A pos security control system and method

By employing continuous verification and dynamic authorization mechanisms in the POS security control system, the vulnerability of POS devices to cyberattacks has been resolved, resulting in enhanced security and business stability.

CN115499508BActive Publication Date: 2026-01-09BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211119608.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-14
Publication Date
2026-01-09
Estimated Expiration
2042-09-14

AI Technical Summary

Technical Problem

POS devices are vulnerable to cybersecurity threats. Attackers can exploit them to infiltrate the entire network, causing system paralysis and leakage of sensitive information. Existing static access control policies cannot effectively protect against these threats.

Method used

The system employs a POS security control system, which includes the target POS device, zero-trust gateway, device management system, intelligence system, trust engine, and backend application system. Through continuous verification and dynamic authorization mechanisms, it ensures the security of each access request.

Benefits of technology

It improved the security of the backend application system, reduced the risk of attacks, and ensured system security and stable business operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115499508B_ABST
    Figure CN115499508B_ABST
Patent Text Reader

Abstract

The application discloses a POS security control system and method, which can be applied to the financial field or other fields. A target POS device sends a target network transaction request to a zero trust gateway and a device management system. The target network transaction request is each network transaction request sent by the target POS device. The zero trust gateway sends the target network transaction request to a trust engine. The device management system verifies the target network transaction request, obtains a verification result corresponding to the target network transaction request, and sends the verification result and attribute information of the target POS device to the trust engine. The trust engine determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, intelligence information of an abnormal POS device sent by an intelligence system and a security policy, and sends the decision result to the zero trust gateway. The zero trust gateway determines whether to release the target network transaction request according to the decision result. In this way, the security of a background application system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and in particular to a POS security control system and method. BACKGROUND

[0002] The POS intelligence management system POS device is an IOT device installed by a financial institution at a special merchant or an agent network point, and can be subjected to various network security threats. Attackers can use POS devices scattered everywhere to gradually penetrate the entire network, attack core business and other background application systems, and cause system paralysis, sensitive information leakage, etc.

[0003] Currently, the POS device accesses a static-based access control strategy, and once authenticates and long-term trusts network transaction requests sent by the POS device. Once the POS device is attacked and hijacked, a series of damages will be caused to the background application system. SUMMARY

[0004] To solve the above technical problems, the present application provides a POS security control system and method, which can improve the security of the background application system, reduce the risk of being attacked, and maximize the protection of system security and smooth operation of business.

[0005] To achieve the above purpose, the technical scheme provided by the present application is as follows:

[0006] The present application provides a POS security control system, which comprises a target POS device, a zero-trust gateway, a device management system, an intelligence system, a trust engine and a background application system.

[0007] The target POS device is configured to send a target network transaction request to the zero-trust gateway and the device management system, wherein the target network transaction request is each network transaction request sent by the target POS device.

[0008] The zero-trust gateway is configured to send the target network transaction request to the trust engine.

[0009] The device management system is configured to verify the target network transaction request, obtain a verification result corresponding to the target network transaction request, and obtain attribute information of the target POS device, and send the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine.

[0010] The intelligence system is configured to send collected intelligence information of abnormal POS devices to the trust engine.

[0011] The trust engine is configured to, after receiving the target network transaction request, determine a decision result according to a verification result corresponding to the target network transaction request, attribute information of the target POS device, intelligence information of the abnormal POS device, and a security policy, and send the decision result to the zero-trust gateway; the decision result is used to indicate whether to authorize the target network transaction request.

[0012] The zero-trust gateway is further configured to determine whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

[0013] Optionally, the device management system is further configured to issue a device certificate for the target POS device, and record a binding relationship between the target POS device and the device certificate.

[0014] Optionally, the target network transaction request includes a device certificate of the target POS device.

[0015] The device management system is specifically configured to verify the device certificate of the target POS device in the target network transaction request, and obtain a verification result corresponding to the target network transaction request; the verification result corresponding to the target network transaction request includes a verification result of the device certificate of the target POS device.

[0016] Optionally, the intelligence information of the abnormal POS device includes one or more of device abnormal basic information, device abnormal behavior information, device abnormal running environment information, and device abnormal running state information of the abnormal POS device.

[0017] Optionally, the attribute information of the target POS device includes basic information of the target POS device, request behavior information of the target POS device, running environment information of the target POS device, and running state information of the target POS device.

[0018] Optionally, the trust engine is specifically configured to, after receiving the target network transaction request, compare the basic information of the target POS device with the device abnormal basic information of the abnormal POS device, and obtain a first comparison result.

[0019] The request behavior information of the target POS device is compared with the device abnormal behavior information of the abnormal POS device to obtain a second comparison result.

