A data transmission method and apparatus
By combining the detection module with the operating system and secure operating area of the terminal device, and using simple user operations to complete the verification, the problem of heavy user mental burden and automated attacks in the existing technology is solved, and the security and convenience are improved.
Patent Information
- Application Number
- CN202110265228.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-11
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2041-03-11
AI Technical Summary
Existing human-machine verification methods place a heavy psychological burden on users, especially those with poor eyesight or hearing, and are easily exploited by automated attack tools, leading to a decline in network system security.
By combining the operating system running area and the secure running area of the terminal device, the detection module in the secure running area completes the verification through simple user operations, such as vertical, horizontal, shaking or double-clicking, and ensures the security of data transmission through encrypted signature.
It reduces the mental burden of user authentication, improves authentication security, prevents automated attacks, and ensures the security and integrity of data transmission.
Smart Images

Figure CN115080975B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular to a data transmission method and apparatus. Background Technology
[0002] The booming World Wide Web (WEB) has spurred the creation of numerous automated attack software programs. Driven by the profits of the gray market internet industry, automated internet attacks not only consume vast amounts of computing, communication, and marketing resources, but also wantonly steal and leak sensitive personal information from ordinary users. For example, when users log in with account passwords, apply for SMS verification codes, send emails, or participate in marketing promotions, they need to prevent malicious attacks and competition from automated bots. The common practice is to use human-machine verification technology, such as image or voice recognition-based CAPTCHAs, to prevent cyberattacks.
[0003] A representative example of CAPTCHAs is Google's nine-square grid CAPTCHA. The main idea is to use images or audio clips that are difficult for machines to recognize but are recognizable by users. These are displayed or played for the user to examine, guiding them to understand and recognize the content of the images and answer questions on the interface to complete the verification. For example, a nine-square grid CAPTCHA requires users to find street view photos containing cars among nine images, and a correct answer is required to pass the verification.
[0004] While this verification method can effectively prevent attackers from simulating user operations on the terminal and improve network system security, it requires users to recognize information such as images, text, or voice verification codes, which is very mentally taxing and not user-friendly for ordinary users. It is even more difficult for people with poor eyesight or hearing. As can be seen from the comments and complaints under many posts on the Internet, users are dissatisfied with and helpless about this kind of human-computer verification method. Summary of the Invention
[0005] This application provides a data transmission method and apparatus, mainly used to solve the human-machine verification problem on mobile terminal devices, which can significantly reduce the mental burden of verification for users. Specifically, this application discloses the following technical solutions:
[0006] In a first aspect, this application provides a data transmission method applicable to a terminal device, the terminal device including an operating system running area and a secure running area, the operating system running area being isolated from the secure running area, the operating system running area including a first detection module, and the secure running area including a second detection module, the method comprising:
[0007] When the first detection module receives a one-time transaction ID sent by the risk control server, a session window pops up on the display interface of the terminal device, and sends a first signal to the second detection module. The first signal is used to activate the detection function of the second detection module. The session window is used to instruct the user to perform a first operation on the terminal device. The first operation includes performing a vertical, horizontal, shaking, or double-click operation on the terminal device.
[0008] The second detection module initiates the detection function, responds to the user's first operation, acquires the first data generated by the user performing the first operation, and sends the first data to the first detection module when the first data meets a preset condition.
[0009] The first detection module receives the first data and sends the first data to the risk control server.
[0010] Optionally, the secure operating area is a Trusted Execution Environment (TEE) OS.
[0011] Optionally, the first detection module is for detecting CA, and the second detection module is for detecting TA.
[0012] The method provided in this embodiment combines the risk control system with the safe operating area (TEE). By utilizing the function of the second detection module running in the safe operating area, it can acquire the user's operations on the terminal device, such as vertical positioning, horizontal positioning, shaking, and double-clicking, and thus complete the verification of the user's operation. This avoids the user having to identify and select complex verification codes, such as nine-square grids, online. This method greatly reduces the mental burden on the user, and verification can be completed with just simple operations on the mobile phone.
[0013] In conjunction with the first aspect, in one possible implementation of the first aspect, the method further includes:
[0014] The second detection module binds the first data and the one-time transaction ID to obtain the second data, signs the second data using the private key of the terminal device to obtain the first signature value, and sends the second data and the first signature value to the first detection module.
[0015] The first detection module encapsulates the second data and the first signature value into third data and sends the third data to the risk control server.
[0016] In this implementation, a second detection module is used to acquire the first data collected by the sensor. This first data is then bound, signed, encrypted, and sent to the rich operating system of the terminal device. Since the signed and encrypted data (i.e., data 3) cannot be decrypted or tampered with during transmission between different layers of the terminal device and between the terminal device and the cloud device, the security of the encrypted data transmission is guaranteed. This prevents attackers from launching attacks on the business system without hardware, resulting in higher security.
[0017] In conjunction with the first aspect, in another possible implementation of the first aspect, the method further includes: the second detection module sending the certificate chain of the terminal device to the first detection module, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys; after receiving the certificate chain sent by the second detection module, the first detection module sends the certificate chain to the risk control server.
[0018] In conjunction with the first aspect, in another possible implementation of the first aspect, the method further includes: the first detection module receiving a first verification result obtained by the risk control server after verifying the three data; and the first detection module closing the session window when the first verification result indicates that the user has passed the verification.
[0019] In conjunction with the first aspect, in another possible implementation of the first aspect, the operating system runtime area further includes a fake user detection module, which, before receiving the one-time transaction ID, further includes:
[0020] The fake user detection module sends a request message to the first detection module, the request message being used to request verification of the user's authenticity; and, after receiving the request message, sends a first detection request to the first detection module.
[0021] After receiving the first detection request, the first detection module verifies the legitimacy of the first application; when the verification of the first application is "legitimate", the first detection module sends a second detection request to the risk control server.
[0022] The first detection module receives the one-time transaction ID sent by the risk control server, including: the first detection module receives the one-time transaction ID generated by the risk control server according to the second detection request.
[0023] In this implementation, the security of access is further enhanced by verifying the legitimacy of the first application's identity and allowing access to and activation of the second detection module's detection function only when the legitimacy of the first application's identity is verified.
[0024] In conjunction with the first aspect, in another possible implementation of the first aspect, the second detection module sends the first data to the first detection module, including: the second detection module sends the first data to the first detection module using an application programming interface (API).
[0025] In conjunction with the first aspect, in another possible implementation of the first aspect, before acquiring the first data generated by the user performing the first operation, the method further includes: the second detection module obtaining the package name of the Android application package APK that integrates the first detection module; determining whether the package name of the APK is in the whitelist of at least one APK package name of the second detection module, and then activating the sensor of the terminal device. The sensor of the terminal device is used to collect the data generated by the user's first operation.
[0026] In conjunction with the first aspect, in another possible implementation of the first aspect, the method further includes: the first detection module sending the first verification result and the one-time transaction ID to the fake user detection module;
[0027] The fake user detection module determines whether the user's first operation has "passed" the verification based on the first verification result. If so, it sends a business operation request to the business application server and receives the operation result fed back by the business application server based on the business operation request. The business operation request includes the one-time transaction ID.
[0028] In conjunction with the first aspect, in another possible implementation of the first aspect, the second detection module detects that the first data satisfies the preset condition, including:
[0029] When the component of gravitational acceleration in the y-axis direction of the first data is g y When the difference between the first data and the free fall acceleration g is within a preset range, the first data satisfies the preset condition.
[0030] Alternatively, when the component of gravitational acceleration in the z-axis direction of the first data is g z If the difference between the first data and the free fall acceleration g is within a preset range, the first data satisfies the preset condition.
[0031] Alternatively, when the components of the terminal device's acceleration in the x, y, and z axes are a x a y a z If any acceleration component of any axis satisfies at least four changes in opposite directions with amplitudes greater than a preset value, then the first data is confirmed to satisfy the preset condition.
[0032] Alternatively, if the time interval between two consecutive clicks by the user on the display screen in the first data, and the difference between two pixel values in the two consecutive click areas on the display screen are both less than a preset value, then the first data is determined to meet the preset condition.
[0033] Wherein, the component of gravitational acceleration in the y-axis direction, g y And the component g in the z-axis direction z It can be measured and acquired by a gravity sensor; the acceleration components a of the terminal device in the x-axis, y-axis, and z-axis directions. x a y a z It can be collected by a linear acceleration sensor.
[0034] Secondly, this application also provides a data transmission method applied to a risk control server, the method comprising:
[0035] The risk control server sends a one-time transaction ID to the first detection module of the terminal device; and receives the first data or third data output by the first detection module after activating the detection function of the second detection module of the terminal device based on the one-time transaction ID.
[0036] The first detection module of the terminal device runs in the operating system running area, and the second detection module runs in the secure running area. The operating system running area and the secure running area are isolated from each other. The first data is the data generated by the user performing a first operation on the terminal device. The third data is generated by encapsulating the second data and the first signature value. The first operation includes performing vertical, horizontal, shaking, or double-click operations on the terminal device.
[0037] In conjunction with the second aspect, in one possible implementation of the second aspect, when the terminal device receives the third data, it further includes:
[0038] The risk control server receives the certificate chain of the terminal device, wherein the certificate chain of the terminal device and the private key of the terminal device are an asymmetric key pair; verifies the legality of the certificate chain of the terminal device; when the certificate chain is legal, the risk control server uses the certificate chain to verify the signature of the third data to obtain a first verification result; and sends the first verification result to the first detection module.
