Financial terminal authentication method, authentication device, program product and storage medium

By generating and managing SM2 certificates on the backend server and using MAC addresses and CPU serial numbers to verify the updated SM2 certificates of financial terminals, the problem of ID cards, facial recognition and SMS verification codes being easily tampered with is solved, and efficient and secure financial terminal authentication is achieved.

CN118916864BActive Publication Date: 2025-09-09中国邮政储蓄银行股份有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411102360.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-12
Publication Date
2025-09-09
Estimated Expiration
2044-08-12

AI Technical Summary

Technical Problem

Among existing financial terminal authentication methods, identity cards, facial recognition, and SMS verification codes are easily tampered with, and the validity of authentication cannot be guaranteed. At the same time, the cost of deploying hardware equipment is high.

Method used

By generating and managing SM2 certificates between the backend server and the financial terminal, using MAC address and CPU serial number for authentication, generating and updating SM2 certificates and storing them in the database, verifying whether the certificates have been tampered with, and denying or allowing access requests.

Benefits of technology

It improves the effectiveness of financial terminal authentication, reduces the deployment cost of hardware equipment, and ensures the security and reliability of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118916864B_ABST
    Figure CN118916864B_ABST
Patent Text Reader

Abstract

The present application provides a financial terminal authentication method, authentication device, program product, and storage medium. Upon receiving a registration request message from a financial terminal, the method generates and sends at least an updated SM2 certificate to the financial terminal, and stores at least the updated SM2 certificate and terminal information in a database. Upon receiving an access request message from the financial terminal, the method determines whether the updated SM2 certificate in the PIN pad has been tampered with based on at least verification data, the updated SM2 certificate in the database, and the terminal information in the database. If the updated SM2 certificate in the PIN pad has been tampered with, an access denial message is sent to the financial terminal. If the updated SM2 certificate in the PIN pad has not been tampered with, an access permission message is sent to the financial terminal. This method solves the problem in existing financial terminal authentication methods that cannot guarantee the validity of authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of financial terminal authentication, and in particular to a financial terminal authentication method, a financial terminal authentication device, a computer program product, and a computer-readable storage medium. Background Art

[0002] Currently, the problems with financial terminal authentication methods are as follows:

[0003] Only after passing the device access test, ID card test, face recognition test, bank card test and SMS verification code test in sequence can the financial terminal be activated and the application homepage can be accessed normally. These activation schemes have the problem that the ID card, face and SMS verification code are easily tampered with, and the validity of the authentication cannot be guaranteed.

[0004] Other hardware devices need to be deployed between the financial terminal and the backend server to assist in completing the financial terminal authentication, which is costly.

[0005] Currently, there is no solution to the above problem. Summary of the Invention

[0006] The main purpose of this application is to provide a financial terminal authentication method, a financial terminal authentication device, a computer program product and a computer-readable storage medium to at least solve the problems in the prior art.

[0007] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a financial terminal authentication method is provided, which is applied to a background server, which is communicatively connected to the financial terminal, and the background server has a database. The method includes: upon receiving the registration request information sent by the financial terminal, at least generating and sending an updated SM2 certificate to the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database, the registration request information indicating a request to complete the registration process of the financial terminal, the registration request information including: the terminal information and the initial SM2 certificate, the terminal information including: the MAC address of the financial terminal, the CPU serial number of the financial terminal, the initial SM2 certificate being the SM2 certificate in the password keyboard of the financial terminal when the financial terminal leaves the factory, the updated SM2 certificate being an SM2 certificate different from the initial SM2 certificate, and the financial terminal being used to store the updated SM2 certificate stored in the password keyboard; in the case of receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the password keyboard has been tampered with at least based on the verification data, the updated SM2 certificate in the database and the terminal information in the database, the access request information at least includes: the verification data, the verification data is obtained by the financial terminal at least using the updated SM2 certificate in the password keyboard to encrypt at least the terminal information, the access request information indicates a request to access the backend server; in the case of the updated SM2 certificate in the password keyboard being tampered with, sending a deny access information to the financial terminal, and in the case of the updated SM2 certificate in the password keyboard not being tampered with, sending a grant access information to the financial terminal, the deny access information indicating that the financial terminal is denied access to the backend server, and the grant access information indicating that the financial terminal is allowed to access the backend server.

[0008] Optionally, upon receiving the registration request information sent by the financial terminal, at least an updated SM2 certificate is generated and sent to the financial terminal, and at least the updated SM2 certificate and terminal information are stored in the database, including: upon receiving the registration request information sent by the financial terminal, verifying whether the initial SM2 certificate is valid; if the initial SM2 certificate is valid, at least an updated SM2 certificate is generated and sent to the financial terminal, and at least the terminal information and the updated SM2 certificate are stored in the database.

[0009] Optionally, when the access request information sent by the financial terminal is received, whether the updated SM2 certificate in the password keyboard has been tampered with is determined at least based on the verification data, the updated SM2 certificate in the database and the terminal information in the database, including: when the access request information sent by the financial terminal is received, the updated SM2 certificate and the terminal information are obtained from the database according to the terminal number of the financial terminal, the access request information includes: the terminal number of the financial terminal, the terminal number consists of numbers and letters, and the terminal numbers of any two financial terminals are different; at least based on the verification data, the updated SM2 certificate in the database and the terminal information in the database, whether the updated SM2 certificate in the password keyboard has been tampered with is determined.

