Upgrading method of cabinet external cleaning equipment and computer readable storage medium
Through certificate file authorization and encryption protection, the legality and security of the upgrade and maintenance of off-cabinet cleaning equipment are ensured. Through automated upgrade process, the problems of high upgrade and maintenance costs, troublesome operation and unsafe compliance in the existing technology are solved, and efficient and safe upgrade and maintenance are achieved.
Patent Information
- Application Number
- CN202411989855.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-27
AI Technical Summary
The upgrade and maintenance of existing off-cabinet cleaning equipment has legality and safety issues, and the upgrade and maintenance cost is high, the operation is troublesome, and it is unsafe and compliant.
Through the form of certificate file authorization, ensure the legality of the upgrade and maintenance operation, and protect the upgrade files through encryption to prevent malicious tampering. Use bank terminals to automatically push certificate files to the outside cabinet clearing equipment through the HID protocol to achieve unmanned automation upgrades.
It improves the legality and safety of the upgrade and maintenance of off-cabinet cleaning equipment, reduces the joint commissioning efficiency of equipment manufacturers and banks, reduces the upgrade and maintenance costs, and enhances the convenience and safety of operation.
Smart Images

Figure CN120046140A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of equipment upgrading, and particularly relates to an upgrading method for off-counter cleaning equipment and a computer-readable storage medium. Background Art
[0002] Most of the current off-counter cleaning equipment used by banks adopts the Android system. Compared with ordinary Android devices, due to security considerations, bank off-counter cleaning equipment requires customization, such as shielding the native system desktop and prohibiting the WiFi communication networking function. Although this design can improve the security of the device system, it also makes it difficult to upgrade and maintain the device. With the expansion of banking services, the degree of customer customization of off-counter cleaning products is getting higher and higher, and the UI (User Interface) requirements change more frequently. Currently, every time a bank requests to change the UI of the device application program, the device manufacturer needs to cooperate to develop the corresponding application program apk, and after the manufacturer upgrades the device, the bank can start joint debugging and testing to see the display effect on the device side. This solution not only has a long demand confirmation cycle, low development and joint debugging efficiency, but also has a high cost of upgrading and maintenance. Because off-counter cleaning equipment cannot be connected to the Internet, at present, some off-counter cleaning equipment upgrades and maintenance are carried out by inserting a TF card or a USB flash drive and other storage media into the device card slot and entering the background setting interface to upgrade the device. This solution requires manual operation to upgrade each device using a TF card or a USB flash drive and other storage media, which is not only time-consuming but also troublesome to operate. Moreover, the upgrade source is stored in an external storage medium, which is easy to be stolen and tampered with, and is not safe and compliant. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide an upgrading method for off-counter cleaning equipment and a computer-readable storage medium, which can improve the legality and security of the upgrading and maintenance operations of off-counter cleaning equipment.
[0004] To solve the above technical problem, the technical solution adopted by the present invention is: an upgrading method for off-counter cleaning equipment, including: The off-counter cleaning equipment listens for whether the certificate file is updated. The certificate file includes subject data and basic data. The subject data includes data obtained by encrypting the certificate issuer and the upgrade file with a key pair. The basic data includes the key index number of the key. If updated, the off-counter cleaning equipment determines the key according to the basic data in the latest certificate file and the key data stored by itself, and decrypts the subject data in the latest certificate file with the key to obtain the certificate issuer and the upgrade file. Judge whether the decrypted certificate issuer is correct. If correct, upgrade the application of the off-counter cleaning equipment according to the decrypted upgrade file.
[0005] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned method is implemented.
[0006] The beneficial effects of the present invention are as follows: The legality of the entire upgrade and maintenance operation can be ensured through the form of certificate file authorization; the main part of the certificate file is encrypted, which can prevent the upgrade file from being maliciously tampered with, greatly improving the security. Moreover, the confirmation of the certificate issuer further standardizes the use of the upgrade and maintenance operation of the off-cabinet cleaning device, ensuring that it will not be misused. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figure 1 It is a flowchart of a method for upgrading an off-cabinet cleaning device according to the present invention; Figure 2 It is a flowchart of the method in the first embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0008] To describe in detail the technical content, the achieved objectives and the effects of the present invention, the following is described in conjunction with the embodiments and with reference to the drawings.
