An intelligent cashbox encryption method, system and storage medium based on digital certificates
Through the encryption method of smart box with digital certificates and zero-knowledge verification, the problem of insufficient security of traditional smart box is solved, the secure storage and communication of data is realized, and the security and attack resistance are improved.
Patent Information
- Application Number
- CN202510443468.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The existing smart boxes are insufficient security, traditional encryption methods are prone to leaking keys, high computing overhead, and complex certificate management, making it difficult to meet security needs.
Digital certificates are used to verify the legality, generate session keys, perform two-way authentication through zero-knowledge authentication, and split the data into first encrypted data and second encrypted data to store separately, encrypted using the server, and ensure data integrity by combining hash values and digital signatures.
It improves the security of smart boxes, prevents data from being eavesdropped or tampered, reduces the risk of single-point leakage, and enhances the ability to resist attacks.
Smart Images

Figure CN120151083B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of intelligent cash boxes, and particularly to an intelligent cash box encryption method, system and storage medium based on digital certificates. Background Art
[0002] As a device for storing valuables such as cash and bills, intelligent cash boxes are widely used in places such as banks and supermarkets. Their security is directly related to asset protection and business compliance. Traditional technologies mostly use symmetric encryption (such as AES), asymmetric encryption (such as RSA), or digital certificate authentication based on PKI, combined with username and password for identity verification.
[0003] In the prior art, as an embedded device, due to limited device resources, the symmetric encryption key of the intelligent cash box is prone to leakage, the asymmetric encryption has a large computational overhead, and the traditional authentication method based on the intelligent cash box is easy to be cracked, making it difficult to ensure that the data has not been tampered with. At the same time, there are certificate management defects, that is, under a large number of devices, the management of certificate issuance, update and revocation is complex, and relying on a single CA institution is prone to single-point risks, thus resulting in the security of the intelligent cash box not meeting the security requirements of its actual use scenario. Summary of the Invention
[0004] To solve the above technical problems, this application provides an intelligent cash box encryption method, system and storage medium based on digital certificates to improve the security of intelligent cash boxes.
[0005] The technical solutions provided in this application are described below:
[0006] The first aspect of this application provides an intelligent cash box encryption method based on digital certificates, including:
[0007] Start the intelligent cash box and verify the legitimacy of the digital certificate of the intelligent cash box device;
[0008] When the digital certificate is verified, establish a communication link between the intelligent cash box and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link;
[0009] Perform two-way authentication on the intelligent cash box and the server through a zero-knowledge authentication method;
[0010] When the authentication is passed, control the intelligent cash box to encrypt its own stored data with the session key to obtain private data;
[0011] Generate verification data for the private data according to the data of the intelligent cash box, where the verification data is used to verify the legitimacy and integrity of the private data;
[0012] Split the private data according to the preset rules to obtain first encrypted data and second encrypted data;
[0013] Store the first encrypted data in the intelligent safe, send the second encrypted data and the verification data to the server, and store the second encrypted data in the server through the server to complete the encryption.
[0014] Optionally, after storing the first encrypted data in the intelligent safe, sending the second encrypted data and the verification data to the server, and storing the second encrypted data in the server through the server to complete the encryption, the method further includes:
[0015] When the intelligent safe receives an opening instruction, control the intelligent safe to obtain the second encrypted data and the verification data from the server;
[0016] Recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rules;
[0017] Verify the legality and integrity of the verification data;
[0018] If the verification data passes the verification, decrypt the private data using the session key to obtain the original stored data of the intelligent safe;
[0019] According to the opening instruction, control the intelligent safe to perform an opening operation.
[0020] Optionally, the verification of the legality and integrity of the verification data includes:
[0021] When the encryption method is a symmetric encryption algorithm with integrity protection, obtain the verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key;
[0022] When the encryption method is a digital signature algorithm, obtain the digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0023] Optionally, before recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rules, the method further includes:
[0024] Obtain the first hash value of the second encrypted data calculated by the server, and calculate the second hash value of the second encrypted data by the intelligent safe;
[0025] When the first hash value and the second hash value are consistent, determine that the second encrypted data is secure data, so that the intelligent safe recombines the private data through the first encrypted data and the second encrypted data.