[0010] Optionally, determining whether the updated SM2 certificate in the PIN keyboard has been tampered with is performed at least based on the verification data, the updated SM2 certificate in the database, and the terminal information in the database, including: using the updated SM2 certificate in the database to decrypt the verification data to obtain first summary information, and using the SM3 algorithm to encrypt at least the terminal information in the database to obtain second summary information, the verification data is obtained by the financial terminal sequentially encrypting at least the terminal information using the SM3 algorithm and the updated SM2 certificate in the PIN keyboard; when the first summary information is different from the second summary information, determining that the updated SM2 certificate in the PIN keyboard has been tampered with; when the first summary information is the same as the second summary information, determining that the updated SM2 certificate in the PIN keyboard has not been tampered with.

[0011] Optionally, the SM3 algorithm is used to encrypt at least the terminal information in the database to obtain second summary information, including: using the SM3 algorithm to encrypt the terminal information in the database and the terminal number of the financial terminal to obtain the second summary information, and the verification data is obtained by the financial terminal using the SM3 algorithm and the updated SM2 certificate in the password keyboard to encrypt the terminal information and the terminal number of the financial terminal in sequence.

[0012] Optionally, at least an updated SM2 certificate is generated and sent to the financial terminal, and the updated SM2 certificate and terminal information are stored in the database, including: generating the terminal number of the financial terminal at least based on the terminal information, the terminal number consisting of numbers and letters, and the terminal numbers of any two financial terminals are different; sending the updated SM2 certificate and the terminal number of the financial terminal to the financial terminal, and storing the terminal number of the financial terminal, the updated SM2 certificate, and the terminal information in the database, the financial terminal having a memory, and the financial terminal is used to store the terminal number of the financial terminal in the memory.

[0013] Optionally, generating the terminal number of the financial terminal at least based on the terminal information includes: generating the terminal number of the financial terminal based on the terminal information and area information, the area information including: the name of the area where the financial terminal is located.

[0014] According to another aspect of the present application, a financial terminal authentication device is provided, which is applied to a background server, which is communicatively connected to the financial terminal, and the background server has a database. The device includes: a generating and sending storage unit for generating and sending at least an updated SM2 certificate to the financial terminal upon receiving registration request information sent by the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database, wherein the registration request information indicates a request to complete the registration process of the financial terminal, and the registration request information includes: the terminal information and an initial SM2 certificate, and the terminal information includes: the MAC address of the financial terminal, the CPU serial number of the financial terminal, the initial SM2 certificate is the SM2 certificate in the password keyboard of the financial terminal when the financial terminal leaves the factory, the updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate, and the financial terminal is used to store the updated SM2 certificate in the password keyboard. keyboard; a determining unit, configured to, upon receiving an access request message sent by the financial terminal, determine whether the updated SM2 certificate in the password keyboard has been tampered with, at least based on verification data, the updated SM2 certificate in the database and the terminal information in the database, the access request message comprising at least: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the password keyboard, the access request message indicating a request to access the backend server; a sending unit, configured to, upon receiving an access request message sent by the financial terminal, send an access rejection message to the financial terminal, and upon receiving an access permission message, send an access permission message to the financial terminal, wherein the access rejection message indicates that the financial terminal is denied access to the backend server, and the access permission message indicates that the financial terminal is allowed access to the backend server.

[0015] According to another aspect of the present application, a computer program product is provided, comprising a computer program / instruction, which implements any one of the financial terminal authentication methods when executed by a processor.

[0016] According to another aspect of the present application, a computer-readable storage medium is provided, which includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute any one of the financial terminal authentication methods.

[0017] Applying the technical solution of the present application, first, upon receiving the registration request information sent by the financial terminal, at least an updated SM2 certificate is generated and sent to the financial terminal, and at least the updated SM2 certificate and terminal information are stored in the database; then, upon receiving the access request information sent by the financial terminal, at least based on the verification data, the updated SM2 certificate in the database and the terminal information in the database, it is determined whether the updated SM2 certificate in the password keyboard has been tampered with; finally, if the updated SM2 certificate in the password keyboard has been tampered with, an access denial message is sent to the financial terminal; if the updated SM2 certificate in the password keyboard has not been tampered with, an access permission message is sent to the financial terminal; the present application performs financial terminal authentication based on the MAC address and CPU serial number of the financial terminal. Since the MAC address and CPU serial number are difficult to be tampered with, the validity of the authentication can be guaranteed, thereby solving the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of a process flow of a financial terminal authentication method provided according to an embodiment of the present application is shown;

[0019] Figure 2 A schematic diagram of a process flow of a financial terminal authentication method provided according to an embodiment of the present application is shown;

[0020] Figure 3 The figure shows a structural block diagram of a financial terminal authentication device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0021] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0022] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0024] For ease of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0025] MAC (Media Access Control) address: It is a unique identifier for network devices (such as computers, mobile phones, routers, etc.) on the network. It is used to distinguish different devices. The MAC address consists of 48 hexadecimal digits, usually separated by colons or dashes. The MAC address of each device is unique and can be used to identify the device and communicate on the local area network. The MAC address is fixed when the device is manufactured and cannot be changed.

[0026] CPU (Central Processing Unit) serial number: refers to the unique identifier of the central processing unit, used to identify and distinguish different processors. The CPU serial number is usually assigned by the manufacturer during the production process and is used to help identify a specific processor. The CPU serial number can be viewed in a computer system through software or command-line tools. In some cases, the CPU serial number can also be used to verify the authenticity of the processor and prevent piracy.

[0027] As introduced in the background technology, the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication. In order to solve the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication, the embodiments of the present application provide a financial terminal authentication method, a financial terminal authentication device, a computer program product and a computer-readable storage medium.

[0028] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present invention.

