Intelligent money box encryption method and system based on digital certificate, and storage medium
Through digital certificate-based encryption methods, including digital certificate verification, zero-knowledge authentication and session key encryption, the problem of insufficient security of smart boxes is solved, and efficient data security and attack resistance are achieved.
Patent Information
- Application Number
- CN202510443468.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The existing smart boxes are inadequate in security, easy to be cracked, and the certificate management is complex, which makes it impossible to meet the security needs of actual use scenarios.
Using a digital certificate-based encryption method, digital certificate verification, zero-knowledge authentication and session key encryption ensures secure communication between the smart box and the server, and improves data security through data splitting and integrity verification.
Effectively prevent access to forged equipment, ensure the security of data transmission, reduce the risk of data leakage, and improve the security and attack resistance of smart boxes.
Smart Images

Figure CN120151083A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of intelligent cash boxes, and particularly to an intelligent cash box encryption method, system, and storage medium based on digital certificates. Background Art
[0002] As a device for storing valuables such as cash and bills, intelligent cash boxes are widely used in places such as banks and supermarkets, and their security is directly related to asset protection and business compliance. Traditional technologies mostly use symmetric encryption (such as AES), asymmetric encryption (such as RSA), or digital certificate authentication based on PKI, combined with username and password for identity verification.
[0003] In the prior art, as an embedded device, due to limited device resources, the symmetric encryption key of the intelligent cash box is prone to leakage, the asymmetric encryption has a large computational overhead, and the traditional authentication method based on the intelligent cash box is easily cracked, making it difficult to ensure that the data has not been tampered with. At the same time, there are certificate management defects, that is, under a large number of devices, the management of certificate issuance, update, and revocation is complex, and relying on a single CA institution is prone to single-point risks, resulting in the security of the intelligent cash box not meeting the security requirements of its actual use scenario. Summary of the Invention
[0004] To solve the above technical problems, this application provides an intelligent cash box encryption method, system, and storage medium based on digital certificates to improve the security of intelligent cash boxes.
[0005] The technical solutions provided in this application are described below: The first aspect of this application provides an intelligent cash box encryption method based on digital certificates, including: Start the intelligent cash box and verify the legitimacy of the digital certificate of the intelligent cash box device; When the digital certificate is verified, establish a communication link between the intelligent cash box and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link; Authenticate the intelligent cash box and the server bidirectionally through a zero-knowledge authentication method; When the authentication is passed, control the intelligent cash box to encrypt its own stored data through the session key to obtain private data; Generate verification data for the private data according to the data of the intelligent cash box, where the verification data is used to verify the legitimacy and integrity of the private data; Split the private data according to a preset rule to obtain first encrypted data and second encrypted data; Store the first encrypted data in the intelligent money box, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete the encryption.
[0006] Optionally, after storing the first encrypted data in the intelligent money box, sending the second encrypted data and the verification data to the server, and storing the second encrypted data by the server to complete the encryption, the method further includes: When the intelligent money box receives an opening instruction, control the intelligent money box to obtain the second encrypted data and the verification data from the server; Recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule; Verify the legality and integrity of the verification data; If the verification data passes the verification, decrypt the private data using the session key to obtain the original stored data of the intelligent money box; According to the opening instruction, control the intelligent money box to perform an opening operation.
[0007] Optionally, the verifying the legality and integrity of the verification data includes: When the encryption method is a symmetric encryption algorithm with integrity protection, obtain the verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key; When the encryption method is a digital signature algorithm, obtain the digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent money box.
[0008] Optionally, before recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rule, the method further includes: Obtain the first hash value of the second encrypted data calculated by the server, and calculate the second hash value of the second encrypted data by the intelligent money box; When the first hash value and the second hash value are the same, determine that the second encrypted data is secure data, so that the intelligent money box recombines the private data through the first encrypted data and the second encrypted data.
[0009] Optionally, after the digital certificate passes the verification, establishes a communication link between the intelligent money box and the server, and generates a session key, the method further includes: Store the session key in the security module and / or trusted execution environment of the intelligent money box; Control the intelligent locker and the server to establish a connection according to a preset period and / or a preset communication data volume, and obtain a new session key to replace the session key.
[0010] Optionally, verifying the legality of the digital certificate of the intelligent locker device includes: Obtain the number of devices of all intelligent lockers in the collaborative network; When the number of devices is 1, locally verify the digital certificate of the intelligent locker to obtain a verification result; When the number of devices is not 1, execute a voting mechanism based on the blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent locker and obtain a verification result; When the verification result is not passed, reject the establishment of a communication link between the intelligent locker and the server, and generate an alarm feedback.
[0011] Optionally, after rejecting the establishment of a communication link between the intelligent locker and the server and generating an alarm feedback, the method further includes: Input the verification result into the artificial intelligence-based memory model of the intelligent locker, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result; Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior; If the processing method is successfully obtained, add a processing label to the verification result; If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0012] The second aspect of the present application provides a digital certificate-based intelligent locker encryption system, including: A first verification unit for starting the intelligent locker and verifying the legality of the digital certificate of the intelligent locker device; A first establishment unit for establishing a communication link between the intelligent locker and the server and generating a session key when the digital certificate is verified, and the session key is a temporary symmetric key generated according to the communication link; A second verification unit for performing two-way authentication on the intelligent locker and the server through a zero-knowledge authentication method; An encryption unit for controlling the intelligent locker to encrypt its own stored data through the session key to obtain private data when the authentication is passed; A generation unit for generating verification data of the private data according to the data of the intelligent locker, and the verification data is used to verify the legality and integrity of the private data; A splitting unit, configured to split the private data according to a preset rule to obtain first encrypted data and second encrypted data; A first storage unit, configured to store the first encrypted data in the intelligent safe, and send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete encryption.
