WO2014032377A1 - 一种银行移动终端数据签名装置、方法及安全认证系统 - Google Patents

一种银行移动终端数据签名装置、方法及安全认证系统 Download PDF

Info

Publication number
WO2014032377A1
WO2014032377A1 PCT/CN2012/086480 CN2012086480W WO2014032377A1 WO 2014032377 A1 WO2014032377 A1 WO 2014032377A1 CN 2012086480 W CN2012086480 W CN 2012086480W WO 2014032377 A1 WO2014032377 A1 WO 2014032377A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile terminal
transaction data
bank
signature
data
Prior art date
Application number
PCT/CN2012/086480
Other languages
English (en)
French (fr)
Inventor
钱斌
伊劲松
王怡
杨珣
曾凯
林森
Original Assignee
中国工商银行股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国工商银行股份有限公司 filed Critical 中国工商银行股份有限公司
Publication of WO2014032377A1 publication Critical patent/WO2014032377A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • G06Q20/3227Aspects of commerce using mobile devices [M-devices] using secure elements embedded in M-devices

Definitions

  • the invention relates to the field of security authentication technology, in particular to a security authentication technology applied to a mobile terminal, in particular to a bank mobile terminal data signature device, a method and a security authentication system.
  • mobile terminals mobile phones and other mobile terminal applications are increasingly widespread, and mobile client banking applications for mobile terminals are also increasing.
  • domestic commercial banks have launched mobile client banks that support Apple's iOS system, Android system and Windows Phone system. It mainly includes mobile banking and mobile terminal online banking.
  • the security mechanism of the mobile client bank mainly includes: a payment account and a mobile phone number binding, using a transparent mobile phone number, a static password, an OTP (a short message dynamic password or a dynamic token)
  • the existing security mechanism has the following shortcomings: The customer mobile phone and the security authentication method have high coupling, once the mobile phone is lost, the binding mechanism and the SMS dynamic password. The security protection is weak; at present, the mobile terminal Trojan can monitor keyboard events and remote hijacking data, so static passwords also have certain risks.
  • USB Key widely used by online banking users of banks provides high security.
  • the data interfaces vary widely, and the existing USB Key cannot be promoted. Summary of the invention
  • the embodiment of the invention provides a bank mobile terminal data signature device
  • the bank mobile terminal data signature device comprises: an audio converter, configured to decode the received transaction data audio signal including the bank mobile terminal transaction data. Generating transaction data of the bank mobile terminal; the signing module is configured to sign transaction data of the bank mobile terminal generated by the audio converter to generate signature transaction data; wherein the signature generated by the signature module Transaction data Thereafter, the audio converter encodes the signature transaction data, generates a signature transaction data audio signal, and transmits the signature to the bank mobile terminal.
  • an embodiment of the present invention further provides a data signing method for a bank mobile terminal, where the method includes: collecting a transaction data audio signal including transaction data of a bank mobile terminal; decoding the transaction data audio signal to generate the Transaction data of the bank mobile terminal; signing the transaction data of the generated bank mobile terminal, generating signature transaction data; encoding the signature transaction data, generating a signature transaction data audio signal, and transmitting the signal to the bank mobile terminal.
  • an embodiment of the present invention further provides a bank mobile terminal security authentication system
  • the bank mobile terminal security authentication system includes: a bank mobile terminal, a bank mobile terminal data signature device, and a bank server; wherein, the bank mobile Receiving, by the terminal, transaction data input by the user, encoding the transaction information to generate a transaction data audio signal including the bank mobile terminal transaction data, and transmitting the transaction data audio signal to the bank mobile terminal data signature device;
  • the bank mobile terminal data signature device comprises: an audio converter, configured to decode the received transaction data audio signal including the bank mobile terminal transaction data, and generate transaction data of the bank mobile terminal; Signing transaction data of the bank mobile terminal generated by the protocol converter to generate signature transaction data; wherein, after the signature transaction data generated by the signature module, the audio converter performs the signature transaction data Encoding Generating a signature transaction data audio signal and transmitting it to a bank mobile terminal, wherein the bank mobile terminal decodes the received signature transaction data audio signal to generate signature transaction data, and sends the signature transaction data to the bank a server; the bank
  • the invention provides a security signature and authentication device applied to a mobile terminal.
  • the audio converter is connected with an audio port of a smart terminal such as a mobile phone or a tablet computer to realize signature verification in a transaction process.
  • the function which reduces the risk of user identity fraud, illegal interception of sensitive data and tampering of transaction information.
  • the voice interface standard of the mobile terminal is relatively uniform, and the wide application applicability of the USB Key is realized based on this.
  • FIG. 1 is a structural block diagram of a bank mobile terminal data signature device according to the present invention
  • FIG. 2 is a flow chart of a method for data signature of a bank mobile terminal according to the present invention