[0029] In this embodiment, a financial terminal authentication method running on a backend server is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0030] Figure 1 Flowchart of the financial terminal authentication method according to the embodiment of the present application. Figure 1 As shown, the method includes the following steps:

[0031] Step S201: upon receiving a registration request from the financial terminal, generating and sending at least an updated SM2 certificate to the financial terminal, and storing the updated SM2 certificate and terminal information in the database;

[0032] The registration request information indicates a request to complete the registration process of the financial terminal. The registration request information includes: the terminal information and the initial SM2 certificate. The terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal. The initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory. The updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate. The financial terminal is used to store the updated SM2 certificate in the PIN pad.

[0033] Specifically, when the financial terminal leaves the factory, the initial SM2 certificate must first be entered into the password keyboard of the financial terminal. The financial terminal authorization registration process is as follows: when the financial terminal starts, the platform software starts automatically and displays the registration page. The operator clicks to register, and the financial terminal sends a registration request message to the background server, that is, the financial terminal uploads the terminal information and the initial SM2 certificate to the background server to request to complete the registration process. The background server regenerates the SM2 certificate for the financial terminal, that is, at least generates an updated SM2 certificate, and at least stores the updated SM2 certificate and terminal information in the database, and at least sends the updated SM2 certificate to the financial terminal. The financial terminal stores the updated SM2 certificate in the password keyboard. At this point, the terminal authorization registration is successful, and the platform software can be used normally.

[0034] In an optional solution, the above step S201 can be implemented as follows:

[0035] Step S2011: upon receiving the registration request information sent by the financial terminal, verify whether the initial SM2 certificate is valid;

[0036] Specifically, the initial SM2 certificate is stored in the database of the background server. During the authorization registration process of the financial terminal, the background server determines whether the initial SM2 certificate sent by the financial terminal is the same as the initial SM2 certificate in the database. If they are the same, it means that the initial SM2 certificate is valid. If they are different, it means that the initial SM2 certificate is invalid.

[0037] Step S2012: If the initial SM2 certificate is valid, at least generate and send an updated SM2 certificate to the financial terminal, and at least store the terminal information and the updated SM2 certificate in the database.

[0038] Specifically, during the authorization registration process of the financial terminal, if the initial SM2 certificate is valid, the backend server regenerates the SM2 certificate for the financial terminal, that is, at least generates an updated SM2 certificate, stores the updated SM2 certificate and terminal information in the database, and at least updates the SM2 certificate to the financial terminal.

[0039] In an optional solution, the above step S2012 can be implemented as follows:

[0040] Step S20121: generating a terminal number for the financial terminal based at least on the terminal information, wherein the terminal number is composed of numbers and letters, and the terminal numbers of any two financial terminals are different;

[0041] Specifically, during the authorization registration process of the financial terminal, the backend server generates a terminal number of the financial terminal based at least on the terminal information. This terminal number is unique, that is, the terminal numbers of different financial terminals are different.

[0042] Specifically, a hash algorithm may be used based on the terminal information to generate the terminal number of the financial terminal.

[0043] In an optional solution, the above step S20121 can be implemented as follows:

[0044] The terminal number of the financial terminal is generated according to the terminal information and the region information, wherein the region information includes the name of the region where the financial terminal is located.

[0045] Specifically, during the authorization registration process of the financial terminal, the backend server generates a terminal number of the financial terminal according to the terminal information and the region information, so as to increase the security of the terminal number of the financial terminal.

[0046] Step S20122, sending the updated SM2 certificate and the terminal number of the financial terminal to the financial terminal, and storing the terminal number of the financial terminal, the updated SM2 certificate and the terminal information in the database. The financial terminal has a memory, and the financial terminal is used to store the terminal number of the financial terminal in the memory.

[0047] Specifically, during the authorization registration process of the financial terminal, the backend server stores the terminal number, updated SM2 certificate and terminal information of the financial terminal in the database, and sends the updated SM2 certificate and the terminal number of the financial terminal to the financial terminal. The financial terminal stores the updated SM2 certificate in the password keyboard and stores the terminal number of the financial terminal in the memory.

[0048] Step S202, upon receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database;

[0049] The access request information at least includes: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, and the access request information indicating a request to access the backend server;

[0050] Specifically, the access authentication process of the financial terminal is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. At least the updated SM2 certificate in the password keyboard is used to encrypt the terminal information to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request information to the background server, that is, the financial terminal uploads the verification data to the background server. The background server determines whether the updated SM2 certificate in the password keyboard has been tampered with based on at least the verification data, the updated SM2 certificate in the database and the terminal information in the database.

[0051] In an optional solution, the above step S202 can be implemented as follows:

[0052] Step S2021: Upon receiving the access request information sent by the financial terminal, obtaining the updated SM2 certificate and the terminal information from the database based on the terminal number of the financial terminal, wherein the access request information includes: the terminal number of the financial terminal, which consists of numbers and letters and the terminal numbers of any two financial terminals are different;

[0053] Step S2022: determining whether the updated SM2 certificate in the PIN pad has been tampered with based at least on the verification data, the updated SM2 certificate in the database, and the terminal information in the database.

[0054] Specifically, the financial terminal access authentication process is as follows: the background server obtains the updated SM2 certificate and terminal information from the database based on the terminal number of the financial terminal. The background server determines whether the updated SM2 certificate in the password keyboard has been tampered with based on at least the verification data, the updated SM2 certificate in the database and the terminal information in the database.

[0055] In an optional solution, the above step S2022 can be implemented as follows:

[0056] Step S20221: Decrypt the verification data using the updated SM2 certificate in the database to obtain first digest information, and encrypt at least the terminal information in the database using the SM3 algorithm to obtain second digest information. The verification data is obtained by encrypting at least the terminal information using the SM3 algorithm and the updated SM2 certificate in the PIN pad.

