WO2010148646A1 - 一种银行卡支付系统中主密钥安全自动下载的方法及其系统 - Google Patents

一种银行卡支付系统中主密钥安全自动下载的方法及其系统 Download PDF

Info

Publication number
WO2010148646A1
WO2010148646A1 PCT/CN2010/000926 CN2010000926W WO2010148646A1 WO 2010148646 A1 WO2010148646 A1 WO 2010148646A1 CN 2010000926 W CN2010000926 W CN 2010000926W WO 2010148646 A1 WO2010148646 A1 WO 2010148646A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
secure
download
update
public
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2010/000926
Other languages
English (en)
French (fr)
Inventor
陈贤强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to CA2766491A priority Critical patent/CA2766491C/en
Priority to SG2011095908A priority patent/SG177349A1/en
Publication of WO2010148646A1 publication Critical patent/WO2010148646A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/0873Details of the card reader
    • G07F7/088Details of the card reader the card reader being part of the point of sale [POS] terminal or electronic cash register [ECR] itself
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/355Personalisation of cards for use
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07GREGISTERING THE RECEIPT OF CASH, VALUABLES, OR TOKENS
    • G07G1/00Cash registers
    • G07G1/12Cash registers electronically operated
    • G07G1/14Systems including one or more distant stations co-operating with a central processing unit