  • FIG. 3 is a structural block diagram of an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a bank mobile terminal security authentication system according to the present invention.
  • FIG. 5 is a flowchart of a working process of a bank mobile terminal security authentication system according to an embodiment of the present invention
  • FIG. 6 is a schematic diagram of a preferred scheme 1 of an audio converter according to an embodiment of the present invention
  • FIG. 7 is a structural block diagram of a USB Key in a first preferred embodiment of the present invention.
  • FIG. 8 is a schematic diagram of a second preferred embodiment of an audio converter according to an embodiment of the present invention.
  • USB Key 9 is a structural block diagram of a USB Key according to a second preferred embodiment of the present invention.
  • FIG. 10 is a structural block diagram of a USB Key according to a third preferred embodiment of the present invention. detailed description
  • the present invention discloses a bank mobile terminal data signature device
  • the bank mobile terminal data signature device includes: an audio converter 102, configured to receive the transaction data audio including the bank mobile terminal transaction data. The signal is decoded to generate the number of transactions of the bank mobile terminal.
  • the audio converter 102 has an audio connector 101, and the audio converter 102 realizes connection with the bank mobile terminal through the audio connector 101;
  • the signature module 103 is configured to sign the transaction data of the bank mobile terminal generated by the audio converter, and generate The signature transaction data; wherein, after the signature transaction data generated by the signature module, the audio converter encodes the signature transaction data, generates a signature transaction data audio signal, and sends the signal to the bank mobile terminal through the audio connector.
  • the bank mobile terminal data signature device of the present invention further includes: a battery compartment for providing power to the signature module 103, a Micro USB interface, and an audio converter 102 connected to the signature module 103 via a Micro USB interface, and further, the signature in the present invention Module 103 can be a USB Key.
  • the present invention discloses a data signing method for a bank mobile terminal.
  • FIG. 2 a flowchart of a data signing method for a bank mobile terminal is disclosed. The steps include:
  • Step S101 Collect a transaction data audio signal including transaction data of the bank mobile terminal; and in step S102, decode the transaction data audio signal to generate transaction data of the bank mobile terminal;
  • Step S103 Sign the generated transaction data of the bank mobile terminal to generate signature transaction data
  • Step 104 Encode the signature transaction data, generate a signature transaction data audio signal, and send the signal to the bank mobile terminal.
  • FIG. 3 is a structural block diagram of an embodiment of the present invention.
  • the bank mobile terminal data signature device is composed of a USB Key 21, an audio converter 22, and a battery compartment 23.
  • the audio converter 22 includes an audio connector 24, an audio converter 25, and a MicroUSB connector 26.
  • the USB Key 21 in the embodiment of the present invention implements a signature authentication function for transaction data; and can be separately connected to a PC through a standard USB connector for signature authentication of an online bank.
  • the audio converter 22 realizes the connection between the USB Key and the mobile terminal, transmits the client signature plaintext and ciphertext, and provides conversion of audio and USB protocols;
  • the battery compartment 23 supplies power to the USB Key.
  • the audio connector 24 is a 3.5mm or 2.5mm audio connector, and is connected to an audio port of the mobile terminal to transmit audio data;
  • the protocol converter 25 implements the conversion of transaction data between audio and USB protocols; and the HOST (master device) function of the USB.
  • the MicroUSB connector 26 is a standard MicroUSB interface and is connected to the USBKey.
  • the bank mobile terminal data signature device of the invention realizes a two-way communication mode.
  • the bank mobile terminal transmits the signed plaintext data to the USB Key 21 through the audio converter 22, and after the digital signature is completed inside the USB Key 21, the USB Key 21 transmits the signed data back to the mobile terminal through the audio converter 22. .
  • the invention also discloses a bank mobile terminal security authentication system, the system comprising: a bank mobile terminal, a bank mobile terminal data signature device and a bank server; wherein, the bank mobile terminal receives the transaction data input by the user, and encodes the transaction information Generating a transaction data audio signal including bank mobile terminal transaction data;
  • the bank mobile terminal data signature device comprises: an audio connector for collecting transaction data audio signals including bank mobile terminal transaction data; and a protocol converter for using transaction data
  • the audio signal is decoded to generate transaction data of the bank mobile terminal;
  • the signature module is configured to sign the transaction data of the bank mobile terminal generated by the protocol converter to generate signature transaction data; and after the signature transaction data generated by the signature module,
  • the protocol converter encodes the signature transaction data, generates a signature transaction data audio signal and transmits it to the bank mobile terminal through the audio connector, and the bank mobile terminal decodes the received signature transaction data audio signal to generate Name transaction data, transaction data signature will be sent to the bank server; the bank server to generate results based on security authentication signature transaction data
