WO2018059262A1 - 用于hce模式的数据加密方法 - Google Patents
用于hce模式的数据加密方法 Download PDFInfo
- Publication number
- WO2018059262A1 WO2018059262A1 PCT/CN2017/102076 CN2017102076W WO2018059262A1 WO 2018059262 A1 WO2018059262 A1 WO 2018059262A1 CN 2017102076 W CN2017102076 W CN 2017102076W WO 2018059262 A1 WO2018059262 A1 WO 2018059262A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- security information
- information interaction
- application
- key
- encryption method
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
Definitions
- the present invention relates to a data encryption method, and more particularly to a data encryption method for an HCE mode.
- the mobile terminal typically includes an application processor, an NFC controller, and a security unit (SE), such as in the form of an SD card or an SE chip. Used to store sensitive information (such as data encryption keys, etc.).
- SE security unit
- the above conventional mobile security information interaction scheme has the following problems: since a separate hardware security unit is required, the cost is high and the compatibility complexity is increased (for example, every additional security carrier needs to be regression tested for all applications, and Each additional application also requires regression testing of all security carriers).
- a mobile security information exchange scheme based on HCE (Host Card Emulation) mode is proposed.
- the mobile terminal only includes an application processor and an NFC controller, and is based on security stored at the mobile terminal.
- the application ciphertext key (such as transaction key UDK) in the application encrypts sensitive information (such as transaction data, application transaction counters, etc.) to ensure security during information interaction.
- the above-mentioned HCE mode-based mobile security information interaction scheme has a problem that since the application ciphertext key is stored in the security application at the mobile terminal and can be used indefinitely, there is a risk of potential malicious misappropriation. Therefore, the safety is low.
- the present invention proposes a data encryption method for the HCE mode with high security.
- a data encryption method for an HCE mode comprising the following steps:
- the Key Management and Data Processing Server generates one or more restriction keys for the security information interaction application residing on the particular mobile terminal and sends the generated one or more restriction keys to The security information is interactively applied;
- the security information interaction application when performing data interaction for a security information interaction count value according to a user instruction, the security information interaction application is based on one of the one or more restriction keys to encrypt security information interaction data to generate an application Ciphertext, and sending the application ciphertext to the key management and data processing server;
- the key management and data processing server checks the validity and legality of the application ciphertext, and performs subsequent and the security information after the verification succeeds Interaction data processing operations.
- the step (A1) further comprises: the key management and data processing server interacting with the application based on the security information or periodically periodically counting the values according to the security information.
- the preset range generates the one or more restriction keys.
- the step (A2) further comprises: the security information interaction application transmitting the application ciphertext to the key management and data processing server via a near field communication channel.
- the step (A1) further comprises: the key management and data processing server storing an application ciphertext key associated with the security information interaction application, and based on the The one or more restriction keys are generated using a ciphertext key.
- the security information interaction application stores the one or more restriction keys in a trusted execution environment or a white-box encryption library provided by the mobile terminal.
- each of the one or more restriction keys is bound to a security information interaction count value, that is, the security information interaction application is initiated based on current security information.
- the security information of the interaction count value is used when interacting with the current security information.
- a restricted key that is bound.
- the security information interaction application increments the security information interaction count value maintained by it by one each time the associated set of security information interaction processes is completed.
- each of the one or more restriction keys fails after being used once.
- the key management and data processing server generates a restriction key corresponding thereto based on each security information interaction count value, and the security information interaction application is initiated based on the current
- the security information of the security information interaction count value is generated by using a restriction key bound to the current security information interaction count value to generate the application ciphertext to ensure the uniqueness of each application ciphertext.
- the step (A1) further comprises: generating the one or more restriction keys in the following manner: (1) using an application associated with the security information interaction application The ciphertext key performs a predetermined arithmetic operation on the predetermined character string to obtain an intermediate key; (2) uses the intermediate key to perform each of a specific range of security information interaction count values and their inverted values A predetermined arithmetic operation to obtain a restriction key respectively corresponding to each of the specific range of security information interaction count values.