[0020] The running environment information of the target POS device is compared with the device abnormal running environment information of the abnormal POS device to obtain a third comparison result.

[0021] The running state information of the target POS device is compared with the device abnormal running state information of the abnormal POS device to obtain a fourth comparison result;

[0022] According to the verification result corresponding to the target network transaction request, the first comparison result, the second comparison result, the third comparison result, the fourth comparison result, and a security policy, a decision result is determined, and the decision result is sent to the zero-trust gateway.

[0023] Optionally, a network transmission data encryption channel is established between the zero-trust gateway and the target POS device, and a network transmission data encryption channel is established between the zero-trust gateway and the background application system.

[0024] Optionally, the basic information of the target POS device includes device version information of the target POS device.

[0025] Optionally, the running environment information of the target POS device includes access time, access location, and access network environment of the target POS device.

[0026] The application further provides a POS security control method, which is applied to a POS security control system; the POS security control system includes a target POS device, a zero-trust gateway, a device management system, an intelligence system, a trust engine, and a background application system; the method includes:

[0027] The target POS device sends a target network transaction request to the zero-trust gateway and the device management system; the target network transaction request is each network transaction request sent by the target POS device;

[0028] The zero-trust gateway sends the target network transaction request to the trust engine;

[0029] The device management system verifies the target network transaction request, obtains a verification result corresponding to the target network transaction request, and obtains attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine;

[0030] The intelligence system sends intelligence information of an abnormal POS device collected by the intelligence system to the trust engine;

[0031] The trust engine receives the target network transaction request, determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the intelligence information of the abnormal POS device, and a security policy, and sends the decision result to the zero-trust gateway; the decision result is used to indicate whether to authorize the target network transaction request;

[0032] The zero-trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

[0033] Through the above technical solution, the present application has the following beneficial effects:

[0034] The present application provides a POS security control system and method, which includes a target POS device, a device management system, an intelligence system, a trust engine, a zero-trust gateway, and a background application system. The target POS device sends a target network transaction request to the zero-trust gateway and the device management system. The target network transaction request is each network transaction request sent by the target POS device. The zero-trust gateway sends the target network transaction request to the trust engine. The device management system verifies the target network transaction request, obtains the verification result corresponding to the target network transaction request, and obtains the attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine. The intelligence system sends the collected intelligence information of the abnormal POS device to the trust engine. The trust engine receives the target network transaction request, determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the intelligence information of the abnormal POS device, and a security policy, and sends the decision result to the zero-trust gateway. The zero-trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system. The decision result is used to indicate whether to authorize the target network transaction request. In this way, the POS security control system can realize continuous verification of the network transaction request sent by the POS device, improve the security of the background application system, reduce the risk of being attacked, and maximize the protection of system security and smooth operation of business. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0036] Figure 1 A schematic diagram of a zero trust architecture provided for an embodiment of the present application;

[0037] Figure 2 A structural schematic diagram of a POS security control system provided for an embodiment of the present application;

[0038] Figure 3 A flowchart of a POS security control method provided for an embodiment of the present application. DETAILED DESCRIPTION

[0039] In order to make the above objectives, characteristics and advantages of the present application more apparent, easy to understand and more comprehensible, the embodiments of the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0040] In order to facilitate understanding and explaining the technical solutions provided by the embodiments of the present application, the background art related to the embodiments of the present application will be introduced first.

[0041] Internet of Things (IoT) is a network obtained by extending and expanding the Internet, combining various information sensing devices with the network to form a huge network, realizing the interconnection and intercommunication of people, machines and things at any time and any place.

[0042] Point of Sales (POS) is a terminal reader equipped with bar code or optical character recognition code technology, with cash or barter amount of money. The POS device (i.e. POS machine) is installed in the special merchant and agent network of credit card, so that the POS device is connected with the computer network, and the electronic fund automatic transfer can be realized. The POS device has the functions of supporting consumption, pre-authorization, balance inquiry and transfer.

[0043] Common IOT attack types include: IOT device theft, physical tampering attack type; distributed denial of service (DDoS) attack type of devices, gateways and servers exposed to the Internet; interception, redirection and other attack types of IOT communication; identity spoofing and disguise, password cracking, constructing false control message injection and other attack types; protocol eavesdropping, malicious base station man-in-the-middle attack and other attack types; IOT Trojan horse, malware and other attack types; using excessive authorization to conduct horizontal attacks and other attack types.

[0044] As an IOT device installed by a financial institution in a special merchant or agent network, the POS device may also be subject to various network security threats of the above IOT attack types. Attackers can use POS devices scattered in various places to gradually penetrate the entire network, attack core business and other background application systems, cause system paralysis, sensitive information leakage, etc.

