Request response method, device, equipment, medium
Patent Information
- Application Number
- CN202210903461.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-29
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2042-07-29
AI Technical Summary
[0003]但是,在实现本公开的发明构思的过程中,发明人发现,在实时电子支付的数据交互过程中,会产生诸如插入恶意U盘HID、毛刺攻击、量子能量攻击等衍生攻击,导致交易风险
[0044]According to embodiments of this disclosure, by acquiring transaction request information and transaction environment information, a credibility score for the transaction request is generated based on these information. Then, the identification information and transaction rule information of the first terminal are input into an access control model, which outputs an access control result. Based on the credibility score and the access control result, valid data suitable for executing the transaction can be filtered from the transaction request, and the target transaction data is sent to the second terminal. Based on the access control result of the access control model and the credibility score of the transaction request, data that may lead to derivative attacks can be filtered out when the first terminal initiates a transaction request, thereby effectively mitigating the transaction risks caused by derivative attacks.
Smart Images

Figure CN115689568B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the fields of information security technology and financial technology, specifically to a request-response method, apparatus, device, medium, and program product. Background Technology
[0002] With the development of information technology, electronic payment methods are becoming increasingly widespread, such as IC cards, mobile eSE cards, mobile SIM card payments, and so on.
[0003] However, in the process of realizing the inventive concept disclosed herein, the inventors discovered that during the data interaction process of real-time electronic payment, derivative attacks such as inserting malicious USB flash drives (HID), glitch attacks, and quantum energy attacks may occur, leading to transaction risks. Summary of the Invention
[0004] In view of the above problems, this disclosure provides a request-response method, apparatus, device, medium, and program product.
[0005] According to one aspect of this disclosure, a request-response method is provided, comprising:
[0006] In response to a transaction request initiated by the first terminal to conduct a transaction with the second terminal, the system obtains transaction request information and transaction environment information; the transaction request information includes the identification information of the first terminal, transaction rule information, and the identification information of the second terminal.
[0007] The credibility of a transaction request is generated based on the transaction request information and the transaction environment information.
[0008] The identification information and transaction rule information of the first terminal are input into the access control model, and the access control result is output. The access control result indicates whether the transaction rule information meets the access control conditions of the first terminal.
[0009] Based on trustworthiness and access control results, target transaction data is determined from the transaction request; the target transaction data represents valid data used to execute the transaction.
[0010] Based on the identification information of the second terminal, the target transaction data is sent to the second terminal.
[0011] According to embodiments of this disclosure, the credibility of a transaction request is generated based on transaction request information and transaction environment information, including:
[0012] The first credibility of the transaction request information is determined by calculating the first information entropy of the transaction request information;
[0013] The second credibility of the transaction environment information is determined by calculating the second information entropy of the transaction environment information.
[0014] The credibility of the transaction request is generated based on the first credibility and the second credibility.
[0015] According to embodiments of this disclosure, the above request-response method further includes:
[0016] Based on the first level of credibility, determine the target transaction request information from the transaction request information;
[0017] Based on the second level of credibility, the target trading environment information is determined from the trading environment information.
[0018] According to embodiments of this disclosure, target transaction data is determined from a transaction request based on trust level and access control results. The target transaction data represents valid data for executing the transaction, including:
[0019] Generate a data filtering matrix based on the credibility and access control results;
[0020] Target transaction data is determined based on transaction request information, transaction environment information, and data filtering matrix.
[0021] According to embodiments of this disclosure, the identification information and transaction rule information of the first terminal are input into the access control model, and the access control result is output, including:
[0022] Based on the first terminal identification information, the target access subject information is determined;
[0023] Based on the transaction rules, determine the target authorization information;
[0024] Input the target access subject information and target authorization permission information into the access control model, and output the access control result.
[0025] According to embodiments of this disclosure, the above request-response method further includes:
[0026] If the access control result is "access allowed", the target transaction data is encrypted using an encryption algorithm to obtain the encrypted target transaction data.
[0027] Send encrypted data of the first target transaction to the first terminal;
[0028] Receive encrypted data of a second target transaction fed back by a first terminal, wherein the encrypted data of the second target transaction includes encrypted data of the first target transaction and key information of the first terminal;
[0029] Send encrypted data of the second target transaction to the second terminal.
