Key replacement, locker rental transaction and password modification method based on full-automatic storage box system

By dynamically generating and replacing public and private key pairs through a fully automated safe deposit box system, and combining this with national cryptographic algorithms to generate password envelopes, the security risks in bank password keyboard encryption technology are resolved, achieving low-cost, high-efficiency transaction security and user password protection.

CN118249998BActive Publication Date: 2025-12-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410338737.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-22
Publication Date
2025-12-16
Estimated Expiration
2044-03-22

AI Technical Summary

Technical Problem

In existing bank password keypad encryption technologies, fixed keys are at risk of being stolen by hackers, and non-national cryptographic algorithms are at risk of being cracked, resulting in insufficient security for online fund transfers.

Method used

The fully automated safe deposit box system dynamically generates public and private key pairs, uses an encryption service platform to generate working keys, and replaces the private key at the low-level terminal. It also generates password envelopes using national cryptographic algorithms, thus realizing dynamic key replacement and password encryption verification.

Benefits of technology

It effectively prevents hacker attacks, ensures the integrity of over-the-counter transactions in the fully automated safe deposit box system and the confidentiality of user passwords, and achieves simple and low-cost security encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118249998B_ABST
    Figure CN118249998B_ABST
Patent Text Reader

Abstract

The disclosure provides a key replacement, a box rental transaction and a password modification method based on a full-automatic safe box system, which can be applied to the financial field, and the method comprises the following steps: in response to a check-in transaction initiated by a low-cabinet terminal, the full-automatic safe box system calls a password keyboard to randomly generate a public-private key pair, wherein the public-private key pair comprises a public key and a private key matched with each other, the public key is stored in the full-automatic safe box system, and the private key is stored in the low-cabinet terminal; the full-automatic safe box system forwards the public key to an encryption service platform and initiates a generation request of a working key to the encryption service platform; the encryption service platform generates a first working key and a second working key based on the generation request and returns the first working key and the second working key to the full-automatic safe box system; and the full-automatic safe box system transmits the second working key to the low-cabinet terminal, so that the low-cabinet terminal replaces the private key with the second working key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure pertains to the field of financial technology, specifically involving a method for key replacement, safe deposit box transactions, and password modification based on a fully automated safe deposit box system. Background Technology

[0002] Currently, the financial sector is moving towards networking, with more and more banks exchanging financial information via computer networks. Ensuring the security of this information and preventing its illegal theft and modification has become a primary goal in the development of bank network informatization. Among existing technologies for PIN pad encryption in bank branches, fixed keys and non-national cryptographic algorithms are used for password encryption and verification. However, using fixed keys carries the risk of being stolen by hackers, while using non-national cryptographic algorithms carries the risk of being cracked. Summary of the Invention

[0003] In view of the above problems, this disclosure provides a method and apparatus for key replacement, safe deposit box transaction, and password modification based on a fully automated safe deposit box system. This method overcomes the shortcomings of existing encryption technologies by employing dynamic key replacement, password encryption, and password verification techniques to ensure the integrity of over-the-counter transactions and the confidentiality of user passwords within the fully automated safe deposit box system. It is simple to implement, has low implementation costs, and effectively prevents hacker attacks.

[0004] According to the first aspect of this disclosure, a key replacement method based on a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The method includes: in response to a check-in transaction initiated by the low-level terminal, the fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair, wherein the generated public-private key pair includes a paired public key and a private key, the public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-level terminal; the fully automated safe deposit box system forwards the public key to the encryption service platform and initiates a working key generation request to the encryption service platform; based on the generation request, the encryption service platform generates a first working key and a second working key, and returns the first working key and the second working key to the fully automated safe deposit box system; the fully automated safe deposit box system transmits the second working key to the low-level terminal, so that the low-level terminal replaces its private key with the second working key.

[0005] According to embodiments of this disclosure, the encryption service platform generates a first working key and a second working key based on a generation request, wherein the first working key is ciphertext used to verify the password, and the second working key is a key used to encrypt the public key.

[0006] According to a second aspect of this disclosure, a method for renting safe deposit boxes based on a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The method includes verification and processing of a reserved safe deposit box password. The verification includes: in response to the rental transaction request, the low-level terminal uses the keypad to generate a first ciphertext encrypted with a working key and sends it to the fully automated safe deposit box system; the fully automated safe deposit box system sends the first ciphertext to the encryption service platform; based on the first ciphertext, the encryption service platform generates a first national cryptographic password envelope and sends it to the fully automated safe deposit box system; the fully automated safe deposit box system sends the first national cryptographic password envelope to a personal settlement application for verification; the personal settlement application sends the verification result to the fully automated safe deposit box system to complete the verification.