[0057] Step S20222: When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with; when the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0058] Specifically, the access authentication process of the financial terminal is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. The SM3 algorithm and the updated SM2 certificate in the password keyboard are used in sequence to encrypt at least the terminal information to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request message to the background server, that is, the financial terminal uploads the verification data to the background server. The background server uses the updated SM2 certificate in the database to decrypt the verification data to obtain the first summary information, and uses the SM3 algorithm to encrypt at least the terminal information in the database to obtain the second summary information. When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with. When the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0059] Specifically, the financial terminal sequentially uses the SM3 algorithm and the updated SM2 certificate in the PIN pad to encrypt at least the terminal information, adopting a double encryption algorithm to further enhance the security of transmission.

[0060] In an optional solution, the step S20221 of encrypting at least the terminal information in the database using the SM3 algorithm to obtain the second summary information may be implemented as follows:

[0061] The terminal information in the database and the terminal number of the financial terminal are encrypted using the SM3 algorithm to obtain the second summary information. The verification data is obtained by the financial terminal using the SM3 algorithm and the updated SM2 certificate in the password keyboard to encrypt the terminal information and the terminal number of the financial terminal.

[0062] Specifically, the financial terminal access authentication process is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. The SM3 algorithm and the updated SM2 certificate in the password keyboard are used in turn to encrypt the terminal information and the terminal number of the financial terminal to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request message to the background server, that is, the financial terminal uploads the verification data to the background server. The background server uses the updated SM2 certificate in the database to decrypt the verification data to obtain the first summary information, and uses the SM3 algorithm to encrypt the terminal information and the terminal number of the financial terminal in the database to obtain the second summary information. When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with. When the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0063] Specifically, since the terminal number is difficult to be tampered with, the validity of the authentication can be further guaranteed.

[0064] Step S203: If the updated SM2 certificate in the PIN pad has been tampered with, sending an access denial message to the financial terminal; if the updated SM2 certificate in the PIN pad has not been tampered with, sending an access permission message to the financial terminal;

[0065] The access-denying information indicates that the financial terminal is denied access to the backend server, and the access-allowing information indicates that the financial terminal is allowed to access the backend server.

[0066] Specifically, if the updated SM2 certificate in the password keyboard is tampered with, the financial terminal is deemed illegal, and an access denial message is sent to the financial terminal, denying the financial terminal access to the backend server. If the updated SM2 certificate in the password keyboard is not tampered with, the financial terminal is deemed legal, and an access permission message is sent to the financial terminal, allowing the financial terminal to access the backend server, so that the operator can normally access the application homepage and perform normal business operations.

[0067] Specifically, the present application does not require deployment of other hardware devices between the financial terminal and the backend server, thereby reducing the authentication cost of the financial terminal.

[0068] Through the above embodiment, first, when the registration request information sent by the above-mentioned financial terminal is received, at least the updated SM2 certificate is generated and sent to the above-mentioned financial terminal, and at least the updated SM2 certificate and the terminal information are stored in the above-mentioned database. Then, when the access request information sent by the above-mentioned financial terminal is received, at least based on the verification data, the updated SM2 certificate in the above-mentioned database and the above-mentioned terminal information in the above-mentioned database, it is determined whether the updated SM2 certificate in the above-mentioned password keyboard has been tampered with. Finally, when the updated SM2 certificate in the above-mentioned password keyboard has been tampered with, an access denial message is sent to the above-mentioned financial terminal. When the updated SM2 certificate in the above-mentioned password keyboard has not been tampered with, an access permission message is sent to the above-mentioned financial terminal. The present application performs financial terminal authentication based on the MAC address and CPU serial number of the financial terminal. Since the MAC address and the CPU serial number are difficult to be tampered with, the validity of the authentication can be guaranteed, thereby solving the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication.

[0069] In order to enable those skilled in the art to more clearly understand the technical solution of the present application, the implementation process of the financial terminal authentication method of the present application will be described in detail below with reference to specific embodiments.

[0070] This embodiment relates to a specific financial terminal authentication method, such as Figure 2 As shown, the following steps are included:

[0071] Step S1: upon receiving the registration request information sent by the financial terminal, verifying whether the initial SM2 certificate is valid, wherein the registration request information indicates a request to complete the registration process of the financial terminal, and the registration request information includes: the terminal information and the initial SM2 certificate, wherein the terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal, the initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory, the updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate, and the financial terminal is used to store the updated SM2 certificate in the PIN pad;

[0072] Step S2: if the initial SM2 certificate is valid, generating the terminal number of the financial terminal based on the terminal information and the region information, wherein the region information includes the name of the region where the financial terminal is located;

[0073] Step S3: sending the updated SM2 certificate and the terminal number of the financial terminal to the financial terminal, and storing the terminal number of the financial terminal, the updated SM2 certificate, and the terminal information in the database; the financial terminal has a memory, and the financial terminal is used to store the terminal number of the financial terminal in the memory;

[0074] Step S4: upon receiving the access request information sent by the financial terminal, obtaining the updated SM2 certificate and the terminal information from the database according to the terminal number of the financial terminal;

[0075] Step S5: Decrypting the verification data using the updated SM2 certificate in the database to obtain first digest information, and encrypting the terminal information in the database and the terminal number of the financial terminal using the SM3 algorithm to obtain the second digest information. The verification data is obtained by encrypting the terminal information and the terminal number of the financial terminal using the SM3 algorithm and the updated SM2 certificate in the PIN pad in sequence.

[0076] Step S6: When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with; when the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0077] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0078] The embodiments of the present application also provide a financial terminal authentication device. It should be noted that the financial terminal authentication device of the embodiments of the present application can be used to execute the financial terminal authentication method provided in the embodiments of the present application. This device is used to implement the above-mentioned embodiments and preferred embodiments, and the details already described will not be repeated here. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0079] The following introduces the financial terminal authentication device provided in the embodiment of the present application.

