Summary of the invention
Overcome the deficiencies in the prior art of the present invention combines PKI digital authenticating protection system, the isolation based on secure hardware
Environment and mobile intelligent terminal payment scheme based on two-way trust propose a kind of intelligent movable based on secure hardware isolation
Terminal payment system and method.
The present invention implements a kind of mobile intelligent terminal payment system and method based on secure hardware isolation, the system
It is suitable for mobile intelligent terminal with method, the system and method include:
When the mobile intelligent terminal carries out delivery operation, the payment application installed on mobile intelligent terminal can be with clothes
Payment general flow (such as generation order) is realized in device connection of being engaged in, can with the point-to-point wireless connection of secure hardware progress and carry out
Data Encryption Transmission realizes user password verifying and the transmitting of payment authentication information.
Before secure hardware use is operated, by trusting preset operation for the public key certificate of payment server, CA
Certificate, user pay public key certificate and import, and building forms server and the two-way trust systems basis of secure hardware, and requires user
Payment cipher is set, which pays public key certificate to user in secure hardware for realizing user and carry out delivery operation
Authorization.
When mobile intelligent terminal needs to carry out delivery operation, is interacted by payment application with server and complete payment data
It generates, and payment data is encrypted by way of point-to-point wireless connection and is sent to after secure hardware is signed the service that returns
Device completes verifying, specifically includes:
1) it when mobile intelligent terminal needs to carry out delivery operation, is interacted using payment application with server, completes payment
Data (including User ID, trade company ID, commodity ID, quantity, unit price, total price, order ID, payment information ID, random challenge value etc.)
Generation.
2) application is paid on mobile intelligent terminal and establish point-to-point connection with secure hardware, and carry out key agreement foundation and add
Secret letter road.
3) mobile intelligent terminal pays application for random challenge, order ID, payment information ID, payment information (User ID, quotient
Family ID, total price etc.) encryption after be sent to secure hardware.
4) it is shown after secure hardware decrypts payment information, user is confirming errorless rear input payment cipher, and to the branch
Password is paid to be verified.After paying the corresponding private key of public key certificate to the data signature received using user after being verified,
Symmetric cryptographic key is generated, signing messages, order ID, payment information ID are encrypted to obtain data A using the encryption key,
Encryption key is encrypted using server public key to obtain B, combines both into digital envelope.Digital envelope is passed through built
Vertical safe lane is back to mobile intelligent terminal.
5) digital envelope received is transmitted to server by mobile intelligent terminal.
6) server by utilizing private key ciphertext data B obtains encryption key, is being decrypted, is being obtained to A using encryption key
Signing messages, order ID, payment information ID.Signing messages is verified using client public key, and verifies order ID, payment information ID
Etc. after information, whether validation of payment succeeds.
7) payment result is back to mobile intelligent terminal by server.
The basic thought of this programme is described below, the present invention mentions on basis the advantages of drawing existing solution
Go out the design philosophy of oneself, specifically, the technology of the present invention includes that scheme includes the following aspects:
Aspect one: payment system mainly includes three payment server, mobile intelligent terminal and secure hardware parts.Payment
Server is interacted with mobile intelligent terminal, completes to remove other links other than user authentication in payment flow.Secure hardware with
Mobile intelligent terminal interaction, completes user authentication part mostly important in payment flow.Utilize the independent operating of secure hardware
Environment protects the authentication data safety of user;It is preset by the trust in secure hardware, using mobile intelligent terminal as channel, with
Server establishes the payment implementation method of two-way trust.
Aspect two: secure hardware has individual system independently of mobile intelligent terminal, and it is raw externally to provide random number
At, certificate request, the service such as Information Signature.Secure hardware has secure storage function, and preset user authentication can be protected to believe
Breath.In payment process, secure hardware needs user's input payment cipher to verify, and is paid after being verified using user
Public key certificate private key is to being back to mobile intelligent terminal after payment data encrypted signature.Mainly there are these points:
Random number generation module: secure hardware provides real random number generator, can once provide the random of random length
Number, the random number can be used to the key as symmetric cryptography.
Pay signature blocks: secure hardware requests specified account after receiving order ID, payment information ID and payment information
It number signs.Secure hardware will utilize hardware display reminding customer transaction (such as glittering transaction LED light), and payment information is shown
Show the display screen in secure hardware, user is waited to input payment cipher confirmation.Payment cipher is used for the private key of decryption verification payment
Carry out signature operation.
