Financial service processing method and apparatus, storage medium, and electronic device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-07
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]本申请的主要目的在于提供一种金融业务的处理方法及装置、存储介质和电子设备,以解决相关技术中采用移动设备进行生物特征验证容易被计算机恶意程序入侵,导致办理金融业务的安全性比较低的问题
[0023]This application employs the following steps: The target device receives a request for processing a target financial transaction initiated by a target object, and sends the request to an encryption server. The request includes at least the target device's ID, the request for processing the target financial transaction, and a timestamp. The encryption server processes the request to obtain first data information, which is then returned to the target device. This first data information is encrypted and includes at least the first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least the total number N of biometric features to be collected corresponding to the target financial transaction and the second sequence numbers of N quantum random numbers, where N is a positive integer greater than or equal to 1. The target device verifies the biometric features of the target object based on the first data information, obtains a first verification result, and if the first verification result indicates that the verification is successful, the target device sends second data information to the encryption server. The second data information is encrypted and includes at least: a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The encryption server verifies the second data information to obtain a second verification result, and if the second verification result indicates that the verification is successful, the target device handles the target financial transaction. This solves the problem in related technologies where biometric verification using mobile devices is easily compromised by malicious computer programs, resulting in low security for financial transactions. In this application, a target device receives a request for a financial transaction initiated by a target object, sends the request to an encryption server, processes the request to obtain first data information, and sends the first data information to the target device. The target device verifies the target object's biometrics based on the first data information, obtains a first verification result, and if the first verification result indicates successful verification, sends second data information to the encryption server. The encryption server verifies the second data information and sends the second verification result to the target device. If the second verification result indicates successful verification, the target device processes the financial transaction. By performing multiple verifications on the data between the target device and the encryption server, and by encrypting the data transmission between the target device and the encryption server multiple times using quantum random numbers, the reliability of the biometric verification result is ensured, thereby improving the security of financial transactions.
Smart Images

Figure CN116781276B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of financial technology, and more specifically, to a method and apparatus for processing financial transactions, a storage medium, and an electronic device. Background Technology
[0002] In today's information age, accurately identifying an individual and protecting information security has become a critical social issue that must be addressed. Traditional identity authentication methods, due to their susceptibility to forgery and loss, are increasingly failing to meet societal needs. Currently, the most convenient and secure solution is undoubtedly biometric identification technology. Biometric identification technology refers to a technology that uses human biometric characteristics for identity authentication. Specifically, biometric identification technology closely integrates computer science with high-tech methods such as optics, acoustics, biosensors, and biostatistics principles to identify individuals using their inherent physiological and behavioral characteristics. When using biometric identification technology to verify personal identity, the security of individual biometric data is paramount. Once biometric data is leaked, it can cause irreparable damage, as individual biometric characteristics are unique and cannot be altered. Examples include fingerprints, facial images, and iris scans. Therefore, when conducting financial transactions, users are often unwilling to store their biometric information on non-private public devices, such as financial institution servers, nor do they want their biometric data collected or verified on non-private devices, such as through workplace cameras. To address user concerns about the leakage of personal biometric information, financial institutions typically initiate identity verification requests to users' private mobile devices during financial transactions. The devices then perform biometric verification, and the verification results are transmitted back to the financial institution, which accepts the results and processes the transaction. However, if malicious programs compromise the mobile devices during the biometric data collection and verification process, the verification results received by the financial institution may not be genuine. For example, after the financial institution initiates an identity verification request, the mobile device collects and verifies the user's biometrics, resulting in a failed verification. However, if a malicious program then compromises the mobile device and replaces the verification result with a successful one, the financial institution will process the transaction upon receiving this maliciously altered result, posing a significant security risk to financial transactions.
[0003] There is currently no effective solution to the problem that using mobile devices for biometric verification in related technologies is vulnerable to intrusion by malicious computer programs, resulting in low security for financial transactions. Summary of the Invention
[0004] The main objective of this application is to provide a method, apparatus, storage medium, and electronic device for processing financial transactions, in order to solve the problem that the use of mobile devices for biometric verification in related technologies is easily invaded by malicious computer programs, resulting in low security for handling financial transactions.
[0005] To achieve the above objectives, according to one aspect of this application, a method for processing financial transactions is provided. The method includes: receiving, via a target device, a processing request information for a target financial transaction initiated by a target object, and sending the processing request information to an encryption server, wherein the processing request information includes at least: the ID of the target device, the processing request for the target financial transaction, and timestamp information; processing the processing request information via the encryption server to obtain first data information, and returning the first data information to the target device, wherein the first data information is encrypted data information, and the first data information includes at least: a first sequence number of at least one quantum random number and an authentication message, wherein the authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial transaction and a second sequence number of N quantum random numbers. The column number, where N is a positive integer greater than or equal to 1; the target device verifies the biometrics of the target object based on the first data information to obtain a first verification result, and if the first verification result indicates that the verification is successful, the target device sends second data information to the encryption server, wherein the second data information is encrypted data information, and the second data information includes at least: a third sequence number of at least one quantum random number and a verification result message, the verification result message including at least the first verification result; the encryption server verifies the second data information to obtain a second verification result, and if the second verification result indicates that the verification is successful, the target financial business is processed through the target device.
[0006] Furthermore, before processing the processing request information through the encryption server to obtain the first data information, the method further includes: generating multiple quantum random numbers through a quantum random number generator, assigning a sequence number to each quantum random number, storing the multiple quantum random numbers and the sequence number of each quantum random number in the target device; and storing the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in the encryption server.
[0007] Further, the first data information is obtained by processing the processing request information through the encryption server, including: verifying the processing request information, and if the processing request information is verified, randomly selecting at least one quantum random number as a first sequence number; determining the total number N of the biometric features to be collected corresponding to the target financial business and the second sequence number of the N quantum random numbers, wherein the second sequence number of the N quantum random numbers is any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; encrypting the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the authentication message; and encrypting the authentication message and the first sequence number of the at least one quantum random number according to a preset transmission key to obtain the first data information.
[0008] Further, the verification of the biometrics of the target object by the target device based on the first data information to obtain the first verification result includes: decrypting the first data information according to a preset transmission key to obtain the first sequence number of the at least one quantum random number and the authentication message; decrypting the authentication message according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the total number N of the biometrics to be collected and the second sequence number of the N quantum random numbers; collecting the biometrics of the target object according to the total number N of the biometrics to be collected and the second sequence number of the N quantum random numbers to obtain N biometrics; and performing authentication based on the N biometrics to obtain the first verification result.
[0009] Furthermore, before sending the second data information to the encryption server through the target device after the first verification result indicates that the verification has passed, the method further includes: determining the third sequence number of the at least one quantum random number from the second sequence numbers of the N quantum random numbers, and performing an encryption operation on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to the target algorithm to obtain a first operation result; encrypting the first verification result and the first operation result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the verification result message; and encrypting the verification result message and the third sequence number of the at least one quantum random number according to a preset transmission key to obtain the second data information.
[0010] Further, verifying the second data information through the encryption server to obtain a second verification result includes: decrypting the second data information according to a preset transmission key to obtain the verification result message and the third sequence number of the at least one quantum random number; processing the third sequence number of the at least one quantum random number according to the second sequence number of the N quantum random numbers to obtain a second operation result; decrypting the verification result message according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the first verification result and the first operation result; and verifying the first operation result according to the second operation result to obtain the second verification result.
