WO2014063546A1 - 处理来自移动终端的数据访问请求的设备和方法 - Google Patents
处理来自移动终端的数据访问请求的设备和方法 Download PDFInfo
- Publication number
- WO2014063546A1 WO2014063546A1 PCT/CN2013/083846 CN2013083846W WO2014063546A1 WO 2014063546 A1 WO2014063546 A1 WO 2014063546A1 CN 2013083846 W CN2013083846 W CN 2013083846W WO 2014063546 A1 WO2014063546 A1 WO 2014063546A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- request
- mobile terminal
- data access
- processing
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4012—Verifying personal identification numbers [PIN]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/42—Confirmation, e.g. check or permission by the legal debtor of payment
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
Definitions
- the P0S terminal can initiate an interaction and debit operation to the electronic cash application at will; in the mobile terminal environment, since the mobile terminal is an untrusted entity, if it is still accepted according to the current electronic cash application The interaction of the process will inevitably lead to the electronic cash application being accessed by the illegal client and deducting the money, which will bring the corresponding property loss to the cardholder.
- the offline transaction deduction voucher information is generated and saved on the P0S terminal for later clearing, and the same, if the offline transaction deduction voucher information is stored in the mobile
- the terminal will also be illegally tampered with and stolen.
- the present invention provides a method of processing a data access request from a mobile terminal in a data storage device, comprising: receiving a request for data access to the data storage device; The initiator of the request submits an identity authentication request; verifying the identity authentication content input by the initiator in response to the identity authentication request; reflecting the result of the verification by changing the state of the one-time session identifier, wherein the one-time session identifier
- the status is in a state of failing verification each time a processing data access request is received; if the verification is passed, the modification request for the data is approved and executed, and the modified content is recorded in the status information table; and the encryption is issued at the mobile terminal
- the encrypted service request is responded only when the encrypted service request contains information corresponding to the record in the status information table.
- the method of processing a data access request from a mobile terminal wherein the data is electronic cash account data, the modification request is caused by a transaction of the electronic cash account, and the value of the data modification is an authorization of the transaction
- the amount information, the status information table is an offline transaction completion status information table, which includes at least an application transaction counter and the authorized amount.
- the method for processing a data access request from a mobile terminal further includes performing encryption and message verification code calculation on the transaction data information in which the matching record exists in the status information table, and transmitting the calculation result to the background system.
- the data storage device in the method of processing a data access request from a mobile terminal is an IC card.
- the data stored in the data storage device in the method of processing a data access request from a mobile terminal is electronic cash account data.
- the encryption algorithm used in the step of encrypting transaction data information in which the matching record exists in the state information table in the method for processing a data access request from the mobile terminal is a symmetric algorithm or an asymmetric algorithm, and the transaction data
- the information is the debit memo from the method for processing the data access request from the mobile terminal, and the encrypted message is also sent to the background for verification.
- the offline transaction completion status information table in the method of processing a data access request from a mobile terminal only supports the application itself to perform insertion and deletion operations.
- the step of processing the modified content into the status information table in the method for processing a data access request from the mobile terminal includes inserting the application transaction counter corresponding to the transaction and the authorized amount into the offline transaction. Complete the status information table.
- the present invention provides an apparatus for processing a data access request from a mobile terminal in a data storage device, comprising: a receiving device that receives a request for data access to the data storage device; and an identity authentication initiating device
- the originator of the request proposes an identity authentication request
- the verification device verifies the identity authentication content input by the initiator in response to the identity authentication request
- - the risk certificate result recording device reflects by changing the state of the one-time session identifier a result of the verification, wherein the status of the one-time session identifier is in a state of failing verification each time a processing data access request is received; modifying the device, if approved, approving and executing the modification request for the data, and Modify content record
- the encryption service request response means, when the mobile terminal issues an encryption service request, responding to the encryption service only when the encryption service request includes information corresponding to the record in the status information table request.
- the debit payment can be effectively prevented from being accessed by the malicious program without obtaining the authorization of the card holder, the offline transaction data of the non-book can be effectively prevented from being encrypted, and the electronic cash offline transaction can be effectively prevented.
- the data was illegally stolen and tampered with during the process of being sent to the background. From a broader perspective, the present invention provides more secure access to data in data storage devices.