[0009] Please refer to Figure 1 , a method for upgrading an off-cabinet cleaning device, comprising: The off-cabinet cleaning device monitors whether the certificate file is updated. The certificate file includes main data and basic data. The main data includes data obtained by encrypting the certificate issuer and the upgrade file with a key. The basic data includes the key index number of the key. If it is updated, the off-cabinet cleaning device determines the key according to the basic data in the latest certificate file and the key data stored in itself, and decrypts the main data in the latest certificate file with the key to obtain the certificate issuer and the upgrade file. Judge whether the decrypted certificate issuer is correct. If it is correct, upgrade the application of the off-cabinet cleaning device according to the decrypted upgrade file.
[0010] As can be seen from the above description, the beneficial effects of the present invention are as follows: It can improve the legality and security of the upgrade and maintenance operation of the off-cabinet cleaning device.
[0011] Further, before the off-cabinet cleaning device monitors whether the certificate file is updated, it further includes: The device manufacturer randomly generates a preset number of keys, and imports the preset number of keys, their corresponding encryption algorithm types and key index numbers as key data into the encryption chip of the off-cabinet cleaning device when the device leaves the factory.
[0012] As described above, by importing the key data into the encryption chip of the off-site clearing device when it leaves the factory, it is convenient for the subsequent off-site clearing device to determine the specific decryption key and ensure the security of the key.
[0013] Further, before the off-site clearing device monitors whether the certificate file is updated, it further includes: The device manufacturer randomly selects a key from the preset number of keys, and generates a certificate file according to the upgrade file and the one key; Deploy the certificate file to the bank back-end server; The bank terminal obtains the certificate file from the bank back-end server; The bank terminal determines whether the certificate file in the off-site clearing device is consistent with the certificate file stored by itself; If they are inconsistent, the bank terminal pushes the certificate file stored by itself to the off-site clearing device through the HID protocol.
[0014] As described above, when the bank terminal initiates a business transaction, the certificate file is automatically pushed to the off-site clearing device through the HID protocol of the off-site clearing device to complete the upgrade, without the need to manually operate the upgrade device using an external storage medium, improving the convenience of the upgrade.
[0015] Further, generating the certificate file according to the upgrade file and the one key includes: Generate basic data according to the encryption algorithm type and key index number corresponding to the one key; Encrypt the certificate issuer and the upgrade file with the one key to obtain the subject data; Generate a certificate file according to the basic data and the subject data.
[0016] As described above, the key is not directly introduced into the certificate file, but its encryption algorithm type and index number are recorded to ensure the security of the key; by encrypting the upgrade file, the upgrade file can be prevented from being maliciously tampered with, ensuring the security of the upgrade file.
[0017] Further, the bank terminal determines whether the certificate file in the off-site clearing device is consistent with the certificate file stored by itself, including: The bank terminal determines whether the hash value of the certificate file in the off-site clearing device is consistent with the hash value of the certificate file stored by itself.
[0018] As described above, it is possible to determine whether the certificate files are consistent by comparing the MD5 values.
[0019] Further, the out-of-counter clearing device determines a key according to the basic data in the latest certificate file and the key data stored by itself, and decrypts the main data in the latest certificate file according to the key to obtain the certificate issuer and the upgrade file, including: The out-of-counter clearing device reads the basic data in the latest certificate file and transmits it to the encryption chip; The encryption chip obtains the corresponding key from the key data stored by itself according to the encryption algorithm type and the key index number in the basic data; The main data in the latest certificate file is decrypted by the corresponding key to obtain the certificate issuer and the upgrade file.
[0020] Further, the upgrade file includes an interface file; The upgrade of the out-of-counter clearing device application according to the decrypted upgrade file includes: Updating the application page of the out-of-counter clearing device according to the decrypted interface file.
[0021] Further, the updating of the application page of the out-of-counter clearing device according to the decrypted interface file includes: Save the decrypted interface file to the file system of the out-of-counter clearing device, and load the interface file in the file system through the Webview control.
[0022] As can be seen from the above description, each time the bank changes the UI requirements, it can customize the interface solution. The device manufacturer only needs to cooperate to generate the certificate file and does not need to cooperate with the bank to develop the out-of-counter clearing device application program, which can greatly reduce the upgrade and maintenance costs of the device manufacturer.
[0023] Further, the interface file is a Web template page file.
