A secure encryption method, device and product suitable for payment system
By adopting a two-layer encryption mechanism, dynamic key management and adjustable BCrypt encryption algorithm in the payment system, the shortcomings of existing payment systems in terms of security and user experience are solved, and higher security and performance are achieved.
Patent Information
- Application Number
- CN202510098413.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing payment systems have shortcomings in terms of security and user experience, including the lack of multi-level security measures, a single encryption mechanism, insufficient key management, the system does not support tripartite integration and unclear performance architecture.
The authorization token is encrypted using a two-layer encryption mechanism and an optimization method of dynamic key generation and rotation. The BCrypt encryption algorithm is optimized through adjustable working factors, and user privacy data is encrypted, and authorized and verified through the OAuth 2.0 protocol.
It improves the security and user experience of the system, improves the performance and flexibility of the payment system, and can more effectively protect user data and realize cross-platform and cross-regional interconnection.
Smart Images

Figure CN119539807B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a security encryption method, device and product suitable for a payment system. Background Art
[0002] The original microservice architecture used by the payment system for overseas countries is relatively simple, focusing mainly on meeting the decoupling requirements between services of a single project, and only realizing the basic communication functions between services. Under this architecture, the system completes the generation and distribution of tokens through tool classes, but lacks a unified management mechanism for token verification. In addition, no effective solution is provided for the problem of non-sense refresh during user use, resulting in users having to log in again frequently, significantly reducing the user experience. At the same time, the system still has deficiencies in supporting the international three-party request protocol standard, and cannot meet the needs of the payment system to open up resources to the outside world. As a modern payment system, it is urgent to provide efficient and secure interfaces to facilitate third-party companies or service providers to call payment services, thereby achieving cross-platform and cross-regional interconnection and interoperability, and improving the flexibility and internationalization capabilities of the system.
[0003] Security issues: The existing payment system has Spring Security (a security framework) at the application layer, which is deployed in the security framework of each microservice. However, the system lacks multi-level security measures, such as end-to-end encryption, multi-factor authentication, real-time monitoring, and anomaly detection.
[0004] The existing payment system has shortcomings in the encryption and storage of user sensitive information, which are mainly manifested in the single encryption mechanism, reliance on fixed algorithms such as the Advanced Encryption Standard 256 (AES-256) with a 256-bit key length or the Secure Hash Algorithm (SHA-256) with a 256-bit key length, and lack of high-level security support; key management is not sophisticated enough, and static keys are usually used for encryption without key rotation, expiration and backup mechanisms. Once the key is compromised, user data will face extremely high risks; the current payment system has multi-level encryption protection measures, and different encryption strategies are not applied to stored data and transmitted data respectively, resulting in the same protection of sensitive data under different security requirements, and unable to respond to complex security threats in a targeted manner; the existing encryption methods have limited ability to resist decryption, lack dynamic encryption and adaptive algorithm adjustment capabilities, and it is difficult to optimize the encryption strategy in real time according to the evolution of hardware performance and attack methods, resulting in a gradual decline in the effect of user privacy protection during long-term operation.
[0005] The system does not support third-party integration. The current system does not have good third-party integration support capabilities. Third-party integration refers to allowing another company's product to apply for the use rights of our payment products to achieve multi-platform and multi-field payment, which limits the flexibility and convenience of external service and application access, and is difficult to meet the increasingly diverse business needs.
[0006] The performance and architecture of the existing microservice architecture are unclear, which is not conducive to business expansion. The system lacks standardization and optimization in the selection of communication methods between services, and fails to make reasonable choices between communication methods such as HTTP and Remote Procedure Call (RPC), resulting in low reliability and efficiency of service communication. Summary of the invention
[0007] The present invention aims to solve at least one of the technical problems existing in the related art. To this end, the present invention provides a secure encryption method, device and product suitable for a payment system, which encrypts an authorization token through a double-layer encryption mechanism and an optimized method for dynamic key generation and rotation; optimizes the BCrypt (cross-platform file encryption tool) encryption algorithm through an adjustable work factor, and encrypts user privacy data through the optimized BCrypt encryption algorithm.