[0013] Optionally, the system further includes: A first obtaining unit, configured to control the intelligent safe to obtain the second encrypted data and the verification data from the server when the intelligent safe receives an opening instruction; A recombination unit, configured to recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule; A third verification unit, configured to verify the legality and integrity of the verification data; A decryption unit, configured to, if the verification data passes the verification, decrypt the private data using the session key to obtain the original stored data of the intelligent safe; An execution unit, configured to control the intelligent safe to perform an opening operation according to the opening instruction.
[0014] Optionally, the third verification unit is specifically configured to: When the encryption method is a symmetric encryption algorithm with integrity protection, obtain a verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key; When the encryption method is a digital signature algorithm, obtain a digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0015] Optionally, the system further includes: A second obtaining unit, configured to obtain a first hash value of the second encrypted data calculated by the server, and calculate a second hash value of the second encrypted data by the intelligent safe; A determination unit, configured to determine that the second encrypted data is secure data when the first hash value is the same as the second hash value, so that the intelligent safe recombines the private data through the first encrypted data and the second encrypted data.
[0016] Optionally, the system further includes: A second storage unit, configured to store the session key in a security module and / or a trusted execution environment of the intelligent safe; A second establishment unit, configured to control the intelligent safe and the server to establish a connection according to a preset period and / or a preset communication data volume, obtain a new session key, and replace the session key.
[0017] Optionally, the first verification unit is specifically configured to: Obtain the number of devices of all intelligent safes in the collaborative network; When the number of devices is 1, locally verify the digital certificate of the intelligent safe to obtain a verification result; When the number of devices is not 1, execute a voting mechanism based on a blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent safe and obtain a verification result; When the verification result is not passed, reject the intelligent safe and the server from establishing a communication link, and generate an alarm feedback.
[0018] Optionally, the first verification unit is further specifically configured to: Input the verification result into the artificial intelligence-based memory model of the intelligent safe, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result; Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain a corresponding processing method according to the abnormal behavior; If the processing method is successfully obtained, add a processing label to the verification result; If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0019] A third aspect of the present application provides an intelligent safe encryption device based on a digital certificate, and the device includes: A processor, a memory, an input / output unit, and a bus; The processor is connected to the memory, the input / output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method of the first aspect and any optional method in the first aspect.
[0020] A fourth aspect of the present application provides a computer-readable storage medium, and a program is stored on the computer-readable storage medium. When the program is executed on a computer, it executes the method of the first aspect and any optional method in the first aspect.
[0021] As can be seen from the above technical solutions, in this application, digital certificates and zero-knowledge verification are used to prevent forged devices from accessing. Session key encryption is used to ensure a secure communication environment and prevent data from being eavesdropped or tampered with. Data integrity verification is used to ensure data security, and data splitting and storage are used to reduce the impact of data leakage and avoid single-point leakage, thereby enhancing the security and anti-attack ability of the intelligent cash box, and further enhancing the security during the opening and data processing of the intelligent cash box. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0023] Figure 1 FIG. Figure 2a FIG. Figure 2b FIG. Figure 3 FIG. Figure 4 FIG. Figure 5 FIG. Figure 6 FIG. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] It should be noted that the digital certificate-based intelligent cash box encryption method provided in this application can be applied to a terminal, a system, or a server. For example, the terminal can be a smart phone, a computer, a tablet computer, a smart TV, a smart watch, a portable computer terminal, or a fixed terminal such as a desktop computer. For the convenience of description, this application takes the terminal as the execution subject for illustration.
[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0026] Please refer to Figure 1 , the present application first provides an embodiment of an intelligent cash box encryption method based on digital certificates, and this embodiment includes: S101. Start the intelligent cash box and verify the legality of the digital certificate of the intelligent cash box device; After the intelligent cash box device is started, it is first necessary to verify the legality of the digital certificate to ensure the credibility of the device's identity. This verification process can be based on the public key infrastructure (PKI) or other trust mechanisms to confirm whether the digital certificate of the intelligent cash box is valid, and prevent illegal devices from accessing the system.
[0027] Specifically, first start the intelligent cash box device. The intelligent cash box is a physical device used to store cash or other valuables and has data processing and communication capabilities. After startup, the intelligent cash box obtains the pre-configured digital certificate from its internal memory or security module. The digital certificate is issued by a trusted certificate authority (CA) and contains the public key and identity identification information of the intelligent cash box. Verifying the legality of the digital certificate includes: verifying the validity of the certificate through the certificate chain, checking whether the certificate is within the validity period, and confirming that the certificate is not included in the revocation list (CRL). If the verification passes, proceed to the next step; if the verification fails, terminate the process and record the exception log.
[0028] S102. When the digital certificate verification passes, establish a communication link between the intelligent cash box and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link; If the digital certificate verification of the intelligent cash box is successful, a secure communication link is established between the intelligent cash box and the server. In this process, the intelligent cash box and the server use the elliptic curve Diffie-Hellman (ECDH) key exchange algorithm to generate a session key. This key is a temporary symmetric key dynamically generated according to the current communication link and is used for subsequent data encryption to ensure the security of communication.
[0029] Specifically, the secure link uses the Transport Layer Security (TLS) protocol or a similar protocol to negotiate communication parameters through a handshake process. In this process, the intelligent cash box and the server generate a session key through the key exchange algorithm. The session key is a temporary symmetric key and is only valid for the current communication session. For example, the key length of the AES-256 encryption standard is 256 bits.
[0030] S103. Perform two-way authentication on the intelligent safe and the server through a zero-knowledge authentication method; After establishing secure communication, adopt the Zero-Knowledge Proof (ZKP) method to perform two-way authentication on the intelligent safe and the server to ensure the authenticity of both parties' identities.