[0007] According to embodiments of this disclosure, the reserved safe deposit box password processing includes: obtaining user authorization for the entered information; after obtaining user authorization, entering the safe deposit box password through a low-level terminal, wherein the low-level terminal encrypts the safe deposit box password to obtain a second ciphertext and sends it to the fully automatic safe deposit box system; the fully automatic safe deposit box system calls the encryption service platform and uploads the working key in encryption machine format, the second ciphertext, and the safe deposit box number to obtain a second national cryptographic password envelope; the fully automatic safe deposit box system calls the encryption service platform again and uploads the second national cryptographic password envelope and the safe deposit box number to obtain the storage ciphertext and save it.

[0008] According to a third aspect of this disclosure, a method for modifying the password of a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The method includes original safe deposit box verification and password modification processing. The original safe deposit box verification process includes: obtaining user authorization to enter the original safe deposit box password; after obtaining user authorization to enter the original safe deposit box password, entering the original safe deposit box password through the low-level terminal; the low-level terminal encrypting the original safe deposit box password with a working key and sending it to the fully automated safe deposit box system; the fully automated safe deposit box system transmitting the encrypted information of the original safe deposit box to the encryption service platform; the encryption service platform returning the verification result to the fully automated safe deposit box system, which then forwards it to the low-level terminal.

[0009] According to embodiments of this disclosure, the process of modifying a safe deposit box password includes: after the original safe deposit box password is verified, the user enters the target safe deposit box password through the low-level terminal; the target safe deposit box password is encrypted with a working key and then transmitted to the fully automated safe deposit box system; the fully automated safe deposit box system transmits the safe deposit box number, the target safe deposit box password, and the working key to the encryption service platform to obtain the target safe deposit box password envelope; the encryption service platform sends the target safe deposit box password envelope to the fully automated safe deposit box system.

[0010] According to a fourth aspect of this disclosure, a key replacement device based on a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The device includes: a public-private key pair generation module, a key request sending module, a working key generation module, and a key replacement module. The public-private key pair generation module is used to respond to a check-in transaction initiated by the low-level terminal by calling the keypad to randomly generate a public-private key pair. The generated public-private key pair includes a paired public key and a private key. The public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-level terminal. The key request sending module is used for the fully automated safe deposit box system to forward the public key to the encryption service platform and initiate a working key generation request to the encryption service platform. The working key generation module is used for the encryption service platform to generate a first working key and a second working key based on the generation request, and return the first working key and the second working key to the fully automated safe deposit box system. The key replacement module is used for the fully automated safe deposit box system to transmit the second working key to the low-level terminal, so that the low-level terminal replaces its private key with the second working key.

[0011] According to the fifth aspect of this disclosure, a safe deposit box rental transaction device based on a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The device includes a verification module and a reserved safe deposit box password processing module. The verification module includes: a first ciphertext generation unit, used to generate a first ciphertext encrypted with a working key using the keypad in response to the safe deposit box rental transaction request, and send it to the fully automated safe deposit box system; a first ciphertext sending unit, used by the fully automated safe deposit box system to send the first ciphertext to the encryption service platform; a first password envelope generation unit, used by the encryption service platform to generate a first national cryptographic password envelope based on the first ciphertext and send it to the fully automated safe deposit box system; a first national cryptographic password envelope sending unit, used by the fully automated safe deposit box system to send the first national cryptographic password envelope to a personal settlement application for verification processing; and a verification unit, used by the personal settlement application to send the verification result to the fully automated safe deposit box system to complete the verification.

[0012] According to embodiments of this disclosure, the reserved safe deposit box password processing module includes: a user authorization unit for obtaining user authorization for input information; a password input unit for inputting the safe deposit box password through a low-level terminal after obtaining user authorization, wherein the low-level terminal encrypts the safe deposit box password to obtain a second password ciphertext and sends it to the fully automated safe deposit box system; a second password envelope generation unit for the fully automated safe deposit box system to call the encryption service platform and upload the working key in encryption machine format, the second password ciphertext, and the safe deposit box number to obtain a second national cryptographic password envelope; and a ciphertext storage unit for the fully automated safe deposit box system to call the encryption service platform again and upload the second national cryptographic password envelope and the safe deposit box number to obtain and save the stored ciphertext.