  • FIG. 4 it is a schematic diagram of an embodiment of a bank mobile terminal security authentication system according to the present invention, a mobile terminal 401, a U shield 403, and a bank server 402.
  • a U shield is used to implement the signature module of the present invention.
  • the signature function, U shield 403 is connected to the mobile terminal 401 via an audio converter 404.
  • the mobile terminal 401 is a smart terminal such as a mobile phone or a tablet computer, and the mobile terminal 401 is installed with a mobile banking client to interact with the client.
  • the bank server 402 verifies the customer signature data and provides financial services to the customer.
  • the steps include:
  • Step S01 The client inputs transaction information at the mobile banking transaction interface of the mobile terminal 401;
  • Step S02 The mobile terminal 401 performs audio encoding on the digital signal, and transmits the audio signal through the audio converter 404 connected to the left and right channels of the mobile terminal 401.
  • U shield 403 To U shield 403;
  • Step S03 After the audio converter 404 performs audio decoding on the received data, the information to be signed is transmitted to the U shield 403, and the transaction element is displayed on the LCD screen of the U shield 403 to be confirmed by the user;
  • Step S04 After the user confirms, U shield 403 signs the data
  • Step S05 U shield 403 is audio encoded by audio converter 404 and uploaded to mobile terminal 401;
  • Step S06 The mobile terminal 401 receives the client signature information, and performs audio decoding to generate signature data.
  • Step S07 The mobile terminal 401 sends the signature data to the bank server 402.
  • Step S08 Perform security authentication on the signature data at the bank server 402 to generate a security authentication result
  • Step S09 Return the generated security authentication result to the mobile terminal for subsequent transaction processing.
  • the audio converter of the invention not only has the functions of connecting devices, transmitting data, and converting protocols, but also integrates the battery compartment to supply power to the USB Key.
  • the USB Key that is currently used by bank customers does not require any modification or upgrade. It can be connected to the mobile terminal through the audio adapter for normal use, ensuring compatibility.
  • FIG. 6 is a schematic diagram of a first preferred embodiment of an audio converter according to an embodiment of the present invention.
  • the battery compartment 501 is integrated on the audio adapter and is equipped with a dry battery or a lithium battery. Audio conversion in this embodiment
  • the device is combined with the U shield to form an audio U shield.
  • FIG. 7 it is a structural block diagram of the audio U shield in the preferred scheme 1 of the embodiment of the present invention.
  • the battery compartment 231 is integrated in the audio adapter 22, is connected to the protocol converter 25 and the MicroUSB connector 26, and supplies power to the USB Key through the MicroUSB connector 26.
  • the audio adapter is integrated with the battery compartment and has a charging function.
  • the audio adapter not only has the function of connecting devices, transmitting data, and converting protocols, but also integrates the battery compartment to power the USB Key. It also charges the rechargeable battery in the battery compartment, improving the battery's battery life.
  • the USB Key that is currently used by bank customers does not require any modification or upgrade. It can be connected to the mobile terminal through an audio adapter for normal use, improving compatibility.
  • FIG. 8 is a schematic diagram of a second preferred embodiment of an audio converter according to an embodiment of the present invention.
  • the battery compartment is integrated on the audio adapter and is equipped with a rechargeable battery.
  • the standard USB connector 801 of the audio converter can be connected to the computer to charge the rechargeable battery in the battery compartment 501.
  • FIG. 9 is a structural block diagram of an audio U shield according to a second preferred embodiment of the present invention.
  • the battery compartment 232 is integrated in the audio converter 22, is connected to the protocol converter 25 and the MicroUSB connector 26, and supplies power to the USB Key through the MicroUSB connector 26.
  • USB Charging Connector 27 Use the standard USB connector to connect to the battery compartment 232 to charge the battery in the battery compartment when connected to the computer's USB port.
  • Preferred solution three USB Key integrated battery compartment.
  • USB Key integrates the battery compartment, and the audio adapter acts only as an audio data conversion and transmission channel. Can be used as a new USB Key design. Further enhance the function of the USB Key itself.
  • FIG. 10 it is a schematic structural diagram of an audio U shield of the third scheme.
  • the battery compartment 233 is integrated into the USB Key 21 and is equipped with a dry battery to power the USB Key. Further, the battery compartment 233 is equipped with a rechargeable lithium battery, and charges the battery in the battery compartment 233 when the USB Key is connected to the computer via a standard USB connector.
  • the audio converter provided by the example of the present invention supports an existing USB Key or a new USB Key to access each mobile terminal in an active manner.
  • USB Key digitally signs the data to complete two-way authentication. Thereby reducing the risk of user identity fraud, illegal interception of sensitive data and tampering of transaction information.
  • the mobile terminal voice interface standard is relatively unified, and based on this, the existing USB Key is widely used.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Telephone Function (AREA)

