A financial data encryption transmission system and method based on layered security architecture
Through layered security architecture design, multiple physical protections, high-speed differential signal transmission and double encryption processing, the security and reliability issues of the financial data transmission system are solved, efficient data encryption and key management are achieved, and the system's protection capabilities and data integrity are improved.
Patent Information
- Application Number
- CN202510149810.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-02-11
AI Technical Summary
When facing various security threats such as physical intrusion, electromagnetic leakage, and man-in-the-middle attacks, existing financial data transmission systems have problems such as low electromagnetic shielding effectiveness, incomplete temperature monitoring, poor signal integrity, single encryption mechanism, and key management risks, resulting in insufficient security and reliability.
It adopts a layered security architecture design, including an outer protection layer, a data transmission layer, a financial data processing layer and a core storage layer, which achieves multiple protections and high reliability through physical protection, electromagnetic shielding, high-speed differential signal transmission, double encryption processing and distributed key storage.
It achieves safe, reliable and high-performance encrypted transmission of financial data, effectively prevents physical and electromagnetic attacks, ensures data integrity and key security, and improves the stability and reliability of the system.
Smart Images

Figure CN119966733B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data transmission, and in particular relates to a financial data encryption transmission system and method based on a layered security architecture. Background Art
[0002] Financial data faces multiple security threats during transmission, including physical intrusion, electromagnetic leakage, and man-in-the-middle attacks. Its security is directly related to the stable operation of the financial system and the safety of user funds.
[0003] Currently, embedded systems used for financial data transmission generally use simple metal shielding. The metal shielding layer is usually a single-layer structure, with low electromagnetic shielding effectiveness and prone to the "honeycomb effect", that is, a sharp drop in shielding effectiveness in certain specific frequency bands. Temperature monitoring coverage is not comprehensive, and local overheating or cooling attacks cannot be detected in time, which makes the system vulnerable to temperature-based side-channel attacks. For example, attackers can use local cooling to leave memory data residuals, thereby stealing sensitive information.
[0004] In terms of data transmission, existing technologies mainly use single-ended signal transmission or simple differential transmission methods. In high-speed data transmission scenarios, this transmission method seriously degrades signal integrity. Single-ended signals are easily interfered by common-mode noise, and simple differential transmission can also cause signal reflection and crosstalk due to impedance mismatch. In addition, in terms of data encryption processing, most systems only use a single encryption algorithm, such as AES or SM4. The data integrity verification mechanism is simple, usually only using CRC and other checksums, which cannot effectively prevent targeted data tampering attacks. The centralized storage of keys poses a single point of failure risk. Once the storage medium is damaged or the key is leaked, the security of the entire system will collapse.
[0005] These problems seriously restrict the security and reliability of financial data transmission systems. Therefore, there is an urgent need to develop a new type of financial data encryption transmission system based on a layered security architecture. Summary of the Invention
[0006] The purpose of the present invention is to provide a financial data encryption transmission system and method based on a layered security architecture. Through technical innovations such as layered architecture design, multiple physical protection mechanisms, high-reliability data transmission technology, dual encryption processing mechanism, and distributed key storage scheme, a safe, reliable, and high-performance financial data encryption transmission system is realized.
[0007] In the first aspect, the present invention provides a financial data encryption transmission system based on a layered security architecture, wherein the multi-layer embedded circuit board includes multiple functional layers connected in sequence, and the functional layers are physically structured from the outside to the inside as follows: an outer protective layer, a data transmission layer, a financial data processing layer, and a core storage layer.
[0008] The outer protective layer is used for physical security protection of multi-layer embedded circuit boards. The outer protective layer includes: a physical tamper-proof shell, an electromagnetic shielding grid unit and a temperature sensor array unit. The physical tamper-proof shell is made of alloy material and is used to prevent external physical intrusion and destructive attacks; the electromagnetic shielding grid unit is arranged inside the physical tamper-proof shell and adopts a hexagonal honeycomb structure to prevent electromagnetic leakage and interference. The single side length is 2~3mm, achieving a shielding effectiveness of not less than 60dB; the temperature sensor array unit uses multiple temperature sensors evenly distributed in the electromagnetic shielding grid unit to monitor the temperature of the outer protective layer.
