Outward Marketing Terminal Business Processing System and Method
By setting up control modules and security components in the marketing terminal, combined with multiple verifications from the business backend server and client terminal, the problem of low information security of the dispatched marketing terminal is solved, and terminal legality verification and information security guarantee are achieved.
Patent Information
- Application Number
- CN202110388042.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-12
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-04-12
AI Technical Summary
The information security of existing bank outsourcing marketing terminals is low, and anti-counterfeiting measures are easily imitated and have poor results.
Set up a control module, an information collection module and a secure element with built-in root key in the marketing terminal. The terminal verification information is generated through the root key and authenticates with the business backend server. The encrypted verification information is generated and secondary verification is performed through the client terminal, and the customer custom identification code is displayed to prove the legitimacy of the terminal.
It improves the information security of the dispatched marketing terminal, prevents the use of fake terminals, and ensures the integrity and reliability of information transmission.
Smart Images

Figure CN113094688B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security and can also be used in the financial field. Specifically, it relates to an expatriate marketing terminal service processing system and method. Background Art
[0002] With the increasingly fierce competition in the banking industry and the continuous improvement of service awareness, each bank is carrying out some expatriate door-to-door services, such as on-site marketing and handling of business at some large enterprises, parks or communities. When carrying out these on-site services, bank staff will carry and use some special expatriate marketing terminals to market products or handle business for customers. Currently, the anti-counterfeiting measures adopted by banks in this regard are mostly printing LOGs on devices, etc., with low imitation costs and poor anti-counterfeiting effects. Summary of the Invention
[0003] Aiming at the problems in the prior art, this application provides an expatriate marketing terminal service processing system and method, which can effectively improve the information security when expatriate users use the marketing terminal.
[0004] To solve at least one of the above problems, this application provides the following technical solutions:
[0005] In a first aspect, this application provides an expatriate marketing terminal service processing system, including: a control module, an information collection module provided in the marketing terminal, and a security element with a root key built in. The control module is electrically connected to the information collection module and the security element respectively;
[0006] The control module is also connected to the business background server. After receiving the terminal activation verification request sent by the user through the information collection module, the control module generates terminal verification information according to the root key in the security element and sends it to the business background server, so that the business background server performs the first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes;
[0007] The control module is also used to receive the working key sent by the business background server, and after receiving the terminal encryption verification request sent by the user through the information collection module, generate encryption verification information according to the working key and display the encryption verification information in the form of a two-dimensional code, so that the customer terminal held by the customer sends the encryption verification information and the customer-defined identification code to the business background server by scanning the two-dimensional code, and the business background server performs the second terminal identity verification operation according to the encryption verification information, and returns the customer-defined identification code after the second terminal identity verification operation passes;
[0008] The control module is further configured to display the customer-defined identification code after receiving the customer-defined identification code sent by the service background server.
[0009] Further, the control module is further configured to store the working key in the security element after receiving the working key sent by the service background server.
[0010] Further, an information transmission module disposed in the marketing terminal is included, and the control module performs wireless communication with the service background server through the information transmission module.
[0011] Further, a touch screen disposed on the marketing terminal is included, the touch screen is connected to the control module, and the touch screen is configured to display the customer-defined identification code sent by the service background server and the basic service information pre-bound to the marketing terminal.
[0012] Further, a card reading module is included, the card reading module is disposed on the marketing terminal, and the card reading module is configured to detect and collect the electronic card information of the customer after receiving the service handling instruction sent by the user through the information collection module, and send the electronic card information to the control module, so that the control module sends the electronic card information to the service background server for corresponding service handling operations.
[0013] Further, the card reading module includes at least one of a second-generation ID card reading device for reading the second-generation ID card information of the customer, a non-contact IC card reading device for reading the bank IC card information of the customer, a magnetic stripe reading device for reading the magnetic stripe information of the customer's bank card, and an NFC reading device for reading the NFC portable device information of the customer.
[0014] In a second aspect, the present application provides an expatriate marketing terminal service processing method, including:
[0015] Receiving a terminal activation verification request sent by a user, generating terminal verification information according to a root key and sending it to a service background server, so that the service background server performs a first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes;
[0016] Receive the terminal encryption verification request sent by the user, generate encryption verification information according to the working key, and display the encryption verification information in the form of a two-dimensional code, so that the customer terminal held by the customer sends the encryption verification information and the customer-defined identification code to the business background server by scanning the two-dimensional code, and enable the business background server to perform a second terminal identity verification operation according to the encryption verification information, and return the customer-defined identification code after the second terminal identity verification operation passes;
[0017] After receiving the customer-defined identification code sent by the business background server, display the customer-defined identification code.