[0031] Specifically, the zero-knowledge proof protocol can adopt the Schnorr protocol or a similar non-interactive zero-knowledge proof method. The intelligent safe generates proof information to prove that it holds the private key bound to the digital certificate without revealing the content of the private key; the server also generates proof information to verify its identity. The verification process is completed through the random challenges and responses exchanged between the two parties. If both parties pass the verification, their identities are confirmed as legal, and the subsequent steps are continued.
[0032] The zero-knowledge proof protocol adopts protocols such as zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) or zk-STARKs (Zero-Knowledge Transparent Argument of Knowledge) to ensure that the identity verification does not disclose any sensitive information and only verifies the correctness of the identity. The zero-knowledge authentication method requires mutual authentication between the intelligent safe and the server.
[0033] The specific verification process is as follows: The intelligent safe encrypts the identity information with the private key to generate a commitment value. The commitment value is used for the intelligent safe to prove its identity information without directly exposing the real information. The server sends a random challenge to the intelligent safe, requiring it to prove the possession of the private key through the zero-knowledge proof method. The intelligent safe generates a response, which can only be generated by an entity with the correct private key. The server confirms the identity of the intelligent safe by verifying the validity of the response.
[0034] The server uses the private key to generate a commitment value related to the identity, similar to the identity verification process of the intelligent safe. The server sends a random challenge to the intelligent safe through a signature or encryption protocol, requiring the intelligent safe to verify its knowledge of the commitment.
[0035] The intelligent safe verifies the identity of the server according to the provided server response and the zero-knowledge proof method. After successful verification, the intelligent safe confirms that the server's identity is legal.
[0036] Use the zero-knowledge proof to simultaneously complete the security verification process of key exchange, ensuring that both communication parties generate a shared key without disclosing private information.
[0037] Use zero - knowledge proofs to complete the exchange process of the encryption algorithm, ensuring that both parties can jointly calculate the shared session key without directly exchanging the key itself. The two parties can confirm each other's shared key through zero - knowledge proofs and use the shared key for subsequent communication encryption.
[0038] Ensure that zero - knowledge authentication not only completes authentication but also prevents common security threats such as man - in - the - middle attacks and replay attacks. Specifically, in each authentication process, the intelligent safe and the server both generate a new random challenge, which includes elements such as a timestamp and a session number, ensuring that each verification process is unique and preventing replay attacks. Use certificate chain verification and public key infrastructure to ensure that the exchanged public keys are trustworthy and prevent forged public keys from being substituted in man - in - the - middle attacks.
[0039] It should be noted that if the zero - knowledge authentication fails, the device needs to wait for a preset number of seconds and then retry. After a preset number of failed attempts, it enters the locked mode and requires manual review. The preset description and the preset number of failed attempts can be set through terminal input.
[0040] S104. When the authentication passes, control the intelligent safe to encrypt its own stored data with the session key to obtain private data; After completing the two - way authentication, the intelligent safe uses the session key to encrypt the stored data to generate private data to prevent the data from being accessed or tampered with without authorization during storage.
[0041] Specifically, the intelligent safe reads the stored data from its internal storage unit (such as flash memory or hard disk). The stored data can include sensitive information such as transaction records and device status logs. Use the session key generated in step S102 to encrypt the stored data to generate private data. The encryption algorithm can use a symmetric encryption algorithm, such as the AES - CBC mode. The specific process is as follows: divide the stored data into blocks (for example, each block is 128 bits), and encrypt it with the session key and a randomly generated initialization vector to obtain the private data in ciphertext form. The length of the private data is the same as that of the stored data, but the content cannot be directly read.
[0042] S105. Generate verification data for the private data according to the data of the intelligent safe, and the verification data is used to verify the legality and integrity of the private data; The system generates verification data based on the encrypted private data. The verification data can be a hash value, a digital signature, or a verification ID. Specifically, the verification data is obtained according to the used encryption method, and the verification data is used for subsequent data integrity and legality checks.
[0043] S106. Split the private data according to preset rules to obtain the first encrypted data and the second encrypted data; To further improve data security, the private data is sharded and stored according to a preset splitting rule, and is split into first encrypted data and second encrypted data to prevent the risk of single-point leakage.
[0044] Split the private data according to a preset rule, specifically: Split the private data according to a preset ratio; and / or Split the private data according to data weight or data characteristics.
[0045] Among them, the terminal splits the private data into two parts according to a preset rule: first encrypted data (D1) and second encrypted data (D2). The preset rule can be splitting by a fixed ratio. For example, the first 50% of the private data is used as D1, and the latter 50% is used as D2; or splitting according to the data content characteristics or weights. For example, splitting at the entry boundary of the transaction record or according to the weight label of the data. Among them, the weight of the data privacy level is obtained through a preset weight list. Generally, the intelligent safe behavior (unboxing time, content information of the actual stored items) is a high-weight behavior, and the intelligent safe maintenance data (connection record with the server, intelligent safe firmware upgrade record) is a low-weight behavior.
[0046] In the case of using two preset rules for data splitting at the same time, the private data is mainly split according to data weight or data characteristics. When the splitting content reaches the preset ratio, stop data splitting to generate the first encrypted data and the second encrypted data to ensure that the complete data content cannot be obtained without merging the first encrypted data and the second encrypted data.
[0047] After splitting, the sum of the lengths of D1 and D2 is equal to the total length of the private data, and each part is in ciphertext form and cannot be parsed to the original stored data alone.
[0048] It should be noted that the preset rule is an optional item. The preset rule is selected according to the user's needs to split the private data according to the preset ratio or according to the data weight. Among them, when splitting according to the preset ratio, the splitting ratio is set by the user's active input.
[0049] S107. Store the first encrypted data in the intelligent safe, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete encryption.
[0050] The first encrypted data is stored locally in the intelligent safe to ensure data accessibility. The second encrypted data and the verification data are sent to the server, and the server stores the second encrypted data to achieve separate data storage. Even if a certain storage location is breached, the attacker cannot directly restore the complete data.