- the step (A2) further comprises: setting an expiration date for each of the one or more restriction keys, and not using a certain restriction key if the expiration date is exceeded , the limit key is invalid.
- the user is able to add an additional cryptographic operation based on the biometric identification and/or unlocking password to the one or more restriction keys stored by the security information interaction application.
- the data encryption method for HCE mode disclosed by the present invention has the advantage that since the restriction key can only be used once, it can be stored in a trusted execution environment or a white box database provided by the mobile terminal without independence.
- the hardware security unit has low cost and can avoid or mitigate the risk of the key being maliciously stolen, so it has high security.
- FIG. 1 is a flow chart of a data encryption method for an HCE mode in accordance with an embodiment of the present invention.
- the data encryption method for HCE mode disclosed by the present invention includes the following steps: (A1) Key management and data processing server for security information interaction application resident and running on a specific mobile terminal Generating one or more restriction keys (LUK) and transmitting the generated one or more restriction keys to the security information interaction application; (A2) performing a counter value for a security information interaction according to user instructions
- the security information interaction application interacts with the encrypted security information (eg, transaction information, etc.) based on one of the one or more restriction keys to generate an application when the data is interactive (eg, the value of the application transaction counter ATC) a ciphertext (for example, an ARQC ciphertext in the financial field), and transmitting the application ciphertext to the key management and data processing server; (A3) after receiving the application ciphertext, the key management And the data processing server verifies the validity and legality of the application ciphertext (for example
- the step (A1) further includes: the key management and data processing server interacting with the request or periodicity of the application based on the security information.
- the one or more restriction keys are generated according to a preset range of security information interaction count values.
- the step (A2) further includes: the security information interaction application transmitting the application ciphertext to the Key management and data processing server.
- the step (A1) further includes: the key management and data processing server storing an application associated with the security information interaction application a ciphertext key (UDK), and generating the one or more restriction keys based on the application ciphertext key.
- the key management and data processing server storing an application associated with the security information interaction application a ciphertext key (UDK), and generating the one or more restriction keys based on the application ciphertext key.
- the security information interaction application stores the one or more in a trusted execution environment or a white-box encryption library provided by the mobile terminal. Limit the key.
- each of the one or more restriction keys is tied to a security information interaction counter value (eg, the value of the application transaction counter ATC) Determining (ie, each of the plurality of restriction keys has a one-to-one correspondence with each of the plurality of security information interaction count values), that is, the security information interaction application is initiating an interaction based on the current security information.
- the security information is exchanged using a restricted key that is bound to the current security information interaction count value.
- the security information interaction application is configured each time after completing an associated set of security information interaction processes (eg, completing a transaction process) The value of the security information interaction count of the maintenance is increased by one.
- each of the one or more restriction keys fails after being used once.
- the key management and data processing server generates a restriction key corresponding thereto based on each security information interaction count value
- the security The sexual information interaction application generates the application ciphertext by using a restriction key bound to the current security information interaction count value when initiating the security information interaction based on the current security information interaction count value to ensure each application.
- the uniqueness of ciphertext is a restriction key bound to the current security information interaction count value when initiating the security information interaction based on the current security information interaction count value.
- the step (A1) further comprises: generating the one or more restriction keys in the following manner: (1) use and the security
- the sexual information interaction application is associated with the application ciphertext key pair predetermined string (eg "CCCCYYMMDDHHNN80", where "CCCC” is a parameter update counter, which is set to UDK plus 1 per batch, "YY” is the year, its The range is 00-99, "MM” is the month, the range is 01-12, “DD” is the date, its range is 01-31, “HH” is the hour, its range is 00-23, “NN” is the current Each time the key update is incremented by one in the hour, the current value is the number of parameter updates within one hour, the range is 0x00-0xFF, "80” is a fixed padding bit) Performing a predetermined arithmetic operation (such as a symmetric encryption algorithm) to obtain the middle Key (LUK-A1); (2) a security
- the step (A2) further includes: setting an expiration date for each of the one or more restriction keys, and if some If the restricted key exceeds the validity period and is not used, the restricted key is invalid.