[0045] Currently, the POS device accesses a static-based access control strategy, and once authentication, long-term trust is performed on the network transaction request sent by the POS device. Once the POS device is attacked and hijacked, a series of damages will be caused to the background application system.

[0046] Based on this, the embodiments of the present application provide a POS security control system and method. The system includes a target POS device, a device management system, an intelligence system, a trust engine, a zero-trust gateway, and a background application system. The target POS device sends a target network transaction request to the zero-trust gateway and the device management system. The zero-trust gateway sends the target network transaction request to the trust engine. The device management system verifies the target network transaction request, obtains a verification result corresponding to the target network transaction request, and obtains attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine. The intelligence system sends intelligence information of an abnormal POS device collected by the intelligence system to the trust engine. The trust engine determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the intelligence information of the abnormal POS device, and a security policy after receiving the target network transaction request, and sends the decision result to the zero-trust gateway. The zero-trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system. The decision result is used to indicate whether the target network transaction request is authorized. In this way, the zero-trust gateway can realize continuous verification of the network transaction request sent by the POS device, improve the security of the background application system, reduce the risk of being attacked, and maximize the protection of system security and smooth operation of business.

[0047] In order to facilitate understanding of the POS security control system and method provided by the embodiments of the present application, some technical terms are introduced.

[0048] First, the commodity purchase scenario and the POS device in this scenario are introduced.

[0049] In the commodity purchase scenario, commodity information is first created in the computer. The bar code on the commodity is directly read through the optical reading device on the cash register device (or the code is directly input through the keyboard), and then the commodity information (unit price, department, discount, etc.) can be displayed in the computer. The sales details (selling price, department, time period, customer layer, etc.) of each commodity are recorded in the computer. The total price of the commodity, i.e., the transaction amount, can be calculated based on the sales details of each commodity and the read commodity information.

[0050] Further, the magnetic stripe information of the cardholder on the bank card can be read by the card reader of the POS device. The POS device operator inputs the transaction amount, and the cardholder inputs the personal identity information (i.e., the key). Further, the transaction amount and the key are sent to the financial institution background application system, such as the card issuing bank system. After completing the online transaction, information of success or failure is returned, and corresponding bills are printed. The application of the POS device realizes online consumption of bank cards such as credit cards and debit cards, greatly changing people's payment habits. Especially, the mobile POS device using wireless communication technology such as general packet radio service (GPRS) module further improves the convenience of payment, avoids tedious labor such as manual query of blacklists and single pressure, and improves work efficiency.

[0051] For ease of understanding, zero trust and a zero trust architecture will be introduced below.

[0052] The zero trust mechanism is a representative of a new generation of network security protection mechanisms. The zero trust mechanism mainly means that verification is performed every time an access request is received, that is, continuous verification, and never trust. It can be understood that, by default, no one, device, and system inside and outside the enterprise network is trusted. The trust basis of access control is reconstructed based on identity authentication and authorization every time an access request is received, so as to ensure that the identity is trusted, the device is trusted, the application is trusted, and the link is trusted.

[0053] In the zero trust mechanism, all requests attempting to connect resources are verified before access rights are granted, and continuous evaluation is performed during the entire connection. In the zero trust mechanism, information such as identity data, security infrastructure, risk analysis data, and the like can be used to make a judgment, and thus trigger dynamic execution of enterprise security policies. Zero trust improves the traditional inefficient security model based on boundaries to an efficient enterprise security model centered on resources and identity. In this way, the enterprise can perform reasonable access control in a dynamically changing environment, ultimately improving security, reducing risk, simplifying operational operations, and increasing business agility. The zero trust architecture does not establish trust based on network location, but effectively protects network communication and business access without relying on network transmission layer physical security mechanisms.

[0054] Referring to Figure 1 , Figure 1 A schematic diagram of a zero trust architecture provided by an embodiment of the present application.

[0055] As Figure 1As shown, the supporting system of the zero-trust architecture is called the control plane, and the other parts are called the data plane. The data plane is directed and configured by the control plane. Access subjects in the data plane send access requests to the zero-trust gateway to obtain protected resources. The zero-trust gateway forwards the access requests to the trust engine for processing by the control plane. Control plane processing includes verifying the access subject's device and user identities, as well as analyzing threat intelligence and contextual information. Fine-grained control policies are also implemented at this layer; the control plane can authorize based on roles within the organization, time, or device type. If an access subject needs to access resources with a higher security level, then stronger authentication is required.

