WO2016065739A1 - 一种智能终端及身份认证方法 - Google Patents

一种智能终端及身份认证方法 Download PDF

Info

Publication number
WO2016065739A1
WO2016065739A1 PCT/CN2015/070063 CN2015070063W WO2016065739A1 WO 2016065739 A1 WO2016065739 A1 WO 2016065739A1 CN 2015070063 W CN2015070063 W CN 2015070063W WO 2016065739 A1 WO2016065739 A1 WO 2016065739A1
Authority
WO
WIPO (PCT)
Prior art keywords
module
conversion module
digital certificate
processor
hardware
Prior art date
Application number
PCT/CN2015/070063
Other languages
English (en)
French (fr)
Inventor
陈柳章
Original Assignee
深圳市文鼎创数据科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市文鼎创数据科技有限公司 filed Critical 深圳市文鼎创数据科技有限公司
Publication of WO2016065739A1 publication Critical patent/WO2016065739A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the invention belongs to the technical field of information security, and particularly relates to an intelligent terminal and an identity authentication method.
  • Online banking provides users with various types of financial services through the Internet, enabling users to handle banking business conveniently and quickly without leaving their homes.
  • Most online banks use hardware digital certificates to complete identity authentication during the transaction process. Inside the hardware digital certificates are stored digital certificates and user private keys that represent the unique identity of the user. The above stored information cannot be exported to the outside of the hardware digital certificate for life. , The identity authentication process involved in all online banking business is completed inside the hardware digital certificate to ensure the credibility of identity authentication and ensure the security of online banking transactions.
  • the hardware digital certificate is integrated into the smart terminal, and its advantage is that the user does not need to carry an additional hardware device.
  • the display screen and key device of the smart terminal are completely controlled by the processor of the smart terminal, and criminals may present false transaction pages to users through malicious programs such as viruses and Trojan horses to trick users into unknowingly Perform identity authentication, confirm false transaction information, complete malicious transactions, and cause user property losses.
  • the purpose of the embodiments of the present invention is to provide an intelligent terminal, which aims to solve the problem that the current identity authentication method of online banking has the risk of inducing users to confirm false transactions, and the security is poor.
  • an intelligent terminal including a processor, a conversion module, a hardware digital certificate module, and an input and output device,
  • the processor and the hardware digital certificate module are mutually independent hardware devices
  • the conversion module is simultaneously connected with the processor and the hardware digital certificate module;
  • the input and output device is connected with the conversion module
  • the conversion module is used to switch the control right of the input and output device to the hardware digital certificate module during the transaction confirmation process.
  • Another objective of the embodiments of the present invention is to provide an identity authentication method based on the above-mentioned smart terminal, including:
  • the processor inputs the key data output by the online banking client to the conversion module
  • the conversion module sends the key data to the hardware digital certificate module
  • the conversion module switches the control right of the input and output device to the hardware digital certificate module, so that the hardware digital certificate module performs transaction confirmation based on the key data;
  • the conversion module sends the confirmation result to the processor so that the online banking client can process the transaction data according to the confirmation result.
  • the processor and the hardware digital certificate module are configured as two independent hardware devices.
  • the hardware digital certificate controls the input and output devices to realize the processor and the input and output.
  • the hardware isolation of the device eliminates the risk of false transaction information being confirmed, and improves the transaction security of online banking.
  • Figure 1 is a block diagram of the hardware structure of an intelligent terminal provided by an embodiment of the present invention.
  • FIG. 2 is a block diagram of the hardware structure of an intelligent terminal provided by another embodiment of the present invention.
  • FIG. 3 is a block diagram of the hardware structure of an intelligent terminal provided by another embodiment of the present invention.
  • FIG. 4 is an implementation flowchart of an identity authentication method provided by an embodiment of the present invention.
  • Fig. 5 is an implementation flowchart of an identity authentication method provided by another embodiment of the present invention.
  • the processor and the hardware digital certificate module are configured as two independent hardware devices.
  • the hardware digital certificate module controls the input and output devices to realize the processor and input
  • the hardware isolation of the output device eliminates the risk of false transaction information being confirmed and improves the transaction security of online banking.
  • a hardware digital certificate module is embedded in a smart terminal.
  • the smart terminal includes, but is not limited to, a computer, a smart phone, a tablet, or a handheld computer (Personal Digital Assistant, PDA) and other terminal equipment.
  • Fig. 1 shows a block diagram of the hardware structure of an intelligent terminal provided by an embodiment of the present invention. For ease of description, only the parts related to this embodiment are shown.
  • the terminal includes a processor 11, a conversion module 12, a hardware digital certificate module 13, and an input and output device 14.
  • the processor 11 is the computing core and control core of the smart terminal, and the smart system (such as the android system, iOS system) can be built on the hardware environment with the processor 11 as the core, so as to realize the smart terminal of the online banking client. Operation in the system.
  • the smart system such as the android system, iOS system
  • the hardware digital certificate module 13 is a hardware device with a built-in single-chip microcomputer or smart card chip, which has a certain storage space, can store the user's private key and digital certificate, and uses its built-in public key algorithm to authenticate the user's identity.
