Payment method, POS machine and computer storage medium
By introducing a timer circuit into the NFC module of the POS machine, limiting the card reading time and combining it with signal analysis, the problem of relay attacks is solved, achieving a balance between improved payment security and convenience.
Patent Information
- Application Number
- CN202510563655.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-09-16
AI Technical Summary
Existing technologies are difficult to effectively prevent relay attacks, which threatens the security of contactless payment systems.
By introducing a timer circuit into the NFC module of the POS machine, the contactless card reading time is limited to no more than the card reading operation time and the preset card reading time limit. Combined with signal strength analysis and time window matching algorithm, the relay attack risk is detected, security alarms are triggered, and transactions are intercepted.
Significantly reduce the possibility of relay attacks, improve payment security, maintain convenience, reduce implementation costs, and optimize user experience.
Smart Images

Figure CN120655288A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of financial payment security technology, and in particular to a payment method, a POS machine and a computer storage medium. Background Art
[0002] With the increasing popularity of contactless payment technology, contactless card reading capabilities on POS terminals (such as NFC) have become widely used in mobile payment scenarios. However, this convenience also presents security risks. Criminals can use devices like mobile phones as relays, relaying signals from legitimate payment cards to POS terminals, thereby enabling unauthorized payment operations. This attack, known as a "relay attack," poses a serious threat to the security of payment systems.
[0003] Traditional encryption technologies and communication protocols often fail to completely prevent relay attacks. Therefore, a more direct and efficient prevention method is needed. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a payment method, a POS machine and a computer storage medium, aiming to solve at least one of the above technical problems.
[0005] In a first aspect, the present invention provides a technical solution to the above-mentioned technical problem as follows: a payment method, applied to a POS machine, wherein the NFC module in the POS machine includes a timer circuit, and the method comprises: Reading the payment information of the relay terminal by a contactless card reading method, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; If the payment information is successfully read within the card reading operation time and the preset card reading time limit, the payment is completed based on the payment information.
[0006] The beneficial effect of the present invention is that the contactless card reading time (the time for reading the payment information) can be shortened by setting the card reading operation time and the preset card reading time upper limit through the timer circuit, that is, the time for reading the payment information is limited to the card reading operation time and the preset card reading time upper limit through hardware and software, significantly reducing the possibility of relay attacks.
[0007] On the basis of the above technical solution, the present invention can also be improved as follows.
[0008] Furthermore, the method further comprises: When the time for reading the payment information exceeds the card reading operation time or a preset upper limit of the card reading time, the reading of the payment information is interrupted.
[0009] Furthermore, the payment information is obtained based on a contactless signal generated by contacting the relay terminal; the method further includes: When abnormal signal fluctuation of the contactless signal is detected, it is determined that there is a relay attack risk.
[0010] Furthermore, the method further comprises: The total time taken to successfully read the payment information is compared with the preset card reading time of a valid payment card. If the total time taken is greater than the preset card reading time of the valid payment card, it is determined that there is a risk of a relay attack.
[0011] Furthermore, when there is a risk of relay attack, the method further includes: Trigger a security alert and block the transaction.
[0012] Furthermore, the method further comprises: If the payment information is not successfully read or a suspicious operation is detected, a prompt message is generated.
[0013] In a second aspect, in order to solve the above technical problems, the present invention further provides a POS machine, wherein the NFC module in the POS machine includes a timer circuit, and the POS machine includes: A payment information reading module, configured to read the payment information of the relay terminal by contactless card reading, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; The payment module is configured to complete payment based on the payment information if the payment information is successfully read within the card reading operation time and a preset card reading time upper limit.
[0014] In a third aspect, in order to solve the above technical problems, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the payment method of the present application is implemented.
[0015] Additional aspects and advantages of the present application will be given in part in the following description, which will become apparent from the following description, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments of the present invention.
[0017] Figure 1 A schematic diagram of a payment method according to an embodiment of the present invention; Figure 2A schematic diagram of a standard flow chart of contactless card reading for a POS machine provided in one embodiment of the present invention; Figure 3 A schematic diagram of a relay attack detection process provided by one embodiment of the present invention; Figure 4 A schematic diagram of a card reading time control flow provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] The principles and features of the present invention are described below. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.