[0009] The data transmission layer is used for transmitting financial data, and the data transmission layer includes: a high-speed differential signal line pair, a crosstalk suppression structure and an impedance matching network; the characteristic impedance of the high-speed differential signal line pair is 100Ω±10%, the line width is 5±0.1mil, and the line spacing is 20±0.2mil; the near-end crosstalk NEXT of the crosstalk suppression structure is <-40dB, and the far-end crosstalk FEXT is <-35dB; the impedance matching network supports dynamic adjustment of 85Ω-115Ω, with a step accuracy of 0.5Ω.
[0010] The financial data processing layer is used to encrypt and verify financial data in real time. The financial data processing layer includes: an encryption processing unit, a key management unit and a data verification unit. The data verification unit uses the SHA-3 / SM3 algorithm to ensure data integrity.
[0011] The core storage layer is used to store financial data and event logs, and includes: a storage unit and an audit log unit; the storage unit stores the system's sensitive financial data and keys, and the keys are sharded using a threshold scheme; the audit log unit is used to record all encryption operations and abnormal events.
[0012] Furthermore, the outer protective layer is provided with an anti-electromagnetic leakage coating on the physical anti-tampering shell, and its attenuation coefficient is satisfy , ,in is the operating frequency, that is, the frequency of the financial data electrical signal, is the magnetic permeability, is the conductivity, is the coating thickness.
[0013] Furthermore, the key is stored in shards using a threshold scheme, and the threshold scheme includes:
[0014] The characteristic is a large prime number Finite field of Perform basic operations on Must be a prime number based on the master key to be split and Random coefficient construction polynomial , its construction formula is:
[0015] ;
[0016] in, is the master key to be split, , are randomly selected polynomial coefficients, each of which also belongs to , , The minimum number of shards required to reconstruct the key;
[0017] Evaluating polynomials exist Differences , The value at key shards , these shards are assigned to different storage locations so that any , shards can be used to reconstruct the master key, and Shards with 1 or fewer shards cannot obtain any information about the master key.
[0018] Furthermore, the differential signal of the data transmission layer satisfies the total timing deviation of the signal during transmission, that is, the total jitter cannot exceed 15% of the unit interval, , ,in, is random jitter, , is deterministic jitter;
[0019] Eye opening , ,in is high level, is low level, is the bit error rate.
[0020] Furthermore, the temperature sensing array unit includes multiple temperature sensors, the arrangement density of the temperature sensors is not less than 4 per square centimeter, the temperature monitoring accuracy is ±0.5°C, and the sampling frequency is not less than 10Hz; the temperature sensing array unit also includes a temperature abnormality alarm module, which triggers an alarm signal when it detects that the local temperature change rate is greater than 5°C / s or the temperature exceeds 85°C, and records the alarm information in the audit log unit.
[0021] Furthermore, the encryption processing unit adopts a dual encryption mechanism, including: a symmetric encryption module, which uses the AES-256 / SM4 algorithm for data encryption; an asymmetric encryption module, which uses the RSA-2048 / SM2 algorithm for key encapsulation;
[0022] The encryption processing unit has an operating speed of no less than 1 Gbps, supports parallel processing of multiple data streams, and has a hardware random number generator, the output of which passes the NISTSP800-22 randomness test.
[0023] In a second aspect, the present invention provides a method for encrypting and transmitting financial data based on a layered security architecture, which utilizes the financial data encryption transmission system based on a layered security architecture described in the first aspect to implement encrypted transmission of financial data. The method comprises:
[0024] Physical security protection is provided through the outer protective layer, and the integrity of the electromagnetic shielding grid unit is monitored. When a grid break or short circuit is detected, a system alarm is triggered; temperature data from the temperature sensor array unit is collected, and when abnormal temperature changes are detected, an alarm message is recorded.
[0025] Data transmission through the data transmission layer, real-time monitoring of differential signal integrity ,when When the impedance is automatically adjusted; crosstalk suppression is performed to ensure near-end crosstalk , far-end crosstalk .