[0026] Optionally, after the digital certificate is verified and passed, a communication link between the intelligent safe and the server is established and a session key is generated, the method further includes:
[0027] Store the session key in the security module and / or trusted execution environment of the intelligent safe;
[0028] Control the intelligent safe and the server to establish a connection according to a preset period and / or preset communication data volume, and obtain a new session key to replace the session key.
[0029] Optionally, verifying the legality of the digital certificate of the intelligent safe device includes:
[0030] Obtain the number of devices of all intelligent safes in the collaborative network;
[0031] When the number of devices is 1, locally verify the digital certificate of the intelligent safe to obtain a verification result;
[0032] When the number of devices is not 1, execute a voting mechanism based on the blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent safe and obtain a verification result;
[0033] When the verification result is not passed, reject the establishment of a communication link between the intelligent safe and the server and generate an alarm feedback.
[0034] Optionally, after rejecting the establishment of a communication link between the intelligent safe and the server and generating an alarm feedback, the method further includes:
[0035] Input the verification result into the artificial intelligence-based memory model of the intelligent safe, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result;
[0036] Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior;
[0037] If the processing method is successfully obtained, add a processing label to the verification result;
[0038] If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0039] The second aspect of the present application provides an intelligent safe encryption system based on a digital certificate, including:
[0040] The first verification unit is used to start the intelligent money box and verify the legality of the digital certificate of the intelligent money box device;
[0041] The first establishment unit is used to establish a communication link between the intelligent money box and the server and generate a session key when the digital certificate verification is passed, and the session key is a temporary symmetric key generated according to the communication link;
[0042] The second verification unit is used to perform two-way authentication on the intelligent money box and the server through a zero-knowledge authentication method;
[0043] The encryption unit is used to control the intelligent money box to encrypt its own stored data through the session key to obtain private data when the authentication is passed;
[0044] The generation unit is used to generate verification data of the private data according to the data of the intelligent money box, and the verification data is used to verify the legality and integrity of the private data;
[0045] The splitting unit is used to split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0046] The first storage unit is used to store the first encrypted data in the intelligent money box, send the second encrypted data and the verification data to the server, and store the second encrypted data through the server to complete encryption.
[0047] Optionally, the system further includes:
[0048] The first acquisition unit is used to control the intelligent money box to acquire the second encrypted data and the verification data from the server when the intelligent money box receives an opening instruction;
[0049] The recombination unit is used to recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule;
[0050] The third verification unit is used to verify the legality and integrity of the verification data;
[0051] The decryption unit is used to decrypt the private data using the session key to obtain the original stored data of the intelligent money box if the verification data verification is passed;
[0052] The execution unit is used to control the intelligent money box to perform an opening operation according to the opening instruction.
[0053] Optionally, the third verification unit is specifically used for:
[0054] When the encryption method is a symmetric encryption algorithm with integrity protection, obtain the verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key;
[0055] When the encryption method is a digital signature algorithm, obtain the digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0056] Optionally, the system further includes:
[0057] A second acquisition unit, configured to acquire a first hash value of the second encrypted data calculated by the server, and calculate a second hash value of the second encrypted data through the intelligent safe;
[0058] A determination unit, configured to determine that the second encrypted data is secure data when the first hash value is the same as the second hash value, so that the intelligent safe reorganizes the private data through the first encrypted data and the second encrypted data.
[0059] Optionally, the system further includes:
[0060] A second storage unit, configured to store the session key in a security module and / or a trusted execution environment of the intelligent safe;
[0061] A second establishment unit, configured to control the intelligent safe and the server to establish a connection according to a preset period and / or a preset communication data volume, and obtain a new session key to replace the session key.
