invention clearer, embodiment of the present invention is done detailed description further below in conjunction with accompanying drawing.
Embodiment 1
The embodiment of the invention provides a kind of processing method of transaction message, specifically is that USBKey describes with the intelligent cipher key equipment.In the present embodiment, USB Key is connected to client host, and has output device and input unit on the above-mentioned USB Key.
Referring to Fig. 1, a kind of processing method of transaction message, the specific implementation step is as follows:
Step 101: client host and USB Key connect;
Step 102: client host receives the Transaction Information of user's input, and generates transaction message according to above-mentioned Transaction Information;
In present embodiment step 102, the Transaction Information of user that client host receives input can be that the input unit by client host receives, simultaneously when having input unit on the USB Key, the Transaction Information of user's input that client host receives also can be that the input unit by USB Key receives;
In embodiments of the present invention, the Transaction Information of user input can for:
Produce account: 6222030200000384
Change account over to: 6227881000987
The amount of money: 1000.5
Time: 2009-12-06
In embodiments of the present invention, the form of transaction message has multiple;
Preferably, in the present embodiment, can generate the transaction message of XML form according to above-mentioned Transaction Information, be transaction message 1, particularly, transaction message 1 is:
<? xml version=" 1.0 " encoding=" utf-8 "?〉<SignData〉<TradeType name=" row in transfer accounts "〉innerTransfer</TradeType〉<SubType name=" wage card "〉salary card</SubType〉<Timestamp〉12345</Timestamp〉<Fields〉<PayerAcNo name=" produce account: "〉6222030200000384</PayerAcNo〉<PayeeAcNo name=" change over to account: "〉6227881000987</PayeeAcNo〉<Amount name=" amount of money: "〉1000.5</Amount〉<TranDate name=" time: "〉2009-12-06</TranDate〉<JnlNo〉xxxxxxx</JnlNo〉</Fields〉</SignData 〉
Perhaps,
In the embodiment of the invention, the Transaction Information of user input can also for:
Change account number over to: 6227881000987
The amount of money: 1000.5
Correspondingly, also can generate the transaction message that is not the XML form according to above-mentioned Transaction Information, be transaction message 2, particularly, the transaction message 2 of generation is:
The * toAccountNo=6227881000987*amount=1000.5*purpose=transaction payment of transferring accounts in accountNoFrom=6222030200000384*fromName=is capable * remark=2009-12-06
Whether step 103: client host is resolved transaction message, need to show according to the content in the transaction message transaction message is divided into plurality of sections;
In present embodiment step 103, whether client host needs to show that according to the content in the transaction message operation that transaction message is divided into plurality of sections is specially:
Whether client host needs to show according to the content in the rule judgment transaction message of making an appointment earlier, whether needs show that transaction message is divided into plurality of sections according to the content in the transaction message again, and the rule of wherein making an appointment is that client host and USB Key make an appointment;
Particularly, in the present embodiment, when transaction message was the transaction message of XML form, the rule of making an appointment was:
Judge whether contain the Fields element in the transaction message, in transaction message, contain the Fields element, and the daughter element of Fields element has the name attribute, then need content displayed to comprise the value of name attribute and the value of element; And,, then need content displayed also to comprise the value of name attribute in these elements if having the name attribute in these elements for other elements in the transaction message; And the display part of each element has delegation of one's own;
For example, according to above-mentioned rule, can obtain needing content displayed to be in the transaction message 1 of present embodiment:
Transfer accounts in the row
Wage card
Produce account: 6222030200000384
Change account over to: 6227881000987
The amount of money: 1000.5
Time: 2009-12-06
Correspondingly, the some transaction message sections after transaction message 1 is cut apart are specially:
<?xml?version=″1.0″encoding=″utf-8″?><SignData><TradeType?name=″
Transfer accounts in the row
″>innerTransfer</TradeType><SubType?name=″
Wage card
″>salary card</SubType><Timestamp>12345</Timestamp><Fields><PayerAcNo?name=″
Produce account:
″>
6222030200000384
</PayerAcNo><PayeeAcNo?name=″
Change account over to:
″>
6227881000987
</PayeeAcNo><Amount?name=″
The amount of money:
″>
1000.5
</Amount><TranDate?name=″
Time:
″>
2009-12-06
</TranDate><JnlNo>xxxxxxx</JnlNo></Fields></SignData>
Transaction message and former transaction message after cutting apart as can be seen from above-mentioned transaction message are as broad as long, transaction message do not cut apart transaction message is changed, each row is just represented one section transaction message after cutting apart, in the present embodiment, client host has been divided into 21 sections with transaction message;
Perhaps,
When transaction message is not the transaction message of XML form, and transaction message is specially the X=Y structure, and the centre is when separating with * number, the rule of then making an appointment can also for:
Y when needing content displayed to be X=toAccountNo and X=amount, what wherein toAccountNo represented in practical business is to change account number over to, is the amount of money and Amount represents;
For example, according to above-mentioned rule, can obtain needing content displayed to be in the transaction message 2 of present embodiment:
6227881000987
1000.5
Correspondingly, the some transaction message sections after transaction message 2 is cut apart are specially:
* toAccountNo=transfers accounts in accountNoFrom=6222030200000384*fromName=is capable
6227881000987
*amount=
1000.5
* purpose=transaction payment * remark=2009-12-06
Also as can be seen transaction message is not cut apart from above-mentioned transaction message transaction message is changed, each row is just represented one section transaction message after cutting apart, and in the present embodiment, client host has been divided into 5 sections with transaction message;
Simultaneously, in the present embodiment, can also will separate with separator between the some transaction message sections after cutting apart, separator can be " * " number, " # " and "; " or the like.