[0051] Specifically, the first encrypted data is stored in the local storage unit of the intelligent safe, such as a non-volatile memory, to ensure that part of the data can be retained even when disconnected from the server. The second encrypted data and the verification data are sent to the server through the established communication link. When sending, the TLS protocol can be used to encrypt the transmitted data to prevent interception. After receiving the second encrypted data and the verification data, the server stores them in a database or a distributed storage system, marked and associated with the identifier of the intelligent safe. Thus, the encryption process is completed, and the private data is distributed and stored at both ends of the intelligent safe and the server.
[0052] This embodiment prevents forged devices from accessing through digital certificates and zero-knowledge verification, ensures a secure communication environment to prevent data from being eavesdropped or tampered with through session key encryption, ensures data security through data integrity verification, reduces the impact of data leakage by splitting and storing data, and avoids single-point leakage, thereby enhancing the security and anti-attack ability of the intelligent safe.
[0053] Please refer to Figure 2a and Figure 2b This application embodiment provides another embodiment of the intelligent safe encryption method based on digital certificates, and this embodiment includes: S201. Start the intelligent safe and verify the legality of the digital certificate of the intelligent safe device; S202. When the digital certificate is verified, establish a communication link between the intelligent safe and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link; Steps S201 to S202 in this embodiment are similar to steps S101 to S102 in the foregoing embodiment, and will not be elaborated here specifically.
[0054] S203. Store the session key in the security module and / or trusted execution environment of the intelligent safe; After the intelligent safe and the server establish secure communication and generate a session key, the system will store the key in the security module or trusted execution environment of the intelligent safe. This measure can protect the session key from being stolen or tampered with, avoid the security risks brought by key leakage, and ensure the encryption security of data during transmission and storage.
[0055] Specifically, after the session key is generated through the communication link between the intelligent cash box and the server in step S202, it needs to be securely stored to prevent leakage. The intelligent cash box stores the session key in its security module (such as a hardware security module HSM) or a trusted execution environment (TEE, such as ARM TrustZone or Intel SGX). Specifically, if a security module is used, the session key is stored in an encrypted form within a dedicated chip and protected by physical isolation and access control; if a TEE is used, the session key is stored in an isolated execution environment and unauthorized access is prevented through memory encryption and runtime isolation. When storing, a timestamp or session identifier can be added to the session key for subsequent management or replacement.
[0056] S204. Control the intelligent cash box and the server to establish a connection according to a preset period and / or a preset communication data volume, obtain a new session key, and replace the session key.
[0057] To prevent potential security risks caused by using the same key for a long time, the system will trigger the connection between the intelligent cash box and the server according to a preset period (such as every once in a while) or a preset communication data volume (such as when the encrypted data reaches a certain size), obtain a new session key, and replace the old key.
[0058] Specifically, the preset period can be a time period, for example, triggering key update once every 24 hours; the preset communication data volume can be a cumulative transmission data threshold, for example, triggering update when it reaches 10MB. In addition, when a security event is triggered, such as detecting abnormal access, unauthorized attempts, or suspicious communications, the server and the intelligent cash box will force key update. When the above conditions are met, the intelligent cash box initiates a connection request to the server, renegotiates communication parameters through the TLS protocol, and generates a new session key. After the new key is generated, it replaces the old key stored in the security module or TEE, and the old key is securely erased (such as by overwriting with zero values) to ensure that it cannot be recovered for use.
[0059] It should be noted that in the actual usage scenario, the latest key version number is recorded through the blockchain to ensure that all devices can be correctly synchronized. If the key update fails, the current key is retained and updated again during the next session.
[0060] S205. Perform two-way authentication on the intelligent cash box and the server through a zero-knowledge authentication method; S206. When the authentication is passed, control the intelligent cash box to encrypt its own stored data through the session key to obtain private data; S207. Generate verification data for the private data according to the data of the intelligent cash box, and the verification data is used to verify the legality and integrity of the private data; S208. Split the private data according to a preset rule to obtain first encrypted data and second encrypted data; S209. Store the first encrypted data in the intelligent safe, and send the second encrypted data and the verification data to the server. The server stores the second encrypted data to complete the encryption; Steps S204 to S209 in this embodiment are similar to steps S103 to S107 in the foregoing embodiment, and will not be elaborated here specifically.
[0061] S210. When the intelligent safe receives an opening instruction, control the intelligent safe to obtain the second encrypted data and the verification data from the server; The intelligent safe is temporarily stored in the RAM to prevent data leakage. After receiving the opening instruction, the intelligent safe requests the server to obtain the second encrypted data and the verification data.
[0062] Specifically, the opening instruction is triggered by user input or a remote control signal, and the decryption and opening process is started when triggered. After the server returns the data, the intelligent safe sends a request message with the device identifier using a pre-established TLS connection. The server retrieves the corresponding second encrypted data and verification data from the database according to the identifier and returns them through an encrypted channel. After receiving them, the intelligent safe temporarily stores the second encrypted data and the verification data in the memory for subsequent processing.
[0063] S211. Obtain the first hash value of the second encrypted data calculated by the server, and calculate the second hash value of the second encrypted data through the intelligent safe; The server calculates the first hash value of the second encrypted data, stores it and returns it to the intelligent safe. The intelligent safe calculates the second hash value using the same hash algorithm.
[0064] Specifically, to verify the integrity of the second encrypted data during transmission, the intelligent safe obtains the first hash value calculated by the server. The first hash value is calculated by the server using the SHA-256 algorithm when storing the second encrypted data and is returned together with the second encrypted data. At the same time, the intelligent safe performs local calculation on the received second encrypted data to generate a second hash value, also using the SHA-256 algorithm. The calculation process ensures that the input data is consistent. For example, the complete byte sequence of the second encrypted data is hashed, and the result is a 256-bit fixed-length hash value.
