Secure Payment Method and System for Contactless Transactions
By performing initial security checks in transaction applications and real-time authentication with the backend system, the security problems of general equipment in contactless bank card transactions are solved, and a secure contactless transaction method and system is realized, which expands the application scope and reduces deployment costs.
Patent Information
- Application Number
- CN202111325109.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-11-10
AI Technical Summary
How to achieve secure contactless bank card transactions on general-purpose devices to avoid the security risks of sensitive data storage and processing caused by the lack of anti-tampering circuits and security chips.
By performing initial security checks in trading applications, including version updates, key component integrity checks and end-cloud authentication, obtaining terminal transaction parameters and account security keys, performing contactless transaction data processing, and performing legality authentication and data clearing with the backend monitoring system to ensure the security of the transaction process.
Improves the security of general-purpose devices in contactless transactions, expands the scope of transaction implementation, and reduces deployment costs and time.
Smart Images

Figure CN113988858B_ABST
Abstract
Description
Technical Field
[0001] The present invention mainly relates to payment information technology, and particularly to a secure payment method and system for contactless transactions. Background Art
[0002] With the rapid development of Internet technology, online payment has gradually replaced cash payment and become the mainstream payment method. Bank card payment, with its fast and secure transaction characteristics, is one of the important payment means in the global online payment system. As the carriers of payment transactions, the security and convenience of payment terminals and applications have also been increasingly emphasized. To achieve secure bank card payment, a dedicated POS terminal is usually adopted nowadays to provide a secure execution environment for transaction processing, which brings R & D, certification, and deployment costs to POS manufacturers and acquirers. For general devices, due to the lack of anti-disassembly circuits, security chips, etc., there are security risks in the storage and processing of sensitive data, and most solutions cannot ensure the security when using general devices for payment, thus restricting the application of bank card payment functions in general devices.
[0003] Therefore, how to ensure the security when users use general devices for payment is an urgent problem to be solved. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a secure payment method for contactless transactions, which can ensure the security when a general device is used for payment.
[0005] The technical solution adopted by the present invention to solve the above technical problem is a secure payment method for contactless transactions, including: the transaction application performs an initialization security check on the application terminal, including sequentially checking the version update of the transaction application, the integrity of the key components of the transaction application, and the security authentication between the application terminal and the background monitoring system; if the initialization security check is qualified, the application terminal provides a terminal user login interface for receiving the login information of the terminal user; the transaction application obtains terminal transaction parameters and a terminal account security key from the background transaction processing system; starts a contactless transaction between the application terminal and the payment device, and the application terminal obtains payment account data of the payment device; the transaction application performs security processing on the payment account data; the transaction application sends the monitoring data of the contactless transaction to the background monitoring system, and the background monitoring system performs legality authentication on the monitoring data; the transaction application sends the transaction message data of the contactless transaction to the background transaction processing system and obtains a transaction result from the background transaction processing system; and the transaction application performs a completion process on the contactless transaction and clears the payment account data cache.
[0006] In an embodiment of the present invention, the transaction application includes an authentication component and a transaction kernel component. The steps of checking the integrity of the key components of the transaction application include: checking the integrity of the authentication component, checking the integrity of the transaction kernel component, and checking the integrity of the system log of the transaction application.
[0007] In an embodiment of the present invention, the steps of checking the security authentication between the application terminal and the background monitoring system include: sending the device status data of the application terminal to the background monitoring system, the background monitoring system performing a security determination on the device status data according to established rules, after the result of the security determination is passed, the transaction application obtaining a random number test seed from the background monitoring system and performing a random number check, if the result of the random number check is passed, the security authentication between the application terminal and the background monitoring system is successful.
[0008] In an embodiment of the present invention, after the terminal user login interface receives the login information of the terminal user, it further includes: the transaction application sending the login information to the background monitoring system for verifying the legality of the terminal user.
[0009] In an embodiment of the present invention, the terminal transaction parameters include one or any combination of the application ID of the transaction application, the terminal parameters of the application terminal, and the public key of the authentication center. The terminal account security key includes a terminal account data key and / or a PIN encryption key.
[0010] In an embodiment of the present invention, it further includes: writing the terminal transaction parameters into the transaction kernel component of the transaction application; storing the terminal account security key into the security module of the transaction application.
[0011] In an embodiment of the present invention, the application terminal is an Android device including an NFC module.
[0012] In an embodiment of the present invention, the application terminal includes a camera and an NFC interface. The steps of starting a non-contact transaction between the application terminal and a payment device further include: locking the permissions of the camera and the NFC interface before the application terminal obtains the payment account data of the payment device, and the application terminal interacting with the payment device through the NFC module.