Step 104: several transaction message sections after client host will be cut apart are issued USB Key successively, and the transaction message section that needs are shown is carried out mark simultaneously;
Particularly, in the present embodiment, some transaction message sections after client host will be cut apart by some Hash instructions are issued USB Key, wherein every instruction comprises a transaction message section, the length of each transaction message section can be inequality, last transaction message section can be equally be issued USBKey by Ha sh instruction, finishes with not showing with the Sign instruction of data that transaction message sends then, perhaps directly carries last transaction message section with the Sign instruction and issues USB Key;
Wherein, the method for the transaction message section of needs demonstration being carried out mark has two kinds, is respectively:
Method one is carried out mark with checking marker character to the transaction message section that needs show;
With transaction message 1 is that example describes, and in transaction message 1, the transaction message section that need carry out mark is specially:
Transfer accounts in the row
Wage card
Produce account:
6222030200000384
Change account over to:
6227881000987
The amount of money:
1000.5
Time:
2009-12-06
Wherein, checking marker character is that client host and USB Key make an appointment, and the transaction message section is carried out mark transaction message itself is not had any change with checking marker character;
Further, in the present embodiment, the literal and the control character that add the modification of some computings that do not participate in signing in can also the transaction message section after cutting apart, to improve display effect, improve user experience, the literal and the control character of these modification property can't change transaction message section and precedence thereof.
Method two is provided with the transaction message section of coming needs show by the corresponding flag bit to each transaction message section and carries out mark, wherein flag bit be meant that client host and USB Key make an appointment with some bytes;
In the present embodiment, transaction message section after each is cut apart one first flag bit of all making an appointment, can carry out mark to the transaction message section that needs show by first flag bit being provided with not only, can also whether participate in computing to this transaction message section and carry out mark, when first flag bit is set to first about definite value, represent that then this transaction message section participates in computing, but do not need to show, when first flag bit is set to second about definite value, represent that then this transaction message section participates in computing, and need show, when first flag bit is set to the 3rd about definite value, represent that then this transaction message section does not participate in computing, but need show; Wherein first about definite value, second about definite value and the 3rd about definite value are that client host and USB Key make an appointment;
Particularly, it is that example illustrates that present embodiment is respectively 0,1 and 2 with first about definite value, second about definite value and the 3rd about definite value, is about to first flag bit and is set at 0 o'clock, represents that this transaction message section participates in computing, but does not need to show; First flag bit is set at 1 o'clock, represents that this transaction message section participates in computing, and need show; First flag bit is set at 2 o'clock, represents that this transaction message section does not participate in computing, but need show;
In the method, client host also needs to pass down some and need show but do not need the Chinese Fields that participates in signing in the transaction message section that passes down after cutting apart, so that the user understands;
Be that example describes specifically with transaction message 2, in transaction message 2, client host also needs to pass down " change over to account number: " and " amount of money: " Chinese Fields in the transaction message section that passes down after cutting apart, and carry out mark by the first flag bit setting of each transaction message section correspondence being come whether each transaction message section needed to show and whether need to participate in computing, specific as follows:
* toAccountNo=transfers accounts in accountNoFrom=6222030200000384*fromName=is capable
First flag bit is set to 0;
Change account number over to:
First flag bit is set to 2;
6227881000987
First flag bit is set to 1;
*amount=
First flag bit is set to 0;
The amount of money:
First flag bit is set to 2;
1000.5
First flag bit is set to 1;
* purpose=transaction payment * remark=2009-12-06
First flag bit is set to 0;
Further,, make user's easy to understand, can also when making an appointment first flag bit, arrange one second flag bit, strengthen display effect when first flag bit is set, specifically see table by second flag bit is set in order to strengthen display effect;
Figure BSA00000379784200121
Correspondingly, the actual sequence of message that passes down is as follows:
Figure BSA00000379784200122
Figure BSA00000379784200131
Correspondingly, final display effect is:
Change account number over to: 6227881000987
The amount of money: 1000.5
Step 105:USB Key receives several transaction message sections after cutting apart of client host transmission successively, and to the transaction message section that the receives HASH computing of dividing into groups, keep this result calculated and grouping rest parts, as the initial parameters of next Hash grouping computing, and cumulative data length;
In present embodiment step 105, the HASH computing of dividing into groups specifically also comprises to the transaction message section that receives: judgement is with checking marker character the transaction message section that needs show to be carried out mark, still by first flag bit being provided with come the transaction message section that needs are shown to carry out mark;
When being when checking transaction message section that marker character shows needs and carry out mark, the then All Activity message segment that receives of 105 pairs of this steps HASH computing of dividing into groups;