[0062] Optionally, the first verification unit is specifically configured to:
[0063] Obtain the number of devices of all intelligent safes in the collaborative network;
[0064] When the number of devices is 1, locally verify the digital certificate of the intelligent safe to obtain a verification result;
[0065] When the number of devices is not 1, execute a voting mechanism based on a blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent safe to obtain a verification result;
[0066] When the verification result is not passed, reject the intelligent safe and the server from establishing a communication link, and generate an alarm feedback.
[0067] Optionally, the first verification unit is further specifically configured to:
[0068] Input the verification result into the artificial intelligence-based memory model of the intelligent safe, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result;
[0069] Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior;
[0070] If the processing method is successfully obtained, add a processing label to the verification result;
[0071] If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0072] The third aspect of this application provides an intelligent safe encryption device based on a digital certificate, and the device includes:
[0073] A processor, a memory, an input / output unit, and a bus;
[0074] The processor is connected to the memory, the input / output unit, and the bus;
[0075] The memory stores a program, and the processor calls the program to execute the method in the first aspect and any optional method in the first aspect.
[0076] The fourth aspect of this application provides a computer-readable storage medium, and a program is stored on the computer-readable storage medium. When the program is executed on a computer, it executes the method in the first aspect and any optional method in the first aspect.
[0077] It can be seen from the above technical solutions that this application prevents forged devices from accessing through digital certificates and zero-knowledge verification, ensures a secure communication environment to prevent data from being eavesdropped or tampered with through session key encryption, ensures data security through data integrity verification, reduces the impact of data leakage by splitting and storing data, and avoids single-point leakage, thereby improving the security and anti-attack ability of the intelligent safe, and further improving the security during the opening and data processing of the intelligent safe. Description of the Drawings
[0078] In order to more clearly illustrate the technical solutions in this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0079] Figure 1 It is a schematic flowchart of an embodiment of the intelligent safe encryption method based on a digital certificate in this application;
[0080] Figure 2a It is a schematic flowchart of an embodiment in the first stage of the intelligent cash box encryption method based on digital certificates in this application;
[0081] Figure 2b It is a schematic flowchart of an embodiment in the second stage of the intelligent cash box encryption method based on digital certificates in this application;
[0082] Figure 3 It is a schematic flowchart of another embodiment of the intelligent cash box encryption method based on digital certificates in this application;
[0083] Figure 4 It is a schematic structural diagram of an embodiment of the intelligent cash box encryption system based on digital certificates in this application;
[0084] Figure 5 It is a schematic structural diagram of another embodiment of the intelligent cash box encryption system based on digital certificates in this application;
[0085] Figure 6 It is a schematic structural diagram of an embodiment of the intelligent cash box encryption device based on digital certificates in this application. Detailed implementation manners
[0086] It should be noted that the intelligent cash box encryption method based on digital certificates provided in this application can be applied to terminals, systems, or servers. For example, the terminal can be a smart phone, computer, tablet computer, smart TV, smart watch, portable computer terminal, or a fixed terminal such as a desktop computer. For the convenience of description, this application takes the terminal as the execution entity for example.
[0087] Next, the technical solutions in this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0088] Please refer to Figure 1 , this application first provides an embodiment of the intelligent cash box encryption method based on digital certificates, and this embodiment includes:
[0089] S101. Start the intelligent cash box and verify the legality of the digital certificate of the intelligent cash box device;
[0090] After the intelligent cash box device is started, the legality verification of the digital certificate needs to be carried out first to ensure the credibility of the device's identity. This verification process can be based on the public key infrastructure (PKI) or other trust mechanisms to confirm whether the digital certificate of the intelligent cash box is valid and avoid illegal devices from accessing the system.
[0091] Specifically, first, start the intelligent cash box device. The intelligent cash box is a physical device used to store cash or other valuables and has data processing and communication capabilities. After startup, the intelligent cash box obtains a pre-configured digital certificate from its internal memory or security module. The digital certificate is issued by a trusted certificate authority (CA) and contains the public key and identity information of the intelligent cash box. Verifying the legality of the digital certificate includes: verifying the validity of the certificate through the certificate chain, checking whether the certificate is within the validity period, and confirming that the certificate is not included in the revocation list (CRL). If the verification passes, proceed to the next step; if the verification fails, terminate the process and record an exception log.