  • a common hardware digital certificate module is USB Key, which is a hardware digital certificate that uses a USB interface.
  • the hardware digital certificate module 13 is a device embedded in the smart terminal.
  • the processor 11 and the hardware digital certificate module 13 are two independent hardware devices that are connected to the conversion module 12 at the same time, and the conversion module 12 is connected to the input/output device 14, and the conversion module 12 is in the processor
  • the control right of the input/output device 14 is switched between the hardware digital certificate module 11 and the hardware digital certificate module 13, so as to realize the hardware isolation between the processor 11 and the input/output device 14 in the transaction confirmation process.
  • the input and output device 14 may be a touch screen, or the input part of the input and output device 14 may be understood as a keyboard, a mouse, a microphone, etc., and the output part may be understood as a display screen, a display, a speaker, etc.
  • the processor 11 and the hardware digital certificate module 13 can be connected to the conversion module 12 through their own dedicated and independent hardware channels. Then the conversion module 12 can distinguish between two different hardware channels. It is recognized whether the processor 11 or the hardware digital certificate module 12 is currently communicating with it.
  • the conversion module 12 can identify whether the processor 11 or the hardware digital certificate module 12 is currently communicating with it by distinguishing different communication protocols.
  • the conversion module 12 may also be a hardware device integrated in the hardware digital certificate module 13, thereby reducing the design size of the circuit board, which is beneficial to the miniaturization of the product.
  • the smart terminal may further include a prompt module 15 connected to the conversion module 12, and the prompt module includes an LED lamp or a buzzer or an independent prompt display screen.
  • the prompt module 15 is only controlled by the conversion module 12. While the conversion module 12 switches the control of the input and output device 14 to the hardware digital certificate module 13, the prompt module 15 can use LED lights to light up or flash, The buzzer works or lights up the independent display screen, etc., and once the control of the input and output device 14 is switched back to the processor 11, the work of the prompt module 15 is stopped, thereby prompting the ownership of the control of the input and output device .
  • FIG. 4 shows an implementation flowchart of an identity authentication method provided by an embodiment of the present invention, which is described in detail as follows:
  • the processor inputs the key data output by the online banking client to the conversion module.
  • Online banking client that is, the bank uses Internet technology to provide customers with financial services such as account opening, inquiry, reconciliation, intra-bank transfer, inter-bank transfer, credit, online securities, investment and wealth management and other financial services applications through the Internet.
  • financial services such as account opening, inquiry, reconciliation, intra-bank transfer, inter-bank transfer, credit, online securities, investment and wealth management and other financial services applications through the Internet.
  • the online banking client terminal needs to output key data for the user to confirm before finally completing the transaction. For example, a user purchases goods on a shopping website and makes an online payment through an online banking client.
  • the online banking client needs to display the shopping website’s merchant name and transaction amount and other key data output to the user; another example ,
  • the key data can also include the user name and password of the current online bank account To Code or biometrics such as fingerprints, iris, face recognition, etc., for the user to confirm whether the current transaction is his account.
  • biometrics such as fingerprints, iris, face recognition, etc.
  • the operating system can call a background thread to monitor the output data of the online banking client.
  • the processor When monitoring the output of key data from the online banking client, the processor first inputs the key data to the conversion module.
  • the conversion module switches the control right of the input and output device to the hardware digital certificate module, so that the hardware digital certificate module performs transaction confirmation based on the key data.
  • the hardware digital certificate module obtains the control right of the input and output device, and outputs the received key data to the input and output device through the conversion module for display (for example, the transaction information in the key data and the user name currently logged in the online bank account are output Display), and at the same time, it receives the input content of the input and output device via the conversion module (for example, the user enters "confirm” or "cancel” on the input and output device to confirm the transaction information, or the user enters the user password on the input and output device to confirm the transaction information. Indicates confirmation of transaction information), thereby completing the transaction confirmation process and obtaining the confirmation result.
  • the conversion module communicates with the processor through the hardware channel corresponding to the processor, and communicates with the hardware digital certificate module through the hardware channel corresponding to the hardware digital certificate module .
  • the conversion module receives the display data from the hardware channel corresponding to the hardware digital certificate module, sends the display data to the input and output device for display, and returns the input data of the input and output device to the hardware digital certificate module through the hardware channel. That is, when the conversion module receives the key data input by the processor, the conversion module will switch the control of the input and output device to the hardware digital certificate module. At this time, the conversion module only transfers data from the hardware channel corresponding to the hardware digital certificate module. The data is sent to the input and output device for display. At the same time, for the data returned by the input and output device, the conversion module only returns the data to the hardware digital certificate module through the hardware channel corresponding to the hardware digital certificate module for processing.