[0030] According to embodiments of this disclosure, the above request-response method further includes:
[0031] Based on the identifier of the second terminal, the data transmission condition information is determined, which includes format condition information and quantity condition information;
[0032] Based on the format and quantity information, the target transaction data is converted into a target data file;
[0033] The target data file is sent to the second terminal based on the identifier of the second terminal.
[0034] Another aspect of this disclosure provides a request-response apparatus, comprising: an acquisition module, a generation module, an access control module, a first determination module, and a first sending module. The acquisition module is used to acquire transaction request information and transaction environment information in response to a transaction request initiated by a first terminal to transact with a second terminal; the transaction request information includes identification information of the first terminal, transaction rule information, and identification information of the second terminal. The generation module is used to generate a credibility level for the transaction request based on the transaction request information and the transaction environment information. The access control module is used to input the identification information of the first terminal and the transaction rule information into an access control model and output an access control result, the access control result indicating whether the transaction rule information meets the access permission control conditions of the first terminal. The first determination module is used to determine target transaction data from the transaction request based on the credibility level and the access control result, the target transaction data representing valid data for executing the transaction. The first sending module is used to send the target transaction data to the second terminal based on the identification information of the second terminal.
[0035] According to embodiments of this disclosure, the generation module includes a first determining unit, a second determining unit, and a first generating unit. The first determining unit is used to determine a first credibility of the transaction request information by calculating a first information entropy of the transaction request information. The second determining unit is used to determine a second credibility of the transaction environment information by calculating a second information entropy of the transaction environment information. The first generating unit is used to generate the credibility of the transaction request based on the first credibility and the second credibility.
[0036] According to embodiments of this disclosure, the request response device further includes a second determining module and a third determining module. The second determining module is used to determine target transaction request information from the transaction request information based on a first level of confidence. The third determining module is used to determine target transaction environment information from the transaction environment information based on the second level of confidence.
[0037] According to embodiments of this disclosure, the first determining module includes a second generating unit and a third determining unit. The second generating unit is used to generate a data filtering matrix based on trustworthiness and access control results. The third determining unit is used to determine target transaction data based on transaction request information, transaction environment information, and the data filtering matrix.
[0038] According to embodiments of this disclosure, the access control module includes a fourth determining unit, a fifth determining unit, and an output unit. The fourth determining unit is used to determine target access subject information based on first terminal identification information. The fifth determining unit is used to determine target authorization permission information based on transaction rule information. The output unit is used to input the target access subject information and the target authorization permission information into the access control model and output the access control result.
[0039] According to embodiments of this disclosure, the request response device further includes an encryption module, a third sending module, a receiving module, and a fourth sending module. The encryption module is used to encrypt the target transaction data using an encryption algorithm when the access control result is "allowed," obtaining encrypted target transaction data. The third sending module is used to send the first encrypted target transaction data to the first terminal. The receiving module is used to receive the second encrypted target transaction data fed back by the first terminal, wherein the second encrypted target transaction data includes the first encrypted target transaction data and the key information of the first terminal. The fourth sending module is used to send the second encrypted target transaction data to the second terminal.
[0040] According to embodiments of this disclosure, the request response device further includes a fourth determining module, a conversion module, and a second sending module. The fourth determining module is used to determine data transmission condition information based on the identifier of the second terminal, wherein the data transmission condition information includes format condition information and quantity condition information. The conversion module is used to convert the target transaction data into a target data file based on the format condition information and quantity condition information. The second sending module is used to send the target data file to the second terminal based on the identifier of the second terminal.
[0041] Another aspect of this disclosure provides an electronic device, including: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the above-described request-response method.
[0042] Another aspect of this disclosure provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the above-described request-response method.
[0043] Another aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the above-described request-response method.
[0044] According to embodiments of this disclosure, by acquiring transaction request information and transaction environment information, a credibility score for the transaction request is generated based on these information. Then, the identification information and transaction rule information of the first terminal are input into an access control model, which outputs an access control result. Based on the credibility score and the access control result, valid data suitable for executing the transaction can be filtered from the transaction request, and the target transaction data is sent to the second terminal. Based on the access control result of the access control model and the credibility score of the transaction request, data that may lead to derivative attacks can be filtered out when the first terminal initiates a transaction request, thereby effectively mitigating the transaction risks caused by derivative attacks. Attached Figure Description
[0045] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0046] Figure 1 The illustration schematically depicts application scenarios of request-response methods, apparatus, devices, media, and program products according to embodiments of the present disclosure;
[0047] Figure 2 A flowchart illustrating a request-response method according to an embodiment of the present disclosure is shown schematically.
