WO2013071858A1 - 一种智能电视支付密钥系统以及基于智能电视的支付方法 - Google Patents
一种智能电视支付密钥系统以及基于智能电视的支付方法 Download PDFInfo
- Publication number
- WO2013071858A1 WO2013071858A1 PCT/CN2012/084565 CN2012084565W WO2013071858A1 WO 2013071858 A1 WO2013071858 A1 WO 2013071858A1 CN 2012084565 W CN2012084565 W CN 2012084565W WO 2013071858 A1 WO2013071858 A1 WO 2013071858A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- payment
- module
- digest value
- key
- smart television
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
- H04L9/3006—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters
- H04L9/302—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters involving the integer factorization problem, e.g. RSA or quadratic sieve [QS] schemes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/41—Structure of client; Structure of client peripherals
- H04N21/426—Internal components of the client ; Characteristics thereof
- H04N21/42607—Internal components of the client ; Characteristics thereof for processing the incoming bitstream
- H04N21/42623—Internal components of the client ; Characteristics thereof for processing the incoming bitstream involving specific decryption arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/45—Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies, resolving scheduling conflicts
- H04N21/462—Content or additional data management e.g. creating a master electronic programme guide from data received from the Internet and a Head-end or controlling the complexity of a video stream by scaling the resolution or bit-rate based on the client capabilities
- H04N21/4623—Processing of entitlement messages, e.g. ECM [Entitlement Control Message] or EMM [Entitlement Management Message]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/56—Financial cryptography, e.g. electronic payment or e-cash
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/60—Digital content management, e.g. content distribution
- H04L2209/601—Broadcast encryption
Definitions
- the present invention relates to a smart television payment key system and a smart television based payment method, and more particularly to a smart television payment key system for asymmetric keys and a smart television based payment method.
- the micropayment is mainly for the TV user to purchase the video and video service.
- the TV service operator provides the user with a virtual account. The user can pre-charge the account. When a small payment is required, the virtual user account is deducted. Fees; large payments are generally applied to TV commerce, personal finance, premium recharge and user virtual account recharge.
- the TV payment is based on a cardless payment solution, and the cardholder operates the remote control to operate the menu of the television screen to complete the payment.
- the user can select the bound bank card number, enter the personal password or the validity period or CVN2 (ie check code) and other bank sensitive information through the remote control of the smart TV terminal to realize cardless payment (pre-binding requires the user to input the cardholder assistance).
- the authentication information is sent to the card issuing party for verification); or the transaction element such as the bank card sensitive information and the cardholder's auxiliary authentication information is manually input to realize the cardless transaction.
- FIG. N is a block diagram showing the structure of a prior art television payment system.
- the television payment system includes: a payment client 801, a payment channel pre-system (TPP) 802, a smart TV payment pre-device (ie TVP) 803, and a content providing platform associated therewith (also referred to as Integrated broadcast control platform) 804.
- TPP payment channel pre-system
- TVP smart TV payment pre-device
- the entire TV payment system securely controls the data as it transmits the transaction message.
- the Internet-based online TV payment that has appeared on the market its transaction financial transaction data is encrypted and transmitted through the SSL and HTTPS protocols.
- the TV terminal and the server end authenticate each other through digital certificates, perform key exchange; encrypt and conceal the data transmitted by the asymmetric key; achieve the purpose of secure transmission of data.
- the application of the existing asymmetric cryptography technology is more that the terminal only encrypts the user PIN with the public key and performs trans-encryption on the server side.
- the present invention has been made in view of the above problems, and aims to provide a smart, cost-effective smart television payment key system and a smart television based payment method.
- the smart television payment key system of the present invention is characterized in that it has a payment client device and a TVP encryption device, and the payment client device includes: a public key storage module, which is preset with the following public key; a user interface module, Obtaining transaction information and sensitive data, generating transaction information from the obtained transaction information, and invoking a public key from the public key storage module; and encrypting the sensitive information by using a public key invoked by the user interface module
- the client encrypts the data; and the sending module, the client encrypted data and the message body are used as a transaction message body to the TVP encryption device, and the TVP encryption device has: a key generation module, configured to generate a private key and a public key corresponding to the private key; a private key storage module, configured to store the private key, a receiving module, configured to receive a transaction message body sent from the payment client device; and a decryption module, the call is stored in the The private key in the private key storage module decrypts the client encrypted data in the
- the sending module has a compression coding unit that compresses and encodes the transaction message, and a transmission unit that sends the compressed and encoded transaction message
- the receiving module has a receiving unit that receives the transaction message and a decoding and decompressing unit that decodes and decompresses the transaction message.
- the encryption module encrypts the sensitive information by using an RSA asymmetric encryption algorithm
- the decryption module performs asymmetric private key decryption by using the private key to encrypt the data.
- the payment client device further includes: a first digest value calculation module configured to calculate a digest value for the transaction message body and use the calculated digest value as the sensitive data, where the TVP encryption device further includes a second digest value calculation module for calculating a digest value for the received transaction message body; a digest value comparison module, comparing the digest value calculated in the second digest value calculation module and decompressing by the decoding Whether the digest value contained in the sensitive data obtained after decompressing the unit decoding is consistent.
- a first digest value calculation module configured to calculate a digest value for the transaction message body and use the calculated digest value as the sensitive data
- the TVP encryption device further includes a second digest value calculation module for calculating a digest value for the received transaction message body
- a digest value comparison module comparing the digest value calculated in the second digest value calculation module and decompressing by the decoding Whether the digest value contained in the sensitive data obtained after decompressing the unit decoding is consistent.
- the first digest value calculation module and the second digest value calculation module calculate a digest value for the transaction message body by using a secure hash algorithm.
- the digest value comparison module discards the message when it is determined that the digest value is inconsistent.
- the public key has a corresponding validity period over time and the intensity gradually increases over time.
- the public key is three, which are 1152 bits, 1408 bits, and 1984 bits, respectively.
- the private key and the public key correspond to an index number.
- the sending module further sends the index number to the TVP encryption device together with the transaction message body.
- the decryption module is further configured to perform trans-encryption of the decrypted PIN BLOCK (password format) by using a symmetric key.
- the TVP encryption device is provided with: a dynamic code generating module, generating a dynamic code according to a request from the payment client device, storing the dynamic code, and transmitting the dynamic code to a user; a dynamic code comparison module, a comparison The dynamic code stored in the dynamic code generating module and the dynamic code included in the transaction message body.
- the dynamic code comparison module discards the message if it is determined that the dynamic code stored in the dynamic code generating module and the dynamic code in the transaction message body are inconsistent.
- the smart TV-based payment method of the present invention utilizes a payment client device and
- the TVP encryption device performs the television payment, and the method includes: acquiring the transaction information and the sensitive data; and encrypting the acquired sensitive data by using the public key; and encrypting the encrypted sensitive data and the transaction information a transmitting step of the payment client terminal device to the TVP encrypting device; a receiving step of receiving sensitive data and transaction information transmitted from the payment client device; receiving with a private key pair corresponding to the public key The decryption step of decrypting sensitive data.
- the sensitive information is performed by using a public key
- RSA asymmetric encryption in which the asymmetric data is decrypted by asymmetric key using the private key.
- the transaction message is compressed and encoded, and then sent, in the receiving and receiving step, after the transaction message is received, the transaction message is decoded and decompressed. .
- the smart TV-based payment method of the present invention further comprises: calculating, by the payment client device, a digest value for the transaction message body and using the calculated digest value as the first digest value of the sensitive data a second digest value calculation step of calculating a digest value for the received transaction message body by the TVP encryption device; comparing the digest value calculated by the second digest value calculation step and the decoding solution step by the second digest value calculation step The digest value comparison step of whether the digest value contained in the sensitive data obtained after decryption is consistent.