[0019] The following describes in detail the technical solution of the present invention and how the technical solution of the present invention solves the above-mentioned technical problems using specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following embodiments of the present invention are described in conjunction with the accompanying drawings.
[0020] The solution provided by the embodiment of the present invention can be applied to any application scenario requiring contactless payment.
[0021] The embodiment of the present invention provides a possible implementation method, such as Figure 1 As shown in FIG, a flow chart of a payment method is provided. The solution can be executed by any electronic device, for example, a POS machine, or by a POS machine and a relay terminal. For the convenience of description, the method provided by the embodiment of the present invention will be described below using a POS machine as an example of the execution subject. The NFC module in the POS machine includes a timer circuit, such as Figure 1 As shown in the flowchart, the method may include the following steps: S10, reading the payment information of the relay terminal by a contactless card reading method, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; S20: If the payment information is successfully read within the card reading operation time and the preset card reading time limit, the payment is completed based on the payment information.
[0022] The method of the present invention can shorten the contactless card reading time (the time for reading the payment information) by setting the card reading operation time and the preset card reading time upper limit by the timer circuit. That is, the time for reading the payment information is limited to the card reading operation time and the preset card reading time upper limit by hardware and software, thereby significantly reducing the possibility of relay attacks.
[0023] The present invention will be further described below with reference to the following specific embodiments. Figure 2The diagram shows a standard process flow for contactless card reading on a POS machine. In this process, the terminal refers to the POS machine, and the card refers to the relay terminal. In this standard process, there is no time limit for reading payment information, nor is there any detection for relay attack risks. However, the entire process belongs to the prior art. Based on this, this embodiment provides a payment method, which is applied to a POS machine. The NFC module in the POS machine includes a timer circuit and can include the following steps: S10, reading the payment information of the relay terminal by a contactless card reading method, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; The relay end is a terminal used by users for contactless payment, such as a mobile phone.
[0024] Contactless payments are made in POS terminals using the NFC module. Users can place the relay terminal near the relay terminal to access payment information via a contactless card reader. This contactless payment method is also known as waving a card to pay.
[0025] The payment information may be generated by a payment application on the relay end, and specifically is information required to complete the payment, such as the user's payment account ID, payment amount, etc.
[0026] The time to read the payment information refers to the time it takes from the POS machine receiving the payment request from the relay end to obtaining the payment information. Figure 3 The time taken from selecting the PPSE to receiving the GPO return value is shown in . The PPSE can be understood as the payment request initiated, i.e., the start of card search, and the GPO return value can be understood as the payment information required for payment. This payment information refers to the information used for payment after user authorization. "AID" is used for the application identifier on the terminal. Figure 3 Compared to Figure 2 The prior art shown in Figure 2 The process of limiting the time of reading payment information is added in the process of Figure 3 The blank part of the content Figure 2 The contents of the corresponding parts are consistent.
[0027] In the POS terminal, the card read operation time set by hardware (timer circuit) serves as the time limit for reading payment information. The card read time limit set by software also serves as the time limit for reading payment information. The card read time limit and the card read operation time can be the same, for example, 0.3 seconds. A card read time control module can be developed in the POS terminal's operating system to set the card read time limit.
[0028] In the contactless card reader module of a POS terminal, the card reading time (i.e., the time it takes to read the payment information) is typically 500 milliseconds to 1 second in the event of a relay attack. This can be reduced to less than 0.3 seconds through hardware and software measures (without affecting normal card swiping, which generally takes less than 0.1 seconds). This adjustment can significantly reduce the time window (a period of time) during which the POS terminal listens for contactless signals, thereby reducing the likelihood of being vulnerable to relay attacks. If the time window is set to x seconds, only data within the current x seconds will be counted, and data from the previous x seconds or the next x seconds will not be considered.
[0029] S20: If the payment information is successfully read within the card reading operation time and the preset card reading time limit, the payment is completed based on the payment information.
[0030] Among them, the process of completing payment based on payment information is the same as the payment process in the prior art and will not be repeated here.
[0031] Optionally, the method further includes: When the time for reading the payment information exceeds the card reading operation time or a preset upper limit of the card reading time, the reading of the payment information is interrupted.
[0032] When the time for reading the payment information exceeds the card reading operation time or the preset upper limit of the card reading time, it indicates the possibility of a relay attack and the card reading operation needs to be forcibly terminated.