- FIG. 1 shows the steps of a method of processing a data access request from a mobile terminal
- FIG. 2 shows an offline transaction completion status information table
- Fig. 3 shows the processing performed on the offline transaction completion status information table.
- an electronic computing device can include one or more processors that perform one or more particular functions.
- Electronic cash transactions can be viewed as a process of processing data in a data storage device.
- Electronic cash transactions under the contact interface the first can be forced to insert Cardperson offline personal identification number (PIN) verification.
- PIN personal identification number
- the mechanism On the mobile terminal, when the client interacts with the electronic cash, the mechanism will have the following functions: (1) authentication of the cardholder identity; (2) authentication of the client accessing the electronic cash application.
- the "Cardholder PIN Verification Pass” is introduced here.
- This flag is a one-time session flag, that is, the flag is reset to invalid each time an electronic cash application is selected.
- the card's electronic cash application will set the "cardholder PIN verification pass sign", which will be used in the electronic cash application to generate one of the basis for approval of the offline transaction ciphertext. .
- step S106 includes performing encryption, deleting the corresponding record from the status information table, and returning the encrypted result to the mobile terminal.
- the device in the data storage device that processes the data access request from the mobile terminal may include a receiving device, an identity authentication initiating device, a verifying device, and a verification result recording device.
- the mobile terminal accessing data in the data storage device includes a requesting device, a verification input device, a data access device, and a result receiving device.
- the requesting device issues a request for data access to the data storage device;
- the verification input device is for inputting the identity authentication content;
- the data access device accesses and modifies the data in the data storage device; and
- the result receiving device receives the modified data in the data storage device.
- a smart card equipped with electronic cash receives an electronic cash debit operation process after receiving an application ciphertext command.
- the electronic cash payment transaction is performed on the mobile terminal through the contact interface.
- the client decides to apply the corresponding transaction to the card according to the behavior analysis result of the card, the card is on the card.
- the electronic cash application After receiving the request, the electronic cash application performs the following processing: first, it is checked whether the cardholder PIN verification pass flag is set. If the result of the check is "No", then return directly without debit processing. If the result of the check is "Yes", then the authorized amount is deducted and the balance of the electronic cash is updated later.
- an offline transaction completion status information table is introduced here.
- the structure of the table is shown in Figure 2.
- the size of the table is not fixed and can be set according to actual needs. As a preferred mode, the size can be set to five. At the same time, the content of the field can also be expanded according to actual needs. This table is maintained by the application itself and is not readable or writable externally.
- the application transaction counter value and the authorized amount corresponding to the transaction are inserted into the table.
- the card When the card external entity requests the offline transaction data encryption service to the card electronic cash application, the card first determines whether the offline transaction belongs to the consumer transaction of the account after receiving the data, and the judgment base mainly includes the primary account and the issuing bank. Account information such as application data and electronic cash issuing bank authorization code. If the result of the judgment is "No”, then an error verification code is returned; if the result of the judgment is "Yes”, then it is judged whether there is a matching record. If the result of the judgment is "No”, then the error face code is returned. If the result of the judgment is "Yes”, then it is judged whether the authorized amount is the same.
- a secure transmission key system is also introduced to encrypt offline transaction data and message authentication code (MAC) calculation.
- the encryption algorithm used may be a symmetric algorithm or an asymmetric algorithm.
- the secure transmission key system includes at least the following keys: (1) an encryption key for offline transaction voucher data, and also calculates a corresponding MAC; (2) an externally provided transmission message encryption key; (3) external The provided transmission "3 ⁇ 4 text MAC calculation key.
- the transaction voucher data contains the content involved in the record in the status information table, thereby realizing the legality of requesting the encrypted content. Sexuality and uniqueness are certified.
- the electronic cash flow through the exhibition needs to provide the following secure operation interfaces: (1) offline transaction voucher data encryption and MAC calculation operation interface; (2) externally provided transmission message encryption interface; (3) externally provided transmission message MAC computing interface.
- the above security key system may be symmetric or ⁇ based asymmetric.
- this method can be implemented in hardware, firmware, software, or any combination thereof.
- devices can be in one or more application specific integrated circuits (AS ICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable Gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronics, or other device units designed to perform functions such as those described herein, or any combination thereof.