Definitions

  • the method of paying for security from the middle of the system is related to the security system, especially the payment security system.
  • Background Wood Banking (Ba Ca) is not popular for payment tools.
  • the usual payment system includes the sales terminal (Po O Sae POS Terminal Management System (Tem aa age Sys em T) P PA) and hardware (adwa ea dSec y od e S ) wherein the OS terminal accepts the information-passive function, accepts the instructions of the phase, completes the financial transaction information, and the OS terminal centralized management parameter downloading and downloading under the T system, or the delivery of the special OS terminal to the O terminal
  • the centralized management and delivery system (p PA ) of the transaction result information is the TP and A line security storage and the security hardware of the P (adwa ea dSec y od e S) is the settlement of several dense external hardware. , text and file source and storage.
  • Both parts of (AC) A are generated by T S in the OS to T S to download and use T and store their algorithms are all using the highly secure 3 ES algorithm.
  • Hugh work Download process 1 shows that the OS terminal generates T secrets from T S to T and the A OS terminal receives the P and A ciphertext passwords of the T S return. In the very payment, the P is used by the password, and the P is held on the P.
  • the middle P is the 3 ES algorithm that uses the hardware. It is currently the user's security is not very high, the algorithm is usually in finance. As you can see from the above work download, T is very good. If T intercepts PA or even P can be cracked by 3DES algorithm, it will be very safe to pay. Therefore, whether T can be safely downloaded to the OS terminal will also be a security step. Below we will directly use the existing T download method but the T generated T plain text directly to the OS terminal. There are a large number of security vulnerabilities in the operation. It is very convenient to intercept the work download and P of the possibility that there is a possibility of manual writing. C plaintext is generated by TS TS. The plaintext C is stored by the T terminal in the OS terminal C.
  • T is saved in C. As long as you get the C card, you can download the work and P from the plaintext.
  • the C ciphertext is determined by the T generated by the TS ( ).
  • the C ciphertext in the C OS terminal C is reused and the stored C line is solved earlier.
  • the way is to enhance the function of C in the clear text. Only the talents of each C can reduce the insecure factors in the existing text.
  • O Terminal TS generated T cipher-specific OS terminal (OS terminal) The OS terminal connected directly to the O terminal reduces the early insecure factor.
  • the security of the mode is not the same as the C mode, but there is a terminal that is inconvenient, and it is very direct in the merchant.
  • T download method exists mainly under There is a possibility of a manual approach. Clear security vulnerabilities in plaintext are also easily handled by special operations. C ciphertext and S have partially solved the security in the early but C and OS custody and still have a relatively large security. All of the above T downloading methods require industrial intervention to directly operate the OS terminal, which requires wood support to the O terminal to complete the download. The cost of each work is relatively high, especially in the case where the number of OS terminals is relatively large and the barrier terminals are heavy.
  • the purpose of the content book is to provide a secure self-downloading method to solve the security in the download. It is very convenient to pay for the T-Secure download method. It is very convenient to sell the terminal OS terminal management system TS, and hardware. T households, public and private OS terminal passwords are easy to generate TTS public TSTS
  • T storage Step, T S and Generate ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ ⁇ OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS OS
  • T 3 is stored in the TS number. Steps in the T OS terminal connection agent T need to update the update under normal circumstances, need OS terminal update T as long as the O terminal to the TS any include, transaction, etc. then the TS will need to update the OS terminal in the text in the TS The result of the regular result is that the update of T is completed and the self-updating of T is completed. TS completes the solution of T and stores whether the OS terminal has updated T successfully.
  • the disclosed payment system includes a sales terminal OS, a terminal management system TS, and a hardware TS user account, which are stored in the number of T stored therein. Storage of TS