[0033] In this solution, on the basis of shortening the card reading time, a relay attack detection mechanism is added: The first one is that the payment information is obtained based on the contactless signal generated by the POS machine contacting the relay end; that is, when the POS machine contacts the relay end in a contactless manner, a contactless signal will be generated, and the generation time of this contactless signal will last at least for the time taken to read the payment information. Then, during the generation time of the contactless signal, the method also includes: when an abnormal signal fluctuation of the contactless signal is detected, determining that there is a risk of relay attack.
[0034] Among them, abnormal signal fluctuations indicate that there may be a risk of relay attack. The abnormal signal fluctuations are specifically at least one of the following: the signal strength of the contactless signal changes greatly during the generation time of the contactless signal, the change frequency is fast, or the signal strength is greater than the set strength threshold.
[0035] Second, the method further includes: The total time taken to successfully read the payment information is compared with the preset card reading time of a valid payment card. If the total time taken is greater than the preset card reading time of the valid payment card, it is determined that there is a risk of a relay attack.
[0036] The preset valid payment card read time can be set based on the card read operation time or a preset upper limit for the card read time, for example, also set to 0.3 seconds. The total time required to successfully read the payment information can be used as a time window, which is compared with the preset valid payment card read time. If the total time is greater than the preset valid payment card read time, a relay attack risk is determined.
[0037] As an example, see Figure 4 The card reading time control flow chart shown in Figure 4 The process and time from card search to obtaining the GPO return value are shown in the figure. The IC card refers to the relay end, wherein the normal card swipe processing time refers to the time spent to successfully obtain payment information once through the solution of this application (230ms), plus the total relay network time (not less than 20ms, including relay network transmission time, relay network transmission connection time, relay node / mobile phone forwarding time, relay node + two mobile phone forwarding time) is not less than 250ms, that is, the sum of the normal card swipe processing time plus the total relay network time (the total time to successfully read the payment information) is not less than 250ms, then the card reading time of the legitimate payment card is set to 300ms. When the total time to successfully read the payment information exceeds 300ms, it indicates that there is a risk of relay attack.
[0038] Optionally, when there is a risk of relay attack, the method further includes: A security alert is triggered and the transaction is blocked. The user may also be prompted to redo the operation.
[0039] Optionally, the method further includes: If the payment information is not successfully read or a suspicious operation is detected, a prompt message is generated.
[0040] Suspicious operations refer to read operations (payment information read operations) not initiated by the relay user, or two read operations received within 300ms from the same relay. Prompt messages will be displayed to alert users of potential payment risks or to change the card reading method (e.g., inserting the card).
[0041] Optionally, the prompt information may be at least one of the following: The POS screen displays "Payment abnormality, please try again"; "Please insert IC card" will be displayed on the POS screen; "Please change the card reading method" will be displayed on the POS screen; Audible alarm.
[0042] Compared with the prior art, the solution of the present invention has the following technical effects: 1. Improved payment security: By shortening card reading time—limiting it to less than 0.3 seconds through hardware or software—this significantly reduces the possibility of relay attacks and ensures user payment security. Signal strength analysis and a time window matching algorithm are combined to accurately detect and block relay attacks. On-screen prompts and audible alerts enhance user security awareness and payment experience.
[0043] 2. Reduce technical complexity: No major changes are required to existing payment protocols, implementation costs are low, and it is easy to promote.
[0044] 3. Optimize user experience: While improving security, maintain the convenience of payment operations without requiring additional user operations.
[0045] Based on Figure 1 Based on the same principle as the method shown in , an embodiment of the present invention further provides a POS machine, wherein the NFC module in the POS machine includes a timer circuit, and the POS machine may include a payment information reading module 210 and a payment module 220, wherein: The payment information reading module 210 is used to read the payment information of the relay terminal by a contactless card reading method, and the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time limit; The payment module 220 is configured to complete payment based on the payment information if the payment information is successfully read within the card reading operation time and a preset card reading time limit.
[0046] Optionally, the POS machine further includes: The interruption module is used to interrupt the reading of the payment information when the time for reading the payment information reaches the card reading operation time or a preset card reading time upper limit.