Abstract

本发明公开了一种银行移动终端数据签名装置、方法及安全认证系统,其中,银行移动终端数据签名装置包括:音频转换器,用于对接收到的包含有银行移动终端交易数据的交易数据音频信号进行解码,生成银行移动终端的交易数据;签名模块,用于对协议转换器生成的银行移动终端的交易数据进行签名,生成签名交易数据;其中,签名模块生成的签名交易数据后,音频转换器对签名交易数据进行编码,生成签名交易数据音频信号,并发送到银行移动终端。

Description

一种银行移动终端数据签名装置、 方法及安全认证系统 技术领域
本发明关于安全认证技术领域, 特别是关于应用于移动终端的安全认证 技术, 具体的讲是一种银行移动终端数据签名装置、 方法及安全认证系统。 背景技术
目前, 手机、 平板电脑等移动终端应用日益广泛, 应用于移动终端的移 动客户端银行应用也日益增多, 国内各商业银行先后推出支持苹果 iOS系 统、 Android系统和 Windows Phone系统的移动客户端银行, 主要包括手机 银行和移动终端网银。
现有技术中, 移动客户端银行的安全机制主要包括: 支付账户和手机号 绑定、 使用透传手机号、 静态密码、 OTP (短信动态密码或动态令牌
TOKEN) 等, 但现有的移动客户端银行的安全机制总体安全状况不够完 善, 现有安全机制有以下不足: 客户手机与安全认证方式耦合性高, 一旦手 机丢失, 绑定机制和短信动态密码安全防护较弱; 目前移动终端木马可以做 到监听键盘事件和远程劫持数据, 因此静态密码也存在一定风险。
与之相对的, 目前银行网上银行用户广泛使用的 USB Key提供了较高 的安全性。 但是对于智能终端, 不同厂商, 甚至同一厂商不同型号的智能终 端的数据接口千差万别, 无法推广使用现有的 USB Key。 发明内容
本发明实施例提供了一种银行移动终端数据签名装置, 所述的银行移动 终端数据签名装置包括: 音频转换器, 用于对接收到的包含有银行移动终端 交易数据的交易数据音频信号进行解码, 生成银行移动终端的交易数据; 所 述的签名模块, 用于对所述的音频转换器生成的银行移动终端的交易数据进 行签名, 生成签名交易数据; 其中, 所述的签名模块生成的签名交易数据 后, 所述的音频转换器对所述的签名交易数据进行编码, 生成签名交易数据 音频信号, 并发送到银行移动终端。
同时本发明实施例还提供了一种银行移动终端数据签名方法, 所述的方 法包括: 采集包含银行移动终端交易数据的交易数据音频信号; 对所述的交 易数据音频信号进行解码, 生成所述的银行移动终端的交易数据; 对生成的 银行移动终端的交易数据进行签名, 生成签名交易数据; 对所述的签名交易 数据进行编码, 生成签名交易数据音频信号, 并发送到银行移动终端。
此外, 本发明实施例还提供了一种银行移动终端安全认证系统, 所述的 银行移动终端安全认证系统包括: 银行移动终端、 银行移动终端数据签名装 置以及银行服务器; 其中, 所述的银行移动终端, 接收用户输入的交易数 据, 将所述交易信息编码生成包含有银行移动终端交易数据的交易数据音频 信号, 并将所述交易数据音频信号发送到所述银行移动终端数据签名装置; 所述的银行移动终端数据签名装置包括: 音频转换器, 用于对接收到的包含 有银行移动终端交易数据的交易数据音频信号进行解码, 生成银行移动终端 的交易数据; 所述的签名模块, 用于对所述的协议转换器生成的银行移动终 端的交易数据进行签名, 生成签名交易数据; 其中, 所述的签名模块生成的 签名交易数据后, 所述的音频转换器对所述的签名交易数据进行编码, 生成 签名交易数据音频信号, 并发送到银行移动终端, 所述的银行移动终端将接 收到所述的签名交易数据音频信号解码生成签名交易数据, 将所述的签名交 易数据发送到所述的银行服务器; 所述的银行服务器, 根据接收到的签名交 易数据生成安全认证结果。
本发明提出一种应用于移动终端的安全签名及认证装置, 当客户在移动 终端银行进行交易时, 通过音频转换器与手机、 平板电脑等智能终端的音频 口连接, 实现交易过程中的签名认证功能, 从而降低用户身份冒用、 敏感数 据非法截持和交易信息被篡改的风险。 移动终端语音接口标准相对统一, 以 此为基础实现 USB Key广泛的应用适用性。 为让本发明的上述和其他目的、 特征和优点能更明显易懂, 下文特举较 佳实施例, 并配合所附图式, 作详细说明如下。 附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见地, 下面 描述中的附图仅仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明公开了一种银行移动终端数据签名装置的结构框图; 图 2为本发明公开银行移动终端数据签名方法流程图;