[0039] In conjunction with the second aspect, in one possible implementation of the second aspect, the method further includes: the risk control server receiving a business operation request sent by the business application server, the business operation request including the one-time transaction ID; querying the value corresponding to the one-time transaction ID based on the one-time transaction ID, generating a second verification result, the value including verification "passed" or "failed", and sending the second verification result to the business application server.
[0040] In conjunction with the second aspect, in another possible implementation of the second aspect, the method further includes: the risk control server destroying the one-time transaction ID and the second verification result.
[0041] Thirdly, this application also provides a terminal device, including an operating system running area and a secure running area, wherein the operating system running area is isolated from the secure running area, the operating system running area includes a first detection module, and the secure running area includes a second detection module, wherein...
[0042] The first detection module is used to pop up a session window on the display interface of the terminal device and send a first signal to the second detection module when it receives a one-time transaction ID sent by the risk control server. The session window is used to instruct the user to perform a first operation on the terminal device. The first operation includes performing a vertical, horizontal, shaking, or double-click operation on the terminal device. The first signal is used to activate the detection function of the second detection module.
[0043] The second detection module is used to activate the detection function, respond to the user's first operation, obtain the first data generated by the user performing the first operation, and send the first data to the first detection module when the first data meets the preset conditions.
[0044] The first detection module is also used to receive the first data and send the first data to the risk control server.
[0045] In conjunction with the third aspect, in one possible implementation of the third aspect, the second detection module is further configured to bind the first data and the one-time transaction ID to obtain second data, sign the second data using the private key of the terminal device to obtain a first signature value, and send the second data and the first signature value to the first detection module; the first detection module is further configured to encapsulate the second data and the first signature value into third data, and send the third data to the risk control server.
[0046] In conjunction with the third aspect, in another possible implementation of the third aspect, the second detection module is further configured to send the certificate chain of the terminal device to the first detection module, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys; the first detection module is further configured to send the certificate chain to the risk control server after receiving the certificate chain sent by the second detection module.
[0047] In conjunction with the third aspect, in another possible implementation of the third aspect, the first detection module is further configured to receive a first verification result obtained by the risk control server after verifying the three data, and to close the session window when the first verification result indicates that the user has passed the verification.
[0048] In conjunction with the third aspect, in another possible implementation of the third aspect, the operating system runtime area further includes a fake user detection module. Before the first detection module receives the one-time transaction ID, the fake user detection module is used to send a request message to the first detection module, the request message being used to request verification of the user's authenticity. After receiving the request message, it sends a first detection request to the first detection module. The first detection module is also used to verify the legitimacy of the first application after receiving the first detection request. When the verification of the first application is "legitimate", it sends a second detection request to the risk control server and receives the one-time transaction ID generated by the risk control server based on the second detection request.
[0049] In conjunction with the third aspect, in another possible implementation of the third aspect, the first detection module is further configured to send the first data to the first detection module using an application programming interface (API).
[0050] In conjunction with the third aspect, in another possible implementation of the third aspect, the second detection module is further configured to obtain the package name of the Android application package APK integrating the first detection module before obtaining the first data generated by the user performing the first operation; and determine whether the package name of the APK is in the whitelist of at least one APK package name of the second detection module, and then activate the sensor of the terminal device.
[0051] In conjunction with the third aspect, in another possible implementation of the third aspect, the first detection module is further configured to send the first verification result and the one-time transaction ID to the fake user detection module;
[0052] The fake user detection module is further configured to determine whether the user's first operation has "passed" the verification based on the first verification result. If so, it sends a business operation request to the business application server, the business operation request including the one-time transaction ID. In addition, it is also configured to receive the operation result sent by the business application server based on the business operation request.
[0053] In conjunction with the third aspect, in another possible implementation of the third aspect, it is further used to determine that the first data satisfies the preset condition when the first data satisfies any one of the following conditions:
[0054] When the component of gravitational acceleration in the y-axis direction of the first data is g y When the difference between the free fall acceleration g and the free fall acceleration g is within a preset range,
[0055] Alternatively, when the component of gravitational acceleration in the z-axis direction of the first data is g z The difference between the free fall acceleration g and the free fall acceleration g is within a preset range;
[0056] Alternatively, when the components of the terminal device's acceleration in the x, y, and z axes are a x a y a z In the process, there exists an acceleration component along any axis that satisfies at least four changes in opposite directions with amplitudes greater than a preset value;
[0057] Alternatively, when the time interval between two consecutive clicks by the user on the display screen in the first data, and the difference between two pixel values in the two consecutive click areas on the display screen, are both less than a preset value.
[0058] Fourthly, this application also provides a server, comprising: a sending unit for sending a one-time transaction ID to a first detection module of a terminal device; and a receiving unit for receiving first data or third data output by the first detection module after activating the detection function of a second detection module of the terminal device based on the one-time transaction ID.
[0059] The first detection module of the terminal device runs in the operating system running area, and the second detection module runs in the secure running area. The operating system running area and the secure running area are isolated from each other. The first data is the data generated by the user performing a first operation on the terminal device. The third data is generated by encapsulating the second data and the first signature value. The first operation includes performing vertical, horizontal, shaking, or double-click operations on the terminal device.
[0060] In conjunction with the fourth aspect, one possible implementation of the fourth aspect also includes a processing unit.
[0061] The receiving unit is further configured to receive the certificate chain of the terminal device, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys;
[0062] The processing unit is used to verify the legality of the certificate chain of the terminal device. When the certificate chain is legal, the unit uses the certificate chain to verify the third data and the first signature value to obtain the first verification result.
[0063] The sending unit is further configured to send the first verification result to the terminal device.
[0064] In conjunction with the fourth aspect, in another possible implementation of the fourth aspect, the receiving unit is further configured to receive a business operation request sent by the business application server, wherein the business operation request includes the one-time transaction ID;
[0065] The processing unit is further configured to query the value corresponding to the one-time transaction ID based on the one-time transaction ID, and generate a second verification result, wherein the value includes verification "passed" or "failed";
[0066] The sending unit is further configured to send the second verification result to the business application server.
[0067] In conjunction with the fourth aspect, in another possible implementation of the fourth aspect, the processing unit is further configured to destroy the one-time transaction ID and the second verification result.
[0068] Fifthly, this application also provides a data transmission system, including: a terminal device and a risk control server.
[0069] The terminal device includes the apparatus as described in the third aspect and any embodiment of the third aspect; the risk control server includes the apparatus as described in the fourth aspect and any embodiment of the fourth aspect.
[0070] In another possible implementation, the system further includes: a business application server.
[0071] The business application server is configured to receive a business operation request sent by the terminal device, the business operation request including the one-time transaction ID; send the one-time transaction ID to the risk control server; receive a second verification result fed back by the risk control server; and when the second verification result is the same as the first verification result, execute a business operation to obtain an operation result, and send the operation result to the terminal device.
[0072] In a sixth aspect, this application also provides a data transmission apparatus, which includes at least one processor and an interface circuit, wherein the interface circuit is configured to provide instructions and / or data to the at least one processor; the at least one processor is configured to execute the instructions to implement the methods in the first aspect and various implementations thereof.
[0073] In addition, the at least one processor also implements the methods in the second aspect and various implementations thereof by executing the instructions.
[0074] Optionally, the device may further include a memory for storing the instructions and / or data.
[0075] Optionally, the at least one processor and the interface circuit can be integrated into a single processing chip or chip circuit.
[0076] Optionally, the device is a terminal device, including but not limited to mobile phones, PCs, and tablet computers.
[0077] Optionally, the device is a network device, which includes, but is not limited to, servers and controllers. Examples include business application servers and risk control servers.
[0078] In a seventh aspect, this application also provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, can be used to perform the methods in the first aspect and various implementations thereof, and the methods in the second aspect and various implementations thereof.
[0079] In addition, this application also provides a computer program product including computer instructions that, when executed by a computer or processor, can implement the methods in the first aspect and various implementations thereof, and the methods in the second aspect and various implementations thereof.
[0080] It should be noted that the beneficial effects of the various implementation methods of the second to seventh aspects mentioned above are the same as those of the first aspect and its various implementation methods. For details, please refer to the description of the beneficial effects in the first aspect and its various implementation methods, which will not be repeated here. Attached Figure Description
[0081] Figure 1 This is a schematic diagram illustrating different application scenarios in human-computer interaction, provided as an embodiment of this application.
[0082] Figure 2 This application provides a schematic diagram of the structure of a communication system according to an embodiment of the present application.
[0083] Figure 3 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application;
[0084] Figure 4 A signaling flowchart of a data transmission method provided in an embodiment of this application;
[0085] Figure 5 A signaling flowchart for another data transmission method provided in this application embodiment;
[0086] Figure 6a A schematic diagram illustrating a conversation window prompting a user to perform a first operation, provided as an embodiment of this application;
[0087] Figure 6b A schematic diagram illustrating another session window prompting the user to perform a first operation, provided in an embodiment of this application;
[0088] Figure 7 A signaling flowchart for yet another data transmission method provided in this application embodiment;
[0089] Figure 8 A signaling flowchart for yet another data transmission method provided in this application embodiment;
[0090] Figure 9 A schematic diagram of a sensor coordinate system provided in an embodiment of this application;
[0091] Figure 10a This is a schematic diagram of the structure of a data transmission device provided in an embodiment of this application;
[0092] Figure 10b This is a schematic diagram of another data transmission device provided in an embodiment of this application;
[0093] Figure 11 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Detailed Implementation
[0094] To enable those skilled in the art to better understand the technical solutions in the embodiments of this application, the technical solutions in the embodiments of this application will be further described in detail below with reference to the accompanying drawings. Before describing the technical solutions in the embodiments of this application, the application scenarios of the embodiments of this application will first be described with reference to the accompanying drawings.