[0080] Figure 3 : is a structural block diagram of a financial terminal authentication device according to an embodiment of the present application. Figure 3 As shown, the device includes:

[0081] A generating and sending storage unit 10 is configured to generate and send at least an updated SM2 certificate to the financial terminal upon receiving the registration request information sent by the financial terminal, and store the updated SM2 certificate and terminal information in the database;

[0082] The registration request information indicates a request to complete the registration process of the financial terminal. The registration request information includes: the terminal information and the initial SM2 certificate. The terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal. The initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory. The updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate. The financial terminal is used to store the updated SM2 certificate in the PIN pad.

[0083] Specifically, when the financial terminal leaves the factory, the initial SM2 certificate must first be entered into the password keyboard of the financial terminal. The financial terminal authorization registration process is as follows: when the financial terminal starts, the platform software starts automatically and displays the registration page. The operator clicks to register, and the financial terminal sends a registration request message to the background server, that is, the financial terminal uploads the terminal information and the initial SM2 certificate to the background server to request to complete the registration process. The background server regenerates the SM2 certificate for the financial terminal, that is, at least generates an updated SM2 certificate, and at least stores the updated SM2 certificate and terminal information in the database, and at least sends the updated SM2 certificate to the financial terminal. The financial terminal stores the updated SM2 certificate in the password keyboard. At this point, the terminal authorization registration is successful, and the platform software can be used normally.

[0084] In an optional solution, the generating and sending storage unit includes:

[0085] a verification subunit, configured to verify whether the initial SM2 certificate is valid upon receiving the registration request information sent by the financial terminal;

[0086] Specifically, the initial SM2 certificate is stored in the database of the background server. During the authorization registration process of the financial terminal, the background server determines whether the initial SM2 certificate sent by the financial terminal is the same as the initial SM2 certificate in the database. If they are the same, it means that the initial SM2 certificate is valid. If they are different, it means that the initial SM2 certificate is invalid.

[0087] The generating, sending and storing subunit is configured to generate and send at least an updated SM2 certificate to the financial terminal when the initial SM2 certificate is valid, and store at least the terminal information and the updated SM2 certificate in the database.

[0088] Specifically, during the authorization registration process of the financial terminal, if the initial SM2 certificate is valid, the backend server regenerates the SM2 certificate for the financial terminal, that is, at least generates an updated SM2 certificate, stores the updated SM2 certificate and terminal information in the database, and at least updates the SM2 certificate to the financial terminal.

[0089] In an optional solution, the generating and sending storage subunit includes:

[0090] a generating module, configured to generate a terminal number of the financial terminal based at least on the terminal information, wherein the terminal number is composed of numbers and letters, and the terminal numbers of any two financial terminals are different;

[0091] Specifically, during the authorization registration process of the financial terminal, the backend server generates a terminal number of the financial terminal based at least on the terminal information. This terminal number is unique, that is, the terminal numbers of different financial terminals are different.

[0092] Specifically, a hash algorithm may be used based on the terminal information to generate the terminal number of the financial terminal.

[0093] In an optional solution, the above generation module is used to:

[0094] The terminal number of the financial terminal is generated according to the terminal information and the region information, wherein the region information includes the name of the region where the financial terminal is located.

[0095] Specifically, during the authorization registration process of the financial terminal, the backend server generates a terminal number of the financial terminal according to the terminal information and the region information, so as to increase the security of the terminal number of the financial terminal.

[0096] A sending storage module is used to send the above-mentioned updated SM2 certificate and the above-mentioned terminal number of the above-mentioned financial terminal to the above-mentioned financial terminal, and store the above-mentioned terminal number of the above-mentioned financial terminal, the above-mentioned updated SM2 certificate, and the above-mentioned terminal information in the above-mentioned database. The above-mentioned financial terminal has a memory, and the above-mentioned financial terminal is used to store the above-mentioned terminal number of the above-mentioned financial terminal in the above-mentioned memory.

[0097] Specifically, during the authorization registration process of the financial terminal, the backend server stores the terminal number, updated SM2 certificate and terminal information of the financial terminal in the database, and sends the updated SM2 certificate and the terminal number of the financial terminal to the financial terminal. The financial terminal stores the updated SM2 certificate in the password keyboard and stores the terminal number of the financial terminal in the memory.

[0098] a determination unit 20 configured to, upon receiving the access request information sent by the financial terminal, determine whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database;

[0099] The access request information at least includes: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, and the access request information indicating a request to access the backend server;

[0100] Specifically, the access authentication process of the financial terminal is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. At least the updated SM2 certificate in the password keyboard is used to encrypt the terminal information to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request information to the background server, that is, the financial terminal uploads the verification data to the background server. The background server determines whether the updated SM2 certificate in the password keyboard has been tampered with based on at least the verification data, the updated SM2 certificate in the database and the terminal information in the database.

[0101] In an optional solution, the determining unit includes:

[0102] an acquiring subunit, configured to, upon receiving the access request information sent by the financial terminal, acquire the updated SM2 certificate and the terminal information from the database based on the terminal number of the financial terminal, wherein the access request information includes: the terminal number of the financial terminal, the terminal number consisting of numbers and letters, and the terminal numbers of any two financial terminals being different;

[0103] The determining subunit is configured to determine whether the updated SM2 certificate in the PIN pad has been tampered with based at least on the verification data, the updated SM2 certificate in the database, and the terminal information in the database.

[0104] Specifically, the financial terminal access authentication process is as follows: the background server obtains the updated SM2 certificate and terminal information from the database based on the terminal number of the financial terminal. The background server determines whether the updated SM2 certificate in the password keyboard has been tampered with based on at least the verification data, the updated SM2 certificate in the database and the terminal information in the database.

