WO2015055120A1 - 用于安全性信息交互的装置 - Google Patents

用于安全性信息交互的装置 Download PDF

Info

Publication number
WO2015055120A1
WO2015055120A1 PCT/CN2014/088640 CN2014088640W WO2015055120A1 WO 2015055120 A1 WO2015055120 A1 WO 2015055120A1 CN 2014088640 W CN2014088640 W CN 2014088640W WO 2015055120 A1 WO2015055120 A1 WO 2015055120A1
Authority
WO
WIPO (PCT)
Prior art keywords
information interaction
security information
security
external
communication unit
Prior art date
Application number
PCT/CN2014/088640
Other languages
English (en)
French (fr)
Inventor
王明博
华锦芝
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Publication of WO2015055120A1 publication Critical patent/WO2015055120A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Definitions

  • the present invention relates to an apparatus for information interaction, and more particularly to an apparatus for security information interaction.
  • security information interaction that is, security interaction requirements, such as in the financial field
  • networks especially mobile networks.
  • the payment transaction process is becoming more and more important.
  • a USB Key is generally used as a hardware carrier of a digital certificate, and a network node (for example, a personal computer connected to the Internet) is connected to the USB Key through a USB interface to perform a security information interaction process, wherein
  • the USB Key can store the user's private key (the user's private key is stored in the password lock) and the digital certificate, and use the built-in public key algorithm to authenticate the user's identity.
  • the existing technical solutions have the following problems: (1) Since the specific interface (for example, the type A male port) used can only communicate with a computer and cannot be used for various types of mobile terminals, it does not have a wide range. Applicability; (2) It is inconvenient to use because it requires manual insertion during use and also needs to install a specific driver; (3) Since it can only support a single identity authentication scenario, the application is single.
  • the specific interface for example, the type A male port
  • the present invention proposes an apparatus for security information interaction capable of supporting multiple identity authentication scenarios and having wide applicability and ease of use.
  • An apparatus for security information interaction includes:
  • a controller that performs a security mode with an external security information interaction terminal via a communication module Data communication to perform related security information interaction processes
  • the cryptographic coprocessing module is configured to assist the controller to perform an encryption algorithm based on the security parameter to perform data communication in the security mode;
  • the storage module is configured to store the security parameter.
  • a communication module configured to establish a data communication link between the device for security information interaction and the external security information interaction terminal.
  • the communication module further includes:
  • the first communication unit being capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on a USB interface;
  • the second communication unit being capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on an NFC interface;
  • a third communication unit capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on a Bluetooth interface.
  • the external security information interaction terminal is a POS machine supporting an NFC or Bluetooth communication protocol or a computer or mobile terminal as a network node.
  • the means for security information interaction comprises a power source in the form of a rechargeable lithium battery, and when the means for security information interaction is connected to the computer via a USB interface The lithium battery is charged while the lithium battery provides power to the device for security information interaction when the device for security information interaction uses an NFC or Bluetooth communication protocol.
  • the means for security information interaction is still capable of establishing the security information based on the NFC interface by the second communication unit.
  • a data communication link between the interacting device and the external security information interaction terminal, wherein the coupling element of the second communication unit is capable of generating electrical energy by electromagnetic coupling to thereby interact with the security information The device provides electrical energy.
  • the means for security information interaction includes a clock capable of providing timestamp information of the means for security information interaction.
  • the means for security information interaction has a Bluetooth switch when the third communication unit is required to establish the security for use based on a Bluetooth communication protocol
  • the Bluetooth switch must be manually turned on when the data communication link between the device for sexual information interaction and the external security information interaction terminal is turned on, and can be manually turned off after the security information interaction process is completed.
  • the security parameter includes a private key of the user and a digital certificate.
  • the PIN identity authentication process is required when private data in the security parameters needs to be used and the associated encryption algorithm is used.