[0095] The technical solution of this embodiment can be applied to the field of human-computer verification technology, including various application scenarios in the human-computer interaction process, such as... Figure 1 As shown, this includes, but is not limited to, user registration, login, password reset, and pre-order purchases.
[0096] For example, in the "user registration" scenario, business service providers or cloud service providers, such as developers or app owners, may initiate the user verification process in this embodiment at the registration submission interface to prevent malicious registration by users who may register a large number of spam accounts without verification codes. This will prevent malicious attacks by automated testing software.
[0097] For example, in a "login" scenario, attackers can use a large amount of user information obtained from illegal channels, such as old usernames and keys, to repeatedly attempt to log in to a certain application, thereby increasing the likelihood of the application being successfully tested and the attacker gaining login access. Furthermore, the technical solution of this embodiment can also be activated during the interaction process, based on business needs, if malicious attacks from automated testing tools are detected.
[0098] The technical solution in this embodiment serves as a pre-emptive human-machine verification method in the various application scenarios described above, used to prevent business applications from being automatically attacked and logged in, thereby improving the risk resistance of business applications.
[0099] The technical solution in this embodiment can be applied to a Huawei Mobile Services (HMS) environment. HMS can be understood as a collection of Huawei Cloud services, including Huawei Account, in-app payment, Huawei Push Service, Huawei Cloud Drive Service, Huawei Advertising Service, Messaging Service, paid download service, Quick Apps, and other services. HMS and HMS applications integrate Huawei's chips, devices, and cloud computing capabilities, forming a set of HMS core services (HMSCore), tools, and platforms for integrated development environment (IDE) development and testing, and together with third-party applications, provide functional services to global users.
[0100] See Figure 2This is a schematic diagram of a communication system provided in this embodiment. The system includes a terminal side and a cloud side, and the terminal side and the cloud side are connected via a wireless network, such as WLAN or WiFi. The terminal side includes at least one terminal device 10. Further, the terminal device can be a portable device, such as a smartphone, tablet computer, personal computer (PC), foldable terminal, wearable device with wireless communication capabilities (e.g., smartwatch or bracelet), user device (UE), augmented reality (AR) or virtual reality (VR) device, headphones, etc. This embodiment does not limit the specific form of the terminal device. In addition, the various terminal devices described above are equipped with the Android operating system and / or systems compatible with Android.
[0101] The cloud side includes at least one server, such as a risk control server 20, a business application server 30, etc. Optionally, it may also include other network devices, such as switches, etc., but this embodiment does not limit this.
[0102] The structure of the terminal device provided in this embodiment is described below.
[0103] Figure 3 The diagram shown illustrates the software architecture of any of the aforementioned terminal devices. The software architecture of the terminal device is a layered structure, with layers connected through software interfaces. In some embodiments, the Android system can be divided into, from top to bottom, the application layer, the application framework layer, the operating system layer, and the kernel layer (or hardware layer).
[0104] The application layer includes a series of application packages, such as camera, calendar, maps, as well as calling, navigation, and SMS applications. Each application package corresponds to an APK (Android application package). Developers can design and write these applications using the Java language, enabling them to coexist peacefully and equally.
[0105] The application framework layer is the foundation of Android application development. It provides application programming interfaces (APIs) and a programming framework for applications within the application layer. The application framework layer includes predefined functions. For example, it may include a window manager, content provider, phone manager, asset manager, and notification manager.
[0106] Operating system libraries include multiple functional modules. Examples include: a surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), and 2D graphics engines (e.g., SGL).
[0107] The kernel layer, or hardware platform layer, is the layer between hardware and software. For example, the Linux kernel includes at least the display driver, audio driver, CPU, network card, camera driver, USB driver, and sensor driver.
[0108] The application layer and application framework layer run in a virtual machine (Dalvik Virtual Machine). The virtual machine executes the Java files of the application layer and application framework layer as binary files. The operating system layer and kernel layer below the application framework layer can be referred to as the underlying system. The underlying system includes the low-level display system that provides display services; for example, the low-level display system includes the display driver in the kernel layer and the window manager in the operating system library.
[0109] In this embodiment, the ability to detect fake users is enabled in the application framework layer. Based on the risk control server, the risk level of the user terminal is assessed. For users with risks, the ability to detect fake users is provided in the security detection kit of the terminal device. This ability is used to provide the terminal device with a means of detecting users based on the Trusted Execution Environment (TEE), thereby bringing users a good experience and high security, while mitigating the risk of automated attacks on HMS applications.
[0110] Figure 3As shown, the terminal device 10 includes a Rich Operating System (Rich OS) 11 and a Secure Execution Environment (TEE OS) 12. The Rich OS is an Android operating system used to provide the Android system runtime environment; the TEE OS is used to provide a Trusted Execution Environment (TEE), and the Rich OS 11 and the Secure Execution Environment 12 are isolated from each other and each has an independent operating system.
[0111] The application layer of the rich operating system 11 includes at least one application (APP), such as a first application (APP). This first application (APP) includes a fake user detection module. This fake user detection module is used to integrate with the mobile application providing services, providing functions such as verification initiation and verification completion callbacks. This fake user detection module can be configured through a software development kit (SDK).
[0112] The application framework layer of the rich operating system 11 includes a fake user service module, which has the function of detecting client applications (CAs). Optionally, the fake user service module includes a first detection module. Further, the first detection module is a CA detection or CA detection functional unit.
[0113] The application framework layer also provides an API interface for accessing the secure operating zone 12, enabling the first detection module to establish a transmission channel, namely "channel 3", with the secure operating zone 12. The secure operating zone 12 includes a TEE application layer and a TEE core layer. The TEE application layer includes a second detection module, which provides the terminal device with the function of detecting Trusted Applications (TAs).
[0114] Optionally, the second detection module is a detection TA or a detection TA functional unit.
[0115] The TEE kernel is used to access hardware secure resources, which include a secure storage area. This secure storage area stores keys, sensor data, and other information. Furthermore, the data in the secure storage area cannot be arbitrarily modified by the operating system.
[0116] Furthermore, the functions of each of the above modules are summarized in Table 1 below, as shown in Table 1.
[0117] Table 1. Module Function List
[0118]
[0119]
[0120] also, Figure 3 The document also illustrates the transmission channels between the various modules. Specifically, the application layer and the framework layer on the terminal side can transmit data via "Channel 1," which is the application programming interface (API). Similarly, the transmission channel "Channel 3" between the aforementioned first detection module and the second detection module is also implemented using an API interface.
[0121] The transmission channels between terminal device 10 and risk control server 20 in the cloud, namely "Channel 2", and between terminal device 10 and business application server 30, namely "Channel 4", can both use wireless mobile communication transmission, such as WLAN, Bluetooth, WiFi, etc. Similarly, the transmission channel between business application server 30 and risk control server 20, namely "Channel 5", can also use any of the above-mentioned wireless communication transmission methods.
[0122] Optionally, the wireless communication transmission of channels 2, 4 and 5 may adopt the Secure Hypertext Transfer Protocol (HTTPS), which includes, but is not limited to, HTTPS, HTTP over SSL, HTTP Secure, etc.
[0123] The technical solution provided in this embodiment will be described in detail below.
[0124] This embodiment provides a data transmission method that utilizes a data source within a trusted execution environment on the terminal side, simplifying human-computer interaction verification operations, significantly reducing the user's mental burden, and ensuring data transmission security. Specifically, as shown... Figure 4 As shown, the structure applied to the aforementioned terminal device includes the following steps in the data transmission method:
[0125] S1: The terminal device initiates a detection request to the risk control server. This detection request is used to request a one-time transaction ID (Identity document) from the risk control server. Specifically, as follows... Figure 5 As shown, step S1 includes:
[0126] S101: The first application sends a request message to the fake user detection module. The request message is used to request verification of the user's authenticity and to request and invoke the functions of the fake user service module.
[0127] In the above Figure 1 In any of the scenarios shown, if a high risk or malicious attack by automated testing tools is detected during user login / registration interactions, step S101 is executed.
[0128] Optionally, the fake user detection module is an SDK in the application layer. This SDK has at least the following functions: providing mobile application integration for business, providing verification initiation functions, and verification completion callbacks, etc.
[0129] S102: After receiving the request message, the fake user detection module sends a first detection request to the first detection module.
[0130] Specifically, after receiving the first request message sent by the first application, the fake user detection module sends the first detection request to the first detection module in the fake user service module through "channel 1".
[0131] Optionally, the first detection module is a CA detection module.
[0132] S103: After receiving the first detection request sent by the fake user detection module, the first detection module first verifies the legitimacy of the first application.
[0133] One possible implementation is that the first detection module authenticates the legitimacy of the first application (APP) through the application framework layer. Specifically, the first application sends its relevant information to the first detection module. This information includes the application's package name, the fingerprint of its certificate, and its functional identifier. This information is unique within the app store; when the first application is listed, the app store assigns it this information. This information can be set by the developer when issuing the APK for the first application.