[0013] In an embodiment of the present invention, the steps of the transaction application performing security processing on the payment account data include: performing desensitization processing and encryption processing on the payment account data, wherein the encryption processing is performed through the security module of the transaction application.
[0014] In an embodiment of the present invention, the monitoring data of the contactless transaction includes one or any combination of the end - user ID, the application terminal ID, the transaction identifier of the contactless transaction, and the geographical location where the contactless transaction occurs.
[0015] In an embodiment of the present invention, it further includes: the transaction application periodically checks the security authentication between the application terminal and the background monitoring system.
[0016] In an embodiment of the present invention, it further includes: when a PIN needs to be input for the contactless transaction, before inputting the PIN, the transaction application performs the initialization security check and sends the result of the initialization security check to the background monitoring system, and the background monitoring system determines whether the application terminal meets the condition for inputting the PIN.
[0017] In an embodiment of the present invention, it further includes: the transaction application provides a PIN input interface for receiving the PIN; the transaction application combines the received PIN and the payment account data to form PIN combination data, and the security module of the transaction application encrypts the PIN combination data and clears the plain - text cache data of the PIN and the payment account data.
[0018] In an embodiment of the present invention, the transaction message data of the contactless transaction includes the ciphertext of the payment account data and / or the ciphertext of the PIN combination data.
[0019] In an embodiment of the present invention, the payment device is a contactless bank card.
[0020] The present invention also proposes a secure payment system for contactless transactions to solve the above - mentioned technical problems, including: an application terminal with a transaction application, a background monitoring system, and a background transaction processing system; a memory for storing instructions executable by a controller; and a controller for controlling the application terminal, the background monitoring system, and the background transaction processing system to execute the instructions to implement the secure payment method as described above.
[0021] Before the execution of the contactless transaction of the secure payment method of the present invention, by checking the security status of the transaction application and the application terminal in the initialization stage and performing interactive authentication with the background system, and performing security processing and legality authentication in the transaction execution stage, the security of the entire transaction process is ensured, so that the application terminal can be extended to the scope of general devices, expanding the implementation scope of contactless transactions and greatly reducing the deployment cycle and cost of the acquiring application. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings, where:
[0023] Figure 1 is an exemplary flowchart of a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0024] Figure 2 is a framework diagram of an application terminal in a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0025] Figure 3 A framework diagram of a transaction application in a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0026] Figure 4 is a specific implementation example flowchart of steps S110 - S120 in a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0027] Figure 5 is a specific implementation example flowchart of steps S130 - S180 in a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0028] Figure 6 is an exemplary timing diagram of a secure payment method for non-contact transactions according to an embodiment of the present invention;
[0029] Figure 7 is a system block diagram of a secure payment system for non-contact transactions according to an embodiment of the present invention. Specific Embodiments
[0030] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings.
[0031] In the following description, many specific details are set forth to facilitate a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0032] As shown in this application and the claims, unless the context clearly indicates otherwise, words such as "a", "an", "one", and / or "the" are not specifically singular and may also include the plural. Generally speaking, the terms "including" and "comprising" only indicate the inclusion of the steps and elements that have been clearly identified, and these steps and elements do not constitute an exclusive list. A method or device may also include other steps or elements.
[0033] Although the terms used in this application are selected from well-known and commonly used terms, some of the terms mentioned in the specification of this application may be chosen by the applicant according to his or her judgment, and their detailed meanings are described in the relevant parts of the description herein. In addition, it is required to understand this application not only through the actual terms used, but also through the meanings implied by each term.
[0034] Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of this application. It should be understood that the operations before or below do not necessarily need to be executed precisely in sequence. On the contrary, various steps can be executed in reverse order or simultaneously. Also, other operations can be added to these processes, or one or more steps can be removed from these processes.
[0035] Figure 1 is an exemplary flowchart of a secure payment method for contactless transactions according to an embodiment of the present invention. Refer to Figure 1 As shown, the secure payment method of this embodiment includes the following steps:
[0036] Step S110: The transaction application performs an initial security check on the application terminal, including sequentially checking the version update of the transaction application, the integrity of the key components of the transaction application, and the security authentication between the application terminal and the background monitoring system.
[0037] Step S120: The application terminal provides a terminal user login interface for receiving the login information of the terminal user.
[0038] Step S130: The transaction application obtains the terminal transaction parameters and the terminal account security key from the background transaction processing system.
[0039] Step S140: Initiate a contactless transaction between the application terminal and the payment device, and the application terminal obtains the payment account data of the payment device.