[0092] S102. When the digital certificate is verified successfully, establish a communication link between the intelligent cash box and the server, and generate a session key. The session key is a temporary symmetric key generated according to the communication link.
[0093] If the digital certificate of the intelligent cash box is verified successfully, a secure communication link is established between the intelligent cash box and the server. During this process, the intelligent cash box and the server use the Elliptic Curve Diffie-Hellman (ECDH) key exchange algorithm to generate a session key. This key is a temporary symmetric key dynamically generated according to the current communication link and is used for subsequent data encryption to ensure the security of communication.
[0094] Specifically, the secure link adopts the Transport Layer Security (TLS) protocol or a similar protocol to negotiate communication parameters through a handshake process. During this process, the intelligent cash box and the server generate a session key through a key exchange algorithm. The session key is a temporary symmetric key and is only valid for the current communication session. For example, the key length of the AES-256 encryption standard is 256 bits.
[0095] S103. Authenticate the intelligent cash box and the server bidirectionally through a zero-knowledge authentication method.
[0096] After establishing secure communication, use the zero-knowledge authentication (Zero-Knowledge Proof, ZKP) method to authenticate the intelligent cash box and the server bidirectionally to ensure the authenticity of both parties' identities.
[0097] Specifically, the zero-knowledge proof protocol can adopt the Schnorr protocol or a similar non-interactive zero-knowledge proof method. The intelligent cash box generates proof information to prove that it holds the private key bound to the digital certificate without disclosing the content of the private key; the server also generates proof information to verify its identity. The verification process is completed through the random challenges and responses exchanged between the two parties. If both parties' verifications pass, confirm that the identities are legal and continue to execute the subsequent steps.
[0098] Zero-knowledge proof protocols, such as those based on zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) or zk-STARKs (Zero-Knowledge Transparent Argument of Knowledge), ensure that authentication does not disclose any sensitive information and only verifies the correctness of the identity. Zero-knowledge authentication methods require mutual authentication between the smart safe and the server.
[0099] The specific verification process is as follows:
[0100] The smart safe encrypts the identity information with a private key to generate a commitment value. The commitment value is used for the smart safe to prove the identity information without directly exposing the real information. The server sends a random challenge to the smart safe, requiring it to prove the possession of the private key through a zero-knowledge proof method. The smart safe generates a response, which can only be generated by an entity with the correct private key. The server confirms the identity of the smart safe by verifying the validity of the response.
[0101] The server uses the private key to generate a commitment value related to the identity, similar to the identity verification process of the smart safe. The server sends a random challenge to the smart safe through a signature or encryption protocol, requiring the smart safe to verify its knowledge of the commitment.
[0102] The smart safe verifies the identity of the server according to the provided server response and the zero-knowledge proof method. After successful verification, the smart safe confirms that the server identity is legal.
[0103] Use zero-knowledge proof to complete the security verification process of key exchange, ensuring that both communication parties generate a shared key without disclosing private information.
[0104] Use zero-knowledge proof to complete the exchange process of encryption algorithms, ensuring that both parties can jointly calculate the shared session key without directly exchanging the key itself. Both parties can confirm each other's shared key through zero-knowledge proof and use the shared key for subsequent communication encryption.
[0105] Ensure that zero-knowledge authentication not only completes authentication but also prevents common security threats such as man-in-the-middle attacks and replay attacks. Specifically, in each authentication process, the smart safe and the server both generate a new random challenge, which includes elements such as a timestamp and a session number, to ensure that each verification process is unique and prevent replay attacks. Use certificate chain verification and public key infrastructure to ensure that the exchanged public keys are trustworthy and prevent forged public keys from being substituted in man-in-the-middle attacks.