- the user can add the biometric identification and/or unlock password based on the one or more restriction keys stored in the security information interaction application. Additional encryption operations.
- the data encryption method for HCE mode disclosed by the present invention has the following advantages: since the restriction key can only be used once, it can be stored in a trusted execution environment or a white box database provided by the mobile terminal. Without the need for a separate hardware security unit, the cost is low, and the risk of the key being maliciously stolen can be avoided or mitigated, so that it has high security.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
- Telephone Function (AREA)
- Signal Processing For Digital Recording And Reproducing (AREA)
Abstract
本发明提出了用于HCE模式的数据加密方法,所述方法包括:密钥管理及数据处理服务器针对驻留并运行于特定的移动终端上的安全性信息交互应用生成一个或多个限制密钥,并将所生成的一个或多个限制密钥发送至安全性信息交互应用;在根据用户指令进行针对一个安全性信息交互计数值的数据交互时,安全性信息交互应用基于一个或多个限制密钥中的一个加密安全性信息交互数据以生成应用密文,并将应用密文发送至密钥管理及数据处理服务器;在接收到所述应用密文后,密钥管理及数据处理服务器校验应用密文的有效性和合法性,并在验证成功后执行后续的与所述安全性信息交互数据相关联的处理操作。本发明所公开的方法具有高的安全性。
Description
本发明涉及数据加密方法,更具体地,涉及用于HCE模式的数据加密方法。
目前,随着计算机和网络应用的日益广泛以及不同领域的业务种类的日益丰富,使用移动终端(例如智能手机)并经由近场通信技术(例如NFC技术)实施安全性信息交互过程(即对安全性要求较高的信息交互过程,诸如金融领域中的支付交易过程)变得越来越重要。
在常规的基于NFC通信协议的移动式安全性信息交互方案中,移动终端典型地包括应用处理器、NFC控制器以及安全单元(SE),所述安全单元例如是SD卡或SE芯片的形式。用于存储敏感信息(例如数据加密密钥等等)。
然而,上述常规的移动式安全性信息交互方案存在如下问题:由于需要独立的硬件安全单元,故成本较高,并且兼容复杂性增高(例如,每增加一款安全载体需要回归测试所有应用,而每增加一款应用同样需要回归测试所有安全载体)。
为了解决上述问题,基于HCE(Host Card Emulation)模式的移动式安全性信息交互方案被提出,基于该方案,移动终端仅包括应用处理器和NFC控制器,并基于存储于移动终端处的安全性应用中的应用密文密钥(例如交易密钥UDK)加密敏感信息(例如交易数据、应用交易计数器等等)来确保信息交互过程中的安全性。
然而,上述基于HCE模式的移动式安全性信息交互方案存在如下问题:由于应用密文密钥被存储于移动终端处的安全性应用中且能够被无限使用,故存在潜在的被恶意盗用的风险,故安全性较低。
因此,存在如下需求:提供具有高的安全性的用于HCE模式的数据加密方法。
发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了具有高的安全性的用于HCE模式的数据加密方法。
本发明的目的是通过以下技术方案实现的:
一种用于HCE模式的数据加密方法,所述用于HCE模式的数据加密方法包括下列步骤:
(A1)密钥管理及数据处理服务器针对驻留并运行于特定的移动终端上的安全性信息交互应用生成一个或多个限制密钥,并将所生成的一个或多个限制密钥发送至所述安全性信息交互应用;
(A2)在根据用户指令进行针对一个安全性信息交互计数值的数据交互时,所述安全性信息交互应用基于所述一个或多个限制密钥中的一个加密安全性信息交互数据以生成应用密文,并将所述应用密文发送至所述密钥管理及数据处理服务器;
(A3)在接收到所述应用密文后,所述密钥管理及数据处理服务器校验所述应用密文的有效性和合法性,并在验证成功后执行后续的与所述安全性信息交互数据相关联的处理操作。