图 3为本发明一实施例的结构框图;
图 4为本发明一种银行移动终端安全认证系统示意图;
图 5为本发明实施例中银行移动终端安全认证系统的工作流程图; 图 6为本发明实施例中音频转换器的优选方案一的示意图;
图 7为本发明实施例的优选方案一中 USB Key的结构框图;
图 8为本发明实施例中音频转换器的优选方案二的示意图;
图 9为本发明实施例的优选方案二的 USB Key的结构框图;
图 10为本发明实施例的优选方案三的 USB Key的结构框图。 具体实施方式
下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进行 清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而 不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有做 出创造性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
如图 1所示, 本发明公开了一种银行移动终端数据签名装置, 该银行移 动终端数据签名装置包括: 音频转换器 102, 用于对接收到的包含有银行移 动终端交易数据的交易数据音频信号进行解码, 生成银行移动终端的交易数 据; 音频转换器 102具有音频接头 101, 音频转换器 102通过音频接头 101 实现与银行移动终端的的连接; 签名模块 103, 用于对音频转换器生成的银 行移动终端的交易数据进行签名, 生成签名交易数据; 其中, 签名模块生成 的签名交易数据后, 音频转换器对签名交易数据进行编码, 生成签名交易数 据音频信号, 并通过音频接头发送到银行移动终端。
本发明的银行移动终端数据签名装置还包括: 电池仓, 用于为签名模块 103提供电能, Micro USB接口, 音频转换器 102通过 Micro USB接口与签 名模块 103相连接, 此外, 本发明中的签名模块 103可以为 USB Key。
同时, 本发明公开了一种银行移动终端数据签名方法, 如图 2所示, 为 本发明公开银行移动终端数据签名方法流程图, 歩骤包括:
歩骤 S101 , 采集包含银行移动终端交易数据的交易数据音频信号; 歩骤 S102, 对交易数据音频信号进行解码, 生成银行移动终端的交易 数据;
歩骤 S103 , 对生成的银行移动终端的交易数据进行签名, 生成签名交 易数据;
歩骤 104, 对签名交易数据进行编码, 生成签名交易数据音频信号, 并 发送到银行移动终端。
结合具体实施例对本发明做详细说明如下:
如图 3所示, 为本发明一实施例的结构框图。 本实施例中银行移动终端 数据签名装置由 USB Key 21、 音频转换器 22、 电池仓 23构成。 其中音频 转换器 22包括音频接头 24、 音频转换器 25、 MicroUSB接头 26。
本发明实施例中的 USB Key 21实现对交易数据的签名认证功能; 可通 过标准 USB接头单独与 PC连接应用于网上银行的签名认证。
音频转换器 22实现 USB Key和移动终端的连接, 传输客户签名明文和 密文, 并提供音频和 USB协议的转换;
电池仓 23向 USB Key供电。 本发明实施例中, 音频接头 24为 3.5mm或 2.5mm音频接头, 与移动终 端的音频口连接, 传输音频数据;
协议转换器 25实现交易数据在音频和 USB协议之间的转换; 以及 USB的 HOST (主设备) 功能。
本发明中 MicroUSB接头 26为标准 MicroUSB接口, 与 USBKey连 接。
本发明银行移动终端数据签名装置实现双向通讯方式。 在数字签名交易 中, 银行移动终端将签名明文数据通过音频转换器 22传入 USB Key 21, 在 USB Key 21内部完成数字签名后, USB Key 21将签名后数据通过音频转换 器 22传回移动终端。
本发明同时公开了一种银行移动终端安全认证系统, 该系统包括: 银行 移动终端、 银行移动终端数据签名装置以及银行服务器; 其中, 银行移动终 端, 接收用户输入的交易数据, 并将交易信息编码生成包含有银行移动终端 交易数据的交易数据音频信号; 银行移动终端数据签名装置包括: 音频接 头, 用于采集包含有银行移动终端交易数据的交易数据音频信号; 协议转换 器, 用于对交易数据音频信号进行解码, 生成银行移动终端的交易数据; 所 述的签名模块, 用于对协议转换器生成的银行移动终端的交易数据进行签 名, 生成签名交易数据; 签名模块生成的签名交易数据后, 协议转换器对签 名交易数据进行编码, 生成签名交易数据音频信号并通过音频接头发送到银 行移动终端, 银行移动终端将接收到签名交易数据音频信号解码生成签名交 易数据, 将签名交易数据发送到银行服务器; 银行服务器, 根据接收到的签 名交易数据生成安全认证结果。