[0024] As can be seen from the above description, by adopting the Web template page, what you see is what you get. Without upgrading the application program apk of the out-of-counter clearing device, the effect can be seen, the demand confirmation cycle is shortened, and the joint debugging efficiency of the device manufacturer and the bank is effectively improved.
[0025] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described above is implemented.
[0026] Embodiment 1 Please refer to Figure 2 , Embodiment 1 of the present invention is: a method for upgrading an out-of-counter clearing device. In this embodiment, taking the update of the out-of-counter clearing device application page as an example for description.
[0027] As Figure 2 shown, it includes the following steps: S1: When the off-site clearing device leaves the factory, the device manufacturer imports the key data into the encryption chip of the off-site clearing device.
[0028] Specifically, the device manufacturer randomly generates a preset number of keys through a key management tool. In this embodiment, 16 groups of international algorithm (3DES) keys and national cryptography algorithm (SM4) keys are randomly generated respectively, and a corresponding key index number is generated for each key. Then, according to each key, its corresponding encryption algorithm type, and the key index number, key data is generated and imported into the password keyboard encryption chip of the off-site clearing device for storage when the off-site clearing device leaves the factory.
[0029] Furthermore, the following operations will also be performed when the off-site clearing device leaves the factory: 1. The off-site clearing device manufacturer and the bank agree on corresponding js (JavaScript) methods. For example, it is agreed that clicking on the physical button on the device side calls the corresponding js method, and the execution result is returned to the device side through the agreed js method (such as the alert() method).
[0030] 2. When the off-site clearing device leaves the factory, it is built-in with an Android WebView control and an application for JS interaction, as well as a set of initial interface files (initial Web template page files).
[0031] 3. When the off-site clearing device leaves the factory, it is built-in with a set of high-speed HID data download protocols, which are used to push interface files to the device side through HID (Human Interface Device) when the bank initiates business transactions later.
[0032] S2: The device manufacturer randomly selects one key from the preset number of keys, generates a certificate file according to the upgrade file and the one key, and deploys the certificate file to the bank's back-end server.
[0033] In this embodiment, the certificate file includes subject data and basic data. Specifically, the device manufacturer randomly selects one group of keys, encrypts the certificate issuer and the upgrade file with this key to obtain the subject data of the certificate file, and at the same time takes the corresponding encryption algorithm type and key index number of this key as the basic data of the certificate file. After generating the certificate file, the device manufacturer will provide the certificate file to the science and technology department of the bank, and the bank's science and technology personnel will deploy the certificate file to the back-end server of the trading system.
[0034] In this embodiment, the upgrade file includes an interface file, namely a Web template page file, which contains Html code, CSS style sheets, JavaScript code, and image resources. Among them, the Html code defines various parts of the page, such as titles, paragraphs, lists, tables, etc. by using various tags, thereby constructing the basic framework of the page. Through the CSS style sheets, the position, font, color, and other styles of the elements in the web page can be precisely controlled, thus achieving diverse page effects. By introducing image resources, the page content becomes more abundant, enhancing the visual appeal of the page. Through the JavaScript code, two-way interaction with the out-of-cabinet clearing device application can be achieved.
[0035] S3: The bank terminal obtains the certificate file from the bank's back-end server.
[0036] Specifically, when the bank terminal initiates a business transaction, the terminal transaction system will obtain the certificate file through the bank's internal network.
[0037] S4: The bank terminal determines whether the certificate file in the out-of-cabinet clearing device is consistent with the certificate file stored in itself. If not, step S5 is executed.
[0038] Specifically, when the bank terminal initiates a business transaction, it first determines whether the MD5 value of the certificate file in the out-of-cabinet clearing device is consistent with the MD5 value of the certificate file saved in itself. If they are consistent, it does not need to be pushed to the out-of-cabinet clearing device.
[0039] S5: The bank terminal pushes the certificate file stored in itself to the out-of-cabinet clearing device.
[0040] Specifically, the bank terminal pushes the certificate file to the out-of-cabinet clearing device through the HID protocol.
[0041] S6: The out-of-cabinet clearing device listens for whether the certificate file is updated. If so, step S7 is executed.
[0042] S7: The out-of-cabinet clearing device determines the key based on the basic data in the latest certificate file and the key data stored in itself, and decrypts the main data in the latest certificate file according to the key to obtain the certificate issuer and the upgrade file.