[0026] Data is processed through the financial data processing layer, and the transmitted data is double-encrypted and the SHA-3 / SM3 algorithm is used for data integrity verification. The specific steps of the double encryption process include:
[0027] Step S31: Generate a session key using a hardware random number generator to generate a 256-bit symmetric encryption key.
[0028] Step S32, encrypting the transmitted data using the AES-256 / SM4 algorithm;
[0029] Step S33, encrypting the session key using the recipient's RSA-2048 / SM2 public key;
[0030] Step S34, encapsulating and transmitting the encrypted session key and data;
[0031] In step S35, the receiver first uses the private key to decrypt to obtain the session key, and then uses the session key to decrypt the data.
[0032] The core storage layer is used to store data, and the (t, k) threshold scheme is used to store keys in shards, and system operation logs and abnormal events are recorded.
[0033] Furthermore, the differential signal integrity in the data transmission layer The calculation formula is:
[0034] ;in, and Represent the positive and negative voltages of the differential pair, is the reference voltage, used for normalization of the formula, and its value is half of the differential swing; Indicates the jitter standard deviation, and the total jitter is obtained by eye diagram measurement , perform Gaussian decomposition to obtain the jitter standard deviation, and the number of measurement points should be no less than 10,000 sampling points; is the unit interval, i.e. a bit period of data transmission, ; is the observation period, the value is not less than 1000 .
[0035] Furthermore, the method for automatically adjusting the impedance of the data transmission layer includes:
[0036] Real-time acquisition of differential signal waveform data, when detected When the impedance is automatically adjusted, the impedance is gradually adjusted within the range of 85Ω-115Ω with a step accuracy of 0.5Ω.
[0037] Recalculate after each adjustment ,until Or when the adjustment range boundary is reached, the impedance adjustment process is recorded in the audit log unit.
[0038] Furthermore, the data integrity check using the SHA-3 / SM3 algorithm includes:
[0039] When the SHA-3 algorithm is selected: the Keccak-f
[1600] permutation function is executed for the absorption phase, the data block is XORed with the state matrix, and then the compression function is executed to generate the intermediate state;
[0040] When the SM3 algorithm is selected: message expansion is performed to generate 132 message words; the compression function is executed to generate intermediate states;
[0041] A final hash value is generated based on the intermediate state. For SHA-3, the hash value output length is 512 bits, and for SM3, the hash value output length is 256 bits. The hash value is encapsulated and transmitted together with the original data. The receiver recalculates the hash value of the received data and compares it with the received hash value. If there is any inconsistency, an integrity alarm is triggered.
[0042] The beneficial effects of the present invention are as follows:
[0043] The present invention realizes a secure, reliable and high-performance financial data encryption transmission system through layered architecture design, multiple physical protection mechanisms, high-reliability data transmission technology, dual encryption processing mechanism and distributed key storage solution, which has significant technical advantages and practical application value; the system can effectively solve the problems existing in the existing technology such as insufficient physical security protection, poor data transmission reliability, single encryption mechanism, and key management risks, and provides reliable technical support for the secure transmission of financial data. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 A schematic diagram of a financial data encryption transmission system based on a layered security architecture according to the present invention;
[0045] Figure 2 This is a signal normalized amplitude test diagram corresponding to different differential integrity levels according to the present invention. DETAILED DESCRIPTION
[0046] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention are described clearly and completely below. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present invention.
[0047] Example 1
[0048] like Figure 1 As shown, this is a schematic diagram of the composition of a financial data encryption transmission system based on a layered security architecture of the present invention. The multi-layer embedded circuit board includes multiple functional layers connected in sequence. The functional layers are physically structured from the outside to the inside as follows: an outer protective layer, a data transmission layer, a financial data processing layer, and a core storage layer.