在上面所公开的方案中,优选地,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器基于所述安全性信息交互应用的请求或者周期性地根据安全性信息交互计数值的预设范围生成所述一个或多个限制密钥。
在上面所公开的方案中,优选地,所述步骤(A2)进一步包括:所述安全性信息交互应用经由近场通信信道将所述应用密文发送至所述密钥管理及数据处理服务器。
在上面所公开的方案中,优选地,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器存储与所述安全性信息交互应用相关联的应用密文密钥,并基于该应用密文密钥生成所述一个或多个限制密钥。
在上面所公开的方案中,优选地,所述安全性信息交互应用在所述移动终端提供的可信执行环境或白盒加密库中存储所述一个或多个限制密钥。
在上面所公开的方案中,优选地,所述一个或多个限制密钥中的每个与一个安全性信息交互计数值绑定,即所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相
绑定的一个限制密钥。
在上面所公开的方案中,优选地,所述安全性信息交互应用在每次完成相关联的一组安全性信息交互过程后将其维护的安全性信息交互计数值加1。
在上面所公开的方案中,优选地,所述一个或多个限制密钥中的每个在被使用一次后均失效。
在上面所公开的方案中,优选地,所述密钥管理及数据处理服务器基于每个安全性信息交互计数值生成与其相对应的限制密钥,并且所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相绑定的一个限制密钥生成所述应用密文,以确保每个应用密文的唯一性。
在上面所公开的方案中,优选地,所述步骤(A1)进一步包括:以如下方式生成所述一个或多个限制密钥:(1)使用与所述安全性信息交互应用相关联的应用密文密钥对预定字符串执行预定的运算操作以获得中间密钥;(2)使用所述中间密钥对特定范围的安全性信息交互计数值中的每个及其取反后的值执行预定的运算操作,以得到与所述特定范围的安全性信息交互计数值中的每个分别对应的限制密钥。
在上面所公开的方案中,优选地,所述步骤(A2)进一步包括:为所述一个或多个限制密钥中的每个设定有效期,并且如果某个限制密钥超过有效期未被使用,则该限制密钥失效。
在上面所公开的方案中,优选地,用户能够对所述安全性信息交互应用存储的所述一个或多个限制密钥增加基于生物识别和/或解锁口令的附加的加密操作。
本发明所公开的用于HCE模式的数据加密方法具有以下优点:由于限制密钥仅能够使用一次,故其可以被存储在移动终端所提供的可信执行环境或白盒数据库中,而无需独立的硬件安全单元,故成本较低,并且能够避免或者减轻密钥被恶意盗用的风险,故具有高的安全性。
结合附图,本发明的技术特征以及优点将会被本领域技术人员更好地理解,其中:
图1是根据本发明的实施例的用于HCE模式的数据加密方法的流程图。
图1是根据本发明的实施例的用于HCE模式的数据加密方法的流程图。如图1所示,本发明所公开的用于HCE模式的数据加密方法包括下列步骤:(A1)密钥管理及数据处理服务器针对驻留并运行于特定的移动终端上的安全性信息交互应用生成一个或多个限制密钥(LUK),并将所生成的一个或多个限制密钥发送至所述安全性信息交互应用;(A2)在根据用户指令进行针对一个安全性信息交互计数值(例如应用交易计数器ATC的值)的数据交互时,所述安全性信息交互应用基于所述一个或多个限制密钥中的一个加密安全性信息交互数据(例如交易信息等等)以生成应用密文(例如金融领域中的ARQC密文),并将所述应用密文发送至所述密钥管理及数据处理服务器;(A3)在接收到所述应用密文后,所述密钥管理及数据处理服务器校验所述应用密文的有效性和合法性(例如以与步骤(A2)所采用的方式相同的方式生成应用密文副本,并随之将所接收的应用密文与应用密文副本相比对),并在验证成功后执行后续的与所述安全性信息交互数据相关联的处理操作。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器基于所述安全性信息交互应用的请求或者周期性地根据安全性信息交互计数值的预设范围生成所述一个或多个限制密钥。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述步骤(A2)进一步包括:所述安全性信息交互应用经由近场通信信道将所述应用密文发送至所述密钥管理及数据处理服务器。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器存储与所述安全性信息交互应用相关联的应用密文密钥(UDK),并基于该应用密文密钥生成所述一个或多个限制密钥。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述安全性信息交互应用在所述移动终端提供的可信执行环境或白盒加密库中存储所述一个或多个限制密钥。