Trusted certificates module: secure hardware is stored with preset trusted certificates, public key certificate, CA including payment server
Certificate, user pay public key certificate.These trusted certificates are obtained by the index of agreement.
Aspect three: this method provides the mobile intelligent terminal payment system and method being isolated based on secure hardware, mainly exists
Sensitive data is protected in payment whole flow process.Data are believed in payment server and mobile intelligent terminal interaction by encryption
Pipe protection, data are protected in mobile intelligent terminal and secure hardware interaction by encryption channel.The sensitive data of user such as user
Payment certificate private key is stored in secure hardware, and attacker can not read sensitive data.The number transmitted via mobile intelligent terminal
According to for dynamic ephemeral data, fail after the completion of payment process.Pass through the protection of encryption channel and secure hardware, attacker
The payment information of user can not be obtained, the safety in payment process is comprehensively improved.
Compared with prior art, the present invention having the advantage that
(1) by user's payment certificate private key and password storage in secure hardware, these sensitive datas is effectively prevent to be attacked
The person of hitting obtains, and substantially increases the safety of payment system.
(2) payment information will be confirmed by user in secure hardware, effectively prevent payment information to be maliciously tampered, into one
Step improves the safety of payment system.
Specific embodiment
For the purpose of the present invention, advantage and technical solution is more clearly understood, below by way of specific implementation, and combine
Attached drawing, the present invention is described in more detail.
As shown in Figure 1, the method is specifically implemented by the following steps:
One, based on the implementation method for trusting preset secure hardware
Secure hardware trust is preset, refers to and leads in secure hardware for before paying, needing to carry out certificate to secure hardware
Enter, the initialization operations such as user password setting, the preliminary trust systems for establishing payment.Being preset in secure hardware has payment to take
The public key certificate of business device, CA certificate, user pay public key certificate.The public key certificate of payment server is mainly used for symmetric cryptography
Key is encrypted, and realizes the encapsulation of digital envelope;CA certificate is used for secure launch process, realizes the verifying to secure hardware;
User pays public key certificate and is mainly used for showing user identity to server.User needs that payment cipher is arranged in secure hardware,
The payment cipher, which will be used to pay user the corresponding private key of public key certificate, to be encrypted, and during continuation payment, is needed
User inputs payment cipher, to get paid the corresponding private key of public key certificate.
As shown in Fig. 2, being divided into mirror image on three component parts, including cured sheets, root in secure hardware secure launch process
Verify packet mirror image, secure firmware.Wherein, mirror image contains check code, and the code of load root verifying packet mirror image in cured sheets;
Root verifying packet mirror image contains signature hash check value, the check code of root verifying packet mirror image, and the code of load secure firmware;
Secure firmware includes the signature hash check value of secure firmware, security system code;Detailed process is as follows:
(1) system electrification loads mirror image in cured sheets, and mirror image reads root verifying packet mirror image and with preset CA in cured sheets
Certificate calculates its Hash, and is compared with the hash check value of storage.If consistent, root verifying packet mirror image is loaded,
Root verifying packet mirror image operation is jumped to, otherwise, then stops starting.
(2) root verifying packet mirror image reads secure firmware, and calculates the signature cryptographic Hash of secure firmware, in secure firmware
Signature hash check value is compared verifying.It is no if always, loading secure firmware and jumping to secure firmware operation
Then, stop starting.
(3) secure firmware brings into operation, and loads and run random number generation module, payment signature blocks, trusted certificates mould
Block.
After secure hardware starting, mainly there are generating random number service, trusted certificates service, and provide for mobile intelligent terminal
Digital signature service is paid, is specifically included that
Generating random number service: secure hardware provides randomizer, can once provide the random number of random length,
The random number can be used to the key as symmetric cryptography.It pays Digital signature service and sends RANDOM NUMBER request to secure hardware, and take
With parameter N (length that N is description request random number), in correct situation, secure hardware returns to the random number that length is N.It is no
Then return to error code.