[0134] When the first application calls the detection function of the first detection module, it sends the relevant information of the first application to the first detection module. Correspondingly, after receiving the relevant information of the first application, the first detection module determines whether the package name, certificate fingerprint, and function identifier of the first application contained therein are valid. When the identity of the first application (APP) is verified to be valid, step 104 is executed.
[0135] In this implementation, the legitimacy of the first application is verified, and only legitimate applications are allowed to initiate detection requests, thereby excluding and filtering out some applications that have tampered with the signature, and preventing illegal applications from launching detection attacks.
[0136] S104: When the authentication of the first application APP is "legitimate", the first detection module sends a second detection request to the risk control server.
[0137] The second detection request is used to request a one-time transaction ID from the risk control server. Specifically, the first detection module sends the second detection request in accordance with the HTTPS protocol specification.
[0138] Return to Figure 4 The method further includes:
[0139] S2: After receiving the detection request (corresponding to the second detection request in S104), the risk control server generates a one-time transaction ID.
[0140] The risk control server generates a one-time transaction ID according to a preset algorithm. This one-time transaction ID can be a random string of at least 32 bytes, which may contain numbers, letters, symbols, etc. Furthermore, this one-time transaction ID has a single-use validity period to prevent secondary use and guessing.
[0141] S3: The risk control server sends the one-time transaction ID to the terminal device.
[0142] Specifically, the risk control server sends the one-time transaction ID to the first detection module of the terminal device, and correspondingly, the first detection module receives the one-time transaction ID sent by the risk control server.
[0143] S4: After receiving the one-time transaction ID, the first detection module pops up a session window on the display interface of the terminal device.
[0144] The session window is used to instruct the user to perform a first operation on the terminal device. The first operation includes the user performing operations such as verticalizing, flattening, shaking, or double-clicking on the terminal device.
[0145] In one example, such as Figure 6a As shown, during the user's mobile phone number registration process, when the terminal device's first detection module receives the one-time transaction ID, a session window 1 pops up on the display interface. Session window 1 prompts the user to perform the first operation, "Please lift your phone and keep it upright," and displays a diagram demonstrating this operation. In another example, as... Figure 6b As shown, a session window 2 pops up on the display interface of the terminal device. In the session window 2, the user is prompted to perform the first operation of "shake the phone left and right" and a picture demonstrating the operation is displayed.
[0146] It should be understood that the conversation window may also prompt the user to perform other operations, such as drawing a circle or the figure "8" on the display screen. This embodiment does not limit the execution of the first operation mentioned above, but these operations do not include mentally taxing operations such as searching for letters, Chinese characters, or recognizing images.
[0147] S5: The first detection module sends a first signal (or a first instruction) to the second detection module. The first signal is used to start and invoke the detection function of the second detection module.
[0148] The second detection module is a running program operating in the secure operating zone 12, such as a TA detection module. Specifically, the first detection module sends the first signal to the second detection module through the TEE ClientAPI provided by the application framework layer.
[0149] S6: When the second detection module receives the first signal sent by the first detection module, it starts the detection function and, in response to the user's first operation, obtains the first data (data 1) generated by the user performing the first operation.
[0150] Specifically, after receiving the first signal, the second detection module initializes the state of the second detection module in the TEE application layer, enabling its detection function and placing it in a state of listening to the sensor data of the terminal device, waiting for the user to perform the first operation according to the prompts in the session window. After the user completes the first operation according to the prompts in the session window in S4, user operation data, i.e., data 1, is generated and collected by at least one sensor and stored in the aforementioned secure storage area. The second detection module retrieves data 1 from this secure storage area.
[0151] Optionally, before receiving data 1 in S6, the method further includes: the second detection module obtaining the package name of the Android application package APK that integrates the first detection module; determining whether the package name of the APK is in the whitelist of at least one APK package name of the second detection module; if so, it indicates that the identity of the first detection module is qualified, and the detection function of the second detection module is allowed to be called. At this time, the sensor of the terminal device is activated, and the data 1 is obtained by using the sensor.
[0152] The sensors in the terminal device include: accelerometer, gyroscope, pressure sensor, etc.
[0153] S7: The second detection module detects whether data 1 meets the preset conditions. When data 1 meets the preset conditions, it sends data 1 to the first detection module.
[0154] Specifically, the second detection module transmits data 1 to the first detection module using the aforementioned "channel 3". Correspondingly, the first detection module receives data 1.
[0155] The specific process of determining whether data 1 generated by the first operation meets the preset conditions in S7 will be explained later in this embodiment. Furthermore, if data 1 does not meet the preset conditions, obtaining user data fails, and the process returns to the previous step S6, waiting again for the first data generated by the user performing the first operation.
[0156] S8: After receiving data 1, the first detection module sends data 1 to the risk control server.
[0157] The method provided in this embodiment combines the risk control system with the safe operating area (TEE). By utilizing the function of the second detection module running in the safe operating area, it can acquire the user's operations on the terminal device, such as vertical positioning, horizontal positioning, shaking, and double-clicking, and thus complete the verification of the user's operation. This avoids the user having to identify and select complex verification codes, such as nine-square grids, online. This method greatly reduces the mental burden on the user, and verification can be completed with just simple operations on the mobile phone.
[0158] In addition, the user data 1 is obtained from the secure storage area in the secure operating environment TEE. Since the secure storage area is not allowed to be accessed by applications of the rich operating system of the terminal device, the security of data storage is guaranteed.
[0159] In another possible implementation, such as Figure 7 As shown, steps S1 to S6 are the same as the method flow in the aforementioned embodiment. In step S7, when the second detection module detects whether data 1 meets the preset conditions, it further includes:
[0160] S7': When the second detection module detects that the data 1 meets the preset conditions, it signs the data 1 to obtain the second data (data 2) and the first signature value.
[0161] Specifically, the process includes: the second detection module binding the data 1 and the one-time transaction ID to obtain the second data (data 2), and then using the private key of the terminal device to sign the data 2 to obtain the first signature value.
[0162] In this embodiment, the private key and public key of the terminal device are a pair of asymmetric keys. The private key of the terminal device is set at the factory and the public key of the terminal device can be the certificate chain of the terminal device. The certificate chain of the terminal device includes the device certificate, the device CA certificate, the root certificate, etc., and the certificate chain can be determined according to the certificate system of different terminal devices. This embodiment does not limit this.
[0163] In this embodiment, step S7' signing can employ a "digital signature" method. A digital signature (also known as a public-key digital signature) is a string of numbers that only the sender of the information can generate and that cannot be forged by others. This string of numbers also serves as valid proof of the authenticity of the information sent by the sender. It is implemented using public-key cryptography techniques and is a method for authenticating digital information. A digital signature typically defines two complementary operations: one for signing and the other for verification. Digital signatures are an application of asymmetric key encryption technology and digital digest technology.
[0164] The signing process includes: when sending data, the sender (terminal device) generates a message digest from the message text (data1) using a hash function, and then encrypts this digest using the sender's private key. This encrypted digest is sent to the receiver along with the message (data1) as the digital signature of the message (i.e., the first signature value). In this embodiment, the receiver is a risk control server.
[0165] S8': The second detection module sends data 2 and the first signature value to the first detection module. Correspondingly, the first detection module receives data 2 and the first signature value using the interface API.
[0166] Optionally, the signing process may also include: the second detection module signing the package name of the first application, the fingerprint of the application certificate, the unique identifier of the first application, and other information, and sending the signed values to the first detection module.
[0167] In addition, the second detection module also sends the certificate chain of the terminal device to the first detection module.
[0168] S9: The first detection module encapsulates the data received from the second detection module to obtain the third data (data 3).
[0169] One possible implementation is that the data to be encapsulated includes data 2 and the first signature value. Alternatively, another possible implementation is that the data to be encapsulated, in addition to data 2 and the first signature value, also includes the terminal device's certificate chain and / or information such as the first application identifier.
[0170] S10: The first detection module sends data 3 to the risk control server to request the risk control server to verify the user's first operation.
[0171] Correspondingly, the risk control server receives the data 3 sent by the first detection module.
[0172] S11: The risk control server verifies the data 3 and obtains a first verification result. Specifically, step S11 includes:
[0173] S11-1: The risk control server verifies the legality of the certificate chain of the terminal device. Specifically, it determines whether the certificate chain is legal based on the validity period of the certificate chain of the terminal device, wherein the certificate chain can be a level 3 certificate chain.
[0174] S11-2: When the certificate chain is valid, the risk control server uses the certificate chain to verify the data 3 and the first signature value to obtain a first verification result, which includes "pass" and "fail".
[0175] Specifically, after receiving data 3, the risk control server first deserializes data 3 to obtain data 2 and a first signature value (two fields). Then, it uses the same hash function as the sender (terminal device) to hash data 2, calculating a first digest value. Next, it uses the terminal device's certificate chain (public key) to decrypt the digital signature attached to the message (i.e., the first signature value) to obtain a second digest value. The server compares the previously calculated first digest value and the second digest value. If they are the same, the terminal user's signature verification is confirmed to have "passed"; if the two digests are different, the terminal user's signature verification is confirmed to have "failed".
[0176] In this example, the first digest value obtained by the risk control server after decrypting data 2 includes: a one-time transaction ID, and the first verification result of the end user ("pass" or "fail").