[0043] Specifically, if the certificate is updated, first read the basic data in the certificate file and transmit it to the encryption chip. The encryption chip determines whether it is an international algorithm (3DES) key or a national cryptographic algorithm (SM4) key according to the encryption algorithm type in the basic data, and then obtains the specific key from the key data stored in itself according to the key index number. After taking out the key, decrypt the main data in the certificate file to obtain the certificate issuer and the upgrade file.
[0044] S8: Determine whether the certificate issuer obtained by decryption is correct. If so, execute step S9.
[0045] If the decryption is successful, verify the certificate issuer. For example, it can be determined whether the certificate issuer is a preset device manufacturer. If so, the certificate issuer is considered correct.
[0046] S9: Perform an upgrade of the out-of-cabinet cleaning device application according to the upgrade file obtained by decryption.
[0047] After confirming that it is the correct certificate issuer, save the upgrade file obtained by decryption to the file system of the out-of-cabinet cleaning device. In this embodiment, the interface file (Web template page file) is saved to the file system of the out-of-cabinet cleaning device, and then the out-of-cabinet cleaning device application page is updated according to the interface file.
[0048] Specifically, the out-of-cabinet cleaning device uses the Webview control provided by the Android system to load the interface file in the file system, thereby completing the update of the out-of-cabinet cleaning device application page.
[0049] For example, the out-of-cabinet cleaning application calls the loadUrl() method or the evaluateJavascript() method through a Webview instance to execute the corresponding JavaScript code in the Web template page, thereby implementing functions such as submitting forms, responding to button clicks, and validating inputs to update the Web page. The Webview instance of the out-of-cabinet cleaning application registers object mapping through the addJavascriptInterface() method or intercepts the alert(), confirm(), and prompt() message contents of the JavaScript code dialog box through the WebChromeClient callback, and sends the results returned by the JavaScript code to the out-of-cabinet cleaning device application, thereby realizing two-way interaction between the Web page and the out-of-cabinet cleaning device.
[0050] In the prior art, during the joint debugging process with the bank, it is necessary to upgrade the device application first to see the modification effect, which affects the joint debugging efficiency. Moreover, every time the bank changes the UI requirements, the device manufacturer needs to upgrade the device application, and the upgrade process takes a long time and there may be damage to the application upgrade.
[0051] In this embodiment, by using a Web template page, what you see is what you get. Without upgrading the application program apk of the off-counter clearing device, the effect can be seen, the requirement confirmation cycle is shortened, and the joint debugging efficiency of the device manufacturer and the bank is effectively improved. Every time the bank changes the UI requirement, the device manufacturer only needs to provide the Web template page to the bank side. Without upgrading the device, the bank side can directly see the UI effect on the PC side, shortening the requirement confirmation cycle and greatly improving the joint debugging efficiency. Moreover, this embodiment can avoid problems such as insufficient internal network bandwidth, long upgrade installation time, poor upgrade experience, and abnormal subsequent startup of the device caused by abnormal power-off during the upgrade process when upgrading the device application program apk. This embodiment has strong flexibility. In the later stage, the bank can develop and customize the Web template page by itself. The device manufacturer only needs to cooperate in making the certificate file and does not need to cooperate with the bank side in developing the off-counter clearing device application program, which can greatly reduce the upgrade and maintenance costs of the device manufacturer. Also, through the form of certificate file authorization, the legality of the entire upgrade and maintenance operation can be ensured. By encrypting the Web template page file, the Web template page file can be prevented from being maliciously tampered with, greatly improving the security.
[0052] Embodiment 2 This embodiment is a computer-readable storage medium corresponding to the above embodiment, on which a computer program is stored. When the program is executed by a processor, it realizes each step of an upgrade method for an off-counter clearing device as described in the above embodiment and can achieve the same technical effect, which will not be repeated here.