[0013] According to the sixth aspect of this disclosure, a password modification transaction device based on a fully automated safe deposit box system is provided. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform. The low-level terminal is equipped with a keypad. The device includes an original safe deposit box verification module and a safe deposit box password modification processing module. The original safe deposit box verification module includes: a user authorization unit for obtaining user authorization to enter the original safe deposit box password; an original password entry unit for entering the original safe deposit box password through the low-level terminal after obtaining user authorization, wherein the low-level terminal encrypts the original safe deposit box password using a working key and sends it to the fully automated safe deposit box system; an encrypted information sending unit for the fully automated safe deposit box system to transmit the encrypted information of the original safe deposit box to the encryption service platform; and a verification result generation unit for the encryption service platform to return the verification result to the fully automated safe deposit box system, which then forwards it to the low-level terminal.

[0014] According to embodiments of this disclosure, the safe deposit box password modification module includes: a target password generation unit, used for transmitting the target safe deposit box password entered by the user through a low-level terminal after the original safe deposit box password has been verified, the target safe deposit box password being encrypted with a working key and then transmitted to the fully automated safe deposit box system; a target password envelope generation unit, used for transmitting the safe deposit box number, the target safe deposit box password, and the working key to the encryption service platform by the fully automated safe deposit box system to obtain the target safe deposit box password envelope; and a target password envelope sending unit, used for the encryption service platform to send the target safe deposit box password envelope to the fully automated safe deposit box system. Attached Figure Description

[0015] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0016] Figure 1 This schematically illustrates a system architecture suitable for key replacement, safe deposit box transaction, and password modification methods and apparatus based on a fully automated safe deposit box system, according to embodiments of the present disclosure.

[0017] Figure 2 A flowchart illustrating a key replacement method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown schematically.

[0018] Figure 3 The flowchart illustrating the password verification process in a safe deposit box rental transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown in the illustration.

[0019] Figure 4 The flowchart illustrating the reserved safe deposit box password processing in the safe deposit box rental transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown in the illustration.

[0020] Figure 5 The flowchart illustrating the password verification process in a password modification transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown in the illustration.

[0021] Figure 6 The flowchart illustrating the process of modifying the safe deposit box password in the password modification transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown in the illustration.

[0022] Figure 7 This schematically illustrates a structural block diagram of a key replacement device based on a fully automated safe deposit box system according to an embodiment of the present disclosure;

[0023] Figure 8 This schematic diagram illustrates a structural block diagram of a safe deposit box rental transaction device based on a fully automated safe deposit box system according to an embodiment of the present disclosure;

[0024] Figure 9 The diagram illustrates a structural block diagram of a password modification transaction device based on a fully automated safe deposit box system according to an embodiment of the present disclosure. Detailed Implementation

[0025] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0026] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0027] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0028] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).

[0029] The accompanying drawings illustrate several block diagrams and / or flowcharts. It should be understood that some blocks, or combinations thereof, in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor, these instructions can create means for implementing the functions / operations described in these block diagrams and / or flowcharts. The technology of this disclosure can be implemented in hardware and / or software (including firmware, microcode, etc.). Alternatively, the technology of this disclosure can take the form of a computer-readable storage medium storing instructions thereon, on which executable instructions are stored, which, when executed by a processor, cause the processor to perform the methods of this disclosure.

[0030] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0031] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this disclosure all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0032] Before describing the specific embodiments of this disclosure in detail, technical terms will first be explained to facilitate a better understanding of this disclosure. Personal Fully Automated Safe Deposit Box Service Management System (hereinafter referred to as the Fully Automated Safe Deposit Box System): Fully automated safe deposit box equipment is deployed at branch locations to provide safe deposit box services.

[0033] The embodiments of this disclosure provide a method for key replacement, safe rental transaction, and password modification based on a fully automated safe deposit box system. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform, respectively. The low-level terminal is equipped with a keypad. The method includes: a key replacement method based on the fully automated safe deposit box system, a safe rental transaction method based on the fully automated safe deposit box system, and a password modification method based on the fully automated safe deposit box system. The key replacement method based on the fully automated safe deposit box system includes: in response to a check-in transaction initiated by the low-level terminal, the fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair, wherein the generated public-private key pair includes a paired public key and a private key, the public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-level terminal; the fully automated safe deposit box system forwards the public key to the encryption service platform and initiates a working key generation request to the encryption service platform; based on the generation request, the encryption service platform generates a first working key and a second working key, and returns the first working key and the second working key to the fully automated safe deposit box system; the fully automated safe deposit box system transmits the second working key to the low-level terminal, so that the low-level terminal replaces the private key with the second working key.