[0018] Further, the generating encryption verification information according to the working key and displaying the encryption verification information in the form of a two-dimensional code includes:
[0019] Perform an encryption calculation on the working key and the random characters according to a preset encryption algorithm to obtain an encryption key;
[0020] Perform a hash function encryption on the encryption key, the random characters, the device information code of the marketing terminal, and the current timestamp to obtain the encryption verification information and display it in the form of a two-dimensional code.
[0021] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the method for processing the business of the dispatched marketing terminal are implemented.
[0022] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for processing the business of the dispatched marketing terminal are implemented.
[0023] As can be seen from the above technical solutions, the present application provides a system and method for processing the business of a dispatched marketing terminal. By setting a security element in the marketing terminal to first verify the legality of the terminal when the marketing terminal is enabled, and obtaining a working key from the business background server after the verification passes, and then when the marketing terminal actually performs a business operation, generating encryption verification information through the working key, and at the same time obtaining the encryption verification information through the customer's own customer terminal and sending it to the business background server to enable the customer to perform a second identity verification on the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legality of the marketing terminal, thereby ensuring the information security when using the marketing terminal. Description of the Drawings
[0024] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0025] Figure 1 It is a structural diagram of an expatriate marketing terminal business processing system in an embodiment of the present application;
[0026] Figure 2 It is a structural diagram of an expatriate marketing terminal business processing system in a specific embodiment of the present application;
[0027] Figure 3 It is one of the flow diagrams of the expatriate marketing terminal business processing method in an embodiment of the present application;
[0028] Figure 4 It is the second flow diagram of the expatriate marketing terminal business processing method in an embodiment of the present application;
[0029] Figure 5 It is a structural diagram of an electronic device in an embodiment of the present application. Detailed implementation manners
[0030] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0031] Considering the problem of insecure information in the existing expatriate marketing terminals, the present application provides an expatriate marketing terminal business processing system and method. When the marketing terminal is enabled, the security element set in the marketing terminal first verifies the terminal's legitimacy, and after the verification passes, obtains a working key from the business background server. Then, when the marketing terminal actually performs business operations, the working key is used to generate encrypted verification information, and at the same time, the encrypted verification information is obtained through the customer's own customer terminal and sent to the business background server to enable the customer to perform a secondary identity verification on the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legitimacy of the marketing terminal, thereby ensuring the information security when using the marketing terminal.
[0032] In order to effectively improve the information security of expatriate users when using the marketing terminal, this application provides an embodiment of an expatriate marketing terminal business processing system for implementing all or part of the content of the expatriate marketing terminal business processing method. Refer to Figure 1 , the expatriate marketing terminal business processing system specifically includes the following components: a control module, an information collection module, and a security element with a root key built therein, where the control module is electrically connected to the information collection module and the security element respectively.
[0033] The control module is also connected to the business background server. After receiving the terminal activation verification request sent by the user through the information collection module, the control module generates terminal verification information based on the root key in the security element and sends it to the business background server, so that the business background server performs the first terminal identity verification operation based on the terminal verification information and returns a working key after the first terminal identity verification operation passes.
[0034] The control module is also used to receive the working key sent by the business background server. After receiving the terminal encryption verification request sent by the user through the information collection module, the control module generates encryption verification information based on the working key and displays the encryption verification information as a QR code, so that the customer terminal held by the customer sends the encryption verification information and the customer-defined identification code to the business background server by scanning the QR code, and the business background server performs the second terminal identity verification operation based on the encryption verification information and returns the customer-defined identification code after the second terminal identity verification operation passes.
[0035] The control module is also used to display the customer-defined identification code after receiving the customer-defined identification code sent by the business background server.
[0036] Optionally, the security element can be a security chip (abbreviated as SE, usually provided in the form of a chip. To prevent external parsing attacks and protect data security, it has encryption / decryption logic circuits in the chip. Once the encrypted data is written, it cannot be read, only verified or erased and rewritten). At the same time, the security element can also be provided with a device for self-destruction of the key when the device is disassembled to ensure the absolute security of the internal information.
[0037] Optionally, the root key can be written during the initial installation of the application and is used to verify the legality of the device each time the terminal is activated (for example, when the expatriate arrives at the designated business handling location and signs in); the working key can be encrypted by the business background server with the root key and transmitted to the expatriate marketing terminal and written into the SE after each sign-in and relevant verifications are completed. The validity period can be custom-set (for example, not exceeding 1 day), and the working key will be redownloaded each time after signing out and signing in again.