[0105] In an optional solution, the above-mentioned determination subunit includes:

[0106] a decryption module configured to decrypt the verification data using the updated SM2 certificate in the database to obtain first digest information, and encrypt at least the terminal information in the database using the SM3 algorithm to obtain second digest information, wherein the verification data is obtained by encrypting at least the terminal information by the financial terminal using the SM3 algorithm and the updated SM2 certificate in the PIN pad in sequence;

[0107] A determination module is used to determine that the updated SM2 certificate in the password keyboard has been tampered with when the first summary information is different from the second summary information; and to determine that the updated SM2 certificate in the password keyboard has not been tampered with when the first summary information is the same as the second summary information.

[0108] Specifically, the access authentication process of the financial terminal is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. The SM3 algorithm and the updated SM2 certificate in the password keyboard are used in sequence to encrypt at least the terminal information to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request message to the background server, that is, the financial terminal uploads the verification data to the background server. The background server uses the updated SM2 certificate in the database to decrypt the verification data to obtain the first summary information, and uses the SM3 algorithm to encrypt at least the terminal information in the database to obtain the second summary information. When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with. When the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0109] Specifically, the financial terminal sequentially uses the SM3 algorithm and the updated SM2 certificate in the PIN pad to encrypt at least the terminal information, adopting a double encryption algorithm to further enhance the security of transmission.

[0110] In an optional solution, the above-mentioned determination module is used to:

[0111] The terminal information in the database and the terminal number of the financial terminal are encrypted using the SM3 algorithm to obtain the second summary information. The verification data is obtained by the financial terminal using the SM3 algorithm and the updated SM2 certificate in the password keyboard to encrypt the terminal information and the terminal number of the financial terminal.

[0112] Specifically, the financial terminal access authentication process is as follows: when the financial terminal is started, the platform software starts automatically and enters the application homepage for initialization. The financial terminal obtains the terminal information and the updated SM2 certificate in the password keyboard. At this time, the updated SM2 certificate in the password keyboard may have been tampered with or not. The SM3 algorithm and the updated SM2 certificate in the password keyboard are used in turn to encrypt the terminal information and the terminal number of the financial terminal to obtain verification data. The application homepage makes an initialization request, and the financial terminal sends an access request message to the background server, that is, the financial terminal uploads the verification data to the background server. The background server uses the updated SM2 certificate in the database to decrypt the verification data to obtain the first summary information, and uses the SM3 algorithm to encrypt the terminal information and the terminal number of the financial terminal in the database to obtain the second summary information. When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the password keyboard has been tampered with. When the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the password keyboard has not been tampered with.

[0113] Specifically, since the terminal number is difficult to be tampered with, the validity of the authentication can be further guaranteed.

[0114] The sending unit 30 is configured to send an access denial message to the financial terminal if the updated SM2 certificate in the PIN pad is tampered with, and send an access permission message to the financial terminal if the updated SM2 certificate in the PIN pad is not tampered with;

[0115] The access-denying information indicates that the financial terminal is denied access to the backend server, and the access-allowing information indicates that the financial terminal is allowed to access the backend server.

[0116] Specifically, if the updated SM2 certificate in the password keyboard is tampered with, the financial terminal is deemed illegal, and an access denial message is sent to the financial terminal, denying the financial terminal access to the backend server. If the updated SM2 certificate in the password keyboard is not tampered with, the financial terminal is deemed legal, and an access permission message is sent to the financial terminal, allowing the financial terminal to access the backend server, so that the operator can normally access the application homepage and perform normal business operations.

[0117] Specifically, the present application does not require deployment of other hardware devices between the financial terminal and the backend server, thereby reducing the authentication cost of the financial terminal.

[0118] Through the above embodiment, first, when the registration request information sent by the above-mentioned financial terminal is received, at least the updated SM2 certificate is generated and sent to the above-mentioned financial terminal, and at least the updated SM2 certificate and the terminal information are stored in the above-mentioned database. Then, when the access request information sent by the above-mentioned financial terminal is received, at least based on the verification data, the updated SM2 certificate in the above-mentioned database and the above-mentioned terminal information in the above-mentioned database, it is determined whether the updated SM2 certificate in the above-mentioned password keyboard has been tampered with. Finally, when the updated SM2 certificate in the above-mentioned password keyboard has been tampered with, an access denial message is sent to the above-mentioned financial terminal. When the updated SM2 certificate in the above-mentioned password keyboard has not been tampered with, an access permission message is sent to the above-mentioned financial terminal. The present application performs financial terminal authentication based on the MAC address and CPU serial number of the financial terminal. Since the MAC address and the CPU serial number are difficult to be tampered with, the validity of the authentication can be guaranteed, thereby solving the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication.

[0119] The financial terminal authentication device includes a processor and memory. The aforementioned units are stored as program units in the memory, and the processor executes the program units stored in the memory to implement the corresponding functions. The aforementioned modules are all located in the same processor; alternatively, the aforementioned modules may be located in different processors in any combination.

[0120] The processor includes a core, which retrieves the corresponding program unit from the memory. One or more cores can be set, and the problem of the inability of the existing financial terminal authentication method to ensure the validity of the authentication can be solved by adjusting the core parameters.

[0121] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0122] An embodiment of the present invention provides a computer-readable storage medium, which includes a stored program. When the program is executed, the device where the computer-readable storage medium is located is controlled to execute the financial terminal authentication method.