[0048] Figure 3 The illustration shows a flowchart illustrating the process of generating a credibility of a transaction request based on transaction request information and transaction environment information, according to an embodiment of the present disclosure.
[0049] Figure 4 The illustration shows a flowchart of inputting the identification information and transaction rule information of a first terminal into an access control model and outputting the access control result according to an embodiment of the present disclosure.
[0050] Figure 5 A schematic diagram illustrating the hardware architecture of a request-response method according to an embodiment of the present disclosure is shown.
[0051] Figure 6 A schematic block diagram of a request response apparatus according to an embodiment of the present disclosure is shown; and
[0052] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing a request-response method according to an embodiment of the present disclosure. Detailed Implementation
[0053] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0054] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0055] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0056] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).
[0057] It should be noted that the request response method and apparatus disclosed herein can be used in the fields of information security technology and financial technology, as well as in any field other than the fields of financial technology and information security technology. The application fields of the request response method and apparatus disclosed herein are not limited.
[0058] This disclosure provides a request-response method, comprising: responding to a transaction request initiated by a first terminal to conduct a transaction with a second terminal, obtaining transaction request information and transaction environment information; the transaction request information includes identification information of the first terminal, transaction rule information, and identification information of the second terminal; generating a credibility of the transaction request based on the transaction request information and the transaction environment information; inputting the identification information of the first terminal and the transaction rule information into an access control model, and outputting an access control result, the access control result indicating whether the transaction rule information meets the access permission control conditions of the first terminal; determining target transaction data from the transaction request based on the credibility and the access control result, the target transaction data indicating valid data used to execute the transaction; and sending the target transaction data to the second terminal based on the identification information of the second terminal.
[0059] Figure 1 The illustration shows an application scenario diagram of the request-response method according to an embodiment of the present disclosure.
[0060] like Figure 1 As shown, application scenario 100 according to this embodiment may include terminal devices 101, 102, and 103, network 104, and server 105. Network 104 is used as a medium to provide a communication link between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.
[0061] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0062] Terminal devices 101, 102, and 103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0063] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using terminal devices 101, 102, and 103 (for example only). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0064] It should be noted that the request-response method provided in this embodiment can generally be executed by server 105. Accordingly, the request-response device provided in this embodiment can generally be located in server 105. The request-response method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Accordingly, the request-response device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.
[0065] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0066] The following will be based on Figure 1 The described scene, through Figures 2-5 The request-response method of the disclosed embodiments will be described in detail.
[0067] Figure 2 A flowchart illustrating a request-response method according to an embodiment of the present disclosure is shown schematically.
[0068] like Figure 2 As shown, the request-response method of this embodiment includes operations S210 to S250.
[0069] In operation S210, in response to a transaction request initiated by the first terminal to conduct a transaction with the second terminal, transaction request information and transaction environment information are obtained; the transaction request information includes the identification information of the first terminal, transaction rule information, and the identification information of the second terminal.
[0070] According to embodiments of this disclosure, the first terminal can be a hardware device for executing transactions, such as a chip attached to a smart device like a mobile phone, such as a visual Bluetooth IC card, a mobile phone eSE card, a mobile phone SD card, or a mobile phone SIM card. The transaction medium on which the chip relies can be a mobile phone or various hardware transaction systems or platforms containing a main control unit such as a security chip. The second terminal can be a hardware device similar to the first terminal, or a software system capable of conducting transactions with the first terminal.
[0071] According to embodiments of this disclosure, transaction rule information may include rules for reading keys and checking key status during the transaction execution process. Transaction environment information may include physical environment information between the first terminal and the second terminal, and heartbeat status information between the first terminal and the second terminal. For example, if the first terminal and the second terminal rely on Bluetooth for data transmission, the physical distance between them can determine whether Bluetooth transmission can be achieved; therefore, the physical distance between the first terminal and the second terminal can be considered as physical environment information. Physical environment information may also include spatial environment data of the first terminal and the second terminal, such as electromagnetic signal strength data. Heartbeat status information may include the heartbeat status of the terminal hardware components, or the heartbeat status indicating whether the terminal software is functioning correctly.
[0072] In operation S220, the credibility of the transaction request is generated based on the transaction request information and the transaction environment information.