[0177] Optionally, if the certificate chain is found to be invalid or illegitimate in S11-1, the identity of the fake user service module is determined to be illegitimate, and the process is terminated.
[0178] Optionally, the method further includes: storing the first verification result, as well as the data 2 and the one-time transaction ID.
[0179] Optionally, the method also includes: setting a cache expiration time on the risk control server, for example, a cache expiration time of 5 minutes, and deleting the first verification result, one-time transaction ID and data 2 after the cache expiration time.
[0180] S12: The risk control server sends the first verification result to the terminal device.
[0181] Specifically, the risk control server sends the first verification result to the first detection module of the terminal device. Correspondingly, the first detection module receives the first verification result.
[0182] S13: If the first verification result indicates that the user has passed the verification, then the first detection module closes the aforementioned session window, which is the session window that popped up in step S4. Alternatively, it closes the display interface waiting for the user to perform the first operation.
[0183] Additionally, if the verification result is "failed", the first detection module displays "failed" or "unqualified" on the terminal device's display interface, and the process terminates.
[0184] S14: The first detection module sends the first verification result to the fake user detection module in the application layer.
[0185] In addition, the first detection module also sends the one-time transaction ID and / or relevant information of the first application, such as the function identifier of the first application, to the fake user detection module.
[0186] Correspondingly, the fake user detection module receives the first verification result, the one-time transaction ID, and / or the function identifier of the first application, and determines, based on the first verification result, that the risk control server has completed the signature verification of the user, and whether the signature verification of the user's first operation has passed.
[0187] This method utilizes a secure operating zone TEE OS to run a second detection module. This module acquires user data (data 1) generated by user operations collected by sensors. This user data is then bound, signed, encrypted, and sent to the rich operating system of the terminal device. Since the signed and encrypted data (data 3) cannot be decrypted or tampered with during transmission between different layers of the terminal device and between the terminal device and the cloud device, the security of the encrypted data transmission is guaranteed. This prevents attackers from launching attacks on fake users without hardware intervention. Compared to traditional verification methods such as image and voice verification codes, which are vulnerable to AI attacks, the "digital signature" verification method provided in this embodiment, combined with the hardware and software of the terminal device, enhances anti-cracking capabilities and eliminates the need for extensive collection and persistent tracking of user data, thus protecting user privacy.
[0188] In addition, the above method also includes: the risk control server establishing a mapping relationship map between the first verification result and the one-time transaction ID.<key,value> Wherein, the key is the one-time transaction ID, and the first verification result is the value. In this embodiment, the mapping relationship is established as <one-time transaction ID, passed>. Optionally, if the first verification result in S11 above is "failed", the mapping relationship becomes <one-time transaction ID, failed>.
[0189] Based on the established mapping relationship, this embodiment also provides a secondary verification process for user operations, which can be implemented using a business application server. Specifically, as shown below... Figure 8 As shown, the method includes the following steps:
[0190] S15: After receiving the first verification result and the one-time transaction ID sent by the first detection module, the fake user detection module determines whether the verification of the user operation has passed.
[0191] S16: If the verification result is "passed", the fake user detection module sends a business operation request to the business application server. The business operation request initiates a secondary verification process on the business application server and includes the one-time transaction ID.
[0192] In addition, the business operation request also includes a username and login password. For example, during the aforementioned "login" operation, the terminal device sends the username, login password, and one-time transaction ID to the business application server.
[0193] Correspondingly, the business application server receives the business operation request from the fake user detection module, and the business operation request can be transmitted through the aforementioned "channel 4".
[0194] S17: After receiving the business operation request, the business application server sends the business operation request to the risk control server. Specifically, the business application server sends the business operation request to the risk control server through the aforementioned "channel 5".
[0195] S18: After receiving the business operation request, the risk control server queries the mapping relationship for the value corresponding to the one-time transaction ID contained in the business operation request and obtains the second verification result.
[0196] The mapping relationship refers to the correspondence between the value recorded by the risk control server and the one-time transaction ID (key), i.e., a map.<key,value> The key is a one-time transaction ID, and the value includes "pass" or "fail". The second verification result may be the same as or different from the first verification result. When the risk control server detects that the one-time transaction ID is risky or has already been used, it determines that the value is "fail".
[0197] In this embodiment, it is assumed that the value corresponding to the one-time transaction ID is "passed" according to the mapping relationship. Then the second verification result is the same as the first verification result in S11 above.
[0198] S19: The risk control server sends the second verification result to the business application server.
[0199] S20: The business application server receives the second verification result sent by the risk control server, performs corresponding business operations based on the second verification result, and obtains the operation result.
[0200] Specifically, the application server determines whether the first operation identified by the one-time transaction ID by the terminal user has passed verification based on the second verification result. If it has passed, the application server will submit the username and password sent by the terminal device to its own application database for verification. If the verification fails, there is a risk of being deceived and subsequently subjected to a credential stuffing attack. In this case, access to and execution of the application operation are not permitted.
[0201] The execution of the corresponding business operations includes registration, login, password reset, and submission operations such as purchasing, and these operations are all business operations protected by the detection system.
[0202] S21: The business application server sends the operation result to the fake user detection module. This operation result is used to instruct the fake user detection module to continue the interaction process with the user. For example, it instructs the user to allow login and perform post-login operations, such as browsing and shopping.
[0203] In addition, after S19 above, the risk control server deletes or destroys the second verification result, thereby avoiding long-term recording of user verification results on the server side, such as one-time transaction IDs and whether the verification is passed or not. This method can delete all interaction information involved in the detection process in a short time, thereby avoiding long-term storage of user-related data (data 1 to data 3) and reducing the possibility of these recorded data being stolen or attacked by attackers.
[0204] This method performs secondary verification on the first verification result obtained by the terminal device through the business application server, thereby increasing the security of the system and preventing the one-time transaction ID from being reused and used to obtain authorization.
[0205] It should be noted that the aforementioned business application server and risk control server can be integrated into one server, and this integrated server can be used to execute all the methods and steps of the aforementioned business application server and risk control server.
[0206] The following section provides a detailed description of the second detection module's detection of whether data 1 meets preset conditions in step S7.
[0207] First, define the sensor coordinate system of the terminal device. Typically, the sensor frame is expressed using a standard 3-axis coordinate system, consisting of the x-axis, y-axis, and z-axis. For most sensors, the coordinate system is defined relative to the device's screen when the device is held in its default orientation. For example... Figure 9 As shown, when the terminal device is held in the default orientation, the coordinates are defined as follows: the x-axis points to the right along the horizontal direction of the screen, the y-axis points vertically upwards from the bottom edge of the screen along the top edge, and the z-axis points outwards from the screen panel. In this coordinate system, the z-axis coordinate when facing away from the screen is negative.
[0208] Furthermore, the coordinate system can be used by the following sensors: accelerometers, gravity sensors, linear acceleration sensors, etc.
[0209] The first operation includes operations performed by the user on the terminal device such as vertical, horizontal, shaking, or double-clicking. Specifically, in S7, the second detection module detects whether the data 1 is the first operation mentioned above, including the following situations.
[0210] Example 1
[0211] The first operation performed by the user is the operation prompted by the aforementioned session window 1 to "lift the phone and keep it upright". The data generated by this first operation is data 1. Therefore, the aforementioned S7 includes:
[0212] S7-1: The second detection module obtains data 1 collected by the gravity sensor from the secure storage area.
[0213] Data 1 contains three components: the components of gravitational acceleration along the x, y, and z axes. When the terminal device is in a vertical position, the gravitational acceleration component along the y-axis, collected by the gravity sensor, is represented as g. y , and g y It approaches a gravitational acceleration g; where g, also known as the acceleration due to free fall, is a constant, approximately equal to 9.8 m / s². 2(meters per square second).
[0214] S7-2: Determine the gravitational acceleration component g in the y-axis direction. y Whether the difference between the free fall acceleration g and the free fall acceleration g is within a preset range. For example, the preset range is less than or equal to 0.3 m / s².
[0215] S7-3: If yes, then determine that data 1 satisfies the preset condition; otherwise, the preset condition is not satisfied.
[0216] For example, if the absolute value of the difference between two gravitational accelerations satisfies |g y If -g|≤0.3, then data 1 is determined to meet the preset condition. If |g y If -g|>0.3, then the preset condition is not met. In this case, the prompt content in session window 1 remains unchanged, and the user can be allowed to click to cancel the operation, or the prompt operation can be canceled if the terminal device does not receive the correct first operation from the user within a certain period of time.
[0217] Example 2
[0218] When the first operation is to prompt the user to perform the operation "Please place the phone flat and hold it" in the conversation window
[0219] The data 1 obtained in S7-1 above includes the components of gravitational acceleration in the x, y, and z axes. When the terminal device is in a vertical position, the gravitational acceleration component in the z-axis direction is represented as g. z , and g z Approaching a gravitational acceleration g;
[0220] Specifically, S7-2 above includes: determining the gravitational acceleration component g in the z-axis direction. z Is the difference between the free fall acceleration g and the free fall acceleration g within a preset range? For example, is the absolute value of the difference less than or equal to 0.3 m / s²?
[0221] S7-3 above: If yes, then determine that data 1 meets the preset conditions; otherwise, the preset conditions are not met.