When being by first flag bit being provided with when coming that the transaction message section that needs show carried out mark, then this step 105 also comprises and judges that first flag bit is set to 0 or 1 or be set to 2, if be set to 0 or at 1 o'clock, represent that then this transaction message section need participate in the computing of signing, to the HASH computing of dividing into groups of this transaction message section, if be set at 2 o'clock, represent that then this transaction message section does not need to participate in the signature computing, do not need the HASH computing of dividing into groups of this transaction message section.
Step 106:USB Key judges whether the transaction message section that receives needs to show, if need, then execution in step 107, otherwise direct execution in step 108;
In the present embodiment, correspondingly, USB Key judges that the method whether the transaction message section needs to show also comprises two kinds, and is specific as follows:
Method 1 judges whether contain the marker character of checking of making an appointment in the transaction message section, if having, illustrates that then this transaction message section need show, if do not have, illustrates that then this transaction message section does not need to show;
Method 2 judges that first flag bit of transaction message section correspondence is to be set to 0, still is set to 1 or 2, if be set to 0, represents that then this transaction message section does not need to show, if be set to 1 or 2, represents that then this transaction message section need show.
Step 107: this transaction message section is deposited in the display buffer district;
Step 108: judge whether the instruction that receives is the Sign instruction, if, then execution in step 109, if not, then return step 105, continue next section transaction message section that the receives HASH computing of dividing into groups is kept this result calculated and grouping rest parts, as the initial parameters of next Hash grouping computing, and cumulative data length;
Step 109: on the basis of current initial parameters, add these data that receive, data total length and cover, generate the final Hash result of whole message;
Step 110:USB Key shows the transaction message section that is stored in the buffer memory viewing area, waits for user's input information;
In the present embodiment, if when be example with transaction message 1, then the information of USB Key demonstration can be:
Transfer accounts in the row
Wage card
Produce account: 6222030200000384
Change account over to: 6227881000987
The amount of money: 1000.5
Time: 2009-12-06
Perhaps, the information of demonstration can also be:
The wage card of transferring accounts in the row produces account: 6222030200000384 change account over to: 6227881000987 amount of money: 1000.5 times: 2009-12-06
If when being example with transaction message 2, then the information of USB Key demonstration can be:
Change account number over to: 6227881000987
The amount of money: 1000.5
Step 111: the information to user's input judges that if the information of user's input is cancellation information, then execution in step 112, if the information of user's input is confirmation, then execution in step 113;
Step 112:USB Key is to client host main frame prompting error message or cancellation information;
Step 113:USB Key signs to the final Ha sh result who calculates in the step 109, and the result that will sign returns to client host.
The method that present embodiment provides a kind of transaction message to handle, the method that provides by present embodiment, transaction message can be resolved at client host, need not to resolve in USB Key inside, and guaranteed the safety that USB Key signs to the information of needs signature, improved flexibility, accelerated treatment effeciency transaction message.
Embodiment 2
The embodiment of the invention provides a kind of client host 20 and a kind of intelligent cipher key equipment 30, so that the method in the foregoing description 1 is implemented.Wherein, intelligent cipher key equipment 30 links to each other with client host 20, and referring to Fig. 2, client host 20 comprises: interface module 21, communication module 22, input module 23, generation module 24, judge module 25, cut apart module 26 and mark module 27;
Interface module 21 is used for client host 20 and connects with intelligent cipher key equipment 30;
Communication module 22, be used for client host 20 and carry out communication with intelligent cipher key equipment 30, specifically be used for the transaction message section after cutting apart is sent intelligent cipher key equipment 30, send signature command to intelligent cipher key equipment 30, also be used to receive error message or the cancellation information that intelligent cipher key equipment 30 returns, and also be used to receive the signature result that intelligent cipher key equipment 30 returns;
Input module 23 is used for importing relationship trading information for the user;
Generation module 24 is used for the Transaction Information generation transaction message by input module 23 inputs according to the user;
Whether judge module 25 is used for needing to show according to the content of the rule judgment transaction message of making an appointment;
Cut apart module 26, be used for whether needing to show to come transaction message is cut apart, transaction message is divided into plurality of sections according to the content of transaction message;
Correspondingly, communication module 22 specifically is used for sending to intelligent cipher key equipment 30 successively with cutting apart the plurality of sections transaction message that module 26 obtains;
Mark module 27, the transaction message section that is used for needs are shown is carried out mark.
In an embodiment, the method that the transaction message section that 27 pairs of needs of mark module show is carried out mark has two kinds, and is as follows:
Method 1 is carried out mark with checking marker character to the transaction message section that needs show;
Method 2 is provided with the transaction message section that needs are shown to carry out mark by first flag bit to every section transaction message section correspondence;
Further, when the transaction message section that shows when 2 pairs of needs of using method is carried out mark,, can also second flag bit of every section transaction message section correspondence be provided with, thereby strengthen display effect, be convenient to the user and understand in order to strengthen display effect.
In the present embodiment, client host 20 can also comprise:
Parsing module 28 is used for resolving cutting apart the transaction message that 26 pairs of transaction message of module generate generation module 24 before cutting apart;