[0040] Step S150: The transaction application performs security processing on the payment account data.
[0041] Step S160: The transaction application sends the monitoring data of the contactless transaction to the background monitoring system, and the background monitoring system performs legality authentication on the monitoring data.
[0042] Step S170: The transaction application sends the transaction message data of the contactless transaction to the background transaction processing system and obtains the transaction result from the background transaction processing system.
[0043] Step S180: The transaction application performs completion processing on the contactless transaction and clears the payment account data cache.
[0044] Next, the above steps will be introduced in detail through specific embodiments.
[0045] In step S110, the present invention sets up a transaction application on the application terminal. The present invention does not limit the specific form of the application terminal, and the application terminal can be any general device such as a mobile phone, a computer, a POS machine, etc. that can install the transaction application. The present invention does not limit the specific implementation manner and format of the transaction application, and the transaction application is an application program that can be installed on a general device to implement contactless bank card transactions.
[0046] In some embodiments, the application terminal is an Android device including an NFC module, and correspondingly, the transaction application is an Android application.
[0047] To facilitate the description of the specific execution process of the secure payment method of the present invention, the present invention provides exemplary block diagrams of the application terminal and the transaction application, and describes each step of the secure payment method in combination with the application terminal and the transaction application. Figure 2 It is a framework diagram of the application terminal in the secure payment method for contactless transactions according to an embodiment of the present invention. Figure 3 A framework diagram of the transaction application in the secure payment method for contactless transactions according to an embodiment of the present invention. Refer to Figure 2 As shown, the application terminal 200 of this embodiment includes one or more of an NFC module 210, a camera 220, and an NFC interface 230. Among them, the application terminal 200 can interact with the payment device through the NFC module 210. The payment device can be a device with contactless payment function.
[0048] In some embodiments, the payment device is a contactless bank card.
[0049] Refer to Figure 3 As shown, the transaction application 300 of this embodiment includes one or more of a security module 310, an authentication component 320, a transaction kernel component 330, a version check module 340, a log module 350, a transaction module 360, a monitoring module 370, and an input module 380. These components and modules are only used to represent the components or modules for implementing the corresponding functions of the transaction application 300, and are not used to limit the specific components, modules and their quantities to be included in the transaction application 300.
[0050] In step S110, when the transaction application 300 is started and the network connection is successful, an initial security check is performed in the application terminal 200. The objects of the initial check include the version update of the transaction application 300, the integrity of the key components of the transaction application 300, and the security authentication between the application terminal 200 and the background monitoring system.
[0051] In some embodiments of the present invention, the transaction application 300 checks for application updates after startup. Specifically, when the network connection is successful, the version check module 340 of the transaction application 300 is started. The version check module 340 can send a request to the server side to check whether there is an updated version of the transaction application 300. If the version on the server side is higher than the installed application version, the application update is executed. In addition, the transaction application 300 can also detect whether the built-in white box key of the application has been updated. If there is an update, the key management interface of the security module 310 is called to perform the white box key update. In some embodiments, the steps for checking the integrity of the key components of the transaction application 300 include: checking the integrity of the authentication component 320, checking the integrity of the transaction kernel component 330, and checking the integrity of the system log of the transaction application 300 through the log module 350. If any abnormality is detected, a check failure is prompted on the user interface, and subsequent steps are not allowed to be executed. Thus, payment transaction security issues caused by incomplete key components are avoided.
[0052] Step S110 also includes the step of checking the security authentication between the application terminal 200 and the background monitoring system. In some embodiments, the background monitoring system is set in the cloud. Therefore, this step can also be referred to as "end-cloud authentication". Specifically, this step may include the following steps S111 - S114:
[0053] Step S111: Send the device status data of the application terminal 200 to the background monitoring system.
[0054] Combined with Figure 3 , in this step, the authentication component 320 in the transaction application 300 sends the collected information including the information of the application terminal 200 and the information of the transaction application 300 to the background monitoring system through a secure channel for authentication. The above application terminal information and transaction application information include: the platform and version number of the application terminal 200, transaction application information (package name, fingerprint), the version number of the transaction application 300, the situation where the transaction application 300 and its configuration are modified, the situation where the transaction application 300 and its configuration are tampered with, the situation where the public key and certificate of the transaction application 300 are modified or tampered with, whether the transaction application 300 is running in the developer mode, whether the transaction application 300 is running in the debug mode, the transaction application 300 modifies its running environment after initial configuration, the inspection situation of the transaction application 300, the status of the payment kernel, the operation status of the random number generator function, the communication ports of the open interfaces accessed by the transaction application 300 and the system interface permissions, and the number of transactions since the last execution of the security authentication, one or any combination of them.