[0049] The outer protective layer is used for physical security protection of multi-layer embedded circuit boards. It includes a physical tamper-proof housing, an electromagnetic shielding grid unit, and a temperature sensor array unit. The physical tamper-proof housing is made of an alloy material to prevent external physical intrusion and destructive attacks. The electromagnetic shielding grid unit, located within the physical tamper-proof housing, adopts a hexagonal honeycomb structure to prevent electromagnetic leakage and interference. Each side has a side length of 2-3mm and achieves a shielding effectiveness of no less than 60dB. Specifically, this embodiment uses a regular hexagonal honeycomb unit with a side length of 2.5mm. The conductive mesh layer is formed on an FR-4 substrate via a laser etching process, with a grid line width of 0.2mm. The conductive mesh layer is reliably connected to the physical tamper-proof housing via a welding process. This structure achieves an average shielding effectiveness of 65dB in the 100MHz-1GHz frequency band, and has good structural strength and strong resistance to mechanical impact. The temperature sensor array unit uses multiple temperature sensors evenly distributed within the electromagnetic shielding grid unit to monitor the temperature of the outer protective layer.
[0050] The data transmission layer is used for transmitting financial data, and the data transmission layer includes: a high-speed differential signal line pair, a crosstalk suppression structure and an impedance matching network; the characteristic impedance of the high-speed differential signal line pair is 100Ω±10%, the line width is 5±0.1mil, and the line spacing is 20±0.2mil; the near-end crosstalk NEXT of the crosstalk suppression structure is <-40dB, and the far-end crosstalk FEXT is <-35dB; the impedance matching network supports dynamic adjustment of 85Ω-115Ω, with a step accuracy of 0.5Ω.
[0051] The following measures are adopted to achieve crosstalk suppression: the minimum spacing between differential pairs is maintained at 4 times the line width, that is, 20mil; a "zigzag" staggered wiring strategy is adopted in key routing areas, and the staggered period of adjacent differential pairs is 1 / 4 of the signal rise time; ground via surround technology is used at interlayer vias, and the via spacing is 3 times the diameter of the signal via; actual measurement results show that: at a data rate of 1Gbps, the average near-end crosstalk is -45dB, and the maximum does not exceed -42dB; the average far-end crosstalk is -38dB, and the maximum does not exceed -36dB; the timing jitter caused by crosstalk is less than 0.02UI.
[0052] The financial data processing layer is used to encrypt and verify financial data in real time. The financial data processing layer includes: an encryption processing unit, a key management unit and a data verification unit. The data verification unit uses the SHA-3 / SM3 algorithm to ensure data integrity.
[0053] The core storage layer is used to store financial data and event logs, and includes: a storage unit and an audit log unit; the storage unit stores the system's sensitive financial data and keys, and the keys are sharded using a threshold scheme; the audit log unit is used to record all encryption operations and abnormal events.
[0054] The outer protective layer is also provided with an anti-electromagnetic leakage coating on the physical anti-tampering shell, and its attenuation coefficient is satisfy , ,in is the operating frequency, that is, the frequency of the financial data electrical signal, is the magnetic permeability, is the conductivity, is the coating thickness.
[0055] The key is stored in fragments using a threshold scheme, and the threshold scheme includes:
[0056] The characteristic is a large prime number Finite field of Perform basic operations on the master key to be split and Random coefficient construction polynomial , its construction formula is:
[0057] ;
[0058] in, is the master key to be split, , are randomly selected polynomial coefficients, each of which also belongs to , , The minimum number of shards required to reconstruct the key;
[0059] Evaluating polynomials exist Differences , The value at key shards , these shards are assigned to different storage locations so that any , shards can be used to reconstruct the master key, and Shards with 1 or fewer shards cannot obtain any information about the master key.
[0060] The differential signal of the data transmission layer satisfies the total timing deviation of the signal during transmission, that is, the total jitter cannot exceed 15% of the unit interval, , ,in, is random jitter, , is deterministic jitter;
[0061] Eye opening , ,in is high level, is low level, is the bit error rate.
[0062] The temperature sensing array unit includes multiple temperature sensors, the arrangement density of the temperature sensors is not less than 4 per square centimeter, the temperature monitoring accuracy is ±0.5°C, and the sampling frequency is not less than 10Hz; the temperature sensing array unit also includes a temperature abnormality alarm module, which triggers an alarm signal when it detects that the local temperature change rate is greater than 5°C / s or the temperature exceeds 85°C, and records the alarm information in the audit log unit.