  • the easy-going household T uses the public of T S . It will be stored in a public T or specially converted to 3 ES storage. Steps in the TS OS terminal interface T need new OS terminal update T As long as the OS terminal to the TS any, transaction, etc., the TS will need to update the OS terminal in the TS to the need of the new The update has been completed on T. The update of T is new to other frequently used cases. This T is easy-going and closed, and the T is not in the safe storage.
  • T ciphertext can be solved in T. Because the security of the algorithm is very high, even if the ciphertext is intercepted, it is completely cracked, which completely solves the security vulnerabilities existing in the existing T download.
  • the Hugh method solves the defects in the existing T.
  • This paper proposes a method to securely download T.
  • the download of T is completely controlled and managed by T S.
  • the number of S-terminal exchanges is completed.
  • the intervention in the middle of the work greatly reduces the cost of power and the safety and reliability of T.
  • the security of T introduces a public-private algorithm.
  • the idea of the algorithm is to first save the TS in the number of TSs stored in the number of TSs.
  • the OS terminal downloads the download process shown in step 2, and generates the TS private and secrets the number of OS terminals stored in the TS.
  • the public download OS terminal receives the public return of the TS.
  • T is generated by T, and some means are used to go to the O terminal and then the O-terminal according to the solution means that the text can be intercepted by the rabbit or the internal solution.
  • the method of generating T in reverse is its T is generated by the OS in the password and is generated by using the previously downloaded TS directly in the TS and then by TS.
  • T using T to directly save the plaintext of the T is not present.
  • the TS 3 ES T is stored in the number of T.
  • the existing S terminal management can be connected to the P and A updates, and P is a transparent work intervention.
  • the T update process of the method is shown in the following steps.
  • the instruction provided by the O terminal is generated by the O terminal.
  • the TS is stored in the TS and the TS is not stored directly.
  • the pre-existing 3 ES T stores the P and A exchanges in the TS. Whether the T OS terminal has been updated with T successfully.
  • the above update process shows that T is also used by easy-going households.
  • T plain text does not appear in the secure storage (and) externally. It uses T ciphertext in TS to solve the problem of sending out the gods. The security is very high, even if the interception of the ciphertext is very cracked, it completely solves the security vulnerabilities in the existing T download.
  • the update process of the easy-going households T needs to add instructions to the existing passwords.
  • the add-on instruction will be stored in the TS with a public TK or a special 3E.
  • This article introduces the new process of T.
  • the update process of T is determined by the OS terminal.
  • the management requirements of the OS terminal need to be updated in the interface of the TS OS terminal.
  • 1) Update 2) Need to update Under normal circumstances, the normal situation refers to There is no need to update the T update in the T system. Requires OS terminal to update T than newly installed O terminal or original T use
  • the OS terminal includes any incoming or outgoing T to T, it will need to be updated by T S in the connection.
  • the OS terminal in T S is valid and the update is valid.
  • the update process of T completes the self-update of T. From this point of view, all updates and management are completed on the T S. No additional intervention and scheduling of wood support is required to update the OS terminal. If the T S receives the update T of the OS terminal under the update, it directly rejects the data of the rabbit OS terminal or steals it from other OS terminals. In the case where the OS terminal fails to update T K , the OS terminal automatically updates the T update process by the T S OS terminal.
  • the T-safe download method described in this article only requires the existing and intermediate-increasing instructions. The download and security management requirements of T are both safe and reliable in the existing T. It is a safe and reliable method. The method of sending God's method is very safe and the non-algorithm of the user can not use the existing OS terminal, and other self-terminals that have a beautiful appearance are more commercially worth than the AT terminal and the payment terminal.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Accounting & Taxation (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Theoretical Computer Science (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Finance (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Cash Registers Or Receiving Machines (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Input From Keyboards Or The Like (AREA)