[0008] The present invention provides a security encryption method applicable to a payment system, comprising:
[0009] The dynamic key is obtained by optimizing the dynamic key generation and rotation method;
[0010] Encrypt the authorization token through a double-layer encryption mechanism and dynamic key;
[0011] By adjusting the work factor, the target work factor is obtained, and the encryption salt is optimized through dynamic keys to obtain encryption salt protection;
[0012] Optimize BCrypt encryption algorithm through target work factor and encryption salt protection;
[0013] Encrypt user privacy data using the optimized BCrypt encryption algorithm;
[0014] Encrypt the payment system by encrypting authorization tokens and encrypting user privacy data.
[0015] According to a security encryption method applicable to a payment system provided by the present invention, the optimization method for dynamic key generation and rotation includes:
[0016] The dynamic key ID generated based on the timestamp and the random number is stored in the key pool;
[0017] Parse the header key of the authorization token to obtain the header key ID, search for the dynamic key ID in the key pool based on the header key ID, and obtain the dynamic key;
[0018] Decrypt the payload of the authorization token using the dynamic key.
[0019] A secure encryption method applicable to a payment system provided according to the present invention also includes the double-layer encryption mechanism embedding a key into the header of an authorization token and performing AES-256 encryption on the payload portion of the authorization token.
[0020] A secure encryption method applicable to a payment system provided by the present invention also includes a dynamic key ID generated based on a timestamp and a random number, including:
[0021] Get the current system timestamp;
[0022] Use a random number generator to generate a random number of fixed length;
[0023] Combine the timestamp with the random number to obtain the dynamic key ID. The calculation expression of the dynamic key ID is:
[0024]
[0025] in, is the dynamic key ID, is the SHA-256 hash algorithm, is the current system timestamp, A random number generated by the random number generator.
[0026] According to a security encryption method applicable to a payment system provided by the present invention, the method further includes adjusting the work factor to obtain a target work factor, including:
[0027] Set the target encryption time and threshold and initialize the work factor,
[0028] If the time required for encryption is less than the target encryption time and the difference between the time required for encryption and the target encryption time is greater than or equal to the threshold, increase the work factor;
[0029] If the time required for encryption is greater than the target encryption time and the difference between the time required for encryption and the target encryption time is greater than or equal to the threshold, then reduce the work factor;
[0030] If the difference between the time required for encryption and the target encryption time is less than the threshold, the adjustment is terminated;
[0031] The calculation expression of the target work factor is:
[0032]
[0033] in, is the target work factor, The time required to encrypt for the current work factor, Encrypt time for the target, is the value of the variable when the objective function reaches its minimum value.
[0034] A secure encryption method suitable for a payment system provided by the present invention also includes a BCrypt encryption algorithm and encryption salt protection. A 16-byte random salt value is automatically generated through the BCrypt encryption algorithm, and the random salt value is mixed with a dynamic key to optimize the encryption salt to obtain encryption salt protection.
[0035] According to a security encryption method applicable to a payment system provided by the present invention, the payment system also adopts the OAuth 2.0 protocol for authorization and verification, and the OAuth 2.0 protocol has a built-in refresh token and a customized refresh filter.
[0036] According to a security encryption method suitable for a payment system provided by the present invention, the OAuth 2.0 protocol also includes an access token, the access token is used for user identity authentication and authorization to access resources, the refresh token re-acquires a new access token after the access token expires, and the refresh filter automatically detects within T time before the end of the validity period of the access token.
[0037] The present invention also provides a security encryption device applicable to a payment system, which is used to execute any of the above-mentioned security encryption methods applicable to a payment system, including:
[0038] A dynamic key acquisition module, wherein the dynamic key acquisition module obtains a dynamic key through an optimization method of dynamic key generation and rotation;
[0039] An authorization token encryption module, wherein the authorization token encryption module encrypts the authorization token through a double-layer encryption mechanism and a dynamic key;
[0040] An adjustment module, wherein the adjustment module obtains a target work factor by adjusting the work factor, and obtains encryption salt protection by optimizing the encryption salt through a dynamic key;
[0041] An encryption algorithm optimization module, wherein the encryption algorithm optimization module optimizes the BCrypt encryption algorithm through a target working factor and encryption salt protection;
[0042] A user privacy encryption module, which encrypts user privacy data using an optimized BCrypt encryption algorithm;
[0043] A payment system encryption module, wherein the payment system encryption module encrypts the payment system by encrypting the authorization token and encrypting the user's private data.
[0044] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-mentioned security encryption methods applicable to a payment system.
[0045] The above one or more technical methods in the embodiments of the present invention have at least one of the following technical effects:
[0046] The present invention provides a comprehensive data protection solution for users through authorization token optimization and BCrypt encryption algorithm optimization, which not only improves the security of the system, but also improves the user experience and the performance of the payment system.