[0011] Further, processing the third sequence number of the at least one quantum random number based on the second sequence number of the N quantum random numbers to obtain the second operation result includes: determining whether the third sequence number of the at least one quantum random number exists among the second sequence numbers of the N quantum random numbers, and obtaining a determination result; if the determination result indicates that the third sequence number of the at least one quantum random number exists among the second sequence numbers of the N quantum random numbers, determining the quantum random number corresponding to the third sequence number based on the third sequence number of the at least one quantum random number; and performing encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm to obtain the second operation result.
[0012] To achieve the above objectives, according to another aspect of this application, a financial transaction processing system is also provided. The system includes: a target device, configured to receive a request for processing a target financial transaction initiated by a target object, send the request information to an encryption server, receive first data information returned by the encryption server, verify the biometric features of the target object based on the first data information to obtain a first verification result, send second data information to the encryption server if the first verification result indicates successful verification, and process the target financial transaction if the second verification result indicates successful verification, wherein the first data information is first data information obtained by the encryption server processing the request information, and the second data information is data information obtained by the target device based on the first verification result; the encryption server is configured to process the request information to obtain the first data information, send the first data information to the target device, receive the second data information returned by the target device, verify the second data information, and obtain a second verification result.
[0013] Furthermore, the financial transaction processing system also includes a quantum random number generator, used to generate multiple quantum random numbers, and store the multiple quantum random numbers and the sequence number of each quantum random number in the target device and the encryption server.
[0014] To achieve the above objectives, according to another aspect of this application, a financial transaction processing apparatus is provided. The apparatus includes: a sending unit, configured to receive a processing request information for a target financial transaction initiated by a target object through a target device, and send the processing request information to an encryption server, wherein the processing request information includes at least: the ID of the target device, the processing request for the target financial transaction, and timestamp information; and a processing unit, configured to process the processing request information through the encryption server to obtain first data information, and return the first data information to the target device, wherein the first data information is encrypted data information, and the first data information includes at least: a first sequence number of at least one quantum random number and an authentication message, wherein the authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial transaction and a second sequence number of N quantum random numbers. Where N is a positive integer greater than or equal to 1; a first verification unit is used to verify the biometrics of the target object based on the first data information through the target device, obtain a first verification result, and send second data information to the encryption server through the target device if the first verification result indicates that the verification is successful, wherein the second data information is encrypted data information, and the second data information includes at least: a third sequence number of at least one quantum random number and a verification result message, wherein the verification result message includes at least the first verification result; a second verification unit is used to verify the second data information through the encryption server, obtain a second verification result, and process the target financial business through the target device if the second verification result indicates that the verification is successful.
[0015] Furthermore, the device further includes: a first storage unit for generating multiple quantum random numbers through a quantum random number generator, assigning a sequence number to each quantum random number, and storing the multiple quantum random numbers and the sequence number of each quantum random number in the target device; and a second storage unit for storing the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in the encryption server.
[0016] Further, the processing unit includes: a first verification module, used to verify the processing request information, and, if the processing request information is verified as passed, randomly select at least one first sequence number of a quantum random number; a determination module, used to determine the total number N of the biometric features to be collected corresponding to the target financial business and the second sequence number of the N quantum random numbers, wherein the second sequence number of the N quantum random numbers is any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; a first encryption module, used to encrypt the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers according to the quantum random number corresponding to the first sequence number of the at least one quantum random number, to obtain the authentication message; and a second encryption module, used to encrypt the authentication message and the first sequence number of the at least one quantum random number according to a preset transmission key, to obtain the first data information.
[0017] Further, the first verification unit includes: a first decryption module, used to decrypt the first data information according to a preset transmission key to obtain a first sequence number of the at least one quantum random number and the authentication message; a second decryption module, used to decrypt the authentication message according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers; a collection module, used to collect the biometric features of the target object according to the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers to obtain N biometric features; and a second verification module, used to verify the identity based on the N biometric features to obtain the first verification result.
[0018] Furthermore, the device further includes: a computation unit, configured to determine the third sequence number of the at least one quantum random number from the second sequence numbers of the N quantum random numbers, and perform encryption computation on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to a target algorithm to obtain a first computation result; a first encryption unit, configured to encrypt the first verification result and the first computation result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the verification result message; and a second encryption unit, configured to encrypt the verification result message and the third sequence number of the at least one quantum random number according to a preset transmission key to obtain the second data information.
[0019] Further, the second verification unit includes: a third decryption module, used to decrypt the second data information according to a preset transmission key to obtain the verification result message and the third sequence number of the at least one quantum random number; a calculation module, used to process the third sequence number of the at least one quantum random number according to the second sequence number of the N quantum random numbers to obtain a second calculation result; a fourth decryption module, used to decrypt the verification result message according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the first verification result and the first calculation result; and a third verification module, used to verify the first calculation result according to the second calculation result to obtain the second verification result.
[0020] Further, the operation module includes: a judgment submodule, used to judge whether there is a third sequence number of at least one quantum random number among the second sequence numbers of the N quantum random numbers, and obtain a judgment result; a determination submodule, used to determine the quantum random number corresponding to the third sequence number based on the third sequence number of the at least one quantum random number when the judgment result indicates that there is a third sequence number of the at least one quantum random number among the second sequence numbers of the N quantum random numbers; and an operation submodule, used to perform encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm, and obtain a second operation result.
[0021] According to another aspect of the present invention, a computer-readable storage medium is also provided, which stores a computer program, wherein the computer program controls the device where the computer-readable storage medium is located to perform the financial business processing method described above when it is running.
[0022] To achieve the above objectives, according to one aspect of this application, an electronic device is provided, comprising one or more processors and a memory, the memory being used to store the processing method of the financial business implemented by the one or more processors as described above.
[0023] This application employs the following steps: The target device receives a request for processing a target financial transaction initiated by a target object, and sends the request to an encryption server. The request includes at least the target device's ID, the request for processing the target financial transaction, and a timestamp. The encryption server processes the request to obtain first data information, which is then returned to the target device. This first data information is encrypted and includes at least the first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least the total number N of biometric features to be collected corresponding to the target financial transaction and the second sequence numbers of N quantum random numbers, where N is a positive integer greater than or equal to 1. The target device verifies the biometric features of the target object based on the first data information, obtains a first verification result, and if the first verification result indicates that the verification is successful, the target device sends second data information to the encryption server. The second data information is encrypted and includes at least: a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The encryption server verifies the second data information to obtain a second verification result, and if the second verification result indicates that the verification is successful, the target device handles the target financial transaction. This solves the problem in related technologies where biometric verification using mobile devices is easily compromised by malicious computer programs, resulting in low security for financial transactions. In this application, a target device receives a request for a financial transaction initiated by a target object, sends the request to an encryption server, processes the request to obtain first data information, and sends the first data information to the target device. The target device verifies the target object's biometrics based on the first data information, obtains a first verification result, and if the first verification result indicates successful verification, sends second data information to the encryption server. The encryption server verifies the second data information and sends the second verification result to the target device. If the second verification result indicates successful verification, the target device processes the financial transaction. By performing multiple verifications on the data between the target device and the encryption server, and by encrypting the data transmission between the target device and the encryption server multiple times using quantum random numbers, the reliability of the biometric verification result is ensured, thereby improving the security of financial transactions. Attached Figure Description
[0024] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:
[0025] Figure 1This is a flowchart of a financial transaction processing method provided according to an embodiment of this application;
[0026] Figure 2 This is a schematic diagram of a financial transaction processing system provided according to an embodiment of this application;
[0027] Figure 3 This is a flowchart of a financial transaction processing method provided according to an embodiment of this application. Figure 1 ;
[0028] Figure 4 This is a schematic diagram of a financial transaction processing system provided according to an embodiment of this application;
[0029] Figure 5 This is a schematic diagram of a financial transaction processing apparatus provided according to an embodiment of this application;
[0030] Figure 6 This is a schematic diagram of an electronic device provided according to an embodiment of this application. Detailed Implementation
[0031] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0032] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0033] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0034] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties. For example, this system has an interface with the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving consent from the aforementioned user or organization.