  • the conversion module communicates with the processor through the pre-appointed first communication protocol, and communicates with the hardware digital certificate module through the pre-appointed second communication protocol , So as to distinguish whether it is the processor or the hardware digital certificate module that is currently communicating with it.
  • the conversion module receives the display data conforming to the communication protocol of the hardware digital certificate module, sends the display data to the input and output device for display, and returns the input data of the input and output device to the hardware in a format conforming to the communication protocol of the hardware digital certificate module.
  • Digital certificate module is the display data conforming to the communication protocol of the hardware digital certificate module.
  • the hardware digital certificate module returns a confirmation result to the conversion module.
  • the conversion module sends the confirmation result to the processor so that the online banking client can process the transaction data according to the confirmation result.
  • the hardware digital certificate module After obtaining the confirmation result, the hardware digital certificate module returns the confirmation result to the conversion module.
  • the conversion module receives the confirmation result, it knows that the transaction confirmation process is over, the conversion module sends the confirmation result to the processor, and the processor is receiving the confirmation result.
  • the confirmation result is fed back to the online banking client.
  • the confirmation result may also include a digital signature generated in the hardware digital certificate module and representing user identity authentication.
  • the online banking client uses the confirmation result to communicate with the online banking server, and finally the entire transaction process is completed.
  • the method further includes:
  • the conversion module switches the control right of the input/output device to the processor.
  • the conversion module receives the display data from the hardware channel corresponding to the processor, and sends the display data to the input and output device for display. And the input data of the input and output device is returned to the processor through the hardware channel. That is, when the conversion module receives the confirmation result returned by the hardware digital certificate module, the conversion module switches the control of the input and output device back to the processor. At this time, the conversion module only sends the data from the hardware channel corresponding to the processor to The input and output device displays, and at the same time, for the data returned by the input and output device, the conversion module only returns the data to the processor for processing through the hardware channel corresponding to the processor.
  • the conversion module receives the display data conforming to the processor communication protocol, and sends the display data to the input To
  • the output device displays and returns the input data of the input and output device to the processor in a format that conforms to the processor communication protocol.
  • the input and output devices in the transaction confirmation process are completely controlled by the security chip device in the hardware digital certificate module, it can ensure that the transaction information finally displayed on the screen that requires the user to confirm is true, and it is also guaranteed to be returned to The user confirms that the information on the online banking server is true, and not false data generated by viruses or Trojan horse programs implanted in the operating system, thereby ensuring the security of online banking transactions and avoiding unnecessary property losses for users.
  • the method further includes:
  • the conversion module terminates the operation of the prompt module.
  • the conversion module after the conversion module switches the control of the input and output device to the hardware digital certificate module, the conversion module triggers the prompt module to start working, and the prompt module can use the LED light to light up or flash, and the buzzer to work or light up.
  • Independent prompts work by means of display screens, etc., and once the control of the input and output devices is switched back to the processor, the work of the prompting module is stopped.
  • the user Based on the prompt effect of the prompt module, the user can confirm that the current input and output device has been controlled by the hardware digital certificate module, and the transaction environment is under relatively safe conditions, and the transaction can be confirmed with peace of mind, thus bringing double security to the safe progress of the transaction Guaranteed.
  • the functions of the modules involved in the smart terminal provided in the embodiment of the present invention are as follows:
  • the processor is used to input key data output by the online banking client to the conversion module;
  • the conversion module is used to send the key data to the hardware digital certificate module
  • the conversion module is further configured to switch the control right of the input and output device to the hardware digital certificate module, so that the hardware digital certificate module performs transaction confirmation based on the key data;
  • the conversion module is further configured to send the confirmation result to the processor, so that the online banking client can process transaction data according to the confirmation result.
  • the processor is further configured to, after the conversion module sends the confirmation result to the processor, the conversion module to switch the control right of the input/output device to the processor.
  • the processor and the hardware digital certificate module are configured as two independent hardware devices.
  • the hardware digital certificate controls the input and output devices to realize the processor and the input and output.
  • the hardware isolation of the device eliminates the risk of false transaction information being confirmed, and improves the transaction security of online banking.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本发明适用于信息安全技术领域,提供了一种智能终端及身份认证方法,包括处理器、转换模块、硬件数字证书模块和输入输出装置,所述处理器与所述硬件数字证书模块为相互独立的硬件装置;所述转换模块同时与所述处理器、所述硬件数字证书模块连接;所述输入输出装置与所述转换模块连接;所述转换模块用于在交易确认过程中将所述输入输出装置的控制权切换给所述硬件数字证书模块。本发明杜绝了虚假交易信息被确认的风险,提高了网上银行的交易安全性。