[0055] Step S112: The background monitoring system makes a security determination on the device status data according to the established rules. The above-mentioned established rules correspond to the application terminal information and transaction application information in step S111. A security determination is made on the above information according to the established rules. If the determination and authentication fail, the transaction application 300 prompts an error and refuses to execute the subsequent steps. By making a security determination on the application terminal information and transaction application information, transaction security issues caused by the tampering of relevant information can be avoided.
[0056] After the result of the security determination is passed, the transaction application 300 obtains a random number test seed from the background monitoring system and performs a random number check. The application terminal 200 checks whether the function of the application terminal random number generator is normal according to the random number test seed obtained by the transaction application 200. If it is not normal, it prompts an error and refuses to execute the subsequent steps.
[0057] The security authentication between the application terminal 200 and the background monitoring system is successful. After the check in step S113 passes, the security verification between the application terminal 200 and the background monitoring system is successful, and the subsequent steps can be executed.
[0058] According to step S110, performing an initial security check after the transaction application 300 is started can avoid transaction security issues caused by security vulnerabilities of the transaction application 300 and the application terminal 200, and improve the security of the entire transaction process.
[0059] In some embodiments of the present invention, the transaction application 300 periodically checks the security authentication between the application terminal 200 and the background monitoring system. That is, the transaction application 300 periodically performs the security authentication between the application terminal 200 and the background monitoring system in step S110. For example, the time interval is set to 30 minutes. If the authentication component 320 detects that 30 minutes have passed since the last security authentication, the security authentication between the application terminal 200 and the background monitoring system is started again for parameter synchronization. After the authentication is correct, the application terminal 200 and the background monitoring system perform time synchronization and request a trusted random number seed. The application terminal 200 can send the random number seed to a payment device including a bank card. The payment device generates an authorization message through key operation. Thereafter, the application terminal 200 sends the message to the acquiring background for verification. If the verification passes, the subsequent steps are continued; otherwise, an error is prompted and the subsequent steps are stopped from being executed. The present invention does not limit the specific length of this time interval. The step of periodic check can be executed at any time period after the transaction application 300 is started, or can be executed in the background of the application terminal 200, regardless of whether the transaction application 300 is started.
[0060] In step S120, when the initialization security check in step S110 is qualified, the application terminal 200 provides a terminal user login interface for receiving the login information of the terminal user. The present invention places no restrictions on the terminal user, who can be a merchant, an individual, etc. Under normal circumstances, the terminal user as the cashier is mostly a merchant, and the transaction application 300 is a type of acquiring application.
[0061] In some embodiments, after the terminal user login interface receives the login information of the terminal user, it further includes: the transaction application 300 sends the login information to the background monitoring system for verifying the legitimacy of the terminal user. The login information may include the username and password of the terminal user. The transaction application 300 sends the username and password of the terminal user to the background monitoring system for verification. If the login is unsuccessful, it prompts failure and performs re-login. If the login fails multiple times, a freezing mechanism is executed to prevent brute-force attacks on merchant information. By verifying the legitimacy of the terminal user and limiting the number of logins, illegal logins are prevented, and the security of the entire transaction process is improved.
[0062] Figure 4 It is a flowchart of a specific implementation example of steps S110 - S120 in the secure payment method for contactless transactions according to an embodiment of the present invention. Steps S110 - S120 are used to illustrate the initialization process when the transaction application 300 is started. Among them, the transaction application 300 is specifically implemented as an application store, which includes a security module, an authentication component, a transaction kernel component, a log module, etc.; the background monitoring system is set in the cloud; the terminal user is a merchant. Refer to Figure 4 As shown, the steps of this embodiment include:
[0063] Step S410: Check whether there is an update for the transaction application in the application store and update the white-box key of the security module;
[0064] Step S420: Perform security checks on key modules such as the authentication component, the transaction kernel component, and the system log;
[0065] Step S430: Perform end-cloud authentication, establish a secure channel with the background monitoring system, and send the inspection results and device status to the background monitoring system for determination;
[0066] Step S440: Perform merchant identity authentication, and a legitimate merchant can log in to the transaction application and initiate payment.
[0067] According to the above steps S110 and S120, the initialization security check of the transaction application 300 can be completed to ensure the establishment of a reliable secure channel between the transaction application 300 and the background monitoring system, confirm the identity of the legitimate merchant, and facilitate the subsequent execution of specific transactions.