- AS ICs application specific integrated circuits
- DSPs digital signal processors
- DSPDs digital signal processing devices
- PLDs programmable logic devices
- FPGAs field programmable Gate arrays
- processors controllers, microcontrollers, microprocessors, electronics, or other device units designed to perform functions such as those described herein, or any combination thereof.
- the methods can be implemented with modules that perform the functions described herein or any combination thereof.
- any machine readable shield that tangibly embodying instructions can be used in implementing such methods.
- software or code may be stored in the memory and executed by the processing unit.
- the memory can be implemented in the processing unit and/or external to the processing unit.
- memory refers to any type of long-term, short-term, volatile, non-volatile, or other memory, and is not limited to any particular type of memory or the number of memories or types of storage media.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Storage Device Security (AREA)
Abstract
本发明提出了一种处理来自移动终端的数据访问请求的方法,包括:接收向数据存储装置发出的数据访问的请求;提出身份认证要求;验证身份认证内容;通过改变一次性会话标识的状态来反映验证的结果;如果通过验证则批准和执行对数据的修改请求,并将修改内容记录到状态信息表中;以及在移动终端发出加密服务请求时,仅在加密服务请求中含有和状态信息表中的记录相对应的信息时响应加密服务请求。通过使用本发明可以解决电子现金被恶意程序访问扣款等问题。
Description
处理来自移动终端的数据访问请求的设备和方法 技术领域
本发明总体上涉及信息处理技术, 尤其涉及关于 IC卡中的数据 的访问和处理的技术。
背景技术
随着 IC卡迁移进程的不断推进和移动支付业务的不断发展, 越 来越多的移动终端被置入了安全芯片。这些芯片包括但不限于智能 SD 卡、 SIM卡、 "苹果皮" 附件等。 而且这些移动终端装载了 PB0C电子 现金应用, 从而使用户享受到了快捷的支付体验。 但由于 PB0C规范 在定义时仅考虑了基于 P0S终端的传统交易受理环境, 认为 P0S终端 是可信的实体, 并没有考虑到有一天电子现金会被植入移动终端中, 并用于移动支付。
在传统的 P0S终端受理环境下, P0S终端可以随意向电子现金应 用发起交互并进行扣款操作; 而在移动终端环境下, 由于移动终端是 不可信的实体, 如果还按照当前电子现金应用的受理流程进行交互, 势必会导致电子现金应用被非法客户端访问并扣款, 给持卡人带来相 应的财产损失。同时按照电子现金脱机交易的定义,脱机交易完成后, 会生成脱机交易扣款凭证信息保存在 P0S终端上用于日后清算,同理, 如果该脱机交易扣款凭证信息存储在移动终端上也将被非法篡改和 窃取。
因此, 需要一种新的技术来解决电子现金被恶意程序访问扣款、 应用对非本账户的脱机交易数据进行加密处理以及电子现金脱机交
易数据在上送给后台的过程中被非法窃取和篡改等问题。 此外, 也希 望有一种技术来解决更广范围内的安全地访问数据存储装置中的数 据的问题。
发明内容
