Method and device for processing return data

By using SFTP protocol and encryption factors to encrypt the private key of the merchant’s equipment in the online processing process of the return business, the security risks of the return business are solved, and the multi-level encryption protection of return requests is realized, which significantly improves the security of the return process.

CN119963306AInactive Publication Date: 2025-05-09BANK OF COMM CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510020115.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure CN119963306A_ABST
    Figure CN119963306A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a return data processing method and device, relates to the technical field of communication, and can improve the security of a return service. The return data processing method comprises the following steps: in response to a received encrypted return request sent by merchant equipment, determining a first encrypted private key and a second encrypted private key of the merchant equipment in a private key database based on a return identifier of the merchant equipment; decrypting the obtained target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant equipment; decrypting the first encrypted private key based on the encryption factor to obtain a first private key, and decrypting the second encrypted private key based on the encryption factor to obtain a second private key; decrypting the encrypted goods return request based on the first private key to obtain a goods return request, and verifying the integrity of the goods return request based on the second private key; and if the goods return request passes the integrity verification, carrying out goods return processing based on the goods return request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method and device for processing return data. Background Art

[0002] In the field of bank acquiring, transactions such as consumption and pre-authorization are called positive transactions, while returns are called negative transactions. Positive transactions have been processed online since the beginning of electronic acquiring business, but the online processing of negative transactions has always lagged behind the development speed of positive transactions. With the continuous advancement of information technology, the docking method of negative transactions (return business) has also developed from manual processing to online processing.

[0003] However, the online processing flow of the return business still has security risks, which may lead to serious security problems in the return business. For example, during the return process, the merchant equipment and the acquirer's return system are authenticated through FTP tools, and a simple account / password authentication mechanism is used to transmit return-related data. This return method has great security risks, such as being easily attacked by dictionary attacks and credential stuffing, making it impossible to complete the return business safely. Therefore, how to improve the security of the return business is an urgent problem to be solved. Summary of the invention

[0004] In order to solve the above problems, the present application provides a method and device for processing return data.

[0005] In a first aspect, a method for processing return data is provided, comprising:

[0006] In response to receiving an encrypted return request sent by a merchant device, determining a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device;

[0007] Decrypt the acquired target factor based on a preset encryption algorithm to obtain the encryption factor of the merchant device;

[0008] Decrypting the first encrypted private key based on the encryption factor to obtain the first private key, and decrypting the second encrypted private key based on the encryption factor to obtain the second private key;

[0009] decrypting the encrypted return request based on the first private key to obtain the return request, and verifying the integrity of the return request based on the second private key;

[0010] If the return request passes the integrity verification, the return process is performed based on the return request.

[0011] Furthermore, before receiving the return request sent by the merchant device, the method further includes:

[0012] Establish a connection with the merchant's equipment based on the SFTP protocol;

[0013] Receive the first private key and the second private key sent by the merchant device, and obtain the encryption factor;

[0014] Encrypting the first private key based on the encryption factor to obtain a first encrypted private key, and encrypting the second private key based on the encryption factor to obtain a second encrypted private key;

[0015] The first encrypted private key and the second encrypted private key are stored in a private key database, and the encryption factor is encrypted to obtain a target factor.

[0016] Further, encrypting the first private key based on the encryption factor to obtain the first encrypted private key, and encrypting the second private key based on the encryption factor to obtain the second encrypted private key, includes:

[0017] Divide the first private key into a plurality of first sub-private keys, and divide the second private key into a plurality of second sub-private keys;

[0018] Encrypting multiple first sub-private keys based on a preset encryption method and an encryption factor, and merging the encrypted multiple first sub-private keys to obtain a first encrypted private key;

[0019] Based on a preset encryption method and an encryption factor, multiple second sub-private keys are encrypted, and the encrypted multiple second sub-private keys are combined to obtain a second encrypted private key.

[0020] Further, the second private key is a grid cipher private key;

[0021] The steps of generating the second private key include:

[0022] The merchant device determines a cryptographic algorithm based on the return request;

[0023] The merchant device determines the structure of the second private key based on a lattice cryptographic algorithm;

[0024] The merchant device generates the second private key based on the structure of the second private key and preset cryptographic parameters.

[0025] Further, the return request includes a target return amount;

[0026] Perform return processing based on return requests, including:

[0027] Determine the original transaction corresponding to the return request based on the return request, where the original transaction includes the total transaction amount and the historical return amount;

[0028] The actual return amount is determined based on the target return amount, total transaction amount, and historical return amount.

[0029] In a second aspect, the present application provides a device for processing return data, comprising:

[0030] A private key determination module, configured to determine, in response to receiving an encrypted return request sent by a merchant device, a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device;

[0031] A first decryption module, used to decrypt the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device;

[0032] A second decryption module, configured to decrypt the first encrypted private key based on the encryption factor to obtain the first private key, and to decrypt the second encrypted private key based on the encryption factor to obtain the second private key;

[0033] A third decryption module, configured to decrypt the encrypted return request based on the first private key to obtain the return request, and verify the integrity of the return request based on the second private key;

[0034] The return processing module is used to perform return processing based on the return request if the return request passes the integrity verification.