  • the means for security information interaction can use one or a combination of the following three authentication modes: static data authentication, dynamic data authentication, and dynamic password authentication.
  • the apparatus for security information interaction disclosed by the present invention has the following advantages: (1) Since one or a combination of static data authentication (SDA), dynamic data authentication (DDA), and dynamic password authentication (OTP) can be used, Therefore, it can support multiple identity authentication scenarios; (2) data communication can be performed with an external security information interaction terminal through a USB interface, or a Bluetooth interface, or an NFC interface, and it is not necessary to manually use a Bluetooth interface or an NFC interface. The device is inserted, so that it has wide applicability and ease of use.
  • SDA static data authentication
  • DDA dynamic data authentication
  • OTP dynamic password authentication
  • FIG. 1 is a schematic structural diagram of an apparatus for security information interaction in accordance with an embodiment of the present invention.
  • the apparatus for security information interaction disclosed by the present invention includes a controller 1, a cryptographic coprocessing module 2, a storage module 3, and a communication module 4.
  • the controller 1 performs data communication in a secure mode with the external security information interaction terminal via the communication module 6 to perform an associated security information interaction process.
  • the cryptographic coprocessing module 2 is configured to assist the controller 1 to perform based on security parameters.
  • a line encryption algorithm is used to perform data communication in the secure mode.
  • the storage module 3 is configured to store the security parameter.
  • the communication module 4 is configured to establish a data communication link between the device for security information interaction and the external security information interaction terminal.
  • the communication module 4 further includes a first communication unit, a second communication unit, and a third communication unit.
  • the first communication unit is capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on a USB interface.
  • the second communication unit is capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on an NFC (Near Field Communication) interface.
  • the third communication unit is capable of establishing a data communication link between the device for security information interaction and the external security information interaction terminal based on a Bluetooth interface.
  • the external security information interaction terminal is a POS machine supporting an NFC or Bluetooth communication protocol or a computer or a mobile terminal (such as a smart phone) as a network node. , tablet, etc.).
  • the apparatus for security information interaction disclosed herein includes a power source 5 in the form of a rechargeable lithium battery.
  • a power source 5 in the form of a rechargeable lithium battery.
  • the lithium battery when the device for security information interaction is connected to a computer through a USB interface, the lithium battery is charged, and when the device for security information interaction uses an NFC or Bluetooth communication protocol, A lithium battery provides electrical energy to the device for security information interaction.
  • the means for security information interaction when the lithium battery is low in power, can still be based on NFC by the second communication unit (The near field communication interface establishes a data communication link between the means for security information interaction and the external security information interaction terminal.
  • the coupling element of the second communication unit is capable of generating electrical energy by electromagnetic coupling to provide electrical energy to the means for security information interaction.
  • the apparatus for security information interaction disclosed by the present invention comprises a clock 6 capable of providing timestamp information of the means for security information interaction.
  • the apparatus for security information interaction disclosed by the present invention has a Bluetooth switch when the third communication unit is required to establish the apparatus for security information interaction and the external security based on a Bluetooth communication protocol
  • the Bluetooth switch when the data communication link between the sexual information interaction terminals It must be turned on manually and can be manually turned off after the security information interaction process is completed.
  • the Bluetooth switch can be set to be automatically turned off after the Bluetooth function is turned on for a predetermined period of time (eg, 5 minutes).
  • the security parameter includes a private key of the user and a digital certificate.
  • the apparatus for security information interaction when private data (such as a user's private key, digital certificate or device timestamp) in the security parameter needs to be used and an associated encryption algorithm is used A PIN (Personal Identification Number) identity authentication process is required.
  • private data such as a user's private key, digital certificate or device timestamp
  • PIN Personal Identification Number
  • the apparatus for security information interaction disclosed by the present invention is capable of using one or a combination of the following three authentication modes: static data authentication (SDA), dynamic data authentication (DDA), and dynamic password authentication (OTP). .