为了至少解决上述问题的一个方面, 本发明提出了一种在数据存 储装置中的处理来自移动终端的数据访问请求的方法, 包括: 接收向 所述数据存储装置发出的数据访问的请求; 向所述请求的发起者提出 身份认证要求; 验证所述发起者响应所述身份认证要求所输入的身份 认证内容; 通过改变一次性会话标识的状态来反映验证的结果, 其中 所述一次性会话标识的状态在每次接收到处理数据访问请求时处于 未通过验证的状态; 如果通过验证则批准和执行对所述数据的修改请 求, 并将修改内容记录到状态信息表中; 以及在移动终端发出加密服 务请求时, 仅在所述加密服务请求中含有和所述状态信息表中的记录 相对应的信息时响应所述加密服务请求。
所述的处理来自移动终端的数据访问请求的方法, 其中所述数据 是电子现金账户数据, 所述修改请求由所述电子现金账户的交易引 起, 所述数据修改的值是所述交易的授权金额, 所述状态信息表是脱 机交易完成状态信息表, 其至少包括应用交易计数器和所述授权金 额,
所述的处理来自移动终端的数据访问请求的方法中所述加密服 务请求中含有的和所述状态信息表中的记录相对应的信息包括: 账户 对应, 交易计数器值对应; 以及授权金额对应。
所述的处理来自移动终端的数据访问请求的方法还包括对在所 述状态信息表中存在匹配记录的交易数据信息进行加密和报文验证 代码计算, 并将计算结果发送给后台系统。
所述的处理来自移动终端的数据访问请求的方法中所述数据存 储装置是 IC卡。
所述的处理来自移动终端的数据访问请求的方法中所述移动终 端是手机或者平板电脑。
所述的处理来自移动终端的数据访问请求的方法中所述数据存 储装置中存储的数据是电子现金账户数据。
所述的处理来自移动终端的数据访问请求的方法中对在所述状 态信息表中存在匹配记录的交易数据信息进行加密的步骤所使用的 加密算法是对称算法或者非对称算法, 所述交易数据信息是扣款凭证 自 所述的处理来自移动终端的数据访问请求的方法中还将加密后 的报文发送给后台进行验证。
所述的处理来自移动终端的数据访问请求的方法中所述脱机交 易完成状态信息表仅仅支持应用自身进行插入和删除操作。
所述的处理来自移动终端的数据访问请求的方法中所述将修改 内容记录到状态信息表中的步骤包括将所述交易对应的应用交易计 数器只和所迷授权金额插入到所述脱机交易完成状态信息表中。
本发明提出了一种在数据存储装置中的处理来自移动终端的数 据访问请求的设备, 包括: 接收装置, 其接收向所述数据存储装置发 出的数据访问的请求; 身份认证发起装置, 其向所述请求的发起者提 出身份认证要求; 验证装置, 其验证所述发起者响应所述身份认证要 求所输入的身份认证内容; -险证结果记录装置, 通过改变一次性会话 标识的状态来反映验证的结果, 其中所述一次性会话标识的状态在每 次接收到处理数据访问请求时处于未通过验证的状态; 修改装置, 如 果通过验证则批准和执行对所述数据的修改请求, 并将修改内容记录
到状态信息表中; 以及加密服务请求响应装置, 在移动终端发出加密 服务请求时, 仅在所述加密服务请求中含有和所述状态信息表中的记 录相对应的信息时响应所述加密服务请求。
通过使用本发明, 可以有效防止在没有得到持卡人授权的情况下 被恶意程序访问扣款, 可以有效防止对非本账户的脱机交易数据进行 加密处理, 并且可以有效防止电子现金脱机交易数据在上送给后台的 过程中被非法窃取和篡改。 从更广范围内看, 本发明可以更安全地访 问数据存储装置中的数据。
附图说明
为便于理解, 下面参照附图通过非限定性例子来描述本发明的实 施例。 图中:
图 1示出了处理来自移动终端的数据访问请求的方法的步骤; 图 2示出了脱机交易完成状态信息表;
图 3示出了对脱机交易完成状态信息表进行的处理。
具体实施方式
除非另加具体说明, 正如从以下论述中也可以认识到的那样, 在 本说明书的通篇中, 利用诸如 "处理,, 、 "判断,, 之类术语的论述表 示使用诸如计算机或类似电子计算装置之类的特定设备的动作或过 程。 在本说明书的上下文中, 计算机或者类似电子计算装置能够操纵 或变换信号。 这些信号在计算机或类似电子计算装置的存储器、 寄存 器或者其它信息存储装置、 传输装置或者显示装置中通常表示为物理 电子或磁量。 例如, 电子计算装置可以包括执行一个或更多的特定功 能的一个或更多的处理器。
电子现金交易, 可以被视为处理在数据存储装置中的数据的过 程。 在接触式界面下进行电子现金交交易, 首先可以强制要求进行插
卡人脱机个人身份标识号码(PIN )验证。 在移动终端上, 当客户端 与电子现金交互时, 该机制将具有如下作用: ( 1 )对持卡人身份进 行认证; ( 2 )对访问电子现金应用的客户端进行认证。
为了实现上述安全机制,这里引入了 "持卡人 PIN验证通过标志", 该标志为一次性会话标志, 即每次选择电子现金应用后, 该标志都会 被重置为无效。 而一旦持卡人脱机 PIN验证成功后, 卡内电子现金应 用将置位 "持卡人 PIN验证通过标志" , 该标志将被用于电子现金应 用生成批准脱机交易密文的依据之一。