[0035] Furthermore, the return data processing device also includes:

[0036] A connection establishment module is used to establish a connection with a merchant device based on the SFTP protocol;

[0037] A private key receiving module, used to receive a first private key and a second private key sent by a merchant device, and obtain an encryption factor;

[0038] A private key encryption module, configured to encrypt a first private key based on an encryption factor to obtain a first encrypted private key, and to encrypt a second private key based on the encryption factor to obtain a second encrypted private key;

[0039] The private key storage module is used to store the first encrypted private key and the second encrypted private key in a private key database, and encrypt the encryption factor to obtain the target factor.

[0040] Furthermore, the private key encryption module includes:

[0041] A private key division unit, used to divide the first private key into a plurality of first sub-private keys, and to divide the second private key into a plurality of second sub-private keys;

[0042] A first encryption unit, configured to encrypt a plurality of first sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted plurality of first sub-private keys to obtain a first encrypted private key;

[0043] The second encryption unit is used to encrypt multiple second sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted multiple second sub-private keys to obtain a second encrypted private key.

[0044] Further, the second private key is a grid cipher private key;

[0045] The steps of generating the second private key include:

[0046] The merchant device determines a cryptographic algorithm based on the return request;

[0047] The merchant device determines the structure of the second private key based on a lattice cryptographic algorithm;

[0048] The merchant device generates the second private key based on the structure of the second private key and preset cryptographic parameters.

[0049] Further, the return request includes a target return amount;

[0050] The return processing module includes:

[0051] The transaction determination unit is used to determine the original transaction corresponding to the return request based on the return request, and the original transaction includes the total transaction amount and the historical return amount.

[0052] The amount determination unit is used to determine the actual return amount based on the target return amount, the total transaction amount, and the historical return amount.

[0053] In a third aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method for processing return data when executing the program.

[0054] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-mentioned method for processing return data.

[0055] In a fifth aspect, the present application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the above-mentioned return data processing method.

[0056] The technical solution provided by the present application is that the acquirer return server encrypts the two private keys of the merchant device interacting with it through the encryption factor, and encrypts the encryption factor, so that when the acquirer server receives the return request from the merchant device, it first needs to decrypt the target factor to obtain the encryption factor, and then use the encryption factor to decrypt the encrypted private key to obtain multiple private keys, and finally use multiple private keys to decrypt the encrypted return request to obtain the complete return request. In the entire return process, the return request is protected at multiple levels. Even if one encryption layer is cracked, other layers can still provide protection, thereby improving the security of the return process. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate some embodiments of this specification or technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0058] Figure 1 A schematic diagram of the architecture of a return system provided in an embodiment of the present application;

[0059] Figure 2 A flowchart of a method for processing return data provided in an embodiment of the present application;

[0060] Figure 3 A flowchart of another method for processing return data provided in an embodiment of the present application;

[0061] Figure 4 A flowchart of another method for processing return data provided in an embodiment of the present application;

[0062] Figure 5 A flowchart of another method for processing return data provided in an embodiment of the present application;

[0063] Figure 6 A flowchart of another method for processing return data provided in an embodiment of the present application;

[0064] Figure 7 A schematic diagram of the structure of a device for processing return data provided in an embodiment of the present application;

[0065] Figure 8 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0066] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in some embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on some embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0067] It should be noted that the terms "first", "second", etc. in the specification and claims of this document and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of this document described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, device, product or equipment that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment. It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solution of this application comply with the relevant provisions of relevant laws and regulations.

[0068] With the continuous development of information technology and the intensification of commercial competition, the timeliness and quality of merchants' return services have become key factors in competition. A key factor for merchants to provide return services to customers is the clearing connection with banks. The connection method of return business has evolved from manual processing to online processing, but online processing has some restrictions on both the merchant side and the bank side. In the return process, the bank's security authentication of the merchant side is crucial. The traditional security authentication method is implemented through FTP tools, and the account / password authentication mechanism is used to transmit return-related data. However, this security authentication method has problems such as dictionary attacks and credential stuffing.

[0069] In the related art, although there is a secure file transfer protocol (SFTP) for data transmission, in actual application, the SSH protocol key used for encryption is not easy to save and is easy to lose. Therefore, how to improve the security of the return business is an urgent problem to be solved.

[0070] Based on this, the present application provides a method and device for processing return data, which improves the security of the return process through the SFTP protocol and additional encryption methods.

[0071] like Figure 1 As shown in FIG. 1 , it is a schematic diagram of the architecture of a return system provided in an embodiment of the present application. The method for processing return data provided in the present application can be applied to the following examples: Figure 1 The return system shown in the figure includes: an acquiring bank return server 10, a merchant device 20, an NGINX proxy server 30, a clearing server 40, and an account entry and debit server 50.

[0072] In some embodiments, the acquirer return server 10 interacts with the merchant device 20 through the NGINX proxy server 30. The SFTP protocol is established between the acquirer return server 10 and the merchant device 20, and the data transmission between the two is completed based on the SFTP protocol.

