WO2019127145A1 - 一种公私钥对获取方法、系统和pos终端 - Google Patents

一种公私钥对获取方法、系统和pos终端 Download PDF

Info

Publication number
WO2019127145A1
WO2019127145A1 PCT/CN2017/119121 CN2017119121W WO2019127145A1 WO 2019127145 A1 WO2019127145 A1 WO 2019127145A1 CN 2017119121 W CN2017119121 W CN 2017119121W WO 2019127145 A1 WO2019127145 A1 WO 2019127145A1
Authority
WO
WIPO (PCT)
Prior art keywords
public
private key
key pair
plaintext
pos terminal
Prior art date
Application number
PCT/CN2017/119121
Other languages
English (en)
French (fr)
Inventor
彭波涛
孟陆强
Original Assignee
福建联迪商用设备有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 福建联迪商用设备有限公司 filed Critical 福建联迪商用设备有限公司
Priority to PCT/CN2017/119121 priority Critical patent/WO2019127145A1/zh
Priority to CN201780002233.7A priority patent/CN108235798A/zh
Publication of WO2019127145A1 publication Critical patent/WO2019127145A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07GREGISTERING THE RECEIPT OF CASH, VALUABLES, OR TOKENS
    • G07G1/00Cash registers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)

Definitions

  • the present invention relates to the field of data security, and in particular, to a public and private key pair acquisition method, system, and POS terminal.
  • asymmetric public-private key pairs are used more and more frequently, especially POS terminals.
  • Many security solutions need to rely on trusted public-private key pairs to implement. Therefore, the function of obtaining public-private key pairs becomes a POS terminal.
  • the existing POS terminal generates a public-private key pair for encrypting and decrypting data to be transmitted in real time when data needs to be transmitted securely.
  • the speed of generating public-private key pairs in real time must be fast enough to meet the needs of application services. Usually, it takes several seconds (in the case of RSA 1024-bit keys, some acquirers want RSA key generation speed to be less than 3 seconds). This time requirement can significantly affect productivity or the user experience.
  • POS terminals typically generate public-private key pairs through dedicated security processors, or generate public-private key pairs through software algorithms.
  • the chip currently available for the POS terminal to generate the public-private key pair is slow. For example, generating a public-private key pair corresponding to the RSA 2048 takes at least 5 to 6 seconds, and the hardware cost is high. Compared with the hardware generation method, the use of software algorithms to generate public-private key pairs is slower.
  • the RSA public key pair generated on the network is used to generate code. Some RSA 2048-bit keys need to be generated for several hours.
  • the technical problem to be solved by the present invention is how to improve the speed at which a POS terminal acquires a public-private key pair.
  • the technical solution adopted by the present invention is:
  • the present invention provides a public-private key pair acquisition method, including:
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • the present invention also provides a POS terminal comprising one or more first processors and a first memory, the first memory storing a program and configured to perform the following steps by the one or more first processors :
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • the present invention further provides a public-private key pair obtaining method, including:
  • the key terminal generates a preset number of public and private key pairs to obtain an initial public-private key pair set;
  • the key terminal encrypts the initial public-private key pair set to obtain a public-private key-to-ciphertext set
  • the POS terminal acquires the public-private key pair ciphertext set
  • the POS terminal decrypts the public-private key pair ciphertext set, and obtains a public-private key pair plaintext set;
  • the POS terminal saves the public key to the plaintext to the storage unit corresponding to the security chip of the POS terminal;
  • the public-private key selects a public-private key pair from the plaintext set.
  • the present invention further provides a public-private key pair acquisition system, including a POS terminal and a key terminal;
  • the key terminal includes one or more second processors and a second memory, the second memory storing a program, and configured to perform the following steps by the one or more second processors:
  • the POS terminal includes one or more third processors and a third memory, the third memory storing a program, and configured to perform the following steps by the one or more third processors:
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • the present invention has the beneficial effects that the present invention generates a large number of public and private key pairs in advance through a key terminal independent of the POS terminal, and after the POS terminal is manufactured, directly imports a preset number of encrypted public and private key pairs from the key terminal.
  • the public-private key pair is stored in a storage unit with high security in the POS terminal.
  • the key terminal is a dedicated public-private key pair generating device, such as an encryption machine, which can generate a large number of public-private key pairs with high randomness, and the key terminal has high security.
  • the key terminal encrypts the generated public-private key pair and then transmits it to the POS terminal, ensuring the security of the public-private key pair during the transmission process.
  • the POS terminal generally has a data security storage area as a financial payment device.
  • the present invention stores the public and private key in plaintext in a storage unit with high security in the POS terminal. Therefore, the generation of the public-private key pair and the transmission of the public-private key pair to the storage public-private key pair have high security. Therefore, the preset number of public-private key pairs stored in the POS terminal have high randomness and security. Suitable for business applications that transmit critical data securely. Different from the prior art in which a public-private key pair is generated in real time in a POS terminal, in the process of using a POS terminal, when the service demand of the public-private key pair is obtained, the public-private is directly selected from the storage unit with higher security.
  • the key pair can be omitted, and the process of generating the public-private key pair in real time is omitted, so that the total length of the public-private key pair is less than one hundred milliseconds, which greatly improves the POS terminal to obtain a public-private key pair with high randomness and security.
  • the speed can meet the needs of real-time security data transmission services with high requirements.
  • FIG. 1 is a flow chart of a specific implementation manner of a method for acquiring a public-private key pair according to the present invention
  • FIG. 2 is a structural block diagram of a specific implementation manner of a POS terminal according to the present invention.
  • FIG. 3 is a flow chart of a specific implementation manner of another public-private key pair obtaining method provided by the present invention.
  • FIG. 4 is a structural block diagram of a specific implementation manner of a public-private key pair acquisition system provided by the present invention.
  • a first processor 2. a first memory; 3. a second processor; 4. a second memory; 5. a third processor; 6. a third memory; 101; a POS terminal;
  • FIG. 1 and FIG. 4 Please refer to FIG. 1 and FIG. 4,
  • the present invention provides a public-private key pair obtaining method, including:
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • selecting the public-private key pair from the public-private key to the plaintext set is specifically:
  • the method further includes:
  • the key terminal establishes a communication connection with the POS terminal through the local area network, thereby effectively preventing the public key to intercept the ciphertext during the data transmission process, and improving the security of the public-private key pair stored in the POS terminal.
  • the present invention further provides a POS terminal including one or more first processors 1 and a first memory 2, the first memory 2 storing a program and configured to be configured by the one or The plurality of first processors 1 perform the following steps:
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • selecting the public-private key pair from the public-private key to the plaintext set is specifically:
  • the method further includes:
  • the present invention further provides a public-private key pair obtaining method, including:
  • the key terminal generates a preset number of public and private key pairs to obtain an initial public-private key pair set;
  • the key terminal encrypts the initial public-private key pair set to obtain a public-private key-to-ciphertext set
  • the POS terminal acquires the public-private key pair ciphertext set
  • the POS terminal decrypts the public-private key pair ciphertext set, and obtains a public-private key pair plaintext set;
  • the POS terminal saves the public key to the plaintext to the storage unit corresponding to the security chip of the POS terminal;
  • the public-private key selects a public-private key pair from the plaintext set.
  • the key terminal encrypts the initial public-private key pair set, and obtains a public-private key-to-ciphertext set, specifically:
  • the key terminal presets an encryption key
  • the key terminal encrypts the initial public-private key pair set according to the encryption key, and obtains a public-private key-to-ciphertext set.
  • the POS terminal decrypts the public-private key pair ciphertext set, and obtains a public-private key pair plaintext set, specifically:
  • the POS terminal presets a decryption key corresponding to the encrypted public and private key
  • the POS terminal decrypts the public-private key pair ciphertext set according to the decryption key, and obtains a public-private key-pair plaintext set.
  • selecting the public-private key pair from the public-private key to the plaintext set is specifically:
  • the POS terminal acquires a random number generated by a hardware random number generator
  • the POS terminal sorts the public-private key pair to the plaintext set, and obtains an ordered collection of plain-private key pairs in plaintext;
  • the POS terminal acquires a public-private key pair corresponding to the random number from the public-private key to the plaintext ordered set.
  • the POS terminal deletes the public-private key pair from the public-private key to the plaintext set.
  • the POS terminal before the POS terminal acquires the public-private key pair ciphertext set, the POS terminal further includes:
  • the key terminal establishes a communication connection with a local area network
  • the POS terminal establishes a communication connection with the local area network.
  • the present invention further provides a public-private key pair acquisition system, including a POS terminal 101 and a key terminal 102;
  • the key terminal comprises one or more second processors 3 and a second memory 4, the second memory 4 storing a program and configured to perform the following steps by the one or more second processors 3 :
  • the POS terminal comprises one or more third processors 5 and a third memory 6, the third memory 6 storing a program and being configured to perform the following steps by the one or more third processors 5:
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • decrypting the public-private key pair ciphertext set to obtain a public-private key pair plaintext set specifically:
  • selecting the public-private key pair from the public-private key to the plaintext set is specifically:
  • the third processor performs the following steps:
  • the second processor performs the following steps:
  • the third processor performs the following steps:
  • Embodiment 1 of the present invention is:
  • This embodiment provides a public-private key pair obtaining method, including:
  • the POS terminal and the key terminal are connected through a USB data line.
  • the POS terminal establishes a communication connection with a local area network by wire or wirelessly
  • the key terminal establishes a communication connection with the same local area network by wire or wirelessly.
  • the key terminal and the POS terminal establish a communication connection through the local area network, thereby effectively avoiding the interception of the ciphertext by the public and private keys during the data transmission process, and improving the security of the public-private key pair stored in the POS terminal.
  • S2 Obtain a ciphertext of a preset number of public-private key pairs from the key terminal, and obtain a public-private key-to-ciphertext set.
  • the key terminal is a dedicated public-private key pair generating device, such as an encryption machine, which can generate a large number of public-private key pairs with high randomness, and the key terminal has high security.
  • the key terminal is independent of the POS terminal, and generates a random public-private key pair during the production process of the POS terminal. After the POS terminal is produced, the public-private key pair generated in the key terminal and not allocated to other POS terminals is directly imported. Save time costs by going to the current POS terminal.
  • the POS terminal may inject a decryption key corresponding to the encryption key used by the key terminal to transmit the public-private key to the ciphertext, and the POS terminal may decrypt the public-private key pair ciphertext acquired from the key terminal according to the decryption key.
  • the POS terminal is a financial payment device, and its own security chip has extremely high security, and it is difficult for criminals to steal public and private key pairs stored in the security chip.
  • selecting the public-private key pair from the public-private key to the plaintext set specifically:
  • a POS terminal stores 1000 pairs of public key private keys, and the 1000 pairs of public key private keys are sorted from 1 to 1000.
  • the hardware random number generator When the POS terminal is to perform transaction data transmission, the hardware random number generator generates a random number 500 in real time. , the public-private key pair with the serial number of 500 is used as the encryption and decryption transaction data.
  • the public-private key pair is selected by the random number generated in real time, so that the result of selecting the public-private key pair is random and unpredictable, which further improves the security of the transaction data.
  • the public-private key pair with sequence number 500 has been used as the encryption and decryption transaction data
  • the public-private key pair with the sequence number of 500 is deleted or marked as used.
  • Embodiment 2 of the present invention is:
  • the embodiment provides a POS terminal, including one or more first processors 1 and a first memory 2, the first memory 2 storing a program and configured to be configured by the one or more first processors 1 Perform the following steps:
  • the POS terminal and the key terminal are connected through a USB data line.
  • the POS terminal establishes a communication connection with a local area network by wire or wirelessly
  • the key terminal establishes a communication connection with the same local area network by wire or wirelessly.
  • S2 Obtain a ciphertext of a preset number of public-private key pairs from the key terminal, and obtain a public-private key-to-ciphertext set.
  • selecting the public-private key pair from the public-private key to the plaintext set specifically:
  • Embodiment 3 of the present invention is:
  • This embodiment provides a public-private key pair obtaining method, including:
  • the key terminal establishes a communication connection with a local area network; the POS terminal establishes a communication connection with the local area network.
  • the POS terminal and the key terminal are connected through a USB data line.
  • the key terminal and the POS terminal establish a communication connection through the local area network, thereby effectively avoiding the interception of the ciphertext by the public and private keys during the data transmission process, and improving the security of the public-private key pair stored in the POS terminal.
  • the key terminal generates a preset number of public-private key pairs to obtain an initial public-private key pair set.
  • the key terminal encrypts the initial public-private key pair set, and obtains a public-private key-to-ciphertext set.
  • the key terminal presets an encryption key
  • the key terminal encrypts the initial public-private key pair set according to the encryption key, and obtains a public-private key-to-ciphertext set.
  • the key terminal is a dedicated public-private key pair generating device, such as an encryption machine, which can generate a large number of public-private key pairs with high randomness, and the key terminal has high security.
  • the key terminal is independent of the POS terminal, and generates a random public-private key pair during the production process of the POS terminal. After the POS terminal is produced, the public-private key pair generated in the key terminal and not allocated to other POS terminals is directly imported. Save time costs by going to the current POS terminal.
  • the POS terminal acquires the public-private key pair ciphertext set.
  • the POS terminal decrypts the public-private key pair ciphertext set, and obtains a public-private key pair plaintext set.
  • the POS terminal presets a decryption key corresponding to the encrypted public and private key
  • the POS terminal decrypts the public-private key pair ciphertext set according to the decryption key, and obtains a public-private key-pair plaintext set.
  • the POS terminal saves the public-private key pair plaintext to a storage unit corresponding to the security chip of the POS terminal.
  • the POS terminal is a financial payment device, and its own security chip has extremely high security, and it is difficult for criminals to steal public and private key pairs stored in the security chip.
  • selecting the public-private key pair from the public-private key to the plaintext set specifically:
  • the POS terminal acquires a random number generated by a hardware random number generator
  • the POS terminal sorts the public-private key pair to the plaintext set, and obtains an ordered collection of plain-private key pairs in plaintext;
  • the POS terminal acquires a public-private key pair corresponding to the random number from the public-private key to the plaintext ordered set.
  • a POS terminal stores 1000 pairs of public key private keys, and the 1000 pairs of public key private keys are sorted from 1 to 1000.
  • the hardware random number generator When the POS terminal is to perform transaction data transmission, the hardware random number generator generates a random number 500 in real time. , the public-private key pair with the serial number of 500 is used as the encryption and decryption transaction data.
  • the public-private key pair is selected by the random number generated in real time, so that the result of selecting the public-private key pair is random and unpredictable, which further improves the security of the transaction data.
  • the speed of generating random numbers by hardware is much higher than that of software generating random numbers. Therefore, generating a random number by a hardware random number generator provided by the POS terminal to randomly select a public-private key pair from a large number of public-private key pairs is beneficial to improve Select the speed of the public and private key pair.
  • the POS terminal deletes the public-private key pair from the public-private key to the plaintext set.
  • the public-private key pair with sequence number 500 has been used as the encryption and decryption transaction data
  • the public-private key pair with the sequence number of 500 is deleted or marked as used.
  • Embodiment 4 of the present invention is:
  • This embodiment provides a public-private key pair acquisition system, including a POS terminal 101 and a key terminal 102;
  • the key terminal 102 includes one or more second processors 3 and a second memory 4, the second memory 4 storing a program and configured to be executed by the one or more second processors 3 step:
  • Encrypting the initial public-private key pair set to obtain a public-private key-to-ciphertext set specifically: pre-setting an encryption key; encrypting the initial public-private key pair set according to the encryption key, to obtain a public-private key-to-ciphertext set.
  • the POS terminal 101 includes one or more third processors 5 and a third memory 6, the third memory 6 storing a program and configured to perform the following steps by the one or more third processors 5 :
  • the public key pair is saved to the plaintext to the storage unit corresponding to the security chip of the POS terminal.
  • a public-private key pair is selected from the public-private key to the plaintext set.
  • selecting the public-private key pair from the public-private key to the plaintext set specifically: acquiring a random number generated by the hardware random number generator; sorting the public-private key pair of the plaintext, and obtaining the public-private key pair in the plaintext An ordered set; obtaining a public-private key pair corresponding to the random number from the public-private key to the plain-text ordered set.
  • the public-private key pair obtaining method, system, and POS terminal provided by the present invention generate a large number of public-private key pairs in advance through a key terminal independent of the POS terminal, and the POS terminal is directly generated from the key after being produced.
  • the terminal imports a preset number of encrypted public-private key pairs, and stores the public-private key pair in a storage unit with high security in the POS terminal.
  • the preset number of public-private key pairs stored in the POS terminal have high randomness and security, and are suitable for service applications that securely transmit important data.
  • the public-private is directly selected from the storage unit with higher security.
  • the key pair can be omitted, and the process of generating the public-private key pair in real time is omitted, so that the total length of the public-private key pair is less than one hundred milliseconds, which greatly improves the POS terminal to obtain a public-private key pair with high randomness and security.
  • the speed can meet the needs of real-time security data transmission services with high requirements.