[0065] S212. When the first hash value and the second hash value are the same, determine that the second encrypted data is secure data, so that the intelligent safe recombines the private data through the first encrypted data and the second encrypted data.
[0066] Specifically, if the first hash value is equal to the second hash value, it indicates that the data has not been tampered with, and data merging is performed; if the first hash value is not equal to the second hash value, it indicates that the data may have been tampered with, decryption is refused, and an alarm message is sent to the server.
[0067] S213. Recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule; According to the preset rule used in step S208, recombine the first encrypted data and the second encrypted data into the complete private data. Specifically, if the preset rule is proportional division (for example, the first encrypted data is the first 50% and the second encrypted data is the last 50%), then the first encrypted data and the second encrypted data are merged in sequence by byte splicing; if the rule is based on content features, then recombination is performed according to the predefined segmentation identifier. After recombination, the length and content of the private data should be the same as the private data during encryption, generating the complete ciphertext data for subsequent verification and decryption.
[0068] S214. When the encryption method is a symmetric encryption algorithm with integrity protection, obtain the verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key; The encryption method is a symmetric encryption algorithm with integrity protection (such as AES-GCM, AES-CCM), and the verification data contains the verification Tag. The intelligent safe extracts the verification Tag from the verification data. The verification Tag is generated by the session key and the private data during encryption. The verification process is as follows: Use the session key stored in the security module or TEE and the recombined private data to verify whether the obtained verification Tag matches through the AES-GCM algorithm. That is, calculate the authentication value of the recombined private data and compare it with the obtained verification Tag. If they are consistent, the integrity of the recombined private data passes; if they are inconsistent, the verification fails.
[0069] S215. When the encryption method is a digital signature algorithm, obtain the digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0070] If the encryption method is a digital signature algorithm (such as RSA / ECDSA digital signature), verify the digital signature through the public key of the intelligent safe to ensure that the data has not been tampered with.
[0071] Specifically, the verification data contains a digital signature. The intelligent suitcase extracts the digital signature from the verification data, and the digital signature is generated by signing the hash value of the private data with a private key. The verification process is as follows: Use the public key of the intelligent suitcase to decrypt the digital signature to obtain the hash value H1, calculate the hash value H2 of the recombined private data (such as SHA-256), and compare H1 and H2. If they are equal, it is confirmed that the recombined private data is complete and the source is legal; if they are not equal, the verification fails.
[0072] S216. If the verification data passes the verification, use the session key to decrypt the private data to obtain the original stored data of the intelligent suitcase; When the verification of S214 or S215 passes, the intelligent suitcase decrypts the private data using the session key. If it is AES-GCM, since the Tag verification has been passed before decryption, directly use the session key and the initialization vector to perform AES-GCM decryption to obtain the original stored data; if it is ordinary symmetric encryption (such as AES-CBC), then use the session key and the initialization vector to decrypt the private data. The decrypted original stored data is the transaction record or status data of the intelligent suitcase, and is restored to the plaintext form.
[0073] S217. According to the opening instruction, control the intelligent suitcase to perform an opening operation.
[0074] After successful decryption, perform a physical operation according to the opening instruction, such as unlocking the mechanical lock or electronic lock of the intelligent suitcase to allow the user to access the items stored inside. Specifically, the controller of the intelligent suitcase receives the decrypted data and verifies whether it contains opening permission information (such as a specific command code). If it meets the requirements, it drives the actuator to complete the opening. If the data is abnormal or the permission is insufficient, it remains in the locked state and records a log.
[0075] In this embodiment, through the secure storage and dynamic update of the session key, the integrity verification of the second encrypted data, the recombination and verification of the private data, and the decryption and opening operations, high-security processing of the data of the intelligent suitcase is achieved. The protection and timeliness of the session key are enhanced, and the integrity and legality of the data are ensured through multi-level verification (hash comparison, Tag or signature verification), and finally the opening operation is safely executed. This implementation method is applicable to scenarios that require regular key updates and strict verification of data integrity.
[0076] Please refer to Figure 3 , another embodiment of the intelligent suitcase encryption method based on a digital certificate is provided in the embodiment of the present application. This embodiment includes: S301. Start the intelligent suitcase and obtain the number of devices of all intelligent suitcases within the collaborative network; When the intelligent suitcase is started, its hardware and communication modules are initialized first, and then it detects the presence of other intelligent suitcase devices in the network through a collaborative network (such as a local area network or an Internet of Things protocol). Specifically, the intelligent suitcase broadcasts device discovery messages (such as UDP-based multicast messages) and receives responses from other devices. For each valid response received, the counter is incremented by 1, and finally the number of devices N of all intelligent suitcases within the collaborative network is obtained. The number of devices reflects the total number of active intelligent suitcases in the current network. For example, N may be 1 (only itself) or greater than 1 (including other devices).
[0077] S302. When the number of devices is 1, locally verify the digital certificate of the intelligent suitcase to obtain a verification result; When the detected number of devices N is equal to 1, it means that only the current intelligent suitcase is running in the network, and no collaborative verification is required. The intelligent suitcase performs local digital certificate verification: reads the digital certificate from its internal memory or security module. The certificate is issued by a trusted certificate authority (CA) and contains a public key and an identity identifier. The verification process includes checking the certificate signature (using the CA public key), the validity period, and whether it is in the locally stored revocation list (CRL). If the certificate passes all checks, the verification is successful; if the local certificate verification fails, it tries to request the nearest trusted server or device for auxiliary verification until it is confirmed that the verification cannot be completed, generates an exception, and records a log.