  • SDA static data authentication
  • DDA dynamic data authentication
  • OTP dynamic password authentication
  • the static data authentication is used to confirm key static data stored in the apparatus for security information interaction.
  • the basic process is as follows: (1) external security information interaction terminal (PC or client in the mobile terminal) through the USB interface or wireless
  • the communication mode interacts with the device for security information interaction, and selects an SDA authentication mode;
  • the device for security information interaction uses a certificate authority public key index, an application publisher public key certificate, and a signature
  • the application data is provided to an external security information interaction terminal (a client in a PC or a mobile terminal), and the external security information interaction terminal submits the data to the server for verification; (3) the server side verifies the issuer public key certificate.
  • the dynamic password authentication uses a time-based one-time password algorithm (TOTP), that is, every 60 seconds, generating one and time Correlation and unpredictable random number combination for strong identity authentication
  • TOTP time-based one-time password algorithm
  • the basic process is as follows: (1) external security information interaction terminal (PC or client in mobile terminal) through USB interface or wireless communication mode and the use Interact with devices that interact with security information and select OTP Authentication mode; (2) the device for security information interaction responds to the request and returns a list of available functions: OTP function and clock synchronization function; (3) if external security information interaction terminal (in PC or mobile terminal)
  • the client selects the OTP function, and the device for security information interaction automatically reads the hash value of the OTP token in the hardware, the current timestamp, and calculates the dynamic password using the TOTP algorithm;
  • the device for security information interaction transmits the calculated dynamic password and device ID to an external security information interaction terminal (a client in a PC or a mobile terminal); (5) an external security information interaction
  • the dynamic data authentication performs the same data authentication process as SDA, and uses the private key of itself to perform important data. Signature to ensure that important security information is not illegally falsified and to prevent the device used for security information interaction from being forged.
  • the basic process is as follows: (1) External security information interaction terminal (PC or client in mobile terminal) Interacting with the device for security information interaction via a USB interface or wireless communication mode, and selecting a DDA authentication mode; (2) the device for security information interaction responds to the request and requires external security information interaction The terminal provides a hardware PIN code; (3) the device for security information interaction accepts the PIN code, and if the verification passes, sends a list of encryption and other services that it can provide to the external security information interaction terminal; 4) The external security information interaction terminal selects an authentication algorithm to be used and sends a message that needs to be signed to the security information.
  • PC External security information interaction terminal
  • Means means for using said security information interaction built
  • the algorithm performs signature encryption on the message that the user needs to sign
  • the device for security information interaction packages the original text, the signed ciphertext and the own digital certificate to external security according to the PKCS#7 standard.
  • the information interaction terminal; (7) the external security information interaction terminal sends the message to the authentication server; (8) the authentication server reads the information conforming to the PKCS#7 standard, and completes the certificate verification, the blacklist check, and the report.
  • the authentication server checks the decrypted message with the original text, and if the same, authenticates. It can be seen from the above that the DDA authentication method is complicated, and it is necessary to input a PIN code.
  • the device for security information interaction also needs cryptographic operations internally. Therefore, the authentication method is suitable for scenarios with high security requirements (for example, In the financial field, the bank card password is encrypted and signed during the online banking transaction).
  • the apparatus for security information interaction disclosed by the present invention has the following advantages: (1) one of static data authentication (SDA), dynamic data authentication (DDA), and dynamic password authentication (OTP) can be used. Or a combination thereof, so that it can support multiple identity authentication scenarios; (2) data communication with an external security information interaction terminal through a USB interface, or a Bluetooth interface, or an NFC interface, and in the case of adopting a Bluetooth interface or an NFC interface There is no need to manually insert the device, so it has wide applicability and ease of use.
  • SDA static data authentication
  • DDA dynamic data authentication
  • OTP dynamic password authentication