如图 4所示, 为本发明一种银行移动终端安全认证系统一实施方式的 示意图, 移动终端 401、 U盾 403和银行服务器 402, 本实施例中, 采用 U 盾实现本发明中签名模块的签名功能, U盾 403通过音频转换器 404与移动 终端 401相连接。 本实施例中移动终端 401为手机、 平板电脑等智能终端, 移动终端 401 安装有手机银行客户端, 与客户进行交互。 银行服务器 402验证客户签名数 据并为客户提供金融服务。
如图 5所示, 为本实施例的处理流程图, 歩骤包括:
歩骤 S01 : 客户在移动终端 401的手机银行交易界面输入交易信息; 歩骤 S02: 移动终端 401将数字信号进行音频编码, 并通过与移动终端 401的左右声道相连接的音频转换器 404传送到 U盾 403 ;
歩骤 S03 : 音频转换器 404对接收到的数据进行音频解码后, 将待签名 信息传至 U盾 403中, 并在 U盾 403的液晶屏显示交易要素待用户进行确 认;
歩骤 S04: 用户确认后, U盾 403对数据进行签名;
歩骤 S05 : U盾 403通过音频转换器 404进行音频编码, 上传至移动终 端 401 ;
歩骤 S06: 移动终端 401接收客户签名信息, 并进行音频解码, 生成签 名数据;
歩骤 S07: 移动终端 401将签名数据发送至银行服务器 402;
歩骤 S08: 在银行服务器 402对签名数据进行安全认证, 生成安全认证 结果;
歩骤 S09: 将生成的安全认证结果返回到移动终端, 进行后续交易处 理。
本发明的音频转换器不仅具有连接设备、 传输数据、 转换协议的功能, 还集成了电池仓为 USB Key供电。 当前银行客户一般使用的 USB Key本身 不需要进行任何改造和升级, 就可以通过音频转接器连接到移动终端上正常 使用, 保证了兼容性。
如图 6所示, 为本发明实施例中音频转换器的优选方案一的示意图。 电 池仓 501集成在音频转接器上, 搭载干电池或锂电池。 本实施例中音频转换 器与 U盾结合构成音频 U盾, 如图 7所示, 为本发明实施例的优选方案一 中音频 U盾的结构框图。
电池仓 231集成在音频转接器 22中, 与协议转换器 25和 MicroUSB接 头 26连接, 并通过 MicroUSB接头 26向 USB Key供电。
优选方案二: 音频转接器与电池仓集成, 并具备充电功能。
音频转接器不仅具有连接设备、 传输数据、 转换协议的功能, 还集成电 池仓为 USB Key供电。 并可为电池仓中的充电电池充电, 提高了电池的续 航能力。 当前银行客户一般使用的 USB Key本身不需要进行任何改造和升 级, 可以通过音频转接器连接到移动终端上正常使用, 提高兼容性。
如图 8所示, 为本发明实施例中音频转换器的优选方案二的示意图。 电池仓集成在音频转接器上, 搭载充电电池, 音频转换器的标准 USB 接头 801可以连接电脑, 为电池仓 501中的充电电池充电。
如图 9所示, 为本发明实施例的优选方案二的音频 U盾的结构框图。 电池仓 232集成在音频转换器 22中, 与协议转换器 25和 MicroUSB接 头 26连接, 并通过 MicroUSB接头 26向 USB Key供电。 USB充电接头 27 使用标准 USB接头, 与电池仓 232连接, 可在与电脑 USB接口连接时, 对 电池仓中电池充电。
优选方案三: USB Key集成电池仓。
USB Key集成电池仓, 音频转接器仅作为音频数据转换和传输通道。 可作为新型 USB Key的设计方案。 进一歩强化 USB Key自身的功能。
如图 10所示, 为优选方案三的音频 U盾的结构示意图。
电池仓 233集成在 USB Key 21中, 搭载干电池为 USB Key供电。 进一 歩的, 电池仓 233搭载可充电锂电池, 在 USB Key通过标准 USB接头与电 脑连接时, 给电池仓 233中电池充电。
本发明实例提供的音频转换器支持现有 USB Key或新增 USB Key以有 源方式接入各移动终端。 当客户在移动终端银行进行交易时, 通过 USB Key对数据进行数字签名, 完成双向认证。 从而降低用户身份冒用、 敏感数 据非法截持和交易信息被篡改的风险。 移动终端语音接口标准相对统一, 以 此为基础实现现有的 USB Key的广泛应用。
本发明中应用了具体实施例对本发明的原理及实施方式进行了阐述, 以 上实施例的说明只是用于帮助理解本发明的方法及其核心思想; 同时, 对于 本领域的一般技术人员, 依据本发明的思想, 在具体实施方式及应用范围上 均会有改变之处, 综上所述, 本说明书内容不应理解为对本发明的限制。