[0068] In step S130, the transaction application 300 obtains the terminal transaction parameters and the terminal account security key from the background transaction processing system.
[0069] In an embodiment of the present invention, the terminal transaction parameters include one or any combination of the application ID of the transaction application 300, the terminal parameters of the application terminal 200, and the public key of the authentication center. The terminal account security key includes the terminal account data key and / or the PIN encryption key. PIN is the personal password in a payment transaction.
[0070] In some embodiments of the present invention, before the transaction application 300 obtains the terminal transaction parameters and the terminal account security key from the background transaction processing system, it may further include reconfirming the environment in which the application terminal 200 operates. If the operating environment is the developer mode or the debug mode, an error is prompted and subsequent steps are rejected. If the operating environment is normal, the transaction application 300 establishes a secure channel with the background transaction processing system, and the transaction application 300 obtains the terminal transaction parameters and the terminal account security key from the background transaction processing system through this secure channel.
[0071] In some embodiments, the terminal transaction parameters may be written into the transaction kernel component 330 of the transaction application 300, and the terminal account security key may be separately stored in the security module 310 of the transaction application 300.
[0072] In step S140, a non-contact transaction between the application terminal 200 and the payment device is started, and the application terminal 200 obtains the payment account data of the payment device.
[0073] Reference Figure 2 As shown, in an embodiment of the present invention, the application terminal 200 is an Android device including an NFC module 210, and may further include a camera 220 and an NFC interface 230. The payment device includes a non-contact bank card. The step of starting a non-contact transaction between the application terminal 200 and the payment device further includes: before the application terminal 200 obtains the payment account data of the payment device, locking the permissions of the camera 220 and the NFC interface 230, and then the application terminal 200 interacts with the payment device through the NFC module 210 to obtain the transaction-related data of the payment device. The payment device transaction-related data belongs to sensitive information. By locking the permissions of the camera 220 and the NFC interface 230, it is possible to prevent third-party applications from illegally stealing sensitive information, thereby improving the security of the transaction process. Specifically, as Figure 3As shown, the permissions to lock the camera 220 and the NFC interface 230 can be executed through the transaction module 360 in the transaction application 300, without the need for additional development and design of the application terminal 200, reducing the transaction cost. At the same time, by checking the security status of the transaction application and the application terminal and interacting with the background system for real-time authentication, the security of the transaction is guaranteed, such that the transaction application does not require the application terminal to have physical anti-disassembly, system tailoring, and configuration of a security unit, enabling some general-purpose devices to be used as the application terminal 200.
[0074] In step S150, the transaction application 300 performs security processing on the payment account data.
[0075] In an embodiment of the present invention, after obtaining the payment account data of the payment device, the transaction application 300 performs security processing on the payment account data to enhance the confidentiality of the payment account data.
[0076] In some embodiments, the security processing includes the following steps: performing desensitization processing and encryption processing on the payment account data. Among them, the encryption processing is performed through the security module 310 in the transaction application 300.
[0077] In some embodiments of the present invention, the method for performing desensitization processing on the payment account data includes hiding the key data of the bank card number. For example, the first 6 and the last 4 digits of the bank card number are retained, and the other parts are masked. For example, if the bank card number is: 6226123456789012, after desensitization processing, it is 6226***9012. The method for performing encryption processing on the payment account data includes encrypting using the account data key described above, and the encryption algorithm includes one or any combination of TDES, AES, and SM4. It can be understood that the above embodiments do not constitute a limitation on the desensitization processing and encryption processing methods in the present invention.
[0078] In step S160, the transaction application sends the monitoring data of the contactless transaction to the background monitoring system, and the background monitoring system performs legality authentication on the monitoring data.
[0079] Reference Figure 3 As shown, in an embodiment of the present invention, the monitoring module 370 in the transaction application 300 can be used to upload the monitoring data of the contactless transaction to the background monitoring system. If the monitoring system determines that the transaction is illegal, it prompts an error and terminates the subsequent transaction. If it determines that the transaction is legal, the subsequent steps are performed. Among them, the monitoring data of the contactless transaction includes one or any combination of the terminal user ID, the application terminal ID, the transaction identifier of the contactless transaction, and the geographical location where the contactless transaction occurs.
[0080] In some embodiments of the present invention, when the transaction application 300 detects that a PIN needs to be entered for a contactless transaction, before the PIN is entered, the transaction application 300 performs an initial security check and establishes a secure channel with the background monitoring system, and sends the result of the initial security check to the background monitoring system through the secure channel. The background monitoring system determines whether the application terminal 200 meets the condition for entering the PIN. If the input condition is not met, the subsequent transaction is terminated. If the condition is met, the subsequent steps are continued. The initial security check is the step S110 as described above, including checking the integrity of the authentication component 210, the integrity of the transaction kernel component 230, and the integrity of the system log 240.