[0222] For example, if |g z If -g|≤0.3, then the user's first operation is determined to meet the preset condition; otherwise, the preset condition is not met. In this case, the prompt content in the session window remains unchanged, and the user can be allowed to click to cancel the operation, or the prompt operation can be canceled if the terminal device still does not receive the correct first operation from the user within a certain period of time.
[0223] Example 3
[0224] When the first operation prompts the user to perform the operation "Please shake your phone left and right" in "Session Window 2", the data 1 includes the components a of the terminal device's acceleration in the x-axis, y-axis, and z-axis directions. x a y a z In the middle, determine the acceleration component 'a' along any one of the three axes. x a y a z If the acceleration component of any one of the three axes satisfies at least four changes in opposite directions with amplitudes greater than a preset value, then it is confirmed that the terminal device has been shaken by the user. The reversal of the acceleration component direction on each axis can be represented by an accelerometer, such as a linear accelerometer, in the "Sense" application software. If at least four reversals in direction are not satisfied, then data1 is determined not to meet the preset condition.
[0225] For example, the acceleration component a in any axial direction x a y or a z If the changes occur more than 4 times and the amplitude is greater than 15 m / s², it is considered that the user has performed a left-right shaking operation on the phone.
[0226] Example 4
[0227] When the first operation is a double-click operation performed by the user on the terminal device, data 1 includes: the time interval between two consecutive clicks on the display screen, and two pixel values of the area clicked by the user on the display screen, such as a first pixel value and a second pixel value. It is determined whether the time interval is less than a preset value, and whether the difference between the first pixel value and the second pixel value does not exceed a preset pixel value. If both are true, then data 1 is determined to meet the preset conditions; otherwise, the preset conditions are not met.
[0228] For example, detecting two consecutive clicks by a user on a terminal device involves obtaining the time interval and two pixel values by listening to click events on the display screen. If the time interval is less than 300 milliseconds (ms) and the difference between the pixel values is no more than 30 pixels, then the user is considered to have performed a double-click operation.
[0229] It should be noted that for data 1 generated by the user performing other operations, various sensors can be used to collect different user data and determine whether each data meets the preset conditions, thereby determining whether data 1 meets the preset conditions, that is, determining whether the operation performed by the user on the terminal device is a normal operation performed according to the prompts in the session window.
[0230] This method utilizes a data source from trusted hardware on the edge and prompts users to perform actions such as vertical, horizontal, shaking, and double-clicking through the display interface. Compared to traditional image, text, or voice verification codes, these actions greatly simplify the interaction, making the interaction simple and significantly reducing the mental burden on users.
[0231] The following describes the apparatus embodiments corresponding to the above method embodiments.
[0232] Figure 10a This is a schematic diagram of a data transmission device provided in an embodiment of this application. The device can be a terminal device, or it can be a component located in the server, such as a chip. Furthermore, the device can implement all the functions of the terminal device in the foregoing embodiments and execute a data transmission method from the foregoing embodiments.
[0233] The device includes a rich operating system 11 and a secure operating zone 12. The rich operating system 11 is the operating system of the terminal device, such as Android, and the secure operating zone 12 is a TEE secure application environment. The rich operating system 11 and the secure operating zone 12 are isolated from each other. Specifically, the rich operating system 11 includes a first application 1101 and a fake user service module 1102. Further, the first application 1101 includes a fake user detection module, and the fake user service module 1102 includes a first detection module. A second detection module 1201 is included in the TEE application layer of the secure operating zone 12.
[0234] The first detection module is used to pop up a session window on the display interface of the terminal device when it receives a one-time transaction ID sent by the risk control server, and to send a first signal to the second detection module; the session window is used to instruct the user to perform a first operation on the terminal device, the first operation including performing a vertical, horizontal, shaking or double-click operation on the terminal device, and the first signal is used to activate the detection function of the second detection module.
[0235] The second detection module is used to activate the detection function, respond to the user's first operation, obtain the first data generated by the user performing the first operation, and send the first data to the first detection module when the first data meets the preset conditions.
[0236] The first detection module is also used to receive the first data and send the first data to the risk control server.
[0237] Optionally, in one possible implementation of this embodiment, the second detection module is further configured to bind the first data and the one-time transaction ID to obtain second data, sign the second data using the private key of the terminal device to obtain a first signature value, and send the second data and the first signature value to the first detection module. The first detection module is further configured to encapsulate the second data and the first signature value into third data and send the third data to the risk control server.
[0238] Optionally, in another possible implementation of this embodiment, the second detection module is further configured to send the certificate chain of the terminal device to the first detection module, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys; the first detection module is further configured to send the certificate chain to the risk control server after receiving the certificate chain sent by the second detection module.
[0239] Optionally, in another possible implementation of this embodiment, the first detection module is further configured to receive a first verification result obtained by the risk control server after verifying the three data, and to close the session window when the first verification result indicates that the user has passed the verification.
[0240] Optionally, in another possible implementation of this embodiment, the operating system runtime area further includes a fake user detection module, which is executed before the first detection module receives the one-time transaction ID.
[0241] The fake user detection module is used to send a request message to the first detection module, the request message being used to request verification of the user's authenticity; after receiving the request message, it sends a first detection request to the first detection module.
[0242] The first detection module is further configured to verify the legitimacy of the first application after receiving the first detection request; when the verification of the first application is "legitimate", send a second detection request to the risk control server and receive the one-time transaction ID generated by the risk control server according to the second detection request.
[0243] Optionally, the first detection module is further configured to send the first data to the first detection module using an application programming interface (API).
[0244] Optionally, in another possible implementation of this embodiment, the second detection module is further configured to obtain the package name of the Android application package APK that integrates the first detection module before obtaining the first data generated by the user performing the first operation; and determine if the package name of the APK is in the whitelist of at least one APK package name of the second detection module, then activate the sensor of the terminal device.
[0245] Optionally, in another possible implementation of this embodiment, the first detection module is further configured to send the first verification result and the one-time transaction ID to the fake user detection module.
[0246] The fake user detection module is further configured to determine whether the user's first operation has "passed" the verification based on the first verification result. If so, it sends a business operation request to the business application server, wherein the business operation request includes the one-time transaction ID.
[0247] The fake user detection module is also used to receive the operation results sent by the business application server based on the business operation request.
[0248] Optionally, in another possible implementation of this embodiment, the second detection module is further configured to determine that the first data satisfies the preset condition when the first data satisfies any one of the following conditions:
[0249] When the component of gravitational acceleration in the y-axis direction of the first data is g y When the difference between the free fall acceleration g and the free fall acceleration g is within a preset range,
[0250] Alternatively, when the component of gravitational acceleration in the z-axis direction of the first data is g z The difference between the free fall acceleration g and the free fall acceleration g is within a preset range;
[0251] Alternatively, when the components of the terminal device's acceleration in the x, y, and z axes are a x a y a z In the process, there exists an acceleration component along any axis that satisfies at least four changes in opposite directions with amplitudes greater than a preset value;
[0252] Alternatively, when the time interval between two consecutive clicks by the user on the display screen in the first data, and the difference between two pixel values in the two consecutive click areas on the display screen, are both less than a preset value.
[0253] In addition, this embodiment also provides another data transmission device, such as Figure 10bAs shown, the device includes the risk control server described in the previous embodiment, used to implement the functions of the aforementioned risk control server. The device includes a receiving unit 1301, a processing unit 1302, and a sending unit 1303. Additionally, the device may include other units and modules, such as a storage unit.
[0254] Furthermore, the sending unit 1303 is used to send a one-time transaction ID to the first detection module of the terminal device; the receiving unit 1301 is used to receive the first data or the third data output by the first detection module after it starts the detection function of the second detection module of the terminal device according to the one-time transaction ID.
[0255] The first detection module of the terminal device runs in the operating system running area, and the second detection module runs in the secure running area. The operating system running area and the secure running area are isolated from each other. The first data is the data generated by the user performing a first operation on the terminal device. The third data is generated by encapsulating the second data and the first signature value. The first operation includes performing vertical, horizontal, shaking, or double-click operations on the terminal device.
[0256] Optionally, in one possible implementation of this embodiment, the receiving unit 1301 is further configured to receive the certificate chain of the terminal device, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys. The processing unit 1302 is configured to verify the legality of the certificate chain of the terminal device; when the certificate chain is legal, the processing unit 1302 uses the certificate chain to verify the third data and the first signature value to obtain the first verification result; the sending unit 1303 is further configured to send the first verification result to the terminal device.
[0257] Optionally, in another possible implementation of this embodiment, the receiving unit 1301 is further configured to receive a business operation request sent by the business application server, the business operation request including the one-time transaction ID; the processing unit 1302 is further configured to query the value corresponding to the one-time transaction ID according to the one-time transaction ID, and generate a second verification result, the value including verification "passed" or "failed"; the sending unit 1303 is further configured to send the second verification result to the business application server.
[0258] Optionally, in another possible implementation of this embodiment, the processing unit 1302 is further configured to destroy the one-time transaction ID and the second verification result.
[0259] It should be noted that, Figure 10b The data transmission device shown can also be a business application server, used to implement the aforementioned methods and steps of the business application server.
[0260] In another hardware implementation, this embodiment also provides a terminal device, as shown in Figure 10. The terminal device may include a processor 110 and a memory 120, and further includes: a USB interface 130, a power management module 140, a battery 141, antenna 1, antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0261] The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an accelerometer sensor 180C, a gravity sensor 180D, and a touch sensor 180E. In addition, the sensor module 180 may also include a fingerprint sensor, a temperature sensor, an ambient light sensor, etc.