Claims

权利要求书
1、 一种银行移动终端数据签名装置, 其特征在于, 所述的银行移动终 端数据签名装置包括:
音频转换器, 用于对接收到的包含有银行移动终端交易数据的交易数据 音频信号进行解码, 生成银行移动终端的交易数据;
签名模块, 用于对所述的音频转换器生成的银行移动终端的交易数据进 行签名, 生成签名交易数据; 其中,
所述的签名模块生成的签名交易数据后, 所述的音频转换器对所述的签 名交易数据进行编码, 生成签名交易数据音频信号, 并发送到银行移动终 端。
2、 如权利要求 1所述的银行移动终端数据签名装置, 其特征在于, 所 述的银行移动终端数据签名装置还包括:
电池仓, 用于为所述签名模块提供电能。
3、 如权利要求 1所述的银行移动终端数据签名装置, 其特征在于, 所 述的音频转换器具有音频接头。
4、 如权利要求 1所述的银行移动终端数据签名装置, 其特征在于, 所 述的签名模块为 USB Key。
5、 如权利要求 4所述的银行移动终端数据签名装置, 其特征在于, 所 述的音频转换器还具有 Micro USB接口, 所述的音频转换器通过所述 Micro USB接口与 USB Key相连接。
6、 如权利要求 2所述的银行移动终端数据签名装置, 其特征在于, 所 述的电池仓搭载干电池或锂电池。
7、 如权利要求 1所述的银行移动终端数据签名装置, 其特征在于, 所 述的银行移动终端包括: 安装有移动客户端银行的手机及安装有移动客户端 银行平板电脑。
8、 一种银行移动终端数据签名方法, 其特征在于, 所述的方法包括: 采集包含银行移动终端交易数据的交易数据音频信号;
对所述的交易数据音频信号进行解码, 生成银行移动终端的交易数据; 对生成的银行移动终端的交易数据进行签名, 生成签名交易数据; 对所述的签名交易数据进行编码, 生成签名交易数据音频信号, 并发送 到银行移动终端。
9、 一种银行移动终端安全认证系统, 其特征在于, 所述的系统包括: 银行移动终端、 银行移动终端数据签名装置以及银行服务器; 其中,
所述的银行移动终端, 接收用户输入的交易数据, 将所述交易信息编码 生成包含有银行移动终端交易数据的交易数据音频信号, 并将所述交易数据 音频信号发送到所述银行移动终端数据签名装置;
所述的银行移动终端数据签名装置包括:
音频转换器, 用于对接收到的包含有银行移动终端交易数据的交易数据 音频信号进行解码, 生成银行移动终端的交易数据;
所述的签名模块, 用于对所述的音频转换器生成的银行移动终端的交易 数据进行签名, 生成签名交易数据; 其中,
所述的签名模块生成的签名交易数据后, 所述的音频转换器对所述的签 名交易数据进行编码, 生成签名交易数据音频信号, 并发送到银行移动终 端, 所述的银行移动终端将接收到所述的签名交易数据音频信号解码生成签 名交易数据, 将所述的签名交易数据发送到所述的银行服务器;
所述的银行服务器, 根据接收到的签名交易数据生成安全认证结果。
10、 如权利要求 9所述的银行移动终端安全认证系统, 其特征在于, 所 述的银行移动终端包括: 安装有移动客户端银行的手机及安装有移动客户端 银行平板电脑。
PCT/CN2012/086480 2012-09-03 2012-12-13 一种银行移动终端数据签名装置、方法及安全认证系统 WO2014032377A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2012103222512A CN102903044A (zh) 2012-09-03 2012-09-03 一种银行移动终端数据签名装置、方法及安全认证系统
CN201210322251.2 2012-09-03

Publications (1)

Publication Number Publication Date
WO2014032377A1 true WO2014032377A1 (zh) 2014-03-06

Family

ID=47575262

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/086480 WO2014032377A1 (zh) 2012-09-03 2012-12-13 一种银行移动终端数据签名装置、方法及安全认证系统