[0056] Furthermore, the control plane dynamically decides, through the trust engine, whether access subjects such as "users, applications, and devices" in the data plane can access objects such as "data, applications, and systems." That is, the trust engine assesses whether the access request has legitimate authorization. The zero-trust gateway, acting as an access proxy, can block or allow the access request based on the trust engine's assessment result. Once the control plane completes its check and determines that the access request is authorized, it dynamically configures the data plane, allowing the zero-trust gateway to allow the access request and receive access traffic from that client (and only that client), thus enabling the access subject to authorize access to objects such as "data, applications, and systems." In addition, the control plane can also coordinate and configure specific parameters of the encrypted tunnel for the access requester and the accessed resources, including one-time temporary credentials, keys, and temporary port numbers.

[0057] Based on the above, see Figure 2 , Figure 2 This is a schematic diagram of the structure of a POS security control system provided in an embodiment of this application. Figure 2 As shown, the POS security control system includes: target POS device 101, zero-trust gateway 102, device management system 103, intelligence system 104, trust engine 105, and back-end application system 106. Figure 2 The dashed lines in the diagram represent the control plane, and the solid lines represent the data plane.

[0058] Figure 2 The target POS device 101 shown is the POS device that generates the network transaction request. For example, when a user uses the POS device to make a payment, the target POS device 101 reads the bank card and generates a network transaction request. This network transaction request is used to access the backend application system 106, such as a financial institution's backend application system, to enable operations on the amount in the bank card, such as deducting a certain amount from the bank card. In this embodiment, before the network transaction request can access the backend application system 106, it needs to be authorized through the zero-trust gateway 102, as shown in the following process.

[0059] The target POS device 101 is configured to send a target network transaction request to the zero trust gateway 102 and the device management system 103. The target network transaction request is each network transaction request sent by the target POS device 101.

[0060] It can be understood that each network transaction request in the target POS device 101 needs to rely on the POS security control system provided by the embodiments of the present application for security control. That is, the zero trust gateway 102 needs to judge whether to authorize access for each network transaction request.

[0061] The core part of the POS security control system provided by the embodiments of the present application is the zero trust gateway. The zero trust gateway is generally deployed at the network entrance. After the target network transaction request is sent out from the POS device, the access authorization of the zero trust gateway is needed to access the background application system. As an optional example, to avoid attackers discovering and attacking the port, the zero trust security gateway is deployed in the isolation zone DMZ to provide the only entrance for external access.

[0062] The zero trust gateway is configured to send the target network transaction request to the trust engine.

[0063] When the zero trust gateway receives the target network transaction request, the request is forwarded to the trust engine, so that the trust engine decides whether to authorize access for the target network transaction request, and returns the decision result to the zero trust gateway.

[0064] The device management system 103 is configured to verify the target network transaction request, obtain a verification result corresponding to the target network transaction request, and obtain attribute information of the target POS device, and send the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine.

[0065] It can be understood that after the device management system receives the target network transaction request, the request is verified to obtain a verification result corresponding to the target network transaction request.

[0066] As an optional example, the device management system is further configured to pre-issue a device certificate for the target POS device, and record a binding relationship between the target POS device and the device certificate. In this way, each POS device has a corresponding unique identity, so that the gateway or platform can verify the identity of the POS device, intercept illegal POS devices, and continuously record the behavior log of the legal POS device. It can be understood that the device certificate is a digital certificate, which is an identity of the target POS device.

[0067] Based on this, in a possible implementation, the device certificate of the target POS device is included in the target network transaction request.

[0068] The device management system is specifically configured to verify the device certificate of the target POS device in the target network transaction request and obtain a verification result corresponding to the target network transaction request. The verification result corresponding to the target network transaction request includes a verification result of the device certificate of the target POS device.

[0069] In the implementation, since the binding relationship between the target POS device and the device certificate is recorded in the device management system, the device certificate of the target POS device in the target network transaction request is verified, and a verification result corresponding to the target network transaction request is obtained. Specifically, the device certificate of the target POS device in the target network transaction request is compared with the device certificate bound to the target POS device recorded in the device management system, and a comparison result is obtained. If the comparison result is matched, the verification result is passed. For example, the field information of the device certificate is compared with the inventory library data in the device management system to obtain the comparison result. The inventory library data is the field information in the device certificate bound to the target POS device recorded in the device management system.

[0070] It can be known that in the embodiment of the application, the device management system issues a separate device certificate for each POS device. When the POS device sends a request for network communication, the device certificate is submitted. The device certificate not only proves that the POS device is known and registered, but also proves the unique identity of the device. The POS device has an identity, so that the POS device can identify its own identity to the resource to be accessed.