[0073] In some embodiments, the acquiring bank return server 10 receives a return request sent by the merchant device 20 through the NGINX proxy server, performs return processing based on the return request, and sends the return data to the merchant device 20 through the NGINX proxy server 30.

[0074] In some embodiments, after receiving the return request, the acquiring bank return server 10 initiates a settlement instruction to the settlement server 40 .

[0075] In some embodiments, the clearing server 40 performs business clearing based on the clearing instruction, and initiates an account entry and debit instruction to the account entry and debit server 50, so that the account entry and debit server 50 performs merchant debits and cardholder account entry.

[0076] like Figure 2 As shown, it is a flow chart of the method for processing return data provided by the present application. The method for processing return data is applied to the acquirer return server, and specifically includes the following steps:

[0077] S101. In response to receiving an encrypted return request sent by a merchant device, determine a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device.

[0078] S102: Decrypt the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device.

[0079] S103. Decrypt the first encrypted private key based on the encryption factor to obtain the first private key, and decrypt the second encrypted private key based on the encryption factor to obtain the second private key.

[0080] S104. Decrypt the encrypted return request based on the first private key to obtain the return request, and verify the integrity of the return request based on the second private key.

[0081] S105: If the return request passes the integrity verification, the return process is performed based on the return request.

[0082] The technical solution provided by the present application is that the acquirer return server encrypts the two private keys of the merchant device interacting with it through the encryption factor, and encrypts the encryption factor, so that when the acquirer server receives the return request from the merchant device, it first needs to decrypt the target factor to obtain the encryption factor, and then use the encryption factor to decrypt the encrypted private key to obtain multiple private keys, and finally use multiple private keys to decrypt the encrypted return request to obtain the complete return request. In the entire return process, the return request is protected at multiple levels. Even if one encryption layer is cracked, other layers can still provide protection, thereby improving the security of the return process.

[0083] Each step is explained in detail below:

[0084] S101. In response to receiving an encrypted return request sent by a merchant device, determine a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device.

[0085] Among them, the encrypted return request is the return request encrypted by the merchant device using the first public key and the second public key. The first public key is used to ensure the security of the return request. After the merchant device uses the first public key to encrypt the return request, the return request can only be obtained after the encrypted return request is decrypted using the first private key corresponding to the first public key. The second public key is used to ensure the integrity of the return request. After the merchant device uses the second public key to encrypt the return request, the integrity of the return request can be verified only after the encrypted return request is decrypted using the second private key corresponding to the second public key to determine whether the return request has been tampered with. The first encryption private key is the encrypted first private key, and the second encryption private key is the encrypted second private key.

[0086] Exemplarily, when an encrypted return request from a merchant device is received, the return identifier of the corresponding merchant device can be determined according to the encrypted return request. The return identifier of the merchant device is stored in the private key database together with the first encrypted private key and the second encrypted private key of the merchant device. Therefore, when an encrypted return request from a merchant device is received, the first encrypted private key and the second encrypted private key of the merchant device can be determined according to the return identifier. The return identifier of the merchant device can be a device identifier of the merchant device.

[0087] S102: Decrypt the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device.

[0088] Among them, the target factor is the encrypted encryption factor. The preset encryption algorithm can be a symmetric encryption algorithm, an asymmetric encryption algorithm, a hash algorithm, etc. After using the encryption factor to encrypt the first private key and the second private key, the acquirer return server encrypts the encryption factor by using the preset encryption algorithm to obtain the target factor. Exemplarily, encrypting the encryption factor to obtain the target factor and decrypting the target factor to obtain the encryption factor are both implemented using the same preset encryption algorithm. After decrypting the target factor to obtain the encryption factor, the acquirer return server stores the encryption factor in the memory.

[0089] S103. Decrypt the first encrypted private key based on the encryption factor to obtain the first private key, and decrypt the second encrypted private key based on the encryption factor to obtain the second private key.

[0090] Exemplarily, the encryption factor can be a string. In the actual encryption or encryption process, a fixed-length encryption key is generated based on the encryption factor and a key derivation function (such as PBKDF2, SHA-256), and encryption and decryption are performed based on the encryption key. For example, after obtaining the encryption factor, a fixed-length encryption key is generated by the encryption key and the SHA-256 function. Next, in order to enhance the security of encryption, a random initial variable is generated, and the first private key and the second private key are encrypted based on the encryption key, the initial variable, and the symmetric encryption algorithm to obtain the first encrypted private key and the second encrypted private key, and the first encrypted private key, the second encrypted private key and the initial variable are stored in the private key database. Correspondingly, in the decryption process, the first encrypted private key, the second encrypted private key and the initial variable are obtained, and the same encryption key in the encryption process is generated by the encryption factor and the initial variable, and the first encrypted private key and the second encrypted private key are decrypted based on the encryption key to obtain the first private key and the second private key.

[0091] S104. Decrypt the encrypted return request based on the first private key to obtain the return request, and verify the integrity of the return request based on the second private key.