Abstract

一种用于安全性信息交互的装置,所述装置包括:控制器,其经由通信模块与外部安全性信息交互终端进行安全模式下的数据通信以执行相关的安全性信息交互过程;加密协处理模块,其用于协助所述控制器基于安全参数执行加密算法以进行所述安全模式下的数据通信;存储模块,其用于存储所述安全参数;通信模块,其用于建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。所述用于安全性信息交互的装置能够支持多种身份认证场景并且具有广泛的适用性和使用便捷性。

Description

用于安全性信息交互的装置 技术领域
本发明涉及用于信息交互的装置,更具体地,涉及用于安全性信息交互的装置。
背景技术
目前,随着网络应用的日益广泛以及不同领域的业务种类的日益丰富,通过网络(特别是移动网络)进行安全性信息交互(即对安全性要求较高的信息交互过程,例如金融领域中的支付交易过程)变得越来越重要。
在现有的技术方案中,通常使用USB Key作为数字证书的硬件载体,并且网络节点(例如与互联网相连的个人电脑)通过USB接口与所述USB Key相连接以执行安全性信息交互过程,其中,所述USB Key可以存储用户的私钥(所述用户的私钥保存在密码锁中)以及数字证书,并利用内置的公钥算法实现对用户身份的认证。
然而,现有的技术方案存在如下问题:(1)由于所采用的特定的接口(例如A型公口)仅能与计算机进行通信而不能用于各种类型的移动终端,故不具有广泛的适用性;(2)由于在使用时需要人工插入并且还需要安装特定的驱动程序,故使用不便;(3)由于仅能支持单一的身份认证场景,故应用场合单一。
因此,存在如下需求:提供能够支持多种身份认证场景并且具有广泛的适用性和使用便捷性的用于安全性信息交互的装置。
发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了能够支持多种身份认证场景并且具有广泛的适用性和使用便捷性的用于安全性信息交互的装置。
本发明的目的是通过以下技术方案实现的:
一种用于安全性信息交互的装置,所述用于安全性信息交互的装置包括:
控制器,所述控制器经由通信模块与外部安全性信息交互终端进行安全模 式下的数据通信以执行相关的安全性信息交互过程;
加密协处理模块,所述加密协处理模块用于协助所述控制器基于安全参数执行加密算法以进行所述安全模式下的数据通信;
存储模块,所述存储模块用于存储所述安全参数。
通信模块,所述通信模块用于建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
在上面所公开的方案中,优选地,所述通信模块进一步包括:
第一通信单元,所述第一通信单元能够基于USB接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路;
第二通信单元,所述第二通信单元能够基于NFC接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路;
第三通信单元,所述第三通信单元能够基于蓝牙接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
在上面所公开的方案中,优选地,所述外部安全性信息交互终端是支持NFC或蓝牙通信协议的POS机或作为网络节点的计算机或移动终端。
在上面所公开的方案中,优选地,所述用于安全性信息交互的装置包括可充电的锂电池形式的电源,并且当所述用于安全性信息交互的装置通过USB接口被连接到计算机时,所述锂电池被充电,而当所述用于安全性信息交互的装置使用NFC或蓝牙通信协议时所述锂电池为所述用于安全性信息交互的装置提供电能。
在上面所公开的方案中,优选地,当所述锂电池电量不足时,所述用于安全性信息交互的装置仍然能够通过所述第二通信单元基于NFC接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路,其中,所述第二通信单元的耦合元件能够通过电磁耦合作用而产生电能,从而为所述用于安全性信息交互的装置提供电能。
在上面所公开的方案中,优选地,所述用于安全性信息交互的装置包括时钟,所述时钟能够提供所述用于安全性信息交互的装置的时间戳信息。
在上面所公开的方案中,优选地,所述用于安全性信息交互的装置具有蓝牙开关,当需要使用所述第三通信单元以基于蓝牙通信协议建立所述用于安全 性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路时,所述蓝牙开关必须被手动地开启,并且在所述安全性信息交互过程被完成后能够被手动地关闭。
在上面所公开的方案中,优选地,所述安全参数包括用户的私钥以及数字证书。
