Terminal control system supporting GMS and PCI PTS dual authentication and transaction method
By adopting the system architecture of Android-Linux+Protected VM (AVF)+Trust Zone+SE on smart POS terminals, the problem of difficulty in passing GMS and PCI PTS authentication in the existing technology is solved, and a terminal control system with high security and flexibility is realized.
Patent Information
- Application Number
- CN202510336858.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-05-30
AI Technical Summary
Existing smart POS terminals are difficult to pass GMS and PCI PTS authentication at the same time, resulting in limited security and flexibility.
The system architecture of Android-Linux+Protected VM (AVF)+Trust Zone+SE is adopted to separate secure and non-secure business logic through the Protected VM module, TEE module and SE module to ensure that sensitive operations are performed in a protected environment.
It realizes supporting GMS and PCI PTS authentication at the same time, improves the security and flexibility of the terminal control system, and avoids the transformation of Android native systems.
Smart Images

Figure CN120071522A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent payment terminals, and in particular, to a terminal control system and a transaction method that support dual authentication of GMS and PCI PTS. Background Art
[0002] With the rapid development of mobile payment and intelligent devices, the intelligent POS terminal system is increasingly widely used in fields such as retail, catering, and finance. The intelligent POS terminal system not only needs to support multiple payment methods (such as bank cards, QR code payment, etc.), but also needs to meet the high requirements of the payment industry for security. Currently, the intelligent POS terminal system is usually built based on the Android-Linux operating system, and with its rich application ecosystem and mature development framework, it can quickly implement diverse payment functions.
[0003] Researchers have found that most of the intelligent POS terminals on the market currently pass the PCI PTS certification. However, the PCI PTS certification has relatively high security requirements for POS terminals. In order to meet the security requirements, many device manufacturers will modify the intelligent POS terminals, such as trimming unnecessary system components, modifying the permission authorization mechanism, and adding a custom application signature verification mechanism. However, these practices conflict with the requirements of GMS certification, resulting in the abnormal operation of GMS components. Therefore, it is usually very difficult for intelligent POS terminals to pass both GMS and PCI PTS certifications simultaneously. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: to provide a terminal control system and a transaction method that support dual authentication of GMS and PCI PTS, so as to solve the problem that it is very difficult for existing intelligent POS terminals to pass both GMS and PCI PTS certifications simultaneously.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is: a terminal control system that supports dual authentication of GMS and PCI PTS, which includes a secure world module and a non-secure world module. The non-secure world module includes a REE module, and the REE module is used to execute non-confidential business logic and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering; the secure world module includes a Protected VM module, an SE module, and a TEE module. The Protected VM module is used to execute the first secure service that does not involve interface rendering. The SE module is used to execute the second secure service. The TEE module is used to store non-financial related secure credential data; wherein, the REE module is respectively communicatively connected to the Protected VM module and the TEE module, and the Protected VM module is communicatively connected to the SE module.
[0006] Further, in the terminal control system of the present invention, the REE module includes a first application module and an application program module, and the first application module is communicatively connected to the application program module and the Protected VM module respectively.
[0007] Further, in the terminal control system of the present invention, the first application module includes a system service module, an AIDL service module, and a client application module. The system service module is communicatively connected to the AIDL service module and the Protected VM module respectively, and the AIDL service module is communicatively connected to the client application module.
[0008] Further, in the terminal control system of the present invention, the Protected VM module includes a Microdroid module, and the Microdroid module includes a second application module. The second application module is communicatively connected to the system service module and the SE module respectively, and the second application module is used to execute the first security service that does not involve interface rendering.
[0009] Further, in the terminal control system of the present invention, the TEE module includes a Trusty OS module and a trusted application program module, and the trusted application program module is communicatively connected to the client application module.
[0010] Further, in the terminal control system of the present invention, the security credential data includes a certificate and a key.
[0011] Further, in the terminal control system of the present invention, it further includes a security monitor module, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
[0012] Correspondingly, the present invention further provides a transaction method, which is applied to the terminal control system as described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the REE module renders and displays a PIN code input interface; S2: When the user operates the PIN code input interface, the REE module transfers the control right of the touch screen to the Microdroid module through a secure communication mechanism; S3: After the Microdroid module takes over the control right of the touch screen, it receives and parses the input data of the user to obtain the PIN code input by the user; S4: The Microdroid module sends the PIN code to the SE module. The SE module encrypts the PIN code and passes the encrypted PIN code to the bank card. S5: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program. S6: The payment program determines whether to complete the payment transaction according to the authorization result.
