Method, device and equipment for transaction security protection between financial institutions and medium
By using randomly generated quantum states and symmetric encryption keys in transactions between financial institutions, combining quantum state authentication with traditional encryption algorithms, the problem of traditional encryption algorithms being easily cracked is solved, and the security and real-time performance of the transaction process are improved.
Patent Information
- Application Number
- CN202411963701.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-30
AI Technical Summary
The existing transaction security protection schemes between financial institutions are based on traditional encryption algorithms that generate keys that are easily cracked, posing security risks and resulting in low confidentiality, integrity and real-time performance of transaction data.
Using randomly generated quantum states and symmetric encryption keys, which are stored in hardware security modules and used for authentication and data transmission during transactions, the authentication method of quantum states and the encryption method of traditional encryption algorithms are combined to improve transaction security.
It effectively prevents the transaction process from being leaked or interrupted due to abnormal events, improves data confidentiality, integrity and real-time performance, and ensures the security and stability of the transaction process.
Smart Images

Figure CN119904234B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of financial technology, and in particular to a transaction security protection method and device between financial institutions, equipment and medium. BACKGROUND
[0002] In the process of transaction between the business systems of two financial institutions, the business systems of the two financial institutions need to authenticate each other first. After the authentication is passed, the business system of the financial institution initiating the transaction transmits transaction data to the business system of the financial institution responding to the transaction, and the business system of the financial institution responding to the transaction receives the transaction data and interacts with the business system of the financial institution initiating the transaction according to the transaction data. In order to ensure the normal progress of the transaction between the financial institutions, the transaction process needs to be protected.
[0003] In the related art, a common transaction security protection scheme is to perform identity authentication and transaction data transmission based on a key generated by a traditional encryption algorithm and related information in the process of transaction between financial institutions. The transaction security protection scheme in the related art performs transaction security protection based on a key generated by a traditional encryption algorithm and related information, which is easy to crack and has a great security risk, resulting in that the transaction process between the financial institutions is easy to be leaked or interrupted due to abnormal events, and the data confidentiality, integrity and real-time performance of the transaction process between the financial institutions are low. SUMMARY
[0004] The present application provides a transaction security protection method and device between financial institutions, equipment and medium, to solve the problem that the transaction security protection scheme in the related art performs transaction security protection based on a key generated by a traditional encryption algorithm and related information, which is easy to crack and has a great security risk, resulting in that the transaction process between the financial institutions is easy to be leaked or interrupted due to abnormal events, and the data confidentiality, integrity and real-time performance of the transaction process between the financial institutions are low.
[0005] According to an aspect of the present application, a transaction security protection method between financial institutions is provided, comprising:
[0006] After detecting the protection start information, enter the transaction security protection mode;
[0007] After detecting the transaction initiation request, determine a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request according to a randomly generated quantum state, store the random quantum key and the symmetric encryption key to a hardware security module, and perform identity authentication and transaction data transmission according to the random quantum key and the symmetric encryption key in the process of transaction with the transaction response system;
[0008] After detecting a transaction response request, determine a random quantum key and a symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request, store the random quantum key and the symmetric encryption key in a hardware security module, and during a transaction with the transaction initiation system, perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key.
[0009] According to another aspect of the present invention, there is provided a transaction security protection device between financial institutions, comprising:
[0010] A mode entry module is used to enter the transaction security protection mode after detecting the protection start information;
[0011] a first protection module configured to, after detecting a transaction initiation request, determine, based on a randomly generated quantum state, a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during a transaction with the transaction response system;
[0012] The second protection module is configured to, after detecting a transaction response request, determine a random quantum key and a symmetric encryption key shared with the transaction initiating system based on a randomly generated quantum state sent by the transaction initiating system of the transaction response request, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during a transaction with the transaction initiating system.
[0013] According to another aspect of the present invention, an electronic device is provided, comprising:
[0014] at least one processor;
[0015] and a memory communicatively coupled to the at least one processor;
[0016] The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the transaction security protection method between financial institutions described in any embodiment of the present invention.
[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the transaction security protection method between financial institutions described in any embodiment of the present invention when executed.
[0018] According to another aspect of the present invention, a computer program product is provided. The computer program product includes a computer program. When the computer program is executed by a processor, the computer program implements the transaction security protection method between financial institutions described in any embodiment of the present invention.
[0019] The technical solution of the embodiment of the present invention enters a transaction security protection mode after detecting protection start information; after detecting a transaction initiation request, determines a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request based on a randomly generated quantum state, stores the random quantum key and the symmetric encryption key in a hardware security module, and performs identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction response system; after detecting a transaction response request, determines a random quantum key and a symmetric encryption key shared with a transaction initiation system based on a randomly generated quantum state sent by a transaction initiation system of the transaction response request, stores the random quantum key and the symmetric encryption key in a hardware security module, and performs identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction initiation system, thereby solving the problem that the transaction security protection solution in the related art performs transaction security protection based on keys and related information generated by traditional encryption algorithms, which is easy to crack and has great security risks, resulting in the transaction process between financial institutions being easily leaked or The problems of low data confidentiality, integrity and real-time performance in transaction processes between financial institutions can be solved by, before the transaction process initiated or responded to by the business system of the financial institution begins, the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction can be determined based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction, and the shared random quantum key and symmetric encryption key can be securely stored through a hardware security module. During the transaction process initiated or responded to by the business system of the financial institution, identity authentication and transaction data transmission can be performed based on the shared random quantum key and symmetric encryption key determined before the transaction begins. The reliability of identity authentication can be improved based on the authentication method combined with quantum state. The security of transaction data transmission can be improved based on the encryption method combined with quantum key and traditional encryption algorithm, thereby effectively protecting the transaction security of the transaction process initiated or responded to by the business system of the financial institution, avoiding the leakage or interruption of the transaction process initiated or responded by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0020] It is to be understood that the embodiments described herein are merely exemplary of the application and that a person skilled in the art can devise other embodiments without departing from the scope of the present application. It is also to be understood that not all of the features and / or benefits described and / or illustrated herein need be present in every embodiment of the application. The scope of the application should therefore not be limited to the features and / or benefits described and / or illustrated herein, but should be given the full scope that the claims afford based on the entirety of the specification. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.
[0022] Figure 1 A flow chart of a transaction security protection method between financial institutions provided by the first embodiment of the present application.
[0023] Figure 2 A flow chart of a transaction security protection method between financial institutions provided by the second embodiment of the present application.
[0024] Figure 3 A flow chart of a transaction security protection method between financial institutions provided by the third embodiment of the present application.