因此, 为了在数据存储装置中的处理来自移动终端的数据访问请 求, 可以实施以下步骤, 包括: 接收向数据存储装置发出的数据访问 的请求(S101 ) ; 向请求的发起者提出身份认证要求(S102 ) ; 验证 发起者响应所述身份认证要求所输入的身份认证内容(S103 ) ; 以及 通过改变一次性会话标识的状态来反映验证的结果(S104 ) 。 这里的 一次性会话标识的状态在每次接收到处理数据访问请求时处于未通 过验证的状态。 然后, 如果通过验证则批准和执行对所述数据的修改 请求, 并将修改内容记录到状态信息表中 (S105 ) ; 最后, 在移动终 端发出加密服务请求时, 仅在所述加密服务请求中含有和所述状态信 息表中的记录相对应的信息时响应所述加密服务请求(S106 ) 。 图 1 示出了上述步骤。 步骤 S106中的响应所述加密服务请求包括执行加 密、 从状态信息表中删除对应的记录以及将加密的结果返回给移动终 端。
相应的, 在数据存储装置中的处理来自移动终端的数据访问请求 的设备可以包括接收装置、 身份认证发起装置、 验证装置以及验证结 果记录装置。 接收装置接收向数据存储装置发出的数据访问的请求; 身份认证发起装置向请求的发起者提出身份认证要求; 验证装置验证
发起者响应身份认证要求所输入的身份认证内容; 验证结果记录装置 通过改变一次性会话标识的状态来反映验证的结果, 这里的一次性会 话标识的状态在每次接收到处理数据访问请求时处于未通过验证的 状态。
相应的, 访问在数据存储装置中的数据的移动终端包括请求装 置、 验证输入装置、 数据访问装置以及结果接收装置。 请求装置向数 据存储装置发出数据访问的请求; 验证输入装置用于输入身份认证内 容; 数据访问装置访问和修改数据存储装置中的数据; 结果接收装置 接收数据存储装置中的修改过后的数据。
在关于电子现金的应用中, 装有电子现金的智能卡片收到生成应 用密文命令后执行电子现金扣款操作流程。
引入持卡人脱机 PIN验证机制后, 在移动终端上, 通过接触式界 面进行电子现金支付交易, 当客户端根据自身的行为分析结果决定向 卡片请求相应的交易应用密文类型时, 卡片上电子现金应用收到该请 求后执行如下处理:首先是检查持卡人 PIN验证通过标志是否被置位。 如果检查的结果是 "否" , 那么则直接返回而不进行扣款处理。 如果 检查的结果是 "是" , 那么接下来扣除授权金额, 并且之后更新电子 现金的余额。
这里, 只有当持卡人 PIN验证通过后 (即持卡人 PIN验证通过标 志被置位) , 才允许对电子现金进行脱机扣款。
为了防止对非本账户的脱机交易数据进行加密处理, 这里引入了 脱机交易完成状态信息表。 在该实施例中, 上述方法中的扣除授权金 额和更新电子现金的余额这两个步骤之间还有一个设置脱机交易完 成状态信息表的步驟。该表的结构如图 2所示。该表的大小不是固定, 可以根据实际需要进行设置。 作为优选方式, 其大小可设定在 5个。
同时字段内容也可以根据实际需要进行扩展。 该表由应用自身维护, 对外不可读写。
该表只支持应用自身进行插入和删除两个操作, 具体用途如下:
( 1 )插入。
当卡片批准本次脱机交易后, 将该笔交易对应的应用交易计数器 值和授权金额插入该表中。
( 2 )删除。
当卡外实体向卡内电子现金应用请求脱机交易数据加密服务时, 卡内在收到数据后首先判断该笔脱机交易是否属于本帐户的消费交 易, 而判断依据主要有主帐号、 发卡行应用数据和电子现金发卡行授 权码等帐户信息。 如果判断的结果是 "否" , 那么返回错误验证码; 如果判断的结果是 "是" , 那么再判断是否存在匹配的记录。 如果判 断的结果是"否",那么还是返回错误脸证码。如果判断的结果是"是", 那么再判断授权金额是否一致。 如果判断的结果是 "否" , 那么返回 错误验证码; 如果判断的结果是 "是" , 那么进行加密, 接着从脱机 交易完成状态信息表中删除对应记录, 并最后返回加密的结果。 这样 可以保证只对本账户的脱机交易数据进行加密处理。 图 3示出了上述 步骤。
为了保证脱机交易数据的安全, 这里还引入了一套安全传输密钥 体系对脱机交易数据进行加密、 报文验证代码 (MAC)计算等操作。 所 使用的加密算法可以是对称算法也可以是非对称算法。
安全传输密钥体系至少包含如下密钥: ( 1 )一笔脱机交易凭证 数据的加密密钥, 同时也计算相应的 MAC; ( 2 )对外提供的传输报文 加密密钥; ( 3 )对外提供的传输《¾文 MAC计算密钥。 交易凭证数据 含有状态信息表中记录涉及的内容, 从而实现对请求加密内容的合法
性和唯一性进行认证。
所以经过 展的电子现金需要提供如下的安全操作接口: ( 1 ) 脱机交易凭证数据加密和 MAC计算操作接口; ( 2 )对外提供的传输 报文加密接口; ( 3 )对外提供的传输报文 MAC计算接口。 其中 ( 1 ) 的操作权限: 被判断为属于本帐户的、 且在移动终端上完成的脱机交 易凭证数据; ( 2 ) 的操作权限: 持卡人脱机 PIN验证通过; ( 3 ) 的 操作权限: 持卡人脱机 PIN验证通过。