Description

一种智能终端及身份认证方法 技术领域
本发明属于信息安全技术领域,尤其涉及一种智能终端及身份认证方法。
背景技术
网上银行通过互联网向用户提供各种类型的金融服务,使用户足不出户就能够方便快捷地办理银行业务。各网上银行大多采用硬件数字证书的方式完成交易过程中的身份认证,在硬件数字证书内部存放着代表用户唯一身份的数字证书和用户私钥,上述存放的信息终身不可导出到硬件数字证书的外部,网上银行所有业务所涉及的身份认证过程均在该硬件数字证书内部完成,以保证身份认证的可信性,保障网上银行的交易安全。
目前,已有一体式的身份认证方案,即,将硬件数字证书集成在智能终端内部,其优点为无需用户额外携带硬件装置。然而,该方式中智能终端的显示屏及按键装置完全由智能终端的处理器进行控制,不法分子可能通过病毒、木马等恶意程序将虚假交易页面呈现给用户,来诱骗用户在不知情的情况下进行身份认证,确认虚假交易信息,完成恶意交易,从而造成用户的财产损失。
对发明的公开
技术问题
本发明实施例的目的在于提供一种智能终端,旨在解决目前网上银行的身份认证方式存在诱导用户确认虚假交易的风险,安全性差的问题。
问题的解决方案
技术解决方案
本发明实施例是这样实现的,一种智能终端,包括处理器、转换模块、硬件数字证书模块和输入输出装置,
所述处理器与所述硬件数字证书模块为相互独立的硬件装置;
所述转换模块同时与所述处理器、所述硬件数字证书模块连接;
所述输入输出装置与所述转换模块连接;
所述转换模块用于在交易确认过程中将所述输入输出装置的控制权切换给所述硬件数字证书模块。
本发明实施例的另一目的在于提供一种基于上述智能终端的身份认证方法,包括:
所述处理器将网上银行客户端输出的关键数据输入至所述转换模块;
所述转换模块将所述关键数据发送给所述硬件数字证书模块;
所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块,以使所述硬件数字证书模块基于所述关键数据执行交易确认;
所述硬件数字证书模块向所述转换模块返回确认结果;
所述转换模块将所述确认结果发送给所述处理器,以使所述网上银行客户端根据所述确认结果处理交易数据。
发明的有益效果
有益效果
在本发明实施例中,将处理器和硬件数字证书模块配置为两个独立的硬件装置,在进行交易确认的过程中,由硬件数字证书对输入输出装置进行控制,实现了处理器与输入输出装置的硬件隔离,杜绝了虚假交易信息被确认的风险,提高了网上银行的交易安全性。
对附图的简要说明
附图说明
图1是本发明实施例提供的智能终端的硬件结构框图;
图2是本发明另一实施例提供的智能终端的硬件结构框图;
图3是本发明又一实施例提供的智能终端的硬件结构框图;
图4是本发明实施例提供的身份认证方法的实现流程图;
图5是本发明另一实施例提供的身份认证方法的实现流程图。
发明实施例
本发明的实施方式
为了使本发明的目的、技术方案及优点更加清楚明白,以下结合附图及实施例 ,对本发明进行进一步详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不用于限定本发明。
在本发明实施例中,将处理器和硬件数字证书模块配置为两个独立的硬件装置,在进行交易确认的过程中,由硬件数字证书模块对输入输出装置进行控制,实现了处理器与输入输出装置的硬件隔离,杜绝了虚假交易信息被确认的风险,提高了网上银行的交易安全性。
需要说明的是,本发明实施例所基于的是硬件数字证书模块内嵌在智能终端内部的一体化方案,其中,智能终端包括但不限于计算机、智能手机、平板或者掌上电脑(Personal Digital Assistant,PDA)等终端设备。图1示出了本发明实施例提供的智能终端的硬件结构框图。为了便于说明,仅示出了与本实施例相关的部分。
参照图1,该终端包括了处理器11、转换模块12、硬件数字证书模块13和输入输出装置14。
其中,处理器11为智能终端的运算核心和控制核心,智能系统(例如android系统、iOS系统)可搭建于以处理器11为核心所搭载的硬件环境之上,从而实现网上银行客户端在智能系统中的运行。
硬件数字证书模块13为内置单片机或者智能卡芯片的硬件设备,具备一定的存储空间,可以存储用户的私钥以及数字证书,并利用其内置的公钥算法实现对用户身份的认证。常见的硬件数字证书模块为USB Key,其为一种采用USB接口的硬件数字证书。在本发明实施例中,区别于常见的与终端硬件分离的USB Key,硬件数字证书模块13为内嵌于智能终端内部的装置。
在本发明实施例中,处理器11和硬件数字证书模块13作为两个相互独立的硬件装置,同时与转换模块12建立连接,而转换模块12与输入输出装置14相连,转换模块12在处理器11和硬件数字证书模块13之间对输入输出装置14的控制权进行切换,从而在交易确认过程中实现处理器11与输入输出装置14的硬件隔离。