Abstract

本发明涉及一种公私钥对获取方法、系统和POS终端,本发明通过密钥终端生成预设个数公私钥对,得到初始公私钥对集合;密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合;POS终端获取所述公私钥对密文集合;POS终端解密所述公私钥对密文集合,得到公私钥对明文集合;POS终端保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;当POS终端检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。实现提高POS终端获取公私钥对的速度。

Description

一种公私钥对获取方法、系统和POS终端 技术领域
本发明涉及数据安全领域,尤其涉及一种公私钥对获取方法、系统和POS终端。
背景技术
在电子支付体系中,越来越频繁的使用非对称公私钥对,尤其是POS终端,很多安全方案都需要依赖于可信的公私钥对来实现,因此,获取公私钥对的功能成为POS终端的一个必需的功能。现有的POS终端是在需要安全传输数据时实时生成用于加解密待传输数据的公私钥对。实时生成公私钥对的速度必须足够快以满足应用业务的需求,通常要求在几秒(以RSA1024位密钥为例,某些收单机构希望RSA密钥产生速度在3秒以内)左右,超过此时间要求则会显著影响到生产效率或者用户体验。
目前,POS终端一般通过专用的安全处理器来产生公私钥对,或通过软件算法来产生公私钥对。但是,目前可用于POS终端生成公私钥对的芯片速度较慢,例如,生成一与RSA2048对应的公私钥对至少需耗时5至6秒,且硬件成本较高。而与硬件生成方法相比,采用软件算法生成公私钥对的速度更慢。以网络上常见的RSA公私钥对生成代码来计算,有的产生RSA2048位密钥需要长达数个小时,如果要达到应用的性能要求,需要做大量的算法优化,由于和期望的性能要求(希望在3秒以内)差距太大,其优化难度太高,往往优化到一定程度就遇到瓶颈,无法进一步优化。
技术问题
本发明所要解决的技术问题是:如何提高POS终端获取公私钥对的速度。
技术解决方案
为了解决上述技术问题,本发明采用的技术方案为:
本发明提供一种公私钥对获取方法,包括:
从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
本发明还提供一种POS终端,包括一个或多个第一处理器及第一存储器,所述第一存储器存储有程序,并且被配置成由所述一个或多个第一处理器执行以下步骤:
从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
本发明另提供一种公私钥对获取方法,包括:
密钥终端生成预设个数公私钥对,得到初始公私钥对集合;
密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合;
POS终端获取所述公私钥对密文集合;
POS终端解密所述公私钥对密文集合,得到公私钥对明文集合;
POS终端保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当POS终端检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
本发明另提供一种公私钥对获取系统,包括POS终端和密钥终端;
所述密钥终端包括一个或多个第二处理器及第二存储器,所述第二存储器存储有程序,并且被配置成由所述一个或多个第二处理器执行以下步骤:
生成预设个数公私钥对,得到初始公私钥对集合;
加密所述初始公私钥对集合,得到公私钥对密文集合;
所述POS终端包括一个或多个第三处理器及第三存储器,所述第三存储器存储有程序,并且被配置成由所述一个或多个第三处理器执行以下步骤:
获取所述公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
有益效果
本发明的有益效果在于:本发明通过独立于POS终端的密钥终端事先生成大量公私钥对并加密,POS终端生产好后,直接从密钥终端导入预设个数加密后的公私钥对,并将公私钥对保存在POS终端内安全性较高的存储单元中。其中,密钥终端是专用的公私钥对生成设备,例如加密机,可生成随机性高的大量公私钥对,且密钥终端具有较高的安全性。同时,密钥终端将生成的公私钥对加密后再传输至POS终端,在传输过程中保证了公私钥对的安全性。且POS终端作为金融支付设备一般都带有数据安全存储区,本发明将公私钥对明文存储于POS终端内安全性较高的存储单元。因此,从生成公私钥对、传输公私钥对至存储公私钥对均具有较高的安全性,因此,存储于POS终端内的预设个数公私钥对具有较高的随机性和安全性,适用于安全传输重要数据的业务应用。区别于在POS终端实时生成公私钥对的现有技术,本申请在使用POS终端的过程中,当有获取公私钥对的业务需求时,直接从安全性较高的存储单元中直接选取一公私钥对即可,省去了实时生成公私钥对的过程,使得获取公私钥对的总时长不超过百毫秒,极大程度上提高了POS终端获取具有较高随机性和安全性的公私钥对的速度,可满足实时性要求较高的安全数据传输业务的需求。
附图说明
图1为本发明提供的一种公私钥对获取方法的具体实施方式的流程框图;
图2为本发明提供的一种POS终端的具体实施方式的结构框图;
图3本发明提供的另一种公私钥对获取方法的具体实施方式的流程框图;
图4本发明提供的一种公私钥对获取系统的具体实施方式的结构框图;
标号说明:
1、第一处理器;2、第一存储器;3、第二处理器;4、第二存储器;5、第三处理器;6、第三存储器;101、POS终端;102、密钥终端。
本发明的实施方式
请参照图1以及图4,
如图1所示,本发明提供一种公私钥对获取方法,包括:
从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
进一步地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
获取由硬件随机数发生器生成的随机数;
排序所述公私钥对明文集合,得到公私钥对明文有序集合;
从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
由上述描述可知,通过硬件生成随机数有利于提高公私钥对的随机性。
进一步地,还包括:
从所述公私钥对明文集合中删除所述一公私钥对。
由上述描述可知,消除了重复使用同一公私钥对加密待传输数据的可能性,有利于提高待传输数据的安全性。
进一步地,从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合之前,还包括:
通过局域网与密钥终端建立通信连接。
由上述描述可知,密钥终端与POS终端之间通过局域网建立通信连接,有效避免数据传输过程公私钥对密文被拦截的情况,提高了存储于POS终端的公私钥对的安全性。
如图2所示,本发明还提供一种POS终端,包括一个或多个第一处理器1及第一存储器2,所述第一存储器2存储有程序,并且被配置成由所述一个或多个第一处理器1执行以下步骤:
从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
进一步地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
获取由硬件随机数发生器生成的随机数;
排序所述公私钥对明文集合,得到公私钥对明文有序集合;
从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
进一步地,还包括:
从所述公私钥对明文集合中删除所述一公私钥对。
进一步地,从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合之前,还包括:
通过局域网与密钥终端建立通信连接。
如图3所示,本发明还提供一种公私钥对获取方法,包括:
密钥终端生成预设个数公私钥对,得到初始公私钥对集合;
密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合;
POS终端获取所述公私钥对密文集合;
POS终端解密所述公私钥对密文集合,得到公私钥对明文集合;
POS终端保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当POS终端检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
进一步地,密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合,具体为:
密钥终端预设加密密钥;
密钥终端根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
进一步地,POS终端解密所述公私钥对密文集合,得到公私钥对明文集合,具体为:
POS终端预设与所述加密公私钥对应的解密密钥;
POS终端根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
进一步地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
POS终端获取由硬件随机数发生器生成的随机数;
POS终端排序所述公私钥对明文集合,得到公私钥对明文有序集合;
POS终端从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
进一步地,还包括:
POS终端从所述公私钥对明文集合中删除所述一公私钥对。
进一步地,POS终端获取所述公私钥对密文集合之前,还包括:
密钥终端与一局域网建立通信连接;
POS终端与所述一局域网建立通信连接。
如图4所示,本发明还提供一种公私钥对获取系统,包括POS终端101和密钥终端102;
所述密钥终端包括一个或多个第二处理器3及第二存储器4,所述第二存储器4存储有程序,并且被配置成由所述一个或多个第二处理器3执行以下步骤:
生成预设个数公私钥对,得到初始公私钥对集合;
加密所述初始公私钥对集合,得到公私钥对密文集合;
所述POS终端包括一个或多个第三处理器5及第三存储器6,所述第三存储器6存储有程序,并且被配置成由所述一个或多个第三处理器5执行以下步骤:
获取所述公私钥对密文集合;
解密所述公私钥对密文集合,得到公私钥对明文集合;
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
进一步地,加密所述初始公私钥对集合,得到公私钥对密文集合,具体为:
预设加密密钥;
根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
进一步地,解密所述公私钥对密文集合,得到公私钥对明文集合,具体为:
预设与所述加密公私钥对应的解密密钥;
根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
进一步地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
获取由硬件随机数发生器生成的随机数;
排序所述公私钥对明文集合,得到公私钥对明文有序集合;
从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
进一步地,还包括:
所述第三处理器执行以下步骤:
从所述公私钥对明文集合中删除所述一公私钥对。
进一步地,还包括:
所述第二处理器执行以下步骤:
与一局域网建立通信连接。
进一步地,还包括:
所述第三处理器执行以下步骤:
与所述一局域网建立通信连接。
本发明的实施例一为:
本实施例提供一种公私钥对获取方法,包括:
S1、通过局域网与密钥终端建立通信连接。
可选地,通过USB数据线连接POS终端和密钥终端。
可选地,POS终端通过有线或无线方式与一局域网建立通信连接,密钥终端通过有线或无线方式与同一所述局域网建立通信连接。
其中,密钥终端与POS终端之间通过局域网建立通信连接,有效避免数据传输过程公私钥对密文被拦截的情况,提高了存储于POS终端的公私钥对的安全性。
S2、从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合。
其中,密钥终端是专用的公私钥对生成设备,例如加密机,可生成随机性高的大量公私钥对,且密钥终端具有较高的安全性。密钥终端独立于POS终端,在POS终端的生产过程中不断生成随机的公私钥对,当POS终端生产好后,直接将密钥终端中生成的且未分配给其它POS终端的公私钥对导入到当前POS终端中,节省时间成本。
S3、解密所述公私钥对密文集合,得到公私钥对明文集合。
其中,向POS终端注入与密钥终端传输公私钥对密文时使用的加密密钥对应的解密密钥,POS终端可根据该解密密钥解密从密钥终端获取到的公私钥对密文。
S4、保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元。
其中,POS终端是金融支付设备,其自带的安全芯片具有极高的安全性,不法分子难以窃取存储于安全芯片内的公私钥对。
S5、当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
可选地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
获取由硬件随机数发生器生成的随机数;
排序所述公私钥对明文集合,得到公私钥对明文有序集合;
从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
例如,一POS终端内存储有1000对公钥私钥,将这1000对公钥私钥从1至1000排序,当POS终端要进行交易数据传输时,硬件随机数发生器实时生成一随机数500,则将序号为500的公私钥对用作加解密交易数据。
其中,通过实时生成的随机数选取公私钥对使得每次选取公私钥对的结果是随机的、不可预测的,进一步提高了交易数据的安全性。
S6、从所述公私钥对明文集合中删除所述一公私钥对。