[0063] Taking the initial impedance of 100Ω as an example, the system starts automatic adjustment when it detects SIdiff = 0.82:
[0064] (1) First, adjust upwards by 0.5Ω each time, and measure the SIdiff value three times to take the average value;
[0065] (2) After five adjustments to 102.5Ω, SIdiff = 0.86 was measured, meeting the requirement;
[0066] (3) Write the adjustment record [{time:t1, z:100Ω, si:0.82}, {time:t2, z:100.5Ω, si:0.83}, ..., {time:t6, z:102.5Ω, si:0.86}] into the log.
[0067] This embodiment can also adopt a partition monitoring strategy: divide the entire protection space into 16 monitoring areas, and configure 6 temperature sensors in each area; use a sliding average algorithm to process temperature data with a window size of 1s to reduce the impact of instantaneous fluctuations; set a three-level temperature warning mechanism: Level 1 warning: the temperature change rate of a single sensor is greater than 3°C / s, triggering log recording; Level 2 warning: the temperature change rate of more than 3 sensors in the area is greater than 4°C / s, triggering an alarm prompt; Level 3 warning: if the level 2 warning is met and the temperature exceeds 80°C, the system will be triggered to shut down protectively; when the temperature gradient of adjacent areas exceeds 10°C, the cross-validation mechanism will be activated to prevent misjudgment caused by sensor failure.
[0068] The encryption processing unit adopts a dual encryption mechanism, including: a symmetric encryption module, which uses the AES-256 / SM4 algorithm for data encryption; an asymmetric encryption module, which uses the RSA-2048 / SM2 algorithm for key encapsulation;
[0069] The encryption processing unit has an operating speed of no less than 1 Gbps, supports parallel processing of multiple data streams, and has a hardware random number generator, the output of which passes the NISTSP800-22 randomness test.
[0070] In the specific implementation, a comprehensive performance test was conducted on the encryption processing unit:
[0071] (1) Symmetric encryption performance: When processing 1MB data blocks, AES-256 achieves 2.3Gbps throughput, and SM4 achieves 2.1Gbps throughput.
[0072] (2) Asymmetric encryption performance: RSA-2048 can complete 2000 public key operations per second, and SM2 can complete 2500 signature operations per second.
[0073] (3) Parallel processing capability: When processing 8 data streams simultaneously, the total throughput remains above 1.8 Gbps and the CPU utilization does not exceed 85%.
[0074] (4) The output of the hardware random number generator has been tested by NIST SP800-22 and has passed the 0.01 significance level test in all 15 statistical tests.
[0075] Example 2
[0076] A method for encrypted transmission of financial data based on a layered security architecture, utilizing the system for encrypted transmission of financial data based on a layered security architecture described in the first aspect to implement encrypted transmission of financial data, the method comprising:
[0077] Physical security protection is provided through the outer protective layer, and the integrity of the electromagnetic shielding grid unit is monitored. When a grid break or short circuit is detected, a system alarm is triggered; temperature data from the temperature sensor array unit is collected, and when abnormal temperature changes are detected, an alarm message is recorded.
[0078] Data transmission through the data transmission layer, real-time monitoring of differential signal integrity ,when When the impedance is automatically adjusted; crosstalk suppression is performed to ensure near-end crosstalk , far-end crosstalk .
[0079] Data is processed through the financial data processing layer, and the transmitted data is double-encrypted and the SHA-3 / SM3 algorithm is used for data integrity verification. The specific steps of the double encryption process include:
[0080] Step S31: Generate a session key using a hardware random number generator to generate a 256-bit symmetric encryption key.
[0081] Step S32, encrypting the transmitted data using the AES-256 / SM4 algorithm;
[0082] Step S33, encrypting the session key using the recipient's RSA-2048 / SM2 public key;
[0083] Step S34, encapsulating and transmitting the encrypted session key and data;
[0084] In step S35, the receiver first uses the private key to decrypt to obtain the session key, and then uses the session key to decrypt the data.