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述一个或多个限制密钥中的每个与一个安全性信息交互计数值(例如应用交易计数器ATC的值)绑定(即多个限制密钥中的每个与多个安全性信息交互计数值中的每个具有一一对应关系),即所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相绑定的一个限制密钥。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述安全性信息交互应用在每次完成相关联的一组安全性信息交互过程(例如完成一次交易过程)后将其维护的安全性信息交互计数值加1。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述一个或多个限制密钥中的每个在被使用一次后均失效。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述密钥管理及数据处理服务器基于每个安全性信息交互计数值生成与其相对应的限制密钥,并且所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相绑定的一个限制密钥生成所述应用密文,以确保每个应用密文的唯一性。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述步骤(A1)进一步包括:以如下方式生成所述一个或多个限制密钥:(1)使用与所述安全性信息交互应用相关联的应用密文密钥对预定字符串(例如“CCCCYYMMDDHHNN80”,其中,“CCCC”是参数更新计数器,其每批量次被设置为UDK加1,“YY”是年份,其范围为00-99,“MM”是月份,其范围为01-12,“DD”是日期,其范围为01-31,“HH”是小时,其范围为00-23,“NN”是当前小时内每次密钥更新加1,当前值为一小时内参数更新的次数,其范围是0x00-0xFF,“80”是固定填充位)执行预定的运算操作(例如对称加密算法)以获得中间密钥(LUK-A1);(2)使用所述中间密钥对特定范围(例如每批针对连续的10个安全性信息交互计数值)的安全性信息交互计数值(例如应用交易计数器ATC的值)中的每个及其取反后的值执行预定的运算操作(例如采用与常规的方案中生成过程密钥SK的算法相同的算法),以得到与所述特定范围的安全性信息交互计数值中的每个分别对应的限制密钥。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,所述步骤(A2)进一步包括:为所述一个或多个限制密钥中的每个设定有效期,并且如果某个限制密钥超过有效期未被使用,则该限制密钥失效。
优选地,在本发明所公开的用于HCE模式的数据加密方法中,用户能够对所述安全性信息交互应用存储的所述一个或多个限制密钥增加基于生物识别和/或解锁口令的附加的加密操作。
由上可见,本发明所公开的用于HCE模式的数据加密方法具有下列优点:由于限制密钥仅能够使用一次,故其可以被存储在移动终端所提供的可信执行环境或白盒数据库中,而无需独立的硬件安全单元,故成本较低,并且能够避免或者减轻密钥被恶意盗用的风险,故具有高的安全性。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不局限于上述的实施方式。应该认识到:在不脱离本发明主旨和范围的情况下,本领域技术人员可以对本发明做出不同的变化和修改。
Claims (12)
- 一种用于HCE模式的数据加密方法,所述用于HCE模式的数据加密方法包括下列步骤:(A1)密钥管理及数据处理服务器针对驻留并运行于特定的移动终端上的安全性信息交互应用生成一个或多个限制密钥,并将所生成的一个或多个限制密钥发送至所述安全性信息交互应用;(A2)在根据用户指令进行针对一个安全性信息交互计数值的数据交互时,所述安全性信息交互应用基于所述一个或多个限制密钥中的一个加密安全性信息交互数据以生成应用密文,并将所述应用密文发送至所述密钥管理及数据处理服务器;(A3)在接收到所述应用密文后,所述密钥管理及数据处理服务器校验所述应用密文的有效性和合法性,并在验证成功后执行后续的与所述安全性信息交互数据相关联的处理操作。
- 根据权利要求1所述的用于HCE模式的数据加密方法,其特征在于,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器基于所述安全性信息交互应用的请求或者周期性地根据安全性信息交互计数值的预设范围生成所述一个或多个限制密钥。
- 根据权利要求2所述的用于HCE模式的数据加密方法,其特征在于,所述步骤(A2)进一步包括:所述安全性信息交互应用经由近场通信信道将所述应用密文发送至所述密钥管理及数据处理服务器。
- 根据权利要求3所述的用于HCE模式的数据加密方法,其特征在于,所述步骤(A1)进一步包括:所述密钥管理及数据处理服务器存储与所述安全性信息交互应用相关联的应用密文密钥,并基于该应用密文密钥生成所述一个或多个限制密钥。