[0035] The present invention will now be described in conjunction with preferred implementation steps. Figure 1 This is a flowchart of a financial transaction processing method provided according to an embodiment of this application, such as... Figure 1 As shown, the method includes the following steps:
[0036] Step S101: Receive the processing request information of the target financial business initiated by the target object through the target device, and send the processing request information to the encryption server. The processing request information includes at least: the ID of the target device, the processing request of the target financial business, and timestamp information.
[0037] For example, the target device receives the processing request information of the target financial business initiated by the target object. After receiving the processing request information of the target financial business, it encrypts the processing request and timestamp information of the target financial business according to the pre-set transmission key, packages the encrypted processing request and timestamp information of the target financial business and the ID of the target device into processing request information, and sends the processing request information to the encryption server.
[0038] Step S102: The processing request information is processed by the encryption server to obtain the first data information, and the first data information is returned to the target device. The first data information is encrypted data information and includes at least: the first sequence number of at least one quantum random number and the authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1.
[0039] For example, the request information is processed by an encryption server. After processing, the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers are obtained. For example, biometric features can be human faces, fingerprints, irises, and palm veins. An authentication message is obtained based on the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers. Then, the first sequence number of at least one quantum random number and the authentication message are encrypted according to the pre-set transmission key to obtain the encrypted first data information.
[0040] Step S103: The target device verifies the biometrics of the target object based on the first data information to obtain a first verification result. If the first verification result indicates that the verification is successful, the target device sends second data information to the encryption server. The second data information is encrypted data information and includes at least: a third sequence number of at least one quantum random number and a verification result message. The verification result message includes at least the first verification result.
[0041] For example, the target device verifies the biometrics of the target object based on the first data information and obtains a first verification result. If the first verification result indicates that the biometrics of the target object has been verified, the verification result message including the first verification result and a third sequence number of at least one quantum random number are encrypted according to the pre-set transmission key to obtain the second data information. The target device then sends the second data information to the encryption server.
[0042] Step S104: The second data information is verified by the encryption server to obtain the second verification result. If the second verification result indicates that the verification is successful, the target financial business is processed through the target device.
[0043] For example, the authenticity of the second data information is verified by an encryption server to obtain a second verification result. If the second verification result indicates that the verification is successful, it means that the biometric verification of the target object is successful and the biometric verification result is also reliable. Therefore, the target financial business can be handled through the target device.
[0044] In summary, this application involves receiving a request for a financial transaction initiated by a target object through a target device, sending the request to an encryption server, processing the request to obtain first data information, and then sending the first data information back to the target device. The target device verifies the target object's biometrics based on the first data information, obtains a first verification result, and sends second data information to the encryption server if the first verification result indicates successful verification. The encryption server verifies the second data information and sends the second verification result back to the target device. If the second verification result indicates successful verification, the target device processes the financial transaction. By performing multiple verifications on the data between the target device and the encryption server, and by encrypting the data transmission between the target device and the encryption server multiple times using quantum random numbers, the reliability of the biometric verification result is ensured, thereby improving the security of financial transactions.
[0045] Optionally, in the financial business processing method provided in this application embodiment, before processing the processing request information through the encryption server to obtain the first data information, the method further includes: generating multiple quantum random numbers through a quantum random number generator, assigning a sequence number to each quantum random number, storing the multiple quantum random numbers and the sequence number of each quantum random number in the target device; and storing the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in the encryption server.
[0046] For example, multiple quantum random numbers are generated using a quantum random number generator, and a sequence number is assigned to each quantum random number. These multiple quantum random numbers and their sequence numbers are then written into the target device. For instance, depending on the different financial business processing requirements, up to 1000 facial features may need to be collected. In this case, 1000 quantum random numbers and their sequence numbers need to be written into the target device. Then, the ID of the target device, along with the multiple quantum random numbers and their sequence numbers stored in the target device, are written into an encryption server. This ensures that the encryption server can accurately locate the multiple quantum random numbers and their sequence numbers stored in the target device based on its ID.
[0047] By pre-writing multiple quantum random numbers and the sequence number of each quantum random number into the target device and the encryption server, an encryption basis is provided for the information transmission between the target device and the encryption server. Due to the uncertainty and unpredictability of quantum random numbers, encrypting the information transmission between the target device and the encryption server using quantum random numbers improves the security of the information transmission between the target device and the encryption server.
[0048] In an alternative embodiment, such as Figure 2 As shown, the financial business processing system may further include: a quantum random number generator 20, an encryption server 21, an encryption terminal 22, a target device 23, and an encryption machine 24. The quantum random number generator 20 is used to generate multiple quantum random numbers, the encryption server 21 is used to transmit and process multiple quantum random numbers, the encryption terminal 22 is used to write the multiple quantum random numbers processed by the encryption server 21 to the target device 23, the target device 23 is used to store the multiple quantum random numbers processed by the encryption server 21, and the encryption machine 24 is used to store the ID of the target device 23 and the corresponding multiple quantum random numbers processed by the encryption server 21 stored in the target device 23.
[0049] pass Figure 2The financial business processing system shown implements the storage of quantum random numbers as follows: Quantum random number generator 20 generates multiple quantum random numbers, and the encryption server 21 assigns sequence numbers to the multiple quantum random numbers to obtain the sequence number of each quantum random number. The encryption terminal 22 communicates with the encryption server 21 to write the multiple quantum random numbers and the sequence number of each quantum random number into the target device 23. Then, the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device 23 are transmitted to the encryption server 21. The encryption server 21 stores the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device 23 into the encryption machine 24 connected to the encryption server 21.
[0050] In an optional embodiment, the financial transaction processing system may further include: a quantum random number generator, an encryption server, an encryption terminal, and a target device. The encryption generator is integrated into the encryption server, which stores the ID of the target device and multiple quantum random numbers in the target device, as well as the sequence number of each quantum random number.
[0051] It should be noted that after storing multiple quantum random numbers and the sequence number of each quantum random number in the target device, the target device is issued to the target object. Before activating the target device, the target object needs to register multiple biometric features in the target device. The multiple biometric features stored in the target device are used to verify the identity of the target object when conducting financial transactions.