[0123] Specifically, the financial terminal authentication method includes:

[0124] Step S201: upon receiving a registration request from the financial terminal, generating and sending at least an updated SM2 certificate to the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database;

[0125] The registration request information indicates a request to complete the registration process of the financial terminal. The registration request information includes: the terminal information and the initial SM2 certificate. The terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal. The initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory. The updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate. The financial terminal is used to store the updated SM2 certificate in the PIN pad.

[0126] Step S202, upon receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database;

[0127] The access request information at least includes: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, and the access request information indicating a request to access the backend server;

[0128] Step S203: If the updated SM2 certificate in the PIN pad has been tampered with, sending an access denial message to the financial terminal; if the updated SM2 certificate in the PIN pad has not been tampered with, sending an access permission message to the financial terminal;

[0129] The access-denying information indicates that the financial terminal is denied access to the backend server, and the access-allowing information indicates that the financial terminal is allowed to access the backend server.

[0130] An embodiment of the present invention provides a processor, which is used to run a program, wherein the financial terminal authentication method is executed when the program is run.

[0131] Specifically, the financial terminal authentication method includes:

[0132] Step S201: upon receiving a registration request from the financial terminal, generating and sending at least an updated SM2 certificate to the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database;

[0133] The registration request information indicates a request to complete the registration process of the financial terminal. The registration request information includes: the terminal information and the initial SM2 certificate. The terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal. The initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory. The updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate. The financial terminal is used to store the updated SM2 certificate in the PIN pad.

[0134] Step S202, upon receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database;

[0135] The access request information at least includes: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, and the access request information indicating a request to access the backend server;

[0136] Step S203: If the updated SM2 certificate in the PIN pad has been tampered with, sending an access denial message to the financial terminal; if the updated SM2 certificate in the PIN pad has not been tampered with, sending an access permission message to the financial terminal;

[0137] The access-denying information indicates that the financial terminal is denied access to the backend server, and the access-allowing information indicates that the financial terminal is allowed to access the backend server.

[0138] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program for initializing at least the following method steps:

[0139] Step S201: upon receiving a registration request from the financial terminal, generating and sending at least an updated SM2 certificate to the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database;

[0140] The registration request information indicates a request to complete the registration process of the financial terminal. The registration request information includes: the terminal information and the initial SM2 certificate. The terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal. The initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory. The updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate. The financial terminal is used to store the updated SM2 certificate in the PIN pad.

[0141] Step S202, upon receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database;

[0142] The access request information at least includes: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, and the access request information indicating a request to access the backend server;

[0143] Step S203: If the updated SM2 certificate in the PIN pad has been tampered with, sending an access denial message to the financial terminal; if the updated SM2 certificate in the PIN pad has not been tampered with, sending an access permission message to the financial terminal;

[0144] The access-denying information indicates that the financial terminal is denied access to the backend server, and the access-allowing information indicates that the financial terminal is allowed to access the backend server.

[0145] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, can be centralized on a single computing device, or can be distributed across a network of multiple computing devices. They can be implemented using program code executable by the computing device, and thus, can be stored in a storage device and executed by the computing device. In some cases, the steps shown or described herein can be performed in a different order than that shown, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0146] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0147] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0148] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0149] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0150] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0151] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0152] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0153] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0154] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0155] 1) In the financial terminal authentication method of the present application, first, when the registration request information sent by the above-mentioned financial terminal is received, at least an updated SM2 certificate is generated and sent to the above-mentioned financial terminal, and at least the updated SM2 certificate and the terminal information are stored in the above-mentioned database. Then, when the access request information sent by the above-mentioned financial terminal is received, at least based on the verification data, the updated SM2 certificate in the above-mentioned database and the above-mentioned terminal information in the above-mentioned database, it is determined whether the above-mentioned updated SM2 certificate in the above-mentioned password keyboard has been tampered with. Finally, if the above-mentioned updated SM2 certificate in the above-mentioned password keyboard has been tampered with, an access denial message is sent to the above-mentioned financial terminal. If the above-mentioned updated SM2 certificate in the above-mentioned password keyboard has not been tampered with, an access permission message is sent to the above-mentioned financial terminal. The present application performs financial terminal authentication based on the MAC address and CPU serial number of the financial terminal. Since the MAC address and the CPU serial number are difficult to be tampered with, the validity of the authentication can be guaranteed, thereby solving the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication.

[0156] 2) In the financial terminal authentication method of the present application, first, when the registration request information sent by the above-mentioned financial terminal is received, at least an updated SM2 certificate is generated and sent to the above-mentioned financial terminal, and at least the updated SM2 certificate and the terminal information are stored in the above-mentioned database. Then, when the access request information sent by the above-mentioned financial terminal is received, at least based on the verification data, the updated SM2 certificate in the above-mentioned database and the above-mentioned terminal information in the above-mentioned database, it is determined whether the updated SM2 certificate in the above-mentioned password keyboard has been tampered with. Finally, if the updated SM2 certificate in the above-mentioned password keyboard has been tampered with, an access denial message is sent to the above-mentioned financial terminal. If the updated SM2 certificate in the above-mentioned password keyboard has not been tampered with, an access permission message is sent to the above-mentioned financial terminal. The present application performs financial terminal authentication based on the MAC address and CPU serial number of the financial terminal. Since the MAC address and the CPU serial number are difficult to be tampered with, the validity of the authentication can be guaranteed, thereby solving the problem that the financial terminal authentication method in the prior art cannot guarantee the validity of the authentication.

[0157] The above description is merely a preferred embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.