例如,序号为500的公私钥对已被用作加解密一交易数据,则将序号为500的公私钥对删除,或标记为已使用。以免重复使用同一公私钥对加解密待传输数据,有利于提高待传输数据的安全性。
本发明的实施例二为:
本实施例提供一种POS终端,包括一个或多个第一处理器1及第一存储器2,所述第一存储器2存储有程序,并且被配置成由所述一个或多个第一处理器1执行以下步骤:
S1、通过局域网与密钥终端建立通信连接。
可选地,通过USB数据线连接POS终端和密钥终端。
可选地,POS终端通过有线或无线方式与一局域网建立通信连接,密钥终端通过有线或无线方式与同一所述局域网建立通信连接。
S2、从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合。
S3、解密所述公私钥对密文集合,得到公私钥对明文集合。
S4、保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元。
S5、当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
可选地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
获取由硬件随机数发生器生成的随机数;
排序所述公私钥对明文集合,得到公私钥对明文有序集合;
从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
S6、从所述公私钥对明文集合中删除所述一公私钥对。
本发明的实施例三为:
本实施例提供一种公私钥对获取方法,包括:
S1、密钥终端与一局域网建立通信连接;POS终端与所述一局域网建立通信连接。
可选地,通过USB数据线连接POS终端和密钥终端。
其中,密钥终端与POS终端之间通过局域网建立通信连接,有效避免数据传输过程公私钥对密文被拦截的情况,提高了存储于POS终端的公私钥对的安全性。
S2、密钥终端生成预设个数公私钥对,得到初始公私钥对集合。
S3、密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合。
可选地,密钥终端预设加密密钥;
密钥终端根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
其中,密钥终端是专用的公私钥对生成设备,例如加密机,可生成随机性高的大量公私钥对,且密钥终端具有较高的安全性。密钥终端独立于POS终端,在POS终端的生产过程中不断生成随机的公私钥对,当POS终端生产好后,直接将密钥终端中生成的且未分配给其它POS终端的公私钥对导入到当前POS终端中,节省时间成本。
S4、POS终端获取所述公私钥对密文集合。
S5、POS终端解密所述公私钥对密文集合,得到公私钥对明文集合。
可选地,POS终端预设与所述加密公私钥对应的解密密钥;
POS终端根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
S6、POS终端保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元。
其中,POS终端是金融支付设备,其自带的安全芯片具有极高的安全性,不法分子难以窃取存储于安全芯片内的公私钥对。
S7、当POS终端检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
可选地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:
POS终端获取由硬件随机数发生器生成的随机数;
POS终端排序所述公私钥对明文集合,得到公私钥对明文有序集合;
POS终端从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
例如,一POS终端内存储有1000对公钥私钥,将这1000对公钥私钥从1至1000排序,当POS终端要进行交易数据传输时,硬件随机数发生器实时生成一随机数500,则将序号为500的公私钥对用作加解密交易数据。
其中,通过实时生成的随机数选取公私钥对使得每次选取公私钥对的结果是随机的、不可预测的,进一步提高了交易数据的安全性。并且,通过硬件生成随机数的速度远高于软件生成随机数的方法,因此,通过POS终端自带的硬件随机数发生器生成随机数从大量公私钥对中随机选取一公私钥对有利于提高选取公私钥对的速度。
S8、POS终端从所述公私钥对明文集合中删除所述一公私钥对。
例如,序号为500的公私钥对已被用作加解密一交易数据,则将序号为500的公私钥对删除,或标记为已使用。以免重复使用同一公私钥对加解密待传输数据,有利于提高待传输数据的安全性。
本发明的实施例四为:
本实施例提供一种公私钥对获取系统,包括POS终端101和密钥终端102;
所述密钥终端102包括一个或多个第二处理器3及第二存储器4,所述第二存储器4存储有程序,并且被配置成由所述一个或多个第二处理器3执行以下步骤:
与一局域网建立通信连接。
生成预设个数公私钥对,得到初始公私钥对集合。
加密所述初始公私钥对集合,得到公私钥对密文集合;具体为:预设加密密钥;根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
所述POS终端101包括一个或多个第三处理器5及第三存储器6,所述第三存储器6存储有程序,并且被配置成由所述一个或多个第三处理器5执行以下步骤:
与所述一局域网建立通信连接。
获取所述公私钥对密文集合。
解密所述公私钥对密文集合,得到公私钥对明文集合;具体为,预设与所述加密公私钥对应的解密密钥;根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元。
当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。可选地,从所述公私钥对明文集合中选取一所述公私钥对,具体为:获取由硬件随机数发生器生成的随机数;排序所述公私钥对明文集合,得到公私钥对明文有序集合;从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
从所述公私钥对明文集合中删除所述一公私钥对。
综上所述,本发明提供的一种公私钥对获取方法、系统和POS终端,通过独立于POS终端的密钥终端事先生成大量公私钥对并加密,POS终端生产好后,直接从密钥终端导入预设个数加密后的公私钥对,并将公私钥对保存在POS终端内安全性较高的存储单元中。存储于POS终端内的预设个数公私钥对具有较高的随机性和安全性,适用于安全传输重要数据的业务应用。区别于在POS终端实时生成公私钥对的现有技术,本申请在使用POS终端的过程中,当有获取公私钥对的业务需求时,直接从安全性较高的存储单元中直接选取一公私钥对即可,省去了实时生成公私钥对的过程,使得获取公私钥对的总时长不超过百毫秒,极大程度上提高了POS终端获取具有较高随机性和安全性的公私钥对的速度,可满足实时性要求较高的安全数据传输业务的需求。