Description

支付 統中 安全自 下 的方法 其 統 木領域 本 涉及很 支付 統 尤其涉及很 支付 統中 的安 全保 方式。 背景 木 銀行 (Ba Ca )作力支付工具越未越普及 通常的很 支付 統 包括銷售 終端(Po O Sae POS 終端管理 統(Tem a a age Sys em T ) P PA )和硬件 ( adwa ea dSec y od e S ) 其中 OS終端 接受很 信息 具有通 功能, 接受相 的指 令而完成金融交 信息和有 信息交換的 各 T 統 下的 OS 終端 集中管理 參數下載 下載 接受、 或特 OS終 端的交 向 O 終端 送交易結果信息的集中管理及交 理 統 (p PA ) 是 T P 和 A 行安全存儲 以及 P 的安全 各 硬件 ( adwa ea dSec y od e S )是 的數 密的外固硬件 各 于P 的 和解 、 文和文件 源的 以及存儲 。
(Pe so a de t6ca o umbe P ) 即 是在 交 中 持卡 身份合法性的數 信息 在 和 統中任何林市都不 P 以明文的方式出現 終端 (Tem a as e ey T ) OS終端工作 工作 密的 保存在 統硬件中, 只 能使用 不能 工作 (Wok g key W ) 也
通常包括P 密密 ( P )和 AC 的 ( AK) 工作 胡必須 更新 在 更新的 中用終端 (T ) 工作 形成 再 。 - S終端 于很 支付物合 比 、 酒店 等 是 神不可或 的現代 支付手段 已 融 們的 常生活。很 (特 別是 ) 都由持卡 了 P , 在 行支付 中 O 終端 除了上 銀行 的 信息等資料 外 要求持卡 P 很 持卡 身份合法性, 以 銀行 支付安全 持卡 的 安 全。 了防止P 露或 破解 要求 終端到 信息交互 中 全程 P 行安全 不 在 和同 統中的任 何林市 P 以明文的方式出現。 此 目前 接受 P 的 OS終端 都要求 各 管理休 。 O 終端的 休 分成二 終端 (T ) 和工作 (W )。其中 T 在W 更新的 中 W 每台 OS 終端 T S 同共享唯 的 T 必須要有安全保 措施 只能 硬件 各 不能 W 包括 于 P 密的 P 和
( AC) 的 A 兩部分 均由 T S 戶生 在 OS 向 T S 到 下載 利用 T 和存儲 其 算法 都是使用安全 很高的 3 ES算法。 休工作 下載流程 1所示 OS終端向 T S 到 T 隨和生成 T 密的 P 和 A OS終端接收 T S返 的 P 和 A 密文 存 密碼 。 在很 支付 中 通 由密碼 利用 P 持卡 的 P 上 T S 然 T S再 的 P
行特 特 很
中 P 都是利用硬件 其 使用的 3 ES 算法也 是目前 用戶 安全 別很高的 算法 通常 在金融 並。 上面的工作 下載 中可以看出 T 是 介很 的 。 果T 截取 P A 甚至P 都可以利用 3DES算法 破解, 將 很 支付安全。 所以 T 能否安全下載到 OS終 端 也就 介 安全保 的 步驟。 下面我們把目前現有的 T 下載方法但 下 由 T 生成T 明文 手工方式直接 到 OS終端的 。 方式存在很大的安全漏洞 休操作 很容 截取 T 明文 存在手工 候的可能性 的工作 下載和 P 。 C 明文早 由 T S生成T 明文 C 由 OS終端 C 中 T 明文存 。 方式也存在很大的安全漏洞 T 保存在 C 中 只要拿到 C卡 就可以 T 明文 的工作 下載和P 。 C 密文早 由 T S生成的 T 指定 ( ) 存 C OS終端 C 中 T 密文 再利用存 了 的 C 行解 再早 。 方式是在 C 明文 的 上增強了 功能 有所 只有 各 C 的 才能 T 明文 減少了 在 中存在的不安全因素。 O 終端 T S生成的 T 密文 特制的 OS終端 ( OS終端 ) 直接早 O 終端 連接的 OS 終端 減少了 早 中的不安全因素。 方式的安全 別等同于 C 方式 但存在終端 不方便、 很 在商戶的 直接 T 等 。 上 以上現有的 T 下載方法存在的主要 下 手工 方式存在 力 候的可能性。 明文 存在 重的安全漏洞 也很容易被 特別是通 工操 作的 。 C 密文早 和 S早 然部分解決了 中的安全 但是 C 和 OS的保管 以及 仍然存在比較大的安 全 。 以上所有T 下載手段均需要 工干預直接操作 OS終端 即需要 木支持 到 O 終端的 才能完成下載 各 工成本比較 高 特別是在 OS終端數量比較 、 障終端札比較 重的情況下。 內容 本 的目的在于 提供 安全自 下載的方法 解決 下載 中的安全 。 很 支付 統中 T 安全 下載的方法 很 支付 統 銷售 終端 OS 終端管理 統T S, 和硬件 。 T 戶生 吋公私密 OS終端 密碼 隨和生 成 T T S的公 上 T S T S
T 存儲。 步 , T S 和生成 吋公私密 其中 在 中保存 保存在 T S的數 中 OS終端 起公 下載 接收T S返 的公 將 存 。 步 ,T S接收到 OS終端 的 的 T 由 T S 利用 T 將T 明文直接存 。