Add module 29, be used for modification literal and control character that transaction message section after cutting apart adds some computings that do not participate in signing,, improve user experience to improve display effect.
Each module of the embodiment of the invention can be integrated in one, and also can separate deployment, and above-mentioned module can be merged into a module, also can further split into a plurality of submodules.
Further, in the present embodiment, intelligent cipher key equipment 30 also comprises: interface module 31, communication module 32, computing module 33, judge module 34, memory module 35, display module 36, input module 37 and signature blocks 38;
Interface module 31 is used for intelligent cipher key equipment 30 and connects with client host 20;
Communication module 32 is used for intelligent cipher key equipment 30 and carries out communication with client host 20, specifically is used to receive some transaction message sections that client host 20 sends;
The HASH computing of dividing into groups of computing module 33, the transaction message section that is used for that communication module 32 is received keeps this result calculated and grouping rest parts, as the initial parameters of next Hash grouping computing, and cumulative data length;
Judge module 34 is used to judge whether the transaction message section that communication module 32 receives needs to show;
Correspondingly, in the present embodiment, the method whether the transaction message section that judgement receives needs to show also has two kinds, and is as follows:
Method 1 judges in the transaction message section that receives whether contain the marker character of checking of making an appointment, if having, represents that then this transaction message section need show, if do not have, represents that then this transaction message section does not need to show;
Method 2, first flag bit of judging the transaction message section correspondence that receives is to be set to first about definite value, still be set to second about definite value or the 3rd about definite value, if when being set to the first about definite value, represent that then this transaction message section does not need to show, if when being set to second about definite value or the 3rd about definite value, represent that then this transaction message section need show.
Correspondingly, in the present embodiment, before 33 pairs of transaction message sections of computing module are divided into groups the HASH computing, judge module 34 also is used to judge with checking transaction message section that marker character shows needs and carries out mark, still by first flag bit being provided with come the transaction message section that needs are shown to carry out mark;
When being when checking transaction message section that marker character shows needs and carry out mark, the then All Activity message segment that receives of 33 pairs of communication modules 32 of the computing module HASH computing of dividing into groups;
When being by first flag bit being provided with when coming that the transaction message section that needs show carried out mark, then judge module 34 is used to also judge that first flag bit is set to first about definite value or second about definite value or is set to the 3rd about definite value, if when being set to the first about definite value or the second about definite value, represent that then this transaction message section need participate in the computing of signing, the HASH computing of dividing into groups of 33 pairs of these transaction message sections of computing module, if when being set to the 3rd about definite value, represent that then this transaction message section does not need to participate in the signature computing, computing module 33 does not need the HASH computing of dividing into groups of this transaction message section.
Memory module 35 is used for storing this transaction message section when judge module 34 judges that obtaining the transaction message section need show;
Further, judge module 34 is used to also judge whether communication module 32 receives instruction is the Sign instruction, if, then computing module 33 also is used for adding these data that receive, data total length and cover on the basis of current initial parameters, generate the final Hash result of whole message, if not, then computing module 33 continues the transaction message section that communication module 32 the receives HASH computing of dividing into groups.
Display module 36 is used for showing the transaction message section that is stored in the buffer memory viewing area;
Input module 37 is used for importing Transaction Information for the user, also is used for importing cancellation information or confirmation for the user;
Correspondingly, judge module 34 is used to also to judge that the user is cancellation information or confirmation by input module 37 inputs;
If cancellation information, then communication module 32 also is used for sending error message or cancellation information to client host 20;
If confirmation, then signature blocks 38 be used for when judge module 33 judge obtain user's input be confirmation the time, the final Ha sh result that computing module 33 is obtained signs;
Correspondingly, the communication module 32 signature result that also is used for signature blocks 38 is obtained returns to client host 20.
Present embodiment provides a kind of client host and a kind of intelligent cipher key equipment, transaction message can be resolved at client host, need not to resolve in intelligent cipher key equipment inside, and guaranteed the safety that intelligent cipher key equipment is signed to the information of needs signature, improved flexibility, accelerated treatment effeciency transaction message.
Embodiment 3
Present embodiment provides a kind of treatment system of transaction message, and referring to Fig. 3, this system comprises client host 20 and intelligent cipher key equipment 30, and intelligent cipher key equipment 30 is connected with client host 20;
Wherein client host 20, be used for connecting with intelligent cipher key equipment 30, Transaction Information according to user's input generates transaction message, transaction message is resolved, whether need to show according to the content in the transaction message transaction message is divided into plurality of sections, instruct several transaction message sections after will cutting apart to send to intelligent cipher key equipment 30 successively by some HASH, the transaction message section that needs are shown is carried out mark simultaneously;