- 根据权利要求4所述的用于HCE模式的数据加密方法,其特征在于,所述安全性信息交互应用在所述移动终端提供的可信执行环境或白盒加密库中存储所 述一个或多个限制密钥。
- 根据权利要求5所述的用于HCE模式的数据加密方法,其特征在于,所述一个或多个限制密钥中的每个与一个安全性信息交互计数值绑定,即所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相绑定的一个限制密钥。
- 根据权利要求6所述的用于HCE模式的数据加密方法,其特征在于,所述安全性信息交互应用在每次完成相关联的一组安全性信息交互过程后将其维护的安全性信息交互计数值加1。
- 根据权利要求7所述的用于HCE模式的数据加密方法,其特征在于,所述一个或多个限制密钥中的每个在被使用一次后均失效。
- 根据权利要求8所述的用于HCE模式的数据加密方法,其特征在于,所述密钥管理及数据处理服务器基于每个安全性信息交互计数值生成与其相对应的限制密钥,并且所述安全性信息交互应用在发起基于当前安全性信息交互计数值的安全性信息交互时使用与该当前安全性信息交互计数值相绑定的一个限制密钥生成所述应用密文,以确保每个应用密文的唯一性。
- 根据权利要求9所述的用于HCE模式的数据加密方法,其特征在于,所述步骤(A1)进一步包括:以如下方式生成所述一个或多个限制密钥:(1)使用与所述安全性信息交互应用相关联的应用密文密钥对预定字符串执行预定的运算操作以获得中间密钥;(2)使用所述中间密钥对特定范围的安全性信息交互计数值中的每个及其取反后的值执行预定的运算操作,以得到与所述特定范围的安全性信息交互计数值中的每个分别对应的限制密钥。
- 根据权利要求10所述的用于HCE模式的数据加密方法,其特征在于,所述步骤(A2)进一步包括:为所述一个或多个限制密钥中的每个设定有效期,并且如果某个限制密钥超过有效期未被使用,则该限制密钥失效。
- 根据权利要求11所述的用于HCE模式的数据加密方法,其特征在于,用户能够对所述安全性信息交互应用存储的所述一个或多个限制密钥增加基于生物识别和/或解锁口令的附加的加密操作。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610870709.6A CN106357663A (zh) | 2016-09-30 | 2016-09-30 | 用于hce模式的数据加密方法 |
| CN201610870709.6 | 2016-09-30 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018059262A1 true WO2018059262A1 (zh) | 2018-04-05 |
Family
ID=57866033
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/102076 Ceased WO2018059262A1 (zh) | 2016-09-30 | 2017-09-18 | 用于hce模式的数据加密方法 |
Country Status (3)
| Country | Link |
|---|---|
| CN (1) | CN106357663A (zh) |
| TW (1) | TWI774695B (zh) |
| WO (1) | WO2018059262A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106357663A (zh) * | 2016-09-30 | 2017-01-25 | 中国银联股份有限公司 | 用于hce模式的数据加密方法 |
| CN117037373B (zh) * | 2023-07-31 | 2025-12-02 | 杭州满格智能设备有限公司 | 一种共享充电宝的租赁方法、系统、装置及存储介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105631655A (zh) * | 2015-07-23 | 2016-06-01 | 宇龙计算机通信科技(深圳)有限公司 | 基于hce的移动支付方法及装置、移动终端 |
| CN105635168A (zh) * | 2016-01-25 | 2016-06-01 | 恒宝股份有限公司 | 一种脱机交易装置及其安全密钥的使用方法 |
| CN105678543A (zh) * | 2015-12-31 | 2016-06-15 | 深圳前海微众银行股份有限公司 | 支付密钥计算方法和装置 |
| US9432087B2 (en) * | 2014-10-01 | 2016-08-30 | Gotrust Technology Inc. | Communication system and method for near field communication |