[0013] Further, in the transaction method of the present invention, in step S5, decrypting and verifying the encrypted PIN code to obtain an authorization result includes: Performing a verification operation on the decrypted PIN code to obtain a verification result; if the verification result is verification passed, it is determined that the authorization result is authorized payment; if the verification result is not passed, it is determined that the authorization result is unauthorized payment.
[0014] Further, in the transaction method of the present invention, the method further includes: automatically locking the bank card when the authorization results of the PIN code continuously exceed the preset number of times and are all unauthorized payments.
[0015] The beneficial effects of the present invention are as follows: The present invention provides a terminal control system that simultaneously supports GMS+PCI PTS authentication. Through the comprehensive mechanism of Android-Linux+Protected VM (AVF)+Trust Zone+SE, on the basis of ensuring the security and flexibility of the terminal control system, it effectively supports GMS+PCI PTS authentication: (1) For the services related to security, the present invention is implemented through a secure environment (i.e., the Protected VM module+TEE module+SE module). Specifically: the first secure service that does not involve rendering the interface (such as interface call authentication, signature verification for application installation) is executed through the Protected VM module; the second secure service (such as key management, input / encryption of PIN code, security algorithm) is executed through the SE module; the TEE module stores the security credential data that is not related to finance. In addition, for the secure interface, the present invention separates the interface rendering (non-sensitive operations) from the processing logic of sensitive data input after rendering (such as the business logic of PIN code input), that is, the interface rendering is completed by the REE module, and the operations after rendering are taken over by the Protected VM module, so as to ensure that the sensitive operations in the services related to the secure interface can be in a protected environment throughout the process, thereby greatly improving security.
[0016] That is to say, the present invention implements the services related to security through a secure environment (i.e., Protected VM module + TEE module + SE module), so as to ensure the security requirements of the terminal control system and successfully pass the PCI PTS certification without modifying some native Android functions.
[0017] (2) For the non-security-related part, in the present invention, the non-secure world module (i.e., the REE module) mainly refers to the native Android-Linux system of Google, which can be used to execute non-confidential business logics and perform interface rendering. As described above, the architecture of the above Protected VM module + TEE module + SE module can effectively ensure the security requirements of the terminal control system. Therefore, the present invention can achieve minimal modification to the native Android system. For example, it maintains the native Android application authorization mechanism, the signature verification mechanism of native Android applications, and the system components related to GMS, so that the terminal control system of the present invention can pass the GMS certification.
[0018] In summary, based on the system architecture of Android-Linux + Protected VM (AVF) + Trust Zone + SE, the present invention can effectively support GMS + PCI PTS certification. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a system architecture diagram of the terminal control system supporting dual certifications of GMS and PCI PTS according to an embodiment of the present invention.
[0020] Figure 2 It is another system architecture diagram of the terminal control system supporting dual certifications of GMS and PCI PTS according to an embodiment of the present invention.
[0021] Figure 3 It is a step flowchart of the transaction method of the terminal control system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] To describe in detail the technical content, achieved objectives and effects of the present invention, the following is described in conjunction with embodiments and with reference to the accompanying drawings.
[0023] Researchers found that the system architecture of intelligent POS (Point of Sale) terminals can adopt the Android-Linux + Trust Zone + SE architecture. In this architecture: The intelligent POS terminal uses the Android-Linux operating system, which divides the system into two parts: the Secure World module and the Non Secure World module. Among them, the Non Secure World module mainly refers to the native Android-Linux system of Google; the Secure World module includes Trust Zone technology. However, in actual use, there are many defects in the above system architecture, such as: (1) Due to the security requirements of PCI PTS certification, in order to prevent malicious attacks, intelligent POS terminals usually trim unnecessary system components, modify the permission authorization mechanism, and add a custom application signature verification mechanism. However, these practices conflict with the requirements of GMS certification, resulting in the inability of GMS components to run properly. Therefore, it is usually very difficult for intelligent POS terminals to pass both GMS and PCI PTS certifications (unless a dual-CPU architecture is adopted, which will come at the cost of increased costs).
[0024] (2) Functions related to security such as intelligent POS terminal certificates and keys, terminal status, and lifecycle are implemented through Trust Zone technology. And Trust Zone technology has certain disadvantages: ① Poor flexibility: Trust Zone can only support the same version of the Android system and applications on the same platform; ② Low development efficiency: Trust Zone requires hardware configuration on the host system, resulting in low development efficiency. These disadvantages will bring certain difficulties to developers and increase the development and maintenance costs.