Country Status (2)

Country Link
CN (1) CN102903044A (zh)
WO (1) WO2014032377A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116029735A (zh) * 2023-03-27 2023-04-28 北京恩威特科技有限公司 一种网银账户的安全管理方法与系统

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103902496B (zh) * 2012-12-26 2017-09-08 中国电信股份有限公司 Usb key协议转换设备和方法
CN103258269A (zh) * 2013-04-09 2013-08-21 深圳市亚略特生物识别科技有限公司 用于移动设备的电子支付装置
CN103346889A (zh) * 2013-07-10 2013-10-09 中国建设银行股份有限公司 数字证书认证方法、系统、客户端和数字证书载体
GB201313167D0 (en) * 2013-07-24 2013-09-04 Ibm Automatic rotation of display contents of a handheld companion device rigidly attached to a handheld mobile device
CN103747012B (zh) * 2013-08-01 2017-12-19 戴林巧 网络交易的安全验证方法、装置及系统
CN103839018A (zh) * 2014-01-17 2014-06-04 青岛丽雯互联信息有限公司 基于音频输入输出接口的数据传递方法与装置
CN104836663A (zh) * 2015-03-25 2015-08-12 恒宝股份有限公司 一种基于usbkey的数据交互方法及系统
CN104881621B (zh) * 2015-05-28 2018-08-17 天地融科技股份有限公司 用于电子密钥设备的音频信号转接器及电子密钥设备
CN105260645A (zh) * 2015-10-09 2016-01-20 北京大明五洲科技有限公司 安全认证系统

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050182710A1 (en) * 2002-03-13 2005-08-18 Beamtrust A/S Method of processing an electronic payment cheque
CN102255730A (zh) * 2011-07-11 2011-11-23 吴沙林 数字证书安全锁装置、数字证书认证系统及方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8543496B2 (en) * 2007-04-27 2013-09-24 American Express Travel Related Services Company, Inc. User experience on mobile phone
CN102098159A (zh) * 2010-07-28 2011-06-15 胡旭光 一种用于手机的密钥装置和方法

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050182710A1 (en) * 2002-03-13 2005-08-18 Beamtrust A/S Method of processing an electronic payment cheque
CN102255730A (zh) * 2011-07-11 2011-11-23 吴沙林 数字证书安全锁装置、数字证书认证系统及方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116029735A (zh) * 2023-03-27 2023-04-28 北京恩威特科技有限公司 一种网银账户的安全管理方法与系统

Also Published As

Publication number Publication date
CN102903044A (zh) 2013-01-30

Similar Documents

Publication Publication Date Title
WO2014032377A1 (zh) 一种银行移动终端数据签名装置、方法及安全认证系统
CN101465019B (zh) 实现网络认证的方法及系统
CN103793815A (zh) 适用于银行卡和行业卡的移动智能终端收单系统及方法
WO2013181885A1 (zh) 一种移动终端及其查询智能卡信息的方法和系统
WO2013023499A1 (zh) 手机支付安全控制方法及系统
CN102255730A (zh) 数字证书安全锁装置、数字证书认证系统及方法
CN103984911B (zh) 密码键盘、支付系统及其支付方法
CN102855561A (zh) 一种基于安全芯片和声音载波通信的手机支付器及支付方法
WO2010057405A1 (zh) 利用短信息进行身份认证的方法
CN104144058A (zh) 一种基于声波配对的信息验证方法
CN101790166A (zh) 基于手机智能卡的数字签名方法
CN102831738A (zh) 移动刷卡器,移动支付系统和方法
JP2016103260A (ja) Nfc認証カードを用いた認証方法
WO2017020468A1 (zh) 应用于复合型智能卡设备的数据交互方法和装置
CN203278851U (zh) 一种带有无线通信功能的加密认证设备
WO2015003518A1 (zh) 一种智能电源及利用该智能电源实现移动支付的方法
CN103051640A (zh) 一种基于蓝牙的网银安全设备及其数据通讯方法
CN103530768A (zh) 移动通信支付系统及其用于费用支付的方法
KR101300764B1 (ko) 데이터 통신망과 음성 통신망을 이용한 결제/인증 토큰 발급 방법
CN102685704B (zh) 手机交易方法及系统
CN203070301U (zh) 一种银行移动终端数据签名装置及安全认证系统
CN202904766U (zh) 移动刷卡器,移动支付系统
CN103679441A (zh) 信息交互系统及磁场收发装置
CN207869159U (zh) 移动装置以及用户识别模块卡
CN203387524U (zh) 一种多接口多功能的智能密码钥匙装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12883944

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12883944

Country of ref document: EP

Kind code of ref document: A1