[0034] The embodiments disclosed herein address the shortcomings of existing encryption technologies. By employing dynamic key replacement, password encryption, and password verification technologies, the integrity of over-the-counter transactions in the fully automated safe deposit box system and the confidentiality of user passwords are ensured. This approach is simple, low-cost to implement, and effectively prevents hacker attacks.

[0035] Figure 1 This illustration schematically depicts a system architecture suitable for key replacement, safe deposit box transactions, and password modification methods and apparatus based on a fully automated safe deposit box system, according to embodiments of this disclosure. It should be noted that... Figure 1 The examples shown are merely examples of system architectures that can be applied to the embodiments of this disclosure, in order to help those skilled in the art understand the technical content of this disclosure, but do not mean that the embodiments of this disclosure cannot be used in other devices, systems, environments or scenarios.

[0036] like Figure 1 As shown, the system architecture 100 according to this embodiment may include low cabinet terminals 101, 102, and 103, a fully automatic safe deposit box system 104, and an encryption service platform 105. The fully automatic safe deposit box system 104 is communicatively connected to the clients 101, 102, and 103 and the encryption service platform 105, respectively.

[0037] Users can interact with the fully automated safe deposit box system 104 using clients 101, 102, and 103 to receive or send messages, etc. Various communication client applications can be installed on clients 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0038] Clients 101, 102, and 103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0039] The 104 fully automated safe deposit box system is a bank safe deposit device that provides 24-hour service to renters. It is an automated and unmanned bank safe deposit box system that integrates multiple cutting-edge technologies such as safe deposit box service, monitoring, inquiry, and annual inventory. The operation process includes customer identification, operation guidance, safe deposit box retrieval and return, and usage status recording.

[0040] It should be noted that the key replacement, safe rental transaction, and password modification methods based on the fully automated safe deposit box system provided in this disclosure embodiment can generally be executed by the fully automated safe deposit box system 104. Accordingly, the key replacement, safe rental transaction, and password modification device based on the fully automated safe deposit box system provided in this disclosure embodiment can generally be installed in the fully automated safe deposit box system 104.

[0041] It should be understood that Figure 1 The number of clients, fully automated safe deposit box systems, and encryption service platforms shown is merely illustrative. Depending on implementation needs, any number of clients, fully automated safe deposit box systems, and encryption service platforms can be included.

[0042] The following will be based on Figure 1 The described system architecture, through Figures 2-6 The key replacement, rental transaction, and password modification methods based on the fully automated safe deposit box system disclosed in the present embodiments are described in detail.

[0043] Figure 2 The flowchart illustrating a key replacement method based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown. The fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform, respectively. The low-level terminal is equipped with a keypad, such as... Figure 2 As shown, the method may further include operations S210 to S240.

[0044] When operating S210, in response to the check-in transaction initiated by the low-level terminal, the fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair. The generated public-private key pair includes a public key and a private key that are paired with each other. The public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-level terminal.

[0045] When operating the S220, the fully automated safe deposit box system forwards the public key to the encryption service platform and initiates a request to the encryption service platform to generate a working key.

[0046] Specifically, each day, tellers (or users) initiate a sign-in transaction through the low-counter terminal. The fully automated safe deposit box system calls the key generation interface of the dual-screen keypad and uses an asymmetric algorithm to randomly generate a public-private key pair. The generated public-private key pair includes a paired public key and a private key. The public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-counter terminal.

[0047] During operation S230, the encryption service platform generates a first working key and a second working key based on the generation request, and returns the first working key and the second working key to the fully automated safe deposit box system.

[0048] The fully automated safe deposit box system forwards the public key to the encryption service platform and initiates a working key generation request to the HSM (encryption service platform). Based on the generation request, the encryption service platform uses a symmetric algorithm to generate two keys: a first working key and a second working key. The first working key is the ciphertext used to verify the password, and the second working key is the key used to encrypt the public key.

[0049] During operation of S240, the fully automated safe deposit box system transmits the second working key to the low-level terminal, so that the low-level terminal can replace the private key with the second working key.

[0050] Next, the fully automated safe deposit box system transmits the second working key to the low-level terminal, so that the low-level terminal can replace its private key with the second working key, thus completing the low-level terminal key replacement for the day.