[0073] According to embodiments of this disclosure, genuine and valid transaction request data generally includes multivariate information, and its data is relatively regular and complex, thus exhibiting high information entropy. However, some derivative attack methods often use irregular and less complex data, resulting in low information entropy. Therefore, the credibility of a transaction request can be generated by calculating the information entropy in the transaction request information and transaction environment information. For example, the transaction request information and transaction environment information include: request data A1, request data A2, ..., request data A... i Each request data entry includes different types of data, such as: identification data of the first terminal, transaction rule data, identification data of the second terminal, physical environment data, spatial environment data, heartbeat status data, etc. The information entropy can be determined by calculating the probability of each different type of data appearing in each request data entry. The method for calculating information entropy is well-known in the field and will not be elaborated here. For example, the information entropies corresponding to the request data in the transaction request information are H1, H2, ..., H... n The vector (H1, H2, ..., H) composed of information entropy can be used to form a vector. n The credibility of the transaction request information is determined.
[0074] In operation S230, the identification information and transaction rule information of the first terminal are input into the access control model, and the access control result is output. The access control result indicates whether the transaction rule information meets the access control conditions of the first terminal.
[0075] According to embodiments of this disclosure, the access control model can employ the UCON (Usage Control) access control model. The identification information and transaction rule information of the first terminal are input into the aforementioned UCON access control model, and the access control result F(R) is output, where:
[0076]
[0077] Where F(R) represents the access control result and R represents the transaction rule.
[0078] According to embodiments of this disclosure, the access control result represents the limit value when the number of transaction rules is greater than 0. It can be used to indicate whether the transaction rule information meets the access control conditions of the first terminal. For example, if the access control conditions are met, it means that the transaction request can interact with the first terminal to obtain the transaction key. If the access control conditions are not met, it means that the transaction request cannot interact with the first terminal to obtain the transaction key.
[0079] According to the embodiments of this disclosure, it can be determined directly from the result output by the UCON using the access control model whether the transaction request meets the access control conditions of the first terminal, or it can be determined from the result value output by the UCON using the access control model whether it meets the threshold range, thus determining whether the transaction request meets the access control conditions of the first terminal.
[0080] In operation S240, based on trustworthiness and access control results, target transaction data is determined from the transaction request. The target transaction data represents the valid data used to execute the transaction.
[0081] According to embodiments of this disclosure, target transaction data can be determined from multiple data sources in a transaction request based on trustworthiness and access control results. For example, transaction request A includes: request data A1, request data A2, ..., request data A... i Based on credibility, a dataset M (request data A1, request data A2, ..., request data A1) with high information entropy values can be selected from transaction request A. k (k < i), the dataset N (request data A5, request data A6, ..., request data A) that can satisfy the access control conditions of the first terminal can be filtered out based on the access control results. i Then, you can take the intersection of dataset M and dataset N (request data A5, request data A6, ..., request data A...). k (), as target transaction data.
[0082] According to embodiments of this disclosure, in actual transaction scenarios, it is usually necessary to encrypt transaction data. When the access control result indicates that the first terminal can access the transaction, the target transaction data can be encrypted using an encryption algorithm, sent to the first terminal first, and then the encrypted target transaction data returned by the first terminal is received. Finally, the encrypted target transaction data is sent to the second terminal.
[0083] When operating S250, target transaction data is sent to the second terminal based on the identification information of the second terminal.
[0084] According to embodiments of this disclosure, target data (request data A5, request data A6, ..., request data A) is sent to the second terminal based on the identification information of the second terminal. k ), used to execute transaction operations between the first terminal and the second terminal.
[0085] According to embodiments of this disclosure, by acquiring transaction request information and transaction environment information, a credibility score for the transaction request is generated based on these information. Then, the identification information and transaction rule information of the first terminal are input into an access control model, which outputs an access control result. Based on the credibility score and the access control result, valid data suitable for executing the transaction can be filtered from the transaction request, and the target transaction data is sent to the second terminal. Based on the access control result of the access control model and the credibility score of the transaction request, data that may lead to derivative attacks can be filtered out when the first terminal initiates a transaction request, thereby effectively mitigating the transaction risks caused by derivative attacks.
[0086] Figure 3 The illustration shows a flowchart illustrating the process of generating a transaction request credibility based on transaction request information and transaction environment information, according to an embodiment of the present disclosure.