[0106] It should be noted that if the zero-knowledge authentication fails, the device needs to wait for a preset number of seconds and then retry. After a preset number of failed attempts, it enters the locked mode and requires manual review. The preset description and the preset number of failed attempts can be set through terminal input.
[0107] S104. When the authentication is passed, control the intelligent safe to encrypt its own stored data with the session key to obtain private data;
[0108] After the two-way authentication is completed, the intelligent safe uses the session key to encrypt the stored data to generate private data, so as to prevent the data from being accessed or tampered with without authorization during the storage process.
[0109] Specifically, the intelligent safe reads the stored data from its internal storage unit (such as flash memory or hard disk), and the stored data may include sensitive information such as transaction records and device status logs. Use the session key generated in step S102 to encrypt the stored data to generate private data. The encryption algorithm can adopt a symmetric encryption algorithm, such as the AES-CBC mode. The specific process is as follows: divide the stored data into blocks (for example, 128 bits per block), and encrypt it with the session key and a randomly generated initialization vector to obtain the private data in ciphertext form. The length of the private data is the same as that of the stored data, but the content cannot be directly read.
[0110] S105. Generate verification data for the private data according to the data of the intelligent safe, and the verification data is used to verify the legality and integrity of the private data;
[0111] The system generates verification data based on the encrypted private data. The verification data can be a hash value, a digital signature or a verification ID. Specifically, the verification data is obtained according to the used encryption method, and the verification data is used for subsequent data integrity and legality checks.
[0112] S106. Split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0113] To further improve data security, the private data is split and stored according to a preset splitting rule, and it is split into first encrypted data and second encrypted data to prevent the risk of single-point leakage.
[0114] Splitting the private data according to a preset rule specifically means:
[0115] Split the private data according to a preset ratio;
[0116] and / or
[0117] Split the private data according to the data weight or data characteristics.
[0118] Among them, the terminal splits the private data into two parts according to the preset rules: the first encrypted data (D1) and the second encrypted data (D2). The preset rules can be split according to a fixed ratio, such as taking the first 50% of the private data as D1 and the last 50% as D2; or split according to the data content characteristics or weight, such as dividing by the entry boundaries of the transaction record or dividing by the boundary according to the weight label of the data, wherein the weight of the degree of data privacy is obtained through the preset weight list. In general, the behavior of the smart cash box (opening time, content information of the actual stored items) is a high-weight behavior, and the maintenance data of the smart cash box (connection record with the server, smart cash box firmware upgrade record) is a low-weight behavior.
[0119] When two preset rules are used for data splitting at the same time, private data is split mainly through data weight or data characteristics. When the split content reaches a preset ratio, data splitting is stopped to generate first encrypted data and second encrypted data to ensure that the complete data content of the first encrypted data and the second encrypted data cannot be obtained without merging.
[0120] After the split, the sum of the lengths of D1 and D2 is equal to the total length of the private data, and each part is in ciphertext form, and the original stored data cannot be parsed alone.
[0121] It should be noted that the preset rules are optional. The preset rules choose to split private data according to a preset ratio or according to data weight based on user needs. When splitting according to a preset ratio, the splitting ratio is set by active user input.
[0122] S107: store the first encrypted data in the smart cash box, send the second encrypted data and the verification data to the server, and store the second encrypted data through the server to complete encryption.
[0123] The first encrypted data is stored locally in the smart cash box to ensure data accessibility. The second encrypted data and verification data are sent to the server, which stores the second encrypted data to achieve data separation storage. Even if a storage location is compromised, the attacker cannot directly restore the complete data.
[0124] Specifically, the first encrypted data is stored in a local storage unit of the smart cash box, such as a non-volatile memory, to ensure that part of the data can be retained even if the connection with the server is disconnected. The second encrypted data and the verification data are sent to the server through the established communication link. When sending, the TLS protocol can be used to encrypt the transmission data to prevent interception. After receiving the second encrypted data and the verification data, the server stores them in a database or a distributed storage system, and marks them as associated with the identification of the smart cash box. At this point, the encryption process is completed, and the private data is distributed and stored on both ends of the smart cash box and the server.