[0092] Exemplarily, the acquiring bank return server first uses the first private key to decrypt the encrypted return request to obtain the return request. Then, the return request is verified for integrity using the second private key. For example, the second private key can be used to verify the hash signature of the return request to ensure that the return request has not been tampered with during transmission.

[0093] S105: If the return request passes the integrity verification, the return process is performed based on the return request.

[0094] Exemplarily, the return request passes the integrity verification, indicating that the return request has not been tampered with during the transmission process. The acquirer return server performs return processing based on the return request, generates corresponding return data after the return, and sends the actual return amount to the merchant device.

[0095] In some embodiments, data can be directly transmitted between the acquirer return server and the merchant device, such as a return request can be directly sent from the merchant device to the acquirer return server. Alternatively, to further provide data transmission security and reduce the performance pressure of the acquirer return server, the data transmission between the acquirer return server and the merchant device can be relayed by the NGINX proxy server. For example, the merchant device sends the return request to the NGINX proxy server, which then sends it to the acquirer return server. The acquirer return server sends the return data to the NGINX proxy server, which then sends it to the merchant device.

[0096] In some embodiments, Figure 3 As shown, before receiving the return request sent by the merchant device, it also includes:

[0097] S201. Establish a connection with a merchant device based on the SFTP protocol.

[0098] Exemplarily, the acquiring bank return server receives the connection establishment request from the merchant device and verifies the security of the merchant device. When the merchant device is confirmed to be secure, a connection is established with the merchant device based on the SFTP protocol to ensure that the subsequent first private key, second private key, return request and other related data are transmitted through the SFTP protocol to ensure the security of the data transmission process. In addition, when data transmission is not required, the SFTP connection can be actively closed to reduce the risk of data leakage.

[0099] S202: Receive a first private key and a second private key sent by a merchant device, and obtain an encryption factor.

[0100] Each merchant device corresponds to a unique encryption factor, and the encryption factor may be a string, a byte array, binary data, etc. For example, the encryption factor may be a 128-bit, 16-byte array generated by a random number generator.

[0101] It should be noted that before the acquirer return server receives the first private key and the second private key sent by the merchant device based on the SFTP protocol, the acquirer return server needs to set the encryption factor used to encrypt the first private key and the second private key in advance, and in order to ensure that the encryption factor is not leaked, it is also necessary to encrypt the encryption factor to obtain the target factor and store the target factor in the memory. Therefore, after receiving the first private key and the second private key sent by the merchant device, the acquirer return server needs to first obtain the target factor, decrypt it to obtain the encryption factor, and use the encryption factor to encrypt the first private key and the second private key.

[0102] S203: Encrypt the first private key based on the encryption factor to obtain a first encrypted private key, and encrypt the second private key based on the encryption factor to obtain a second encrypted private key.

[0103] Exemplarily, the acquiring bank's return server encrypts the first private key and the second private key respectively through an encryption factor and using a preset encryption algorithm (such as a symmetric encryption algorithm) to obtain a first encrypted private key and a second encrypted private key.

[0104] S204: Store the first encrypted private key and the second encrypted private key in a private key database, and encrypt the encryption factor to obtain a target factor.

[0105] Among them, the private key database is a database pre-set by the acquiring bank's return server, which is used to store private key information related to each merchant device, such as return identification, encryption private key and other information.

[0106] Exemplarily, the acquirer return server decrypts the target factor through a preset encryption algorithm to obtain an encrypted factor Y, and stores it in variable A. Further, the acquirer return server accesses the merchant's first private key and second private key, and reads the contents of the first private key and the second private key and stores them in variable B. Next, the acquirer return server encrypts variable B through variable A using a preset encryption algorithm to obtain an encrypted private key and stores it in variable C. Finally, the acquirer return server stores variable C in the private key database. In addition, in actual application, the acquirer return server may need to interact with multiple merchant devices. The acquirer return server needs to add a rotation mechanism to ensure that it can loop through the private key-related data of all merchant devices, and repeat the above steps to ensure that the private key information related to all merchant devices is stored in the private key database. In this way, the first private key and the second private key are encrypted through the encryption factor, and the encryption factor is encrypted, so that the double encryption of the private key is achieved, which can effectively avoid the related risks caused by the loss of the first private key and the second private key.

[0107] In some embodiments, Figure 4 As shown, encrypting the first private key based on the encryption factor to obtain the first encrypted private key, and encrypting the second private key based on the encryption factor to obtain the second encrypted private key can be specifically implemented as the following steps:

[0108] S301: Divide a first private key into a plurality of first sub-private keys, and divide a second private key into a plurality of second sub-private keys.

[0109] Exemplarily, the first private key and the second private key may be divided into a plurality of first sub-private keys and second sub-private keys of fixed lengths according to the lengths of the first private key and the second private key. For example, taking the first private key as an example, if the length of the first private key is 640, the first private key may be divided into five first sub-private keys of length 128. If the length of the first private key does not satisfy an integer multiple of the length of the sub-private key, such as if the length of the first private key is 639, the first private key may be divided by padding to obtain five first sub-private keys of length 128.