在上面所公开的方案中,优选地,当需要使用所述安全参数中的私有数据以及使用相关的加密算法时,需要进行PIN身份认证过程。
在上面所公开的方案中,优选地,所述用于安全性信息交互的装置能够使用下列三种认证模式中的一个或其组合:静态数据认证、动态数据认证以及动态密码认证。
本发明所公开的用于安全性信息交互的装置具有以下优点:(1)由于能够使用静态数据认证(SDA)、动态数据认证(DDA)以及动态密码认证(OTP)中的一个或其组合,故能够支持多种身份认证场景;(2)由于能够通过USB接口、或蓝牙接口、或NFC接口与外部安全性信息交互终端进行数据通信,并且在采用蓝牙接口或NFC接口的情况下无需手工地插入该装置,故具有广泛的适用性和使用便捷性。
附图说明
结合附图,本发明的技术特征以及优点将会被本领域技术人员更好地理解,其中:
图1是根据本发明的实施例的用于安全性信息交互的装置的示意性结构图。
具体实施方式
图1是根据本发明的实施例的用于安全性信息交互的装置的示意性结构图。如图1所示,本发明所公开的用于安全性信息交互的装置包括控制器1、加密协处理模块2、存储模块3、以及通信模块4。其中,所述控制器1经由通信模块6与外部安全性信息交互终端进行安全模式下的数据通信以执行相关的安全性信息交互过程。所述加密协处理模块2用于协助所述控制器1基于安全参数执 行加密算法以进行所述安全模式下的数据通信。所述存储模块3用于存储所述安全参数。所述通信模块4用于建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
优选地,在本发明所公开的用于安全性信息交互的装置中,所述通信模块4进一步包括第一通信单元、第二通信单元和第三通信单元。所述第一通信单元能够基于USB接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。所述第二通信单元能够基于NFC(近场通信)接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。所述第三通信单元能够基于蓝牙接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
优选地,在本发明所公开的用于安全性信息交互的装置中,所述外部安全性信息交互终端是支持NFC或蓝牙通信协议的POS机或作为网络节点的计算机或移动终端(诸如智能手机、平板电脑等等)。
优选地,本发明所公开的用于安全性信息交互的装置包括可充电的锂电池形式的电源5。其中,当所述用于安全性信息交互的装置通过USB接口被连接到计算机时,所述锂电池被充电,而当所述用于安全性信息交互的装置使用NFC或蓝牙通信协议时所述锂电池为所述用于安全性信息交互的装置提供电能。
优选地,在本发明所公开的用于安全性信息交互的装置中,当所述锂电池电量不足时,所述用于安全性信息交互的装置仍然能够通过所述第二通信单元基于NFC(近场通信)接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。在其中,所述第二通信单元的耦合元件能够通过电磁耦合作用而产生电能,从而为所述用于安全性信息交互的装置提供电能。
优选地,本发明所公开的用于安全性信息交互的装置包括时钟6,所述时钟6能够提供所述用于安全性信息交互的装置的时间戳信息。
优选地,本发明所公开的用于安全性信息交互的装置具有蓝牙开关,当需要使用所述第三通信单元以基于蓝牙通信协议建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路时,所述蓝牙开关 必须被手动地开启,并且在所述安全性信息交互过程被完成后能够被手动地关闭。可选地,所述蓝牙开关能够被设置为在蓝牙功能被开启预定的时间段(例如5分钟)之后被自动地关闭。
优选地,在本发明所公开的用于安全性信息交互的装置中,所述安全参数包括用户的私钥以及数字证书。
优选地,在本发明所公开的用于安全性信息交互的装置中,当需要使用所述安全参数中的私有数据(例如用户的私钥、数字证书或设备时间戳)以及使用相关的加密算法时,需要进行PIN(个人识别码)身份认证过程。
优选地,本发明所公开的用于安全性信息交互的装置能够使用下列三种认证模式中的一个或其组合:静态数据认证(SDA)、动态数据认证(DDA)以及动态密码认证(OTP)。