[0081] Refer to Figure 3 As shown, for embodiments that require entering a PIN, the transaction application 300 includes an input module 380 for providing an interface for the user to enter a password, such as a password keyboard. In these embodiments, when entering the PIN, the transaction application 300 calls the input module 380 to draw a password keyboard with a random sequence, which is used to receive the entered PIN. Subsequently, the transaction application 300 combines the received PIN and the payment account data to form PIN combination data. Then, the transaction application 300 calls the security module 310 to encrypt the combined data. After the encryption is completed, the input module 380 immediately clears the plaintext cache data of the PIN and the payment account data. Among them, the security module 310 can use the PIN encryption key to encrypt the combined data, and the encryption algorithm includes one or any combination of TDES, AES, and SM4.
[0082] In step S170, the transaction application 300 sends the transaction message data of the contactless transaction to the background transaction processing system and obtains the transaction result from the background transaction processing system.
[0083] In an embodiment of the present invention, after the background monitoring system authenticates the monitoring data as legal, the transaction module 360 in the transaction application 300 sends the transaction message data to the background transaction processing system and obtains the transaction result from the background transaction processing system. Among them, the transaction message data includes the ciphertext of the payment account data and / or the ciphertext of the PIN combination data; the transaction result is transaction approval or transaction rejection.
[0084] In step S180, the transaction application 300 performs a completion process on the contactless transaction and clears the payment account data cache.
[0085] In an embodiment of the present invention, after a transaction is completed, the transaction application 300 accumulates and records transaction information, which can be used for authenticating the transaction application 300 and transaction auditing. Among them, the transaction information can be stored in the application terminal 200 and / or the cloud. The transaction application 300 can also erase the account cache data and related transaction keys. Among them, the account cache data includes the data obtained by desensitizing the payment account data in the foregoing text. By clearing the account data and related transaction keys, it is possible to prevent third parties from illegally obtaining this information, ensuring the security of the transaction process.
[0086] Figure 5 It is a specific implementation example flowchart of steps S130 - S180 in the secure payment method for contactless transactions in an embodiment of the present invention. Steps S130 - S180 are used to illustrate the transaction process in which the transaction application 300 executes a transaction, and steps S510 - S590 are included within the scope of steps S130 - S180. Refer to Figure 5 As shown, the transaction process of this embodiment includes the following steps:
[0087] Step S510: Perform a timed authentication check. If it has been more than 30 minutes since the last security authentication, authenticate with the background monitoring system again; after authentication is completed, download the random number seed.
[0088] Step S520: Obtain transaction - related parameters from the transaction processing background.
[0089] Step S530: Lock the NFC interface and camera permissions, read the bank card data, and obtain information related to the payment account.
[0090] Step S540: Perform desensitization processing and encryption processing on the obtained payment account data.
[0091] Step S550: Check the PIN input environment to ensure that when the cardholder executes PIN input, the transaction application and the application terminal are in a secure state.
[0092] Step S560: Establish a secure channel with the background monitoring system and perform a health check to ensure that the transaction application is in the secure state required by the background monitoring system when the PIN is input.
[0093] Step S570: Draw a random sequence keyboard, the user executes PIN input, and perform secure encryption on the PIN data.
[0094] Step S580: Establish a secure channel with the background, and the transaction application uploads monitoring data and transaction message data to request online authorization.
[0095] Step S590: After the transaction is completed, perform sensitive data clearing.
[0096] Figure 6It is an exemplary timing diagram of a secure payment method for contactless transactions according to an embodiment of the present invention. Refer to Figure 6 As shown, the timing diagram includes the following task execution entities: transaction application 601, payment device 602, background monitoring system 603, and transaction processing system 604. Among them, the transaction application 601 is the same as the Figure 3 transaction application 300 shown, and is set in the application terminal 200. The payment device 602 can be a contactless bank card. The background monitoring system 603 and the transaction processing system 604 are the same as the background monitoring system and the transaction processing system described above respectively, and can both be set in the cloud. Figure 6 All or part of the steps S610 - S621 in the timing process shown in can correspond to all or part of the processes in Figure 1 , Figure 4 , Figure 5 . Among them, the long bars below each task execution entity represent the time progress bar from top to bottom, and the endpoints of the aligned progress bars indicate that the task nodes perform actions at the same time.