[0071] In addition, if the user provides key information on the target POS device 101, the target network transaction request sent by the target POS device also includes the key information. The device management system is also configured to verify the key information. Therefore, the device management system is specifically configured to verify the device certificate of the target POS device in the target network transaction request and the key information, and obtain a verification result corresponding to the target network transaction request. In this case, the verification result includes a verification result of the device certificate of the target POS device and a verification result of the key information.

[0072] In the embodiment of the application, when the target POS device 101 reads the bank card, the bank card information and the attribute information of the target POS device are read, and the information is uploaded to the zero trust gateway 102.

[0073] As an optional example, the attribute information of the target POS device includes basic information of the target POS device, request behavior information of the target POS device, running environment information of the target POS device, and running state information of the target POS device.

[0074] The basic information of the target POS device includes device version information of the target POS device. In addition, the basic information of the target POS device further includes address information (such as a Mac address) of the target POS device, brand information, and contracted merchant information. The request behavior information of the target POS device includes port information, access times, and access traffic size.

[0075] It can be known that the device management system 103 sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine. The verification result corresponding to the target network transaction request and the attribute information of the target POS device serve as decision data for the trust engine to determine whether to perform access authorization for the target network transaction request.

[0076] The intelligence system 104 is configured to send the collected intelligence information of the abnormal POS device to the trust engine.

[0077] The intelligence system 104 collects intelligence information of the abnormal POS device periodically. As an optional example, the intelligence information of the abnormal POS device includes one or more of device abnormal basic information, device abnormal behavior information, device abnormal running environment information, and device abnormal running state information of the abnormal POS device.

[0078] The device abnormal basic information of the abnormal POS device includes device version information of the abnormal POS device, and the device version information of the abnormal POS device is device version information of the abnormal POS device. It can be understood that the intelligence system can realize real-time monitoring of network traffic, detect whether various POS devices have vulnerabilities, and if the device version of the POS device is too low and there is a high-risk vulnerability, the POS device should be isolated until the POS device is upgraded and then can be used. Based on this, the intelligence system collects the device version information of the abnormal POS device with the vulnerability. In addition, the device abnormal basic information further includes device abnormal address information, device abnormal brand information, and device abnormal contracted merchant information.

[0079] The information system obtains the behavior rules of various POS devices, detects whether there is abnormal behavior of the POS device in the recent period, such as unauthorized access to other ports, abnormal access times, abnormal traffic size, abnormal access time, and the like. The behavior of the POS device is relatively fixed, so once abnormal behavior is found, an alarm should be given. Based on this, the information system collects device abnormal behavior information of the abnormal POS device. The device abnormal behavior information includes unauthorized access to other ports, abnormal access times, abnormal traffic size, abnormal access time, and the like. In addition, the information system can also realize the safety monitoring of the running environment and the running state of the POS device, and actively alarm for major events and the like. Based on this, the information system collects device abnormal running environment information and device abnormal running state information of the abnormal POS device.

[0080] The information system 104 sends the collected information of the abnormal POS device to the trust engine. The information of the abnormal POS device is used as decision data for the trust engine to judge whether to authorize access for the target network transaction request. Therefore, the decision data for the trust engine to judge whether to authorize access for the target network transaction request includes the verification result corresponding to the target network transaction request, the attribute information of the target POS device, and the information of the abnormal POS device.

[0081] The trust engine can be exemplarily understood as the brain of the zero trust architecture. The trust engine is a system component for risk analysis on a specific network request or activity, and makes further authorization decisions based on risk assessment. The decision result can determine whether to allow the target network transaction request.

[0082] In specific implementation, the trust engine is configured to, after receiving the target network transaction request, determine a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the information of the abnormal POS device, and a security policy, and send the decision result to the zero trust gateway. The decision result is used to indicate whether to authorize the target network transaction request.

[0083] The trust engine is provided with a security policy and received decision data, and analyzes whether the decision data meets the security policy. If it meets, the decision result is to authorize access for the target network transaction request. If it does not meet, the decision result is not to authorize access for the target network transaction request. It can be understood that the security policy can be determined according to actual conditions. For example, the security policy can be that the verification result corresponding to the target transaction request is passed, and the attribute information of the target POS device and the information of the abnormal POS device do not match.

[0084] Based on this, in a possible implementation, after receiving the target network transaction request, the trust engine specifically compares the basic information of the target POS device with the device abnormal basic information of the abnormal POS device to obtain a first comparison result.

[0085] The request behavior information of the target POS device is compared with the device abnormal behavior information of the abnormal POS device to obtain a second comparison result.

[0086] The running environment information of the target POS device is compared with the device abnormal running environment information of the abnormal POS device to obtain a third comparison result.