[0025] Figure 4 A structural schematic diagram of a transaction security protection device between financial institutions provided by the fourth embodiment of the present application.
[0026] Figure 5 A structural schematic diagram of an electronic device for implementing the transaction security protection method between financial institutions of the embodiments of the present application. DETAILED DESCRIPTION
[0027] In order to make the technical personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort should be within the scope of protection of the present application.
[0028] It should be noted that the terms "target", "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprise", "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data comply with relevant laws, regulations and standards in the relevant regions.
[0030] Example 1
[0031] Figure 1 This is a flowchart of a transaction security protection method between financial institutions provided in the first embodiment of the present invention. This embodiment is applicable to situations where security protection is provided for transaction processes between financial institutions. The method can be executed by a transaction security protection device between financial institutions. The transaction security protection device between financial institutions can be implemented in the form of hardware and / or software, and the transaction security protection device between financial institutions can be configured in the business system of the financial institution. The business system of the financial institution can be a server set up in the financial institution for processing the business of the financial institution. Figure 1 As shown, the method includes:
[0032] Step 101: After detecting protection start information, enter transaction security protection mode.
[0033] Optionally, the transaction security protection mode may refer to a mode in which, after detecting a transaction initiation request or a transaction response request, a random quantum key and a symmetric encryption key are determined, and identity authentication and transaction data transmission are performed according to the random quantum key and the symmetric encryption key during the transaction, thereby providing security protection during transactions between financial institutions within the financial institution's business system. The protection start information may be information received by the financial institution's business system indicating entry into the transaction security protection mode. After the financial institution's business system begins operation, the relevant information and data received and generated by the financial institution's business system may be tested. The financial institution's business system may be tested for receipt of the protection start information, and upon detecting receipt of the protection start information by the financial institution's business system, the transaction security protection mode may be entered.
[0034] Step 102: After detecting a transaction initiation request, determine a random quantum key and a symmetric encryption key shared with the transaction response system of the transaction initiation request based on the randomly generated quantum state, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction response system.
[0035] Optionally, the transaction initiation request may be information received by a financial institution's business system that instructs the financial institution's business system to initiate a designated transaction with another financial institution's business system. The business system of the other financial institution is the transaction response system for the transaction initiation request, i.e., the business system of the other financial institution that needs to respond to the designated transaction initiated by the financial institution's business system and conduct the designated transaction with the financial institution's business system. Whether the financial institution's business system has received the transaction initiation request can be detected. After detecting that the financial institution's business system has received the transaction initiation request, a random quantum key and a symmetric encryption key shared with the transaction response system for the transaction initiation request are determined based on a randomly generated quantum state.
[0036] Optionally, the random quantum key shared by the financial institution's business system and the transaction response system for the transaction initiation request may be a quantum key obtained based on a randomly generated quantum state and usable by both the financial institution's business system and the transaction response system for the transaction initiation request. A quantum state is an abstract mathematical concept that describes the state of a quantum system, such as the polarization state of a photon or the spin state of an electron. A quantum key is a completely random sequence of numbers generated through quantum state transmission and quantum state measurement. Quantum keys have characteristics such as randomness, non-replicability, security, and one-time use. The quantum state generated in the embodiment of the present invention may be a specifically prepared quantum bit with a certain polarization state or spin state. The test base is an algorithm used to measure and encode the quantum state. The random quantum key in the embodiment of the present invention may be a quantum key obtained by measuring and encoding the randomly generated quantum state using the test base.
[0037] Optionally, the symmetric encryption key shared with the transaction response system for the transaction initiation request may be a symmetric encryption key that can be used by both the financial institution's business system and the transaction response system for the transaction initiation request. Symmetric encryption keys include, but are not limited to, Advanced Encryption Standard (AES) keys.
[0038] Optionally, a financial institution's business system's hardware security module (HSM) can be a physical device used to protect and manage digital keys, certificates, and other important information used in the financial institution's business system. Hardware security modules are typically used for encryption and digital signature operations.
[0039] Optionally, determining a random quantum key and a symmetric encryption key shared with the transaction response system that initiated the transaction request based on the randomly generated quantum state includes: randomly generating a quantum state, sending the quantum state to the transaction response system through a quantum communication channel between the transaction response system and the transaction response system, so that the transaction response system measures and encodes the quantum state through a shared test basis to obtain a shared random quantum key, and feeds back the random quantum key; obtaining the random quantum key fed back by the transaction response system; generating a symmetric encryption key shared with the transaction response system, and encrypting the symmetric encryption key using the random quantum key; and sending the encrypted symmetric encryption key to the transaction response system through a classical communication channel between the transaction response system and the transaction response system, so that the transaction response system decrypts the encrypted symmetric encryption key according to the random quantum key to obtain the symmetric encryption key.
[0040] Therefore, before the transaction process initiated by the business system of the financial institution begins, the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction can be determined based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction.
[0041] Optionally, quantum communication channels may be pre-established between the business systems of various financial institutions. These channels can be dedicated communications lines for transmitting quantum-related data, such as quantum states and quantum keys, between the business systems of these financial institutions, ensuring the secure transmission of these data. These channels can be implemented via optical fiber or free-space transmission. The quantum communication channel between the transaction response system and the financial institution can be a pre-established communication line for transmitting quantum-related data, such as quantum states and quantum keys, between the business systems of these financial institutions and the transaction response system. A randomly generated quantum state can be sent to the transaction response system via the quantum communication channel between the financial institution and the transaction response system.
[0042] Optionally, the shared test base can be a pre-configured test base that can be used jointly by the financial institution's business system and the transaction response system that initiates the transaction request, for measuring and encoding quantum states. The transaction response system receives the randomly generated quantum state, measures and encodes the quantum state using the shared test base, and obtains a completely random digital sequence. This digital sequence is then determined as the random quantum key shared by the financial institution's business system and the transaction response system that initiates the transaction request. The shared random quantum key is then fed back to the financial institution's business system via the quantum communication channel between the financial institution's business system and the transaction response system that initiates the transaction request. The random quantum key fed back by the transaction response system can be obtained, thereby obtaining the random quantum key shared by the financial institution's business system and the transaction response system that initiates the transaction request.
[0043] Optionally, a randomly generated symmetric encryption key can be used as the symmetric encryption key shared by the financial institution's business system and the transaction response system for the transaction initiation request. A quantum key encryption algorithm can then be used to encrypt the symmetric encryption key shared by the financial institution's business system and the transaction response system for the transaction initiation request using the random quantum key shared by the financial institution's business system and the transaction response system for the transaction initiation request, thereby obtaining an encrypted symmetric encryption key shared by the financial institution's business system and the transaction response system for the transaction initiation request. The quantum key encryption algorithm can be a pre-set algorithm for encrypting data using a quantum key to obtain the encrypted data.