[0078] S303. When the number of devices is not 1, perform a voting mechanism based on a blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent suitcase to obtain a verification result; When the number of devices N is greater than 1, other intelligent suitcases in the collaborative network participate in the verification process, using a blockchain-based consensus algorithm (such as the Practical Byzantine Fault Tolerance algorithm PBFT). Specifically, the current intelligent suitcase (denoted as node A) broadcasts its digital certificate to the other N - 1 nodes in the network. Each node verifies the legality of the certificate (checks the signature, validity period, etc.) and generates a voting result (pass or fail). The votes are collected through broadcasting, and all nodes execute PBFT consensus: if more than 2 / 3 of the nodes (i.e., (N - 1) / 3 + 1) vote pass, the consensus result is that the verification passes; otherwise, it fails. The final result is recorded as a boolean value and returned to node A as the verification result.
[0079] Specifically, for the verification result obtained in step S302 or S303, when the verification result directly passes, step S309 is executed; when the verification result fails, step S304 is executed.
[0080] S304. When the verification result is fail, reject the intelligent suitcase from establishing a communication link with the server and generate an alarm feedback.
[0081] If the verification result in step S302 or S303 fails, the intelligent money box refuses to establish a communication link with the server. Specifically, the communication module of the intelligent money box terminates the TLS handshake request and marks the status as "verification failed". Meanwhile, an alarm feedback is generated: an alarm message containing a timestamp, device identifier, and failure reason (such as "certificate expired" or "consensus not passed") is constructed and recorded or reported through a predefined channel (such as local log or sent to the management terminal) to ensure that the anomaly is traceable.
[0082] S305. Input the verification result into the artificial intelligence-based memory model of the intelligent money box, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result. Regardless of whether the verification result is passed or not, the verification result is input into the memory model through artificial intelligence for analysis. The memory model can be a machine learning-based classification model (such as Naive Bayes or neural network), which is pre-trained to identify patterns of communication behavior. The input data includes the verification result (boolean value), verification time, and context information (such as the number of network devices). The model analyzes the communication behavior corresponding to the verification result, such as the frequency or time distribution of verification failures, and outputs an analysis result. The analysis result may be a class label (such as "normal", "suspicious") or an anomaly probability value (for example, 0.8 indicates an 80% probability of anomaly).
[0083] Specifically, when the intelligent money box refuses to establish a communication link with the server and generates an alarm feedback, the verification result (such as "verification failed") will be input into the artificial intelligence-based memory model built into the intelligent money box. This memory model adopts advanced deep learning technologies, such as Recurrent Neural Network (RNN) or Long Short-Term Memory Network (LSTM), to effectively process the time-series data of communication behavior. The input data of the model includes but is not limited to the following features: Verification result: such as the status of "verification failed". Timestamp: the time when the verification occurred. Communication frequency: the number of communication attempts per unit time. Historical communication records: communication behavior data over a period of time in the past. By analyzing these input data, the memory model can capture the time-series characteristics and potential patterns of communication behavior, such as abnormal verification failure frequency or abnormal communication attempt intervals. After the analysis is completed, the model outputs an analysis result, which may be one of the following forms: Classification label: such as "high-risk attempt", "suspected device failure". Anomaly probability score: such as 0.85 (indicating an 85% probability of abnormal behavior).
[0084] S306. Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior. Analyze the analysis result of step S305 to identify abnormal behaviors. Specifically, if the analysis result is "suspicious" or the abnormal probability exceeds a preset threshold (such as 0.7), extract abnormal features, such as "continuous multiple verification failures" or "abnormal concentration of verification times". The intelligent money box queries the locally stored processing strategy table according to the abnormal behavior. The table predefines the mapping relationship between abnormal types and processing methods. For example, if the abnormality is "multiple verification failures", the corresponding processing method may be "suspend communication attempts for 10 minutes"; if there is no matching item, proceed to the next step. The processing methods are recorded in the form of text or instructions.
[0085] Specifically, after obtaining the analysis result of S305, the intelligent money box inputs the analysis result into artificial intelligence to further analyze the abnormal behaviors therein using artificial intelligence technology. Specifically, artificial intelligence uses technologies such as natural language processing (NLP) or decision trees to extract key abnormal behavior features from the analysis result. For example: "continuous 5 verification failures"; "multiple communication attempts during non-working hours". Subsequently, the intelligent money box dynamically generates or selects corresponding processing methods through an AI-driven decision engine. The decision engine can be one of the following two forms: Rule-based expert system: Preset the mapping relationship between rules and abnormal behaviors. Reinforcement learning model: Dynamically optimize the processing strategy according to historical data and real-time feedback. For example: If the abnormal behavior is "high-frequency verification failures", the decision engine may output the processing method as "temporarily lock the device for 30 minutes". If the abnormal behavior is "suspected device failure", then output "initiate device self-check". The processing methods are output in the form of instructions or policy descriptions.
[0086] S307. If the processing method is successfully obtained, add a processing label to the verification result; If the processing method is successfully obtained in step S306, the intelligent money box adds a processing label to the verification result. The label is additional metadata, such as "suspend communication for 10 minutes" or "require manual review", and is bound to the verification result and stored in local memory or log. Specifically, the verification result is updated to structured data (such as JSON format), including the original result (passed / failed) and the processing label. After adding the label, the intelligent money box performs corresponding operations according to the label, such as suspending the activities of the communication module.
[0087] It should be noted that if the abnormal behavior affects communication security (such as excessive certificate verification failures), immediately block device communication; if the abnormal behavior affects device performance (such as frequent key update failures), perform delayed processing and send a warning message.
[0088] S308. If the processing method fails to be obtained, retain the verification failed status of the verification result.
[0089] If no matching processing method is found in step S306, the intelligent safe retains the "verification failed" status of the verification result and does not perform additional processing. Specifically, the verification result remains as the boolean value "False", without attaching tags, and the intelligent safe maintains the state of rejecting communication. At the same time, this situation is recorded in the exception log, and the log entry includes the timestamp, device identifier, and a description of "no processing method found" for subsequent analysis or manual intervention.