[0087] The running state information of the target POS device is compared with the device abnormal running state information of the abnormal POS device to obtain a fourth comparison result.

[0088] According to the verification result corresponding to the target network transaction request, the first comparison result, the second comparison result, the third comparison result, the fourth comparison result, and the security policy, a decision result is determined, and the decision result is sent to the zero trust gateway.

[0089] The comparison of the basic information of the target POS device with the device abnormal basic information in the intelligence information of the abnormal POS device includes comparison of the device version information of the target POS device in the basic information of the target POS device with the device version information in the intelligence information of the abnormal POS device, comparison of the address information of the target POS device in the basic information of the target POS device with the device abnormal address information in the intelligence information of the abnormal POS device, comparison of the brand information of the target POS device in the basic information of the target POS device with the device abnormal brand information in the intelligence information of the abnormal POS device, and comparison of the signed merchant information in the basic information of the target POS device with the device abnormal signed merchant information in the intelligence information of the abnormal POS device. The first comparison result is that the basic information of the target POS device matches or does not match the device abnormal basic information of the abnormal POS device.

[0090] It can be understood that the second comparison result is that the request behavior information of the target POS device matches or does not match the device abnormal behavior information of the abnormal POS device. The third comparison result is that the running environment information of the target POS device matches or does not match the device abnormal running environment information of the abnormal POS device. The fourth comparison result is that the running state information of the target POS device matches or does not match the device abnormal running state information of the abnormal POS device.

[0091] It can also be understood that if the security policy is that the verification result corresponding to the target transaction request is passed, and the attribute information of the target POS device and the intelligence information of the abnormal POS device do not match, the verification result corresponding to the target network transaction request needs to be passed, and the first comparison result, the second comparison result, the third comparison result and the fourth comparison result are all mismatched. When the security policy is met, it is determined that the policy result is to give access authorization to the target network transaction request, and the decision result is sent to the zero trust gateway.

[0092] In this way, the trust engine performs access policy evaluation and management on POS device access, and authorizes and verifies the POS device, realizes fine-grained authorization based on the basic attribute information provided by device management and environmental attributes such as login time, login location and network, provides dynamic authorization based on scenario and risk perception based on risk assessment and analysis provided by the intelligence system, and continuously performs permission authentication of the identity of the POS device and the accessed resources in the background application system.

[0093] The zero trust gateway 102 is also configured to determine whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

[0094] It can be understood that when the decision result is to give access authorization to the target network transaction request, the zero trust gateway determines to release the target network transaction request according to the decision result, so that the target POS device can access the background application system.

[0095] Based on the above, according to the security policy of the trust engine, the network transaction request is released or blocked, and the background application system (such as the financial institution background application system involved in the POS transaction) is hidden behind the zero trust gateway, reducing the exposure of the background application system, thereby reducing the attack surface of traditional security threats such as security vulnerabilities, intrusion attacks, ransomware, etc.

[0096] In a possible implementation, a network transmission data encryption channel is established between the zero trust gateway and the target POS device, and a network transmission data encryption channel is established between the zero trust gateway and the background application system.

[0097] As an optional example, the zero trust security gateway establishes a secure sockets layer (SSL) network transmission data encryption channel with the target POS device, provides zero trust full-process trusted security support (such as code signing, national secret SSL secure communication, password application service, etc.), ensures the confidentiality and integrity of the data of both parties, prevents the data from being monitored and obtained, and protects the data privacy and security. The network transmission data encryption channel established between the zero trust gateway and the background application system is similar, which will not be described here.

[0098] Based on the above, the application provides a POS security control system and method. The system includes a target POS device, a device management system, an intelligence system, a trust engine, a zero trust gateway, and a background application system. The target POS device sends a target network transaction request to the zero trust gateway and the device management system. The zero trust gateway sends the target network transaction request to the trust engine. The device management system verifies the target network transaction request, obtains the verification result corresponding to the target network transaction request, and obtains the attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine. The intelligence system sends the intelligence information of the abnormal POS device collected to the trust engine. The trust engine determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the intelligence information of the abnormal POS device, and a security policy after receiving the target network transaction request, and sends the decision result to the zero trust gateway. The zero trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system. The decision result is used to indicate whether the target network transaction request is authorized. In this way, the network transaction request sent by the POS device can be continuously verified, and once an abnormality is found, the POS device can be isolated immediately to avoid greater losses, thereby improving the security of the background application system, reducing the risk of attack, and maximizing the protection of system security and smooth operation of business.