[0044] Optionally, a classical communication channel is pre-established between the business system of each financial institution. The classical communication channel can be a general communication line for transmitting data between the business systems of the financial institutions. The classical communication channel between the transaction response system can be a general communication line pre-established for transmitting data between the business system of the financial institution and the transaction response system. The encrypted symmetric encryption key shared by the business system of the financial institution and the transaction response system initiating the transaction request can be transmitted to the transaction response system through the classical communication channel between the transaction response system. The transaction response system can decrypt the encrypted symmetric encryption key shared by the business system of the financial institution and the transaction response system initiating the transaction request using the random quantum key shared by the business system of the financial institution and the transaction response system initiating the transaction request through the quantum key decryption algorithm to obtain the original symmetric encryption key shared by the business system of the financial institution and the transaction response system initiating the transaction request. The quantum key decryption algorithm can be an algorithm pre-set for decrypting data encrypted based on a quantum key using a quantum key to obtain the original data before encryption. The data encrypted based on a quantum key is data encrypted using a quantum key.
[0045] Optionally, after determining the random quantum key and the symmetric encryption key shared by the transaction response system initiating the transaction request, the determined random quantum key and the symmetric encryption key can be stored in the hardware security module of the business system of the financial institution. The transaction response system can store the determined random quantum key and the symmetric encryption key in the hardware security module of the transaction response system.
[0046] Optionally, in the process of conducting a transaction with the transaction response system, identity verification and transaction data transmission are performed according to the random quantum key and the symmetric encryption key, including: after detecting the identity verification information of the transaction response system, identity verification of the transaction response system is performed according to the digital signature and the quantum state corresponding to the random quantum key; after detecting the transaction data corresponding to the transaction response system, the transaction data corresponding to the transaction response system is encrypted through the symmetric encryption key, and the encrypted transaction data is transmitted to the transaction response system through the secure network channel between the transaction response system, so that the transaction response system decrypts the encrypted transaction data according to the symmetric encryption key to obtain the transaction data.
[0047] Therefore, during the transaction process initiated by the business system of a financial institution, identity authentication and transaction data transmission can be performed based on the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions involved in the transaction, which are determined before the transaction begins. The reliability of identity authentication can be improved based on the identity authentication method combined with the quantum state, and the security of transaction data transmission can be improved based on the encryption method combined with the quantum key and the traditional encryption algorithm, thereby effectively protecting the transaction process initiated by the business system of the financial institution, avoiding the leakage or interruption of the transaction process initiated by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0048] Optionally, the identity authentication information of the transaction response system may be information sent by the transaction response system for identity authentication. The identity authentication information of the transaction response system may include a digital signature of the transaction response system and a quantum state corresponding to the random quantum key. The identity authentication information of the transaction response system may also include biometric information. The digital signature of the transaction response system may be a digital signature generated by the transaction response system for uniquely identifying the transaction response system. The quantum state corresponding to the random quantum key refers to a randomly generated quantum state received by the transaction response system for determining the shared random quantum key. It is possible to detect whether the business system of the financial institution has received the identity authentication information of the transaction response system sent by the transaction response system. After detecting that the business system of the financial institution has received the identity authentication information of the transaction response system sent by the transaction response system, the transaction response system is authenticated based on the digital signature and the quantum state corresponding to the random quantum key.
[0049] Optionally, authenticating the transaction response system based on the digital signature and the quantum state corresponding to the random quantum key includes: detecting whether the digital signature in the authentication information of the transaction response system is identical to the digital signature of the transaction response system stored in the business system of the financial institution, and whether the quantum state in the authentication information of the transaction response system is identical to the randomly generated quantum state sent to the transaction response system; if the digital signature in the authentication information of the transaction response system is identical to the digital signature of the transaction response system stored in the business system of the financial institution, and the quantum state in the authentication information of the transaction response system is identical to the randomly generated quantum state sent to the transaction response system, then determining that the transaction response system has passed authentication, and storing first authentication pass information in an authentication result file; if the digital signature in the authentication information of the transaction response system is not identical to the digital signature of the transaction response system stored in the business system of the financial institution, or the quantum state in the authentication information of the transaction response system is not identical to the randomly generated quantum state sent to the transaction response system, then determining that the transaction response system has failed authentication, and storing first identity authentication failure information in the authentication result file. The first authentication pass information may be information indicating that the transaction response system has passed authentication. The authentication result file may be a pre-set file for storing information indicating whether authentication has passed. The financial institution's business system may determine that the transaction response system has passed authentication based on the first authentication pass information stored in the authentication result file, and may initiate a transaction with the transaction response system. The first authentication failure information may be information indicating that the transaction response system has failed authentication. The financial institution's business system may determine that the transaction response system has failed authentication based on the first authentication failure information stored in the authentication result file, and may not initiate a transaction with the transaction response system.
[0050] Optionally, the transaction data corresponding to the transaction response system may refer to data generated by the business system of the financial institution and related to the transaction process between the business system of the financial institution and the transaction response system, which needs to be sent to the transaction response system. Whether the business system of the financial institution generates transaction data corresponding to the transaction response system may be detected. Upon detecting that the business system of the financial institution generates transaction data corresponding to the transaction response system, the transaction data corresponding to the transaction response system may be encrypted using the symmetric encryption key, and the encrypted transaction data may be sent to the transaction response system via a secure network channel with the transaction response system.
[0051] Optionally, after detecting that the financial institution's business system has generated transaction data corresponding to the transaction response system, the transaction data corresponding to the transaction response system may be encrypted using a symmetric encryption algorithm using a symmetric encryption key shared by the financial institution's business system and the transaction response system that initiated the transaction request, thereby obtaining encrypted transaction data corresponding to the transaction response system. The symmetric encryption algorithm may be a pre-set algorithm for encrypting data using a symmetric encryption key to obtain encrypted data.