[0025] For this reason, please refer to Figure 1 and Figure 2 , the present invention provides a terminal control system that supports dual certifications of GMS and PCI PTS, which includes a Secure World module and a Non Secure World module. The Non Secure World module includes a REE module, and the REE module is used to execute non-confidential business logic and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering; the Secure World module includes a Protected VM module, an SE module, and a TEE module. The Protected VM module is used to execute the first security service that does not involve interface rendering, the SE module is used to execute the second security service, and the TEE module is used to store non-financial related security credential data; among them, the REE module is respectively communicatively connected to the Protected VM module and the TEE module, and the Protected VM module is communicatively connected to the SE module.
[0026] As can be seen from the above description, the beneficial effects of the present invention are as follows: The present invention provides a terminal control system that simultaneously supports GMS + PCI PTS authentication. Through the comprehensive mechanism of Android - Linux + Protected VM (AVF) + Trust Zone + SE, on the basis of ensuring the security and flexibility of the terminal control system, it effectively supports GMS + PCI PTS authentication, where: (1) For the services related to security, the present invention is implemented through a secure environment (i.e., the Protected VM module + TEE module + SE module). Specifically: The first security service that does not involve rendering the interface (such as interface call authentication, signature verification for application installation) is executed through the Protected VM module, and the second security service (such as key management, input / encryption of PIN codes, security algorithms) is executed through the SE module. The TEE module stores security credential data not related to finance (such as certificates and keys). In addition, for the secure interface, the present invention separates the interface rendering (non - sensitive operations) from the processing logic of sensitive data input after rendering (such as the business logic of PIN code input), that is, the interface rendering is completed by the REE module, and the operations after rendering are taken over by the Protected VM module, so as to ensure that the sensitive operations in the services related to the secure interface can be in a protected environment throughout the process, thus greatly improving security.
[0027] That is to say, the present invention implements the services related to security through a secure environment (i.e., the Protected VM module + TEE module + SE module), so as to ensure the security requirements of the terminal control system and successfully pass the PCI PTS authentication without modifying some native Android functions.
[0028] (2) For the non - security - related part, in the present invention, the non - secure world module (i.e., the REE module) mainly refers to the native Google Android - Linux system, which can be used to execute non - confidential business logic and perform interface rendering. As mentioned above, the architecture of the above - mentioned Protected VM module + TEE module + SE module can effectively ensure the security requirements of the terminal control system. Therefore, the present invention can achieve minimal modification to the native Android system. For example, maintaining the native Android application authorization mechanism, maintaining the signature verification mechanism of native Android applications, and maintaining the system components related to GMS, so that the terminal control system of the present invention can pass the GMS authentication.
[0029] In summary, based on the system architecture of Android-Linux + Protected VM (AVF) + Trust Zone + SE, the present invention can effectively support GMS + PCI PTS certification.
[0030] It should be noted that the terminal of the present invention can be a payment device such as an intelligent POS terminal. The GMS (Google Mobile Services Test Certification) is a certification system established by Google. This system aims to ensure that intelligent devices based on the Android system produced by global hardware manufacturers meet Google's standards in terms of compatibility, stability, and performance. Products that pass the GMS certification will obtain authorization to use Google services and related trademarks and can be displayed on Google's official website. The PCI PTS (Payment Card Industry PIN Transaction Security) certification is formulated by the PCI (Payment Card Industry PIN) Security Standards Committee and aims to ensure the confidentiality and integrity of PIN data in payment card transactions. It is a security requirement for payment devices. Therefore, a typical payment device such as a POS terminal needs to take a series of security measures, such as encrypting the transmission and storage of sensitive data, regularly updating and patching system vulnerabilities, restricting access permissions, etc., to ensure that payment data is not leaked or misused.
[0031] The terminal control system described in the present invention uses the Android-Linux operating system, which divides the system into two parts: the Secure World module and the Non Secure World module. Among them, the Non Secure World module mainly refers to the native Android-Linux operating system of Google; the Secure World module mainly refers to the Protected VM (AVF) module, the TEE (Trusted Execution Environment) module, and the external SE (Secure Element) module. The following will elaborate on the above terminal control system in combination with Figure 2 , and elaborate on the above terminal control system in detail.