[0087] like Figure 3 As shown, the method for generating the credibility of a transaction request in this embodiment includes: S310 to S330.
[0088] In operation S310, the first information entropy of the transaction request information is calculated to determine the first credibility of the transaction request information;
[0089] In operation S320, the second information entropy of the transaction environment information is calculated to determine the second credibility of the transaction environment information;
[0090] In operation S330, the credibility of the transaction request is generated based on the first credibility and the second credibility.
[0091] According to embodiments of this disclosure, the transaction rules information in the transaction request information varies significantly across different business domains and is highly complex, resulting in high information entropy. In contrast, the transaction environment information is relatively simple and straightforward. Therefore, to improve the efficiency of filtering effective data, the transaction request information and transaction environment information can be processed separately.
[0092] According to embodiments of this disclosure, the first confidence level can be the average of the information entropy corresponding to multiple data points in the transaction request information, and the second confidence level can be the average of the information entropy of multiple data points in the transaction environment information. The confidence level of the transaction request can be a vector composed of the first confidence level and the second confidence level.
[0093] According to embodiments of this disclosure, by calculating the information entropy of the transaction request information and the information entropy of the transaction environment information respectively, and determining the credibility of the transaction request by the average value of the information entropy, the amount of data processing in subsequent processing can be reduced and the data processing efficiency can be improved.
[0094] Since information entropy can reflect the regularity and complexity of multivariate variables, it can reflect the validity of data to a certain extent. Therefore, information entropy can be used to perform preliminary screening of data in transaction requests.
[0095] According to embodiments of this disclosure, the above request-response method further includes:
[0096] Based on the first level of credibility, determine the target transaction request information from the transaction request information;
[0097] Based on the second level of credibility, the target trading environment information is determined from the trading environment information.
[0098] According to embodiments of this disclosure, the first confidence level can be the average of the information entropy corresponding to multiple data points in the transaction request information. The information entropy range can be determined based on the first confidence level; for example, if the first confidence level is A, the information entropy range can be A ± 0.5. The set of data in the transaction request information whose information entropy is within the range of A ± 0.5 is determined as the target transaction request information.
[0099] According to embodiments of this disclosure, the second confidence level can be the average of the information entropy corresponding to multiple data points in the transaction environment information. The information entropy range can be determined based on the second confidence level; for example, if the second confidence level is B, the information entropy range can be B ± 0.1. The set of data in the transaction environment information whose information entropy is within the range of B ± 0.1 is determined as the target transaction environment information.
[0100] According to embodiments of this disclosure, transaction request information and transaction environment information are initially screened using information entropy through a first credibility and a second credibility, thereby reducing the amount of data processing in subsequent processing.
[0101] According to embodiments of this disclosure, target transaction data is determined from a transaction request based on trust level and access control results. The target transaction data represents valid data for executing the transaction, including:
[0102] Generate a data filtering matrix based on the credibility and access control results;
[0103] Target transaction data is determined based on transaction request information, transaction environment information, and data filtering matrix.
[0104] According to embodiments of this disclosure, an n-dimensional data filtering matrix T can be generated based on the trustworthiness and access control results, wherein the dimension of the data filtering matrix T is determined by the trustworthiness and the granularity of access control.
[0105] According to embodiments of this disclosure, transaction request information and transaction environment information can be normalized to obtain a data matrix A to be processed. The target transaction data can be determined by calculating the product of the data matrix A and the data filtering matrix T.
[0106] According to embodiments of this disclosure, by generating a data filtering matrix based on trustworthiness and access control results, the correlation between information entropy and access control results and the data in the transaction request can be checked, and noisy data or data that may generate derivative attacks in the transaction request can be deleted, thereby obtaining a valid transaction that can be used to execute the transaction and reducing the risk of derivative attacks on the transaction process.
[0107] Figure 4 The illustration shows a flowchart illustrating the input of the identification information and transaction rule information of a first terminal into an access control model and the output of access control results according to an embodiment of the present disclosure.
[0108] like Figure 4 As shown, the output access control results of this embodiment include operations S410 to S430.
[0109] During operation S410, the target access subject information is determined based on the first terminal identification information;
[0110] When operating S420, determine the target authorization information based on the transaction rules information;
[0111] When operating S430, the target access subject information and target authorization permission information are input into the access control model, and the access control result is output.