Intelligent cipher key equipment 30, be used for receiving successively some the HASH instructions that include the transaction message section after cutting apart that client host 20 sends, to the transaction message section that the receives HASH computing of dividing into groups, the transaction message section that needs show is deposited in the buffer memory viewing area, after the signature command that receives client host 20 transmissions, show the transaction message section that need show, and sign, and the result that will sign returns to described client host 20.
In the present embodiment, the Transaction Information of user's input can be the Transaction Information that the user passes through the input unit input of client host 20, can also be the Transaction Information that the user passes through the input unit input of intelligent cipher key equipment 30;
Further, the method that 20 pairs of client hosts need the transaction message section of demonstration to carry out mark has two kinds, and is as follows:
Method 1 is carried out mark with checking marker character to the transaction message section that needs show;
Method 2 is provided with the transaction message section that needs are shown to carry out mark by first flag bit to every section transaction message section correspondence;
Further, when the transaction message section that shows when 2 pairs of needs of using method is carried out mark,, can also second flag bit of every section transaction message section correspondence be provided with, thereby strengthen display effect, be convenient to the user and understand in order to strengthen display effect.
And in the present embodiment, the transaction message section that 30 pairs of intelligent cipher key equipments receive is divided into groups before the HASH computing, also comprise: judgement is with checking marker character the transaction message section that needs show to be carried out mark, still is by first flag bit being provided with come the transaction message section that needs are shown to carry out mark;
When being when checking transaction message section that marker character shows needs and carry out mark, the then All Activity message segment that receives of 30 pairs of the intelligent cipher key equipments HASH computing of dividing into groups;
When being by first flag bit being provided with when coming that the transaction message section that needs show carried out mark, then intelligent cipher key equipment 30 also comprises and judges that first flag bit is set to 0 or 1 or be set to 2, if be set to 0 or at 1 o'clock, represent that then this transaction message section need participate in the computing of signing, to the HASH computing of dividing into groups of this transaction message section, if be set at 2 o'clock, represent that then this transaction message section does not need to participate in the signature computing, do not need the HASH computing of dividing into groups of this transaction message section.
After the transaction message that receives after cutting apart, also comprise: judge whether the transaction message section that receives needs to show, judges that wherein the method whether the transaction message section needs to show also has two kinds, as follows:
Method 1 judges in the transaction message section that receives whether contain the marker character of checking of making an appointment, if having, represents that then this transaction message section need show, if do not have, represents that then this transaction message section does not need to show;
Method 2, first flag bit of judging the transaction message section correspondence that receives is to be set to first about definite value, still be set to second about definite value or the 3rd about definite value, if when being set to the first about definite value, represent that then this transaction message section does not need to show, if when being set to second about definite value or the 3rd about definite value, represent that then this transaction message section need show.
Correspondingly, the transaction message section that the needs that are stored in the buffer memory viewing area show is divided into groups can also comprise before the HASH computing: judge whether this transaction message section that need show needs to participate in the signature computing, first flag bit of promptly judging this transaction message section correspondence is to be set to second about definite value, still be set to the 3rd about definite value, if when being set to the second about definite value, represent that then this transaction message section need participate in the computing of signing, to the HASH computing of dividing into groups of this transaction message section, if when being set to the 3rd about definite value, represent that then this transaction message section does not need to participate in the signature computing, do not need the HASH computing of dividing into groups of this transaction message section.
Correspondingly, intelligent cipher key equipment 30 carries out signature operation showing the described transaction message section that is stored in the display buffer district, and the operation that the signature result is returned to client host 20 is specially:
Intelligent cipher key equipment 30 shows the transaction message section that is stored in the buffer memory viewing area, wait for user's input information, if the information of user's input is cancellation information, then intelligent cipher key equipment 30 is to client host 20 prompting error message or cancellation information, if the information of user's input is confirmation, then 30 pairs of final operation results of intelligent cipher key equipment are signed, and the result that will sign returns to client host 20.
Present embodiment provides a kind of treatment system of transaction message, transaction message can be resolved at client host, need not to resolve in intelligent cipher key equipment inside, and guaranteed the safety that intelligent cipher key equipment is signed to the information of needs signature, improved flexibility, accelerated treatment effeciency transaction message.
The above; only be the specific embodiment of the present invention, but protection scope of the present invention is not limited thereto, anyly is familiar with those skilled in the art in the technical scope that the present invention discloses; can expect easily changing or replacing, all should be encompassed within protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion by described protection range with claim.