[0085] The system's key management strategy specifically includes: session key lifecycle management, the maximum usage time of a single session key does not exceed 1 hour, the session key is forced to be updated when the amount of transmitted data exceeds 1GB, and the current session key is immediately discarded when a replay attack attempt is detected; key backup and recovery mechanism, the k shards of the master key are kept by k independent secure storage modules, each storage module uses independent encryption and access control mechanisms, and key integrity checks are performed regularly. If an abnormality is found, an alarm is triggered; key update strategy, the system master key is forced to be updated once a quarter, and the update process uses a double buffer mechanism to ensure the continuous operation of the system, retain the latest three versions of key materials, and support historical data decryption.
[0086] The core storage layer is used to store data, and the (t, k) threshold scheme is used to store keys in shards, and system operation logs and abnormal events are recorded.
[0087] like Figure 2 As shown in the figure, the signal normalized amplitude test diagram corresponding to different differential integrity of the present invention is shown. In the corresponding signal normalized amplitude test, the horizontal axis is time (ns) and the vertical axis is the normalized signal amplitude. It can be seen that when <0.78, the signal has obvious distortion and overshoot; the differential signal integrity in the data transmission layer satisfy: ; Figure 2 The normalized amplitude curves of the signals at different times clearly show the impact of differential integrity on signal quality. =0.92, the signal has the following characteristics: the overshoot / undershoot of the rising and falling edges are both less than 10%, the stability of the signal swing is within ±3%, and the signal cross point jitter is less than 0.1UI; in contrast, when =0.78, the signal quality is significantly reduced, the overshoot / undershoot increases to more than 15%, the signal swing fluctuation reaches ±8%, and the cross point jitter increases to more than 0.2UI; Therefore, this embodiment sets threshold.
[0088] The differential signal integrity calculation formula is:
[0089] ;in, and Represent the positive and negative voltages of the differential pair, is the reference voltage, used for normalization of the formula, and its value is half of the differential swing; Indicates the jitter standard deviation, and the total jitter is obtained by eye diagram measurement , perform Gaussian decomposition to obtain the jitter standard deviation, and the number of measurement points should be no less than 10,000 sampling points; is the unit interval, i.e. a bit period of data transmission, ; is the observation period, the value is not less than 1000 .
[0090] Taking a data transmission rate of 1 Gbps as an example, with UI = 1 ns and T = 1 μs for measurement, when Vp = 3.3 V, Vn = 0 V, Vref = 1.65 V, and σj = 50 ps, the calculated SIdiff = 0.92 meets the system requirements. Experimental verification shows that under these conditions, the bit error rate (BER) is less than 10-12.
[0091] The method for automatically adjusting the impedance of the data transmission layer includes:
[0092] Real-time acquisition of differential signal waveform data, when detected When the impedance is automatically adjusted, the impedance is gradually adjusted within the range of 85Ω-115Ω with a step accuracy of 0.5Ω.
[0093] Recalculate after each adjustment ,until Or when the adjustment range boundary is reached, the impedance adjustment process is recorded in the audit log unit.
[0094] The data integrity check using the SHA-3 / SM3 algorithm includes:
[0095] When the SHA-3 algorithm is selected: the Keccak-f
[1600] permutation function is executed for the absorption phase, the data block is XORed with the state matrix, and then the compression function is executed to generate the intermediate state;
[0096] When the SM3 algorithm is selected: message expansion is performed to generate 132 message words; the compression function is executed to generate intermediate states;
[0097] A final hash value is generated based on the intermediate state. For SHA-3, the hash value output length is 512 bits, and for SM3, the hash value output length is 256 bits. The hash value is encapsulated and transmitted together with the original data. The receiver recalculates the hash value of the received data and compares it with the received hash value. If there is any inconsistency, an integrity alarm is triggered.
[0098] For a 512-byte data block, this system, operating at a 1GHz clock speed, can process SHA-3 in under 2μs and SM3 in under 1.5μs. In practice, the system supports simultaneous processing of up to 16 data streams, and thanks to its hardware-accelerated hashing unit, it can achieve an overall throughput of 3.2GB / s.