- the digest value is calculated for the transaction message body by using a secure hash algorithm in the first digest value calculation step and the second digest value calculation step.
- the message is discarded if it is determined that the digest value is inconsistent.
- the public key has a corresponding validity period over time and the intensity gradually increases over time.
- the public key is three, which are 1152 bits, 1408 bits, and 1984 bits, respectively.
- the private key and the public key correspond to each other by an index number.
- the index number is also sent to the TVP encryption device together with the transaction message body.
- the decrypting step the decrypted using the symmetric key pair
- PINBLOCK password format
- the smart TV-based payment method of the present invention further comprises: generating a dynamic code according to a request from the payment client device and storing the dynamic code in the TVP encryption device, and transmitting the dynamic code to the user at the same time a dynamic code generating step; comparing a dynamic code stored in the TVP encryption device with a dynamic code comparison step of a dynamic code that is input to the payment client as a sensitive data and sent to the TVP encryption device as a transaction message body .
- the payment client device of the smart television payment key system of the present invention is characterized in that: a public key storage module is configured to pre-store a public key file; a user interface module is configured to obtain transaction information and sensitive data, and the obtained transaction information Generating a message body, and for calling a public key from the public key storage module; the encryption module encrypts the sensitive information by using a public key invoked by the user interface module to obtain client encrypted data; sending module, sending station The client encrypted data and the transaction message composed of the message body.
- the payment client device is further provided with a digest value calculation module for calculating a digest value for the transaction message body.
- the digest value calculation module calculates a digest value for the transaction message body by using a secure hash algorithm.
- the public key has a corresponding validity period over time and the intensity gradually increases over time.
- the public key is three, which are 1152 bits, 1408 bits, and 1984 bits, respectively.
- the encryption module uses the public key to perform an RSA asymmetric encryption algorithm to encrypt the sensitive information to obtain client-side encrypted data.
- the encryption module compresses and encodes the transaction message before transmitting.
- the TVP encryption device in the smart television payment key system of the present invention is characterized in that: a key generation module is configured to generate a private key; and a private key storage module is configured to store the a private key; a receiving module, configured to receive a transaction message body including the client encrypted data; and a decryption module, calling the private key stored in the private key storage module to decrypt the client encrypted data in the transaction message body.
- the decryption module is further configured to perform trans-encryption of the decrypted PIN BLOCK (password format) by using a symmetric key.
- PIN BLOCK password format
- the decryption module is further configured to perform trans-encryption of the decrypted PIN BLOCK (password format) by using a symmetric key.
- the transaction password is in the ciphertext state, thus ensuring the security of the transactional interest.
- a preset public key is adopted, the public key has a long service life, and the encryption density is strong, and both security performance and cost saving can be considered.
- Figure 1 is a schematic configuration diagram showing a smart television payment key system of the present invention.
- Fig. 2 is a view showing a further schematic configuration of a smart television payment key system of the present invention.
- FIG. 3 is a flow chart showing a smart TV based payment method of the present invention. detailed description
- FIG. 1 is a schematic configuration diagram showing a smart television payment key system of the present invention.
- the smart television payment key system of the present invention is installed by a payment client. 100 (i.e., television terminal) and TVP encryption device 200 are constructed.
- the payment client device 100 mainly includes a public key storage module 101, a user interface module 102 (referred to as a UI module in the figure), an encryption module 103, and a sending module 104.
- the TVP encryption device 200 mainly includes a key generation module 201 and a private key storage module. 202.
- the receiving module 203 and the decrypting module 204 The payment client device 100 and TVP encryption device 200 are constructed.
- the payment client device 100 mainly includes a public key storage module 101, a user interface module 102 (referred to as a UI module in the figure), an encryption module 103, and a sending module 104.
- the TVP encryption device 200 mainly includes a key generation module 201 and a private key storage module. 202.
- the public key to be described later is placed in the public key storage module 101 in advance.
- the user interface module 102 obtains the transaction information and the sensitive data, generates the transaction information of the obtained transaction information, and invokes the public key from the public key storage module.
- Transaction information mainly refers to transaction-related information such as transaction amount, transaction content, and transaction time.
- Sensitive data includes bank card account number, transaction password, digest value (ie HASH value, which will be described later), bank card check digit (ie CVN2), card validity period, dynamic code (described later) and other information. .
- the encryption module 103 encrypts the sensitive information using the public key invoked by the user interface module 102, thereby obtaining client encrypted data.
- the transmitting module 104 uses the client encrypted data and the message body as a transaction message body to the TVP encryption device 200.
- the encryption module 103 encrypts the sensitive information using an RSA asymmetric encryption algorithm.
- the RSA asymmetric encryption algorithm is one of the most commonly used asymmetric encryption algorithms.
- the RSA key generation step consists of the following three steps:
- each packet Before encrypting a message, it is divided into smaller data packets than n, and each packet is encrypted.
- the key generation module 201 is configured to generate a private key and a public key.
- the private key storage module 202 is configured to store the private key generated by the key generation module 201.
- the receiving module 203 receives the transaction message body transmitted from the payment client device 100.
- the decryption module 204 invokes the private key stored in the private key storage module 202 to perform asymmetric private key decryption on the client encrypted data in the transaction message body.
- the public key and the private key generated by the key generation module 201 are - corresponding, and they can establish a correspondence relationship by an index number.
- the private key is not available from the outside, and the public key can be obtained externally by means of an interface call.
- the payment client device 100 is pre-positioned by converting the public key generated in the TVP encryption device 200 into a public key file.
- the user interface module 102 invokes the public key to encrypt the data.
- the transmitting module 104 of the client device 100 also transmits the index number corresponding to the public key to the TVP encrypting device 200.
- the private key corresponding to the public key can be found based on the index number.
- each public key is set to a corresponding validity period and the intensity is gradually increased over time.
- three keys of 1152 bits, 1408 bits, and 1984 bits can be set.
- the payment client device 100 prompts the user to input the bank card sensitive information and the verification element through the user interface module 102, and collects the corresponding public key from the public key file according to the time zone of the current date, and performs encryption processing by the encryption module 103. In this way, not only the problem of frequent update of keys in the existing encryption technology but also the key with higher confidentiality over time can be solved.
- the transmitting module 104 specifically includes: a compression encoding unit that compresses and BASE64 encodes the transaction text, and a transmitting unit (not shown) that transmits the compressed and encoded transaction message.
- the receiving module 203 specifically includes: a receiving unit that receives the transaction message and a decoding and decompressing unit that performs BASE64 decoding and decompression on the transaction message.
- the decryption module 204 in the TVP encryption device 200 further utilizes symmetry
- the key and the decrypted PIN BLOCK (password format) are transcoded.
- the reason why transcoding is required is that sensitive information such as bank card passwords in the financial system are not allowed to reside in the application system, including the database and the memory, and therefore must be executed in the TVP encryption apparatus 200.
- the encryption process is not limited to the encryption process.
- Fig. 2 is a view showing a further schematic configuration of a smart television payment key system of the present invention.
- the payment client device 100 further has: configured to calculate a digest value (ie, a HASH value) for the transaction message body and The calculated digest value is used as the first digest value calculation module 105 of the sensitive data.
- the TVP encryption apparatus 200 further includes: a second digest value calculation module 205 for calculating a digest value for the received transaction message body; the digest value comparison module 206 compares the digest value calculated by the second digest value calculation module with Whether the digest value contained in the sensitive data obtained by decoding and decompressing unit decoding and decompressing is consistent.
- a secure hash algorithm is employed as a method of calculating the digest value.