[0099] Based on the above method embodiment, the application provides a POS security control system. The application also provides a POS security control method, which will be described below with reference to the accompanying drawings. Since the principle of solving the problem in the device of the present disclosure is similar to the above-mentioned POS security control system of the application, the implementation of the method can refer to the implementation of the system, and the repeated parts will not be described again.

[0100] Referring to Figure 3 As shown in the figure, the figure is a flowchart of a POS security control method provided by an embodiment of the application. The method is applied to a POS security control system; the POS security control system includes a target POS device, a zero trust gateway, a device management system, an intelligence system, a trust engine, and a background application system. As shown in Figure 3 As shown in the figure, the method can include S301-S306:

[0101] S301: The target POS device sends a target network transaction request to the zero trust gateway and the device management system; the target network transaction request is each network transaction request sent by the target POS device.

[0102] S302: The zero-trust gateway sends the target network transaction request to the trust engine.

[0103] S303: The device management system verifies the target network transaction request, obtains a verification result corresponding to the target network transaction request, and obtains attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine.

[0104] S304: The intelligence system sends the collected intelligence information of the abnormal POS device to the trust engine.

[0105] S305: After receiving the target network transaction request, the trust engine determines a decision result according to the verification result corresponding to the target network transaction request, the attribute information of the target POS device, the intelligence information of the abnormal POS device, and a security policy, and sends the decision result to the zero-trust gateway; the decision result is used to indicate whether to authorize the target network transaction request.

[0106] S306: The zero-trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

[0107] In a possible implementation, the method further includes:

[0108] The device management system issues a device certificate for the target POS device, and records a binding relationship between the target POS device and the device certificate.

[0109] As an optional example, the target network transaction request includes a device certificate of the target POS device. In a possible implementation, the present application embodiment provides a specific implementation of the device management system verifying the target network transaction request in S303 to obtain a verification result corresponding to the target network transaction request, including:

[0110] The device management system verifies the device certificate of the target POS device in the target network transaction request to obtain a verification result corresponding to the target network transaction request; the verification result corresponding to the target network transaction request includes a verification result of the device certificate of the target POS device.

[0111] In a possible implementation, the intelligence information of the abnormal POS device includes one or more of device abnormal basic information, device abnormal behavior information, device abnormal running environment information, and device abnormal running state information of the abnormal POS device.

[0112] In a possible implementation, the attribute information of the target POS device includes basic information of the target POS device, request behavior information of the target POS device, running environment information of the target POS device, and running state information of the target POS device.

[0113] In a possible implementation, the embodiment of the application provides a specific implementation of S305, including:

[0114] After receiving the target network transaction request, the trust engine compares the basic information of the target POS device with the device abnormal basic information of the abnormal POS device, to obtain a first comparison result;

[0115] The request behavior information of the target POS device is compared with the device abnormal behavior information of the abnormal POS device to obtain a second comparison result;

[0116] The running environment information of the target POS device is compared with the device abnormal running environment information of the abnormal POS device to obtain a third comparison result;

[0117] The running state information of the target POS device is compared with the device abnormal running state information of the abnormal POS device to obtain a fourth comparison result;

[0118] According to the verification result corresponding to the target network transaction request, the first comparison result, the second comparison result, the third comparison result, the fourth comparison result, and a security policy, a decision result is determined, and the decision result is sent to the zero trust gateway.

[0119] In a possible implementation, the zero trust gateway and the target POS device establish a network transmission data encryption channel, and the zero trust gateway and the background application system establish a network transmission data encryption channel.

[0120] In a possible implementation, the basic information of the target POS device includes device version information of the target POS device.

[0121] In a possible implementation, the running environment information of the target POS device includes access time, access location, and access network environment of the target POS device.

[0122] Those skilled in the art can understand that, in the above method of the specific implementation, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process, and the specific execution order of each step should be determined according to its function and possible internal logic.

[0123] It should be noted that the POS security control system and method provided in the present application can be used in the financial field or other fields, for example, can be used in the application scenario of the POS device in the financial field to realize transaction. The other fields are any fields other than the financial field, for example, the information security field. The above are only examples and do not limit the application field of the POS security control system and method provided in the present application.

[0124] From the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps of the above-mentioned embodiment methods can be implemented by means of software and the necessary general hardware platforms. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network communication device such as a media gateway, etc.) execute the methods described in the various embodiments or some parts of the embodiments.

[0125] It should be noted that the embodiments in the present specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other.

[0126] It should also be noted that in this document, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles, or devices including a series of elements not only include those elements, but also include other elements not explicitly listed, or further include elements inherent in such processes, methods, articles, or devices. Without more limitations, the element defined by the statement "including a" does not exclude the presence of additional identical elements in the process, method, article, or device including the element.