[0032] In the present invention, the non - secure world module is the REE (Rich Execution Environment) module. The REE module is a non - trusted rich execution environment, which is an open environment vulnerable to attacks. For example, events such as theft of sensitive data and embezzlement of mobile payments often occur. Therefore, in the present invention, security - related services are mainly executed by the Protected VM module and the SE module in the secure world module. In the present invention, the REE module is built based on the Android - Linux system. Compared with the existing terminal control system architecture, the present invention tries not to modify the Android native system as much as possible, so as to maintain the Android native application authorization mechanism, maintain the signature verification mechanism of native Android applications, and maintain system components related to GMS, so as to ensure that the intelligent POS terminal can pass the GMS certification, so that the intelligent POS terminal can obtain authorization to use Google services (such as Google Play, Gmail, Google Maps, etc.).
[0033] In practical applications, the REE module may include an application program module running on Android (i.e., the Applications module in Figure 1 / 2), a first application module (i.e., the services module in Figure 1 ), a framework framework, and components of device manufacturers (such as financial - related modules), etc. Among them, the first application module includes a system service module (i.e., the System service module in Figure 2 ), an AIDL (Android Interface Definition Language) service module, and a CA (Client Application) module. Among them, the system service module is communicatively connected to the application program module, the AIDL service module, and the Secure Modules module respectively, and the CA module is communicatively connected to the AIDL service module. In practical applications, the system service module can interact with the AIDL service module and the Secure Modules module through Binder respectively.
[0034] It should be noted that the above application program module can be an upper-layer APP application program, which can call relevant interfaces of the system service module through binder or JNI. The Android native treble mechanism involves the system domain and the vendor domain. Among them, the system service module refers to the system services in the system domain, and the AIDL service module refers to the system services in the vendor domain (generally referring to hardware-related implementation services). The system service module calls relevant interfaces of the AIDL service module through binder. In addition, in the present invention, the system service module is the system service in the non-secure world, and the Secure Modules module is the system service in the secure world. The system service module can call the interfaces of the Secure Modules module through binder.
[0035] In practical applications, the first application module (i.e., the application running on Android) is used to execute non-confidential business logic and interface rendering. Among them, the interface includes security-related interfaces and non-security-related interfaces. For security-related interfaces, the present invention separates interface rendering from the processing logic of sensitive data input after rendering (such as the business logic of PIN code input), that is, the first application module only performs interface rendering operations, and the operations after interface rendering are taken over by the Protected VM module, so as to complete the business after interface rendering through the Protected VM module and the SE module. For non-security-related interfaces, both interface rendering and the operations after rendering (such as the processing logic of corresponding data input) are completed by the first application module. Among them, for non-security-related interfaces, the operations after interface rendering belong to non-confidential business logic, and for security-related interfaces, the operations after interface rendering belong to the business of the security-related part. It should be noted that the above processing logic of sensitive data input after rendering refers to the full-process control strategy in the intelligent POS terminal to ensure the confidentiality, integrity, and availability of data during input, transmission, processing, and storage for the sensitive data input by the user (such as PIN codes, keys, etc.) through specific system architecture design and security mechanisms.
[0036] As described above, interface rendering includes secure interface rendering and non-secure interface rendering. The secure interface rendering refers to the rendering of security-related interfaces, and the non-secure interface rendering refers to the rendering of non-security-related interfaces. In practical applications, the non-security-related interfaces refer to the interfaces in the intelligent POS terminal for interacting with users, which do not involve the processing of sensitive data, that is, the non-security-related interfaces refer to non-security-related ordinary user interaction interfaces, such as: (1) System upgrade interface: used to prompt the user whether the device needs to be upgraded and display the upgrade progress, which does not involve the processing of sensitive data (such as PIN codes, keys, etc.). (2) Sign-in interface of the POS machine: used for merchants to sign in the device at the POS terminal, which does not involve the processing of highly sensitive data (such as PIN codes, payment card information, etc.). (3) Status display interface: used for users to select transaction types (such as consumption, refund, query, etc.), only involving the selection of transaction types and not involving the processing of sensitive data. The non-confidential business logic refers to the business logic in the system that does not involve the processing of sensitive data, that is, non-security-related services, such as controlling the on and off of the LED light, controlling the buzzer, managing the power state of the device (such as sleep, wake-up, etc.). The security-related interfaces refer to user interfaces related to security such as processing or displaying sensitive data, such as PIN (Personal Identification Number) input interfaces, biometric (such as fingerprint, face recognition) identification interfaces, payment card information display interfaces.