[0051] It should be noted that in the key replacement method of the fully automated safe deposit box system disclosed herein, the fully automated safe deposit box management system will store the working key for the day. The table structure record corresponding to the dual-screen password keypad of the fully automated safe deposit box device and the low cabinet terminal has a field for storing the key, and the rule is that the fully automated safe deposit box device number (low cabinet terminal number) corresponds to the working key for the day.

[0052] Through the embodiments of this disclosure, transaction time, transaction channel, and message integrity MAC (Message Authentication Code) are controlled by dynamic key replacement to effectively prevent replay attacks and ensure the confidentiality of over-the-counter transactions in the fully automated safe deposit box system.

[0053] In the embodiments disclosed herein, for example, a daily password mechanism is adopted. Teller sign-in daily to update the dual-screen PIN pad working key. The teller counter will be equipped with a dual-screen PIN pad for bank card verification and pre-setting safe deposit box passwords. The process of bank card verification and pre-setting safe deposit box passwords is described in detail below.

[0054] Figure 3 A flowchart illustrating the password verification process in a safe deposit box rental transaction method based on a fully automated safe deposit box system according to an embodiment of this disclosure is shown. Figure 3 As shown, operations S310 to S350 may be further included.

[0055] When operating the S310, in response to the rental box transaction demand, the low-level terminal uses the keypad to generate the first ciphertext obtained by encrypting the working key and sends it to the fully automated safe deposit box system.

[0056] In the embodiments disclosed herein, the safe deposit box rental transaction first verifies the bank card's PIN, and then reserves the safe deposit box password. It should be noted that the ciphertext encrypted by the dual-screen PIN pad is not a standard card PIN, requiring the HSM to provide a function to convert it to a card PIN. The bank card verification process and the safe deposit box verification process call the same HSM service.

[0057] For example, when a user conducts a safe deposit box rental transaction through a low-level terminal, the user enters their bank card password, and the low-level dual-screen keypad is encrypted with the main account number (ANSI IX 9.8) according to the UnionPay standard. The bank card number / account number and the plaintext password are then encrypted with the working key to obtain the ciphertext (pinblock) which is transmitted to the fully automated safe deposit box system.

[0058] When operating the S320, the fully automated safe deposit box system sends the first password ciphertext to the encryption service platform.

[0059] In the embodiments disclosed herein, the fully automated safe deposit box system calls the HSM interface service to send the working key (sm4WKey) in encryption machine format, the first ciphertext (pinblock), and the bank card number / account number (cardno) to the encryption service platform.

[0060] When operating the S330, based on the first ciphertext, the encryption service platform generates the first national cryptographic cipher envelope and sends it to the fully automated safe deposit box system.

[0061] When operating the S340, the fully automated safe deposit box system sends the first national cryptographic password envelope to the personal settlement application for verification.

[0062] When operating the S350, the personal billing application sends the verification result to the fully automated safe deposit box system to complete the verification.

[0063] Specifically, the encryption service platform returns a national cryptographic password envelope. Based on the first cryptographic ciphertext, the encryption service platform generates a first national cryptographic password envelope and sends it to the fully automated safe deposit box system. The fully automated safe deposit box system then sends the obtained first national cryptographic password envelope and bank card number / account number to the personal settlement application for verification, and obtains the verification result.

[0064] Figure 4 The illustration schematically shows a flowchart of the safe deposit box password reservation process in a safe deposit box rental transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure. For example... Figure 4 As shown, operations S410 to S440 may be further included.

[0065] When operating S410, obtain user authorization for entering information.

[0066] When operating the S420, after obtaining authorization from the user to enter information, the safe deposit box password is entered through the low cabinet terminal. The low cabinet terminal encrypts the safe deposit box password to obtain a second password ciphertext and sends it to the fully automated safe deposit box system.

[0067] Specifically, the user enters the safe deposit box password through the low-level terminal. The low-level terminal then encrypts the password using the working key, the safe deposit box number, and the safe deposit box password in the format of UnionPay with the main account number (ANSI X 9.8) to obtain the second password ciphertext, which is then transmitted to the fully automated safe deposit box system.

[0068] When operating the S430, the fully automated safe deposit box system calls the encryption service platform and uploads the working key in encryption machine format, the second ciphertext, and the safe deposit box number to obtain the second national cryptographic envelope.

[0069] When operating the S440, the fully automated safe deposit box system calls the encryption service platform again and sends the second national cryptographic envelope and the safe deposit box number to obtain and save the ciphertext.