[0110] S302: Encrypt multiple first sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted multiple first sub-private keys to obtain a first encrypted private key.

[0111] Among them, the preset encryption methods include: Electronic Codebook Mode ECB, Cipher Block Chaining Mode CBC, Cipher Feedback Mode CFB, etc. It should be noted that block encryption can use different encryption methods to encrypt the first sub-private key to meet different security requirements and application scenarios. Exemplarily, the acquiring bank return server independently encrypts 5 first sub-private keys of length 128 respectively through the encryption factor and the selected encryption method, and merges the 5 encrypted first sub-private keys to obtain the first encrypted private key. Correspondingly, in the decryption process of the first encrypted private key, it is necessary to divide the first encrypted private key into 5 first sub-encrypted private keys of length 128, and decrypt them separately, and finally merge the 5 decrypted first sub-private keys to obtain the first private key.

[0112] S303: Encrypt multiple second sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted multiple second sub-private keys to obtain a second encrypted private key.

[0113] Exemplarily, the acquiring bank return server independently encrypts five second sub-private keys of length 128 by using the encryption factor and the selected encryption method, and merges the five encrypted second sub-private keys to obtain the second encrypted private key. Correspondingly, in the decryption process of the second encrypted private key, the second encrypted private key needs to be divided into five second sub-encrypted private keys of length 128, and the decryption processing is performed separately, and finally the five decrypted second sub-private keys are merged to obtain the second private key.

[0114] In this way, the first private key and the second private key are encrypted by means of group encryption, which further improves the security of the encryption, avoids the risks caused by the leakage of the encrypted private key, and ensures the security of the return process.

[0115] In some embodiments, Figure 5 As shown, the second private key is a cipher private key, and the steps of generating the second private key include:

[0116] S401. The merchant device determines a cryptographic algorithm based on a return request.

[0117] Among them, lattice cryptographic algorithms include: ring learning with errors (RLWE), module learning with errors (MLWE), and homomorphic encryption algorithms. Different lattice cryptographic algorithms have different characteristics. For example, RLWE is suitable for scenarios that require efficient polynomial operations and is often used for encryption, signing, homomorphic encryption, etc. MLWE can provide higher flexibility and security and is suitable for application scenarios that require a series of different data structures.

[0118] Specifically, a suitable lattice cryptographic algorithm can be selected according to the data type of the return request. For example, when the return request is text data, a lattice cryptographic algorithm that supports fast encryption and decryption, such as RLWE, MLWE, etc., can be selected. When the return request is image data, a homomorphic encryption algorithm that allows some operations to be performed on the encrypted image can be selected.

[0119] S402: The merchant device determines the structure of the second private key based on a lattice cryptographic algorithm.

[0120] Different lattice cryptographic algorithms correspond to different structures of the second private key. For example, the private key structure corresponding to RLWE is a polynomial, whose coefficients are selected from error distribution (such as Gaussian distribution). For another example, the private key structure corresponding to MLWE is a matrix, and the elements of the matrix are polynomials.

[0121] S403: The merchant device generates a second private key based on the structure of the second private key and preset cryptographic parameters.

[0122] Among them, the lattice cryptographic parameters include: modulus, dimension, error distribution, etc. Exemplarily, take the structure of the second private key as a polynomial as an example. In the process of generating the second private key, a random polynomial is first created, and the coefficients of the polynomial are generated according to the selected error distribution, where common error distributions include Gaussian distribution, uniform distribution, etc. Further, the coefficients of the polynomial are managed according to the modulus to ensure that the coefficients of the polynomial are all within the range of 0-modulus. Finally, the NumPy library in Python and the above-mentioned polynomial, modulus, dimension, and error distribution can be used to generate the second private key.

[0123] In some embodiments, the merchant device generates a second public key based on the second private key, the random polynomial, and the error polynomial.

[0124] Specifically, taking the second private key as a polynomial s(x) as an example, its corresponding second public key depends on the second private key and a set of random polynomials. For example, the structure of the second public key can be (a(x), b(x)), where a(x) is a random polynomial and b(x) is a polynomial calculated based on the second private key and the error polynomial. For example, b(x) in the second public key can be generated according to the following formula:

[0125] b(x)=a(x)·s(x)+e(x)mod q

[0126] Wherein, a(x) is a random polynomial, s(x) is the polynomial of the second private key, e(x) is a randomly generated error polynomial, and q is the modulus in the lattice cryptographic parameters, which is used to limit the range corresponding to the modulus of the calculation result.

[0127] In some embodiments, the merchant device performs block encryption on the return request using the second public key.

[0128] Specifically, when the return request is too large, the return request is first converted into a data format suitable for encryption, and then the return request is divided into multiple data blocks. Appropriate encoding or padding schemes are applied to each data block to ensure that it meets the relevant requirements of the second public key and the encryption algorithm. Then, each data block is encrypted using the second public key. During the encryption process, it is usually designed to map the data block to the lattice space, and then add a random error vector to generate an encrypted return request. In addition, for some lattice cipher variants, additional metadata or tags need to be generated to support the corresponding decryption process. Correspondingly, when the acquirer return server uses the second private key for decryption, it is necessary to map the encrypted return request back to the original data block and remove the previously added error vector. Then, the original data block is decrypted according to the lattice cipher variant and the second private key used, and the decryption process includes verifying the correctness of the metadata or tags to ensure the integrity and authenticity of the data. After the original data block is finally decrypted, the decrypted data block is reassembled into the original file format, the data block can be reassembled in the correct order, and the assembled data is integrity checked to ensure that no errors or damage are introduced during the decryption process.