不具有存儲功能 將T 明文通 T S預先 的 3 E , T 存儲在T S的數 中。 步 在 T OS終端的 接 中 介 T 是否需 要更新的 在 常情況下 更新 , 需要 OS 終端更新 T 只要 O 終端向 T S 任何 包括 到、 交 易等 則由 T S在 接 中將 需要更新 在 文中 OS 終端在 T S的 常 果 到 需要更新 的 已 生 效 則 就 T 的更新 完成 T 的自 更新。 T S完 成T 的解 和存儲 OS終端是否已 更新T 成功。 本 揭示了 安全下載的很 支付 統 包括銷售 終端 OS, 終端管理 統 T S 和硬件 的 T S 戶生 吋公私密 其中 在 中保存 保存在 T 的數 中。 的 存儲 T S 的公
隨和戶生T 利用 T S 的公 。 的 將 用公 密的 T 存儲或者 特換成 3 ES 存儲。 步 在 T S OS終端的 接 介 T 是否需 要 新的 需要 OS終端更新T 只要 OS終端向 T S 任何 到、 交易等 則由 T S 在 接 中將 需要更新 在 文中 OS終端在 T S的 常 果 到 需要 新 的 已 生效 就 T 的更新 完成T 的自 新 其他 常使用情況下 更新 。 本 T 是隨和戶生的 也是封閉的 T 明文不 出 現在安全存儲 各 ( 和 ) 外 在 中都是利用公
T 密文在T 的 中才能解 由于送神非 妳的 算法的安全性很高 就算 截取到密文也很 破解, 完全解決了現有 T 下載 中存在的安全漏洞。
說明 現有 木的工作 下載流程 2力本 下載流程 3力本 T 更新流程。
休 方式 了解決上 現有 T 中存在的缺陷 本 提出了 安全 下載T 的方法。 T 的下載完全由 T S集中控制和管理 S終端的數 交換 完成 在 中 工干預 既 大大減少了 力成本 同 也 了 T 的安全可靠。
了 T 的安全 本方法中引 了公私密 非 算法。 算法的思路是 首先由 T S 戶生 吋公私 密 其中 保存在 中 保存在 T S 的數 中 OS 終端下載 下載流程示意 2所示 步驟 下 T S 和生成 吋公私密 其中 在 中保存 保存在T S的數 OS終端 起公 下載 OS終端接收T S返 的公 存 。 在前面 的 T 方法中 都是由 T 生成T , 利用 些 手段 到 O 終端 再由 O 終端按照 的解 手段 T 明文 存 不管 手段 何先 都 兔 或者內 部 同 的解 手段截取T 明文。 在本文提出的 方法中 則是 反向生成 T 的方法 其 休 是 T 由 OS 在密碼 中隨和生成 利用前面下載的 T S 直接在 中完成 上 T S 再由 T S , 利用 T 將T 明文直接存 明文不 出現 在 外。 于不直接存儲T 的 則 T S預先 的 3 ES T 存儲在 T 的數 中。 特 即可 現有的 S 終端 管理休 銜接在 起 的 P 和 A 更新、 P 都是透明的 工干預。 方法 的 T 更新流程 固 3所示 休步驟 下 O 終端 提供的指令隨和生成T , T S的公 上 T T S T 存 于不直接存儲 T 的 T S預先 的 3 ES T 存儲在T S 的 中 的 P 和 A 交換使用 T OS終端是否已 更新T 成功。 上面的 更新流程 看 T 是隨和戶生的 也是 用的, T 明文不合出現在安全存儲 各 ( 和 ) 外 在 中都是利用 T 密文在T S的 中才能解 由于送神非 妳的 算法的安全性很高, 就算 截取到密文也很 破解 完全解決了上 現有T 下載 中存在的安全漏洞。
了 隨和戶生 T 的更新流程 需要在現有的密碼 上 增 指令 1 )存儲 T 的公 2) 隨和戶生T 利用 T S 的公 。 說, 則需要增 介指令 將 用公 密的 T K 存儲或者 特換成 3 E 存儲在T S 中。 本文介紹 T 新流程 看 T 的更新流程是由 OS終端 的 了 其 管理的要求 需要在 T S OS終端的 接口中 介T 是否需要更新的 即 下 1 ) 更新 2) 需要更新 在 常情況下 常情況是指已 生成有 T 統 常使用 中 不需要更新 T 更新 。 需要 OS終端更 新 T 比 新安裝的 O 終端 或者原有的 T 使用已
只要 OS終端向 T 任何 包括 到、 交 等 則由 T S 在 接 中將 需要更新 在 文中 OS終端在 T S 的 常 果 到 更新 的 已 生效 則 就
T 的更新流程 完成T 的自 更新。由此看 T 更新 所有控制和管理都在 T S 上完成 不再需要 工干預和安排 的 木支持 到 OS終端 更新 T 。 果在 更新 下 T S收到 OS終端 的更新T 的 則直接拒絕 以 兔 OS終端的資料 或盜用到其他 OS終端上使用。 在 OS終端 故障 需要更新 T K 的情況下 則由 T S OS 終端的 需要更新 OS終端自 完成T 更新流程。 本 介紹的 T 安全 下載方法 只需要 現有的 和 中增 羊指令 即可 了 T 的 下載和安 全管理要求 既 兔了現有 T 中存在的安全 少了 工干預 是 安全可靠、 行 有效的方法。 送神方法的特 是 利用了目前安全性很高 且 用戶 的非 算法 不 可以 用到現有的 OS終端 也 于其他存在美似 休 的自 終端 比 AT 終端、 繳費終端等 具有很好的商用 值得 。