输入输出装置14可以为触控屏幕,或者,输入输出装置14中的输入部分可以被理解为键盘、鼠标、麦克风等,而输出部分可以被理解为显示屏、显示器、扬声器等。
作为本发明的一个实施例,处理器11与硬件数字证书模块13可以分别通过各自专属的、相互独立的硬件通道与转换模块12连接,那么转换模块12通过区别两个不同的硬件通道,就能够识别出当前与之进行通信的是处理器11还是硬件数字证书模块12。
作为本发明的另一实施例,转换模块12可以通过区别互不相同的通信协议,识别出当前与之进行通信的是处理器11还是硬件数字证书模块12。
作为本发明的一个实施例,如图2所示,转换模块12也可以为集成在硬件数字证书模块13内部的硬件装置,由此来缩小电路板的设计尺寸,有利于产品的小型化。
作为本发明的一个实施例,如图3所示,该智能终端还可以包括与转换模块12连接的提示模块15,所述提示模块包括LED灯或者蜂鸣器或者独立的提示用显示屏。在本实施例中,提示模块15只受控于转换模块12,在转换模块12将输入输出装置14的控制权切换为硬件数字证书模块13期间,提示模块15可以采用LED灯点亮或闪烁、蜂鸣器工作或者点亮独立的显示屏等方式进行工作,而一旦输入输出装置14的控制权切换回处理器11,提示模块15的工作停止,从而起到提示输入输出装置控制权归属的作用。
接下来结合图1至图3所示的智能终端的硬件结构框图,对本发明实施例提供的身份认证方法进行详细阐述。图4示出了本发明实施例提供的身份认证方法的实现流程图,详述如下:
在S401中,所述处理器将网上银行客户端输出的关键数据输入至所述转换模块。
网上银行客户端,即银行利用Intemet技术,通过Internet向客户提供开户、查询、对账、行内转账、跨行转账、信贷、网上证券、投资理财等金融服务的应用程序,通常,当用户通过操作网上银行客户端办理金融业务时,最终需要由网上银行客户端输出关键数据以供用户确认,才能最终完成交易。例如,用户在购物网站上购买商品,并通过网上银行客户端进行网上支付,那么在交易过程中,网上银行客户端需要将购物网站的商户名以及交易金额等关键数据输出展示给用户;又例如,关键数据还可以包括当前登录网上银行账户的用户名、密 码或指纹、虹膜、人脸识别等生物特征等,以供用户确认当前进行交易的是否为本人账户。当用户确认完交易信息之后,再使用USB Key等硬件数字证书内部的私钥进行数字签名,完成身份认证,最终完成整个交易过程。
在本实施例中,操作系统可以调用后台线程对网上银行客户端的输出数据进行监听,当监听到网上银行客户端输出关键数据时,处理器首先将该关键数据输入给转换模块。
在S402中,所述转换模块将所述关键数据发送给所述硬件数字证书模块。
一旦转换模块接收到处理器输入的关键数据,转换模块就需要对当前输入输出装置的控制权进行切换,将该控制权由处理器切换为硬件数字证书模块。首先,转换模块需要将该关键数据发送给硬件数字证书模块。
在S403中,所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块,以使所述硬件数字证书模块基于所述关键数据执行交易确认。
硬件数字证书模块获取输入输出装置的控制权,其经由转换模块将接收到的关键数据输出到输入输出装置上进行显示(例如,将关键数据中的交易信息以及当前登录网上银行账户的用户名输出显示),同时,其经由转换模块接收输入输出装置的输入内容(例如,用户在输入输出装置上输入“确认”或者“取消”以确认交易信息,或者,用户在输入输出装置上输入用户密码来表示确认交易信息),从而完成交易确认过程,获取到确认结果。
当处理器和硬件数字证书模块分别通过相互独立的硬件通道与转换模块连接时,转换模块通过处理器对应的硬件通道与处理器通信,通过硬件数字证书模块对应的硬件通道与硬件数字证书模块通信。在S403中,转换模块接收来自硬件数字证书模块对应的硬件通道的显示数据,将该显示数据发送至输入输出装置显示,并将输入输出装置输入数据通过该硬件通道返回给硬件数字证书模块。即,在转换模块接收到处理器输入的关键数据开始,转换模块就将输入输出装置的控制权切换给硬件数字证书模块,此时,转换模块只将来自硬件数字证书模块对应的硬件通道的数据发送至输入输出装置进行显示,同时,对于输入输出装置返回的数据,转换模块也只将该数据通过硬件数字证书模块对应的硬件通道返回给硬件数字证书模块进行处理。
当处理器和硬件数字证书模块通过不同的通信协议与转换模块通信时,转换模块通过预先约定好的第一通信协议与处理器通信,通过预先约定好的第二通信协议与硬件数字证书模块通信,从而区分当前与之进行通信的是处理器还是硬件数字证书模块。在S403中,转换模块接收符合硬件数字证书模块通信协议的显示数据,将该显示数据发送至输入输出装置显示,并将输入输出装置的输入数据以符合硬件数字证书模块通信协议的格式返回给硬件数字证书模块。