Claims (21)

1. the processing method of a transaction message is characterized in that, described method comprises:
Client host and intelligent cipher key equipment connect, and generate transaction message according to Transaction Information;
Whether described client host needs to show according to the content in the described transaction message is divided into plurality of sections with described transaction message;
The transaction message section of described client host after with described cutting apart issued described intelligent cipher key equipment successively, and the transaction message section that needs are shown is carried out mark simultaneously;
Described intelligent cipher key equipment receives the transaction message section after described cutting apart, and described transaction message section is carried out computing, and judge whether described transaction message section needs to show;
If need, then the described transaction message section that needs to show is deposited in the display buffer district, and after receiving signature command, show the transaction message section that is stored in the display buffer district, carry out signature operation, the result that will sign returns to described client host;
If do not need, then directly after receiving signature command, show the transaction message section that is stored in the display buffer district, and carry out signature operation that the result that will sign returns to described client host.
2. the processing method of transaction message according to claim 1, it is characterized in that, described Transaction Information is specially the Transaction Information of described client host by the input unit reception user input of described client host, and perhaps described Transaction Information also is specially described client host receives user's input by the input unit of described intelligent cipher key equipment Transaction Information.
3. the processing method of transaction message according to claim 1 is characterized in that, the method that the transaction message section that described client host shows needs is carried out mark specifically comprises:
With the marker character of checking of making an appointment the described transaction message section that needs to show is carried out mark;
Perhaps,
By first flag bit be provided with corresponding with described transaction message section of making an appointment being come the described transaction message section that needs to show is carried out mark.
4. the processing method of transaction message according to claim 3, it is characterized in that, when described client host when checking marker character the described transaction message section that needs to show carried out mark, the transaction message section of then described client host after with described cutting apart sends to before the described intelligent cipher key equipment, and described method also comprises:
The modification literal and the control character that add some computings that do not participate in signing in the transaction message section of described client host after described cutting apart, to improve display effect, improve user experience, and described modification literal and control character can't change the sequencing of the content and the described transaction message section of described transaction message section;
Perhaps,
When described client host when first flag bit be provided with corresponding with described transaction message section of making an appointment being come the described transaction message section that need to show carried out mark, the transaction message section of then described client host after with described cutting apart sends to before the described intelligent cipher key equipment, and described method also comprises:
Described client host is convenient to the user and is understood by the second flag bit setting corresponding with described transaction message section of making an appointment strengthened display effect, improves user experience.
5. the processing method of transaction message according to claim 1 is characterized in that, the divide into groups operation of HASH computing specifically also comprises described intelligent cipher key equipment to described transaction message section:
Judging that described client host is with checking marker character the transaction message section that needs show to be carried out mark, still is by described first flag bit of making an appointment being provided with come the transaction message section that needs are shown to carry out mark;
Obtaining when judgement is when checking transaction message section that marker character shows needs and carry out mark, and then described intelligent cipher key equipment is to the HASH computing of dividing into groups of the described All Activity message segment that receives;
Obtaining when judgement is by described first flag bit of making an appointment being provided with when coming that the transaction message section that needs show carried out mark, then described intelligent cipher key equipment needs also to judge that first flag bit is set to first about definite value or second about definite value or is set to the 3rd about definite value, if when being set to the first about definite value or the second about definite value, represent that then described transaction message section need participate in the computing of signing, described transaction message section is carried out computing, if when being set to the 3rd about definite value, represent that then described transaction message section does not need to participate in the signature computing, does not need described transaction message section is carried out computing.
6. the processing method of transaction message according to claim 1 is characterized in that, described intelligent cipher key equipment judges that the method whether described transaction message section needs to show specifically comprises:
Described intelligent cipher key equipment judge whether contain in the described transaction message section described make an appointment check marker character, if contain described make an appointment check marker character, represent that then described transaction message section need show, if do not contain described make an appointment check marker character, represent that then described transaction message section does not need to show;
Perhaps,
Described intelligent cipher key equipment judges that first flag bit corresponding with described transaction message section of making an appointment is to be set to first about definite value, still be set to second about definite value or the 3rd about definite value, if when being set to the first about definite value, represent that then described transaction message section does not need to show, if when being set to second about definite value or the 3rd about definite value, represent that then described transaction message section need show.
7. the processing method of transaction message according to claim 1, it is characterized in that, described intelligent cipher key equipment shows the described transaction message section that is stored in the display buffer district, carries out signature operation, and the operation that the signature result is returned to described client host is specially:
Described intelligent cipher key equipment shows the described transaction message section that is stored in the buffer memory viewing area, waits for described user's input information;
If the information of described user's input is cancellation information, then described intelligent cipher key equipment is to described client host prompting error message or cancellation information;
If the information of described user's input is confirmation, then described intelligent cipher key equipment is signed to final operation result, and the result that will sign returns to described client host.
8. a client host is characterized in that, described client host is connected with intelligent cipher key equipment, comprising:
Interface module is used for being connected with described intelligent cipher key equipment;
Communication module is used for carrying out communication with described intelligent cipher key equipment;
Input module is used for importing relationship trading information for the user;
Generation module is used for generating transaction message according to the described Transaction Information of user's input;
Judge module is used for judging whether the content of described transaction message needs to show;
Cut apart module, be used for judging the content of the described transaction message that obtains whether needs show described transaction message is divided into plurality of sections according to described judge module;
Mark module, the transaction message section that is used for described needs are shown is carried out mark.
9. client host according to claim 8 is characterized in that described client host also comprises parsing module, is used for the transaction message that described generation module generates is resolved.
10. client host according to claim 8 is characterized in that, the method that the transaction message section that described mark module shows needs is carried out mark specifically comprises:
Described mark module carries out mark with the marker character of checking of making an appointment to the described transaction message section that needs to show;
Perhaps,
Described mark module is by coming that to the first flag bit setting corresponding with described transaction message section of making an appointment the described transaction message section that needs to show is carried out mark.
11. client host according to claim 10 is characterized in that, when described mark module with make an appointment check marker character the described transaction message section that needs to show carried out mark the time, described client host also comprises:
Add module, be used for modification literal and control character that transaction message section after described cutting apart adds some computings that do not participate in signing,, improve user experience to improve display effect;
Perhaps,
When described mark module when first flag bit be provided with corresponding with described transaction message section of making an appointment being come the described transaction message section that need to show carried out mark, described mark module also is used for second flag bit corresponding with described transaction message section of making an appointment is provided with, be used to strengthen display effect, improve user experience.
12. an intelligent cipher key equipment is characterized in that, described intelligent cipher key equipment is connected with client host, comprising:
Interface module is used for being connected with described client host;