[0125] In this embodiment, digital certificates and zero-knowledge verification are used to prevent forged devices from accessing. Session key encryption is used to ensure a secure communication environment and prevent data from being eavesdropped or tampered with. Data integrity verification is used to ensure data security, and data splitting storage is used to reduce the impact of data leakage and avoid single-point leakage, thereby enhancing the security and anti-attack ability of the intelligent cash box.
[0126] Please refer to Figure 2a and Figure 2b , another embodiment of the intelligent cash box encryption method based on digital certificates is provided in the embodiment of the present application. This embodiment includes:
[0127] S201. Start the intelligent cash box and verify the legitimacy of the digital certificate of the intelligent cash box device;
[0128] S202. When the digital certificate is verified, establish a communication link between the intelligent cash box and the server, and generate a session key, where the session key is a temporary symmetric key generated according to the communication link;
[0129] Steps S201 to S202 in this embodiment are similar to steps S101 to S102 in the foregoing embodiment, and will not be elaborated here specifically.
[0130] S203. Store the session key in the security module and / or trusted execution environment of the intelligent cash box;
[0131] After the intelligent cash box and the server establish secure communication and generate a session key, the system will store the key in the security module or trusted execution environment of the intelligent cash box. This measure can protect the session key from being stolen or tampered with, avoid the security risks brought by key leakage, and ensure the encryption security of data during transmission and storage.
[0132] Specifically, after the session key is generated through the communication link between the intelligent cash box and the server in step S202, it needs to be securely stored to prevent leakage. The intelligent cash box stores the session key in its security module (such as a hardware security module HSM) or trusted execution environment (TEE, such as ARM TrustZone or Intel SGX). Specifically, if a security module is used, the session key is stored in an encrypted form in a dedicated chip and protected by physical isolation and access control; if a TEE is used, the session key is stored in an isolated execution environment and protected from unauthorized access through memory encryption and runtime isolation. When storing, a timestamp or session identifier can be added to the session key for subsequent management or replacement.
[0133] S204. Control the intelligent box and the server to establish a connection according to a preset period and / or a preset communication data volume, and obtain a new session key to replace the session key.
[0134] To prevent potential security risks caused by using the same key for a long time, the system will trigger the connection between the intelligent box and the server according to a preset period (such as every once in a while) or a preset communication data volume (such as encrypted data reaching a certain size), obtain a new session key, and replace the old key.
[0135] Specifically, the preset period can be a time period, for example, triggering key update every 24 hours; the preset communication data volume can be a cumulative transmission data threshold, for example, triggering update when reaching 10MB. In addition, when a security event is triggered, such as detecting abnormal access, unauthorized attempts, or suspicious communication, the server and the intelligent box will force key update. When the above conditions are met, the intelligent box initiates a connection request to the server, renegotiates communication parameters through the TLS protocol, and generates a new session key. After the new key is generated, it replaces the old key stored in the security module or TEE, and the old key is securely erased (such as by overwriting with zero values) to ensure that it cannot be recovered for use.
[0136] It should be noted that in the actual usage scenario, the latest key version number is recorded through the blockchain to ensure that all devices can be correctly synchronized. If the key update fails, the current key is retained and updated again during the next session.
[0137] S205. Perform two-way authentication on the intelligent box and the server through a zero-knowledge authentication method;
[0138] S206. When the authentication is passed, control the intelligent box to encrypt its own stored data through the session key to obtain private data;
[0139] S207. Generate verification data for the private data according to the data of the intelligent box, and the verification data is used to verify the legality and integrity of the private data;
[0140] S208. Split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0141] S209. Store the first encrypted data in the intelligent box, send the second encrypted data and the verification data to the server, and store the second encrypted data through the server to complete encryption;
[0142] Steps S204 to S209 in this embodiment are similar to steps S103 to S107 in the foregoing embodiment, and will not be elaborated here specifically.
[0143] S210. When the intelligent locker receives an opening instruction, it controls the intelligent locker to obtain the second encrypted data and the verification data from the server.