在S404中,所述硬件数字证书模块向所述转换模块返回确认结果。
在S405中,所述转换模块将所述确认结果发送给所述处理器,以使所述网上银行客户端根据所述确认结果处理交易数据。
在获取到确认结果之后,硬件数字证书模块将该确认结果返回给转换模块,当转换模块接收到确认结果,即获知交易确认过程结束,转换模块将该确认结果发送给处理器,处理器在接收到该确认结果之后,将该确认结果反馈给网上银行客户端。其中,该确认结果也可以包括在硬件数字证书模块中生成的、代表了用户身份认证的数字签名,网上银行客户端利用该确认结果与网上银行服务端进行通信,最终整个交易过程完成。
作为本发明的一个实施例,如图5所示,在S405所述转换模块将所述确认结果发送给所述处理器之后,所述方法还包括:
S406,所述转换模块将所述输入输出装置的控制权切换至所述处理器。
当处理器和硬件数字证书模块分别通过相互独立的硬件通道与转换模块连接时,在S406中,转换模块接收来自处理器对应的硬件通道的显示数据,将该显示数据发送至输入输出装置显示,并将输入输出装置的输入数据通过该硬件通道返回处理器。即,在转换模块接收到硬件数字证书模块返回的确认结果开始,转换模块就将输入输出装置的控制权切换回处理器,此时,转换模块只将来自处理器对应的硬件通道的数据发送至输入输出装置进行显示,同时,对于输入输出装置返回的数据,转换模块也只将该数据通过处理器对应的硬件通道返回给处理器进行处理。
当处理器和硬件数字证书模块通过不同的通信协议与转换模块通信时,在S406中,转换模块接收符合处理器通信协议的显示数据,将该显示数据发送至输入 输出装置显示,并将输入输出装置的输入数据以符合处理器通信协议的格式返回给处理器。
由于上述交易确认过程中的输入输出装置完全由硬件数字证书模块内的安全芯片装置来进行控制,因此,可以保证最终显示在屏幕上需要用户进行确认的交易信息是真实的,也保证最终返回给网上银行服务端的用户确认信息是真实的,而非病毒或者植入操作系统中的木马程序所生成的虚假数据,由此保证了网上银行的交易安全性,避免了用户不必要的财产损失。
作为本发明的一个实施例,当如图3所示智能终端还包括了提示模块时,在S403所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块期间,所述方法还包括:
所述转换模块触发提示模块工作。
而在S406所述转换模块将所述输入输出装置的控制权切换至所述处理器期间,所述方法还包括:
所述转换模块终止所述提示模块工作。
在本实施例中,当转换模块将输入输出装置的控制权切换为硬件数字证书模块之后,转换模块触发提示模块开始工作,提示模块可以采用LED灯点亮或闪烁、蜂鸣器工作或者点亮独立的提示用显示屏等方式进行工作,而一旦输入输出装置的控制权切换回处理器,提示模块的工作停止。基于该提示模块的提示效果,用户可以确认当前输入输出装置已被硬件数字证书模块控制,交易环境处于相对安全的条件之下,可以安心确认交易,由此为交易的安全进行带来了双重安全保障。
结合本发明实施例提供的身份认证方法,本发明实施例提供的智能终端所涉及的各模块的功能如下:
所述处理器用于将网上银行客户端输出的关键数据输入至所述转换模块;
所述转换模块用于将所述关键数据发送给所述硬件数字证书模块;
所述转换模块还用于将所述输入输出装置的控制权切换至所述硬件数字证书模块,以使所述硬件数字证书模块基于所述关键数据执行交易确认;
所述硬件数字证书模块还用于向所述转换模块返回确认结果;
所述转换模块还用于将所述确认结果发送给所述处理器,以使所述网上银行客户端根据所述确认结果处理交易数据。
可选地,所述处理器还用于在所述转换模块将所述确认结果发送给所述处理器之后,所述转换模块将所述输入输出装置的控制权切换至所述处理器。
可选地,所述转换模块还用于在所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块期间,触发所述提示模块工作,以及在所述转换模块将所述输入输出装置的控制权切换至所述处理器期间,终止所述提示模块工作。
可选地,所述转换模块通过不同的硬件通道或者通过不同的通信协议区分所述处理器和所述硬件数字证书模块。
在本发明实施例中,将处理器和硬件数字证书模块配置为两个独立的硬件装置,在进行交易确认的过程中,由硬件数字证书对输入输出装置进行控制,实现了处理器与输入输出装置的硬件隔离,杜绝了虚假交易信息被确认的风险,提高了网上银行的交易安全性。
以上所述仅为本发明的较佳实施例而已,并不用以限制本发明,凡在本发明的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本发明的保护范围之内。