- the first digest value calculation module 105 calculates a digest value for the transaction message body, and performs the above-described encryption as the sensitive information.
- the digest value is also calculated by the TVE encryption device 200 using the second digest value calculation module 205 for the received message body, and the digest value included in the decrypted sensitive information is performed by the digest value comparison module 206. If the two are not equal, it indicates that the transaction message may have been changed by the tomb during the transmission, and the message is discarded.
- the TVP encryption apparatus 200 may further include: a dynamic code generation module 208 and a dynamic code comparison module 209.
- the dynamic code generation module 208 generates a dynamic code according to a request from the payment client device 100 and stores the dynamic code, and simultaneously transmits the dynamic code to the user by means of a short message or the like.
- the dynamic code is input according to the prompt of the user interface module 102, and the dynamic code is used as the sensitive information, and is encrypted by the encryption module 103 and then transmitted by the sending module 104 to the TVP encryption device 200.
- Receiving module 203 in TVP encryption device 200 The dynamic code received and decrypted by the decryption module 204 is input to the dynamic code comparison module 209, and the dynamic code stored in the dynamic code generation module 208 (i.e., the dynamic code generated by the dynamic code generation module 208 at the earliest) is also input.
- the dynamic code comparison module 209 performs the two processes by the dynamic code comparison module 209. If the two are not equal, it indicates that the transaction message may be altered by the tomb during the transmission process, and the message is discarded.
- the public key is utilized without using the private key, so even if the transaction message is changed by the attacker during the transmission process, the encrypted security information cannot be decrypted and acquired, thereby improving System security.
- the smart television payment key system of the present invention by calculating the digest value of the message and comparing it, even if the transaction message is tombed by the attacker during the transmission process, by verifying the digest value, it can be determined Whether the transaction message has been changed by the tomb has improved the security of the system.
- the smart television payment key system of the present invention by using a dynamic code verification mechanism, the accuracy of the card holder identity can be ensured, and the security of the system is improved.
- the transaction password in each link of the entire transaction, is in a ciphertext state, which is invisible, and the transaction password plaintext is not recorded in any physical medium, therefore, It further ensures the security of transactional interest and improves the security of the system.
- the public key has a long service life and a strong encryption density, and can save costs on the basis of ensuring system security.
- FIG. 3 is a flow chart showing a smart TV based payment method of the present invention.
- the transaction information is acquired to form a transaction message body, and the digest value is calculated for the message body.
- the transaction message body is composed of transaction information and sensitive data.
- Transaction information mainly refers to transaction-related information such as transaction amount, transaction content, and transaction time.
- Sensitive data includes bank card account number, transaction password, summary value, bank card check digit (ie CVN2), card validity period, dynamic code and other information.
- the calculated digest value is also used as the sensitive information together to perform RSA asymmetric encryption by using the public key stored in the public key file to generate encryption.
- Post client name Sense data Next, the encrypted client sensitive data and the message body are transmitted to the TVP encryption device 200 as a transaction message.