[0090] S309. When the digital certificate verification passes, establish a communication link between the intelligent safe and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link; S310. Perform two-way authentication on the intelligent safe and the server through a zero-knowledge authentication method; S311. When the authentication passes, control the intelligent safe to encrypt its own stored data through the session key to obtain private data; S312. Generate verification data for the private data according to the data of the intelligent safe, where the verification data is used to verify the legality and integrity of the private data; S313. Split the private data according to a preset rule to obtain first encrypted data and second encrypted data; S314. Store the first encrypted data in the intelligent safe, send the second encrypted data and the verification data to the server, and store the second encrypted data in the server through the server to complete the encryption.
[0091] Steps S309 to S314 in this embodiment are similar to steps S102 to S107 in the foregoing embodiment, and will not be elaborated here specifically.
[0092] Specifically, this embodiment realizes the dynamic verification and exception handling of the digital certificate of the intelligent safe through collaborative network device quantity detection, local or blockchain consensus verification of digital certificates, exception handling and feedback, and communication behavior analysis based on a memory model. It provides a flexible verification mechanism, adapts to single-device and multi-device scenarios, and enhances the adaptive ability of the system through analysis and processing. This implementation is applicable to an intelligent safe network environment that requires high reliability and collaborative verification.
[0093] The above has described in detail the intelligent safe encryption method based on digital certificates in the embodiments of the present application. Next, the intelligent safe encryption system and device based on digital certificates will be described in detail.
[0094] Please refer to Figure 4 , an embodiment of the intelligent safe encryption system based on digital certificates is provided in the embodiments of the present application, and this embodiment includes: The first verification unit 401 is used to start the intelligent money box and verify the legality of the digital certificate of the intelligent money box device; The first establishment unit 402 is used to establish a communication link between the intelligent money box and the server and generate a session key when the digital certificate is verified, and the session key is a temporary symmetric key generated according to the communication link; The second verification unit 403 is used to perform two-way authentication on the intelligent money box and the server by means of zero-knowledge authentication method; The encryption unit 404 is used to control the intelligent money box to encrypt its own stored data through the session key to obtain private data when the authentication is passed; The generation unit 405 is used to generate verification data for the private data according to the data of the intelligent money box, and the verification data is used to verify the legality and integrity of the private data; The splitting unit 406 is used to split the private data according to a preset rule to obtain first encrypted data and second encrypted data; The first storage unit 407 is used to store the first encrypted data in the intelligent money box, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete encryption.
[0095] In this embodiment, the functions of each unit correspond to the steps in the foregoing Figure 1 illustrated embodiment and will not be elaborated here.
[0096] Please refer to Figure 5 Another embodiment of the intelligent money box encryption system based on digital certificate is provided in the embodiment of the present application. This embodiment includes: The first verification unit 501 is used to start the intelligent money box and verify the legality of the digital certificate of the intelligent money box device; The first establishment unit 502 is used to establish a communication link between the intelligent money box and the server and generate a session key when the digital certificate is verified, and the session key is a temporary symmetric key generated according to the communication link; The second storage unit 503 is used to store the session key in the security module and / or trusted execution environment of the intelligent money box; The second establishment unit 504 is used to control the intelligent money box and the server to establish a connection according to a preset period and / or preset communication data volume, and obtain a new session key to replace the session key.
[0097] The second verification unit 505 is used to perform two-way authentication on the intelligent money box and the server by means of zero-knowledge authentication method; An encryption unit 506, configured to, when the authentication is passed, control the intelligent money box to encrypt its own stored data by using the session key to obtain private data; A generation unit 507, configured to generate verification data for the private data according to the data of the intelligent money box, where the verification data is used to verify the legality and integrity of the private data; A splitting unit 508, configured to split the private data according to a preset rule to obtain first encrypted data and second encrypted data; A first storage unit 509, configured to store the first encrypted data in the intelligent money box, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete the encryption.
[0098] A first obtaining unit 510, configured to, when the intelligent money box receives an opening instruction, control the intelligent money box to obtain the second encrypted data and the verification data from the server; A second obtaining unit 511, configured to obtain a first hash value of the second encrypted data calculated by the server, and calculate a second hash value of the second encrypted data by the intelligent money box; A determination unit 512, configured to, when the first hash value is the same as the second hash value, determine that the second encrypted data is secure data, so that the intelligent money box recombines the private data by using the first encrypted data and the second encrypted data.
[0099] A recombination unit 513, configured to recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule; A third verification unit 514, configured to verify the legality and integrity of the verification data; A decryption unit 515, configured to, if the verification data passes the verification, decrypt the private data by using the session key to obtain the original stored data of the intelligent money box; An execution unit 516, configured to control the intelligent money box to perform an opening operation according to the opening instruction.
[0100] In this embodiment, the third verification unit 514 is specifically configured to: When the encryption method is a symmetric encryption algorithm with integrity protection, obtain a verification Tag from the verification data, and verify the integrity of the private data by using the verification Tag and the session key; When the encryption method is a digital signature algorithm, obtain a digital signature from the verification data, and verify the integrity of the digital signature by using the public key of the intelligent money box.
[0101] In this embodiment, the first verification unit 501 is specifically configured to: Obtain the number of devices of all intelligent lockboxes in the collaborative network; When the number of devices is 1, locally verify the digital certificate of the intelligent lockbox to obtain a verification result; When the number of devices is not 1, execute a voting mechanism based on the blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent lockbox and obtain a verification result; When the verification result is not passed, reject the establishment of a communication link between the intelligent lockbox and the server and generate an alarm feedback.
[0102] In this embodiment, the first verification unit 501 is further specifically configured to: Input the verification result into the artificial intelligence-based memory model of the intelligent lockbox, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result; Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior; If the processing method is successfully obtained, add a processing label to the verification result; If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0103] In this embodiment, the functions of each unit correspond to the steps in the foregoing Figure 2a , Figure 2b and Figure 3 The steps in the illustrated embodiments will not be elaborated here.