Claims

1. A financial terminal authentication method, characterized in that: The method is applied to a backend server, the backend server is in communication with a financial terminal, and the backend server has a database. The method includes: Upon receiving the registration request information sent by the financial terminal, at least an updated SM2 certificate is generated and sent to the financial terminal, and at least the updated SM2 certificate and terminal information are stored in the database, wherein the registration request information indicates a request to complete the registration process of the financial terminal, and the registration request information includes: the terminal information and the initial SM2 certificate, and the terminal information includes: the MAC address of the financial terminal and the CPU serial number of the financial terminal, the initial SM2 certificate is the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory, and the updated SM2 certificate is an SM2 certificate different from the initial SM2 certificate, and the financial terminal is used to store the updated SM2 certificate in the PIN pad; Upon receiving an access request message sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least verification data, the updated SM2 certificate in the database, and the terminal information in the database, the access request message comprising at least: the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, the access request message indicating a request for access to the backend server; In the event that the updated SM2 certificate in the password keyboard is tampered with, an access denial message is sent to the financial terminal. In the event that the updated SM2 certificate in the password keyboard is not tampered with, an access permission message is sent to the financial terminal. The access denial message indicates that the financial terminal is denied access to the backend server, and the access permission message indicates that the financial terminal is allowed to access the backend server.

2. The method according to claim 1, characterized in that Upon receiving the registration request information sent by the financial terminal, at least generating and sending an updated SM2 certificate to the financial terminal, and storing at least the updated SM2 certificate and terminal information in the database, including: Upon receiving the registration request information sent by the financial terminal, verifying whether the initial SM2 certificate is valid; If the initial SM2 certificate is valid, at least an updated SM2 certificate is generated and sent to the financial terminal, and at least the terminal information and the updated SM2 certificate are stored in the database.

3. The method according to claim 1, characterized in that Upon receiving the access request information sent by the financial terminal, determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database, includes: Upon receiving the access request information sent by the financial terminal, obtaining the updated SM2 certificate and the terminal information from the database according to the terminal number of the financial terminal, the access request information including: the terminal number of the financial terminal, the terminal number consisting of numbers and letters, and the terminal numbers of any two financial terminals being different; Determine whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database.

4. The method according to claim 3, characterized in that Determining whether the updated SM2 certificate in the PIN pad has been tampered with based on at least the verification data, the updated SM2 certificate in the database, and the terminal information in the database includes: decrypting the verification data using the updated SM2 certificate in the database to obtain first digest information, and encrypting at least the terminal information in the database using the SM3 algorithm to obtain second digest information, wherein the verification data is obtained by encrypting at least the terminal information by the financial terminal using the SM3 algorithm and the updated SM2 certificate in the PIN pad in sequence; When the first summary information is different from the second summary information, it is determined that the updated SM2 certificate in the PIN pad has been tampered with. When the first summary information is the same as the second summary information, it is determined that the updated SM2 certificate in the PIN pad has not been tampered with.

5. The method according to claim 4, characterized in that The SM3 algorithm is used to encrypt at least the terminal information in the database to obtain second summary information, including: The terminal information in the database and the terminal number of the financial terminal are encrypted using the SM3 algorithm to obtain the second summary information. The verification data is obtained by the financial terminal encrypting the terminal information and the terminal number of the financial terminal using the SM3 algorithm and the updated SM2 certificate in the password keyboard in sequence.

6. The method according to claim 2 or 3, characterized in that At least generating and sending an updated SM2 certificate to the financial terminal, and storing the updated SM2 certificate and terminal information in the database, including: generating a terminal number of the financial terminal based at least on the terminal information, the terminal number consisting of numbers and letters, and the terminal numbers of any two financial terminals are different; The updated SM2 certificate and the terminal number of the financial terminal are sent to the financial terminal, and the terminal number of the financial terminal, the updated SM2 certificate, and the terminal information are stored in the database. The financial terminal has a memory, and the financial terminal is used to store the terminal number of the financial terminal in the memory.

7. The method according to claim 6, characterized in that Generating the terminal number of the financial terminal based at least on the terminal information includes: The terminal number of the financial terminal is generated according to the terminal information and the area information, wherein the area information includes: the name of the area where the financial terminal is located.

8. A financial terminal authentication device, characterized in that: The device is applied to a backend server, which is in communication with a financial terminal and has a database. The device includes: a generating and sending storage unit, configured to, upon receiving registration request information sent by the financial terminal, at least generate and send an updated SM2 certificate to the financial terminal, and store at least the updated SM2 certificate and terminal information in the database, wherein the registration request information indicates a request to complete the registration process of the financial terminal, the registration request information including: the terminal information and the initial SM2 certificate, the terminal information including: the MAC address of the financial terminal and the CPU serial number of the financial terminal, the initial SM2 certificate being the SM2 certificate in the PIN pad of the financial terminal when the financial terminal leaves the factory, the updated SM2 certificate being an SM2 certificate different from the initial SM2 certificate, and the financial terminal being configured to store the updated SM2 certificate in the PIN pad; a determining unit, configured to, upon receiving access request information sent by the financial terminal, determine whether the updated SM2 certificate in the PIN pad has been tampered with based on at least verification data, the updated SM2 certificate in the database, and the terminal information in the database, the access request information comprising at least the verification data, the verification data being obtained by the financial terminal encrypting at least the terminal information using at least the updated SM2 certificate in the PIN pad, the access request information indicating a request for access to the backend server; A sending unit is used to send a denial of access information to the financial terminal when the updated SM2 certificate in the password keyboard is tampered with, and to send a permission of access information to the financial terminal when the updated SM2 certificate in the password keyboard is not tampered with, wherein the denial of access information indicates that the financial terminal is denied access to the backend server, and the permission of access information indicates that the financial terminal is allowed to access the backend server.

9. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the financial terminal authentication method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the financial terminal authentication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Terminal authentication method and device

    CN106452772A

  • Certificate importing method and terminal

    WO2019178763A1