[0037] The non-security world module in the present invention is introduced above. The security world module in the present invention is specifically introduced below. The security world module includes a Protected VM (AVF) module, a TEE module, and an external SE (Secure Element) module, where: (1) The Protected VM module is a protected virtual machine. The main use case of the Protected VM module is not to run an independent operating system, but to provide an isolated execution environment. The Protected VM module includes a Microdroid module, and the Microdroid module is a mini version of the Android OS running in the Protected VM (Virtual Machine). In the Microdroid module, there is a second application module (i.e., the Secure Modules module), and the second application module is communicatively connected to the above system service module through Binder. The Microdroid module (such as the second application module) is used to execute the first security service that does not involve interface rendering. The first security service refers to some security-related business logics, such as interface call authentication, signature verification for application installation, etc.
[0038] (2) The TEE module refers to the Trusted Execution Environment, which refers to Figure 1 the Trust Zone part in []. It should be noted that Trust Zone is a technology that implements the TEE module. In the present invention, the TEE module is mainly used to store non-financial related security credential data, and the non-financial related security credential data includes non-financial related certificates and non-financial related keys. As Figure 2 shown, the TEE module includes a Trusty OS module and a TA (Trusted Application) module, etc. Among them, the Trusty OS module is an operating system running in the Trust Zone secure environment, and the TA module is communicatively connected to the CA module.
[0039] It should be noted that although both Protected VM and Trust Zone are security technologies of the Android system, their purposes and implementation methods are different. Trust Zone is a hardware-level security technology that provides a secure execution environment for running secure code. Protected VM is a resource management technology that provides a secure and private execution environment for executing code, which is very suitable for security-oriented use cases that require a higher security factor than that provided by the Android application sandbox, and even formally verified isolation guarantees. Moreover, in actual applications, although the TEE module has high security, its flexibility is poor and the development efficiency is low. Therefore, to improve the development efficiency and flexibility, the present invention mainly executes the security-related business logic (i.e., the first security service) through the Microdroid module in the Protected VM module.
[0040] In summary, the present invention avoids executing the first security service through the TEE module, but executes the first security service through the Microdroid module (such as the second application module) of the Protected VM module, which can effectively improve the development efficiency and make the terminal control system of the present invention more flexible. Specifically, compared with the TEE module, the main advantages of the Protected VM module are: (1) stronger flexibility: The Protected VM module can run different versions of the Android system and application programs on different platforms. This enables the Protected VM module to meet a wider range of application requirements. (2) higher development efficiency: The Protected VM module can create an independent development environment, which is convenient for developers to develop and test application programs, and this can effectively improve the development efficiency.
[0041] It should be further noted that since the Microdroid module does not support interfaces, the present invention divides the services of security-related interfaces (such as PIN input interfaces, etc.) into two parts. The service of interface rendering is handed over to the REE module for processing, that is, rendering is performed through the REE module, and the service after rendering is handed over to Microdroid for takeover to ensure security.
[0042] (3) The SE (Secure Element) module is an external security component, which is mainly responsible for payment industry-related peripherals and security-related functions, that is, for performing the second security service. For example, functions such as IC card readers, magnetic stripe card readers, financial security-related key management, financial security-related certificate management, PIN input and encryption, and security algorithms. It should be noted that the SE module has extremely high security. By using the above SE module to perform the second security service with high security requirements, such as key management and PIN input, it can significantly improve payment security. That is, the high security and high performance of the SE module enable the intelligent POS terminal to meet the high security requirements of the payment industry, improving the user experience and market competitiveness. In actual application, the SE module and the Microdroid module can interact through serial communication protocols such as SPI / I2C / UART.
[0043] In summary, in the present invention, applications (such as modules related to finance such as printing, EMV, magnetic cards, IC cards, contactless cards, pinpads, etc.) are developed and packaged in the form of APK (Android Application Package Androi, application package) or APEX format (AVF application) and stored in the terminal, thereby respectively forming applications running on Android (i.e., the first application module) and applications running on the Microdroid module in the Protected VM module (i.e., the second application module), and the first application module and the second application module can interact through binder. Among them, the application running on Android is mainly responsible for interface display (i.e., rendering) and executing non-confidential business logic; the application running on the Microdroid module in the Protected VM module is responsible for executing the first security service that does not involve interface rendering. In addition, the application running on Android can also be used to create and manage the life cycle of the Protected VM module.