- the encrypted client-side sensitive data is decrypted by the private key using the private key, and the digest value of the sent message body is obtained by decrypting the asymmetric private key. Dynamic code sent, sensitive information after decryption.
- the encrypted PIN BLOCK (password format) is generated by using the decrypted PIN BLOCK (cryptographic format) and the symmetric key for symmetric key key transcryption.
- the sensitive information after decryption and the encrypted PIN BLOCK (password format) can be applied to transaction processing.
- the digest value is calculated for the received message body. Comparing the calculated digest value of the packet body with the digest value of the above-mentioned sent packet body, verifying whether the two are consistent. If the two are inconsistent, the packet is discarded. If it is judged that the two are consistent, continue processing.
- the verification digest value On the basis of the verification digest value, it is further verified whether the decrypted uplink dynamic code is consistent with the dynamic code stored in the TVP encryption device 200, and discards the message if it is determined that the two are inconsistent. In the case where it is judged that the two are consistent, the transaction processing is continued.
- the smart TV-based payment method of the present invention is implemented by the payment client 100, that is, the television terminal and the TVP encryption device 200, using the smart TV-based payment method of the present invention, using the public key, so even if the transaction message is transmitted during the transmission process The attacker's tomb change, because the private key is not used, the encrypted security information can not be decrypted, which improves the security of the system.
- the smart TV-based payment method of the present invention by calculating the digest value of the message and comparing it, even if the transaction message is tombed by the attacker during the transmission process, the transaction can be judged by verifying the digest value. Whether the message has been changed by the tomb has improved the security of the system.
- the smart TV-based payment method of the present invention by using the dynamic code verification mechanism, the accuracy of the card holder identity can be ensured, and the security of the system is improved.
- the transaction password in all links of the transaction, is in a ciphertext state, which is invisible, and the transaction password is clear.
- the text will not be recorded in any physical medium, thus further ensuring the security of transactional interest and improving the security of the system.
- the public key has a long service life and a strong encryption density, and can save costs on the basis of ensuring system security.
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Multimedia (AREA)
- Databases & Information Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
Abstract
本发明涉及智能电视支付密钥系统和基于智能电视的支付方法。本发明的支付系统包括客户端装置(100)和TVP加密装置(200),其中,所述支付客户端装置(100)具备:公钥存储模块(101)、用户界面模块(102)、加密模块(103)以及发送模块(104),所述TVP加密装置(200)具备:密钥生成模块(201)、私钥存储模块(202)、接收模块(203)、解密模块(204)。利用本发明的智能电视支付密钥系统和基于智能电视的支付方法能够提高支付安全性、节省成本。
Description
一种智能电视支付密钥系统以及基于智能电视的支付方法 技术领域
本发明涉及一种智能电视支付密钥系统以及基于智能电视的 支付方法, 尤其涉及非对称密钥的智能电视支付密钥系统以及基于 智能电视的支付方法。 背景技术
目前电视支付主要应用与两种场景: 小额支付和大额支付。 小 额支付主要是电视用户用于购买影视剧视频服务的费用, 电视服务 运营商为用户提供一个虚拟账户, 用户可以在账户中预先充值, 当 需要小额支付时, 从这个虚拟的用户帐号扣除费用; 大额支付一般 应用于电视商务、 个人理财、 缴费充值以及用户虚拟帐号的充值。 电视支付基于无卡支付解决方案, 持卡人通过遥控器操作对电视屏 幕的菜单进行操作完成支付。 用户能够通过智能电视终端的遥控器 选择已绑定的银行卡卡号、 输入个人密码或有效期或 CVN2 (即校 验码)等银行敏感信息实现无卡支付(事先绑定需要用户输入持卡 人辅助认证信息送发卡方进行验证); 或者直接手动输入银行卡敏 感信息和持卡人辅助认证信息等交易要素实现无卡交易。
图 N是表示现有技术的电视支付系统的结构示意图。 如图 N 所示, 电视支付系统包括: 支付客户端 801、支付通道前置系统(即 TPP ) 802、 智能电视支付前置装置(即 TVP ) 803及与之相关的内 容提供平台 (也称为集成播控平台) 804。 整个电视支付系统在传输 交易报文时对数据进行安全控制。
另一方面, 市场上已出现的基于互联网模式的在线电视支付, 其交易金融交易数据是通过 SSL和 HTTPS协议加密和传输。 电视 终端与服务器端通过数字证书相互认证, 执行密钥交换; 通过非对 称密钥对传送的数据进行加密和隐藏; 达到数据的安全传输目的。
现有非对称加密技术应用更多的是终端只对用户 PIN用公钥进行加 密, 在服务器端进行转加密。
在现有技术中存在以下的问题: 不能绝对确保服务器自己是安 全的。 由于 SSL和 HTTPS协议加密算法及认证机制都是公开的, 且算法较简单, 所以服务器端很容易被仿造; 这点甚至已被攻击者 利用, 常见例子是模仿银行域名的钓鱼攻击。 通过仿造服务器端模 拟与客户端发生交易, 获取银行卡号、 交易密码等金融敏感信息。 而如果通过双向认证的技术可以避免以上的缺陷, 但却增加了开发 和运营成本。 另外, 针对目前无卡支付的日益发展, 发卡方更需要 对除 PIN以外的其他要素进行验证, 包括 CVN2、 有效期等, 甚至 卡号, 因此在交易通道中如何对这些要素进行安全传输是现有体系 无法完全保障的。 发明内容