[0052] Optionally, a secure network channel is pre-established between the business systems of each financial institution. The secure network channel may be a communication line used to transmit encrypted transaction data between the business systems of the financial institution. The secure network channel may be implemented using a secure network protocol. Secure network protocols include, but are not limited to, Transport Layer Security (TLS) and Internet Protocol Security (IPSec). The secure network channel between the transaction response system and the transaction response system may be a pre-established communication line used to transmit encrypted transaction data between the business system of the financial institution and the transaction response system. Encrypted transaction data corresponding to the transaction response system may be sent to the transaction response system via the secure network channel between the transaction response system and the transaction response system. The transaction response system uses a symmetric decryption algorithm to decrypt the encrypted transaction data corresponding to the transaction response system using a symmetric encryption key shared by the business system of the financial institution and the transaction response system that initiated the transaction request, thereby obtaining the original transaction data corresponding to the transaction response system. The symmetric decryption algorithm may be a pre-set algorithm for decrypting data encrypted using a symmetric encryption key using a symmetric encryption key to obtain the original data before encryption. Data encrypted using a symmetric encryption key is data encrypted using the symmetric encryption key.
[0053] Step 103: After detecting a transaction response request, determine a random quantum key and a symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction initiation system.
[0054] Optionally, the transaction response request may be information received by a financial institution's business system that instructs the financial institution's business system to respond to a designated transaction initiated by another financial institution's business system. The other financial institution's business system is the transaction initiating system that initiated the transaction response request, i.e., the business system of the other financial institution that initiated the designated transaction to the financial institution's business system and conducted the designated transaction with the financial institution's business system. Whether the financial institution's business system has received the transaction response request may be detected. After detecting that the financial institution's business system has received the transaction response request, the random quantum key and symmetric encryption key shared with the transaction initiating system may be determined based on the randomly generated quantum state sent by the transaction initiating system that initiated the transaction response request.
[0055] Optionally, the random quantum key shared by the business system of the financial institution and the transaction initiation system of the transaction response request can be a quantum key obtained based on a randomly generated quantum state that can be used jointly by the business system of the financial institution and the transaction initiation system of the transaction response request.
[0056] Optionally, the symmetric encryption key shared with the transaction initiating system of the transaction response request can be a symmetric encryption key that can be used by both the financial institution's business system and the transaction initiating system of the transaction response request. Symmetric encryption keys include but are not limited to: AES keys.
[0057] Optionally, determining a random quantum key and a symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request, includes: measuring and encoding the randomly generated quantum state sent by the transaction initiation system of the transaction response request received through a shared test basis to obtain a random quantum key shared with the transaction initiation system, and feeding back the random quantum key to the transaction initiation system; receiving an encrypted symmetric encryption key shared with the transaction initiation system sent by the transaction initiation system; wherein the encrypted symmetric encryption key shared with the transaction initiation system is encrypted based on the random quantum key; and decrypting the encrypted symmetric encryption key shared with the transaction initiation system based on the random quantum key to obtain the symmetric encryption key shared with the transaction initiation system.
[0058] Therefore, before the transaction process responded by the business system of the financial institution begins, the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction can be determined based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction.
[0059] Optionally, the transaction initiating system of the transaction response request randomly generates a quantum state and transmits the randomly generated quantum state to the financial institution's business system via a quantum communication channel with the financial institution's business system. The system can detect whether the financial institution's business system has received the randomly generated quantum state. After detecting that the financial institution's business system has received the randomly generated quantum state, the system measures and encodes the randomly generated quantum state sent by the transaction initiating system using a shared test base, obtaining a completely random digital sequence. The resulting digital sequence is then determined as a random quantum key shared between the financial institution's business system and the transaction initiating system of the transaction response request. The shared random quantum key is then fed back to the transaction initiating system via the quantum communication channel with the transaction initiating system. The shared test base can be a pre-set test base that can be used jointly by the financial institution's business system and the transaction initiating system of the transaction response request for measuring and encoding quantum states.
[0060] Optionally, the transaction initiation system of the transaction response request can obtain the feedback random quantum key, thereby obtaining the random quantum key shared by the financial institution's business system and the transaction initiation system of the transaction response request. The transaction initiation system of the transaction response request then randomly generates a symmetric encryption key as the symmetric encryption key shared by the financial institution's business system and the transaction initiation system of the transaction response request. The transaction initiation system of the transaction response request can use the random quantum key shared by the financial institution's business system and the transaction initiation system of the transaction response request through a quantum key encryption algorithm to encrypt the symmetric encryption key shared by the financial institution's business system and the transaction initiation system of the transaction response request, thereby obtaining the encrypted symmetric encryption key shared by the financial institution's business system and the transaction initiation system of the transaction response request.
[0061] Optionally, the transaction initiating system of the transaction response request may send an encrypted symmetric encryption key shared by the business system of the financial institution and the transaction initiating system of the transaction response request to the business system of the financial institution via a classical communication channel between the business system of the financial institution and the transaction initiating system of the transaction response request. The business system of the financial institution may detect whether it has received the encrypted symmetric encryption key shared by the business system of the financial institution and the transaction initiating system of the transaction response request sent by the transaction initiating system of the transaction response request. After detecting that the business system of the financial institution has received the encrypted symmetric encryption key shared by the business system of the financial institution and the transaction initiating system of the transaction response request sent by the transaction initiating system of the transaction response request, the encrypted symmetric encryption key shared by the business system of the financial institution and the transaction initiating system of the transaction response request may be decrypted using a random quantum key shared by the business system of the financial institution and the transaction initiating system of the transaction response request using a quantum key decryption algorithm to obtain the original symmetric encryption key shared by the business system of the financial institution and the transaction initiating system of the transaction response request.
[0062] Optionally, after determining the random quantum key and symmetric encryption key shared with the transaction initiating system that responded to the transaction, the determined random quantum key and symmetric encryption key may be stored in the hardware security module of the financial institution's business system. The transaction initiating system will store the determined random quantum key and symmetric encryption key in the hardware security module of the transaction initiating system.
[0063] Optionally, during a transaction with the transaction initiation system, identity authentication and transaction data transmission are performed based on the random quantum key and the symmetric encryption key, including: after detecting the authentication information of the transaction initiation system, authenticating the transaction initiation system based on the digital signature and the quantum state corresponding to the random quantum key; after detecting the encrypted transaction data sent by the transaction initiation system, decrypting the encrypted transaction data sent by the transaction initiation system using the symmetric encryption key to obtain transaction data; wherein the encrypted transaction data sent by the transaction initiation system is encrypted based on the symmetric encryption key.