[0262] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on the communication device. In other embodiments of this application, the communication device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0263] Processor 110 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.
[0264] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can directly retrieve it from the memory, avoiding repeated accesses, reducing the waiting time of the processor 110, and thus improving the efficiency of the system.
[0265] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0266] The USB interface 130 is a USB standard compliant interface, specifically a Mini USB interface, MicroUSB interface, or USB Type-C interface. The USB interface 130 can be used to connect a charger to charge communication devices, and can also be used for data transfer between communication devices and peripheral devices. It can also be used to connect headphones for audio playback. This interface can also be used to connect other electronic devices, such as AR devices.
[0267] The power management module 140 is used to connect the battery 141 to the processor 110. The power management module 140 supplies power to the processor 110, memory 120, display 194, camera 193, and wireless communication module 160, etc. In some embodiments, the power management module 140 may be located within the processor 110.
[0268] The wireless communication function of the terminal device can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor, and baseband processor.
[0269] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the communication device can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization.
[0270] The mobile communication module 150 can provide solutions for wireless communication applications including 2G / 3G / 4G / 5G in communication devices. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110.
[0271] The wireless communication module 160 can provide solutions for wireless communication applications in communication devices, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 can also receive signals to be transmitted from the processor 110, frequency modulate them, amplify them, and convert them into electromagnetic waves for radiation via the antenna 2.
[0272] In some embodiments, antenna 1 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling the terminal device to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include Global Positioning System (GPS), Global Navigation Satellite System (GLONASS), and BeiDou Navigation Satellite System (BDS).
[0273] Display screen 194 is used to display session windows, display interfaces, images, etc. In some embodiments, the terminal device may include one or N display screens, where N is a positive integer greater than 1.
[0274] The terminal device can perform shooting functions through an ISP, camera 193, video codec, GPU, display 194, and application processor. The ISP is used to process the data fed back by the camera 193.
[0275] The memory 120 can be used to store computer executable program code, which includes instructions. The internal memory 120 may include a program storage area and a data storage area. The program storage area may store an operating system, such as a rich operating system and a TEE secure storage area. Each operating system or area can be used to run at least one functional module, such as a first detection module, a second detection module, etc. The data storage area includes a secure storage area for storing user data collected by the sensor module, i.e., first data. In addition, it includes other storage areas for storing the second data, the first signature value, third data, etc.
[0276] Furthermore, memory 120 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc. Processor 110 executes various functional applications and data processing of the communication device by running instructions stored in internal memory 120 and / or instructions stored in memory disposed in the processor.
[0277] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. Gyroscope sensor 180B can be used to determine the motion posture of the terminal device, such as measuring the rotation angle of the terminal device. Accelerometer sensor 180C can detect the magnitude of the acceleration of the terminal device in various directions (generally three axes). Accelerometer sensor 180C also includes a linear accelerometer sensor for obtaining the linear acceleration of the terminal device. Gravity sensor 180D is used to measure the acceleration components of the terminal device in the x-axis, y-axis, and z-axis directions. When the terminal device is in a shaking, translational, or stationary state, gravity sensor 180D can detect the magnitude and direction of the gravitational acceleration components, thereby determining the posture of the terminal device: horizontal, vertical, or shaking state. Touch sensor 180E, also known as a "touch device," can be disposed on display screen 194. Touch sensor 180E and display screen 194 together form a touch screen, also known as a "touchscreen." The 180E touch sensor is used to detect touch operations, such as double-tap, applied to or near it.
[0278] Button 191 includes a power button, volume buttons, etc. Button 190 can be a mechanical button or a touch button. Indicator 192 can be an indicator light, used to indicate charging status, battery level changes, messages, missed calls, notifications, etc.
[0279] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation with the communication device.
[0280] In this embodiment, when the terminal device is used as a data transmission device, it can achieve the functions described in the foregoing embodiments. Figure 4 , Figure 5 , Figure 7 and Figure 8 The method steps shown, and the foregoing Figure 10aIn the device shown, the function of the fake user detection module 1101 can be implemented by components such as the mobile communication module 150, the wireless communication module 160, and the processor 110; the functions to be implemented by the fake user service module 1102 and the second detection module 1201 can be implemented by the processor 110; and the function of the storage unit can be implemented by the memory 120.
[0281] In one possible implementation, utilizing Figure 11 When a terminal device, such as a smartphone, is used, a second detection module is run in the Secure Operating Area (TEE). This second detection module acquires user data (i.e., data 1) generated by user operations collected by sensors. This user data is then bound, signed, encrypted, and sent to the rich operating system of the terminal device. Since the signed and encrypted data (i.e., data 3) cannot be decrypted or tampered with during transmission between different layers of the terminal device and between the terminal device and the cloud device, the security of the encrypted data transmission is guaranteed. This prevents attackers from launching attacks on the business system without hardware intervention. Compared to traditional verification methods such as image and voice verification codes, which are vulnerable to AI attacks, the technical solution in this embodiment combines the hardware and software of the terminal device, improving its anti-cracking capabilities and eliminating the need for extensive collection and persistent tracking of user data, thus protecting user privacy.
[0282] Furthermore, embodiments of this application also provide a data transmission system, which includes at least one terminal device and a server, wherein the structure of the terminal device can be the same as described above. Figure 11 The device structures shown may be the same or different. The server includes a risk control server and a business application server, which are used to implement their respective functions, enabling the data transmission system to implement the data transmission method described in the foregoing embodiments.
[0283] Furthermore, embodiments of this application also provide a computer storage medium, wherein the computer storage medium may store a program, and the program, when executed, may include some or all of the steps of the data transmission method provided in this application. The storage medium may be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0284] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product.
[0285] The computer program product includes one or more computer instructions, such as pairing instructions or transmission instructions, which, when loaded and executed by a computer, generate, in whole or in part, the method flows or functions described in the foregoing embodiments of this application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.
[0286] Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. Additionally, to facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first," "second," etc., are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or execution order, and that "first," "second," etc., do not necessarily imply differences.
[0287] The embodiments described above do not constitute a limitation on the scope of protection of this application.
Claims
1. A data transmission method, characterized in that, The method is applied to a terminal device, the terminal device including an operating system running area and a secure running area, the operating system running area being isolated from the secure running area, the operating system running area including a first detection module, and the secure running area including a second detection module, the method comprising: When the first detection module receives a one-time transaction ID sent by the risk control server, a session window pops up on the display interface of the terminal device. The session window is used to instruct the user to perform a first operation on the terminal device. The first operation includes performing a vertical, horizontal, shaking, or double-click operation on the terminal device. The first detection module sends a first signal to the second detection module, and the first signal is used to activate the detection function of the second detection module; The second detection module activates the detection function and, in response to the user's first operation, acquires the first data generated by the user performing the first operation; When the second detection module detects that the first data meets the preset conditions, it sends the first data to the first detection module. The first detection module receives the first data and sends the first data to the risk control server.
2. The method according to claim 1, characterized in that, The method further includes: The second detection module binds the first data and the one-time transaction ID to obtain the second data, and signs the second data using the private key of the terminal device to obtain the first signature value; The second detection module sends the second data and the first signature value to the first detection module; The first detection module encapsulates the second data and the first signature value into third data and sends the third data to the risk control server.
3. The method according to claim 2, characterized in that, The method further includes: The second detection module sends the certificate chain of the terminal device to the first detection module. The certificate chain of the terminal device and the private key of the terminal device are an asymmetric key pair. After receiving the certificate chain sent by the second detection module, the first detection module sends the certificate chain to the risk control server.
4. The method according to claim 2 or 3, characterized in that, The method further includes: The first detection module receives the first verification result obtained after the risk control server verifies the third data; When the first verification result indicates that the user has passed the verification, the first detection module closes the session window.
5. The method according to claim 1, characterized in that, The operating system runtime area also includes a fake user detection module. Before the first detection module receives the one-time transaction ID, it also includes: The fake user detection module sends a request message to the first detection module, the request message being used to request verification of the user's authenticity. After receiving the request message, the fake user detection module sends a first detection request to the first detection module. After receiving the first detection request, the first detection module verifies the legitimacy of the first application; When the verification of the first application is "legitimate", the first detection module sends a second detection request to the risk control server; The first detection module receives the one-time transaction ID sent by the risk control server, including: The first detection module receives the one-time transaction ID generated by the risk control server based on the second detection request.
6. The method according to claim 1, characterized in that, The second detection module sends the first data to the first detection module, including: The second detection module sends the first data to the first detection module using the application programming interface (API).
7. The method according to claim 4, characterized in that, Before obtaining the first data generated by the user performing the first operation, the method further includes: The second detection module obtains the package name of the Android application package APK that integrates the first detection module; If the package name of the APK is in the whitelist of at least one APK package name in the second detection module, then the sensor of the terminal device is activated.
8. The method according to claim 7, characterized in that, The method further includes: If the operating system running area also includes a fake user detection module, the first detection module sends the first verification result and the one-time transaction ID to the fake user detection module; The fake user detection module determines whether the user's first operation has "passed" the verification based on the first verification result. If so, it sends a business operation request to the business application server. The business operation request includes the one-time transaction ID. The fake user detection module receives the operation results sent by the business application server based on the business operation request.