[0097] As Figure 6 shown, the secure payment method of this embodiment includes the following steps:
[0098] Step S610: The transaction application 601 performs an initialization check.
[0099] Step S611: The transaction application 601 establishes a secure channel with the background monitoring system 603 to perform application terminal and terminal account authentication.
[0100] Step S612: Periodically authenticate the application terminal and the terminal account, obtain security parameters, and synchronize the time.
[0101] Step S613: The transaction application 601 establishes a secure channel with the transaction processing system 604 to obtain transaction parameters.
[0102] Step S614: Perform a transaction between the transaction application 601 and the payment device 602.
[0103] Step S615: The transaction application 601 processes payment account data.
[0104] Step S616: The transaction application 601 checks the environment of the input PIN.
[0105] Step S617: The transaction application 601 establishes a secure channel with the background monitoring system 603 to perform a legality check.
[0106] Step S618: The transaction application 601 encrypts the input PIN.
[0107] Step S619: The transaction application 601 establishes a secure channel with the background monitoring system 603 for transaction monitoring.
[0108] Step S620: The transaction application 601 establishes a secure channel with the transaction processing system 603 for transaction data authentication.
[0109] Step S621: The transaction application 601 clears the account data and keys.
[0110] The above embodiments of the present invention propose a secure payment method for contactless transactions. This method ensures the security of the entire transaction process by checking the security of the transaction application and the application terminal, and performing real-time interactive authentication and legality checks with the background system.
[0111] The present invention also proposes a secure payment system for contactless transactions. The secure payment system includes: an application terminal with a transaction application, a background monitoring system, and a background transaction processing system; a memory for storing instructions executable by a controller; and a controller for controlling the application terminal, the background monitoring system, and the background transaction processing system to execute the instructions to implement the secure payment method described above.
[0112] Figure 7 It is a system block diagram of a secure payment system for contactless transactions according to an embodiment of the present invention. Refer to Figure 7 As shown, the secure payment system 700 has an application terminal 710 with a transaction application, a background monitoring system 720, a background transaction processing system 730, a memory 740, and a controller 750. The application terminal 710, the background monitoring system 720, and the background transaction processing system 730 therein respectively correspond to the application terminal, the background monitoring system, and the background transaction processing system in the foregoing, and the foregoing description can all be used to explain the secure payment system 700.
[0113] In some embodiments, the memory 740 may include a read-only memory (ROM), a random access memory (RAM), etc. When the application is on a personal computer, the secure payment system 700 may further include a hard disk. The internal communication bus can realize data communication between the components of the secure payment system 700. The controller 750 can make judgments and issue prompts for controlling the application terminal 710, the background monitoring system 720, and the background transaction processing system 730 to execute corresponding steps. In some embodiments, the controller 750 may be composed of one or more controllers. The communication port can realize the data communication between the controller 750 and the outside. In some embodiments, the controller 750 can send and receive information and data from the network through the communication port. The result processed by the controller 750 is transmitted to the user device through the communication port and displayed on the user interface.
[0114] The above-mentioned secure payment system can be implemented as a computer program, stored in a hard disk, and loaded into the controller 750 for execution to implement a secure payment system for contactless transactions of the present application.
[0115] The basic concepts have been described above. Obviously, for those skilled in the art, the above invention disclosure is only an example and does not constitute a limitation to the present application. Although not explicitly stated here, those skilled in the art may make various modifications, improvements, and corrections to the present application. Such modifications, improvements, and corrections are proposed in the present application, so such modifications, improvements, and corrections still fall within the spirit and scope of the exemplary embodiments of the present application.
[0116] Meanwhile, the present application uses specific terms to describe the embodiments of the present application. Such as "one embodiment", "an embodiment", and / or "some embodiments" mean a certain feature, structure, or characteristic related to at least one embodiment of the present application. Therefore, it should be emphasized and noted that the "one embodiment" or "an embodiment" or "an alternative embodiment" mentioned twice or more at different positions in this specification does not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the present application can be appropriately combined.
[0117] In some embodiments, numbers are used to describe the components and the quantity of attributes. It should be understood that such numbers used for the description of embodiments are, in some examples, modified by the modifiers "about", "approximately", or "substantially". Unless otherwise stated, "about", "approximately", or "substantially" indicate that the said numbers allow a variation of ±20%. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, and such approximate values can change according to the characteristics required by individual embodiments. In some embodiments, the numerical parameters should consider the specified significant digits and adopt the method of retaining the general number of digits. Although the numerical ranges and parameters used to confirm the breadth of the scope in some embodiments of the present application are approximate values, in specific embodiments, such numerical settings are as precise as possible within the feasible range.