[0099] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A financial data encryption transmission system based on a layered security architecture, characterized in that: The layered security architecture is implemented based on a multi-layer embedded circuit board. The multi-layer embedded circuit includes multiple functional layers connected in sequence. The multiple functional layers are physically arranged from the outside to the inside as follows: an outer protection layer, a data transmission layer, a financial data processing layer, and a core storage layer. The outer protective layer is used for physical security protection of the multi-layer embedded circuit board. The outer protective layer includes: a physical tamper-proof shell, an electromagnetic shielding grid unit, and a temperature sensor array unit. The physical tamper-proof shell is made of an alloy material to prevent external physical intrusion and destructive attacks. The electromagnetic shielding grid unit is arranged inside the physical tamper-proof shell and adopts a hexagonal honeycomb structure to prevent electromagnetic leakage and interference. The length of each side is 2-3mm, achieving a shielding effectiveness of not less than 60dB. The temperature sensor array unit uses multiple temperature sensors evenly distributed in the electromagnetic shielding grid unit to monitor the temperature of the outer protective layer. The data transmission layer is used to transmit financial data and includes: a high-speed differential signal line pair, a crosstalk suppression structure, and an impedance matching network; the characteristic impedance of the high-speed differential signal line pair is 100Ω±10%, the line width is 5±0.1mil, and the line spacing is 20±0.2mil; the near-end crosstalk (NEXT) of the crosstalk suppression structure is less than -40dB, and the far-end crosstalk (FEXT) is less than -35dB; the impedance matching network supports dynamic adjustment from 85Ω to 115Ω, with a step accuracy of 0.5Ω; The financial data processing layer is used to encrypt and verify financial data in real time. The financial data processing layer includes: an encryption processing unit, a key management unit, and a data verification unit. The data verification unit uses the SHA-3 / SM3 algorithm to ensure data integrity. The core storage layer is used to store financial data and event logs, and includes: a storage unit and an audit log unit; the storage unit stores the system's financial data and keys, and the keys are sharded using a threshold scheme; the audit log unit is used to record all encryption operations and abnormal events.
2. A financial data encryption transmission system based on a layered security architecture according to claim 1, characterized in that: The outer protective layer is also provided with an anti-electromagnetic leakage coating on the physical anti-tampering shell, and its attenuation coefficient is satisfy , ,in is the operating frequency, that is, the frequency of the financial data electrical signal, is the magnetic permeability, is the conductivity, is the coating thickness.
3. A financial data encryption transmission system based on a layered security architecture according to claim 2, characterized in that: The key is stored in fragments using a threshold scheme, and the threshold scheme includes: The characteristic is a large prime number Finite field of Perform basic operations on the master key to be split and Random coefficient construction polynomial , its construction formula is: ; in, is the master key to be split, , are randomly selected polynomial coefficients, each of which also belongs to , , The minimum number of shards required to reconstruct the key; Evaluating polynomials exist Differences , The value at key shards , these shards are assigned to different storage locations so that any , shards can be used to reconstruct the master key, and Shards with 1 or fewer shards cannot obtain any information about the master key.
4. A financial data encryption transmission system based on a layered security architecture according to claim 3, characterized in that: The differential signal of the data transmission layer satisfies the total timing deviation of the signal during transmission, that is, the total jitter cannot exceed 15% of the unit interval, , ,in, is random jitter, , represents the jitter standard deviation, is the observation period; is deterministic jitter; Eye opening , ,in is high level, is low level, is the bit error rate.
5. A financial data encryption transmission system based on a layered security architecture according to claim 4, characterized in that: The temperature sensing array unit includes multiple temperature sensors, the arrangement density of the temperature sensors is not less than 4 per square centimeter, the temperature monitoring accuracy is ±0.5°C, and the sampling frequency is not less than 10Hz; the temperature sensing array unit also includes a temperature abnormality alarm module, which triggers an alarm signal when it detects that the local temperature change rate is greater than 5°C / s or the temperature exceeds 85°C, and records the alarm information in the audit log unit.