上述安全密钥体系可以是对称的, 也可以是基于 ΡΠ的非对称。 各种方式来实现。 例如, 这种方法可通过硬件、 固件、 软件或者它们 的任何组合来实现。 在硬件实现中, 例如, 装置可在一个或更多的专 用集成电路 (AS ICs)、 数字信号处理器(DSPs)、 数字信号处理装置 (DSPDs)、 可编程逻辑器件(PLDs)、 现场可编程门阵列(FPGAs)、 处理 器、 控制器、 微控制器、 微处理器、 电子装置或者设计成执行诸如这 里所述的功能的其它装置单元或者它们的任何组合中实现。
同样, 在一些实施例中, 方法可采用执行这里所述功能或者它们 的任何组合的模块来实现。 例如, 有形地具体化指令的任何机器可读 介盾可在实现这类方法中使用。 在一实施例中, 例如, 软件或代码可 存储在存储器中并且由处理单元来运行。 存储器可在处理单元中和 / 或处理单元外部来实现。 这里所使用的术语 "存储器,, 表示任何类型 的长期、 短期、 易失性、 非易失性或者其它存储器, 并且并不局限于 存储器的任何特定类型或者存储器的数量或者存储介质的类型。
存储介质可包括可由计算机、 计算平台、 计算装置等等来访问的 任何可用介质。 作为举例而不是限制, 计算机可读介质可包括 RAM、 ROM, EEPR0M、 CD-ROM或其它光盘存储、 磁盘存储或者其它磁存储装
置, 或者可用于携带或存储釆取指令或数据结构形式的期望的程序代 码并且可由计算机、 计算平台或计算装置来访问的其它任何介质。
虽然上文已经示出了当前被认为是示例特征的内容, 但是本领域 的技术人员将会理解, 在不背离要求保护的主题的情况下, 可以对本 发明中所描述的具体实施例进行各种修改。 特别是, 以 IC卡中的电 子现金为例的实施例可以同样应用到其它数据存储装置中的数据的 应用, 包括相应的方法和装置。 因此, 要求保护的主题并不局限于所 公开的特定示例, 相反, 其包括了落入所附权利要求的范围之内的所 有内容。
Claims
1. 一种在数据存储装置中的处理来自移动终端的数据访问请求 的方法, 包括:
接收向所述数据存储装置发出的数据访问的请求;
向所述请求的发起者提出身份认证要求;
验 ^
通过改变一次性会话标识的状态来反映验证的结果, 其中所述一 次性会话标识的状态在每次接收到处理数据访问请求时处于未通过 验证的状态;
如果通过验证则批准和执行对所述数据的修改请求, 并将修改内 容记录到状态信息表中; 以及
在移动终端发出加密服务请求时, 仅在所述加密服务请求中含有 和所述状态信息表中的记录相对应的信息时响应所述加密服务请求。
2. 如权利要求 1所述的处理来自移动终端的数据访问请求的方 法, 其中所述数据是电子现金账户数据, 所述修改请求由所述电子现 金账户的交易引起, 所述数据修改的值是所述交易的授权金额和相应 的交易状态计数器等账户信息, 所述状态信息表是脱机交易完成状态 信息表, 其至少包括应用交易计数器和所述授权金额。
3. 如权利要求 2所述的处理来自移动终端的数据访问请求的方 法, 其中所述加密服务请求中含有的和所述状态信息表中的记录相对 应的信息, 包括:
账户对应,
交易计数器值对应; 以及
授权金额对应。
4. 如权利要求 1所述的处理来自移动终端的数据访问请求的方 法, 还包括对在所述状态信息表中存在匹配记录的交易数据信息进行 加密和报文验证代码计算, 并将计算结果发送给后台系统。
5. 如权利要求 1 - 4中任意一项所述的处理来自移动终端的数据 访问请求的方法, 其中所述数据存储装置是 IC卡。
6. 如权利要求 1 - 4中任意一项所述的处理来自移动终端的数据 访问请求的方法, 其中所述移动终端是手机或者平板电脑。
7. 如权利要求 1 - 4中任意一项所述的处理来自移动终端的数据 访问请求的方法, 其中所述数据存储装置中存储的数据是电子现金账 户数据。
8. 如权利要求 4所述的处理来自移动终端的数据访问请求的方 法, 其中对在所述状态信息表中存在匹配记录的交易数据信息进行加 密的步骤所使用的加密算法是对称算法或者非对称算法, 所述交易数 据信息是扣款凭证信息。
9. 如权利要求 8所述的处理来自移动终端的数据访问请求的方 法, 其中还将加密后的交易信息凭证报文发送给后台进行验证。
10. 如权利要求 2所述的处理来自移动终端的数据访问请求的方 法, 其中所述脱机交易完成状态信息表仅仅支持应用自身进行插入和 删除操作。
11. 如权利要求 2所述的处理来自移动终端的数据访问请求的方 法, 其中所述将修改内容记录到状态信息表中的步骤包括将所述交易 对应的应用交易计数器只和所述授权金额插入到所述脱机交易完成 状态信息表中。
12. 一种在数据存储装置中的处理来自移动终端的数据访问请求
的设备, 包括:
接收装置, 其接收向所述数据存储装置发出的数据访问的请求; 身份认证发起装置, 其向所述请求的发起者提出身份认证要求; 验证装置, 其验证所述发起者响应所述身份认证要求所输入的身 份认证内容;
-险证结果记录装置, 通过改变一次性会话标识的状态来反映验证 的结果, 其中所述一次性会话标识的状态在每次接收到处理数据访问 请求时处于未通过验证的状态;
修改装置, 如果通过验证则批准和执行对所述数据的修改请求, 并将修改内容记录到状态信息表中; 以及
加密服务请求响应装置, 在移动终端发出加密服务请求时, 仅在 所述力。密服务请求中含有和所述状态信息表中的记录相对应的信息 时响应所述加密服务请求。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210412344.4A CN103778535B (zh) | 2012-10-25 | 2012-10-25 | 处理来自移动终端的数据访问请求的设备和方法 |
| CN201210412344.4 | 2012-10-25 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014063546A1 true WO2014063546A1 (zh) | 2014-05-01 |
Family
ID=50543983
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/083846 Ceased WO2014063546A1 (zh) | 2012-10-25 | 2013-09-19 | 处理来自移动终端的数据访问请求的设备和方法 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN103778535B (zh) |
| WO (1) | WO2014063546A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016141865A1 (zh) * | 2015-03-11 | 2016-09-15 | 中国银联股份有限公司 | 用于移动近场支付的数据传输方法及用户设备 |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12562905B2 (en) | 2024-01-22 | 2026-02-24 | Bank Of America Corporation | System and method for encrypting user device resource transactions |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101394615A (zh) * | 2007-09-20 | 2009-03-25 | 中国银联股份有限公司 | 一种基于pki技术的移动支付终端及支付方法 |
| CN102118745A (zh) * | 2011-01-14 | 2011-07-06 | 中国工商银行股份有限公司 | 一种移动支付数据安全加密方法、装置及手机 |
| CN102665208A (zh) * | 2012-04-06 | 2012-09-12 | 中国工商银行股份有限公司 | 移动终端、终端银行业务安全认证方法及系统 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR2858145A1 (fr) * | 2003-07-24 | 2005-01-28 | France Telecom | Procede et systeme de double authentification securise d'un utilisateur lors de l'acces a un service par l'intermediaire d'un reseau ip |
| CN1889419B (zh) * | 2005-06-30 | 2010-05-05 | 联想(北京)有限公司 | 一种实现加密的方法及装置 |
| CN1963854A (zh) * | 2006-11-27 | 2007-05-16 | 北京握奇数据系统有限公司 | 一种缩短电子货币消费交易时间的方法 |
-
2012
- 2012-10-25 CN CN201210412344.4A patent/CN103778535B/zh active Active
-
2013
- 2013-09-19 WO PCT/CN2013/083846 patent/WO2014063546A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101394615A (zh) * | 2007-09-20 | 2009-03-25 | 中国银联股份有限公司 | 一种基于pki技术的移动支付终端及支付方法 |