[0053] In summary, for an upgrade method and a computer-readable storage medium for an off-counter clearing device provided by the present invention, through the form of certificate file authorization, the legality of the entire upgrade and maintenance operation can be ensured; the main part of the certificate file is encrypted to prevent the upgrade file from being maliciously tampered with, greatly improving the security. Also, the confirmation of the certificate issuer further standardizes the use of the upgrade and maintenance operation of the off-counter clearing device to ensure that it will not be misused; when a business transaction is initiated by a bank terminal, the certificate file is automatically pushed to the off-counter clearing device through the HID protocol of the off-counter clearing device to complete the upgrade, eliminating the need to manually operate the upgrade device using an external storage medium, improving the convenience of the upgrade; at the same time, it has strong flexibility, allowing the bank to develop and customize the Web template page by itself. The device manufacturer only needs to cooperate in making the certificate file and does not need to cooperate with the bank side in developing the off-counter clearing device application program, which can greatly reduce the upgrade and maintenance costs of the device manufacturer.
[0054] The above are only the embodiments of the present invention and do not limit the patent scope of the present invention. All equivalent transformations made using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, are equally included in the patent protection scope of the present invention.
Claims
1. A method for upgrading an off-cabinet cleaning device, characterized in that: include: The off-counter cleaning device monitors whether the certificate file is updated, the certificate file includes main data and basic data, the main data includes data encrypted by a key to the certificate issuer and the upgrade file, and the basic data includes the key index number of the key; If updated, the off-counter clearing device determines the key based on the basic data in the latest certificate file and the key data stored in itself, and decrypts the subject data in the latest certificate file based on the key to obtain the certificate issuer and upgrade file; Determine whether the certificate issuer obtained by decryption is correct. If correct, upgrade the off-board cleaning device application according to the upgrade file obtained by decryption.
2. The method for upgrading the off-counter cleaning equipment according to claim 1, characterized in that: Before the off-counter clearing device monitors whether the certificate file is updated, the method further includes: The equipment manufacturer randomly generates a preset number of keys, and imports the preset number of keys and their corresponding encryption algorithm types and key index numbers as key data into the encryption chip of the off-counter cleaning equipment when the off-counter cleaning equipment leaves the factory.
3. The method for upgrading the off-counter cleaning equipment according to claim 2, characterized in that: Before the off-counter clearing device monitors whether the certificate file is updated, the method further includes: The device manufacturer randomly selects a key from the preset number of keys, and generates a certificate file according to the upgrade file and the key; Deploy the certificate file to the bank's backend server; The bank terminal obtains the certificate file from the bank backend server; The bank terminal determines whether the certificate file in the off-counter clearing device is consistent with the certificate file stored in itself; If they are inconsistent, the certificate file stored in itself will be pushed to the off-cabinet clearing device.
4. The method for upgrading the off-counter cleaning equipment according to claim 3, characterized in that: The step of generating a certificate file according to the upgrade file and the key includes: Generate basic data according to the encryption algorithm type and key index number corresponding to the key; The certificate issuer and the upgrade file are encrypted by the key to obtain the subject data; Generate a certificate file based on the basic data and the subject data.
5. The method for upgrading the off-counter cleaning equipment according to claim 3, characterized in that: The bank terminal determines whether the certificate file in the off-counter clearing device is consistent with the certificate file stored in the bank terminal, including: The bank terminal determines whether the hash value of the certificate file in the off-counter clearing device is consistent with the hash value of the certificate file stored in the bank terminal.
6. The method for upgrading the external cleaning equipment according to claim 2, characterized in that: The off-counter clearing device determines the key according to the basic data in the latest certificate file and the key data stored in itself, and decrypts the subject data in the latest certificate file according to the key to obtain the certificate issuer and the upgrade file, including: The off-counter clearing device reads the basic data in the latest certificate file and transmits it to the encryption chip; The encryption chip obtains the corresponding key from the key data stored in the encryption chip according to the encryption algorithm type and the key index number in the basic data; The subject data in the latest certificate file is decrypted by using the corresponding key to obtain the certificate issuer and the upgrade file.
7. The method for upgrading the off-counter cleaning equipment according to claim 1, characterized in that: The upgrade file includes an interface file; The step of upgrading the off-board cleaning device application according to the upgrade file obtained by decryption includes: According to the decrypted interface file, update the application page of the off-cabinet cleaning device.
8. The method for upgrading the external cleaning equipment according to claim 7, characterized in that: The updating of the application page of the off-counter cleaning device according to the interface file obtained by decryption includes: The decrypted interface file is saved to the file system of the off-cabinet clearing device, and the interface file in the file system is loaded through the Webview control.
9. The method for upgrading the external cleaning equipment according to claim 7 or 8, characterized in that: The interface file is a Web template page file.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.