[0070] In the embodiments of this disclosure, the fully automated safe deposit box system calls the HSM service and uploads the working key (sm4WKey) in encryption machine format, the second ciphertext (pinblock), and the safe deposit box number (boxNo) to obtain the second national cryptographic envelope.

[0071] Through the embodiments of this disclosure, the integrity of over-the-counter transactions in the fully automated safe deposit box system and the confidentiality of customer passwords are ensured by using password encryption and password verification technologies.

[0072] Figure 5 The flowchart illustrating the password verification process in a password modification transaction method based on a fully automated safe deposit box system according to an embodiment of this disclosure is shown. Figure 5 As shown, operations S510 to S540 may be further included.

[0073] When operating the S510, obtain the user's authorization to enter the original safe deposit box password.

[0074] When operating the S520, after obtaining authorization from the user to enter the original safe deposit box password, the original safe deposit box password is entered through the low cabinet terminal. The low cabinet terminal then encrypts the original safe deposit box password with the working key and sends it to the fully automated safe deposit box system.

[0075] When operating the S530, the fully automated safe deposit box system transmits the encrypted information of the original safe deposit box to the encryption service platform.

[0076] When operating the S540, the encryption service platform returns the verification result to the fully automated safe deposit box system, which then forwards it to the low-level terminal.

[0077] Specifically, the user enters the original safe deposit box password through the low-level terminal. This password is then encrypted with a working key and transmitted to the fully automated safe deposit box system. The fully automated safe deposit box system transmits the safe deposit box number, the encrypted original password, the working key, and the original password envelope to the encryption service platform. The encryption service platform returns the verification result to the fully automated safe deposit box system, which then forwards it to the low-level terminal.

[0078] After the original safe deposit box password is verified, the password change transaction will begin, as follows:

[0079] Figure 6 The illustration schematically shows a flowchart of the safe deposit box password modification process in a password modification transaction method based on a fully automated safe deposit box system according to an embodiment of the present disclosure. For example... Figure 6 As shown, operations S610 to S630 may be further included.

[0080] When operating the S610, after the original safe deposit box password is verified, the user enters the target safe deposit box password through the low cabinet terminal. The target safe deposit box password is then encrypted with the working key and transmitted to the fully automated safe deposit box system.

[0081] When operating the S620, the fully automated safe deposit box system transmits the safe deposit box number, the target safe deposit box password, and the working key to the encryption service platform, and obtains the target safe deposit box password envelope.

[0082] When operating the S630, the encryption service platform sends the target safe deposit box password envelope to the fully automated safe deposit box system.

[0083] Specifically, after the original safe deposit box password is verified, the user enters the target safe deposit box password through the low-level terminal. This target safe deposit box password is then encrypted with the working key and transmitted to the fully automated safe deposit box system. The fully automated safe deposit box system transmits the safe deposit box number, the encrypted target new safe deposit box password, and the working key to the encryption service platform. The encryption service platform then sends the safe deposit box number, the encrypted target new safe deposit box password, and the working key, along with the resulting target safe deposit box password envelope obtained by uploading them to the encryption machine, back to the fully automated safe deposit box system.

[0084] The embodiments disclosed herein address the shortcomings of existing encryption technologies. By employing dynamic key replacement, password encryption, and password verification technologies, the integrity of over-the-counter transactions in the fully automated safe deposit box system and the confidentiality of user passwords are ensured. This approach is simple, low-cost to implement, and effectively prevents hacker attacks.

[0085] Based on the above-described key replacement method for a fully automated safe deposit box system, this disclosure also provides a key replacement device for a fully automated safe deposit box system. The following will be combined with... Figure 7 The device is described in detail.

[0086] Figure 7 A schematic block diagram of a key replacement device based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown.

[0087] like Figure 7 As shown, the key replacement device 700 based on the fully automated safe deposit box system in this embodiment includes a public-private key pair generation module 710, a key request sending module 720, a working key generation module 730, and a key replacement module 740.

[0088] The public-private key pair generation module 710 is used to respond to a check-in transaction initiated by the low-level terminal. The fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair. The generated public-private key pair includes a paired public key and a private key. The public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-level terminal. In one embodiment, the public-private key pair generation module 710 can be used to perform the operation S210 described above, which will not be repeated here.

[0089] The key request sending module 720 is used by the fully automated safe deposit box system to forward the public key to the encryption service platform and initiate a working key generation request to the encryption service platform. In one embodiment, the key request sending module 720 can be used to perform the operation S220 described above, which will not be repeated here.