本发明鉴于上述问题, 旨在提供一种安全性高、 节省成本的智 能电视支付密钥系统以及基于智能电视的支付方法。
本发明的智能电视支付密钥系统, 其特征在于, 具备支付客户 端装置和 TVP加密装置,所述支付客户端装置具备:公钥存储模块, 预置有下述的公钥; 用户界面模块, 获得交易信息和敏感数据, 将 获得的交易信息生成报文体, 并且从所述公钥存储模块调用公钥; 加密模块, 利用通过所述用户界面模块调用的公钥对所述敏感信息 进行加密得到客户端加密数据; 以及发送模块, 将所述客户端加密 数据和所述报文体作为交易报文体到所述 TVP加密装置,所述 TVP 加密装置具备: 密钥生成模块, 用于生成私钥和与该私钥——对应 的公钥; 私钥存储模块, 用于存储所述私钥, 接收模块, 用于接收 从所述支付客户端装置发送来的交易报文体; 解密模块, 调用存储 在所述私钥存储模块中的私钥对所述交易报文体中的所述客户端 加密数据进行解密。
优选地, 所述发送模块具有对所述交易报文进行压缩和编码的 压缩编码单元和发送经压缩和编码的所述交易报文的发送单元, 所
述接收模块具有接收所述交易报文的接收单元和对接所述交易报 文进行解码和解压缩的解码解压缩单元。
优选地,所述加密模块利用所述公钥对所述敏感信息进行 RSA 非对称加密算法进行加密, 所述解密模块利用所述私钥所述客户端 加密数据进行非对称私钥解密。
优选地, 所述支付客户端装置还具备: 用于对所述交易报文体 计算摘要值并且将计算出的摘要值作为所述敏感数据的第一摘要 值计算模块,所述 TVP加密装置还具备: 用于对接收到的所述交易 报文体计算摘要值的第二摘要值计算模块; 摘要值比较模块, 比较 所述第二摘要值计算模块中计算得到的摘要值和由所述解码解压 缩单元解码解压后得到的敏感数据中含有的摘要值是否一致。
优选地, 所述第一摘要值计算模块和第二摘要值计算模块利用 安全哈希算法对所述交易报文体计算摘要值。
优选地, 所述摘要值比较模块在判断为所述摘要值不一致的情 况下丢弃报文。
优选地, 所述公钥为具有随时间推移的对应有效期并且强度随 时间推移逐渐增强。
优选地, 所述公钥为 3把, 分别为 1152位、 1408位、 1984位。 优选地, 所述私钥和所述公钥通过索引号对应。
优选地, 所述发送模块还将所述索引号与所述交易报文体一起 发送到所述 TVP加密装置。
优选地, 所述解密模块还用于利用对称密钥对解密后的 PIN BLOCK (密码格式)进行转加密。
优选地, 所述 TVP加密装置具备: 动态码生成模块,根据来自 所述支付客户端装置的请求生成动态码并且存储该动态码, 并将该 动态码发送给用户; 动态码比较模块, 比较所述动态码生成模块中 已存储的动态码和所述交易报文体中包含的动态码。
优选地, 所述动态码比较模块在判断所述动态码生成模块中已 存储的动态码和所述交易报文体中的动态码不一致的情况下丢弃 报文。
本发明的基于智能电视的支付方法, 利用支付客户端装置和
TVP加密装置进行电视支付, 其特征在于, 包括: 获得交易信息和 敏感数据的获取步骤; 利用公钥对所述获取的敏感数据进行加密的 加密步骤; 将加密后的敏感数据和交易信息从所述支付客户终端装 置发送到所述 TVP加密装置的发送步骤;接收从所述支付客户端装 置发送来的敏感数据和交易信息的接收步骤; 用与所述公钥——对 应的私钥对接收到的敏感数据进行解密的解密步骤。
优选地, 在所述加密步骤中, 利用公钥对所述敏感信息进行
RSA非对称加密, 在所述解密步骤中, 利用私钥对所述敏感数据进 行非对称称私钥解密。
优选地, 在所述发送步骤中, 对所述交易报文进行压缩和编码 之后再进行发送, 在所述接收收步骤中, 接收所述交易报文之后对 接所述交易报文进行解码和解压缩。
优选地, 本发明的基于智能电视的支付方法还具备: 在所述支 付客户端装置对所述交易报文体计算摘要值并且将计算出的摘要 值作为所述敏感数据的第一摘要值计算步骤;在所述 TVP加密装置 对接收到的所述交易报文体计算摘要值的第二摘要值计算步骤; 比 较通过所述第二摘要值计算步骤中计算得到的摘要值和通过所述 解码解步骤解密后得到的敏感数据中含有的摘要值是否一致的摘 要值比较步骤。
优选地, 在所述第一摘要值计算步骤和所述第二摘要值计算步 骤中利用安全哈希算法对所述交易报文体计算摘要值。
优选地, 在所述摘要值比较步骤中, 在判断为所述摘要值不一 致的情况下丢弃报文。
优选地, 所述公钥为具有随时间推移的对应有效期并且强度随 时间推移逐渐增强。
优选地, 所述公钥为 3把, 分别为 1152位、 1408位、 1984位。 优选地, 所述私钥和所述公钥通过索引号——对应。
优选地, 在所述发送步骤中, 还将所述索引号与所述交易报文 体一起发送给所述 TVP加密装置。
优选地, 在所述解密步骤中, 利用对称密钥对解密后的
PINBLOCK (密码格式)进行对称密钥加密的转加密步骤。
优选地, 本发明的基于智能电视的支付方法还具备: 根据来自 所述支付客户端装置的请求生成动态码并且将该动态码存储在所 述 TVP加密装置, 同时将该动态码发送给用户的动态码生成步骤; 比较存储在所述 TVP加密装置中的动态码和用户作为敏感数据输 入到所述支付客户端并作为交易报文体发送到所述 TVP加密装置 中的动态码的动态码比较步骤。
优选地, 在所述动态码比较步骤中, 动态码不一致的情况下丢 弃^ =艮文。
本发明的智能电视支付密钥系统的支付客户端装置, 其特征在 于, 公钥存储模块, 用于预先储存公钥文件; 用户界面模块, 用于 获得交易信息和敏感数据, 将获得的交易信息生成报文体, 并且用 于从所述公钥存储模块调用公钥; 加密模块, 利用通过所述用户界 面模块调用的公钥对所述敏感信息进行加密得到客户端加密数据; 发送模块, 发送所述客户端加密数据和所述报文体组成的交易报 文。
优选地, 该支付客户端装置还具备用于对所述交易报文体计算 摘要值的摘要值计算模块。
优选地, 所述摘要值计算模块利用安全哈希算法对所述交易报 文体计算摘要值。
优选地, 所述公钥为具有随时间推移的对应有效期并且强度随 时间推移逐渐增强。
优选地, 所述公钥为 3把, 分别为 1152位、 1408位、 1984位。 优选地, 所述加密模块采用所述公钥进行 RSA 非对称加密算 法对所述敏感信息进行加密得到客户端加密数据。
优选地, 所述加密模块对所述交易报文进行压缩和编码后再进 行发送。
本发明的智能电视支付密钥系统中的 TVP加密装置,其特征在 于, 密钥生成模块, 用于生成私钥; 私钥存储模块, 用于存储所述
私钥; 接收模块, 用于接收包含客户端加密数据的交易报文体; 解 密模块, 调用存储在所述私钥存储模块中的私钥对所述交易报文体 中的客户端加密数据进行解密。
优选地, 所述解密模块还用于利用对称密钥对解密后的 PIN BLOCK (密码格式)进行转加密。 利用上述本发明的智能电视支付 密钥系统、 基于智能电视的支付方法, 由于利用了公钥, 因此即使 交易报文在传输过程中被攻击者墓改, 由于没有利用私钥, 加密后 的安全信息也无法被解密获取, 提高了系统的安全性。 而且, 通过 对报文计算摘要值, 并进行比较, 因此, 即使交易报文在传输过程 中被攻击者墓改, 通过验证摘要值, 就能够准确判断出交易报文是 否被墓改。 进一步, 在验证摘要值的基础上, 通过验证动态码, 能 够进一步保证持卡人身份的准确性。 而且, 在整个交易的各个环节 中, 交易密码都是密文状态, 因此, 确保了交易性息的安全性。 另 夕卜, 在本发明中采用了预置公钥的方式, 公钥使用期长, 加密密度 强, 能够兼顾安全性能和节省成本两方面。 附图说明
图 1是表示本发明的智能电视支付密钥系统的示意构造图。 图 2是表示本发明的智能电视支付密钥系统的进一步的示意构 造图。
图 3是表示本发明的基于智能电视的支付方法的流程图。 具体实施方式
下面介绍的是本发明的多个可能实施例中的一些, 旨在提供对本 发明的基本了解。 并不旨在确认本发明的关键或决定性的要素或限定 所要保护的范围。
为使本发明的目的、 技术方案和优点更加清楚, 下面结合附图对 本发明作进一步的详细描述。
图 1是表示本发明的智能电视支付密钥系统的示意构造图。 如图 1所示, 本发明的智能电视支付密钥系统由支付客户端装
置 100 (即电视终端)和 TVP加密装置 200构成。 支付客户端装置 100主要包括公钥存储模块 101、 用户界面模块 102 (图中简称为 UI模块) 、 加密模块 103、 发送模块 104, TVP加密装置 200主要 包括密钥生成模块 201、 私钥存储模块 202、接收模块 203、 解密模 块 204。
在支付客户端装置 100中, 公钥存储模块 101中预先被置入将 在后面描述的公钥。 用户界面模块 102获得交易信息和敏感数据, 将获得的交易信息生成报文体, 并且从公钥存储模块调用公钥。
交易信息主要是指交易金额、 交易内容、 交易时间等与交易有 关的信息。敏感数据包含银行卡帐号、交易密码、摘要值(即 HASH 值, 将在后文进行描述)、 银行卡校验位(即 CVN2 )、 卡有效期、 动态码(将在后文进行描述)等信息。
加密模块 103利用通过用户界面模块 102调用的公钥对敏感信 息进行加密, 由此得到客户端加密数据。 发送模块 104将该客户端 加密数据和所述报文体作为交易报文体到 TVP加密装置 200。
这里, 加密模块 103在对敏感信息进行加密时采用 RSA非对 称加密算法进行加密。 RSA非对称加密算法是最常用的非对称加密 算法之一。
下面简单说明一下 RSA非对称加密、 解密的过程。
首先, RSA密钥生成步骤包含以下三个步骤:
(1)独立地选取两大素数 p和 q, 计算 n = p x q, 并且计算 φ(η) = (ρ- l)(q- 1);
(2)选一整数 e, ( 1 < e<cp(n), φ(η)与 e互素)。 在模 φ(η)下, e 有唯一逆元, 计算 d=e-1mod(cp(n));
(3)取公钥为 (n,e), 私钥为 (n,d)并销毁 p, q。
接着, RSA加密和解密步骤如下:
加密消息前, 先将它分成比 n小的数据分组, 再对每个分组加 密。
力口密: C=Me ( mod n )
解密: M=Cd ( mod n )
又,在 TVP加密装置 200中,密钥生成模块 201用于生成私钥 和公钥。私钥存储模块 202用于存储密钥生成模块 201生成的私钥。 接收模块 203接收从支付客户端装置 100发送来的交易报文体。 解 密模块 204调用存储在私钥存储模块 202中的私钥对交易报文体中 的客户端加密数据进行非对称私钥解密。
在本发明中,密钥生成模块 201生成的公钥和私钥是——对应, 它们可以通过一个索引号建立对应关系。 私钥从外部不能够获得, 公钥可以通过接口调用的方式由外部获得。 在本发明中, 通过将 TVP加密装置 200中生成的公钥转换成一个公钥文件预先置入到上 述的支付客户端装置 100。 这样, 在支付客户端装置 100对数据进 行加密时, 就由用户界面模块 102调用出该公钥对数据进行加密。 在此同时付客户端装置 100的发送模块 104也会将与公钥对应的索 引号一起发送到 TVP加密装置 200。 这样, 在 TVP加密装置 200 中, 才艮据该索引号就能够找到与该公钥一一对应的私钥。
为了避免公钥频繁升级, 本发明的发明人提出一种在二进制格 式的公钥文件中共预设 3把密钥的方式。 在该方式中, 每把公钥设 置对应的有效期并且强度随时间推移逐渐增加。 作为一个示例, 可 以设置分别为 1152位、 1408位、 1984位的 3把密钥。 支付客户端 装置 100通过用户界面模块 102提示用户输入银行卡敏感信息和验 证要素, 收集后根据当前日期所处哪个时间段从公钥文件中取出对 应的公钥并由加密模块 103进行加密处理。 这样, 不仅能够解决现 有加密技术中需要频繁更新密钥的问题, 还能够提供随时间推移保 密性更高的密钥。
在支付客户端装置 100中, 发送模块 104具体地包括: 对所述 交易 文进行压缩和 BASE64编码的压缩编码单元和发送经压缩和 编码的所述交易报文的发送单元(未图示) 。
相应地, 在 TVP加密装置 200中, 接收模块 203具体地包括: 接收所述交易报文的接收单元和对接所述交易报文进行 BASE64解 码和解压缩的解码解压缩单元。
这里, TVP加密装置 200中的解密模块 204还进一步利用对称
密钥和解密后的 PIN BLOCK (密码格式)进行转加密。 在本发明 中, 需要进行转加密的原因是, 在金融系统中银行卡密码等敏感信 息不允许在应用系统,包括数据库、内存中驻留,因此,必须在 TVP 加密装置 200中进行执行这一转加密过程。
图 2是表示本发明的智能电视支付密钥系统的进一步的示意构 造图。
为了保证信息传输的安全性, 在图 1所示的结构基础上, 如图 2所示, 在支付客户端装置 100还具备: 用于对所述交易报文体计 算摘要值 (即 HASH值)并且将计算出的摘要值作为所述敏感数据 的第一摘要值计算模块 105。相应地。在 TVP加密装置 200还具备: 用于对接收到的交易报文体计算摘要值的第二摘要值计算模块 205; 摘要值比较模块 206, 比较第二摘要值计算模块中计算得到的 摘要值和由解码解压缩单元解码解压后得到的敏感数据中含有的 摘要值是否一致。 这里, 作为计算摘要值的方法, 采用安全哈希算 法。
这样, 在支付客户端装置 100, 由第一摘要值计算模块 105对 交易报文体计算摘要值, 并将该摘要值作为敏感信息进行上述加 密。在 TVP加密装置 200利用第二摘要值计算模块 205对接收到的 报文体也计算摘要值, 同时由摘要值比较模块 206对该计算出的摘 要值与解密后的敏感信息中含有的摘要值进行比较, 如果两者不相 等, 则表明交易报文在传输过程中可能被墓改了, 则丢弃报文。
在此基础上, 为了再进一步保证信息传输的安全性, 除了利用 摘要值进行比对之外, 还可以利用动态码的比对来进一步保证安全 性。 如图 2所示, 具体地, TVP加密装置 200还可以进一步具备: 动态码生成模块 208和动态码比较模块 209。 动态码生成模块 208 根据来自支付客户端装置 100 的请求生成动态码并且存储该动态 码, 同时将该动态码通过短信或者其他等的方式发送给用户。 用户 在支付时, 根据用户接口模块 102的提示输入该动态码, 并将该动 态码作为敏感信息, 通过加密模块 103进行加密后由发送模块 104 发送到 TVP加密装置 200。经 TVP加密装置 200中的接收模块 203
接收并由解密模块 204 解密后的动态码被输入到动态码比较模块 209, 同时, 动态码生成模块 208 中已存储的动态码(即最早由动 态码生成模块 208生成的动态码)也被输入动态码比较模块 209, 由动态码比较模块 209对两者进行, 如果两者不相等, 则表明交易 报文在传输过程中可能被墓改了, 则丢弃报文。
在本发明的智能电视支付密钥系统中, 利用了公钥而没有利用 私钥, 因此即使交易报文在传输过程中被攻击者墓改, 加密后的安 全信息也无法被解密获取, 提高了系统的安全性。
而且, 在本发明的智能电视支付密钥系统中, 通过对报文计算 摘要值, 并进行比较, 因此, 即使交易报文在传输过程中被攻击者 墓改, 通过验证摘要值, 能够判断出交易报文是否被墓改, 提高了 系统的安全性。
而且, 在本发明的智能电视支付密钥系统中, 通过采用动态码 验证机制, 能够保证持卡人身份的准确性, 提高了系统的安全性。
而且, 在本发明智能电视支付密钥系统中, 在整个交易的各个 环节中, 交易密码都是密文状态, 都是不可见的, 交易密码明文也 不会记录在任何物理介质中, 因此, 进一步确保了交易性息的安全 性, 提高了系统的安全性。
而且, 在本发明的智能电视支付密钥系统中, 公钥使用期长, 加密密度强, 能够在保证系统安全的基础上, 节省成本。
下面对于本发明的基于智能电视的支付方法进行说明。
图 3是表示本发明的基于智能电视的支付方法的流程图。
如图 3所示, 在支付客户端装置 100侧, 获取交易信息组成交 易报文体, 对报文体计算摘要值。 其中, 交易报文体由交易信息和 敏感数据。 交易信息主要是指交易金额、 交易内容、 交易时间等与 交易有关的信息。 敏感数据包含银行卡帐号、 交易密码、 摘要值、 银行卡校验位(即 CVN2 ) 、 卡有效期、 动态码等信息。
在支付客户端装置 100侧从获得银行卡卡号、 交易密码等的其 他敏感信息, 将计算出的摘要值也作为敏感信息一起通过利用公钥 文件中存储的公钥进行 RSA 非对称加密, 生成加密后的客户端名
感数据。 接着, 将加密后的客户端敏感数据和报文体作为交易报文 一起发送到 TVP加密装置 200。
在 TVP加密装置 200侧,在接收交易报文后,对发送来的加密 后客户端敏感数据利用私钥进行非对称私钥解密, 通过非对称私钥 解密得到上送报文体的摘要值、 上送的动态码、 解密后敏感信息。
利用解密后的 PIN BLOCK (密码格式)和对称密钥进行对称 密钥密钥转加密, 生成加密后的 PIN BLOCK (密码格式) 。 解密 后敏感信息和加密后 PIN BLOCK (密码格式)可以被应用于交易 处理。
另一方面,在接收交易报文后,对接收到的报文体计算摘要值。 比较该计算得到的报文体的摘要值与上述上送报文体的摘要值, 验 证两者是否一致, 在判断两者不一致的情况下, 丢弃报文。 在判断 两者一致的情况下, 继续处理。
在验证摘要值的基础上, 进一步验证解密后的上送的动态码与 TVP加密装置 200已存储的动态码是否一致,在判断两者不一致的 情况下, 丢弃报文。 在判断两者一致的情况下, 继续交易处理。
本发明的基于智能电视的支付方法利用支付客户端 100即电视 终端和 TVP加密装置 200来实现,利用本发明的基于智能电视的支 付方法,采用公钥, 因此即使交易报文在传输过程中被攻击者墓改, 由于没有采用私钥, 加密后的安全信息也无法被解密获取, 提高了 系统的安全性。
而且, 利用本发明的基于智能电视的支付方法, 通过对报文计 算摘要值, 并进行比较, 因此, 即使交易报文在传输过程中被攻击 者墓改, 通过验证摘要值, 能够判断出交易报文是否被墓改, 提高 了系统的安全性。
而且, 利用本发明的基于智能电视的支付方法, , 通过采用动 态码验证机制, 能够保证持卡人身份的准确性, 提高了系统的安全 性。
而且, 利用本发明的基于智能电视的支付方法, 在整个交易的 各个环节中, 交易密码都是密文状态, 都是不可见的, 交易密码明
文也不会记录在任何物理介质中, 因此, 进一步确保了交易性息的 安全性, 提高了系统的安全性。
而且,利用本发明的基于智能电视的支付方法,公钥使用期长, 加密密度强, 能够在保证系统安全的基础上, 节省成本。
以上例子主要说明了本发明的系统及各种应用方法。 尽管只对 其中一些本发明的实施方式进行了描述, 但是本领域普通技术人员 应当了解, 本发明可以在不偏离其主旨与范围内以许多其他的形式 实施。 因此, 所展示的例子与实施方式被视为示意性的而非限制性 的, 在不脱离如所附各权利要求所定义的本发明精神及范围的情况 下, 本发明可能涵盖各种的修改与替换。
在不偏离本发明的精神和范围的情况下还可以构成许多有很大 差别的实施例。 应当理解, 除了如所附的权利要求所限定的, 本发明 不限于在说明书中所述的具体实施例。
Claims
1.一种智能电视支付密钥系统, 其特征在于, 具备支付客户端 装置(100 )和 TVP加密装置(200 ) ,