[0047] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical method in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0049] Figure 1 It is a flow chart of a secure encryption method applicable to a payment system provided by the present invention.
[0050] Figure 2 It is a structural schematic diagram of a security encryption device suitable for a payment system provided by the present invention.
[0051] Reference numerals:
[0052] 101. Dynamic key acquisition module; 102. Authorization token encryption module; 103. Adjustment module; 104. Encryption algorithm optimization module; 105. User privacy encryption module; 106. Payment system encryption module. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical methods and advantages of the present invention clearer, the technical methods in the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. The following embodiments are used to illustrate the present invention, but cannot be used to limit the scope of the present invention.
[0054] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiment of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0055] Combine the following Figure 1 to Figure 2 The invention describes a secure encryption method, device and product applicable to a payment system.
[0056] like Figure 1 As shown, a secure encryption method applicable to a payment system comprises:
[0057] S1: Obtain dynamic keys through an optimized method of dynamic key generation and rotation;
[0058] S11: storing the dynamic key ID generated based on the timestamp and the random number in the key pool;
[0059] Dynamic key IDs generated based on timestamp and random number include:
[0060] Get the current system timestamp;
[0061] Use a random number generator to generate a random number of fixed length;
[0062] Combine the timestamp with the random number to obtain the dynamic key ID. The calculation expression is:
[0063]
[0064] in, is the dynamic key ID, is the SHA-256 hash algorithm, is the current system timestamp, The random number generated by the random number generator;
[0065] After combining the timestamp and the random number, the SHA-256 hash algorithm is used to generate a Key ID with a fixed length of 64 bits. The Key ID generated by this formula is highly unique and unpredictable. Each time a new key is generated, a unique Key ID is assigned to it and stored in the key pool. The Key ID is not only used to identify the version of the key, but also plays a role in key matching during the JWT generation and verification process.
[0066] S12: Parse the header key of the authorization token to obtain the header key ID, search for the dynamic key ID in the key pool according to the header key ID, and obtain the dynamic key;
[0067] Decrypt the payload of the authorization token using the dynamic key.
[0068] The embedded password in the authorization token header matches the key version of the key pool, ensuring that each authorization token is decrypted and verified using the corresponding latest key.
[0069] S2: Encrypt the authorization token through a double-layer encryption mechanism and dynamic key;
[0070] The double-layer encryption mechanism embeds the key in the header of the authorization token and encrypts the payload of the authorization token with AES-256;
[0071] By encrypting the authorization token payload with AES-256, malicious users cannot decrypt the sensitive information in the token even if it is intercepted during transmission. The encrypted data requires a corresponding dynamic key to decrypt, which increases the difficulty of cracking after a leak.
[0072] Through the key pool and caching mechanism, the payment system can avoid the problem of key synchronization lag while ensuring efficient performance.
[0073] At the same time, the anti-leakage capability of the authorization token has been significantly enhanced, as shown in:
[0074] The authorization token payload is encrypted with AES-256. Even if the authorization token is intercepted during transmission, malicious users cannot decrypt the sensitive information in it. The encrypted data requires the corresponding dynamic key to decrypt, which increases the difficulty of cracking after leakage.
[0075] Traditional static Key IDs may be easily guessed or predicted by attackers, but the Key ID generation method based on timestamps and random numbers makes each Key ID highly random and unique. If an attacker wants to predict or collide with a valid kid, he will have to face huge computational complexity.
[0076] The key rotation strategy ensures that even if a key is exposed or leaked for a long time, it will only affect token verification for a short period of time. By regularly updating the key, the system greatly reduces the risk of leakage caused by long-term use of the same key.
[0077] S3: The target working factor is obtained by adjusting the working factor, and the encryption salt is optimized by the dynamic key to obtain the encryption salt protection;
[0078] Work factor: BCrypt uses an adjustable work factor, called the "cost" parameter, to increase the complexity and time consumption of encryption. Setting a higher cost parameter makes brute force cracking take longer, thereby enhancing data security.
[0079] The work factor is expressed in BCrypt as a power of 2, which represents the complexity of the algorithm, that is, the number of algorithm iterations during the encryption process. If the work factor is set to 10, the number of BCrypt iterations is 2. 10 = 1024, 1024 rounds of processing are performed. If the work factor is set too high, the encryption calculation will become very time-consuming, the difficulty of brute force cracking will be greatly increased, and unnecessary system overhead will be caused.