示例性地,在本发明所公开的用于安全性信息交互的装置中,所述静态数据认证(SDA)用于确认存放在所述用于安全性信息交互的装置中的关键的静态数据的合法性,从而确保该用于安全性信息交互的装置的所有者的合法身份,其基本过程如下:(1)外部安全性信息交互终端(PC或者移动终端中的客户端)通过USB接口或者无线通信方式与所述用于安全性信息交互的装置交互,并选择SDA认证模式;(2)所述用于安全性信息交互的装置将认证中心公钥索引、应用发行商公钥证书、签名的应用数据提供给外部安全性信息交互终端(PC或者移动终端中的客户端),所述外部安全性信息交互终端将这些数据提交给服务器端进行验证;(3)服务器端验证发行商公钥证书的合法性并使用该公钥验证所述用于安全性信息交互的装置中的应用数据的合法性,并且如果合法则验证通过。由上可见,所述静态数据认证(SDA)过程简单快速,但存在一定的安全隐患,故可以用在对安全要求不高,但对用户的操作便利性要求较高的场景中。
示例性地,在本发明所公开的用于安全性信息交互的装置中,所述动态密码认证(OTP)使用基于时间的一次性密码算法(TOTP),即每隔60秒,生成一个与时间相关的、不可预测的随机数组合来进行强身份认证,其基本过程如下:(1)外部安全性信息交互终端(PC或者移动终端中的客户端)通过USB接口或者无线通信方式与所述用于安全性信息交互的装置交互,并选择OTP 认证模式;(2)所述用于安全性信息交互的装置响应请求,并返回可用的功能列表:OTP功能和时钟同步功能;(3)如果外部安全性信息交互终端(PC或者移动终端中的客户端)选择OTP功能,则所述用于安全性信息交互的装置自动地读取硬件内的OTP令牌的Hash值、当前时间戳,并使用TOTP算法计算出动态密码;(4)所述用于安全性信息交互的装置将计算出的动态密码和设备ID传输给外部安全性信息交互终端(PC或者移动终端中的客户端);(5)外部安全性信息交互终端(PC或者移动终端中的客户端)将动态密码、设备ID连同其它认证数据传输给服务器进行验证;(6)服务器端根据设备ID取出与所述用于安全性信息交互的装置相同的令牌(Token)以及基于与该用于安全性信息交互的装置的时间差并使用TOTP算法算出动态密码,随后将计算出的动态密码与提交的动态密码进行比较,如果相同则验证通过;(7)如果在第(3)步中,外部安全性信息交互终端(PC或者移动终端中的客户端)选择时钟同步功能,则所述用于安全性信息交互的装置请求所述外部安全性信息交互终端提供PIN码以进行认证;(8)所述用于安全性信息交互的装置接受PIN码,并且如果验证通过,则所述用于安全性信息交互的装置取出时间戳并提交给所述外部安全性信息交互终端;(9)所述外部安全性信息交互终端(PC或者移动终端中的客户端)将时间戳上传至服务器,服务器随后在数据库中更新与当前用于安全性信息交互的装置的时间差。
示例性地,在本发明所公开的用于安全性信息交互的装置中,所述动态数据认证(DDA)除了执行与SDA相同的数据认证过程之外,还使用自身的私钥对重要数据进行签名,以保证重要的安全性信息不被非法篡改以及防止该用于安全性信息交互的装置被伪造,其基本过程如下:(1)外部安全性信息交互终端(PC或者移动终端中的客户端)通过USB接口或者无线通信方式与所述用于安全性信息交互的装置交互,并选择DDA认证模式;(2)所述用于安全性信息交互的装置响应请求,并要求外部安全性信息交互终端提供硬件PIN码;(3)所述用于安全性信息交互的装置接受PIN码,并且如果验证通过,则将其能够提供的加密及其它服务的列表发送给外部安全性信息交互终端;(4)所述外部安全性信息交互终端选择需要使用的认证算法并将需要签名的报文发送给所述用于安全性信息交互的装置;(5)所述用于安全性信息交互的装置使用内置 算法对用户需要签名的报文进行签名加密;(6)所述用于安全性信息交互的装置根据PKCS#7标准,将原文、签名后的密文和自己的数字证书打包传给外部安全性信息交互终端;(7)所述外部安全性信息交互终端将报文发送给认证服务器;(8)所述认证服务器读取符合PKCS#7标准的信息,并完成证书验证、黑名单检查以及报文解密;(9)所述认证服务器对解密后的报文与原文核对,若相同则通过身份验证。由上可见,DDA认证方法较为复杂,既需要输入PIN码,所述用于安全性信息交互的装置内部还需要密码学运算,因此,该认证方法适用于对安全性要求较高的场景(例如金融领域中在网银交易过程中对银行卡密码进行加密和签名)。
由上可见,本发明所公开的用于安全性信息交互的装置具有下列优点:(1)由于能够使用静态数据认证(SDA)、动态数据认证(DDA)以及动态密码认证(OTP)中的一个或其组合,故能够支持多种身份认证场景;(2)由于能够通过USB接口、或蓝牙接口、或NFC接口与外部安全性信息交互终端进行数据通信,并且在采用蓝牙接口或NFC接口的情况下无需手工地插入该装置,故具有广泛的适用性和使用便捷性。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不局限于上述的实施方式。应该认识到:在不脱离本发明主旨和范围的情况下,本领域技术人员可以对本发明做出不同的变化和修改。