[0038] In a specific example, the user (i.e., the seconded staff member) needs to apply for approval in advance before going out each time. After approval, information such as the name and work photo of the user, the user ID number, the usage time, and the usage scope will be reserved in the business background server. After the staff member arrives at the scene, they sign in. When signing in, two-factor authentication will be performed: device legality authentication and the legality authentication of this outbound service (whether the approval is passed). Only after the sign-in authentication is successful can the marketing terminal obtain the working key. The working key is encrypted by the root key and then sent to the seconded marketing terminal and written into the SE. After signing in, in addition to the normal transaction buttons on the terminal interface, there is also a "Customer Verification" button. When the customer clicks it, a QR code is generated on the screen. The QR code contains the encrypted verification information encrypted with the working key and the device information. The customer can use their mobile phone to log in to the corresponding bank (or UnionPay) APP (or mini-program) and use the dedicated verification tool to scan the QR code. After scanning, the customer randomly enters a four-digit random number such as "8936" on their mobile phone. After the server verifies that the relevant information is correct, it encrypts the random number "8936" with the corresponding working key and sends it to the corresponding marketing terminal. After the terminal decrypts it, it displays "The number you entered is 8936" on the screen, and the reserved information (or part of it) registered by the server such as the name and work photo of the user, the user ID number, the usage time, and the usage scope is displayed on the customer's mobile phone. After the customer checks, the device verification is completed.
[0039] As can be seen from the above description, the seconded marketing terminal service processing system provided by the embodiment of the present application can first verify the legality of the terminal when the marketing terminal is enabled through the security element set in the marketing terminal, obtain the working key from the business background server after the verification is passed, and then generate encrypted verification information through the working key when the marketing terminal actually performs business operations. At the same time, the customer obtains the encrypted verification information through their own customer terminal and sends it to the business background server to enable the customer to perform secondary identity verification on the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legality of the marketing terminal, thereby ensuring the information security when using the marketing terminal.
[0040] In an embodiment of the seconded marketing terminal service processing system of the present application, the following specific content is further included: the control module is further configured to store the working key in the security element after receiving the working key sent by the business background server.
[0041] In an embodiment of the seconded marketing terminal service processing system of the present application, the following specific content is further included: an information transmission module set in the marketing terminal, and the control module performs wireless communication with the business background server through the information transmission module.
[0042] In an embodiment of the dispatched marketing terminal service processing system of the present application, the following specific contents are further included: a touch screen disposed on the marketing terminal, the touch screen is connected to the control module, and the touch screen is used to display the customer-defined identification code sent by the service background server and the basic service information pre-bound with the marketing terminal.
[0043] In an embodiment of the dispatched marketing terminal service processing system of the present application, the following specific contents are further included: a card reading module, the card reading module is disposed on the marketing terminal, and the card reading module is used to detect and collect the electronic card information of the customer after receiving the service handling instruction sent by the user through the information collection module, and send the electronic card information to the control module, so that the control module sends the electronic card information to the service background server for corresponding service handling operations.
[0044] In an embodiment of the dispatched marketing terminal service processing system of the present application, the following specific contents are further included: the card reading module includes at least one of a second-generation ID card reading device for reading the second-generation ID card information of the customer, a non-contact IC card reading device for reading the bank IC card information of the customer, a magnetic stripe reading device for reading the magnetic stripe information of the customer's bank card, and an NFC reading device for reading the NFC portable device information of the customer.
[0045] To further illustrate this solution, the present application also provides a specific application example of applying the above-mentioned dispatched marketing terminal service processing system. See Figure 2 , which specifically includes the following contents: a marketing terminal, a server, an encryption machine, a management terminal, network devices, and related management software.
[0046] Specifically, in addition to the functions of a general marketing terminal, the marketing terminal also has a built-in security element (abbreviated as SE, usually provided in the form of a chip. To prevent external parsing attacks and protect data security, it has encryption / decryption logic circuits in the chip. Once encrypted data is written, it cannot be read, only verified or erased and rewritten).
[0047] At least two keys are stored in the SE: a root key and a working key. The root key is written during the initial installation of the application and updated regularly, and is used to verify the legality of the device during each sign-in; after the server verifies the legality of the device during each sign-in, the working key is encrypted by the server through the root key and transmitted to the dispatched marketing terminal for writing into the SE. The validity period does not exceed 1 day, and the working key will be redownloaded every time after signing out and signing in again. Once the key is written, it cannot be read, only verified or erased and rewritten, and the SE is equipped with a function of self-destructing the key once disassembled.