Claims
1. A secure payment method for non-contact transactions, characterized in that, Including: The transaction application performs initialization security checks on the application terminal, including successively checking for version updates of the transaction application, the integrity of the critical components of the transaction application, and the security authentication between the application terminal and the background monitoring system; If the initialization security check is passed, the application terminal provides a terminal user login interface for receiving the login information of the terminal user; The transaction application obtains terminal transaction parameters and a terminal account security key from the background transaction processing system; Start a contactless transaction between the application terminal and the payment device, and the application terminal obtains payment account data of the payment device; The transaction application performs security processing on the payment account data; The transaction application sends the monitoring data of the contactless transaction to the background monitoring system, and the background monitoring system performs legality authentication on the monitoring data; The transaction application sends the transaction message data of the contactless transaction to the background transaction processing system and obtains a transaction result from the background transaction processing system; and The transaction application performs completion processing on the contactless transaction and clears the payment account data cache The application terminal is an Android device including an NFC module; The application terminal includes a camera and an NFC interface. The step of starting a contactless transaction between the application terminal and the payment device further includes: locking the permissions of the camera and the NFC interface before the application terminal obtains the payment account data of the payment device, and the application terminal interacts with the payment device through the NFC module.
2. The secure payment method according to claim 1, wherein The transaction application includes an authentication component and a transaction kernel component. The step of checking the integrity of the critical components of the transaction application includes: checking the integrity of the authentication component, checking the integrity of the transaction kernel component, and checking the integrity of the system log of the transaction application.
3. The secure payment method according to claim 1, wherein The step of checking the security authentication between the application terminal and the background monitoring system includes: sending the device status data of the application terminal to the background monitoring system, and the background monitoring system performs a security determination on the device status data according to established rules. After the result of the security determination is passed, the transaction application obtains a random number test seed from the background monitoring system and performs a random number check. If the result of the random number check is passed, the security authentication between the application terminal and the background monitoring system is successful.
4. The secure payment method according to claim 1, wherein, After the terminal user login interface receives the login information of the terminal user, it further includes: the transaction application sends the login information to the background monitoring system for verifying the legality of the terminal user.
5. The secure payment method according to claim 1, characterized in that, The terminal transaction parameters include one or any combination of the application ID of the transaction application, the terminal parameters of the application terminal, and the public key of the certification center. The terminal account security key includes a terminal account data key and / or a PIN encryption key.
6. The secure payment method according to claim 5, wherein Also including: Writing the terminal transaction parameters into the transaction kernel component of the transaction application; storing the terminal account security key in the security module of the transaction application.
7. The secure payment method according to claim 1, characterized in that, The steps for the transaction application to perform security processing on the payment account data include: performing desensitization processing and encryption processing on the payment account data, wherein the encryption processing is executed by the security module of the transaction application.
8. The secure payment method according to claim 1, wherein The monitoring data of the contactless transaction includes a combination of one or any of the end-user ID, application terminal ID, transaction identifier of the contactless transaction, and geographical location where the contactless transaction occurs.
9. The secure payment method according to claim 1, wherein It further includes: The transaction application periodically checks the security authentication between the application terminal and the background monitoring system.
10. The secure payment method according to claim 1, characterized in that, It further includes: When the contactless transaction requires PIN input, before the PIN is input, the transaction application performs the initialization security check and sends the result of the initialization security check to the background monitoring system, and the background monitoring system determines whether the application terminal meets the PIN input condition.
11. The secure payment method according to claim 10, wherein It further includes: The transaction application provides a PIN input interface for receiving the PIN; the transaction application combines the received PIN and the payment account data to form PIN combined data, and the security module of the transaction application encrypts the PIN combined data and clears the plaintext cache data of the PIN and the payment account data.
12. The secure payment method according to claim 11, wherein The transaction message data of the contactless transaction includes the ciphertext of the payment account data and / or the ciphertext of the PIN combined data.
13. The secure payment method according to claim 1, wherein The payment device is a contactless bank card.
14. A secure payment system for contactless transactions, comprising: An application terminal with a transaction application, a background monitoring system, and a background transaction processing system; A memory for storing instructions executable by a controller; A controller for controlling the application terminal, the background monitoring system, and the background transaction processing system to execute the instructions to implement the secure payment method according to any one of claims 1-13.
Citation Information
Patent Citations
Payment platform and payment method on basis of intelligent equipment
CN103699989A
Safety control method and apparatus
CN105550866A
Near-field mobile payment method and device, acceptance terminal and storage medium
CN110738490A