Claims (10)

  1. 一种用于安全性信息交互的装置,所述用于安全性信息交互的装置包括:
    控制器,所述控制器经由通信模块与外部安全性信息交互终端进行安全模式下的数据通信以执行相关的安全性信息交互过程;
    加密协处理模块,所述加密协处理模块用于协助所述控制器基于安全参数执行加密算法以进行所述安全模式下的数据通信;
    存储模块,所述存储模块用于存储所述安全参数;
    通信模块,所述通信模块用于建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
  2. 根据权利要求1所述的用于安全性信息交互的装置,其特征在于,所述通信模块进一步包括:
    第一通信单元,所述第一通信单元能够基于USB接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路;
    第二通信单元,所述第二通信单元能够基于NFC接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路;
    第三通信单元,所述第三通信单元能够基于蓝牙接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路。
  3. 根据权利要求2所述的用于安全性信息交互的装置,其特征在于,所述外部安全性信息交互终端是支持NFC或蓝牙通信协议的POS机或作为网络节点的计算机或移动终端。
  4. 根据权利要求3所述的用于安全性信息交互的装置,其特征在于,所述用于安全性信息交互的装置包括可充电的锂电池形式的电源,并且当所述用于安全性信息交互的装置通过USB接口被连接到计算机时,所述锂电池被充电,而当所述用于安全性信息交互的装置使用NFC或蓝牙通信协议时所述锂电池为所述用于安全性信息交互的装置提供电能。
  5. 根据权利要求4所述的用于安全性信息交互的装置,其特征在于,当所述锂电池电量不足时,所述用于安全性信息交互的装置仍然能够通过所述第二 通信单元基于NFC接口建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路,其中,所述第二通信单元的耦合元件能够通过电磁耦合作用而产生电能,从而为所述用于安全性信息交互的装置提供电能。
  6. 根据权利要求5所述的用于安全性信息交互的装置,其特征在于,所述用于安全性信息交互的装置包括时钟,所述时钟能够提供所述用于安全性信息交互的装置的时间戳信息。
  7. 根据权利要求6所述的用于安全性信息交互的装置,其特征在于,所述用于安全性信息交互的装置具有蓝牙开关,当需要使用所述第三通信单元以基于蓝牙通信协议建立所述用于安全性信息交互的装置和所述外部安全性信息交互终端之间的数据通信链路时,所述蓝牙开关必须被手动地开启,并且在所述安全性信息交互过程被完成后能够被手动地关闭。
  8. 根据权利要求7所述的用于安全性信息交互的装置,其特征在于,所述安全参数包括用户的私钥以及数字证书。
  9. 根据权利要求8所述的用于安全性信息交互的装置,其特征在于,当需要使用所述安全参数中的私有数据以及使用相关的加密算法时,需要进行PIN身份认证过程。
  10. 根据权利要求9所述的用于安全性信息交互的装置,其特征在于,所述用于安全性信息交互的装置能够使用下列三种认证模式中的一个或其组合:静态数据认证、动态数据认证以及动态密码认证。
PCT/CN2014/088640 2013-10-18 2014-10-15 用于安全性信息交互的装置 WO2015055120A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310489291.0 2013-10-18
CN201310489291.0A CN104579659A (zh) 2013-10-18 2013-10-18 用于安全性信息交互的装置

Publications (1)

Publication Number Publication Date
WO2015055120A1 true WO2015055120A1 (zh) 2015-04-23

Family

ID=52827672

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/088640 WO2015055120A1 (zh) 2013-10-18 2014-10-15 用于安全性信息交互的装置

Country Status (2)

Country Link
CN (1) CN104579659A (zh)
WO (1) WO2015055120A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107426370A (zh) * 2017-09-07 2017-12-01 温州市图盛科技有限公司 一种智能安全交互通讯装置
CN111813857A (zh) * 2020-07-02 2020-10-23 珑门汽车科技(上海)有限公司 一种基于区块链技术的检测数据管理系统及方法
CN112468301A (zh) * 2020-10-23 2021-03-09 苏州浪潮智能科技有限公司 一种基于区块链的云平台认证的方法、系统、设备及介质
CN112636911A (zh) * 2021-01-05 2021-04-09 杜瑞峰 一种非联网设备接龙取值变函数序列密码生成方式

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106100855A (zh) * 2016-08-19 2016-11-09 江南信安(北京)科技有限公司 可穿戴式移动密码机
CN109639419A (zh) * 2018-12-29 2019-04-16 北京深思数盾科技股份有限公司 密钥保护方法、密钥存储设备及终端设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2005086593A2 (en) * 2004-02-05 2005-09-22 A Little World Private Limited Inter-operable, multi-operator, multi-bank, multi-merchant mobile payment method and a system therefor
CN101807995A (zh) * 2010-01-18 2010-08-18 北京天地融科技有限公司 支持无线通讯的电子签名工具及与终端通信的处理方法
CN103107880A (zh) * 2011-11-09 2013-05-15 深圳市中磁计算机技术有限公司 安全认证装置
CN103164635A (zh) * 2011-12-15 2013-06-19 中国银联股份有限公司 基于扩展参数集的安全性信息交互系统、装置及方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102571346B (zh) * 2011-12-14 2015-06-17 深圳市文鼎创数据科技有限公司 防止智能密钥装置用户口令被盗的方法和装置
CN202634455U (zh) * 2011-12-14 2012-12-26 中国银联股份有限公司 基于蓝牙技术的安全性信息交互系统、装置及移动终端