[0144] The intelligent locker is temporarily stored in the RAM to prevent data leakage. After receiving the opening instruction, the intelligent locker requests the server to obtain the second encrypted data and the verification data.
[0145] Specifically, the opening instruction is triggered by user input or a remote control signal, and the decryption and opening process is started when triggered. After the server returns the data, the intelligent locker sends a request message with the device identifier using a pre-established TLS connection. The server retrieves the corresponding second encrypted data and verification data from the database according to the identifier and returns them through an encrypted channel. After receiving them, the intelligent locker temporarily stores the second encrypted data and the verification data in the memory for subsequent processing.
[0146] S211. Obtain the first hash value of the second encrypted data calculated by the server, and calculate the second hash value of the second encrypted data by the intelligent locker.
[0147] The server calculates the first hash value of the second encrypted data, stores it, and returns it to the intelligent locker. The intelligent locker calculates the second hash value using the same hash algorithm.
[0148] Specifically, to verify the integrity of the second encrypted data during transmission, the intelligent locker obtains the first hash value calculated by the server. The first hash value is calculated by the server using the SHA-256 algorithm when storing the second encrypted data and is returned together with the second encrypted data. At the same time, the intelligent locker performs local calculation on the received second encrypted data to generate the second hash value, also using the SHA-256 algorithm. The calculation process ensures that the input data is consistent, for example, performing a hash operation on the complete byte sequence of the second encrypted data, and the result is a hash value with a fixed length of 256 bits.
[0149] S212. When the first hash value and the second hash value are the same, determine that the second encrypted data is secure data, so that the intelligent locker recombines the private data through the first encrypted data and the second encrypted data.
[0150] Specifically, when the first hash value is equal to the second hash value, the data has not been tampered with, and the data is merged; when the first hash value is not equal to the second hash value, the data may have been tampered with, the decryption is rejected, and an alarm message is sent to the server.
[0151] S213. Recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rules.
[0152] According to the preset rules used in step S208, the first encrypted data and the second encrypted data are recombined into complete private data. Specifically, if the preset rule is proportional segmentation (for example, the first encrypted data is the first 50% and the second encrypted data is the last 50%), the first encrypted data and the second encrypted data are merged in sequence by byte splicing; if the rule is based on content features, they are recombined according to the predefined segmentation identifier. After recombination, the length and content of the private data should be the same as those of the private data during encryption, generating complete ciphertext data for subsequent verification and decryption.
[0153] S214. When the encryption method is a symmetric encryption algorithm with integrity protection, obtain the verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key;
[0154] The encryption method is a symmetric encryption algorithm with integrity protection (such as AES-GCM, AES-CCM), and the verification data contains the verification Tag. The intelligent safe extracts the verification Tag from the verification data. The verification Tag is generated by the session key and the private data during encryption. The verification process is as follows: Use the session key stored in the security module or TEE and the recombined private data to verify whether the obtained verification Tag matches through the AES-GCM algorithm. That is, calculate the authentication value of the recombined private data and compare it with the obtained verification Tag. If they are consistent, the integrity of the recombined private data passes; if they are inconsistent, the verification fails.
[0155] S215. When the encryption method is a digital signature algorithm, obtain the digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0156] If the encryption method is a digital signature algorithm (such as RSA / ECDSA digital signature), verify the digital signature through the public key of the intelligent safe to ensure that the data has not been tampered with.
[0157] Specifically, the verification data contains the digital signature. The intelligent safe extracts the digital signature from the verification data. The digital signature is generated by signing the hash value of the private data with the private key. The verification process is as follows: Use the public key of the intelligent safe to decrypt the digital signature to obtain the hash value H1, calculate the hash value H2 of the recombined private data (such as SHA-256), and compare H1 and H2. If they are equal, it is confirmed that the recombined private data is complete and the source is legal; if they are not equal, the verification fails.