[0048] The dispatched marketing terminal must be used in conjunction with the management system, which includes but is not limited to servers, encryption machines, management terminals, network equipment and related management software.
[0049] Specifically, the management software is installed on the server (server side) and the management terminal (client side) respectively. Before each outbound marketing, bank employees need to submit an application on the management terminal. The application content includes but is not limited to the user, the location of use, the business scope to be used, the serial number of the equipment to be used, the time of use, etc. After approval by the management personnel, the server side will store the outbound service information, including but not limited to the user (including name, work number, photo), location of use, time of use, etc.
[0050] After arriving at the site, the bank staff signs in and signs in on the dispatched marketing terminal. When signing in, the dispatched marketing terminal initiates a legal device verification to the server through the root key. At the same time, the server verifies whether the application for this dispatched service has been approved. After the server verifies that the device is legal and the application for this dispatched service is legal, it sends a working key to the dispatched marketing terminal. The working key is encrypted with the root key and sent to the dispatched marketing terminal and written into the SE.
[0051] At this time, in addition to the normal business handling buttons on the external marketing terminal interface, there is also a "Customer Verification" button. After the customer clicks it, the external marketing terminal generates a QR code on the screen. The process of generating the QR code is as follows:
[0052] (1) The external marketing terminal generates a six-digit random number.
[0053] (2) The external marketing terminal sends this six-digit random number to the built-in SE.
[0054] (3) The built-in SE calls the working key and uses the agreed algorithm to calculate the six-digit random number and generate a calculation result, and then sends the calculation result, which is a segment of numbers, to the dispatched marketing terminal.
[0055] (4) The dispatched marketing terminal encrypts the calculation result, random number, device information code, and timestamp information group using any tamper-proof encryption algorithm (such as a hash algorithm) to form a segment of characters, referred to as "verification information".
[0056] (5) The dispatched marketing terminal converts the verification information into a QR code and displays it on the dispatched terminal screen.
[0057] Then, when the customer conducts anti-counterfeiting verification, they can use their own mobile phone to log in to the corresponding bank (or UnionPay) APP (or mini-program) and use a dedicated verification tool to scan the QR code. After scanning the QR code, the mobile phone will send the verification information contained in the QR code to the server. At this time, the mobile phone verification page prompts the customer to randomly enter a four-digit random number on their own mobile phone. For example, the customer enters "8936". The server then starts to verify the verification information, and the verification process is as follows:
[0058] 1. First, use the same anti-tampering encryption algorithm (such as the hash algorithm) to decrypt the verification information to ensure that the data has not been tampered with. If it has been tampered with, directly send the message "Verification failed, terminal suspicious" to the customer's mobile phone. If it has not been tampered with, proceed to step 2.
[0059] 2. Verify whether the timestamp information is within the valid time. If it has expired, send a message indicating that the information has expired to the customer's mobile phone to prompt the customer to verify again. If it is valid, proceed to step 3.
[0060] 3. Send the six-digit random number to the encryption machine. The encryption machine calculates the random number according to the agreed algorithm and the device code information, and calls the corresponding working key to output the result to the server.
[0061] 4. The server compares the calculation result of the encryption machine with the calculation result of the dispatched marketing terminal sent. If the comparison result is inconsistent, directly send the message "Verification failed, terminal suspicious" to the customer's mobile phone. If the comparison result is consistent, proceed to step 5.
[0062] 5. Send the four-digit random number entered by the customer to the encryption machine and encrypt it according to the device information code by calling the corresponding working key to form encrypted information.
[0063] 6. The server sends the encrypted information to the corresponding dispatched marketing terminal according to the device information code, and sends some information reserved for this dispatched application, such as the user's name and work photo, user ID number, usage time, usage scope (to protect privacy, some fields can be masked as appropriate), etc. to the customer's mobile phone.
[0064] 7. After receiving the encrypted information sent by the server, the dispatched marketing terminal sends it to the SE for decryption, and displays the decryption result on the screen: The random number you entered is "8936", please check.
[0065] 8. The customer checks whether the random number on the screen of the dispatched marketing terminal is the same as the one they entered.
[0066] 9. The customer checks whether the partial information reserved for this dispatched application displayed on the mobile phone, such as the user's name and work photo, user ID number, usage time, usage scope (to protect privacy, some fields can be masked as appropriate), etc. is consistent with the actual situation.
[0067] 10. Verification completed.