[0080] The present invention adjusts and optimizes the working factor of BCrypt to make it intelligently adapt to the hardware of the payment system. Specifically, the time for implementing system password encryption is set to be controlled within 100 milliseconds, and an initial working factor (such as 10) is randomly selected. The test password is encrypted using this working factor. During the encryption process, the time required to complete the encryption is recorded. If the obtained time is much lower than 100 milliseconds, the working factor is increased; if it exceeds 100 milliseconds, it is reduced. Through repeated adjustment and testing of the working factor, the best working factor close to the target time is found. Based on the current hardware performance support and security requirements of the payment system, through continuous testing and optimization, the working factor is set at around 12 to achieve a balance between system security and speed.
[0081] By adjusting the work factor, the target work factor is obtained including:
[0082] Set the target encryption time and threshold and initialize the work factor,
[0083] If the time required for encryption is less than the target encryption time and the difference between the time required for encryption and the target encryption time is greater than or equal to the threshold, increase the work factor;
[0084]
[0085] in, is the new work factor, is the current work factor, The change in work factor,
[0086] If the time required for encryption is greater than the target encryption time and the difference between the time required for encryption and the target encryption time is greater than or equal to the threshold, then reduce the work factor;
[0087]
[0088] If the error between the time required for encryption and the target encryption time is less than the threshold, the adjustment is terminated.
[0089] The calculation expression for work factor optimization is:
[0090]
[0091] in, is the target work factor, The time required to encrypt for the current work factor, Encrypt time for the target, is the value of the variable when the objective function reaches its minimum value.
[0092] Encryption salt protection: BCrypt automatically generates a 16-byte random salt value and superimposes the random salt value with the password, so that the encryption result of the same password is different each time, preventing rainbow table attacks.
[0093] S4: Optimize BCrypt encryption algorithm through target work factor and encryption salt protection;
[0094] The BCrypt encryption algorithm includes encryption salt protection and work factor. The BCrypt encryption algorithm is optimized through target work factor and encryption salt protection.
[0095] The adjustable work factor ensures that the system always runs at the optimal work factor, thereby optimizing the performance of the encryption process while meeting security requirements;
[0096] As the system functions and architecture continue to improve, its hardware performance also improves accordingly, and the original work factor may no longer be secure enough. By regularly adjusting the work factor, we can ensure that the algorithm's anti-cracking ability will not decrease due to the increase in computing power, and ensure that the system's password protection is always in the best state.
[0097] S5: Encrypt user privacy data using the optimized BCrypt encryption algorithm;
[0098] The system needs to perform encryption processing when storing privacy-sensitive information such as user personal information, payment information, identity information, etc. The BCrypt encryption algorithm is optimized through target work factor and encryption salt protection. The payment system of the present invention encrypts user privacy data through the optimized BCrypt encryption algorithm.
[0099] S6: Encrypt the payment system by encrypting the authorization token and encrypting the user's privacy data.
[0100] The payment system uses the Open Authentication (OAuth) 2.0 protocol for authorization and authentication. The OAuth 2.0 protocol has built-in refresh tokens and custom refresh filters.
[0101] The OAuth 2.0 protocol also includes access tokens, which are used to authenticate users and authorize access to resources. Refresh tokens are used to obtain new access tokens after the access token expires. The refresh filter automatically detects the access token within T time after the access token expires.
[0102] In some specific embodiments of the present invention, T=0.5 hours.
[0103] like Figure 2 As shown, a security encryption device suitable for a payment system comprises:
[0104] The dynamic key acquisition module 101 obtains the dynamic key through an optimization method of dynamic key generation and rotation;
[0105] The authorization token encryption module 102 encrypts the authorization token through a double-layer encryption mechanism and a dynamic key;
[0106] The adjustment module 103 obtains a target working factor by adjusting the working factor, and obtains the encryption salt protection by optimizing the encryption salt through the dynamic key;
[0107] The encryption algorithm optimization module 104 optimizes the BCrypt encryption algorithm through target working factors and encryption salt protection;
[0108] The user privacy encryption module 105 encrypts user privacy data using an optimized BCrypt encryption algorithm;
[0109] The payment system encryption module 106 encrypts the payment system by encrypting the authorization token and encrypting the user's private data.
[0110] Through the collaborative work of the above modules, the secure encryption of the payment system is achieved, providing users with a comprehensive data protection solution, which not only improves the security of the system, but also improves the user experience and the performance of the payment system.