[0112] According to embodiments of this disclosure, the core of the access control model is the authorization policy. The subject information in the access control model can be determined based on the first terminal identification information. The target access subject information and the target authorization permission information are input into the access control model to determine whether the current transaction rules conform to the authorization policy of the target access subject. Only when the authorization policy of the target access subject is conformed can the key information for executing the transaction be obtained from the first terminal.
[0113] According to embodiments of this disclosure, for example, transaction rule A is "no key information is required when receiving transaction funds, but key information is required when paying transaction funds." The current transaction request is a payment transaction request initiated by the first terminal, and the authorization policy is "when the first terminal initiates a payment transaction, the receiving terminal is authorized to obtain the key information used to execute the transaction." When the transaction rule information and the identification information of the first terminal are input into the access control model, the output access control result can indicate "the receiving terminal is allowed to obtain the key information used to execute the transaction."
[0114] According to embodiments of this disclosure, fine-grained control of access control permissions based on an access control model, combined with the identification information of the first terminal, can effectively ensure information security during transactions between the first terminal and the second terminal, and effectively reduce the incidence of derivative attacks.
[0115] According to embodiments of this disclosure, the above request-response method further includes:
[0116] Based on the identifier of the second terminal, the data transmission condition information is determined, which includes format condition information and quantity condition information;
[0117] Based on the format and quantity information, the target transaction data is converted into a target data file;
[0118] The target data file is sent to the second terminal based on the identifier of the second terminal.
[0119] According to embodiments of this disclosure, the format condition information may be the transmission protocol format used for interaction between the first terminal and the second terminal. The quantity condition information may be the maximum amount of data that the second terminal can receive.
[0120] According to embodiments of this disclosure, target transaction data can be converted into a target data file with a data size smaller than the maximum data size that the second terminal can receive, according to a transmission protocol format.
[0121] According to embodiments of this disclosure, a target data file is sent to a second terminal.
[0122] According to embodiments of this disclosure, by converting the target transaction data into a target data folder that meets the data reception conditions of the second terminal, and then sending it to the second terminal, the data transmission quality can be improved and the normal operation of the transaction can be guaranteed.
[0123] According to embodiments of this disclosure, the above request-response method further includes:
[0124] If the access control result is "access allowed", the target transaction data is encrypted using an encryption algorithm to obtain the encrypted target transaction data.
[0125] Send encrypted data of the first target transaction to the first terminal;
[0126] Receive encrypted data of a second target transaction fed back by a first terminal, wherein the encrypted data of the second target transaction includes encrypted data of the first target transaction and key information of the first terminal;
[0127] Send encrypted data of the second target transaction to the second terminal.
[0128] Figure 5 A schematic diagram of the hardware architecture of a request-response method according to an embodiment of the present disclosure is shown.
[0129] like Figure 5 As shown, a protection component device 502 is provided in front of the hardware transaction device 501. The protection component device is used to execute the request response method of this embodiment.
[0130] In response to a transaction request initiated by the hardware trading device 501 to the software trading platform 503, the system obtains transaction request data. After transmission through the physical and network environments, the transaction request data first interacts with the protection component device 502 to obtain the target transaction data. Then, the system uses the access key of the hardware trading device 501 to encrypt the target transaction data using the AES128-CMAC algorithm and forwards it to the hardware trading device 501. The system also returns the target transaction data encrypted with the private key to the protection component device 502, which then sends the encrypted target transaction data to the software trading platform 503.
[0131] According to embodiments of this disclosure, target transaction data is encrypted using an encryption algorithm and sent to a first terminal. Then, the encrypted target transaction data containing the first terminal's key information is obtained, thereby improving the information security of the transaction.
[0132] Based on the above request-response method, this disclosure also provides a request-response apparatus. The following will be combined with... Figure 6 The device is described in detail.
[0133] Figure 6 A schematic block diagram of a request response apparatus according to an embodiment of the present disclosure is shown.
[0134] like Figure 6 As shown, the request response device 600 of this embodiment includes an acquisition module 610, a generation module 620, an access control module 630, a first determination module 640, and a first sending module 650.
[0135] The acquisition module 610 is used to respond to a transaction request initiated by the first terminal to conduct a transaction with the second terminal, and to acquire transaction request information and transaction environment information; the transaction request information includes the identification information of the first terminal, transaction rule information, and the identification information of the second terminal. In one embodiment, the acquisition module 610 can be used to perform the operation S210 described above, which will not be repeated here.