[0068] As can be seen from the above, the present application can at least also achieve the following technical effects:
[0069] (1) Installing an SE in the dispatched marketing terminal and downloading a key can be used for anti-counterfeiting verification, which is safe and reliable.
[0070] (2) Adopting the method of QR code verification, converting the key verification information in the SE into a QR code for easy customer authentication.
[0071] (3) During the authentication process, the customer's mobile phone is used as a third-party device (their own mobile phone) and a third-party tool (a dedicated verification tool on the bank or UnionPay APP) for verification, rather than obtaining the verification method from the on-site dispatched marketing terminal, avoiding the situation where illegal personnel use fake tools to authenticate fake devices.
[0072] (4) The entire verification process involves three parties: the marketing terminal, the server (including the encryption machine), and the customer's mobile phone. Two random numbers are applied, one of which is initiated by the customer's mobile phone and displayed on the marketing terminal, ensuring the integrity and reliability of the entire verification process.
[0073] (5) Comparing the information reserved by the server with the actual situation and sending the relevant information to the customer's mobile phone to enhance the reliability of the verification.
[0074] In order to effectively improve the information security when dispatched users use the marketing terminal, the present application provides an embodiment of a method for processing dispatched marketing terminal services. The execution subject can be the marketing terminal. Refer to Figure 3 , and the method for processing dispatched marketing terminal services specifically includes the following content:
[0075] Step S101: Receive the terminal activation verification request sent by the user, generate terminal verification information according to the root key, and send it to the service background server, so that the service background server performs the first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes.
[0076] Step S102: Receive the terminal encryption verification request sent by the user, generate encryption verification information according to the working key, and display the encryption verification information in the form of a QR code, so that the customer terminal held by the customer sends the encryption verification information and the customer-defined identification code to the service background server by scanning the QR code, and the service background server performs the second terminal identity verification operation according to the encryption verification information, and returns the customer-defined identification code after the second terminal identity verification operation passes.
[0077] Step S103: After receiving the customer-defined identification code sent by the service back-end server, display the customer-defined identification code.
[0078] As can be seen from the above description, the method for processing the business of the dispatched marketing terminal provided by the embodiment of the present application can first verify the legality of the terminal through the security element set in the marketing terminal when the marketing terminal is enabled, obtain the working key from the service back-end server after the verification is passed, and then generate encrypted verification information through the working key when the marketing terminal actually performs a business operation. At the same time, obtain the encrypted verification information through the customer's own customer terminal and send it to the service back-end server to enable the customer to perform a secondary authentication of the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legality of the marketing terminal, thereby ensuring the information security when using the marketing terminal.
[0079] In order to ensure the security of information transmission, in an embodiment of the method for processing the business of the dispatched marketing terminal of the present application, refer to Figure 4 , the above step S102 may specifically include the following content:
[0080] Step S201: Perform an encryption calculation on the working key and the random character according to a preset encryption algorithm to obtain an encrypted key.
[0081] Step S202: Perform a hash function encryption according to the encrypted key, the random character, the device information code of the marketing terminal, and the current timestamp to obtain an encrypted verification information and perform a two-dimensional code display.
[0082] From the hardware level, in order to effectively improve the information security of dispatched users when using the marketing terminal, the present application provides an embodiment of an electronic device for implementing all or part of the content in the method for processing the business of the dispatched marketing terminal. The electronic device specifically includes the following content:
[0083] A processor, a memory, a communication interface, and a bus; wherein, the processor, the memory, and the communication interface complete communication with each other through the bus; the communication interface is used to implement information transmission between the dispatched marketing terminal business processing system and related devices such as the core business system, the user terminal, and the related database. The logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, the logic controller can be implemented with reference to the embodiments of the method for processing the business of the dispatched marketing terminal and the embodiments of the dispatched marketing terminal business processing system, and the content is incorporated herein, and the repeated parts are not described again.
[0084] It can be understood that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.
[0085] In practical applications, part of the method for processing the business of the dispatched marketing terminal can be executed on the electronic device side as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. The present application does not make any limitations in this regard. If all operations are completed in the client device, the client device may further include a processor.
[0086] The above-mentioned client device may have a communication module (i.e., a communication unit), and can be communicatively connected to a remote server to realize data transmission with the server. The server may include a server on the task scheduling center side, and in other implementation scenarios, it may also include a server of an intermediate platform, such as a server of a third-party server platform communicatively linked to the task scheduling center server. The server may include a single computer device, or may include a server cluster composed of multiple servers, or a server structure of a distributed device.