[0052] Optionally, in the financial transaction processing method provided in this application embodiment, processing the transaction request information through an encryption server to obtain the first data information includes: verifying the transaction request information, and if the transaction request information is verified, randomly selecting at least one quantum random number as the first sequence number; determining the total number N of biometric features to be collected corresponding to the target financial transaction and the second sequence number of the N quantum random numbers, wherein the second sequence number of the N quantum random numbers is any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; encrypting the total number N of biometric features to be collected and the second sequence number of the N quantum random numbers according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain an authentication message; and encrypting the authentication message and the first sequence number of the at least one quantum random number according to a preset transmission key to obtain the first data information.
[0053] For example, the encryption server calls the transmission key corresponding to the target device ID to decrypt the encrypted request and timestamp information of the target financial business. After verifying that the request and timestamp information of the target financial business are correct, at least one quantum random number is randomly selected from the sequence numbers of multiple stored quantum random numbers. Based on the business category of the target financial business, it is determined that multiple biometric features are required when processing the target financial business, that is, the total number N of biometric features to be collected corresponding to the target financial business is determined above. Then, N quantum random numbers are randomly selected as second sequence numbers. The total number N of biometric features to be collected and the N quantum random numbers are encrypted according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain authentication message. Then, the authentication message and the first sequence number of the selected at least one quantum random number are encrypted according to the preset transmission key to obtain the first data information.
[0054] It should be noted that if the verification of the processing request and timestamp information for the target financial service fails, it indicates that the processing request information is incorrect and the target financial service cannot be processed. Therefore, the processing process for the target financial service will be exited, and the processing request for the target financial service needs to be re-initiated.
[0055] By encrypting the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers, an authentication message is obtained. Then, the authentication message and the first sequence number of at least one quantum random number are encrypted. Through two encryptions, the security of the first data information is guaranteed.
[0056] Optionally, in the financial business processing method provided in this application embodiment, the first verification result is obtained by verifying the biometrics of the target object based on the first data information by the target device. This includes: decrypting the first data information according to a preset transmission key to obtain a first serial number of at least one quantum random number and an authentication message; decrypting the authentication message according to the quantum random number corresponding to the first serial number of at least one quantum random number to obtain the total number N of biometrics to be collected and the second serial number of N quantum random numbers; collecting the biometrics of the target object according to the total number N of biometrics to be collected and the second serial number of N quantum random numbers to obtain N biometrics; and verifying the identity based on the N biometrics to obtain the first verification result.
[0057] For example, firstly, the first data information is decrypted according to a preset transmission key to obtain the first sequence number of at least one quantum random number in the first data information and the authentication message. Then, the authentication message is decrypted according to the quantum random number corresponding to the first sequence number of the preset at least one quantum random number to obtain the total number N of biometric features to be collected and the second sequence number of N quantum random numbers. Then, the biometric features of the target object are collected according to the second sequence number of N quantum random numbers to obtain N biometric features corresponding to the second sequence number of N quantum random numbers. The obtained N biometric features are verified with multiple biometric features stored in the target device to obtain the first verification result.
[0058] The target device collects the biometric features of the target object based on the first data information, and verifies the collected biometric features to obtain the first verification result. This achieves the identity verification of the target object initiating the target financial business and ensures the security of the financial business.
[0059] Optionally, in the financial business processing method provided in this application embodiment, before sending the second data information to the encryption server through the target device when the first verification result indicates that the verification is passed, the method further includes: determining the third sequence number of at least one quantum random number from the second sequence numbers of N quantum random numbers, and performing encryption operation on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to the target algorithm to obtain a first operation result; encrypting the first verification result and the first operation result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain a verification result message; and encrypting the verification result message and the third sequence number of the at least one quantum random number according to the preset transmission key to obtain the second data information.
[0060] For example, if the first verification result is successful, at least one third sequence number of a quantum random number is randomly selected from the second sequence numbers of N quantum random numbers. The quantum random number corresponding to the third sequence number of the at least one quantum random number is encrypted according to the target algorithm to obtain the first encryption result. For example, the target algorithm can be a summation algorithm used to sum the selected quantum random numbers. The first verification result and the first operation result are encrypted according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain a verification result message. Then, the verification result message and the third sequence number of the at least one quantum random number are encrypted according to the preset transmission key to obtain the encrypted second data information.
[0061] It should be noted that if the first verification fails, meaning that the biometrics of the target object collected are different from the biometrics pre-stored in the target device, the target device will prompt the target object to re-identify or exit the target financial transaction process.
[0062] By performing operations on the stored non-repeatable quantum random numbers, a first operation result is obtained. The first operation result and the first verification result are then encrypted to obtain a verification result message. The verification result message and the third sequence number of at least one quantum random number are then encrypted using a transmission key to obtain encrypted second data information. By encrypting the first verification result and the first operation result twice, the security of biometric verification is ensured.
[0063] Optionally, in the financial transaction processing method provided in this application embodiment, verifying the second data information through an encryption server to obtain a second verification result includes: decrypting the second data information according to a preset transmission key to obtain a verification result message and a third sequence number of at least one quantum random number; processing the third sequence number of at least one quantum random number according to the second sequence number of N quantum random numbers to obtain a second operation result; decrypting the verification result message according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain a first verification result and a first operation result; and verifying the first operation result according to the second operation result to obtain a second verification result.
[0064] For example, the second data information is decrypted according to the preset transmission key to obtain the verification result message and the third sequence number of at least one quantum random number. Then, the third sequence number of at least one quantum random number is processed according to the second sequence number of N quantum random numbers to obtain the second operation result. Then, the verification result message is decrypted according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain the first verification result and the first operation result in the verification result message. The first operation result and the second operation result are verified to obtain the second verification result.
[0065] By processing the second data information, a second calculation result is obtained. The first calculation result is then verified based on the second calculation result to obtain a second verification result. Subsequently, the decision on whether to proceed with the target financial transaction is made based on the second verification result, thus ensuring the security of the target financial transaction data.
[0066] Optionally, in the financial business processing method provided in this application embodiment, processing the third sequence number of at least one quantum random number based on the second sequence number of N quantum random numbers to obtain a second operation result includes: determining whether there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, and obtaining a determination result; if the determination result indicates that there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, determining the quantum random number corresponding to the third sequence number based on the third sequence number of at least one quantum random number; and performing encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm to obtain the second operation result.
[0067] For example, first determine whether there is at least one third sequence number of a quantum random number among the second sequence numbers of N quantum random numbers. If the result indicates that at least one third sequence number of a quantum random number is not present in all the second sequence numbers of N quantum random numbers, it means that the identity verification of the target object has failed. Then the target device will prompt the target object to re-identify or exit the target financial business processing procedure.
[0068] If the judgment result indicates that the third sequence number of at least one quantum random number exists in the second sequence number of N quantum random numbers, then determine the quantum random number corresponding to the third sequence number of at least one quantum random number, and then perform encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm to obtain the second operation result.
[0069] By performing encryption operations on the quantum random number corresponding to the third sequence number of at least one quantum random number, a second operation result is obtained. The first operation result is then verified based on the second operation result to obtain a second verification result. The first and second operation results are obtained by operating on the same quantum random number using the same algorithm. However, the first operation result is obtained in the target device, while the second operation result is obtained in the encryption server. Verifying whether the second and first operation results are the same can determine the accuracy of the first operation result during transmission between the target device and the encryption server, thereby ensuring the reliability of the biometric verification result.