[0127] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A POS security control system, characterized by, The POS security control system comprises a target POS device, a zero-trust gateway, a device management system, an intelligence system, a trust engine and a background application system; The target POS device is configured to send a target network transaction request to the zero-trust gateway and the device management system, wherein the target network transaction request is each network transaction request sent by the target POS device; The zero-trust gateway is configured to send the target network transaction request to the trust engine; The device management system is configured to verify the target network transaction request, obtain a verification result corresponding to the target network transaction request, and obtain attribute information of the target POS device, and send the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine; the attribute information of the target POS device comprises basic information of the target POS device, request behavior information of the target POS device, running environment information of the target POS device and running state information of the target POS device; The intelligence system is configured to send collected intelligence information of an abnormal POS device to the trust engine; the intelligence information of the abnormal POS device comprises device abnormal basic information, device abnormal behavior information, device abnormal running environment information and device abnormal running state information of the abnormal POS device; The trust engine is configured to, after receiving the target network transaction request, compare the basic information of the target POS device with the device abnormal basic information of the abnormal POS device to obtain a first comparison result, compare the request behavior information of the target POS device with the device abnormal behavior information of the abnormal POS device to obtain a second comparison result, compare the running environment information of the target POS device with the device abnormal running environment information of the abnormal POS device to obtain a third comparison result, compare the running state information of the target POS device with the device abnormal running state information of the abnormal POS device to obtain a fourth comparison result, determine a decision result according to the verification result corresponding to the target network transaction request, the first comparison result, the second comparison result, the third comparison result, the fourth comparison result and a security policy, and send the decision result to the zero-trust gateway; the decision result is used to indicate whether to authorize the target network transaction request; The zero-trust gateway is further configured to determine whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

2. The system of claim 1, wherein, The device management system is further configured to issue a device certificate for the target POS device and record a binding relationship between the target POS device and the device certificate.

3. The system of claim 1 or 2, wherein, The target network transaction request comprises a device certificate of the target POS device; The device management system is specifically configured to verify the device certificate of the target POS device in the target network transaction request, and obtain a verification result corresponding to the target network transaction request; and the verification result corresponding to the target network transaction request includes a verification result of the device certificate of the target POS device.

4. The system of claim 1, wherein, The basic information of the target POS device includes device version information of the target POS device.

5. The system of claim 1, wherein, The running environment information of the target POS device includes access time, access location and access network environment of the target POS device.

6. The system of claim 1, wherein, The zero-trust gateway and the target POS device establish a network transmission data encryption channel, and the zero-trust gateway and the background application system establish a network transmission data encryption channel.

7. A POS security control method characterized by comprising: The method is applied to a POS security control system. The POS security control system includes a target POS device, a zero-trust gateway, a device management system, an intelligence system, a trust engine and a background application system; and the method includes: The target POS device sends a target network transaction request to the zero-trust gateway and the device management system; the target network transaction request is each network transaction request sent by the target POS device; The zero-trust gateway sends the target network transaction request to the trust engine; The device management system verifies the target network transaction request, obtains a verification result corresponding to the target network transaction request, and obtains attribute information of the target POS device, and sends the verification result corresponding to the target network transaction request and the attribute information of the target POS device to the trust engine; the attribute information of the target POS device includes basic information of the target POS device, request behavior information of the target POS device, running environment information of the target POS device and running state information of the target POS device; The intelligence system sends collected intelligence information of an abnormal POS device to the trust engine; the intelligence information of the abnormal POS device includes device abnormal basic information, device abnormal behavior information, device abnormal running environment information and device abnormal running state information of the abnormal POS device. After the trust engine receives the target network transaction request, the base information of the target POS device is compared with the device abnormal base information of the abnormal POS device to obtain a first comparison result; the request behavior information of the target POS device is compared with the device abnormal behavior information of the abnormal POS device to obtain a second comparison result; the running environment information of the target POS device is compared with the device abnormal running environment information of the abnormal POS device to obtain a third comparison result; the running state information of the target POS device is compared with the device abnormal running state information of the abnormal POS device to obtain a fourth comparison result; according to the verification result corresponding to the target network transaction request, the first comparison result, the second comparison result, the third comparison result, the fourth comparison result and a security policy, a decision result is determined, and the decision result is sent to the zero trust gateway; the decision result is used to indicate whether to authorize the target network transaction request; The zero trust gateway determines whether to release the target network transaction request according to the decision result, so that the target POS device accesses the background application system.

Citation Information

Patent Citations

  • Data access authentication method and device, authentication equipment and authentication system

    CN112738100A

  • Zero-trust-based Internet of Things system, data access method and device and medium

    CN114553540A