[0087] Figure 5 It is a schematic block diagram of the system composition of the electronic device 9600 according to an embodiment of the present application. As Figure 5 shown, the electronic device 9600 may include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It should be noted that this Figure 5 is exemplary; other types of structures can also be used to supplement or replace this structure to implement telecommunications functions or other functions.
[0088] In one embodiment, the function of the method for processing the business of the dispatched marketing terminal can be integrated into the central processing unit 9100. Among them, the central processing unit 9100 may be configured to perform the following controls:
[0089] Step S101: Receive a terminal activation verification request sent by a user, generate terminal verification information according to a root key, and send it to the business background server, so that the business background server performs a first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes.
[0090] Step S102: Receive the terminal encryption verification request sent by the user, generate encryption verification information according to the working key, and display the encryption verification information in the form of a two-dimensional code, so that the customer terminal held by the customer sends the encryption verification information and the customer-defined identification code to the service background server by scanning the two-dimensional code, and enable the service background server to perform a second terminal identity verification operation according to the encryption verification information, and return the customer-defined identification code after the second terminal identity verification operation passes.
[0091] Step S103: After receiving the customer-defined identification code sent by the service background server, display the customer-defined identification code.
[0092] As can be seen from the above description, for the electronic device provided in the embodiment of the present application, when the marketing terminal is enabled, the security element set in the marketing terminal first verifies the legality of the terminal, and after the verification passes, obtains the working key from the service background server. Then, when the marketing terminal actually performs a business operation, the encryption verification information is generated through the working key, and at the same time, the customer obtains the encryption verification information through his own customer terminal and sends it to the service background server to enable the customer to perform a secondary identity verification on the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legality of the marketing terminal, thereby ensuring the information security when using the marketing terminal.
[0093] In another implementation manner, the business processing system of the dispatched marketing terminal can be separately configured from the central processing unit 9100. For example, the business processing system of the dispatched marketing terminal can be configured as a chip connected to the central processing unit 9100, and the functions of the business processing method of the dispatched marketing terminal are realized through the control of the central processing unit.
[0094] As Figure 5 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include Figure 5 all the components shown in Figure 5 ; in addition, the electronic device 9600 may further include
[0095] As Figure 5 shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control unit, and may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.
[0096] Among them, the memory 9140 can be, for example, one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. The above information related to failures can be stored, and in addition, a program for executing relevant information can also be stored. And the central processing unit 9100 can execute the program stored in the memory 9140 to achieve information storage or processing, etc.
[0097] The input unit 9120 provides an input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display can be, for example, an LCD display, but is not limited thereto.
[0098] The memory 9140 can be a solid-state memory. For example, it can be a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be a memory that stores information even when power is off, can be selectively erased, and has more data. An example of this memory is sometimes called an EPROM, etc. The memory 9140 can also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes called a buffer). The memory 9140 can include an application / function storage unit 9142, which is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.
[0099] The memory 9140 can also include a data storage unit 9143, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 can include various drivers of the electronic device for communication functions and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).
[0100] The communication module 9110 is a transmitter / receiver 9110 that transmits and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processing unit 9100 to provide an input signal and receive an output signal, which can be the same as in the case of a conventional mobile communication terminal.
[0101] Based on different communication technologies, in the same electronic device, multiple communication modules 9110 can be provided, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby implementing normal telecommunication functions. The audio processor 9130 may include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 9130 is also coupled to a central processor 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.
[0102] An embodiment of the present application also provides a computer-readable storage medium capable of implementing all steps in the method for processing the business of the dispatched marketing terminal with the execution subject being a server or a client in the above embodiments. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all steps in the method for processing the business of the dispatched marketing terminal with the execution subject being a server or a client in the above embodiments are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0103] Step S101: Receive a terminal activation verification request sent by a user, generate terminal verification information according to a root key, and send it to the business background server, so that the business background server performs a first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes.
[0104] Step S102: Receive a terminal encryption verification request sent by the user, generate encryption verification information according to the working key, and display the encryption verification information as a QR code, so that the customer terminal held by the customer sends the encryption verification information and a customer-defined identification code to the business background server by scanning the QR code, and the business background server performs a second terminal identity verification operation according to the encryption verification information, and returns the customer-defined identification code after the second terminal identity verification operation passes.
[0105] Step S103: Display the customer-defined identification code after receiving the customer-defined identification code sent by the business background server.