[0090] The working key generation module 730 is used by the encryption service platform to generate a first working key and a second working key based on a generation request, and then return the first working key and the second working key to the fully automated safe deposit box system. In one embodiment, the key request sending module 730 can be used to perform the operation S230 described above, which will not be repeated here.

[0091] The key replacement module 740 is used by the fully automated safe deposit box system to transmit the second working key to the low-level terminal, so that the low-level terminal can replace its private key with the second working key. In one embodiment, the key replacement module 740 can be used to perform the operation S240 described above, which will not be repeated here.

[0092] Based on the above-described safe deposit box rental transaction method using a fully automated safe deposit box system, this disclosure also provides a safe deposit box rental transaction device based on the same system. The following will be combined with... Figure 8 The device is described in detail.

[0093] Figure 8 A schematic block diagram of a rental transaction device based on a fully automated safe deposit box system according to an embodiment of the present disclosure is shown.

[0094] like Figure 8 As shown, the safe deposit box rental transaction device based on the fully automated safe deposit box system includes a security verification module 810 and a reserved safe deposit box password processing module 820. The security verification module 810 includes:

[0095] The first ciphertext generation unit is used to respond to the rental box transaction requirement. The low-counter terminal uses the keypad to generate a first ciphertext encrypted with the working key and sends it to the fully automated safe deposit box system. In one embodiment, the first ciphertext generation unit can be used to perform the operation S310 described above, which will not be repeated here.

[0096] The first ciphertext sending unit is used by the fully automated safe deposit box system to send the first ciphertext to the encryption service platform. In one embodiment, the first ciphertext sending unit can be used to perform the operation S320 described above, which will not be repeated here.

[0097] The first cipher envelope generation unit is used to generate a first national cryptographic cipher envelope based on the first ciphertext, and then send it to the fully automated safe deposit box system. In one embodiment, the first cipher envelope generation unit can be used to perform the operation S330 described above, which will not be repeated here.

[0098] The first national cryptographic password envelope sending unit is used by the fully automated safe deposit box system to send the first national cryptographic password envelope to the personal settlement application for password verification. In one embodiment, the first national cryptographic password envelope sending unit can be used to perform the operation S340 described above, which will not be repeated here.

[0099] The verification unit, used in personal settlement applications, sends the verification result to the fully automated safe deposit box system to complete the verification. In one embodiment, the verification unit can be used to perform the operation S350 described above, which will not be repeated here.

[0100] In embodiments of this disclosure, the reserved safe deposit box password processing module 820 includes:

[0101] The user authorization unit is used to obtain user authorization for the entered information. In one embodiment, the user authorization unit can be used to perform the operation S410 described above, which will not be repeated here.

[0102] The password entry unit is used to enter the safe deposit box password through the low-level terminal after obtaining authorization from the user's input information. The low-level terminal encrypts the safe deposit box password to obtain a second ciphertext and sends it to the fully automated safe deposit box system. In one embodiment, the password entry unit can be used to perform the operation S420 described above, which will not be repeated here.

[0103] The second cipher envelope generation unit is used by the fully automated safe deposit box system to call the encryption service platform and upload the working key in encryption machine format, the second ciphertext, and the safe deposit box number to obtain the second national cryptographic cipher envelope. In one embodiment, the second cipher envelope generation unit can be used to perform the operation S430 described above, which will not be repeated here.

[0104] The encrypted storage unit is used by the fully automated safe deposit box system to call the encryption service platform again and send the second national cryptographic envelope and safe deposit box number to obtain and save the encrypted text. In one embodiment, the encrypted storage unit can be used to perform the operation S440 described above, which will not be repeated here.

[0105] Based on the above-described password modification transaction method for a fully automated safe deposit box system, this disclosure also provides a password modification transaction device for a fully automated safe deposit box system. The following will be combined with... Figure 9 The device is described in detail.

[0106] Figure 9 The diagram illustrates a structural block diagram of a password modification transaction device based on a fully automated safe deposit box system according to an embodiment of the present disclosure.

[0107] like Figure 9 As shown, the password modification transaction device based on the fully automated safe deposit box system includes an original safe deposit box verification module 910 and a password modification processing module 920. The original safe deposit box verification module 910 includes:

[0108] The user authorization unit is used to obtain user authorization for entering the original safe deposit box password. In one embodiment, the user authorization unit can be used to perform the operation S510 described above, which will not be repeated here.