[0064] Therefore, during the transaction process responded by the business system of a financial institution, identity authentication and transaction data transmission can be performed based on the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction, which are determined before the transaction begins. The reliability of identity authentication can be improved based on the identity authentication method combined with the quantum state, and the security of transaction data transmission can be improved based on the encryption method combined with the quantum key and the traditional encryption algorithm, thereby effectively protecting the transaction security of the transaction process responded by the business system of the financial institution, avoiding the leakage or interruption of the transaction process responded by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0065] Optionally, the identity authentication information of the transaction initiation system may be information sent by the transaction initiation system for identity authentication. The identity authentication information of the transaction initiation system includes the digital signature of the transaction initiation system and the quantum state corresponding to the random quantum key. The identity authentication information of the transaction initiation system may also include biometric information. The digital signature of the transaction initiation system may be a digital signature generated by the transaction initiation system for uniquely identifying the transaction initiation system. The quantum state corresponding to the random quantum key refers to a randomly generated quantum state sent by the transaction initiation system for determining the shared random quantum key. It is possible to detect whether the business system of the financial institution has received the identity authentication information of the transaction initiation system sent by the transaction initiation system. After detecting that the business system of the financial institution has received the identity authentication information of the transaction initiation system sent by the transaction initiation system, the transaction initiation system is authenticated based on the digital signature and the quantum state corresponding to the random quantum key.
[0066] Optionally, authenticating the transaction initiation system based on the digital signature and the quantum state corresponding to the random quantum key includes: detecting whether the digital signature in the authentication information of the transaction initiation system is identical to the digital signature of the transaction initiation system stored in the business system of the financial institution, and whether the quantum state in the authentication information of the transaction initiation system is identical to the randomly generated quantum state used to determine the shared random quantum key; if the digital signature in the authentication information of the transaction initiation system is identical to the digital signature of the transaction initiation system stored in the business system of the financial institution, and the quantum state in the authentication information of the transaction initiation system is identical to the randomly generated quantum state used to determine the shared random quantum key, then determining that the transaction initiation system has passed authentication, and storing second authentication pass information in an authentication result file; if the digital signature in the authentication information of the transaction initiation system is not identical to the digital signature of the transaction initiation system stored in the business system of the financial institution, or the quantum state in the authentication information of the transaction initiation system is not identical to the randomly generated quantum state used to determine the shared random quantum key, then determining that the transaction initiation system has failed authentication, and storing second identity authentication failure information in the authentication result file. The second authentication pass information may be information used to indicate that the transaction initiation system has passed authentication. The authentication result file may be a pre-set file for storing information indicating whether authentication has passed. The financial institution's business system can determine that the transaction initiating system has passed identity authentication based on the second identity authentication pass information stored in the identity authentication result file, and initiate transactions with the transaction initiating system. The second identity authentication failure information can be information indicating that the transaction initiating system has failed identity authentication. The financial institution's business system can determine that the transaction initiating system has failed identity authentication based on the second identity authentication failure information stored in the identity authentication result file, and will not initiate transactions with the transaction initiating system.
[0067] Optionally, the transaction data corresponding to the financial institution's business system may refer to data generated by the transaction initiation system and related to the transaction process between the financial institution's business system and the transaction initiation system that needs to be sent to the financial institution's business system. The transaction initiation system will encrypt the transaction data corresponding to the financial institution's business system using a symmetric encryption algorithm and a symmetric encryption key shared by the financial institution's business system and the transaction initiation system that responds to the transaction request. The encrypted transaction data corresponding to the financial institution's business system will be sent to the financial institution's business system via a secure network channel between the financial institution and the business system.
[0068] Optionally, it is possible to detect whether the business system of the financial institution has received the encrypted transaction data corresponding to the business system of the financial institution sent by the transaction initiation system. After detecting that the business system of the financial institution has received the encrypted transaction data corresponding to the business system of the financial institution sent by the transaction initiation system, the encrypted transaction data corresponding to the business system of the financial institution is decrypted by using a symmetric decryption algorithm and a symmetric encryption key shared by the business system of the financial institution and the transaction initiation system of the transaction response request to obtain the original transaction data corresponding to the business system of the financial institution.
[0069] Optionally, it also includes: when an abnormal event is monitored, outputting alarm information and executing processing operations corresponding to the abnormal event.
[0070] As a result, during the transaction process initiated or responded to by the financial institution's business system, it is possible to respond promptly to abnormal events monitored in real time to ensure the security and normal progress of the transaction.
[0071] Optionally, abnormal events include, but are not limited to, abnormal data received by a financial institution's business system, abnormal data sent by a financial institution's business system, failure of authentication of a transaction response system, failure of authentication of a transaction initiation system, and interference in the quantum communication channel. During the operation of a financial institution's business system, abnormal events can be monitored. When an abnormal event is detected, an alarm message is output and corresponding processing operations are executed.
[0072] Optionally, the alarm information may be a pre-set message used to indicate the occurrence of an abnormal event. Outputting the alarm information includes: sending the alarm information to a terminal device of a target user. The target user may be a technician responsible for maintaining the business system of a financial institution. The terminal device of the target user may be a terminal device used by the target user.
[0073] Optionally, executing processing operations corresponding to the abnormal event includes: controlling the business system of the financial institution to suspend transactions; or controlling the business system of the financial institution to re-authenticate; or updating the key shared by the business system of the financial institution and the transaction response system or the transaction initiation system.
[0074] The technical scheme of the embodiment of the present application comprises the following steps: after detecting the protection start information, entering the transaction security protection mode; after detecting the transaction initiation request, determining the random quantum key and the symmetric encryption key shared with the transaction response system of the transaction initiation request according to the randomly generated quantum state, storing the random quantum key and the symmetric encryption key to the hardware security module, and performing identity authentication and transaction data transmission according to the random quantum key and the symmetric encryption key in the process of transaction with the transaction response system; after detecting the transaction response request, determining the random quantum key and the symmetric encryption key shared with the transaction initiation system according to the randomly generated quantum state sent by the transaction initiation system of the transaction response request, storing the random quantum key and the symmetric encryption key to the hardware security module, and performing identity authentication and transaction data transmission according to the random quantum key and the symmetric encryption key in the process of transaction with the transaction initiation system. The transaction security protection scheme in the related art is based on the key and related information generated by the traditional encryption algorithm for transaction security protection, which is easy to crack and has great security risks, so that the transaction process between financial institutions is easy to be leaked or interrupted due to abnormal events, and the data confidentiality, integrity and real-time performance of the transaction process between financial institutions are low. The random quantum state and the data interaction between the business systems of the two financial institutions for transaction are determined before the transaction process initiated or responded by the business system of the financial institution starts, the random quantum key and the symmetric encryption key shared by the business systems of the two financial institutions for transaction are determined, and the shared random quantum key and symmetric encryption key are safely stored by the hardware security module. The shared random quantum key and symmetric encryption key determined before the transaction starts are used for identity authentication and transaction data transmission in the transaction process initiated or responded by the business system of the financial institution, the reliability of identity authentication is improved based on the identity authentication method combined with the quantum state, the security of transaction data transmission is improved based on the encryption method combined with the quantum key and the traditional encryption algorithm, and thus the transaction security protection of the transaction process initiated or responded by the business system of the financial institution is effectively performed, the transaction process initiated or responded by the business system of the financial institution is prevented from being leaked or interrupted due to abnormal events, and the data confidentiality, integrity and real-time performance of the transaction process between financial institutions are improved.