[0044] It should be specifically noted that the first security services executed by the above Microdroid module are mainly security services independently designed by some POS manufacturers. For example, the life cycle management service of the POS (managing the status of the POS, such as the manufacturing state, repair state, usage state, development mode, etc.), data collection service, unified response service (functions such as setting configuration items), authentication service (interface call authentication), etc. The second security services executed by the above SE module are mainly security services related to PIN codes, financial security-related keys, etc. For example, security services related to functions such as reading bank card information, PIN code input and encryption, and financial security-related key management. The financial security-related key management includes operations such as generating keys, storing keys, distributing keys, and destroying keys.
[0045] In the present invention, security credential data (i.e., certificates and keys) can be divided into two types, namely, finance-related and non-finance-related. The non-finance-related security credential data includes non-finance-related certificates and non-finance-related keys, which are stored in the above TEE module. The finance-related security credential data includes finance-related keys and finance-related certificates, which are stored in the SE module. That is, the keys and certificates stored in the TEE module mainly participate in the non-finance security-related services of the terminal, and the keys and certificates stored in the SE module mainly participate in the finance security-related services of the terminal. In practical applications, the TA module in the TEE module can be responsible for managing non-finance-related certificates and verifying non-finance-related certificate chains, etc. It should be noted that finance-related keys and finance-related certificates refer to keys and certificates directly used in security mechanisms involving fund flow or sensitive financial data protection such as financial transactions and payment verification. For example, finance-related keys can include the master key of the payment card, the transaction session key, and finance-related certificates can include the mobile payment root certificate, the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) certificate of the payment gateway, etc. The non-finance-related keys and non-finance-related certificates refer to encryption keys and certificates used in non-fund transaction or non-sensitive financial data scenarios, and their core goal is to ensure security requirements such as device authentication, data integrity, and access control. For example, non-finance-related keys can include device unlocking keys, application data encryption keys, and non-finance-related certificates can include enterprise VPN certificates, device identity certificates.
[0046] In addition, as Figure 1 shown, the terminal control system further includes a security monitor module, and the security monitor module is used to be responsible for managing the switching between the secure world module and the non-secure world module.
[0047] In practical applications, the security monitor module (i.e., Figure 1The Secure Monitor module in it can switch the trigger response. Specifically, when the system needs to enter the secure world from the non-secure world to execute security-sensitive tasks, the Secure Monitor will respond to this request. For example, when a payment application needs to perform security operations such as PIN code verification, the payment application will send a switching request to the Secure Monitor, asking to switch to the secure world for processing. At this time, the Secure Monitor will start the switching process.
[0048] The above content specifically introduces the main modules of the terminal control system that supports dual authentication of GMS and PCI PTS in the present invention. Based on this, the following combines Figure 1 to comprehensively elaborate on the system architecture of the terminal control system.
[0049] As Figure 1 shown, in the Non Secure World module, it will include Android (Android operating system), Linux Kernel (i.e., Linux kernel), and hypervisor (i.e., virtual machine monitor). The Android is the basic system for the intelligent POS terminal to run, providing the running environment and basic services for the entire device. The Linux kernel is the core of the Android system, responsible for managing hardware resources, providing system services, implementing process scheduling, and memory management and other basic functions. The hypervisor is responsible for creating, managing, and monitoring virtual machines. In this Android, it also includes: (1) Applications, that is, the application program module. (2) services module, that is, the first application module. (3) Java API (Java application programming interface): provides an interface for calling system functions and implementing application program functions. (4) binder: an inter-process communication mechanism. (5) VirtualizationService: virtualization service, providing virtualization support for the operation of the Protected VM module, managing virtual resources, and implementing resource isolation and allocation. (6) crosvm: a virtual machine monitor written in Rust, used to allocate virtual machine memory, create virtual CPU threads, and implement the backend of virtual devices.
[0050] As Figure 1As shown in the figure, in the Secure World module, it includes the Protected VM (Protected Virtual Machine) module, the TEE module (i.e., Trust Zone), and the SE module. Among them, the Protected VM module includes the Microdroid module and the Linux Kernel (i.e., the Linux kernel). The Microdroid module includes: (1) apexed, zipfuse, authfs: apexed is a component related to the APEX container format, responsible for the management and operation of APEX files; zipfuse is used to mount compressed files in the form of a file system for convenient access; authfs is a unified file system for securely sharing multiple files between Android and the Protected VM (host and guest). (2) NativeAPI, binder: Native API is a native application programming interface; binder is an inter-process communication mechanism, which is used in this system for the interaction between applications running on Android and applications running on Microdroid. (3) Secure Modules, that is, the above-mentioned second application module, which can also be called the security module. (4) microdroid_manager (i.e., the Microdroid manager): responsible for managing the life cycle of the Microdroid module in the Protected VM module, as well as the instance disk. The Linux Kernel includes pvmfw, and pvmfw is the firmware of the protected virtual machine. The TEE module includes the Trusty OS module and the TA module.