6. A financial data encryption transmission system based on a layered security architecture according to claim 5, characterized in that: The encryption processing unit adopts a dual encryption mechanism, including: a symmetric encryption module, which uses the AES-256 / SM4 algorithm for data encryption; an asymmetric encryption module, which uses the RSA-2048 / SM2 algorithm for key encapsulation; The encryption processing unit has an operating speed of no less than 1 Gbps, supports parallel processing of multiple data streams, and has a hardware random number generator, the output of which passes the NISTSP800-22 randomness test.
7. A financial data encryption transmission method based on a layered security architecture, implemented using a financial data encryption transmission system based on a layered security architecture according to any one of claims 1 to 6, characterized in that: The method comprises: The outer protective layer provides physical security protection and monitors the integrity of the electromagnetic shielding grid unit. When a grid break or short circuit is detected, a system alarm is triggered. The temperature data of the temperature sensor array unit is collected and an alarm message is recorded when an abnormal temperature change is detected. Data transmission through the data transmission layer, real-time monitoring of differential signal integrity ,when When the impedance is automatically adjusted; crosstalk suppression is performed to ensure near-end crosstalk , far-end crosstalk ; Data is processed through the financial data processing layer, and the transmitted data is double-encrypted and the SHA-3 / SM3 algorithm is used for data integrity verification. The specific steps of the double encryption process include: Step S31: Generate a session key using a hardware random number generator to generate a 256-bit symmetric encryption key. Step S32, encrypting the transmitted data using the AES-256 / SM4 algorithm; Step S33, encrypting the session key using the recipient's RSA-2048 / SM2 public key; Step S34, encapsulating and transmitting the encrypted session key and data; In step S35, the receiver first uses the private key to decrypt the data to obtain the session key, and then uses the session key to decrypt the data. The core storage layer is used to store data, and the (t, k) threshold scheme is used to store keys in shards, and system operation logs and abnormal events are recorded.
8. The method for encrypting and transmitting financial data based on a layered security architecture according to claim 7, characterized in that: Differential signal integrity in the data transmission layer The calculation formula is: ;in, and Represent the positive and negative voltages of the differential pair, is the reference voltage, used for normalization of the formula, and its value is half of the differential swing; Indicates the jitter standard deviation, and the total jitter is obtained by eye diagram measurement , perform Gaussian decomposition to obtain the jitter standard deviation, and the number of measurement points should be no less than 10,000 sampling points; is the unit interval, i.e. a bit period of data transmission, ; is the observation period, the value is not less than 1000 .
9. The method for encrypting and transmitting financial data based on a layered security architecture according to claim 8, characterized in that: The method for automatically adjusting the impedance of the data transmission layer includes: Real-time acquisition of differential signal waveform data, when detected When the impedance is automatically adjusted, the impedance is gradually adjusted within the range of 85Ω-115Ω with a step accuracy of 0.5Ω. Recalculate after each adjustment ,until Or when the adjustment range boundary is reached, the impedance adjustment process is recorded in the audit log unit.
10. The method for encrypting and transmitting financial data based on a layered security architecture according to claim 9, characterized in that: The data integrity check using the SHA-3 / SM3 algorithm includes: When the SHA-3 algorithm is selected: the Keccak-f[1600] permutation function is executed for the absorption phase, the data block is XORed with the state matrix, and then the compression function is executed to generate the intermediate state; When the SM3 algorithm is selected: message expansion is performed to generate 132 message words; the compression function is executed to generate intermediate states; A final hash value is generated based on the intermediate state. For SHA-3, the hash value output length is 512 bits, and for SM3, the hash value output length is 256 bits. The hash value is encapsulated and transmitted together with the original data. The receiver recalculates the hash value of the received data and compares it with the received hash value. If there is any inconsistency, an integrity alarm is triggered.
Citation Information
Patent Citations
Method for processing full-metal-surface thin copper plate protecting film
CN108617106A
Blockchain data supervision method and system based on attribute encryption
CN111859444A