[0075] Optionally, the quantum communication channels between the business systems of various financial institutions can be established by quantum key distribution hardware. Quantum key distribution hardware can be a hardware device used to establish multiple independent and reliable quantum communication links between the business systems of financial institutions, perform redundant encoding of quantum signals (quantum error correction code Shor or quantum error correction code Steane code), increase signal robustness, and generate and transmit quantum keys. Quantum key distribution hardware can improve the robustness and security of the quantum key generation and transmission processes through redundant encoding and multi-path transmission, especially in the face of quantum decoherence and potential quantum attacks. Quantum decoherence is a phenomenon in quantum mechanics that describes the process by which a quantum system loses its quantum properties (such as superposition and entanglement) due to interaction with the surrounding environment.
[0076] Alternatively, quantum detectors can be used to receive quantum states transmitted by the business systems of various financial institutions via multiple quantum communication channels. The properties of redundant coding can be exploited to detect errors in the received quantum states. If an error is detected, the extra qubits in the redundant coding are used to correct it. Error detection and correction of the received quantum states are achieved using quantum error correction algorithms, which can restore the original quantum state. After successful error correction, the quantum information used to determine the quantum key can be extracted from the remaining qubits.
[0077] Alternatively, a classical communication channel can be used to coordinate information transmitted over multiple paths. Symmetric encryption keys on different paths can be compared, and the symmetric encryption key with the highest consistency can be selected as the final symmetric encryption key.
[0078] Optionally, the hardware security modules of the business systems of various financial institutions can use the stored quantum keys as seeds or auxiliary information to generate symmetric encryption keys. The generated symmetric encryption keys are used for actual transaction encryption. The hardware security module securely stores quantum keys and symmetric encryption keys to ensure that quantum keys and symmetric encryption keys are not accessed by unauthorized persons. The life cycle of the hardware security module key includes generation, storage, use, update, and destruction. The hardware security module can monitor all key usage activities of the business systems of financial institutions and record detailed audit logs to facilitate the detection and response to any abnormal behavior. The hardware security modules of the business systems of various financial institutions provide a secure environment to store and manage keys generated through quantum key distribution technology, while ensuring the security and integrity of the symmetric encryption keys used in the transaction process, which not only improves the security of inter-bank transactions, but also meets regulatory and compliance requirements.
[0079] Example 2
[0080] Figure 2This is a flowchart of a transaction security protection method between financial institutions provided by the second embodiment of the present invention. This embodiment of the present invention can be combined with each optional solution in one or more of the above embodiments. Figure 2 As shown, the method includes:
[0081] Step 201: After detecting the protection start information, enter the transaction security protection mode.
[0082] Step 202: After detecting the transaction initiation request, randomly generate a quantum state, and send the quantum state to the transaction response system of the transaction initiation request through the quantum communication channel between the transaction response system and the transaction response system, so that the transaction response system measures and encodes the quantum state through a shared test basis, obtains a shared random quantum key, and feeds back the random quantum key.
[0083] Step 203: Obtain the random quantum key fed back by the transaction response system.
[0084] Step 204: Generate a symmetric encryption key shared with the transaction response system, and encrypt the symmetric encryption key using the random quantum key.
[0085] Step 205: Send the encrypted symmetric encryption key to the transaction response system through the classical communication channel between the transaction response system and the transaction response system, so that the transaction response system decrypts the encrypted symmetric encryption key according to the random quantum key to obtain the symmetric encryption key.
[0086] Step 206: Store the random quantum key and the symmetric encryption key in a hardware security module.
[0087] Step 207: After detecting the authentication information of the transaction response system, authenticate the transaction response system according to the digital signature and the quantum state corresponding to the random quantum key.
[0088] Step 208: After detecting the transaction data corresponding to the transaction response system, encrypt the transaction data corresponding to the transaction response system using the symmetric encryption key, and send the encrypted transaction data to the transaction response system through a secure network channel between the transaction response system and the transaction response system, so that the transaction response system decrypts the encrypted transaction data according to the symmetric encryption key to obtain the transaction data.
[0089] The technical solution of the embodiment of the present invention can determine the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction before the transaction process initiated by the business system of the financial institution begins, and securely store the shared random quantum key and symmetric encryption key through a hardware security module. During the transaction process initiated by the business system of the financial institution, identity authentication and transaction data transmission can be performed based on the shared random quantum key and symmetric encryption key determined before the transaction begins. The reliability of identity authentication can be improved based on the identity authentication method combined with the quantum state. The security of transaction data transmission can be improved based on the encryption method combined with the quantum key and the traditional encryption algorithm, thereby effectively performing transaction security protection for the transaction process initiated by the business system of the financial institution, avoiding the leakage or interruption of the transaction process initiated by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0090] Example 3
[0091] Figure 3 This is a flowchart of a transaction security protection method between financial institutions provided by the third embodiment of the present invention. This embodiment of the present invention can be combined with each optional solution in one or more of the above embodiments. Figure 3 As shown, the method includes:
[0092] Step 301: After detecting protection start information, enter transaction security protection mode.
[0093] Step 302: After detecting the transaction response request, measure and encode the randomly generated quantum state sent by the transaction initiating system receiving the transaction response request through the shared test basis to obtain a random quantum key shared with the transaction initiating system, and feed the random quantum key back to the transaction initiating system.
[0094] Step 303: Receive the encrypted symmetric encryption key shared with the transaction initiating system and sent by the transaction initiating system.
[0095] The encrypted symmetric encryption key shared with the transaction initiation system is encrypted based on the random quantum key.
[0096] Step 304: Decrypt the encrypted symmetric encryption key shared with the transaction initiation system according to the random quantum key to obtain the symmetric encryption key shared with the transaction initiation system.
[0097] Step 305: Store the random quantum key and the symmetric encryption key in a hardware security module.
[0098] Step 306: After detecting the identity authentication information of the transaction initiating system, authenticate the transaction initiating system based on the digital signature and the quantum state corresponding to the random quantum key.
[0099] Step 307: After detecting the encrypted transaction data sent by the transaction initiation system, decrypt the encrypted transaction data sent by the transaction initiation system using the symmetric encryption key to obtain the transaction data.