Claims (21)

  1. 一种公私钥对获取方法,其特征在于,包括:
    从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
    解密所述公私钥对密文集合,得到公私钥对明文集合;
    保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
    当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
  2. 根据权利要求1所述的公私钥对获取方法,其特征在于,从所述公私钥对明文集合中选取一公私钥对,具体为:
    获取由硬件随机数发生器生成的随机数;
    排序所述公私钥对明文集合,得到公私钥对明文有序集合;
    从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
  3. 根据权利要求1所述的公私钥对获取方法,其特征在于,还包括:
    从所述公私钥对明文集合中删除所述一公私钥对。
  4. 根据权利要求1所述的公私钥对获取方法,其特征在于,从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合之前,还包括:
    通过局域网与密钥终端建立通信连接。
  5. 一种POS终端,其特征在于,包括一个或多个第一处理器及第一存储器,所述第一存储器存储有程序,并且被配置成由所述一个或多个第一处理器执行以下步骤:
    从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合;
    解密所述公私钥对密文集合,得到公私钥对明文集合;
    保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
    当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
  6. 根据权利要求5所述的POS终端,其特征在于,从所述公私钥对明文集合中选取一公私钥对,具体为:
    获取由硬件随机数发生器生成的随机数;
    排序所述公私钥对明文集合,得到公私钥对明文有序集合;
    从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
  7. 根据权利要求5所述的POS终端,其特征在于,还包括:
    从所述公私钥对明文集合中删除所述一公私钥对。
  8. 根据权利要求5所述的POS终端,其特征在于,从密钥终端获取预设个数公私钥对的密文,得到公私钥对密文集合之前,还包括:
    通过局域网与密钥终端建立通信连接。
  9. 一种公私钥对获取方法,其特征在于,包括:
    密钥终端生成预设个数公私钥对,得到初始公私钥对集合;
    密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合;
    POS终端获取所述公私钥对密文集合;
    POS终端解密所述公私钥对密文集合,得到公私钥对明文集合;
    POS终端保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
    当POS终端检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
  10. 根据权利要求9所述的公私钥对获取方法,其特征在于,密钥终端加密所述初始公私钥对集合,得到公私钥对密文集合,具体为:
    密钥终端预设加密密钥;
    密钥终端根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
  11. 根据权利要求10所述的公私钥对获取方法,其特征在于,POS终端解密所述公私钥对密文集合,得到公私钥对明文集合,具体为:
    POS终端预设与所述加密公私钥对应的解密密钥;
    POS终端根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
  12. 根据权利9所述的公私钥对获取方法,其特征在于,从所述公私钥对明文集合中选取一公私钥对,具体为:
    POS终端获取由硬件随机数发生器生成的随机数;
    POS终端排序所述公私钥对明文集合,得到公私钥对明文有序集合;
    POS终端从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
  13. 根据权利要求9所述的公私钥对获取方法,其特征在于,还包括:
    POS终端从所述公私钥对明文集合中删除所述一公私钥对。
  14. 根据权利要求9所述的公私钥对获取方法,其特征在于,POS终端获取所述公私钥对密文集合之前,还包括:
    密钥终端与一局域网建立通信连接;
    POS终端与所述一局域网建立通信连接。
  15. 一种公私钥对获取系统,其特征在于,包括POS终端和密钥终端;
    所述密钥终端包括一个或多个第二处理器及第二存储器,所述第二存储器存储有程序,并且被配置成由所述一个或多个第二处理器执行以下步骤:
    生成预设个数公私钥对,得到初始公私钥对集合;
    加密所述初始公私钥对集合,得到公私钥对密文集合;
    所述POS终端包括一个或多个第三处理器及第三存储器,所述第三存储器存储有程序,并且被配置成由所述一个或多个第三处理器执行以下步骤:
    获取所述公私钥对密文集合;
    解密所述公私钥对密文集合,得到公私钥对明文集合;
    保存所述公私钥对明文集合至与POS终端的安全芯片对应的存储单元;
    当检测到与获取公私钥对操作对应的指令时,从所述公私钥对明文集合中选取一公私钥对。
  16. 根据权利要求15所述的公私钥对获取系统,其特征在于,加密所述初始公私钥对集合,得到公私钥对密文集合,具体为:
    预设加密密钥;
    根据所述加密密钥加密所述初始公私钥对集合,得到公私钥对密文集合。
  17. 根据权利要求16所述的公私钥对获取系统,其特征在于,解密所述公私钥对密文集合,得到公私钥对明文集合,具体为:
    预设与所述加密公私钥对应的解密密钥;
    根据所述解密密钥解密所述公私钥对密文集合,得到公私钥对明文集合。
  18. 根据权利15所述的公私钥对获取系统,其特征在于,从所述公私钥对明文集合中选取一公私钥对,具体为:
    获取由硬件随机数发生器生成的随机数;
    排序所述公私钥对明文集合,得到公私钥对明文有序集合;
    从所述公私钥对明文有序集合中获取与所述随机数对应的公私钥对。
  19. 根据权利要求15所述的公私钥对获取系统,其特征在于,还包括:
    所述第三处理器执行以下步骤:
    从所述公私钥对明文集合中删除所述一公私钥对。
  20. 根据权利要求15所述的公私钥对获取系统,其特征在于,还包括:
    所述第二处理器执行以下步骤:
    与一局域网建立通信连接。
  21. 根据权利要求20所述的公私钥对获取系统,其特征在于,还包括:
    所述第三处理器执行以下步骤:
    与所述一局域网建立通信连接。
PCT/CN2017/119121 2017-12-27 2017-12-27 一种公私钥对获取方法、系统和pos终端 WO2019127145A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2017/119121 WO2019127145A1 (zh) 2017-12-27 2017-12-27 一种公私钥对获取方法、系统和pos终端
CN201780002233.7A CN108235798A (zh) 2017-12-27 2017-12-27 一种公私钥对获取方法、系统和pos终端