| CN106357663A (zh) * | 2016-09-30 | 2017-01-25 | 中国银联股份有限公司 | 用于hce模式的数据加密方法 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10460314B2 (en) * | 2013-07-10 | 2019-10-29 | Ca, Inc. | Pre-generation of session keys for electronic transactions and devices that pre-generate session keys for electronic transactions |
| CN105590200A (zh) * | 2015-03-11 | 2016-05-18 | 中国银联股份有限公司 | 用于移动近场支付的数据传输方法及用户设备 |
| CN105809447A (zh) * | 2016-03-30 | 2016-07-27 | 中国银联股份有限公司 | 基于人脸识别和hce的支付认证方法及认证系统 |
-
2016
- 2016-09-30 CN CN201610870709.6A patent/CN106357663A/zh active Pending
-
2017
- 2017-09-18 WO PCT/CN2017/102076 patent/WO2018059262A1/zh not_active Ceased
- 2017-09-22 TW TW106132668A patent/TWI774695B/zh active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9432087B2 (en) * | 2014-10-01 | 2016-08-30 | Gotrust Technology Inc. | Communication system and method for near field communication |
| CN105631655A (zh) * | 2015-07-23 | 2016-06-01 | 宇龙计算机通信科技(深圳)有限公司 | 基于hce的移动支付方法及装置、移动终端 |
| CN105678543A (zh) * | 2015-12-31 | 2016-06-15 | 深圳前海微众银行股份有限公司 | 支付密钥计算方法和装置 |
| CN105635168A (zh) * | 2016-01-25 | 2016-06-01 | 恒宝股份有限公司 | 一种脱机交易装置及其安全密钥的使用方法 |
| CN106357663A (zh) * | 2016-09-30 | 2017-01-25 | 中国银联股份有限公司 | 用于hce模式的数据加密方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201814579A (zh) | 2018-04-16 |
| TWI774695B (zh) | 2022-08-21 |
| CN106357663A (zh) | 2017-01-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11877213B2 (en) | Methods and systems for asset obfuscation | |
| US11856104B2 (en) | Methods for secure credential provisioning | |
| AU2021203815B2 (en) | Methods for secure cryptogram generation | |
| US11374754B2 (en) | System and method for generating trust tokens | |
| US11824998B2 (en) | System and method for software module binding | |
| US11088838B2 (en) | Automated authentication of a new network element | |
| CN108604280A (zh) | 交易方法、交易信息处理方法、交易终端及服务器 | |
| TWI774695B (zh) | 用於主機卡模擬(hce)的資料加密方法 | |
| TW201828134A (zh) | 基於密文的身份驗證方法 | |
| HK1233396A1 (zh) | 用於hce模式的数据加密方法 | |
| HK1233396A (zh) | 用於hce模式的數據加密方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17854712 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17854712 Country of ref document: EP Kind code of ref document: A1 |