9. The method according to claim 1, characterized in that, The second detection module detects that the first data meets the preset conditions, including: When the component of gravitational acceleration in the y-axis direction of the first data is g y When the difference between the first data and the free fall acceleration g is within a preset range, the first data satisfies the preset condition. Alternatively, when the component of gravitational acceleration in the z-axis direction of the first data is g z If the difference between the first data and the free fall acceleration g is within a preset range, the first data satisfies the preset condition. Alternatively, when the components of the terminal device's acceleration in the x, y, and z axes are a x a y a z If any acceleration component of any axis satisfies at least four changes in opposite directions with amplitudes greater than a preset value, then the first data is confirmed to satisfy the preset condition. Alternatively, if the time interval between two consecutive clicks by the user on the display screen in the first data, and the difference between two pixel values in the two consecutive click areas on the display screen are both less than a preset value, then the first data is determined to meet the preset condition.
10. A data transmission method, characterized in that, Applied to a risk control server, the method includes: The risk control server sends a one-time transaction ID to the first detection module of the terminal device; The risk control server receives the first data or the third data output by the first detection module after it activates the detection function of the second detection module of the terminal device based on the one-time transaction ID. The terminal device's first detection module runs in the operating system's operating area, and the second detection module runs in the secure operating area. The operating system's operating area and the secure operating area are isolated from each other. The first data is the data generated when the user performs a first operation on the terminal device. The third data is generated by encapsulating the second data and the first signature value. The first operation includes performing vertical, horizontal, shaking, or double-click operations on the terminal device. The second data is the data obtained by the second detection module by binding the first data and the one-time transaction ID.
11. The method according to claim 10, characterized in that, When the terminal device receives the third data, it also includes: The risk control server receives the certificate chain of the terminal device, and the certificate chain of the terminal device and the private key of the terminal device are an asymmetric key pair. The risk control server verifies the legality of the certificate chain of the terminal device; When the certificate chain is valid, the risk control server uses the certificate chain to verify the signature of the third data and obtains a first verification result. The risk control server sends the first verification result to the first detection module.
12. The method according to claim 10 or 11, characterized in that, The method further includes: The risk control server receives a business operation request sent by the business application server, and the business operation request includes the one-time transaction ID; The risk control server queries the value corresponding to the one-time transaction ID based on the one-time transaction ID and generates a second verification result, wherein the value includes verification "passed" or "failed"; The risk control server sends the second verification result to the business application server.
13. The method according to claim 12, characterized in that, The method further includes: The risk control server destroys the one-time transaction ID and the second verification result.
14. A terminal device, characterized in that, The system includes an operating system runtime area and a secure runtime area, which are isolated from each other. The operating system runtime area includes a first detection module, and the secure runtime area includes a second detection module. The first detection module is used to pop up a session window on the display interface of the terminal device and send a first signal to the second detection module when it receives a one-time transaction ID sent by the risk control server. The session window is used to instruct the user to perform a first operation on the terminal device. The first operation includes performing a vertical, horizontal, shaking, or double-click operation on the terminal device. The first signal is used to activate the detection function of the second detection module. The second detection module is used to activate the detection function, respond to the user's first operation, obtain the first data generated by the user performing the first operation, and send the first data to the first detection module when the first data meets the preset conditions. The first detection module is also used to receive the first data and send the first data to the risk control server.
15. The terminal device according to claim 14, characterized in that, The second detection module is further configured to bind the first data and the one-time transaction ID to obtain the second data, sign the second data using the private key of the terminal device to obtain the first signature value, and send the second data and the first signature value to the first detection module; The first detection module is further configured to encapsulate the second data and the first signature value into third data, and send the third data to the risk control server.
16. The terminal device according to claim 15, characterized in that, The second detection module is further configured to send the certificate chain of the terminal device to the first detection module, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys; The first detection module is further configured to receive the certificate chain sent by the second detection module and then send the certificate chain to the risk control server.
17. The terminal device according to claim 15 or 16, characterized in that, The first detection module is further configured to receive a first verification result obtained by the risk control server after verifying the three data, and to close the session window when the first verification result indicates that the user has passed the verification.
18. The terminal device according to claim 14, characterized in that, The operating system runtime area also includes a fake user detection module, which is activated before the first detection module receives the one-time transaction ID. The fake user detection module is used to send a request message to the first detection module, the request message being used to request verification of the user's authenticity; after receiving the request message, it sends a first detection request to the first detection module. The first detection module is further configured to verify the legitimacy of the first application after receiving the first detection request; when the verification of the first application is "legitimate", send a second detection request to the risk control server and receive the one-time transaction ID generated by the risk control server according to the second detection request.
19. The terminal device according to claim 14, characterized in that, The first detection module is further configured to send the first data to the first detection module using an application programming interface (API).
20. The terminal device according to claim 17, characterized in that, The second detection module is further configured to obtain the package name of the Android application package APK that integrates the first detection module before obtaining the first data generated by the user performing the first operation; and to determine if the package name of the APK is in the whitelist of at least one APK package name of the second detection module, then activate the sensor of the terminal device.
21. The terminal device according to claim 20, characterized in that, The first detection module is further configured to send the first verification result and the one-time transaction ID to the fake user detection module if the fake user detection module is also included in the operating system running area; The fake user detection module is also used to determine whether the user's first operation has "passed" the verification based on the first verification result. If so, it sends a business operation request to the business application server, and the business operation request includes the one-time transaction ID. The fake user detection module is also used to receive the operation results sent by the business application server based on the business operation request.
22. The terminal device according to claim 14, wherein the second detection module is further configured to determine that the first data satisfies the preset condition when the first data satisfies any one of the following conditions: When the component of gravitational acceleration in the y-axis direction of the first data is g y When the difference between the free fall acceleration g and the free fall acceleration g is within a preset range, Alternatively, when the component of gravitational acceleration in the z-axis direction of the first data is g z The difference between the free fall acceleration g and the free fall acceleration g is within a preset range; Alternatively, when the components of the terminal device's acceleration in the x, y, and z axes are a x a y a z In the process, there exists an acceleration component along any axis that satisfies at least four changes in opposite directions with amplitudes greater than a preset value; Alternatively, when the time interval between two consecutive clicks by the user on the display screen in the first data, and the difference between two pixel values in the two consecutive click areas on the display screen, are both less than a preset value.
23. A server, characterized in that, include: The sending unit is used to send a one-time transaction ID to the first detection module of the terminal device; The receiving unit is configured to receive first data or third data output by the first detection module after it activates the detection function of the second detection module of the terminal device based on the one-time transaction ID. The terminal device's first detection module runs in the operating system's operating area, and the second detection module runs in the secure operating area. The operating system's operating area and the secure operating area are isolated from each other. The first data is the data generated when the user performs a first operation on the terminal device. The third data is generated by encapsulating the second data and the first signature value. The first operation includes performing vertical, horizontal, shaking, or double-click operations on the terminal device. The second data is the data obtained by the second detection module by binding the first data and the one-time transaction ID.
24. The server according to claim 23, characterized in that, It also includes a processing unit, The receiving unit is further configured to receive the certificate chain of the terminal device, wherein the certificate chain of the terminal device and the private key of the terminal device are a pair of asymmetric keys; The processing unit is used to verify the legality of the certificate chain of the terminal device. When the certificate chain is legal, the certificate chain is used to verify the third data and the first signature value to obtain a first verification result. The sending unit is further configured to send the first verification result to the terminal device.
25. The server according to claim 24, characterized in that, The receiving unit is further configured to receive a business operation request sent by the business application server, wherein the business operation request includes the one-time transaction ID; The processing unit is further configured to query the value corresponding to the one-time transaction ID based on the one-time transaction ID, and generate a second verification result, wherein the value includes verification "passed" or "failed"; The sending unit is further configured to send the second verification result to the business application server.
26. The server according to claim 25, characterized in that, The processing unit is also used to destroy the one-time transaction ID and the second verification result.
27. A data transmission system, characterized in that, The system includes: terminal equipment and a risk control server. The terminal device includes the terminal device as described in any one of claims 14 to 22; The risk control server includes the server as described in any one of claims 23 to 26.
28. The system according to claim 27, characterized in that, It also includes business application servers, The business application server is used to receive business operation requests sent by the terminal device, and the business operation request includes the one-time transaction ID; The business application server sends the one-time transaction ID to the risk control server; The business application server receives the second verification result fed back by the risk control server; When the second verification result is the same as the first verification result, a business operation is performed to obtain an operation result. The first verification result is the verification result obtained by the terminal device after receiving the verification of the third data from the risk control server. The third data is the data obtained by the terminal device after encapsulating the second data and the first signature value. The second data is the data obtained by the terminal device after binding the first data and the one-time transaction ID. The first signature value is the signature value obtained by the terminal device after signing the second data using the private key of the terminal device. The application server sends the operation result to the terminal device.
29. A communication device, characterized in that, Includes at least one processor and interface circuitry. The interface circuit is used to provide instructions and / or data to the at least one processor; The at least one processor is configured to execute the instructions to implement the method as claimed in any one of claims 1 to 9, or as claimed in any one of claims 10 to 13.
30. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed, implement the method as claimed in any one of claims 1 to 9, or as claimed in any one of claims 10 to 13.
Citation Information
Patent Citations
Business processing method, device and system
CN105704123A
Mobile terminal safety certification module and method
CN106778140A