所述支付客户端装置( 100 )具备:
公钥存储模块(101 ) , 预置有下述的公钥;
用户界面模块(102 ) , 获得交易信息和敏感数据, 将获得的 交易信息生成报文体, 并且从所述公钥存储模块调用所述公钥; 加密模块(103 ) , 利用通过所述用户界面模块调用的公钥, 对所述敏感信息进行加密, 得到客户端加密数据; 以及
发送模块(104 ) , 将所述客户端加密数据和所述报文体作为 交易报文体发送到所述 TVP加密装置,
所述 TVP加密装置(200 )具备:
密钥生成模块(201 ) , 用于生成私钥和与该私钥——对应的 公钥;
私钥存储模块(202 ) , 用于存储所述私钥;
接收模块(203 ) , 用于接收从所述支付客户端装置发送来的 交易报文体;
解密模块(204 ) , 调用存储在所述私钥存储模块中的私钥对 所述交易报文体中的所述客户端加密数据进行解密。
2. 如权利要求 3所述的智能电视支付密钥系统, 其特征在于, 所述发送模块(104 )具有对所述交易报文进行压缩和编码的 压缩编码单元和发送经压缩和编码的所述交易报文的发送单元, 所述接收模块(203 )具有接收所述交易报文的接收单元和对 接所述交易报文进行解码和解压缩的解码解压缩单元。
3. 如权利要求 2所述的智能电视支付密钥系统, 其特征在于, 所述加密模块(103 )利用所述公钥对所述敏感信息进行 RSA 非对称加密算法进行加密,
所述解密模块(204 )利用所述私钥所述客户端加密数据进行 非对称私钥解密。
4.如权利要求 2所述的智能电视支付密钥系统, 其特征在于, 所述支付客户端装置 (100 )还具备: 用于对所述交易报文体 计算摘要值并且将计算出的摘要值作为所述敏感数据的第一摘要 值计算模块( 105 ) ,
所述 TVP加密装置( 200 )还具备:
用于对接收到的所述交易报文体计算摘要值的第二摘要值计 算模块 ( 205 ) ;
摘要值比较模块(206 ) , 比较所述第二摘要值计算模块中计 算得到的摘要值和由所述解码解压缩单元解码解压后得到的敏感 数据中含有的摘要值是否一致。
5.如权利要求 4所述的智能电视支付密钥系统, 其特征在于, 所述第一摘要值计算模块( 105 )和第二摘要值计算模块( 205 ) 利用安全哈希算法对所述交易报文体计算摘要值。
6. 如权利要求 5所述的智能电视支付密钥系统, 其特征在于, 所述摘要值比较模块(206 )在判断为所述摘要值不一致的情 况下丢弃报文。
7如权利要求 4所述的智能电视支付密钥系统, 其特征在于, 所述公钥为具有随时间推移的对应有效期并且强度随时间推 移逐渐增强。
8. 如权利要求 7所述的智能电视支付密钥系统, 其特征在于, 所述公钥为 3 4巴, 分别为 1152位、 1408位、 1984位。
9.如权利要求 1所述的智能电视支付密钥系统, 其特征在于, 所述私钥和所述公钥通过索引号——对应。
所述发送模块(104 )还将所述索引号与所述交易报文体一起 发送到所述 TVP加密装置。
10.如权利要求 3所述的智能电视支付密钥系统, 其特征在于, 所述解密模块(204 )还用于利用对称密钥对解密后的密码格 式进行转加密。
11. 如权利要求 3所述的智能电视支付密钥系统,其特征在于, 所述 TVP加密装置具备动态码生成模块(208 ) , 根据来自所 述支付客户端装置 (100 ) 的请求生成动态码并且存储该动态码, 同时也将该动态码发送给用户,
所述用户界面模块(102 )作为敏感数据还获得通过用户输入 的该动态码, 由所述加密模块(103 )将该动态码作为所述敏感信 息进行加密并由所述发送模块( 104 )将加密后的动态码作为所述 客户端加密数据与所述报文体作为交易报文体一起发送到所述 TVP加密装置,
所述 TVP加密装置还具备动态码比较模块(209 ) , 比较所述 动态码生成模块(208 ) 中已存储的所述动态码和所述交易报文体 中包含的动态码。
12. 如权利要求 11 所述的智能电视支付密钥系统, 其特征在 于,
所述动态码比较模块( 209 )在判断所述动态码生成模块( 208 ) 中已存储的动态码和所述交易报文体中的动态码不一致的情况下 丢弃^ =艮文。
13.—种基于智能电视的支付方法,利用支付客户端装置和 TVP 加密装置进行电视支付, 其特征在于, 包括:
获得交易信息和敏感数据的获取步骤;
利用公钥对所述获取的敏感数据进行加密的加密步骤; 将加密后的敏感数据和交易信息从所述支付客户终端装置发 送到所述 TVP加密装置的发送步骤;
接收从所述支付客户端装置发送来的敏感数据和交易信息的 接收步骤;
用与所述公钥——对应的私钥对接收到的敏感数据进行解密 的解密步骤。
14.如权利要求 13所述的基于智能电视的支付方法, 其特征在 于,
在所述加密步骤中, 利用公钥对所述敏感信息进行 RSA 非对 称加密,
在所述解密步骤中, 利用私钥对所述敏感数据进行非对称称私 钥解密。
15.如权利要求 14所述的基于智能电视的支付方法, 其特征在 于,
在所述发送步骤中, 对所述交易报文进行压缩和编码之后再进 行发送,
在所述接收收步骤中, 接收所述交易报文之后对接所述交易报 文进行解码和解压缩。
16.如权利要求 15的基于智能电视的支付方法, 其特征在于, 还具备:
在所述支付客户端装置对所述交易报文体计算摘要值并且将 计算出的摘要值作为所述敏感数据的第一摘要值计算步骤;
在所述 TVP加密装置对接收到的所述交易报文体计算摘要值 的第二摘要值计算步骤;
比较通过所述第二摘要值计算步骤中计算得到的摘要值和通 过所述解码解步骤解密后得到的敏感数据中含有的摘要值是否一 致的摘要值比较步骤。
17.如权利要求 16所述的基于智能电视的支付方法, 其特征在 于,
在所述第一摘要值计算步骤和所述第二摘要值计算步骤中利 用安全哈希算法对所述交易报文体计算摘要值。
18.如权利要求 17所述的基于智能电视的支付方法, 其特征在 于,
在所述摘要值比较步骤中, 在判断为所述摘要值不一致的情况 下丢弃报文。
19.如权利要求 18所述的基于智能电视的支付方法, 其特征在 于, 在所述解密步骤中, 利用对称密钥对解密后的密码格式进行转 加密。
20.如权利要求 19所述的基于智能电视的支付方法, 其特征在 于, 还具备:
根据来自所述支付客户端装置的请求生成动态码并且将该动 态码存储在所述 TVP加密装置,同时将该动态码发送给用户的动态 码生成步骤;
比较存储在所述 TVP加密装置中的动态码和用户作为敏感数 据输入到所述支付客户端( 100 )并作为交易报文体发送到所述 TVP 加密装置(200 ) 中的动态码的动态码比较步骤。
21.如权利要求 20 所述的基于智能电视的支付方法, 其特征在 于,
在所述动态码比较步骤中, 动态码不一致的情况下丢弃报文。
22.如权利要求 13 ~ 21任意一项所述的基于智能电视的支付方 法, 其特征在于,
所述公钥为具有随时间推移的对应有效期并且强度随时间推 移逐渐增强。
23.如权利要求 22所述的基于智能电视的支付方法, 其特征在 于,
所述公钥为 3 4巴, 分别为 1152位、 1408位、 1984位。
24.如权利要求 23所述的基于智能电视的支付方法, 其特征在 于,
所述私钥和所述公钥通过索引号——对应。
在所述发送步骤模块中, 还将所述索引号与所述交易报文体一 起发送给所述 TVP加密装置。
25.—种智能电视支付密钥系统的支付客户端装置, 其特征在 于, 公钥存储模块, 用于预先储存公钥文件;
用户界面模块, 用于获得交易信息和敏感数据, 将获得的交易 信息生成报文体, 并且用于从所述公钥存储模块调用公钥;
加密模块, 利用通过所述用户界面模块调用的公钥对所述敏感 信息进行加密得到客户端加密数据;
发送模块, 发送所述客户端加密数据和所述报文体组成的交易 报文。
26.如权利要求 25所述的智能电视支付密钥系统的支付客户端 装置, 其特征在于, 该支付客户端装置还具备用于对所述交易报文体计算摘要值 的摘要值计算模块。
27.如权利要求 4 所述的智能电视支付密钥系统的支付客户端 装置, 其特征在于,
所述摘要值计算模块利用安全哈希算法对所述交易报文体计 算摘要值。
28.如权利要求 27所述的智能电视支付密钥系统的支付客户端 装置, 其特征在于,
所述加密模块采用所述公钥进行 RSA 非对称加密算法对所述 敏感信息进行加密得到客户端加密数据。
29. 如权利要求 28 所述的智能电视支付密钥系统的支付客户 端装置, 其特征在于,
所述加密模块对所述交易报文进行压缩和编码后再进行发送。
30.如权利要求 25 ~ 29任意一项所述的智能电视支付密钥系统 的支付客户端装置, 其特征在于,
所述公钥为具有随时间推移的对应有效期并且强度随时间推 移逐渐增强。
31.如权利要求 30所述的智能电视支付密钥系统的支付客户端 装置, 其特征在于,
所述公钥为 3 4巴, 分别为 1152位、 1408位、 1984位。
32.—种智能电视支付密钥系统中的 TVP加密装置, 其特征在 于,
密钥生成模块(201 ) , 用于生成私钥。
私钥存储模块(202 ) , 用于存储所述私钥,
接收模块( 203 ) , 用于接收包含客户端加密数据的交易报文 体;
解密模块(204 ) , 调用存储在所述私钥存储模块中的私钥对 所述交易报文体中的客户端加密数据进行解密。
33.如权利要求 32所述的智能电视支付密钥系统中的 TVP加密 装置, 其特征在于, 还具备: 所述解密模块 (204)还用于利用对称密钥对解密后的密码格 式进行转加密。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201110361720.7A CN103108245B (zh) | 2011-11-15 | 2011-11-15 | 一种智能电视支付密钥系统以及基于智能电视的支付方法 |