[0070] In an optional embodiment, the target device may be a mobile client, such as a mobile phone. The mobile client has a built-in identity verification device specifically designed for financial institutions. The mobile client receives financial transactions initiated by the target object, and the built-in identity verification device performs biometric verification of the target object.
[0071] In an optional embodiment, the target device may consist of a mobile client and a dedicated device of a financial institution. The dedicated device is equipped with a security chip that stores a transmission key, multiple biometric features of the target object, multiple random numbers, and a serial number for each quantum random number. The dedicated device can communicate with the mobile client through hardware or software connection. The mobile client receives financial transaction requests initiated by the target object and collects the target object's biometric features according to the transaction requests. Then, the dedicated device verifies the target object's biometric features.
[0072] In an alternative embodiment, the following can be employed: Figure 3 The method shown enables the processing of financial transactions. The specific steps are as follows:
[0073] Step S301: The user (target object) selects the target financial service to be processed on the mobile client, enters the relevant information of the target financial service, and initiates an identity verification request.
[0074] Step S302: Detect whether the mobile client is connected to the dedicated device. If the mobile client is not connected to the dedicated device, remind the user to connect to the dedicated device or exit the target financial transaction.
[0075] In step S303, if the mobile client is connected to the dedicated device, the timestamp information and the target financial business processing request are encrypted according to the preset transmission key. The mobile client then packages the dedicated device ID, the encrypted timestamp information, and the target financial business processing request into financial business request information and uploads the financial business request information to the encryption server.
[0076] Step S304: The encryption server uses the ID of the dedicated device to call the corresponding transmission key to decrypt the encrypted timestamp information and the target financial transaction request. After verifying that the timestamp information and the target financial transaction request are correct, it encrypts the data using the preset transmission key to obtain an encrypted message, which is the first data information mentioned above. The encrypted message includes:
[0077] 1. A sequence number of one or more quantum random numbers.
[0078] 2. Using the quantum random number corresponding to the sequence number of one or more of the aforementioned quantum random numbers as the working key, the facial recognition request message is encrypted. The facial recognition request message is equivalent to the aforementioned authentication message, and includes:
[0079] (1) The number of biometric features to be called is determined according to the financial business category, for example, 100 (the number of biometric features to be verified is determined according to the security requirements of different business types. The specific number can fluctuate randomly within a certain range. For example, 100-130 biometric features need to be verified for a transfer of less than 100 yuan. Then, a value can be randomly selected between 100 and 130 each time).
[0080] (2) 100 serial numbers, which can be randomly selected from the serial numbers of multiple quantum random numbers stored in the encryption server.
[0081] (3) Request for facial recognition.
[0082] In step S305, the encrypted message is sent to the mobile client, and the mobile client uses the transmission key in the security chip of the dedicated device to decrypt the encrypted message.
[0083] In step S306, based on the content of the decrypted encrypted message, the dedicated device security chip calls the sequence number of one or more quantum random numbers in the decrypted encrypted message (i.e., the sequence number of one or more quantum random numbers determined in point 1 of step S304) as the working key to decrypt the human image request message.
[0084] Step S307: Based on the decrypted image request message, the mobile client initiates biometric collection, collects 100 biometric features corresponding to the sequence number of 100 quantum random numbers, and sends these 100 biometric features to a dedicated device for identity verification, obtains the first verification result, and determines whether the first verification result is successful. If the first verification result is unsuccessful, the mobile client prompts that the verification has failed, and the user must re-identify or exit the target financial transaction.
[0085] Step S308: If the first verification result passes, one or more quantum random number sequences are randomly selected from the sequence numbers of the 100 quantum random numbers, and the corresponding quantum random number is determined according to the selected sequence numbers. Then, the determined quantum random number is operated on according to the preset algorithm to obtain the first operation result.
[0086] In step S309, after obtaining the first calculation result, the working key determined in point 2 of step S304 is used to encrypt the first calculation result and the first verification result to obtain an authentication message. Then, the authentication message and the sequence number of one or more quantum random numbers selected in step S308 are encrypted according to the preset transmission key, and the encrypted message (second data information) is transmitted to the encryption server.
[0087] In step S310, after the encryption server decrypts the encrypted message using the preset transmission key, it first determines whether the sequence number (third sequence number) of one or more quantum random numbers selected in step S308 is within the range of the sequence numbers (second sequence number) of 100 quantum random numbers required in point (2) of step S304. If the sequence number of one or more quantum random numbers selected in step S308 is not within the range of the sequence numbers of 100 quantum random numbers required in point (2) of step S304, the user authentication fails, and the user is prompted to re-authenticate or exit the target financial business.
[0088] Step S311: If the sequence number of one or more quantum random numbers selected in step S308 is within the range of the sequence numbers of 100 quantum random numbers required in point (2) of step S304, then the corresponding quantum random number is determined according to the sequence number of one or more quantum random numbers selected in step S308, and then the preset algorithm is used to operate on the determined quantum random number to obtain the second operation result.
[0089] Step S312: Use the working key pair to verify whether the first operation result and the second operation result are the same. If the first operation result and the second operation result are the same, it means that the user's identity verification is successful and the target financial business can be processed. If the first operation result and the second operation result are different, it means that the user's identity verification fails and the user is prompted to re-authenticate or exit the processing of the target financial business.
[0090] The financial transaction processing method provided in this application embodiment receives a target financial transaction processing request information initiated by a target object through a target device, and sends the processing request information to an encryption server. The processing request information includes at least: the ID of the target device, the processing request of the target financial transaction, and timestamp information. The encryption server processes the processing request information to obtain first data information, and returns the first data information to the target device. The first data information is encrypted data information, and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial transaction and the second sequence numbers of N quantum random numbers, where N is a positive integer greater than or equal to 1. The target device verifies the biometrics of the target object based on the first data information to obtain a first verification result. If the first verification result indicates successful verification, the target device sends second data information to the encryption server. The second data information is encrypted and includes at least a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The encryption server verifies the second data information to obtain a second verification result. If the second verification result indicates successful verification, the target device processes the target financial transaction. This solves the problem in related technologies where biometric verification using mobile devices is easily compromised by malicious computer programs, leading to low security in financial transactions. In this application, a target device receives a request for a financial transaction initiated by a target object, sends the request to an encryption server, processes the request to obtain first data information, and then sends the first data information back to the target device. The target device verifies the target object's biometrics based on the first data information, obtains a first verification result, and if the first verification result indicates successful verification, sends second data information to the encryption server. The encryption server verifies the second data information and sends the second verification result back to the target device. If the second verification result indicates successful verification, the target device processes the financial transaction. By performing multiple verifications on the data between the target device and the encryption server, and by encrypting the data transmission between the target device and the encryption server multiple times using quantum random numbers, the reliability of the biometric verification result is ensured, thereby improving the security of financial transactions.
[0091] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0092] This application also provides a financial transaction processing system. It should be noted that the financial transaction processing system of this application can be used to execute the financial transaction processing method provided in this application. The following describes the financial transaction processing system provided in this application.
[0093] Figure 4 This is a schematic diagram of a financial transaction processing system according to an embodiment of this application. Figure 4 As shown, the system includes: a target device 41, an encryption server 42, and a quantum random number generator 43.