Claims (8)

  1. 一种智能终端,其特征在于,包括处理器、转换模块、硬件数字证书模块和输入输出装置,
    所述处理器与所述硬件数字证书模块为相互独立的硬件装置;
    所述转换模块同时与所述处理器、所述硬件数字证书模块连接;
    所述输入输出装置与所述转换模块连接;
    所述转换模块用于在交易确认过程中将所述输入输出装置的控制权切换给所述硬件数字证书模块。
  2. 如权利要求1所述的终端,其特征在于,所述处理器和所述硬件数字证书模块分别通过相互独立的硬件通道与所述转换模块连接。
  3. 如权利要求1所述的终端,其特征在于,所述终端还包括:
    与所述转换模块连接的提示模块,所述提示模块包括LED灯、蜂鸣器或者显示屏。
  4. 如权利要求1所述的终端,其特征在于,所述转换模块为集成在所述硬件数字证书模块内部的硬件装置。
  5. 一种基于权利要求1-4任一项所述的智能终端的身份认证方法,其特征在于,包括:
    所述处理器将网上银行客户端输出的关键数据输入至所述转换模块;
    所述转换模块将所述关键数据发送给所述硬件数字证书模块;
    所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块,以使所述硬件数字证书模块基于所述关键数据执行交易确认;
    所述硬件数字证书模块向所述转换模块返回确认结果;
    所述转换模块将所述确认结果发送给所述处理器,以使所述网上银行客户端根据所述确认结果处理交易数据。
  6. 如权利要求5所述的方法,其特征在于,在所述转换模块将所述确认结果发送给所述处理器之后,所述方法还包括: 所述转换模块将所述输入输出装置的控制权切换至所述处理器。
  7. 如权利要求6所述的方法,其特征在于,在所述转换模块将所述输入输出装置的控制权切换至所述硬件数字证书模块期间,所述方法还包括:
    所述转换模块触发提示模块工作;
    在所述转换模块将所述输入输出装置的控制权切换至所述处理器期间,所述方法还包括:
    所述转换模块终止所述提示模块工作。
  8. 如权利要求5所述的方法,其特征在于,所述转换模块通过不同的硬件通道或者通过不同的通信协议区分所述处理器和所述硬件数字证书模块。
PCT/CN2015/070063 2014-10-31 2015-01-04 一种智能终端及身份认证方法 WO2016065739A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410607961.9A CN104393995B (zh) 2014-10-31 2014-10-31 一种智能终端及身份认证方法
CN201410607961.9 2014-10-31

Publications (1)

Publication Number Publication Date
WO2016065739A1 true WO2016065739A1 (zh) 2016-05-06

Family

ID=52611831

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/070063 WO2016065739A1 (zh) 2014-10-31 2015-01-04 一种智能终端及身份认证方法

Country Status (2)