Claims

又 1. 很 支付 統中 T 安全 下載的方法 很 支付 統包括銷售 終端 S 終端管理 統T S 密碼 和硬件 其特 在于 T 戶生 吋公私密 OS終端 隨和生成 T T S的公 上 T S T S T 存儲。
2. 要求 1 的 很 支付 統中 T 安全 下載的方法 其特 在于 T S 生成 吋公私密 其中 在 中保存 保存在T S的數 中。
3. 要求 1 的 很 支付 統中 T 安全 下載的方法 其特 在于 POS終端 起公 下載 接收T S返 的公 將 存 。
4. 要求 1 的 很 支付 統中 T 安全 下載的方法 其特 在于 T S接收到 OS終端 的 的 T 由 T 利用 T 將T 明文直接存 。
5. 要求 1 的 很 支付 統中 T 安全 下載的方法 其特 在于 T 接收到 OS終端 的 的 T 由 T S 利用 T 將T T S 預先 的 3 E T 存儲在T S的數 中
6. 要求 的 很 支付 統中 T 安全 下載的方法 其特 在于 在 T S OS終端的 接口中 介 T 是否需要更新的 。 7 要求6 的 很 支付 統中 T 安全 下載的方法 其特 在于 需要 OS終端更新T 只要 OS 向 T S 任何 包括 到、 交易等 則由 T S在 接口中將 需要更新 在 文中 OS終端在 T 的 常
果 到 更新 的 已 生效 則 就 要求 1 T 的更新 完成T 的自 更新 其他 常使用情況下 更新 。 8. 要求 1 的 很 支付 統中 T 安全自 下載的方法 其特 在于 T S完成T 的解 和存儲 OS 終端是否已 更新T 成功。 9. 安全下載的很 支付 統 包括銷售 終端 OS 終端管理 統T S 密碼 和硬件 , 其特 在于 的 T S 戶生 吋公私密 的 存儲 T S 的 公 密碼 戶生 T 利用 T S 的公
。 10. 要求9 的 安全下載的銀行 支付 統 其特 在于 的 將 用公 密的 T 存 儲或者 特換成3 ES 存儲。 11 要求9 的 安全下載的很 支付 統 其特 在于 的 吋公私密 其中 在 中保存 保存在T S的 中。 12. 要求9 的 安全下載的很 支付 統 其特 在于 在 T S OS終端的 接 中 介 T 是否 需要更新的 。 13. 要求 12 的 安全下載的很 支付 統, 其特 在于 需要 O 終端更新T 只要 OS終端向 T S 任何 包括 到、 交 等 則由 T S在 接口中將 需要更新 在 文中 OS終端在 T S的正常 , 果 到 需要更新 的 已 生效 則 就 T 的 更新 其 他正常使用情況下 更新 。
PCT/CN2010/000926 2009-06-25 2010-06-24 一种银行卡支付系统中主密钥安全自动下载的方法及其系统 Ceased WO2010148646A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CA2766491A CA2766491C (en) 2009-06-25 2010-06-24 A method and system for securely and automatically downloading a master key in a bank card payment system
SG2011095908A SG177349A1 (en) 2009-06-25 2010-06-24 Method for safely and automatically downloading terminal master key in bank card payment system and the system thereof

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910053763.1 2009-06-25
CN200910053763.1A CN101930644B (zh) 2009-06-25 2009-06-25 一种银行卡支付系统中主密钥安全自动下载的方法及其系统

Publications (1)

Publication Number Publication Date
WO2010148646A1 true WO2010148646A1 (zh) 2010-12-29

Family

ID=43369800

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/000926 Ceased WO2010148646A1 (zh) 2009-06-25 2010-06-24 一种银行卡支付系统中主密钥安全自动下载的方法及其系统

Country Status (4)

Country Link
CN (1) CN101930644B (zh)
CA (1) CA2766491C (zh)
SG (1) SG177349A1 (zh)
WO (1) WO2010148646A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103714635A (zh) * 2013-03-15 2014-04-09 福建联迪商用设备有限公司 一种pos终端及其终端主密钥下载模式配置方法
CN106712939A (zh) * 2016-12-27 2017-05-24 百富计算机技术(深圳)有限公司 密钥离线传输方法和装置
CN108365950A (zh) * 2018-01-03 2018-08-03 深圳怡化电脑股份有限公司 金融自助设备密钥的生成方法及装置
CN118631428A (zh) * 2024-05-15 2024-09-10 中国工商银行股份有限公司 密钥更新方法、密钥管理系统、设备、存储介质及产品