[0111] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute a security encryption method suitable for a payment system provided by the above methods.
[0112] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which is implemented when the computer program is executed by a processor to execute the above-mentioned security encryption method applicable to a payment system.
[0113] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the method of this embodiment. Those of ordinary skill in the art may understand and implement it without creative effort.
[0114] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical method is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0115] Finally, it should be noted that the above embodiments are only used to illustrate the technical methods of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical methods described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical methods from the spirit and scope of the technical methods of the embodiments of the present invention.
Claims
1. A secure encryption method suitable for a payment system, characterized in that: include: The dynamic key is obtained by optimizing the dynamic key generation and rotation method; The optimization method for dynamic key generation and rotation includes: The dynamic key ID generated based on the timestamp and the random number is stored in the key pool; Parse the header key of the authorization token to obtain the header key ID, search for the dynamic key ID in the key pool based on the header key ID, and obtain the dynamic key; Use the dynamic key to decrypt the payload of the authorization token; Encrypt the authorization token through a double-layer encryption mechanism and dynamic key; The double-layer encryption mechanism embeds a key into the header of the authorization token and performs AES-256 encryption on the payload of the authorization token; By adjusting the work factor, the target work factor is obtained, and the encryption salt is optimized through dynamic keys to obtain encryption salt protection; By adjusting the work factor, the target work factor is obtained including: Set the target encryption time and threshold and initialize the work factor, If the time required for encryption is less than the target encryption time and the difference between the time required for encryption and the target encryption time is greater than or equal to the threshold, increase the work factor; If the difference between the time required for encryption and the target encryption time is less than the threshold, the adjustment is terminated; The calculation expression of the target working factor is: in, is the target work factor, The time required to encrypt for the current work factor, Encrypt time for the target, The variable value when the objective function reaches the minimum value; the BCrypt encryption algorithm also includes encryption salt protection, which automatically generates a 16-byte random salt value through the BCrypt encryption algorithm, mixes the random salt value with the dynamic key to optimize the encryption salt, and obtains encryption salt protection; Optimize BCrypt encryption algorithm through target work factor and encryption salt protection; Encrypt user privacy data using the optimized BCrypt encryption algorithm; Encrypt the payment system by encrypting authorization tokens and encrypting user privacy data.
2. A secure encryption method applicable to a payment system according to claim 1, characterized in that: Dynamic key IDs generated based on timestamp and random number include: Get the current system timestamp; Use a random number generator to generate a random number of fixed length; Combine the timestamp with the random number to obtain the dynamic key ID. The calculation expression of the dynamic key ID is: in, is the dynamic key ID, is the SHA-256 hash algorithm, is the current system timestamp, A random number generated by the random number generator.
3. A secure encryption method applicable to a payment system according to claim 1, characterized in that: The payment system uses the OAuth 2.0 protocol for authorization and authentication, and the OAuth 2.0 protocol has built-in refresh tokens and customized refresh filters.
4. A secure encryption method applicable to a payment system according to claim 3, characterized in that: The OAuth 2.0 protocol also includes an access token, which is used for user identity authentication and authorization to access resources. The refresh token is used to re-acquire a new access token after the access token expires. The refresh filter automatically detects within T time before the end of the validity period of the access token.
5. A security encryption device suitable for a payment system, characterized in that: A method for executing a security encryption method applicable to a payment system as claimed in any one of claims 1 to 4, comprising: A dynamic key acquisition module, wherein the dynamic key acquisition module obtains a dynamic key through an optimization method of dynamic key generation and rotation; An authorization token encryption module, wherein the authorization token encryption module encrypts the authorization token through a double-layer encryption mechanism and a dynamic key; An adjustment module, wherein the adjustment module obtains a target work factor by adjusting the work factor, and obtains encryption salt protection by optimizing the encryption salt through a dynamic key; An encryption algorithm optimization module, wherein the encryption algorithm optimization module optimizes the BCrypt encryption algorithm through a target working factor and encryption salt protection; A user privacy encryption module, which encrypts user privacy data using an optimized BCrypt encryption algorithm; A payment system encryption module, wherein the payment system encryption module encrypts the payment system by encrypting the authorization token and encrypting the user's private data.
6. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, a secure encryption method suitable for a payment system as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Login token generation and verification method and device and server
CN110493202A
Token sending method and device, access request processing method and device, equipment, medium and product
CN116192371A