| CN201110361720.7 | 2011-11-15 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2013071858A1 true WO2013071858A1 (zh) | 2013-05-23 |
Family
ID=48315761
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2012/084565 Ceased WO2013071858A1 (zh) | 2011-11-15 | 2012-11-14 | 一种智能电视支付密钥系统以及基于智能电视的支付方法 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN103108245B (zh) |
| WO (1) | WO2013071858A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106603484A (zh) * | 2016-10-25 | 2017-04-26 | 雷飏 | 虚拟钥匙方法及应用该方法的装置、后台系统、用户终端 |
| TWI743860B (zh) * | 2020-06-30 | 2021-10-21 | 瑞昱半導體股份有限公司 | 通訊裝置以及網路管理方法 |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103546454A (zh) * | 2013-08-28 | 2014-01-29 | 深圳市龙视传媒有限公司 | 一种加密方法、系统以及相关设备 |
| CN103686437B (zh) * | 2013-12-06 | 2018-12-21 | 康佳集团股份有限公司 | 一种电视机交互式动态密码授权支付方法和系统 |
| CN105516056B (zh) * | 2014-09-24 | 2018-10-26 | 腾泰科技股份有限公司 | 加密文件保护系统及其保护方法 |
| CN105654281A (zh) * | 2015-12-30 | 2016-06-08 | 中国银联股份有限公司 | 一种安全支付系统以及安全支付方法 |
| CN109034796B (zh) * | 2018-06-15 | 2023-09-22 | 安达数据技术(深圳)有限公司 | 基于联盟链的交易监管方法、电子装置及可读存储介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1766920A (zh) * | 2005-11-01 | 2006-05-03 | 广州好易联支付网络有限公司 | 网上安全支付系统及方法 |
| CN101087189A (zh) * | 1998-05-05 | 2007-12-12 | 杰伊·C·陈 | 一种用于电子交易的密码系统和方法 |
| CN101098225A (zh) * | 2006-06-29 | 2008-01-02 | 中国银联股份有限公司 | 安全数据传输方法及支付方法、支付终端和支付服务器 |
| CN101853453A (zh) * | 2009-04-03 | 2010-10-06 | 中兴通讯股份有限公司 | 一种实现移动支付的系统及方法 |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP4304362B2 (ja) * | 2002-06-25 | 2009-07-29 | 日本電気株式会社 | Pki対応の証明書確認処理方法及びその装置、並びにpki対応の証明書確認処理プログラム |
| CN101119471A (zh) * | 2007-08-29 | 2008-02-06 | 北京数码视讯科技有限公司 | 实现数字电视在线支付的系统及方法 |
-
2011
- 2011-11-15 CN CN201110361720.7A patent/CN103108245B/zh active Active
-
2012
- 2012-11-14 WO PCT/CN2012/084565 patent/WO2013071858A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101087189A (zh) * | 1998-05-05 | 2007-12-12 | 杰伊·C·陈 | 一种用于电子交易的密码系统和方法 |
| CN1766920A (zh) * | 2005-11-01 | 2006-05-03 | 广州好易联支付网络有限公司 | 网上安全支付系统及方法 |
| CN101098225A (zh) * | 2006-06-29 | 2008-01-02 | 中国银联股份有限公司 | 安全数据传输方法及支付方法、支付终端和支付服务器 |
| CN101853453A (zh) * | 2009-04-03 | 2010-10-06 | 中兴通讯股份有限公司 | 一种实现移动支付的系统及方法 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106603484A (zh) * | 2016-10-25 | 2017-04-26 | 雷飏 | 虚拟钥匙方法及应用该方法的装置、后台系统、用户终端 |
| TWI743860B (zh) * | 2020-06-30 | 2021-10-21 | 瑞昱半導體股份有限公司 | 通訊裝置以及網路管理方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103108245A (zh) | 2013-05-15 |
| CN103108245B (zh) | 2016-09-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN100539747C (zh) | 认证及检验sms通信的方法 | |
| CN109962784B (zh) | 一种基于数字信封多证书的数据加解密及恢复方法 | |
| CN107248075B (zh) | 一种实现智能密钥设备双向认证和交易的方法及装置 | |
| CN101127604B (zh) | 信息安全传输方法和系统 | |
| WO2013071858A1 (zh) | 一种智能电视支付密钥系统以及基于智能电视的支付方法 | |
| CN102857479B (zh) | 网络通讯的加密方法和系统 | |
| US20020038420A1 (en) | Method for efficient public key based certification for mobile and desktop environments | |
| CN101393628B (zh) | 一种新型的网上安全交易系统和方法 | |
| CN113630407A (zh) | 使用对称密码技术增强mqtt协议传输安全的方法和系统 | |
| CN106713279B (zh) | 一种视频终端身份认证系统 | |
| US9473308B2 (en) | Method and system for implementing digital signature in mobile operating system | |
| CN101631305B (zh) | 一种加密方法及系统 | |
| WO2009115017A1 (zh) | 网络认证服务系统和方法 | |
| CN106789004A (zh) | 一种高效安全的网络通信方法 | |
| CN105610773B (zh) | 一种电能表远程抄表的通讯加密方法 | |
| CN101640590A (zh) | 一种获取标识密码算法私钥的方法和密码中心 | |
| CN104125064B (zh) | 一种动态密码认证方法、客户端及认证系统 | |
| CN114650173A (zh) | 一种加密通讯方法及系统 | |
| CN116248290A (zh) | 身份认证的方法、装置及电子设备 | |
| US11070537B2 (en) | Stateless method for securing and authenticating a telecommunication | |
| WO2007071140A1 (en) | A method for transmitting data securely | |
| WO2015104567A1 (en) | Secure communication between a server and a client web browser | |
| CN118784347A (zh) | 一种电网信息加密与认证方法、系统、装置及介质 | |
| KR20110057376A (ko) | 인증서를 이동 단말기로 전송하는 방법 | |
| CN113922958B (zh) | 基于生物识别和sm2协同密码算法的密码保护方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 12849286 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205N DATED 13/10/2014) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 12849286 Country of ref document: EP Kind code of ref document: A1 |