[0094] The target device 41 is used to receive a request for processing a target financial transaction initiated by a target object, send the request for processing to an encryption server, receive first data information returned by the encryption server, verify the biometric features of the target object based on the first data information to obtain a first verification result, send second data information to the encryption server if the first verification result indicates that the verification is successful, and process the target financial transaction if the second verification result indicates that the verification is successful. The first data information is the first data information obtained by the encryption server processing the request for processing, and the second data information is the data information obtained by the target device based on the first verification result.
[0095] The encryption server 42 is used to process the request information to obtain first data information, send the first data information to the target device, receive the second data information returned by the target device, verify the second data information, and obtain a second verification result.
[0096] A quantum random number generator 43 is used to generate multiple quantum random numbers and store the multiple quantum random numbers and the sequence number of each quantum random number in the target device and the encryption server.
[0097] This application also provides a financial transaction processing apparatus. It should be noted that the financial transaction processing apparatus of this application can be used to execute the financial transaction processing method provided in this application. The following describes the financial transaction processing apparatus provided in this application.
[0098] Figure 5 This is a schematic diagram of a financial transaction processing apparatus according to an embodiment of this application. Figure 5As shown, the device includes: a sending unit 501, a processing unit 502, a first verification unit 503, and a second verification unit 504.
[0099] The sending unit 501 is used to receive the processing request information of the target financial business initiated by the target object through the target device, and send the processing request information to the encryption server. The processing request information includes at least: the ID of the target device, the processing request of the target financial business, and timestamp information.
[0100] The processing unit 502 is used to process the processing request information through an encrypted server to obtain first data information and return the first data information to the target device. The first data information is encrypted data information and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1.
[0101] The first verification unit 503 is used to verify the biometrics of the target object based on the first data information through the target device, obtain the first verification result, and send the second data information to the encryption server through the target device when the first verification result indicates that the verification is successful. The second data information is encrypted data information and includes at least: the third sequence number of at least one quantum random number and the verification result message. The verification result message includes at least the first verification result.
[0102] The second verification unit 504 is used to verify the second data information through the encryption server, obtain the second verification result, and, if the second verification result indicates that the verification is successful, to process the target financial business through the target device.
[0103] The financial transaction processing apparatus provided in this application embodiment receives a target financial transaction processing request information initiated by a target object through a target device via a sending unit 501, and sends the processing request information to an encryption server. The processing request information includes at least: the ID of the target device, the processing request of the target financial transaction, and timestamp information. The processing unit 502 processes the processing request information through the encryption server to obtain first data information, and returns the first data information to the target device. The first data information is encrypted data information, and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial transaction and the second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1. The first verification unit 503 verifies the biometric features of the target object based on the first data information through the target device, obtains a first verification result, and sends second data information to the encryption server through the target device if the first verification result indicates that the verification is successful. The second data information is encrypted data information and includes at least: a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The second verification unit 504 verifies the second data information through the encryption server, obtains a second verification result, and processes the target financial business through the target device if the second verification result indicates that the verification is successful. This solves the problem in related technologies where biometric verification using mobile devices is easily invaded by malicious computer programs, resulting in low security for financial transactions. In this application, a target device receives a request for a financial transaction initiated by a target object, sends the request to an encryption server, processes the request to obtain first data information, and then sends the first data information back to the target device. The target device verifies the target object's biometrics based on the first data information, obtains a first verification result, and if the first verification result indicates successful verification, sends second data information to the encryption server. The encryption server verifies the second data information and sends the second verification result back to the target device. If the second verification result indicates successful verification, the target device processes the financial transaction. By performing multiple verifications on the data between the target device and the encryption server, and by encrypting the data transmission between the target device and the encryption server multiple times using quantum random numbers, the reliability of the biometric verification result is ensured, thereby improving the security of financial transactions.
[0104] Optionally, in the financial business processing apparatus provided in the embodiments of this application, the apparatus further includes: a first storage unit, used to generate multiple quantum random numbers through a quantum random number generator, assign a sequence number to each quantum random number, and store the multiple quantum random numbers and the sequence number of each quantum random number in a target device; and a second storage unit, used to store the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in an encryption server.
[0105] Optionally, in the financial business processing apparatus provided in this application embodiment, the processing unit 502 includes: a first verification module, used to verify the processing request information, and randomly select at least one quantum random number as a first sequence number if the processing request information is verified; a determination module, used to determine the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of the N quantum random numbers, wherein the second sequence number of the N quantum random numbers is any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; a first encryption module, used to encrypt the total number N of biometric features to be collected and the second sequence number of the N quantum random numbers according to the quantum random number corresponding to the first sequence number of the at least one quantum random number, to obtain an authentication message; and a second encryption module, used to encrypt the authentication message and the first sequence number of the at least one quantum random number according to a preset transmission key, to obtain first data information.
[0106] Optionally, in the financial business processing apparatus provided in this application embodiment, the first verification unit 503 includes: a first decryption module, used to decrypt the first data information according to a preset transmission key to obtain a first sequence number of at least one quantum random number and an authentication message; a second decryption module, used to decrypt the authentication message according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain the total number N of biometric features to be collected and the second sequence number of N quantum random numbers; a collection module, used to collect the biometric features of the target object according to the total number N of biometric features to be collected and the second sequence number of N quantum random numbers to obtain N biometric features; and a second verification module, used to perform authentication based on the N biometric features to obtain a first verification result.
[0107] Optionally, in the financial business processing apparatus provided in the embodiments of this application, the apparatus further includes: a computing unit, configured to determine at least one third sequence number of a quantum random number from the second sequence numbers of N quantum random numbers, and perform encryption operations on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to a target algorithm to obtain a first computing result; a first encryption unit, configured to encrypt the first verification result and the first computing result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain a verification result message; and a second encryption unit, configured to encrypt the verification result message and the third sequence number of the at least one quantum random number according to a preset transmission key to obtain second data information.
[0108] Optionally, in the financial business processing apparatus provided in this application embodiment, the second verification unit 504 includes: a third decryption module, used to decrypt the second data information according to a preset transmission key to obtain a verification result message and a third sequence number of at least one quantum random number; a calculation module, used to process the third sequence number of at least one quantum random number according to the second sequence number of N quantum random numbers to obtain a second calculation result; a fourth decryption module, used to decrypt the verification result message according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain a first verification result and a first calculation result; and a third verification module, used to verify the first calculation result according to the second calculation result to obtain a second verification result.
[0109] Optionally, in the financial business processing apparatus provided in this application embodiment, the operation module includes: a judgment submodule, used to judge whether there is at least one third sequence number of quantum random numbers among the second sequence numbers of N quantum random numbers, and obtain a judgment result; a determination submodule, used to determine the quantum random number corresponding to the third sequence number based on the third sequence number of the at least one quantum random number when the judgment result indicates that there is at least one third sequence number of quantum random numbers among the second sequence numbers of N quantum random numbers; and an operation submodule, used to perform encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm, and obtain a second operation result.
[0110] The financial business processing device includes a processor and a memory. The aforementioned sending unit 501, processing unit 502, first verification unit 503, and second verification unit 504 are all stored in the memory as program units. The processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0111] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and adjusting kernel parameters can address the vulnerability of mobile devices used for biometric verification to malicious computer programs, leading to low security in financial transactions.