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103237005A (zh) 2013-03-15 2013-08-07 福建联迪商用设备有限公司 密钥管理方法及系统
CN103220270A (zh) 2013-03-15 2013-07-24 福建联迪商用设备有限公司 密钥下载方法、管理方法、下载管理方法及装置和系统
CN103237004A (zh) * 2013-03-15 2013-08-07 福建联迪商用设备有限公司 密钥下载方法、管理方法、下载管理方法及装置和系统
CN103595718B (zh) * 2013-11-15 2016-08-10 拉卡拉支付有限公司 一种pos终端激活方法、系统、服务平台及pos终端
US9571279B2 (en) * 2014-06-05 2017-02-14 Cavium, Inc. Systems and methods for secured backup of hardware security modules for cloud-based web services
CN105281915B (zh) * 2015-11-04 2018-11-20 博宏信息技术有限公司 一种密码键盘生成密文的方法
CN105978856B (zh) * 2016-04-18 2019-01-25 随行付支付有限公司 一种pos机密钥下载方法、装置及系统
CN106097608B (zh) * 2016-06-06 2018-07-27 福建联迪商用设备有限公司 远程密钥下载方法及系统、收单机构和目标pos终端
CN106209888B (zh) * 2016-07-25 2019-06-04 银联商务有限公司 一种信息传输方法及装置
CN109309567A (zh) * 2018-09-04 2019-02-05 福建联迪商用设备有限公司 一种传递密钥的方法及系统
CN112532567A (zh) * 2019-09-19 2021-03-19 中国移动通信集团湖南有限公司 一种交易加密方法和posp系统
CN111275440B (zh) * 2020-01-19 2023-11-10 中钞科堡现金处理技术(北京)有限公司 远程密钥下载方法及系统
CN111950999B (zh) * 2020-07-28 2024-06-04 银盛支付服务股份有限公司 一种在pos机上实现基于ic卡灌密钥安全方法及系统
CN112464188B (zh) * 2020-12-14 2023-10-31 艾体威尔电子技术(北京)有限公司 一种支付终端与外设密码键盘的绑定方法
CN112462980B (zh) * 2020-12-15 2021-07-20 深圳市捷诚技术服务有限公司 密码防截取方法、装置及pos机
CN113708923A (zh) * 2021-07-29 2021-11-26 银盛支付服务股份有限公司 一种远程下载主密钥的方法及系统
CN114039728B (zh) * 2021-12-24 2024-09-17 中电长城(长沙)信息技术有限公司 一种报文加解密方法及其系统

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2457263A1 (en) * 2003-02-11 2004-08-11 Bahram Seyed Zahir Azami System facilitating a purchase transaction over a wireless network
WO2004104725A2 (en) * 2003-05-20 2004-12-02 Ipdc, L.L.C. Method of disposable command encoding (dce) for security protection
CN1835007A (zh) * 2006-04-07 2006-09-20 浙江通普通信技术有限公司 基于移动通信网络的移动支付方法
CN101048790A (zh) * 2004-08-25 2007-10-03 Sk电信有限公司 利用移动通信终端的认证和支付系统及方法
CN101359383A (zh) * 2008-09-23 2009-02-04 中国移动通信集团广东有限公司 一种基于移动通信的非接触卡应用管理系统及管理方法
CN101436280A (zh) * 2008-12-15 2009-05-20 北京华大智宝电子系统有限公司 实现移动终端电子支付的方法及系统

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1127033C (zh) * 2000-07-20 2003-11-05 天津南开戈德集团有限公司 无线移动网络销售点终端系统
WO2008021581A2 (en) * 2006-02-22 2008-02-21 Hypercom Corporation Secure electronic transaction system
CN101047493A (zh) * 2006-06-02 2007-10-03 华为技术有限公司 获取简单网络管理协议管理密钥的方法及系统
CN101458794A (zh) * 2007-12-10 2009-06-17 国际商业机器公司 增强支付安全性的系统及其方法以及支付中心

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2457263A1 (en) * 2003-02-11 2004-08-11 Bahram Seyed Zahir Azami System facilitating a purchase transaction over a wireless network
WO2004104725A2 (en) * 2003-05-20 2004-12-02 Ipdc, L.L.C. Method of disposable command encoding (dce) for security protection
CN101048790A (zh) * 2004-08-25 2007-10-03 Sk电信有限公司 利用移动通信终端的认证和支付系统及方法
CN1835007A (zh) * 2006-04-07 2006-09-20 浙江通普通信技术有限公司 基于移动通信网络的移动支付方法
CN101359383A (zh) * 2008-09-23 2009-02-04 中国移动通信集团广东有限公司 一种基于移动通信的非接触卡应用管理系统及管理方法
CN101436280A (zh) * 2008-12-15 2009-05-20 北京华大智宝电子系统有限公司 实现移动终端电子支付的方法及系统