Communication module is used for carrying out communication with described client host, specifically is used to receive the transaction message section after cutting apart that described client host sends;
Computing module is used for described transaction message section is carried out computing;
Judge module is used to judge whether described transaction message section needs to show;
Memory module is used to store the transaction message section that described judge module judges that the needs that obtain show;
Display module is used for the transaction message section that shows that described memory module is stored;
Signature blocks is used to carry out signature operation.
13. intelligent cipher key equipment according to claim 12 is characterized in that, described intelligent cipher key equipment also comprises:
Input module is used for importing relationship trading information for the user, and also is used for importing cancellation information or confirmation for the user.
14. intelligent cipher key equipment according to claim 12, it is characterized in that, described computing module carries out before the computing to the transaction message section, described judge module is used to also judge that described client host is with checking marker character the transaction message section that needs show to be carried out mark, still is by described first flag bit of making an appointment being provided with come the transaction message section that needs are shown to carry out mark;
Obtaining when judgement is when checking transaction message section that marker character shows needs and carry out mark, and then described computing module carries out computing to described All Activity message segment;
Obtaining when judgement is by described first flag bit of making an appointment being provided with when coming that the transaction message section that needs show carried out mark, then described judge module is used to also judge that first flag bit is set to first about definite value or second about definite value or is set to the 3rd about definite value, if when being set to the first about definite value or the second about definite value, represent that then described transaction message section need participate in the computing of signing, described computing module carries out computing to described transaction message section, if when being set to the 3rd about definite value, represent that then described transaction message section does not need to participate in the signature computing, described computing module does not need described transaction message section is carried out computing.
15. intelligent cipher key equipment according to claim 12 is characterized in that, described judge module judges that the method whether described transaction message section needs to show specifically comprises:
Described judge module judges whether contain the identifier of checking of making an appointment in the described transaction message section, if contain described make an appointment check identifier, represent that then described transaction message section need show, if do not contain described make an appointment check identifier, represent that then described transaction message section does not need to show;
Perhaps,
Described judge module judges that first flag bit corresponding with described transaction message section of making an appointment is to be set to described first about definite value, still be set to described second about definite value or the 3rd about definite value, if be set to described first about definite value, represent that then described transaction message section does not need to show, if be set to described second about definite value or the described the 3rd about definite value, represent that then described transaction message section need show.
16. intelligent cipher key equipment according to claim 12 is characterized in that, what described judge module also was used to judge described user's input is cancellation information or confirmation;
When described user input be cancellation information the time, described communication module also is used for returning error message or cancellation information to described client host;
When described user input be confirmation the time, described signature blocks is used for final operation result is signed;
Correspondingly, described communication module also is used for the signature result is returned to described client host.
17. the treatment system of a transaction message is characterized in that, described system comprises client host and intelligent cipher key equipment, and described intelligent cipher key equipment is connected with described client host;
Described client host, be used for connecting with described intelligent cipher key equipment, generate transaction message according to Transaction Information, described transaction message is resolved, whether need to show according to the content in the described transaction message described transaction message is divided into plurality of sections, transaction message section after described cutting apart is sent to described intelligent cipher key equipment, and the transaction message section that needs are shown is carried out mark simultaneously;
Described intelligent cipher key equipment, be used to receive the transaction message section after cutting apart that described client host sends, described transaction message section is carried out computing, judge whether described transaction message section needs to show, if need, then described transaction message section is deposited in the display buffer district, and after receiving signature command, show the described transaction message section that is stored in the display buffer district, carry out signature operation, and the result that will sign returns to described client host, if do not need, then directly shows the described transaction message section that is stored in the display buffer district after receiving signature command, carry out signature operation, and the result that will sign returns to described client host.
18. the treatment system of transaction message according to claim 17 is characterized in that, the method that described client host carries out mark to the described transaction message section that need show specifically comprises:
With the marker character of checking of making an appointment the described transaction message section that needs to show is carried out mark;
Perhaps,
By first flag bit be provided with corresponding with described transaction message section of making an appointment being come the described transaction message section that needs to show is carried out mark.
19. the processing method of transaction message according to claim 17 is characterized in that, the divide into groups operation of HASH computing specifically also comprises described intelligent cipher key equipment to described transaction message section:
Judging that described client host is with checking marker character the transaction message section that needs show to be carried out mark, still is by described first flag bit of making an appointment being provided with come the transaction message section that needs are shown to carry out mark;
Obtaining when judgement is when checking transaction message section that marker character shows needs and carry out mark, and then described intelligent cipher key equipment is to the HASH computing of dividing into groups of the described All Activity message segment that receives;
Obtaining when judgement is by described first flag bit of making an appointment being provided with when coming that the transaction message section that needs show carried out mark, then described intelligent cipher key equipment needs also to judge that first flag bit is set to first about definite value or second about definite value or is set to the 3rd about definite value, if when being set to the first about definite value or the second about definite value, represent that then described transaction message section need participate in the computing of signing, described transaction message section is carried out computing, if when being set to the 3rd about definite value, represent that then described transaction message section does not need to participate in the signature computing, does not need described transaction message section is carried out computing.
20. the treatment system of transaction message according to claim 17 is characterized in that, described intelligent cipher key equipment judges that the operation whether described transaction message section needs to show is specially:
Described intelligent cipher key equipment is by judging that whether containing the marker character of checking of making an appointment in the described transaction message section judges whether described transaction message section needs to show, if do not have described make an appointment check marker character, represent that then described transaction message section does not need to show, if contain described make an appointment check marker character, represent that then described transaction message section need show;
Perhaps,
Described intelligent cipher key equipment is to be set to first about definite value by first flag bit of judging described transaction message section correspondence, still be set to second about definite value or the 3rd about definite value and judge whether described transaction message section needs to show, if when being set to the first about definite value, represent that then this transaction message section does not need to show, if when being set to second about definite value or the 3rd about definite value, represent that then this transaction message section need show.
21. the treatment system of transaction message according to claim 17, it is characterized in that, described intelligent cipher key equipment shows the described transaction message section that is stored in the display buffer district, carries out signature operation, and the operation that the signature result is returned to described client host is specially:
Described intelligent cipher key equipment shows the described transaction message section that is stored in the buffer memory viewing area, wait for described user's input information, if the information of described user's input is cancellation information, then described intelligent cipher key equipment is to described client host prompting error message or cancellation information, if the information of described user's input is confirmation, then described intelligent cipher key equipment is signed to final operation result, and the result that will sign returns to described client host.
CN201010580896.7A 2010-12-03 2010-12-03 Method, equipment and system for processing transaction message Active CN102025738B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201010580896.7A CN102025738B (en) 2010-12-03 2010-12-03 Method, equipment and system for processing transaction message