[0129] In some embodiments, the acquiring bank return server may modify the access rights of the first private key and the second private key to further ensure the security of the first private key and the second private key.

[0130] Specifically, after the acquiring bank's return server uses the encryption factor to decrypt the first encrypted private key and the second encrypted private key to obtain the first private key and the second private key, the first private key and the second private key are stored as the first private key file and the second private key file, and placed in the specified file path to facilitate the subsequent decryption process. Furthermore, the access rights of the first private key file and the second private key file are modified to 600 to indicate that the private key file only allows the owner of the private key file to have read and write permissions, and prohibits other devices / users from accessing it. In addition, after the first private key file and the second private key file are used, the first private key file and the second private key file are deleted to ensure that the first private key file and the second private key file will not remain on the hard disk to prevent the risk of leakage.

[0131] In some embodiments, Figure 6 As shown, the return request includes a target return amount. Return processing is performed based on the return request, which can be specifically implemented as follows:

[0132] S501. Determine the original transaction corresponding to the return request based on the return request.

[0133] The original transaction includes the total transaction amount and the historical return amount, and the return request includes the transaction identifier of the original transaction and the target return amount. Exemplarily, after obtaining the return request, the acquirer return server determines the transaction identifier of the original transaction corresponding to the return request. Furthermore, the complete information of the original transaction is determined in the transaction-related database through the transaction identifier, such as the total transaction amount, the historical return amount, the number of historical returns, etc.

[0134] S502: Determine the actual return amount based on the target return amount, the total transaction amount, and the historical return amount.

[0135] For example, the total transaction amount obtained is 1,500 yuan, the historical return amount is 300 yuan, and the target return amount is 1,000 yuan. When the original transaction is completed, the crediting and debiting server credits 1,500 yuan, and the historical return amount is 300 yuan, so the remaining amount of the original transaction is 1,200 yuan, which is higher than the target return amount of 1,000 yuan. When it is determined that the return request meets the relevant regulations, the actual return amount is determined to be 1,000 yuan, and the return is successful, and the actual return amount is sent to the merchant device as return data.

[0136] In another example, the total transaction amount obtained is 1,500 yuan, the historical return amount is 600 yuan, and the target return amount is 1,000 yuan. When the original transaction is completed, the account debit server enters 1,500 yuan, and the historical return amount is 600 yuan. The remaining amount of the original transaction is 900 yuan, which is lower than the target return amount of 1,000 yuan. The actual return amount is determined to be the remaining amount of 900 yuan. If the total transaction amount obtained is 1,500 yuan, the historical return amount is 1,500 yuan, and the target return amount is 1,000 yuan, the remaining amount of the original transaction is 0 yuan, which cannot meet the return requirement, the return fails, and the relevant information of the return failure is sent to the merchant device as return data.

[0137] In some embodiments, in order to ensure the security of the transmission of return data, the private key of the merchant device is also used to encrypt it, and the encrypted return data is transmitted based on the SFTP protocol to further ensure the security of data transmission. Similarly, the process of encrypting return data with a private key is similar to the process of decrypting a return request with a private key. It is necessary to first obtain the encrypted encryption factor, decrypt it to obtain the encryption factor, and then decrypt the encrypted private key to obtain the private key. Finally, the return data is encrypted using the private key, an SFTP connection is established with the merchant device, and security authentication is performed. If the security authentication passes, the encrypted return data is sent to the merchant device.

[0138] To facilitate understanding of the technical solution provided by the present application, the technical solution is described here in the form of a complete example. Specifically, the acquiring bank return server first needs to set an encryption factor for encrypting the first private key and the second private key of the merchant device, and encrypt the encryption factor to obtain the target factor, and store the target factor in the memory. After the acquiring bank return server establishes an SFTP protocol connection with the merchant device, the merchant device sends the first private key and the second private key of the merchant device to the acquiring bank return server (in some embodiments, the merchant device will also send the first public key and the second public key to the acquiring bank return server, so that the acquiring bank return server can encrypt the relevant data of the return processing). In order to ensure the integrity of the first private key and the second private key, the acquiring bank return server obtains the target factor, and decrypts the target factor to obtain the encryption factor used to encrypt the first private key and the second private key, and then uses the encryption factor to encrypt the first private key and the second private key to obtain the first encrypted private key and the second encrypted private key, and stores them in the private key database, and at the same time encrypts the encryption factor to the target factor. The merchant device encrypts the return request using the first public key corresponding to the first private key and the second public key corresponding to the second private key to obtain an encrypted return request, and sends it to the acquirer return server based on the SFTP protocol. The above content is the pre-processing process before the acquirer return server receives the return request sent by the merchant device.