[0047] Optionally, the payment information is obtained based on a contactless signal generated by contacting the relay terminal; and the POS machine further includes: The relay attack detection module is used to determine the presence of a relay attack risk when abnormal signal fluctuations of the contactless signal are detected.
[0048] Optionally, the relay attack detection module is further configured to compare the total time taken to successfully read the payment information with a preset card reading time of a legitimate payment card. If the total time taken is greater than the preset card reading time of the legitimate payment card, it is determined that there is a risk of a relay attack.
[0049] Optionally, when there is a risk of relay attack, the POS machine further includes: Interception alarm module, used to trigger security alarms and intercept transactions.
[0050] Optionally, the POS machine further includes: The prompt module is used to generate a prompt message when the payment information is not successfully read or a suspicious operation is detected.
[0051] Among them, all modules in the POS machine can run in the operating system of the POS machine.
[0052] The POS machine of the embodiment of the present invention can execute the payment method provided by the embodiment of the present invention, and the implementation principle is similar. The actions performed by each module and unit in the POS machine in each embodiment of the present invention correspond to the steps in the payment method in each embodiment of the present invention. For the detailed functional description of each module of the POS machine, please refer to the description in the corresponding payment method shown in the previous text, which will not be repeated here.
[0053] In some embodiments, the POS machine provided by the embodiment of the present invention can be implemented by a combination of software and hardware. As an example, the POS machine provided by the embodiment of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the payment method provided by the embodiment of the present invention. For example, the processor in the form of a hardware decoding processor can adopt one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs) or other electronic components.
[0054] The modules involved in the embodiments of the present invention may be implemented in software or hardware, wherein the name of a module does not necessarily limit the module itself.
[0055] An embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer-readable storage medium is run on a computer, the computer can execute the corresponding contents of the aforementioned method embodiment.
[0056] According to another aspect of the present invention, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various implementations described above.
[0057] Computer program code for performing the operations of the present invention may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0058] It should be understood that the flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.
[0059] The computer-readable storage medium provided by the embodiments of the present invention may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or device.
[0060] The above description is merely a preferred embodiment of the present invention and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in the present invention.
Claims
1. A payment method, characterized in that: Applied to a POS machine, wherein the NFC module in the POS machine includes a timer circuit, the method comprises the following steps: Reading the payment information of the relay terminal by a contactless card reading method, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; If the payment information is successfully read within the card reading operation time and the preset card reading time limit, the payment is completed based on the payment information.
2. The method according to claim 1, characterized in that The method further comprises: When the time for reading the payment information exceeds the card reading operation time or a preset upper limit of the card reading time, the reading of the payment information is interrupted.
3. The method according to claim 1, characterized in that The payment information is obtained based on a contactless signal generated by contacting the relay terminal; the method further includes: When abnormal signal fluctuation of the contactless signal is detected, it is determined that there is a relay attack risk.
4. The method according to claim 1, wherein The method further comprises: The total time taken to successfully read the payment information is compared with the preset card reading time of a valid payment card. If the total time taken is greater than the preset card reading time of the valid payment card, it is determined that there is a risk of a relay attack.
5. The method according to claim 3 or 4, characterized in that When there is a risk of relay attack, the method further includes: Trigger a security alert and block the transaction.
6. The method according to any one of claims 1 to 4, characterized in that The method further comprises: If the payment information is not successfully read or a suspicious operation is detected, a prompt message is generated.
7. A POS machine, characterized in that: The NFC module in the POS machine includes a timer circuit, and the POS machine includes: A payment information reading module, configured to read the payment information of the relay terminal by contactless card reading, wherein the time for reading the payment information does not exceed the card reading operation time set by the timer circuit and the preset card reading time upper limit; The payment module is configured to complete payment based on the payment information if the payment information is successfully read within the card reading operation time and a preset card reading time upper limit.
8. The POS machine according to claim 7, characterized in that: The POS machine also includes: The interruption module is used to interrupt the reading of the payment information when the time for reading the payment information exceeds the card reading operation time or a preset card reading time upper limit.
9. The POS machine according to claim 7, characterized in that: The payment information is obtained based on a contactless signal generated by contacting the relay terminal; the POS machine further includes: The risk detection module is used to determine the presence of a relay attack risk when abnormal signal fluctuations of the contactless signal are detected.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.