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103714635A (zh) * 2013-03-15 2014-04-09 福建联迪商用设备有限公司 一种pos终端及其终端主密钥下载模式配置方法
CN103729943A (zh) * 2013-03-15 2014-04-16 福建联迪商用设备有限公司 一种将传输密钥导入kms系统的方法及系统
CN103729942A (zh) * 2013-03-15 2014-04-16 福建联迪商用设备有限公司 将传输密钥从终端服务器传输到密钥服务器的方法及系统
CN103714635B (zh) * 2013-03-15 2015-11-11 福建联迪商用设备有限公司 一种pos终端及其终端主密钥下载模式配置方法
CN103729943B (zh) * 2013-03-15 2015-12-30 福建联迪商用设备有限公司 一种将传输密钥导入kms系统的方法及系统
CN103729942B (zh) * 2013-03-15 2016-01-13 福建联迪商用设备有限公司 将传输密钥从终端服务器传输到密钥服务器的方法及系统
CN106712939A (zh) * 2016-12-27 2017-05-24 百富计算机技术(深圳)有限公司 密钥离线传输方法和装置
CN108365950A (zh) * 2018-01-03 2018-08-03 深圳怡化电脑股份有限公司 金融自助设备密钥的生成方法及装置
CN118631428A (zh) * 2024-05-15 2024-09-10 中国工商银行股份有限公司 密钥更新方法、密钥管理系统、设备、存储介质及产品

Also Published As

Publication number Publication date
CN101930644B (zh) 2014-04-16
CA2766491C (en) 2016-06-07
CN101930644A (zh) 2010-12-29
SG177349A1 (en) 2012-02-28
CA2766491A1 (en) 2010-12-29

Similar Documents

Publication Publication Date Title
WO2010148646A1 (zh) 一种银行卡支付系统中主密钥安全自动下载的方法及其系统
KR101544722B1 (ko) 부인 방지 방법, 이를 위한 결제 관리 서버 및 사용자 단말기
EP2700003B1 (en) Key management using quasi out of band authentication architecture
US20080289019A1 (en) Framework for automated dissemination of security metadata for distributed trust establishment
JP2002158650A (ja) 認証・暗号化処理代行用のサーバ、アクセスカード、プログラム記録媒体及び携帯端末
CN104468562B (zh) 一种面向移动应用透明的数据安全保护便携式终端
US20130333006A1 (en) Enterprise triggered 2chk association
CN107332701A (zh) 管理节点的方法和系统
WO2013023499A1 (zh) 手机支付安全控制方法及系统
US20170006021A1 (en) Providing a single session experience across multiple applications
CN108234509A (zh) 基于tee和pki证书的fido认证器、认证系统及方法
CN1968095B (zh) 登录本地机的方法和装置
CN109587101A (zh) 一种数字证书管理方法、装置及存储介质
US20250055704A1 (en) Non-repudiation method and system
CN104954123A (zh) 智能pos终端主密钥更新系统及更新方法
CN103152425A (zh) 基于云技术的移动设备的安全管理系统
JP2018037987A (ja) 秘密鍵管理システムおよび秘密鍵管理方法
JP5781678B1 (ja) 電子データ利用システム、携帯端末装置、及び電子データ利用システムにおける方法
CN115761939A (zh) 一种提款箱开关锁控制方法、提款箱、系统及装置
CN104657856A (zh) 基于位置认证的智能移动客户端支付方法及服务器系统
CN109388923B (zh) 一种程序执行方法及装置
JP5678150B2 (ja) ユーザ端末、鍵管理システム、及びプログラム
KR20080087917A (ko) 일회용 비밀번호 생성방법과 키 발급 시스템 및 일회용비밀번호 인증 시스템
KR20190099984A (ko) 개인 키 관리 시스템
CN104144256B (zh) 一种基于移动终端的便携式密码装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10791153

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2766491

Country of ref document: CA

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 23/04/2012)

122 Ep: pct application non-entry in european phase

Ref document number: 10791153

Country of ref document: EP

Kind code of ref document: A1