[0100] The encrypted transaction data sent by the transaction initiation system is encrypted according to the symmetric encryption key.
[0101] The technical solution of the embodiment of the present invention can determine the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction before the transaction process responded by the business system of the financial institution begins, and securely store the shared random quantum key and symmetric encryption key through a hardware security module. During the transaction process responded by the business system of the financial institution, based on the shared random quantum key and symmetric encryption key determined before the transaction begins, identity authentication and transaction data transmission can be performed. The reliability of identity authentication can be improved based on the identity authentication method combined with the quantum state. The security of transaction data transmission can be improved based on the encryption method combined with the quantum key and the traditional encryption algorithm, thereby effectively performing transaction security protection for the transaction process responded by the business system of the financial institution, avoiding the leakage or interruption of the transaction process responded by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0102] Example 4
[0103] Figure 4 This is a schematic diagram of a structure of a transaction security protection device between financial institutions provided by the fourth embodiment of the present invention. The device can be configured in an electronic device. Figure 4 As shown, the device includes: a mode entry module 401 , a first protection module 402 and a second protection module 403 .
[0104] Among them, the mode entry module 401 is used to enter the transaction security protection mode after detecting the protection start information; the first protection module 402 is used to determine the random quantum key and symmetric encryption key shared with the transaction response system of the transaction initiation request based on the randomly generated quantum state after detecting the transaction initiation request, store the random quantum key and the symmetric encryption key in the hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during the transaction with the transaction response system; the second protection module 403 is used to determine the random quantum key and symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request after detecting the transaction response request, store the random quantum key and the symmetric encryption key in the hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during the transaction with the transaction initiation system.
[0105] The technical solution of the embodiment of the present invention enters a transaction security protection mode after detecting protection start information; after detecting a transaction initiation request, determines a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request based on a randomly generated quantum state, stores the random quantum key and the symmetric encryption key in a hardware security module, and performs identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction response system; after detecting a transaction response request, determines a random quantum key and a symmetric encryption key shared with a transaction initiation system based on a randomly generated quantum state sent by a transaction initiation system of the transaction response request, stores the random quantum key and the symmetric encryption key in a hardware security module, and performs identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during transactions with the transaction initiation system, thereby solving the problem that the transaction security protection solution in the related art performs transaction security protection based on keys and related information generated by traditional encryption algorithms, which is easy to crack and has great security risks, resulting in the transaction process between financial institutions being easily leaked or The problems of low data confidentiality, integrity and real-time performance in transaction processes between financial institutions can be solved by, before the transaction process initiated or responded to by the business system of the financial institution begins, the random quantum key and symmetric encryption key shared by the business systems of the two financial institutions conducting the transaction can be determined based on the randomly generated quantum state and the data interaction between the business systems of the two financial institutions conducting the transaction, and the shared random quantum key and symmetric encryption key can be securely stored through a hardware security module. During the transaction process initiated or responded to by the business system of the financial institution, identity authentication and transaction data transmission can be performed based on the shared random quantum key and symmetric encryption key determined before the transaction begins. The reliability of identity authentication can be improved based on the authentication method combined with quantum state. The security of transaction data transmission can be improved based on the encryption method combined with quantum key and traditional encryption algorithm, thereby effectively protecting the transaction security of the transaction process initiated or responded to by the business system of the financial institution, avoiding the leakage or interruption of the transaction process initiated or responded by the business system of the financial institution due to abnormal events, and improving the data confidentiality, integrity and real-time performance of the transaction process between financial institutions.
[0106] In an optional implementation of the embodiment of the present invention, optionally, when performing the operation of determining the random quantum key and symmetric encryption key shared with the transaction response system that initiated the transaction request based on the randomly generated quantum state, the first protection module 402 is specifically configured to: randomly generate a quantum state, and send the quantum state to the transaction response system through a quantum communication channel between the first protection module 402 and the transaction response system, so that the transaction response system measures and encodes the quantum state through a shared test basis to obtain a shared random quantum key and feeds back the random quantum key; obtain the random quantum key fed back by the transaction response system; generate a symmetric encryption key shared with the transaction response system, and encrypt the symmetric encryption key using the random quantum key; and send the encrypted symmetric encryption key to the transaction response system through a classical communication channel between the first protection module 402 and the transaction response system, so that the transaction response system decrypts the encrypted symmetric encryption key based on the random quantum key to obtain the symmetric encryption key.
[0107] In an optional implementation manner of an embodiment of the present invention, optionally, when performing the operations of identity authentication and transaction data transmission according to the random quantum key and the symmetric encryption key during a transaction with the transaction response system, the first protection module 402 is specifically configured to: after detecting the authentication information of the transaction response system, authenticate the transaction response system according to the digital signature and the quantum state corresponding to the random quantum key; after detecting the transaction data corresponding to the transaction response system, encrypt the transaction data corresponding to the transaction response system by using the symmetric encryption key, and send the encrypted transaction data to the transaction response system through a secure network channel with the transaction response system, so that the transaction response system decrypts the encrypted transaction data according to the symmetric encryption key to obtain the transaction data.
[0108] In an optional implementation manner of the embodiment of the present invention, optionally, when performing the operation of determining the random quantum key and symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request, the second protection module 403 is specifically configured to: measure and encode the randomly generated quantum state sent by the transaction initiation system of the transaction response request received through a shared test basis to obtain the random quantum key shared with the transaction initiation system, and feed the random quantum key back to the transaction initiation system; receive the encrypted symmetric encryption key shared with the transaction initiation system sent by the transaction initiation system; wherein the encrypted symmetric encryption key shared with the transaction initiation system is encrypted based on the random quantum key; and decrypt the encrypted symmetric encryption key shared with the transaction initiation system based on the random quantum key to obtain the symmetric encryption key shared with the transaction initiation system.
[0109] In an optional implementation manner of an embodiment of the present invention, optionally, when the second protection module 403 performs the operation of identity authentication and transaction data transmission according to the random quantum key and the symmetric encryption key during a transaction with the transaction initiation system, it is specifically used to: after detecting the authentication information of the transaction initiation system, authenticate the transaction initiation system according to the digital signature and the quantum state corresponding to the random quantum key; after detecting the encrypted transaction data sent by the transaction initiation system, decrypt the encrypted transaction data sent by the transaction initiation system by using the symmetric encryption key to obtain the transaction data; wherein the encrypted transaction data sent by the transaction initiation system is encrypted according to the symmetric encryption key.