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/119121 WO2019127145A1 (zh) 2017-12-27 2017-12-27 一种公私钥对获取方法、系统和pos终端

Publications (1)

Publication Number Publication Date
WO2019127145A1 true WO2019127145A1 (zh) 2019-07-04

Family

ID=62643237

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/119121 WO2019127145A1 (zh) 2017-12-27 2017-12-27 一种公私钥对获取方法、系统和pos终端

Country Status (2)

Country Link
CN (1) CN108235798A (zh)
WO (1) WO2019127145A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109039609A (zh) * 2018-08-24 2018-12-18 深圳美图创新科技有限公司 密钥导入终端的方法及终端

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2247130A1 (en) * 2008-01-23 2010-11-03 China Iwncomm Co., Ltd. Method for managing wireless multi-hop network key
CN103237005A (zh) * 2013-03-15 2013-08-07 福建联迪商用设备有限公司 密钥管理方法及系统
CN105722067A (zh) * 2014-12-02 2016-06-29 阿里巴巴集团控股有限公司 移动终端上数据加/解密方法及装置

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102082790B (zh) * 2010-12-27 2014-03-05 北京握奇数据系统有限公司 一种数字签名的加/解密方法及装置
CN103237004A (zh) * 2013-03-15 2013-08-07 福建联迪商用设备有限公司 密钥下载方法、管理方法、下载管理方法及装置和系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2247130A1 (en) * 2008-01-23 2010-11-03 China Iwncomm Co., Ltd. Method for managing wireless multi-hop network key
CN103237005A (zh) * 2013-03-15 2013-08-07 福建联迪商用设备有限公司 密钥管理方法及系统
CN105722067A (zh) * 2014-12-02 2016-06-29 阿里巴巴集团控股有限公司 移动终端上数据加/解密方法及装置

Also Published As

Publication number Publication date
CN108235798A (zh) 2018-06-29

Similar Documents

Publication Publication Date Title
EP3633913B1 (en) Provisioning a secure connection using a pre-shared key
CN101043326B (zh) 动态信息加密系统和方法
CN107465665A (zh) 一种基于指纹识别技术的文件加解密方法
KR101608815B1 (ko) 폐쇄형 네트워크에서 암복호화 서비스 제공 시스템 및 방법
CN107454590A (zh) 一种数据加密方法、解密方法及无线路由器
CN112187448B (zh) 一种数据加密方法及系统
CN109005184A (zh) 文件加密方法及装置、存储介质、终端
CN104901803A (zh) 一种基于cpk标识认证技术的数据交互安全保护方法
CN112039922B (zh) 一种加密通信方法及装置
CN104038336A (zh) 一种基于3des的数据加密方法
TW201720093A (zh) 安全輸入之方法、裝置及系統
WO2019165571A1 (zh) 一种传输数据的方法及系统
CN113992427A (zh) 基于相邻节点的数据加密发送方法及装置
CN100464337C (zh) 一种usb设备与主机进行安全通信的方法及装置
WO2019127145A1 (zh) 一种公私钥对获取方法、系统和pos终端
US20230114198A1 (en) Device in network
CN114785527B (zh) 数据传输方法、装置、设备及存储介质
WO2020123123A1 (en) Neighbor awareness networking password authentication
TWI611316B (zh) 安全輸入法之文本處理方法、文本處理裝置及文本處理系統
WO2018054144A1 (zh) 对称密钥动态生成方法、装置、设备及系统
CN105791301B (zh) 一种面向多用户组群信密分离的密钥分发管理方法
CN113452508A (zh) 数据加密方法、装置、设备和计算机可读存储介质
CN110636502A (zh) 一种无线加密通信方法和系统
WO2019165572A1 (zh) 一种传输数据的方法及系统
CN107171799A (zh) 一种数据传输加密的方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17936939

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17936939

Country of ref document: EP

Kind code of ref document: A1