[0051] Correspondingly, as Figure 3 shown, the present invention also provides a transaction method, which is applied to the terminal control system described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the REE module renders and displays a PIN code input interface; S2: When the user operates the PIN code input interface, the REE module transfers the control right of the TP (Touch Panel) to the Microdroid module through a secure communication mechanism; S3: The Microdroid module takes over the control right of the touch screen, receives and parses the user's input data to obtain the PIN code input by the user; S4: The Microdroid module sends the PIN code to the SE module, and the SE module encrypts the PIN code and transmits the encrypted PIN code to the bank card; S5: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program; S6: The payment program determines whether to complete the payment transaction according to the authorization result.
[0052] In practical applications, when making a card payment based on the above terminal control system, the specific process can be as follows: (1) After the user inserts the bank card into the intelligent POS terminal, the SE chip module of the intelligent POS terminal reads the bank card information. The SE module can read the bank card information (such as card number, expiration date, etc.) through an IC card reader or a magnetic stripe card reader to obtain the basic information of the bank card, which is convenient for subsequent legal verification of the bank card, ensuring that the transaction can proceed correctly and improving data security.
[0053] (2) After the user enters the transaction amount in the payment program in the REE module, the REE module renders and displays the PIN code input interface (i.e., the bank card password input interface). After the PIN code input interface is rendered, when detecting operations such as the user's touch screen, the REE module transfers the control right of the touch screen to the Microdroid module through a secure communication mechanism. At this time, the Microdroid module takes over the control right of the touch screen.
[0054] (3) Based on the Microdroid module taking over the control right of the touch screen, the user can enter the corresponding PIN code based on the PIN code input interface. The Microdroid module receives and parses the user's input data through the PIN code input interface to parse out the PIN code entered by the user. It should be noted that in the transaction method of the present invention, the PIN code usually refers to the bank card password.
[0055] (4) Then, the Microdroid module sends the PIN code to the SE module, and the SE module encrypts the PIN code to obtain the encrypted PIN code. On this basis, the SE module passes the encrypted PIN code to the bank card.
[0056] (5) The bank card itself contains a processor that can verify the PIN code transmitted by the SE module. After receiving the encrypted PIN code, the bank card decrypts and verifies the encrypted PIN code to obtain a verification result. If the verification result is passed, it is determined that the authorization result is authorized payment; if the verification result fails, it is determined that the authorization result is unauthorized payment. After obtaining the authorization result, the bank card sends the authorization result to the payment program. The payment program determines whether to complete the payment transaction according to the authorization result. If the authorization result is authorized payment, the transaction is allowed; if the authorization result is unauthorized payment, the transaction is rejected.
[0057] As can be seen from the above description, after the PIN code input interface is rendered, the control right of the touch screen is transferred to the Microdroid module through the secure communication mechanism, and the Microdroid module takes over the control right of the touch screen. Compared with the REE module, the Microdroid module and the SE module have higher security, which can greatly improve the payment security.
[0058] In addition, in actual applications, to prevent payment fraud, the bank card can also be locked when the PIN code is verified multiple times and fails. Specifically, when the authorization results of the PIN code continuously exceed the preset number of times and are all unauthorized payments, that is, when the authorization results of multiple PIN codes continuously input by the user are all unauthorized payments, an automatic locking operation is performed on the bank card, thereby temporarily prohibiting the use of the bank card for transactions to prevent the bank card from being used by others and ensuring the security of transactions.