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2005086593A2 (en) * 2004-02-05 2005-09-22 A Little World Private Limited Inter-operable, multi-operator, multi-bank, multi-merchant mobile payment method and a system therefor
CN101807995A (zh) * 2010-01-18 2010-08-18 北京天地融科技有限公司 支持无线通讯的电子签名工具及与终端通信的处理方法
CN103107880A (zh) * 2011-11-09 2013-05-15 深圳市中磁计算机技术有限公司 安全认证装置
CN103164635A (zh) * 2011-12-15 2013-06-19 中国银联股份有限公司 基于扩展参数集的安全性信息交互系统、装置及方法

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107426370A (zh) * 2017-09-07 2017-12-01 温州市图盛科技有限公司 一种智能安全交互通讯装置
CN111813857A (zh) * 2020-07-02 2020-10-23 珑门汽车科技(上海)有限公司 一种基于区块链技术的检测数据管理系统及方法
CN112468301A (zh) * 2020-10-23 2021-03-09 苏州浪潮智能科技有限公司 一种基于区块链的云平台认证的方法、系统、设备及介质
CN112468301B (zh) * 2020-10-23 2022-08-02 苏州浪潮智能科技有限公司 一种基于区块链的云平台认证的方法、系统、设备及介质
US11882227B2 (en) 2020-10-23 2024-01-23 Inspur Suzhou Intelligent Technology Co., Ltd. Blockchain-based cloud platform authentication method, system and device and medium
CN112636911A (zh) * 2021-01-05 2021-04-09 杜瑞峰 一种非联网设备接龙取值变函数序列密码生成方式

Also Published As

Publication number Publication date
CN104579659A (zh) 2015-04-29

Similar Documents

Publication Publication Date Title
US11258777B2 (en) Method for carrying out a two-factor authentication
TWI792284B (zh) 用於驗證對安全裝置功能性之線上存取之方法
AU2015264040B2 (en) Systems and methods for linking devices to user accounts
CN106575416B (zh) 用于向装置验证客户端的系统和方法
EP2995039B1 (en) Systems and methods for secure communication
KR101544722B1 (ko) 부인 방지 방법, 이를 위한 결제 관리 서버 및 사용자 단말기
US8689290B2 (en) System and method for securing a credential via user and server verification
JP6586446B2 (ja) 通信端末および関連システムのユーザーの識別情報を確認するための方法
CN104618116B (zh) 一种协同数字签名系统及其方法
US20190165947A1 (en) Signatures for near field communications
WO2015055120A1 (zh) 用于安全性信息交互的装置
WO2018083604A1 (en) Verifying an association between a communication device and a user
CN106096947B (zh) 基于nfc的半离线匿名支付方法
JP2012530311A5 (zh)
US8397281B2 (en) Service assisted secret provisioning
CN112055019B (zh) 一种建立通信信道的方法及用户终端
CN112352410B (zh) 使用智能卡作为安全令牌的方法和装置,可读存储介质
KR100939725B1 (ko) 모바일 단말기 인증 방법
El Madhoun et al. A cloud-based secure authentication protocol for contactless-nfc payment
CN101944216A (zh) 双因子在线交易安全认证方法及系统
KR20000024445A (ko) 전자서명을 이용한 사용자 인증기법과 무선 전자서명을이용한사용자 인증기법 및 휴대형 처리 도구
KR20120091618A (ko) 연쇄 해시에 의한 전자서명 시스템 및 방법
ES2923919T3 (es) Protección de una comunicación P2P
Faridoon et al. Security Protocol for NFC Enabled Mobile Devices Used in Financial Applications
KR101813069B1 (ko) 키락 장치를 이용한 금융 서비스 제공 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14854161

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 17.08.2016)

122 Ep: pct application non-entry in european phase

Ref document number: 14854161

Country of ref document: EP

Kind code of ref document: A1