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201010580896.7A CN102025738B (en) 2010-12-03 2010-12-03 Method, equipment and system for processing transaction message

Publications (2)

Publication Number Publication Date
CN102025738A true CN102025738A (en) 2011-04-20
CN102025738B CN102025738B (en) 2014-03-26

Family

ID=43866592

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201010580896.7A Active CN102025738B (en) 2010-12-03 2010-12-03 Method, equipment and system for processing transaction message

Country Status (1)

Country Link
CN (1) CN102025738B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103268437A (en) * 2013-05-10 2013-08-28 飞天诚信科技股份有限公司 Method for improving safety of signed data
CN107609872A (en) * 2017-09-07 2018-01-19 北京海泰方圆科技股份有限公司 transaction message processing and sending method and device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051907A (en) * 2007-05-14 2007-10-10 北京握奇数据系统有限公司 Safety certifying method and its system for facing signature data
CN101221641A (en) * 2007-12-20 2008-07-16 魏恺言 On-line trading method and its safety affirmation equipment
CN101304569A (en) * 2008-04-24 2008-11-12 中山大学 Mobile authentication system based on intelligent mobile phone

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051907A (en) * 2007-05-14 2007-10-10 北京握奇数据系统有限公司 Safety certifying method and its system for facing signature data
CN101221641A (en) * 2007-12-20 2008-07-16 魏恺言 On-line trading method and its safety affirmation equipment
CN101304569A (en) * 2008-04-24 2008-11-12 中山大学 Mobile authentication system based on intelligent mobile phone

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103268437A (en) * 2013-05-10 2013-08-28 飞天诚信科技股份有限公司 Method for improving safety of signed data
CN103268437B (en) * 2013-05-10 2016-02-24 飞天诚信科技股份有限公司 A kind of method improving signed data security
CN107609872A (en) * 2017-09-07 2018-01-19 北京海泰方圆科技股份有限公司 transaction message processing and sending method and device

Also Published As

Publication number Publication date
CN102025738B (en) 2014-03-26

Similar Documents

Publication Publication Date Title
US20240013212A1 (en) Transferring cryptocurrency from a remote limited access wallet
CN109493043A (en) The blocking method, apparatus of transaction record, electronic equipment and storage medium
CN104765580B (en) A kind of bill printing intelligence control system for supporting cloud printing technique
CN102123148A (en) Authentication method, system and device based on dynamic password
Asfia et al. Energy trading of electric vehicles using blockchain and smart contracts
CN101236629A (en) On-line payment system and payment procedure
CN104281272B (en) Password Input processing method and processing device
CN101790166A (en) Digital signing method based on mobile phone intelligent card
CN106910303A (en) A kind of supervising device of making out an invoice, billing system and billing method for being applied to tax control
CN107067321A (en) Data security method, server, client and the system of payment beforehand business
CN102833709B (en) A kind of sending method, mobile terminal, server and system of note
CN202394268U (en) On-site payment equipment
CN103699345A (en) Bank business document printing system, and equipment and method for preprocessing and centralized printing
CN105139543A (en) Intelligent card self-service charging method
CN109614596B (en) Electronic bill processing method, device and system
CN105468771B (en) Recommend the method and device of software
CN102025738B (en) Method, equipment and system for processing transaction message
CN109831414A (en) A kind of delivery management method and system of electronic invoice
CN101408970A (en) Method, system and apparatus for implementing batch electronic transaction, and electronic signing tool
CN107977556A (en) The method and device of stamped signature is carried out to online e-file
CN107516251A (en) The method and system of interactive operation based on electronic bill
CN103139306A (en) Method facing forwarding of browse clipping page information and obtaining of enterprise cooperation information interaction
CN102609842A (en) Payment cipher device based on hardware signature equipment, and application method of payment cipher device
CN110430052A (en) A kind of online filling method and device of POS key
CN109409891A (en) Courseware sharing method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 17th floor, building B, Huizhi building, No.9, Xueqing Road, Haidian District, Beijing 100085

Patentee after: Feitian Technologies Co.,Ltd.

Country or region after: China

Address before: 100085 17th floor, block B, Huizhi building, No.9 Xueqing Road, Haidian District, Beijing

Patentee before: Feitian Technologies Co.,Ltd.

Country or region before: China