[0109] The original password input unit is used to input the original safe deposit box password through the low-level terminal after obtaining authorization from the user. The low-level terminal encrypts the original safe deposit box password using a working key and then sends it to the fully automated safe deposit box system. In one embodiment, the original password input unit can be used to perform the operation S520 described above, which will not be repeated here.

[0110] The encrypted information sending unit is used by the fully automated safe deposit box system to transmit the encrypted information of the original safe deposit box to the encrypted service platform. In one embodiment, the encrypted information sending unit can be used to perform the operation S530 described above, which will not be repeated here.

[0111] The verification result generation unit is used by the encryption service platform to return the verification result to the fully automated safe deposit box system, which then forwards it to the low-level terminal. In one embodiment, the verification result generation unit can be used to perform the operation S540 described above, which will not be repeated here.

[0112] In embodiments of this disclosure, the safe deposit box password modification module 920 includes:

[0113] The target password generation unit is used to transmit the target safe deposit box password, which is entered by the user through the low-level terminal after the original safe deposit box password has been verified. The target safe deposit box password is then encrypted with the working key and transmitted to the fully automated safe deposit box system. In one embodiment, the target password generation unit can be used to perform the operation S610 described above, which will not be repeated here.

[0114] The target password envelope generation unit is used by the fully automated safe deposit box system to transmit the safe deposit box number, the target safe deposit box password, and the working key to the encryption service platform to obtain the target safe deposit box password envelope. In one embodiment, the target password envelope generation unit can be used to perform the operation S620 described above, which will not be repeated here.

[0115] The target password envelope sending unit is used by the encryption service platform to send the target safe deposit box password envelope to the fully automated safe deposit box system. In one embodiment, the target password envelope sending unit can be used to perform the operation S630 described above, which will not be repeated here.

[0116] According to embodiments of this disclosure, any of the above-described modules can be combined into one module, or any one of the modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the above-described modules can be at least partially implemented as hardware circuitry, such as a Field Programmable Gate Array (FPGA), a Programmable Logic Array (PLA), a System-on-Chip, a System-on-Substrate, a System-on-Package, an Application-Specific Integrated Circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of software, hardware, and firmware methods, or in a suitable combination of any of these. Alternatively, at least one of the above-described modules can be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0117] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0118] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0119] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A key replacement method based on a fully automated safe deposit box system, wherein the fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform, and the low-level terminal is equipped with a keypad, characterized in that, The method includes: In response to a check-in transaction initiated by the low-counter terminal, the fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair, wherein the generated public-private key pair includes a public key and a private key that are paired together, the public key is stored in the fully automated safe deposit box system, and the private key is stored in the low-counter terminal; The fully automated safe deposit box system forwards the public key to the encryption service platform and initiates a request to the encryption service platform to generate a working key; Based on the generation request, the encryption service platform generates a first working key and a second working key, and returns the first working key and the second working key to the fully automated safe deposit box system. The fully automated safe deposit box system transmits the second working key to the low-level terminal, so that the low-level terminal can replace the private key with the second working key.

2. The key replacement method based on a fully automated safe deposit box system according to claim 1, characterized in that, The encryption service platform generates a first working key and a second working key based on the generation request, wherein; The first working key is the ciphertext used to verify the password, and the second working key is the key used to encrypt the public key.

3. A key replacement device based on a fully automated safe deposit box system, wherein the fully automated safe deposit box system is connected to a low-level terminal and an encryption service platform, and the low-level terminal is equipped with a keypad, characterized in that... The device includes: a public-private key pair generation module, a key request sending module, a working key generation module, and a key replacement module, wherein; The public-private key pair generation module is used to respond to the check-in transaction initiated by the low-counter terminal. The fully automated safe deposit box system calls the keypad to randomly generate a public-private key pair. The generated public-private key pair includes a public key and a private key that are paired with each other. The public key is stored in the fully automated safe deposit box system and the private key is stored in the low-counter terminal. The key request sending module is used by the fully automated safe deposit box system to forward the public key to the encryption service platform and to initiate a request to the encryption service platform to generate a working key; The working key generation module is used by the encryption service platform to generate a first working key and a second working key based on the generation request, and to return the first working key and the second working key to the fully automated safe deposit box system. The key replacement module is used by the fully automated safe deposit box system to transmit the second working key to the low cabinet terminal, so that the low cabinet terminal can replace the private key with the second working key.

Citation Information

Patent Citations

  • Novel payment method and device applying vein recognition

    CN110544098A

  • Data transmission method and device, electronic equipment and computer readable storage medium

    CN116961973A