[0106] As can be seen from the above description, for the computer-readable storage medium provided by the embodiments of the present application, when the marketing terminal is enabled, the security element disposed in the marketing terminal first verifies the legality of the terminal, and after the verification passes, obtains the working key from the business background server. Then, when the marketing terminal actually performs business operations, the working key is used to generate encrypted verification information. At the same time, the encrypted verification information is obtained through the customer's own customer terminal and sent to the business background server to enable the customer to perform re-authentication on the marketing terminal. If the marketing terminal can automatically display the customer-defined identification code, it proves the legality of the marketing terminal, thereby ensuring the information security when using the marketing terminal.
[0107] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, apparatus, or computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0108] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatuses), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one or more of the processes Figure 1 or multiple processes and / or blocks
[0109] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that realizes the functions specified in Figure 1 one or more of the processes Figure 1 or multiple processes and / or blocks
[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide for realizing the functions in the process Figure 1Steps of one or more processes and / or boxes Figure 1 Steps of functions specified in one or more boxes.
[0111] In the present invention, specific embodiments are used to illustrate the principles and implementation manners of the present invention. The description of the above embodiments is only for helping to understand the method and its core idea of the present invention. At the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. An expatriate marketing terminal business processing system, characterized in that, Including: A control module, an information collection module, and a security element with a root key built therein, which are arranged in a marketing terminal. The control module is electrically connected to the information collection module and the security element respectively; The control module is further connected to a business background server. After receiving a terminal activation verification request sent by a user through the information collection module, the control module generates terminal verification information according to the root key in the security element and sends it to the business background server, so that the business background server performs a first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes; The control module is further configured to receive the working key sent by the business background server, and after receiving a terminal encryption verification request sent by the user through the information collection module, generate encryption verification information according to the working key and display the encryption verification information as a two-dimensional code, so that a customer terminal held by a customer sends the encryption verification information and a customer-defined identification code to the business background server by scanning the two-dimensional code, and the business background server performs a second terminal identity verification operation according to the encryption verification information, and returns the customer-defined identification code after the second terminal identity verification operation passes; The control module is further configured to display the customer-defined identification code after receiving the customer-defined identification code sent by the business background server; if the marketing terminal can automatically display the customer-defined identification code, it proves that the marketing terminal is legal; Among them, the process of generating the two-dimensional code is as follows: (1) The dispatched marketing terminal generates a custom identification code; (2) The dispatched marketing terminal sends the custom identification code to the built-in security element; (3) The built-in security element calls the working key to perform an operation on the custom identification code using a predefined algorithm and generates an operation result, and sends the operation result to the dispatched marketing terminal; (4) The dispatched marketing terminal encrypts the operation result, the custom identification code, the device information code, and the timestamp information group once using any anti-tampering encryption algorithm, and forms a character string after encryption as the verification information; (5) The dispatched marketing terminal converts the verification information into a two-dimensional code and displays it on the screen of the dispatched terminal; Among them, the server verifies the verification information, and the verification process is as follows: <1> First, decrypt the verification information using the anti-tampering encryption algorithm to verify that the data has not been tampered with. If it has been tampered with, directly send an "verification failed, terminal suspicious" message to the customer's mobile phone. If it has not been tampered with, execute step <2>; <2> Verify whether the timestamp information is within the valid time. If it has expired, send a message indicating that the information has expired to prompt the customer to verify again. If it is valid, execute step <3>; <3> Send the custom identification code to the encryption machine, and the encryption machine uses a predefined algorithm to calculate the custom identification code according to the device code information by calling the corresponding working key and outputs the result to the server; <4>The server compares the calculation result of the encryption machine with the operation result of the dispatched marketing terminal sent up. If the comparison result is inconsistent, it directly sends the message "Verification failed, terminal suspicious" to the customer's mobile phone. If the comparison result is consistent, it proceeds to step <5>; <5>The custom identification code input by the customer is sent into the encryption machine and encrypted using the corresponding working key according to the device information code to form encrypted information; <6>The server sends the encrypted information to the corresponding dispatched marketing terminal according to the device information code; <7>After receiving the encrypted information sent by the server, the dispatched marketing terminal sends it to the security element for decryption and displays the decryption result on the screen; <8>The customer checks whether the custom identification code on the screen of the dispatched marketing terminal is the same as the one they input.
2. The expatriate marketing terminal service processing system according to claim 1, wherein The control module is also used to store the working key in the security element after receiving the working key sent by the service background server.
3. The expatriate marketing terminal service processing system according to claim 1, wherein, It further includes an information transmission module arranged in the marketing terminal, and the control module communicates wirelessly with the service background server through the information transmission module.