[0136] The generation module 620 is used to generate the credibility of a transaction request based on the transaction request information and the transaction environment information. In one embodiment, the generation module 620 can be used to perform the operation S220 described above, which will not be repeated here.
[0137] The access control module 630 is used to input the identification information and transaction rule information of the first terminal into the access control model and output the access control result. The access control result indicates whether the transaction rule information meets the access permission control conditions of the first terminal. In one embodiment, the access control module 630 can be used to execute the operation S230 described above, which will not be repeated here.
[0138] The first determining module 640 is used to determine target transaction data from the transaction request based on trust level and access control results. The target transaction data represents valid data used to execute the transaction. In one embodiment, the first determining module 640 can be used to perform the operation S240 described above, which will not be repeated here.
[0139] The first sending module 650 is used to send target transaction data to the second terminal based on the identification information of the second terminal. The first sending module 650 can be used to perform the operation S250 described above, which will not be repeated here.
[0140] According to embodiments of this disclosure, the generation module includes a first determining unit, a second determining unit, and a first generating unit. The first determining unit is used to determine a first credibility of the transaction request information by calculating a first information entropy of the transaction request information. The second determining unit is used to determine a second credibility of the transaction environment information by calculating a second information entropy of the transaction environment information. The first generating unit is used to generate the credibility of the transaction request based on the first credibility and the second credibility.
[0141] According to embodiments of this disclosure, the request response device further includes a second determining module and a third determining module. The second determining module is used to determine target transaction request information from the transaction request information based on a first level of confidence. The third determining module is used to determine target transaction environment information from the transaction environment information based on the second level of confidence.
[0142] According to embodiments of this disclosure, the first determining module includes a second generating unit and a third determining unit. The second generating unit is used to generate a data filtering matrix based on trustworthiness and access control results. The third determining unit is used to determine target transaction data based on transaction request information, transaction environment information, and the data filtering matrix.
[0143] According to embodiments of this disclosure, the access control module includes a fourth determining unit, a fifth determining unit, and an output unit. The fourth determining unit is used to determine target access subject information based on first terminal identification information. The fifth determining unit is used to determine target authorization permission information based on transaction rule information. The output unit is used to input the target access subject information and the target authorization permission information into the access control model and output the access control result.
[0144] According to embodiments of this disclosure, the request response device further includes an encryption module, a third sending module, a receiving module, and a fourth sending module. The encryption module is used to encrypt the target transaction data using an encryption algorithm when the access control result is "allowed," obtaining encrypted target transaction data. The third sending module is used to send the first encrypted target transaction data to the first terminal. The receiving module is used to receive the second encrypted target transaction data fed back by the first terminal, wherein the second encrypted target transaction data includes the first encrypted target transaction data and the key information of the first terminal. The fourth sending module is used to send the second encrypted target transaction data to the second terminal.
[0145] According to embodiments of this disclosure, the request response device further includes a fourth determining module, a conversion module, and a second sending module. The fourth determining module is used to determine data transmission condition information based on the identifier of the second terminal, wherein the data transmission condition information includes format condition information and quantity condition information. The conversion module is used to convert the target transaction data into a target data file based on the format condition information and quantity condition information. The second sending module is used to send the target data file to the second terminal based on the identifier of the second terminal.
[0146] According to embodiments of this disclosure, any plurality of modules among the acquisition module 610, generation module 620, access control module 630, first determination module 640, and first transmission module 650 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 610, generation module 620, access control module 630, first determination module 640, and first transmission module 650 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of software, hardware, and firmware methods, or in a suitable combination of any of these methods. Alternatively, at least one of the acquisition module 610, generation module 620, access control module 630, first determination module 640, and first sending module 650 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0147] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing a request-response method according to an embodiment of the present disclosure.
[0148] like Figure 7 As shown, an electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage portion 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0149] RAM 703 stores various programs and data required for the operation of electronic device 700. Processor 701, ROM 702, and RAM 703 are interconnected via bus 704. Processor 701 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 702 and / or RAM 703. It should be noted that the programs may also be stored in one or more memories other than ROM 702 and RAM 703. Processor 701 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0150] According to embodiments of this disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, which is also connected to a bus 704. The electronic device 700 may also include one or more of the following components connected to the I / O interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.