[0112] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0113] This invention provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements a method for processing financial transactions.
[0114] This invention provides a processor for running a program, wherein the program executes a method for processing financial transactions during runtime.
[0115] like Figure 6 As shown, this embodiment of the invention provides an electronic device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: receiving a request for processing a target financial transaction initiated by a target object through the target device, and sending the request information to an encryption server. The request information includes at least: the ID of the target device, the request for processing the target financial transaction, and timestamp information; processing the request information through the encryption server to obtain first data information, and returning the first data information to the target device. The first data information is encrypted data information, and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the target... The target financial transaction involves the following steps: First, the target device verifies the biometric features of the target object based on the first data information to obtain a first verification result. If the first verification result indicates successful verification, the target device sends second data information to an encryption server. The second data information is encrypted and includes at least a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The encryption server then verifies the second data information to obtain a second verification result. If the second verification result indicates successful verification, the target financial transaction is processed through the target device.
[0116] Optionally, before processing the request information through the encryption server to obtain the first data information, the method further includes: generating multiple quantum random numbers through a quantum random number generator, assigning a sequence number to each quantum random number, storing the multiple quantum random numbers and the sequence number of each quantum random number in the target device; and storing the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in the encryption server.
[0117] Optionally, processing the application request information through an encryption server to obtain the first data information includes: verifying the application request information, and if the application request information is verified, randomly selecting at least one quantum random number as the first sequence number; determining the total number N of biometric features to be collected corresponding to the target financial business and the second sequence numbers of the N quantum random numbers, wherein the second sequence numbers of the N quantum random numbers are any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; encrypting the total number N of biometric features to be collected and the second sequence numbers of the N quantum random numbers based on the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain an authentication message; and encrypting the authentication message and the first sequence number of the at least one quantum random number based on a preset transmission key to obtain the first data information.
[0118] Optionally, the biometric verification of the target object by the target device based on the first data information to obtain the first verification result includes: decrypting the first data information according to a preset transmission key to obtain a first serial number of at least one quantum random number and an authentication message; decrypting the authentication message according to the quantum random number corresponding to the first serial number of at least one quantum random number to obtain the total number N of biometric features to be collected and the second serial number of N quantum random numbers; collecting the biometric features of the target object according to the total number N of biometric features to be collected and the second serial number of N quantum random numbers to obtain N biometric features; and performing authentication based on the N biometric features to obtain the first verification result.
[0119] Optionally, before sending the second data information to the encryption server via the target device after the first verification result indicates that the verification has passed, the method further includes: determining the third sequence number of at least one quantum random number from the second sequence numbers of N quantum random numbers, and performing an encryption operation on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to the target algorithm to obtain a first operation result; encrypting the first verification result and the first operation result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain a verification result message; and encrypting the verification result message and the third sequence number of the at least one quantum random number according to a preset transmission key to obtain the second data information.
[0120] Optionally, verifying the second data information through an encryption server to obtain a second verification result includes: decrypting the second data information according to a preset transmission key to obtain a verification result message and a third sequence number of at least one quantum random number; processing the third sequence number of at least one quantum random number according to the second sequence number of N quantum random numbers to obtain a second operation result; decrypting the verification result message according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain a first verification result and a first operation result; and verifying the first operation result according to the second operation result to obtain a second verification result.
[0121] Optionally, processing the third sequence number of at least one quantum random number based on the second sequence number of N quantum random numbers to obtain the second operation result includes: determining whether there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, and obtaining a determination result; if the determination result indicates that there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, determining the quantum random number corresponding to the third sequence number based on the third sequence number of at least one quantum random number; and performing encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm to obtain the second operation result.
[0122] The devices mentioned in this article can be servers, PCs, tablets, mobile phones, etc.
[0123] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program with the following initialization steps: receiving a processing request information for a target financial transaction initiated by a target object through the target device, and sending the processing request information to an encryption server, wherein the processing request information includes at least: the ID of the target device, the processing request for the target financial transaction, and timestamp information; processing the processing request information through the encryption server to obtain first data information, and returning the first data information to the target device, wherein the first data information is encrypted data information, and the first data information includes at least: a first sequence number of at least one quantum random number and an authentication message, the authentication message including at least: the pending information corresponding to the target financial transaction. The system collects a total number N of biometric features and a second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1. The target device verifies the biometric features of the target object based on the first data information to obtain a first verification result. If the first verification result indicates successful verification, the target device sends second data information to an encryption server. The second data information is encrypted and includes at least: a third sequence number of at least one quantum random number and a verification result message, which includes at least the first verification result. The encryption server verifies the second data information to obtain a second verification result. If the second verification result indicates successful verification, the target device processes the target financial transaction.
[0124] Optionally, before processing the request information through the encryption server to obtain the first data information, the method further includes: generating multiple quantum random numbers through a quantum random number generator, assigning a sequence number to each quantum random number, storing the multiple quantum random numbers and the sequence number of each quantum random number in the target device; and storing the ID of the target device and the multiple quantum random numbers and the sequence number of each quantum random number stored in the target device in the encryption server.
[0125] Optionally, processing the application request information through an encryption server to obtain the first data information includes: verifying the application request information, and if the application request information is verified, randomly selecting at least one quantum random number as the first sequence number; determining the total number N of biometric features to be collected corresponding to the target financial business and the second sequence numbers of the N quantum random numbers, wherein the second sequence numbers of the N quantum random numbers are any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; encrypting the total number N of biometric features to be collected and the second sequence numbers of the N quantum random numbers based on the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain an authentication message; and encrypting the authentication message and the first sequence number of the at least one quantum random number based on a preset transmission key to obtain the first data information.
[0126] Optionally, the biometric verification of the target object by the target device based on the first data information to obtain the first verification result includes: decrypting the first data information according to a preset transmission key to obtain a first serial number of at least one quantum random number and an authentication message; decrypting the authentication message according to the quantum random number corresponding to the first serial number of at least one quantum random number to obtain the total number N of biometric features to be collected and the second serial number of N quantum random numbers; collecting the biometric features of the target object according to the total number N of biometric features to be collected and the second serial number of N quantum random numbers to obtain N biometric features; and performing authentication based on the N biometric features to obtain the first verification result.
[0127] Optionally, before sending the second data information to the encryption server via the target device after the first verification result indicates that the verification has passed, the method further includes: determining the third sequence number of at least one quantum random number from the second sequence numbers of N quantum random numbers, and performing an encryption operation on the quantum random number corresponding to the third sequence number of the at least one quantum random number according to the target algorithm to obtain a first operation result; encrypting the first verification result and the first operation result according to the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain a verification result message; and encrypting the verification result message and the third sequence number of the at least one quantum random number according to a preset transmission key to obtain the second data information.
[0128] Optionally, verifying the second data information through an encryption server to obtain a second verification result includes: decrypting the second data information according to a preset transmission key to obtain a verification result message and a third sequence number of at least one quantum random number; processing the third sequence number of at least one quantum random number according to the second sequence number of N quantum random numbers to obtain a second operation result; decrypting the verification result message according to the quantum random number corresponding to the first sequence number of at least one quantum random number to obtain a first verification result and a first operation result; and verifying the first operation result according to the second operation result to obtain a second verification result.