4. The expatriate marketing terminal service processing system according to claim 1, characterized in that, It further includes a touch screen arranged on the marketing terminal. The touch screen is connected to the control module and is used to display the customer custom identification code sent by the service background server and the service information pre-bound to the marketing terminal.
5. The expatriate marketing terminal service processing system according to claim 1, characterized in that It further includes a card reading module arranged on the marketing terminal. The card reading module is used to detect and collect the customer's electronic card information after receiving the service handling instruction sent by the user through the information collection module, and send the electronic card information to the control module, so that the control module sends the electronic card information to the service background server for corresponding service handling operations.
6. The expatriate marketing terminal service processing system according to claim 5, characterized in that, The card reading module includes at least one of a second-generation ID card reading device for reading the second-generation ID card information of the customer, a non-contact IC card reading device for reading the bank IC card information of the customer, a magnetic stripe reading device for reading the magnetic stripe information of the customer's bank card, and an NFC reading device for reading the NFC portable device information of the customer.
7. A method for processing the business of an expatriate marketing terminal, which is applied to the expatriate marketing terminal business processing system according to any one of claims 1 to 6, and is characterized in that, The method includes: Receiving a terminal activation verification request sent by the user, generating terminal verification information according to the root key and sending it to the service background server, so that the service background server performs a first terminal identity verification operation according to the terminal verification information, and returns a working key after the first terminal identity verification operation passes; Receiving the terminal encryption verification request sent by the user, generating encryption verification information according to the working key and displaying the encryption verification information as a QR code, so that the customer terminal held by the customer sends the encryption verification information and the customer custom identification code to the service background server by scanning the QR code, and the service background server performs a second terminal identity verification operation according to the encryption verification information, and returns the customer custom identification code after the second terminal identity verification operation passes; After receiving the customer-defined identification code sent by the service background server, display the customer-defined identification code; if the marketing terminal can automatically display the customer-defined identification code, it proves that the marketing terminal is legal; Among them, the process of generating a QR code is as follows: (1) The dispatched marketing terminal generates a custom identification code; (2) The dispatched marketing terminal sends the custom identification code to the built-in security element; (3) The built-in security element calls the working key to perform an operation on the custom identification code using a predefined algorithm and generates an operation result, and sends the operation result to the dispatched marketing terminal; (4) The dispatched marketing terminal encrypts the operation result, custom identification code, device information code, and timestamp information group once using any anti-tampering encryption algorithm, and forms a string of characters after encryption as the verification information; (5) The dispatched marketing terminal converts the verification information into a QR code and displays it on the screen of the dispatched terminal; Among them, the server verifies the verification information, and the verification process is as follows: <1> First, decrypt the verification information using the anti-tampering encryption algorithm to verify that the data has not been tampered with. If it has been tampered with, directly send a "verification failed, terminal suspicious" message to the customer's mobile phone. If it has not been tampered with, execute step <2>; <2> Verify whether the timestamp information is within the valid time. If it has expired, send an information expiration message to the customer's mobile phone to prompt the customer to verify again. If it is valid, execute step <3>; <3> Send the custom identification code to the encryption machine. The encryption machine uses a predefined algorithm to calculate the custom identification code according to the device code information by calling the corresponding working key and outputs the result to the server; <4> The server compares the calculation result of the encryption machine with the operation result of the dispatched marketing terminal sent above. If the comparison result is inconsistent, directly send a "verification failed, terminal suspicious" message to the customer's mobile phone. If the comparison result is consistent, execute step <5>; <5> Send the custom identification code input by the customer into the encryption machine and encrypt it according to the device information code by calling the corresponding working key to form encrypted information; <6> The server sends the encrypted information to the corresponding dispatched marketing terminal according to the device information code; <7> After receiving the encrypted information sent by the server, the dispatched marketing terminal sends it to the security element for decryption and displays the decryption result on the screen; <8> The customer checks whether the custom identification code on the screen of the dispatched marketing terminal is the same as the one they entered.
8. The method for processing the expatriate marketing terminal service according to claim 7, wherein The generation of the encrypted verification information according to the working key and the display of the encrypted verification information as a QR code include: Performing an encryption calculation on the working key and a random character according to a preset encryption algorithm to obtain an encryption key; Performing a hash function encryption on the encryption key, the random character, the device information code of the marketing terminal, and the current timestamp to obtain the encrypted verification information and display it as a QR code.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the dispatched marketing terminal service processing method according to any one of claims 7 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the dispatched marketing terminal service processing method according to any one of claims 7 to 8.
Citation Information
Patent Citations
System and method for performing transaction security authentication in mobile device
CN106027501A