[0151] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0152] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 702 and / or RAM 703 and / or one or more memories other than ROM 702 and RAM 703 described above.
[0153] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the item recommendation method provided in the embodiments of this disclosure.
[0154] When the computer program is executed by the processor 701, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0155] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 709, and / or installed from a removable medium 711. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0156] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0157] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0158] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0159] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0160] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. A request-response method, comprising: In response to a transaction request initiated by the first terminal to conduct a transaction with the second terminal, the system obtains transaction request information and transaction environment information. The transaction request information includes the identification information of the first terminal, the transaction rule information, and the identification information of the second terminal; A first credibility of the transaction request information is determined by calculating the first information entropy of the transaction request information; the first credibility is the average value of the information entropy corresponding to multiple data points in the transaction request information. A second credibility of the transaction environment information is determined by calculating the second information entropy of the transaction environment information; the second credibility is the average of the information entropies of multiple data points in the transaction environment information. The credibility of the transaction request is generated based on the first credibility and the second credibility; the credibility of the transaction request is a vector composed of the first credibility and the second credibility. The identification information of the first terminal and the transaction rule information are input into the access control model, and the access control result is output. The access control result indicates whether the transaction rule information meets the access control conditions of the first terminal. Based on the trustworthiness and the access control result, target transaction data is determined from the transaction request, wherein the target transaction data represents valid data for executing the transaction; as well as The target transaction data is sent to the second terminal based on the identification information of the second terminal.
2. The method according to claim 1, further comprising: Based on the first level of credibility, the target transaction request information is determined from the transaction request information; Based on the second level of credibility, the target transaction environment information is determined from the transaction environment information.
3. The method according to claim 1, wherein, The step of determining target transaction data from the transaction request based on the trustworthiness and the access control result, wherein the target transaction data represents valid data for executing the transaction, including: Based on the credibility and the access control results, a data filtering matrix is generated; The target transaction data is determined based on the transaction request information, the transaction environment information, and the data filtering matrix.
4. The method according to claim 1, wherein, The step of inputting the identification information of the first terminal and the transaction rule information into the access control model and outputting the access control result includes: Based on the first terminal identification information, the target access subject information is determined; Based on the transaction rules information, determine the target authorization permission information; The target access subject information and the target authorization permission information are input into the access control model, and the access control result is output.
5. The method according to claim 1, further comprising: If the access control result allows access, the target transaction data is encrypted using an encryption algorithm to obtain encrypted target transaction data. Send encrypted data of the first target transaction to the first terminal; Receive the second target transaction encrypted data fed back by the first terminal, wherein the second target transaction encrypted data includes the first target transaction encrypted data and the key information of the first terminal; Send the second target transaction encrypted data to the second terminal.
6. The method according to claim 1, further comprising: Based on the identifier of the second terminal, data transmission condition information is determined, wherein the data transmission condition information includes format condition information and quantity condition information; Based on the format condition information and the quantity condition information, the target transaction data is converted into a target data file; The target data file is sent to the second terminal based on the identifier of the second terminal.
7. A request-response device, comprising: The acquisition module is used to respond to a transaction request initiated by the first terminal to conduct a transaction with the second terminal, and to acquire transaction request information and transaction environment information. The transaction request information includes the identification information of the first terminal, the transaction rule information, and the identification information of the second terminal; A generation module is configured to determine a first credibility of the transaction request information by calculating a first information entropy; the first credibility is the average of the information entropies corresponding to multiple data points in the transaction request information; determine a second credibility of the transaction environment information by calculating a second information entropy; the second credibility is the average of the information entropies of multiple data points in the transaction environment information; and generate the credibility of the transaction request based on the first credibility and the second credibility; the credibility of the transaction request is a vector composed of the first credibility and the second credibility. The access control module is used to input the identification information of the first terminal and the transaction rule information into the access control model and output the access control result, wherein the access control result indicates whether the transaction rule information meets the access control conditions of the first terminal. The first determining module is configured to determine target transaction data from the transaction request based on the credibility and the access control result, wherein the target transaction data represents valid data for executing the transaction; as well as The first sending module is used to send the target transaction data to the second terminal according to the identification information of the second terminal.
8. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 6.
10. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Payment method, server, user terminal, system and storage medium
CN112669042A
Location-based verification method and system for predicting user trustworthiness
CN113168633A