[0139] Next, after the acquirer's return server receives the encrypted return request sent by the merchant device, the acquirer's return server needs to first obtain the target factor and decrypt the target factor to obtain the encryption factor. Then, obtain the first encrypted private key and the second encrypted private key of the merchant device in the private key database, and use the encryption factor to decrypt the first encrypted private key and the second encrypted private key to obtain the first private key and the second private key of the merchant device. Finally, the encrypted return request is decrypted using the first private key and the second private key to obtain the return request, and the return process is performed based on the return request. After the return process, the first public key and the second public key of the merchant device are used to encrypt the relevant data of the return process and send it to the merchant device via the SFTP protocol.

[0140] The technical solution provided by the present application is that the acquirer return server encrypts the two private keys of the merchant device interacting with it through the encryption factor, and encrypts the encryption factor, so that when the acquirer server receives the return request from the merchant device, it first needs to decrypt the target factor to obtain the encryption factor, and then use the encryption factor to decrypt the encrypted private key to obtain multiple private keys, and finally use multiple private keys to decrypt the encrypted return request to obtain the complete return request. In the entire return process, the return request is protected at multiple levels. Even if one encryption layer is cracked, other layers can still provide protection, thereby improving the security of the return process.

[0141] It should be noted that the information collected in this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0142] It should be noted that the technical solution provided in this application provides users with corresponding operation entrances for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.

[0143] Figure 7 A return data processing device provided in an embodiment of the present application is used to execute the above return data processing method, such as Figure 7 As shown, the return data processing device includes: a private key determination module 701, a first decryption module 702, a second decryption module 703, a third decryption module 704, and a return processing module 705.

[0144] The private key determination module 701 is used to determine the first encrypted private key and the second encrypted private key of the merchant device in the private key database based on the return identifier of the merchant device in response to receiving the encrypted return request sent by the merchant device;

[0145] The first decryption module 702 is used to decrypt the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device;

[0146] A second decryption module 703, configured to decrypt the first encrypted private key based on the encryption factor to obtain the first private key, and to decrypt the second encrypted private key based on the encryption factor to obtain the second private key;

[0147] A third decryption module 704, configured to decrypt the encrypted return request based on the first private key to obtain the return request, and verify the integrity of the return request based on the second private key;

[0148] The return processing module 705 is used to perform return processing based on the return request if the return request passes the integrity verification.

[0149] Furthermore, the return data processing device also includes:

[0150] A connection establishment module is used to establish a connection with a merchant device based on the SFTP protocol;

[0151] A private key receiving module, used to receive a first private key and a second private key sent by a merchant device, and obtain an encryption factor;

[0152] A private key encryption module, configured to encrypt a first private key based on an encryption factor to obtain a first encrypted private key, and to encrypt a second private key based on the encryption factor to obtain a second encrypted private key;

[0153] The private key storage module is used to store the first encrypted private key and the second encrypted private key in a private key database, and encrypt the encryption factor to obtain the target factor.

[0154] Furthermore, the private key encryption module includes:

[0155] A private key division unit, used to divide the first private key into a plurality of first sub-private keys, and to divide the second private key into a plurality of second sub-private keys;

[0156] A first encryption unit, configured to encrypt a plurality of first sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted plurality of first sub-private keys to obtain a first encrypted private key;

[0157] The second encryption unit is used to encrypt multiple second sub-private keys based on a preset encryption method and an encryption factor, and merge the encrypted multiple second sub-private keys to obtain a second encrypted private key.

[0158] Further, the second private key is a grid cipher private key;

[0159] The steps of generating the second private key include:

[0160] The merchant device determines a cryptographic algorithm based on the return request;

[0161] The merchant device determines the structure of the second private key based on a lattice cryptographic algorithm;

[0162] The merchant device generates the second private key based on the structure of the second private key and preset cryptographic parameters.

[0163] Further, the return request includes a target return amount;

[0164] The return processing module 705 includes:

[0165] The transaction determination unit is used to determine the original transaction corresponding to the return request based on the return request, and the original transaction includes the total transaction amount and the historical return amount.

[0166] The amount determination unit is used to determine the actual return amount based on the target return amount, the total transaction amount, and the historical return amount.

[0167] The technical solution provided by the present application is that the acquirer return server encrypts the two private keys of the merchant device interacting with it through the encryption factor, and encrypts the encryption factor, so that when the acquirer server receives the return request from the merchant device, it first needs to decrypt the target factor to obtain the encryption factor, and then use the encryption factor to decrypt the encrypted private key to obtain multiple private keys, and finally use multiple private keys to decrypt the encrypted return request to obtain the complete return request. In the entire return process, the return request is protected at multiple levels. Even if one encryption layer is cracked, other layers can still provide protection, thereby improving the security of the return process.

[0168] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer device, and specifically, the computer device may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0169] An embodiment of the present invention provides a computer device, including a memory and a processor, the memory is used to store information including program instructions, the processor is used to control the execution of the program instructions, and the program instructions, when loaded and executed by the processor, implement the steps of the embodiment of the above-mentioned return data processing method. For a specific description, please refer to the embodiment of the above-mentioned return data processing method.