[0059] In summary, the terminal control system and transaction method provided by the present invention are as follows: (1) The first application module running on Android is mainly responsible for interface rendering and non-confidential business logic; the Microdroid module (such as the second application module) running in the Protected VM is mainly responsible for executing security-related logic (does not support interfaces); since interfaces are not supported in Microdroid, security-related interfaces such as the PIN input interface need to be rendered in the REE module, and then the control right of the TP is handed over to the Microdroid module for takeover; the SE module has extremely high security and supports functions such as key management, PIN input and encryption, and security algorithms. Generally speaking, through the comprehensive mechanism of the Protected VM module + TEE module + SE module, the security of certificates, keys, and sensitive information is ensured, and the flexibility and development efficiency are also improved. (2) For the security-related parts: Some security-related services are executed in the Microdroid module within the Protected VM module; the PIN input interface is rendered on the REE side, and after the rendering is completed, the TP will be immediately taken over by Microdroid; some certificates and keys are stored in the TEE module; key management, PIN input and encryption, security algorithms, etc. are implemented in the SE chip module. That is, the security-related parts are implemented through ProtectedVM + TEE + SE, etc. For the non-security-related parts, the Android native system is not modified as much as possible. For example, the Android native application authorization mechanism is maintained, the signature verification mechanism of the native Android application is maintained, and the system components related to GMS are maintained. Generally speaking, the present invention tries not to modify the Android native system to pass the GMS certification, and the security-related parts are all implemented through a secure environment (Protected VM module + TEE module + SE module) to pass the PCI PTS certification. Therefore, the Android-Linux + Protected VM (AVF) + Trust Zone + SE system architecture of the present invention supports GMS + PCI PTS certifications. (3) The present invention provides a terminal control system that simultaneously supports GMS + PCI PTS certifications and is applicable to Android intelligent POS terminals. The security-related parts are executed in a secure environment (Protected VM (AVF) + Trust Zone + SE), and the interface is displayed and implemented in the REE module. Among them, the core financial business logic is implemented in the Protected VM (AVF) module without an interface to improve flexibility and development efficiency.
[0060] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in the related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A terminal control system supporting GMS and PCI PTS dual authentication, characterized in that: It includes a secure world module and a non-secure world module, the non-secure world module includes a REE module, the REE module is used to execute non-confidential business logic and interface rendering, the interface rendering includes secure interface rendering and non-secure interface rendering; the secure world module includes a Protected VM module, a SE module and a TEE module, the Protected VM module is used to execute a first security business that does not involve interface rendering, the SE module is used to execute a second security business, and the TEE module is used to store non-financial related security credential data; wherein the REE module is communicated with the Protected VM module and the TEE module respectively, and the Protected VM module is communicated with the SE module.
2. The terminal control system according to claim 1, characterized in that: The REE module includes a first application module and an application program module, and the first application module is communicatively connected with the application program module and the Protected VM module respectively.
3. The terminal control system according to claim 2, characterized in that: The first application module includes a system service module, an AIDL service module and a client application module. The system service module is communicatively connected with the AIDL service module and the Protected VM module respectively, and the AIDL service module is communicatively connected with the client application module.
4. The terminal control system according to claim 3, characterized in that: The Protected VM module includes a Microdroid module, the Microdroid module includes a second application module, the second application module is communicated with the system service module and the SE module respectively, and the second application module is used to execute a first security business that does not involve interface rendering.
5. The terminal control system according to claim 3, characterized in that: The TEE module includes a Trusty OS module and a trusted application module, and the trusted application module is communicatively connected with the client application module.
6. The terminal control system according to claim 1, characterized in that: The non-finance-related security credential data includes a non-finance-related key and a non-finance-related certificate.
7. The terminal control system according to claim 3, characterized in that: A security monitor module is also included, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
8. A transaction method, applied to the terminal control system according to any one of claims 1 to 7, characterized in that: The following steps are involved: S1: After the user inputs the transaction amount into the payment program in the REE module, the REE module renders and displays a PIN code input interface; S2: When the user operates the PIN code input interface, the REE module transfers the control of the touch screen to the Microdroid module through a secure communication mechanism; S3: After the Microdroid module takes over the control of the touch screen, it receives and parses the user's input data to obtain the PIN code entered by the user; S4: the Microdroid module sends the PIN code to the SE module, the SE module encrypts the PIN code and transmits the encrypted PIN code to the bank card; S5: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program; S6: The payment program determines whether to complete the payment transaction based on the authorization result.
9. The transaction method according to claim 8, characterized in that: In step S5, the encrypted PIN code is decrypted and verified to obtain an authorization result, including: The decrypted PIN code is verified to obtain a verification result; if the verification result is passed, the authorization result is determined to be authorized payment; if the verification result is failed, the authorization result is determined to be unauthorized payment.
10. The transaction method according to claim 9, characterized in that: The method further comprises: If the authorization results of the PIN code are all unauthorized payments for more than a preset number of consecutive times, the bank card will be automatically locked.