Country Link
CN (1) CN104393995B (zh)
WO (1) WO2016065739A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105847007A (zh) * 2016-03-17 2016-08-10 北京众云在线科技有限公司 用于终端设备的身份验证方法和计算机设备
CN105894274A (zh) * 2016-04-05 2016-08-24 杭州复杂美科技有限公司 手机上整合加密芯片的支付方法
RU2634174C1 (ru) * 2016-10-10 2017-10-24 Акционерное общество "Лаборатория Касперского" Система и способ выполнения банковской транзакции
CN108200075B (zh) * 2018-01-17 2021-07-13 上海方付通商务服务有限公司 一种身份认证方法、系统、终端及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090036164A1 (en) * 2007-08-02 2009-02-05 Red Hat, Inc. Smart card accessible over a personal area network
CN101527070A (zh) * 2009-04-15 2009-09-09 唐宇良 安全交易控制方法和系统
CN201548998U (zh) * 2009-09-15 2010-08-11 中信银行股份有限公司 一种辅助实现USB Key安全性的装置
CN102231179A (zh) * 2011-06-20 2011-11-02 北京思创银联科技股份有限公司 便携式个人服务终端

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7895443B2 (en) * 2002-11-05 2011-02-22 Safenet, Inc. Secure authentication using hardware token and computer fingerprint
CN102300211A (zh) * 2010-06-22 2011-12-28 国民技术股份有限公司 一种具有智能密钥功能的移动终端和智能密钥系统及方法
CN103391374B (zh) * 2013-08-08 2015-07-08 北京邮电大学 一种支持无缝切换的双系统终端
CN103729605A (zh) * 2014-01-13 2014-04-16 深圳市中航软件技术有限公司 基于触摸屏的密码输入方法和触控终端
CN103986837B (zh) * 2014-05-28 2017-11-10 天地融科技股份有限公司 信息处理方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090036164A1 (en) * 2007-08-02 2009-02-05 Red Hat, Inc. Smart card accessible over a personal area network
CN101527070A (zh) * 2009-04-15 2009-09-09 唐宇良 安全交易控制方法和系统
CN201548998U (zh) * 2009-09-15 2010-08-11 中信银行股份有限公司 一种辅助实现USB Key安全性的装置
CN102231179A (zh) * 2011-06-20 2011-11-02 北京思创银联科技股份有限公司 便携式个人服务终端

Also Published As

Publication number Publication date
CN104393995B (zh) 2018-12-18
CN104393995A (zh) 2015-03-04

Similar Documents

Publication Publication Date Title
CN202210326U (zh) 一种带键盘的个人支付终端
WO2020107233A1 (zh) 基于区块链的钱包系统及钱包使用方法、以及存储介质
CN110555706A (zh) 基于安全单元和可信执行环境的人脸支付安全方法及平台
US11824642B2 (en) Systems and methods for provisioning biometric image templates to devices for use in user authentication
JP6032626B2 (ja) Nfc認証カードを用いた認証方法
WO2020107232A1 (zh) 一种基于区块链的硬件钱包、交易系统以及存储介质
US20180150846A1 (en) System and method for utilizing biometric data in a payment transaction
KR101812002B1 (ko) 서비스를 인증하기 위한 방법 및 시스템
WO2019179394A1 (zh) 一种获取身份信息的方法、终端及验证服务器
WO2016150028A1 (zh) 一种用于移动认证的方法、设备与系统
CN101321069A (zh) 手机生物身份证明制作、认证方法及其认证系统
US20190065919A1 (en) Payment Card With Integrated Biometric Sensor And Power Source
US10489565B2 (en) Compromise alert and reissuance
WO2016065739A1 (zh) 一种智能终端及身份认证方法
WO2017024766A1 (zh) 一种显示装置、移动设备和显示方法
TWI626607B (zh) Smart card with dynamic token OTP function and working method thereof
CN103761806A (zh) 一种用于移动终端的金融安全系统
WO2016086708A1 (zh) 支付验证方法、装置及系统
US20190012676A1 (en) System and method for utilizing secondary user biometric data for user authorization
KR20180001455A (ko) 구매 트랜잭션을 인증하는 모바일 장치 및 그 방법
TW201523315A (zh) 虛擬卡認證系統及其認證裝置與電腦程式產品
TW201725529A (zh) 供個人以行動裝置進行網路交易之攜帶裝置及其應用方法
KR20110005612A (ko) 생체 인식을 이용한 오티피 운영 방법 및 시스템과 이를 위한 오티피 장치 및 기록매체
KR20110029033A (ko) 범용 가입자 식별 모듈 정보를 이용한 공인 인증서 발급방법 및 시스템과 이를 위한 기록매체
TWM584946U (zh) 匯款系統

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15853815

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15853815

Country of ref document: EP

Kind code of ref document: A1