[0110] In an optional implementation of an embodiment of the present invention, the transaction security protection device between financial institutions may further include: an exception processing module, which is used to output alarm information and execute processing operations corresponding to the abnormal event when an abnormal event is detected.
[0111] The transaction security protection device between financial institutions provided by the embodiment of the present invention can execute the transaction security protection method between financial institutions provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0112] Example 5
[0113] Figure 5A schematic diagram of the structure of an electronic device 10 that can be used to implement the transaction security protection method between financial institutions according to an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, electronic devices, blade electronic devices, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0114] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0115] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0116] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processor, controller, microcontroller, etc. Processor 11 executes the various methods and processes described above, such as the transaction security protection method between financial institutions.
[0117] In some embodiments, the transaction security protection method between financial institutions can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit. In some embodiments, part or all of the computer program can be loaded and / or installed on a heterogeneous hardware accelerator via a ROM and / or a communication unit. When the computer program is loaded into RAM and executed by a processor, one or more steps of the transaction security protection method between financial institutions described above can be performed. Alternatively, in other embodiments, the processor can be configured to execute the transaction security protection method between financial institutions by any other appropriate means (for example, by means of firmware).
[0118] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0119] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or electronic device.
[0120] In the context of the present invention, computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0121] To provide interaction with a user, the systems and techniques described herein can be implemented on a heterogeneous hardware accelerator that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the heterogeneous hardware accelerator. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0122] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as data electronics), or a computing system that includes middleware components (e.g., application electronics), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0123] A computing system may include a client and an electronic device. The client and electronic device are generally remote from each other and typically interact via a communication network. The client-electronic device relationship is established by computer programs running on the respective computers and establishing a client-electronic device relationship. The electronic device may be a cloud electronic device, also known as a cloud computing electronic device or cloud host, a host product within a cloud computing service ecosystem that addresses the management difficulties and limited business scalability of traditional physical hosts and VPS services.
[0124] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0125] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A transaction security protection method between financial institutions, characterized in that: include: After detecting the protection start information, enter the transaction security protection mode; After detecting a transaction initiation request, determining a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request based on a randomly generated quantum state, storing the random quantum key and the symmetric encryption key in a hardware security module, and performing identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during a transaction with the transaction response system; After detecting a transaction response request, determine a random quantum key and a symmetric encryption key shared with the transaction initiation system based on the randomly generated quantum state sent by the transaction initiation system of the transaction response request, store the random quantum key and the symmetric encryption key in a hardware security module, and during a transaction with the transaction initiation system, perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key.
2. The transaction security protection method between financial institutions according to claim 1, characterized in that: Determining, based on the randomly generated quantum state, a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request, including: randomly generating a quantum state, and sending the quantum state to the transaction response system via a quantum communication channel between the transaction response system and the transaction response system, so that the transaction response system measures and encodes the quantum state using a shared test basis to obtain a shared random quantum key, and feeds back the random quantum key; Obtaining the random quantum key fed back by the transaction response system; generating a symmetric encryption key shared with the transaction response system, and encrypting the symmetric encryption key using the random quantum key; The encrypted symmetric encryption key is sent to the transaction response system through a classical communication channel with the transaction response system, so that the transaction response system decrypts the encrypted symmetric encryption key according to the random quantum key to obtain the symmetric encryption key.
3. The transaction security protection method between financial institutions according to claim 2, characterized in that: During a transaction with the transaction response system, identity authentication and transaction data transmission are performed according to the random quantum key and the symmetric encryption key, including: After detecting the authentication information of the transaction response system, authenticating the transaction response system based on the digital signature and the quantum state corresponding to the random quantum key; After detecting the transaction data corresponding to the transaction response system, the transaction data corresponding to the transaction response system is encrypted using the symmetric encryption key, and the encrypted transaction data is sent to the transaction response system through a secure network channel between the transaction response system and the transaction response system, so that the transaction response system decrypts the encrypted transaction data according to the symmetric encryption key to obtain the transaction data.
4. The transaction security protection method between financial institutions according to claim 1, characterized in that: Determining a random quantum key and a symmetric encryption key shared with the transaction initiating system based on a randomly generated quantum state sent by the transaction initiating system of the transaction response request, including: Measuring and encoding the randomly generated quantum state sent by the transaction initiating system of the received transaction response request through a shared test basis to obtain a random quantum key shared with the transaction initiating system, and feeding the random quantum key back to the transaction initiating system; receiving an encrypted symmetric encryption key shared with the transaction initiation system and sent by the transaction initiation system; wherein the encrypted symmetric encryption key shared with the transaction initiation system is encrypted based on the random quantum key; The encrypted symmetric encryption key shared with the transaction initiation system is decrypted according to the random quantum key to obtain the symmetric encryption key shared with the transaction initiation system.
5. The transaction security protection method between financial institutions according to claim 4, characterized in that: During a transaction with the transaction initiation system, identity authentication and transaction data transmission are performed according to the random quantum key and the symmetric encryption key, including: After detecting the authentication information of the transaction initiation system, authenticating the transaction initiation system according to the digital signature and the quantum state corresponding to the random quantum key; After detecting the encrypted transaction data sent by the transaction initiation system, the encrypted transaction data sent by the transaction initiation system is decrypted using the symmetric encryption key to obtain the transaction data; wherein the encrypted transaction data sent by the transaction initiation system is encrypted according to the symmetric encryption key.
6. The transaction security protection method between financial institutions according to claim 1, further comprising: When an abnormal event is detected, an alarm message is output and a processing operation corresponding to the abnormal event is executed.
7. A transaction security protection device between financial institutions, characterized in that: include: A mode entry module is used to enter the transaction security protection mode after detecting the protection start information; a first protection module configured to, after detecting a transaction initiation request, determine, based on a randomly generated quantum state, a random quantum key and a symmetric encryption key shared with a transaction response system of the transaction initiation request, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during a transaction with the transaction response system; The second protection module is configured to, after detecting a transaction response request, determine a random quantum key and a symmetric encryption key shared with the transaction initiating system based on a randomly generated quantum state sent by the transaction initiating system of the transaction response request, store the random quantum key and the symmetric encryption key in a hardware security module, and perform identity authentication and transaction data transmission based on the random quantum key and the symmetric encryption key during a transaction with the transaction initiating system.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the transaction security protection method between financial institutions according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the transaction security protection method between financial institutions according to any one of claims 1 to 6 when executed.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the computer program implements the transaction security protection method between financial institutions according to any one of claims 1 to 6.
Citation Information
Patent Citations
D2D secure mobile communication method and system based on quantum key
CN114362944A
Financial service data transmission method and device, computer equipment and storage medium
CN117278205A