[0104] Please refer to Figure 6 , another embodiment of the intelligent lockbox encryption device based on digital certificate provided by the embodiment of the present application includes: A processor 601, a memory 602, an input / output unit 603, and a bus 604; The processor 601 is connected to the memory 602, the input / output unit 603, and the bus 604; The processor 601 specifically executes the operations corresponding to the steps in the method of Figures 1 to 3 , which will not be elaborated here specifically.
[0105] The present application also relates to a computer-readable storage medium on which a program is stored. When the program runs on a computer, the computer is enabled to execute any of the foregoing methods.
[0106] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0107] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0108] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0109] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0110] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical disks and other media that can store program codes.
Claims
1. A smart cash box encryption method based on digital certificates, characterized in that: The method comprises: Start the smart cash box and verify the legitimacy of the digital certificate of the smart cash box device; When the digital certificate is verified, a communication link between the smart cash box and the server is established, and a session key is generated, wherein the session key is a temporary symmetric key generated according to the communication link; Performing two-way authentication of the smart cash box and the server through a zero-knowledge authentication method; When the identity authentication is passed, the smart cash box is controlled to encrypt its own stored data using the session key to obtain private data; Generating verification data of the private data according to the data of the smart cash box, wherein the verification data is used to verify the legitimacy and integrity of the private data; Splitting the private data according to a preset rule to obtain first encrypted data and second encrypted data; The first encrypted data is stored in the smart cash box, the second encrypted data and the verification data are sent to the server, and the second encrypted data is stored by the server to complete the encryption.
2. The method according to claim 1, characterized in that The method further comprises storing the first encrypted data in the smart cash box, sending the second encrypted data and the verification data to the server, and storing the second encrypted data by the server, after encryption is completed: When the smart cash box receives the opening instruction, the smart cash box is controlled to obtain the second encrypted data and the verification data from the server; Recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rule; Verifying the legitimacy and integrity of the verification data; If the verification data is verified successfully, the private data is decrypted using the session key to obtain the original storage data of the smart cash box; According to the opening instruction, the smart cash box is controlled to perform an opening operation.
3. The method according to claim 2, characterized in that The verification of the legitimacy and integrity of the verification data includes: When the encryption method is a symmetric encryption algorithm with integrity protection, obtaining a verification Tag from the verification data, and verifying the integrity of the private data using the verification Tag and the session key; When the encryption method is a digital signature algorithm, a digital signature is obtained from the verification data, and the integrity of the digital signature is verified using the public key of the smart cash box.
4. The method according to claim 2, characterized in that: Before recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rule, the method further includes: Obtaining a first Hash value of the second encrypted data calculated by the server, and calculating a second Hash value of the second encrypted data by the smart cash box; When the first Hash value and the second Hash value are consistent, the second encrypted data is determined to be secure data, so that the smart cash box reassembles the private data through the first encrypted data and the second encrypted data.
5. The method according to any one of claims 1 to 4, characterized in that After the digital certificate is verified, a communication link between the smart cash box and the server is established, and a session key is generated, the method further includes: Storing the session key in a security module and / or a trusted execution environment of the smart cash box; The smart cash box is controlled to establish a connection with the server according to a preset period and / or a preset communication data volume, and a new session key is obtained to replace the session key.
6. The method according to any one of claims 1 to 4, characterized in that The verification of the legitimacy of the digital certificate of the smart cash box device includes: Get the number of all smart cash boxes in the collaborative network; When the number of the devices is 1, locally verify the digital certificate of the smart cash box to obtain a verification result; When the number of the devices is not 1, a voting mechanism based on a blockchain consensus algorithm is executed by other devices to verify the digital certificate of the smart cash box and obtain a verification result; When the verification result is failure, the smart cash box is refused to establish a communication link with the server, and an alarm feedback is generated.
7. The method according to claim 6, characterized in that After refusing to establish a communication link between the smart cash box and the server and generating an alarm feedback, the method further includes: Inputting the verification result into the artificial intelligence-based memory model of the smart cash box, and analyzing the communication behavior corresponding to the verification result through the memory model to obtain an analysis result; Analyzing abnormal behaviors in the analysis results through the artificial intelligence, and obtaining corresponding processing methods according to the abnormal behaviors; If the processing method is successfully obtained, a processing tag is added to the verification result; If the processing method cannot be obtained, the verification result is retained as a verification failure status.
8. An intelligent cash box encryption system based on digital certificates, characterized in that: The system comprises: A first verification unit, used to start the smart cash box and verify the legitimacy of the digital certificate of the smart cash box device; An establishing unit, used for establishing a communication link between the smart cash box and the server and generating a session key when the digital certificate is verified, wherein the session key is a temporary symmetric key generated according to the communication link; A second verification unit, used for bidirectionally verifying the identity of the smart cash box and the server through a zero-knowledge identity verification method; An encryption unit, used for controlling the smart cash box to encrypt its own stored data by using the session key to obtain private data when the identity verification is passed; A generating unit, configured to generate verification data of the private data according to the data of the smart cash box, wherein the verification data is used to verify the legitimacy and integrity of the private data; A splitting unit, used for splitting the private data according to a preset rule to obtain first encrypted data and second encrypted data; The storage unit is used to store the first encrypted data in the smart cash box, send the second encrypted data and the verification data to the server, and store the second encrypted data through the server to complete the encryption.
9. An intelligent cash box encryption device based on digital certificates, characterized in that: The device comprises: Processor, memory, input-output unit, and bus; The processor is connected to the memory, the input and output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a program stored thereon, wherein the program, when executed on a computer, performs the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Smart contract authentication data privacy protection method based on zero knowledge proof
CN109614820A
Bank entity management method and device and computer readable storage medium
CN116091190A
Electronic deposit box system
US20020046188A1
Secure data interaction method and system
WO2015161690A1