| CN102118745A (zh) * | 2011-01-14 | 2011-07-06 | 中国工商银行股份有限公司 | 一种移动支付数据安全加密方法、装置及手机 |
| CN102665208A (zh) * | 2012-04-06 | 2012-09-12 | 中国工商银行股份有限公司 | 移动终端、终端银行业务安全认证方法及系统 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016141865A1 (zh) * | 2015-03-11 | 2016-09-15 | 中国银联股份有限公司 | 用于移动近场支付的数据传输方法及用户设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103778535A (zh) | 2014-05-07 |
| CN103778535B (zh) | 2017-08-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN108898389B (zh) | 基于区块链的内容验证方法及装置、电子设备 | |
| CN108604345B (zh) | 一种添加银行卡的方法及装置 | |
| CN103443813B (zh) | 通过移动设备认证交易的系统及方法 | |
| CN106416189B (zh) | 用于改进的认证的系统和方法 | |
| CN104969245B (zh) | 用于安全元件交易和资产管理的装置和方法 | |
| US10586229B2 (en) | Anytime validation tokens | |
| CN115004208A (zh) | 利用密码技术生成条形码 | |
| WO2020020329A1 (zh) | 一种支持匿名或实名的离线交易的数字钱包及使用方法 | |
| US10223690B2 (en) | Alternative account identifier | |
| EP2098985A2 (en) | Secure financial reader architecture | |
| CN108234385A (zh) | 一种用户身份认证方法及装置 | |
| CN104899741B (zh) | 一种基于ic银行卡的在线支付方法以及在线支付系统 | |
| CN103152174A (zh) | 应用于停车场的数据处理方法、装置及停车场管理系统 | |
| WO2016044882A1 (en) | Secure transfer of payment data | |
| US11727403B2 (en) | System and method for payment authentication | |
| CN112074835A (zh) | 执行安全操作的技术 | |
| JP2024521777A (ja) | ルールに基づく部分的にオンラインおよびオフライン支払取引を可能にするシステムおよび方法 | |
| TWI715833B (zh) | 一種空中發卡方法、裝置、計算設備、電腦可讀存儲介質及電腦程式產品 | |
| US20160086168A1 (en) | Establishing communication between a reader application and a smart card emulator | |
| CN101408970A (zh) | 实现批量电子交易的方法、系统和装置以及电子签名工具 | |
| GB2508207A (en) | Controlling access to secured data stored on a mobile device | |
| WO2014063546A1 (zh) | 处理来自移动终端的数据访问请求的设备和方法 | |
| KR20160008012A (ko) | 휴대단말기에서의 사용자 인증방법 | |
| WO2019237258A1 (zh) | 数字货币交互方法,数字货币物理载体,终端设备及存储介质 | |
| CN114186994A (zh) | 一种数字货币钱包应用的使用方法、终端及系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13849805 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 20/08/2015) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13849805 Country of ref document: EP Kind code of ref document: A1 |