[0170] Reference below Figure 8 , which shows a schematic diagram of the structure of a computer device 800 suitable for implementing an embodiment of the present application.

[0171] like Figure 8 As shown, the computer device 800 includes a central processing unit (CPU) 801, which can perform various appropriate operations and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage part 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the computer device 800 are also stored. The CPU 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0172] The following components are connected to the I / O interface 805: an input section 806 including a keyboard, a mouse, etc.; an output section 807 including a cathode ray tube (CRT), a liquid crystal feedback device (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, a modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 810 as needed, so that a computer program read therefrom is installed as needed as the storage section 808.

[0173] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program tangibly contained on a machine-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 809, and / or installed from the removable medium 811.

[0174] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0175] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0176] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0177] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0178] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0179] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0180] The acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0181] It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned, and they should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0182] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0183] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0184] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0185] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A method for processing return data, characterized in that: include: In response to receiving an encrypted return request sent by a merchant device, determining a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device; Decrypting the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device; Decrypting the first encrypted private key based on the encryption factor to obtain a first private key, and decrypting the second encrypted private key based on the encryption factor to obtain a second private key; decrypting the encrypted return request based on the first private key to obtain a return request, and verifying the integrity of the return request based on the second private key; If the return request passes the integrity verification, the return process is performed based on the return request.

2. The method for processing return data according to claim 1, characterized in that: Before receiving the return request sent by the merchant device, it also includes: Establishing a connection with the merchant device based on the SFTP protocol; Receiving the first private key and the second private key sent by the merchant device, and obtaining the encryption factor; Encrypting the first private key based on the encryption factor to obtain the first encrypted private key, and encrypting the second private key based on the encryption factor to obtain the second encrypted private key; The first encryption private key and the second encryption private key are stored in the private key database, and the encryption factor is encrypted to obtain a target factor.

3. The method for processing return data according to claim 2, characterized in that: The step of encrypting the first private key based on the encryption factor to obtain the first encrypted private key, and encrypting the second private key based on the encryption factor to obtain the second encrypted private key includes: Divide the first private key into a plurality of first sub-private keys, and divide the second private key into a plurality of second sub-private keys; Encrypting the plurality of first sub-private keys based on a preset encryption method and the encryption factor, and combining the encrypted plurality of first sub-private keys to obtain the first encrypted private key; The plurality of second sub-private keys are encrypted based on the preset encryption method and the encryption factor, and the encrypted plurality of second sub-private keys are combined to obtain the second encrypted private key.

4. The method for processing return data according to claim 1, characterized in that: The second private key is a grid cipher private key; The step of generating the second private key comprises: The merchant device determines a cryptographic algorithm based on the return request; The merchant device determines the structure of the second private key based on the lattice cryptographic algorithm; The merchant device generates the second private key based on the structure of the second private key and preset cryptographic parameters.

5. The method for processing returned goods data according to claim 1, characterized in that: The return request includes a target return amount; The returning process based on the returning request includes: Determine, based on the return request, an original transaction corresponding to the return request, wherein the original transaction includes a total transaction amount and a historical return amount; The actual return amount is determined based on the target return amount, the total transaction amount, and the historical return amount.

6. A device for processing return data, characterized in that: include: A private key determination module, configured to determine, in response to receiving an encrypted return request sent by a merchant device, a first encrypted private key and a second encrypted private key of the merchant device in a private key database based on a return identifier of the merchant device; A first decryption module, configured to decrypt the acquired target factor based on a preset encryption algorithm to obtain an encryption factor of the merchant device; A second decryption module, configured to decrypt the first encrypted private key based on the encryption factor to obtain a first private key, and to decrypt the second encrypted private key based on the encryption factor to obtain a second private key; A third decryption module, configured to decrypt the encrypted return request based on the first private key to obtain a return request, and verify the integrity of the return request based on the second private key; A return processing module is used to perform return processing based on the return request if the return request passes the integrity verification.

7. The device for processing returned goods data according to claim 6, characterized in that: Also includes: A connection establishment module, used to establish a connection with the merchant device based on the SFTP protocol; A private key receiving module, used to receive the first private key and the second private key sent by the merchant device, and obtain the encryption factor; a private key encryption module, configured to encrypt the first private key based on the encryption factor to obtain the first encrypted private key, and to encrypt the second private key based on the encryption factor to obtain the second encrypted private key; A private key storage module is used to store the first encryption private key and the second encryption private key in the private key database, and encrypt the encryption factor to obtain a target factor.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method for processing return data described in any one of claims 1 to 5 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for processing return data described in any one of claims 1 to 5 are implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method for processing return data described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Data security interactive method

    CN103944735A

  • Identity real-name authentication method and authentication system based on express sending

    CN105554032A

  • Return verification method and system based on block chain, server and terminal

    CN111639952A

  • Key escrow method and device, equipment and storage medium

    CN116388979A

  • Order online payment system and payment method

    CN116629871A