Pay Digital signature service: secure hardware requests specified account after receiving order ID, payment information ID and payment information
It number signs.Secure hardware will utilize hardware display reminding customer transaction (such as glittering transaction LED light), and payment information is shown
Show the display screen in secure hardware, user is waited to input payment cipher confirmation.Payment cipher is used for the private key of decryption verification payment
Carry out signature operation.After payment cipher is verified, Digital signature service is paid to generating random number service origination requests, is obtained symmetrical
Encryption key is encrypted to obtain data A, utilizes service using the encryption key to signing messages, order ID, payment information ID
Device public key encrypts encryption key to obtain B, combines both into digital envelope.Mobile intelligent terminal is sent to secure hardware
Signature request is paid, parameter has signature algorithm ID, and random number length, the length of payment information, payment information ID, is ordered random number
Single ID, payment buyer's account length, payment buyer's account, payment seller's account length, payment seller's account, payment amount.This
A little cleartext informations for signature.Secure hardware platform receives parameter and is handled, and in correct situation, returns to the number letter of generation
Envelope.Mistake returns to error code.
Trusted certificates service: secure hardware is stored with preset trusted certificates, public key certificate, CA including payment server
Certificate, user pay public key certificate.These trusted certificates are obtained by the index of agreement.Digital signature service is paid to send out to secure hardware
Trusted certificates module is sent, parameter is that certificate indexes ID.Secure hardware platform is handled according to parameter, in correct situation, is returned
Certificate format, trusted certificates length and trusted certificates content.Mistake returns to error code.
Two, the mobile intelligent terminal based on two-way trust pays implementation method
As shown in figure 3, mobile intelligent terminal terminal payment scheme mainly relies on server certificate and user's payment certificate structure
The two-way trust relationship built, the safety and correctness of process of guaranteeing payment.It is required that being needed pair before carrying out delivery operation process
Secure hardware carries out trusting preset initialization operation.Complete payment flow includes the following steps:
(1) user submits User ID, quotient to server in the interior purchase for completing commodity of payment application of mobile intelligent terminal
Family ID, commodity ID, quantity, unit price, the data such as total price, request generate order.
(2) data (User ID, trade company ID, commodity ID, quantity, unit price, total price) that server is transmitted according to payment application
A new order is generated, and the order ID and order information of generation are inserted into database, then order ID is returned to
Payment application.
(3) payment application selects corresponding order to be paid, and submits order payment request to server, and submit order
ID。
(4) server generates a payment information according to its received order ID, and payment information ID is transmitted to payment and is answered
With.Server can generate a random number S simultaneously, be returned to payment application simultaneously with payment information ID.
(5) payment application is established point-to-point wireless connection (can be Wi-Fi Direct, bluetooth etc.) with secure hardware, and
Negotiate symmetric key using key agreement protocol, establishes encryption channel.
(6) payment application is by random number S, order ID, payment information ID, payment information (including Buyer ID, seller's account
Number, payment amount) be sent to secure hardware after the symmetric key encryption that obtains by step (5).
(7) secure hardware utilizes the data of symmetric cryptographic key decryption step (6), and payment information is shown, prompts to use
Family inputs payment cipher.
(8) user inputs payment cipher, and secure hardware is decrypted to obtain user's payment public key certificate correspondence according to payment cipher
Private key, carry out signature operation with the private key.
(9) private key that secure hardware is obtained using (8) carries out random number S, order ID, payment information ID, payment information
Signature, obtains signing messages, including signature value, public signature key ID.
(10) after secure hardware generates signing messages, start the encapsulation for carrying out digital envelope, generating random number service creation
Random number is as symmetric key, trusted certificates service providing server certificate.
(11) secure hardware starts that digital envelope is calculated: the random number that step (10) is obtained as symmetric key,
Signing messages, order ID, payment information ID are encrypted to obtain data A.Then with the public key in server certificate to symmetrical
Key is encrypted to obtain data B, and data A, B form digital envelope.And digital envelope is sent to mobile terminal device.
(12) digital envelope received is transmitted to server by mobile intelligent terminal.
(13) after server obtains digital envelope, data B is decrypted first with server certificate corresponding private key
Symmetric key is obtained, then data A is decrypted using symmetric key, obtains signing messages, order ID, payment information ID.
Signing messages is verified with the CertPubKey of the corresponding user of payment information ID, confirmation Buyer ID, seller's account, payment
The amount of money does not have mistake.And verify the legitimacy of order ID, payment information ID.After being verified, show server and the body of user
Part is all correct, and two-way trust relationship has built up.The foundation of the relationship then illustrates that this pays and completes, and can carry out the behaviour such as withhold
Make.Payment result is returned to payment application by server.
(16) payment application display payment result is to user.
Above embodiments are provided just for the sake of the description purpose of the present invention, and are not intended to limit the scope of the invention.This
The range of invention is defined by the following claims.It does not depart from spirit and principles of the present invention and the various equivalent replacements made and repairs
Change, should all cover within the scope of the present invention.