[0129] Optionally, processing the third sequence number of at least one quantum random number based on the second sequence number of N quantum random numbers to obtain the second operation result includes: determining whether there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, and obtaining a determination result; if the determination result indicates that there is a third sequence number of at least one quantum random number among the second sequence numbers of N quantum random numbers, determining the quantum random number corresponding to the third sequence number based on the third sequence number of at least one quantum random number; and performing encryption operation on the quantum random number corresponding to the third sequence number according to the target algorithm to obtain the second operation result.
[0130] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0131] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0132] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0133] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0134] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0135] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0136] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0137] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0138] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0139] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for processing financial transactions, characterized in that, The financial transaction processing method is applied to a financial transaction processing system, which includes at least: a target device and an encryption server, comprising: The system receives a request for processing a target financial transaction initiated by a target object through the target device and sends the request information to an encrypted server. The request information includes at least the ID of the target device, the request for processing the target financial transaction, and timestamp information. The encryption server processes the processing request information to obtain first data information, and returns the first data information to the target device. The first data information is encrypted data information and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1. The target device verifies the biometrics of the target object based on the first data information to obtain a first verification result. If the first verification result indicates that the verification is successful, the target device sends second data information to the encryption server. The second data information is encrypted data information and includes at least: a third sequence number of at least one quantum random number and a verification result message. The verification result message includes at least the first verification result. The encryption server verifies the second data information to obtain a second verification result. If the second verification result indicates that the verification is successful, the target financial business is processed through the target device.
2. The method according to claim 1, characterized in that, The financial transaction processing system further includes a quantum random number generator. Before processing the processing request information through the encryption server to obtain the first data information, the method further includes: Multiple quantum random numbers are generated by a quantum random number generator, and a sequence number is assigned to each quantum random number. The multiple quantum random numbers and the sequence number of each quantum random number are stored in the target device. The ID of the target device, the plurality of quantum random numbers stored in the target device, and the sequence number of each quantum random number are stored in the encryption server.
3. The method according to claim 1, characterized in that, The first data information obtained by processing the processing request information through the encryption server includes: The processing request information is verified, and if the processing request information is verified, at least one quantum random number first sequence number is randomly selected; Determine the total number N of the biometric features to be collected corresponding to the target financial business and the second sequence number of the N quantum random numbers, wherein the second sequence number of the N quantum random numbers is any N of the sequence numbers of multiple quantum random numbers stored in the encryption server; The total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers are encrypted based on the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the authentication message; The authentication message and the first sequence number of the at least one quantum random number are encrypted according to a preset transmission key to obtain the first data information.
4. The method according to claim 1, characterized in that, The first verification result obtained by verifying the biometrics of the target object based on the first data information using the target device includes: The first data information is decrypted according to a preset transmission key to obtain the first sequence number of the at least one quantum random number and the authentication message; The authentication message is decrypted based on the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers; Based on the total number N of the biometric features to be collected and the second sequence number of the N quantum random numbers, the biometric features of the target object are collected to obtain N biometric features; Identity verification is performed based on the N biometric features to obtain the first verification result.
5. The method according to claim 1, characterized in that, If the first verification result indicates that the verification is successful, before sending the second data information to the encryption server through the target device, the method further includes: The third sequence number of the at least one quantum random number is determined from the second sequence number of the N quantum random numbers, and the quantum random number corresponding to the third sequence number of the at least one quantum random number is encrypted according to the target algorithm to obtain the first operation result; Based on the quantum random number corresponding to the first sequence number of the at least one quantum random number, the first verification result and the first operation result are encrypted to obtain the verification result message; The verification result message and the third sequence number of the at least one quantum random number are encrypted according to the preset transmission key to obtain the second data information.
6. The method according to claim 5, characterized in that, The second verification result obtained by verifying the second data information through the encryption server includes: The second data information is decrypted according to the preset transmission key to obtain the verification result message and the third sequence number of the at least one quantum random number; Based on the second sequence number of the N quantum random numbers, the third sequence number of the at least one quantum random number is processed to obtain the second operation result; The verification result message is decrypted based on the quantum random number corresponding to the first sequence number of the at least one quantum random number to obtain the first verification result and the first operation result; The first calculation result is verified based on the second calculation result to obtain the second verification result.
7. The method according to claim 6, characterized in that, Based on the second sequence number of the N quantum random numbers, the third sequence number of the at least one quantum random number is processed to obtain the second operation result, which includes: Determine whether a third sequence number of at least one quantum random number exists among the second sequence numbers of the N quantum random numbers, and obtain the determination result; If, in the case where the judgment result represents the existence of a third sequence number of at least one quantum random number among the second sequence numbers of the N quantum random numbers, the quantum random number corresponding to the third sequence number is determined based on the third sequence number of the at least one quantum random number; The quantum random number corresponding to the third sequence number is encrypted using the target algorithm to obtain the second calculation result.
8. A financial transaction processing system, characterized in that, The processing system is used to execute the financial transaction processing method according to any one of claims 1 to 7, comprising: The target device is configured to receive a request for processing a target financial transaction initiated by a target object, send the request for processing to an encryption server, receive first data information returned by the encryption server, verify the biometric features of the target object based on the first data information to obtain a first verification result, send second data information to the encryption server if the first verification result indicates that the verification is successful, and process the target financial transaction if the second verification result indicates that the verification is successful. The first data information is obtained by the encryption server processing the request for processing, and the second data information is obtained by the target device based on the first verification result. The encryption server is configured to process the processing request information to obtain first data information, send the first data information to the target device, receive second data information returned by the target device, verify the second data information, and obtain the second verification result.
9. The processing system according to claim 8, characterized in that, The processing system also includes: A quantum random number generator is used to generate multiple quantum random numbers and store the multiple quantum random numbers and the sequence number of each quantum random number in the target device and the encryption server.
10. A financial transaction processing apparatus, characterized in that, The processing apparatus is used to execute the financial transaction processing method according to any one of claims 1 to 7, comprising: The sending unit is configured to receive the processing request information of the target financial business initiated by the target object through the target device, and send the processing request information to the encryption server, wherein the processing request information includes at least: the ID of the target device, the processing request of the target financial business, and timestamp information; The processing unit is configured to process the processing request information through the encryption server to obtain first data information and return the first data information to the target device. The first data information is encrypted data information and includes at least: a first sequence number of at least one quantum random number and an authentication message. The authentication message includes at least: the total number N of biometric features to be collected corresponding to the target financial business and the second sequence number of N quantum random numbers, where N is a positive integer greater than or equal to 1. The first verification unit is configured to verify the biometrics of the target object based on the first data information through the target device, obtain a first verification result, and send second data information to the encryption server through the target device if the first verification result indicates that the verification is successful. The second data information is encrypted data information and includes at least: a third sequence number of at least one quantum random number and a verification result message. The verification result message includes at least the first verification result. The second verification unit is used to verify the second data information through the encryption server, obtain a second verification result, and, if the second verification result indicates that the verification is successful, process the target financial business through the target device.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the financial business processing method according to any one of claims 1 to 7.
12. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the processing method of the financial business according to any one of claims 1 to 7.
Citation Information
Patent Citations
Financial service verification system and financial service verification method
CN110689351A
Clock model for formal verification of a digital circuit description
US20070271536A1