[0158] S216. If the verification data passes the verification, use the session key to decrypt the private data to obtain the original stored data of the intelligent safe;
[0159] When the verification of S214 or S215 passes, the intelligent safe uses the session key to decrypt the private data. If it is AES-GCM, since the Tag verification has been passed before decryption, directly use the session key and the initialization vector to perform AES-GCM decryption to obtain the original stored data; if it is ordinary symmetric encryption (such as AES-CBC), then use the session key and the initialization vector to decrypt the private data. The original stored data after decryption is the transaction record or status data of the intelligent safe, which is restored to plaintext form.
[0160] S217. According to the opening instruction, control the intelligent safe to perform an opening operation.
[0161] After successful decryption, perform a physical operation according to the opening instruction, such as unlocking the mechanical lock or electronic lock of the intelligent safe to allow the user to access the items stored inside. Specifically, the controller of the intelligent safe receives the decrypted data and verifies whether it contains opening permission information (such as a specific command code). If it meets the requirements, drive the actuator to complete the opening. If the data is abnormal or the permission is insufficient, keep the locked state and record a log.
[0162] In this embodiment, through the secure storage and dynamic update of the session key, the integrity verification of the second encrypted data, the recombination and verification of the private data, and the decryption and opening operations, high-security processing of the intelligent safe data is achieved. The protection and timeliness of the session key are enhanced, and the integrity and legality of the data are ensured through multi-level verification (hash comparison, Tag or signature verification), and finally the opening operation is safely executed. This implementation is applicable to scenarios that require regular key updates and strict verification of data integrity.
[0163] Please refer to Figure 3 , another embodiment of the intelligent safe encryption method based on digital certificates is provided in the embodiment of the present application. This embodiment includes:
[0164] S301. Start the intelligent safe and obtain the number of devices of all intelligent safes in the collaborative network;
[0165] When the intelligent safe starts, first initialize its hardware and communication module, and then detect the presence of other intelligent safe devices in the network through a collaborative network (such as a local area network or an Internet of Things protocol). Specifically, the intelligent safe broadcasts a device discovery message (such as a multicast message based on UDP) and receives responses from other devices. For each valid response received, the counter is incremented by 1, and finally the number of devices N of all intelligent safes in the collaborative network is obtained. The number of devices reflects the total number of active intelligent safes in the current network. For example, N may be 1 (only itself) or greater than 1 (including other devices).
[0166] S302. When the number of devices is 1, locally verify the digital certificate of the intelligent safe to obtain a verification result;
[0167] When the detected number of devices N is equal to 1, it means that only the current intelligent box is running in the network and no collaborative verification is required. The intelligent box performs local digital certificate verification: reads the digital certificate from its internal memory or security module, and the certificate is issued by a trusted Certificate Authority (CA) and contains the public key and identity identifier. The verification process includes checking the certificate signature (using the CA public key), validity period, and whether it is in the locally stored Certificate Revocation List (CRL). If the certificate passes all checks, the verification is successful; if the local certificate verification fails, it tries to request the nearest trusted server or device for auxiliary verification until it is confirmed that the verification cannot be completed, generates an exception, and records a log.
[0168] S303. When the number of devices is not 1, execute a voting mechanism based on the blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent box and obtain a verification result;
[0169] When the number of devices N is greater than 1, other intelligent boxes in the collaborative network participate in the verification process, using a blockchain-based consensus algorithm (such as the Practical Byzantine Fault Tolerance algorithm PBFT). Specifically, the current intelligent box (denoted as node A) broadcasts its digital certificate to the other N - 1 nodes in the network. Each node verifies the legality of the certificate (checks the signature, validity period, etc.) and generates a voting result (pass or fail). The votes are collected through broadcasting, and all nodes execute PBFT consensus: if more than 2 / 3 of the nodes (i.e., (N - 1) / 3 + 1) vote pass, the consensus result is verification pass; otherwise, it is fail. The final result is recorded as a boolean value and returned to node A as the verification result.
[0170] Specifically, for the verification result obtained in step S302 or S303, when the verification result directly passes, execute step S309; when the verification result fails, execute step S304.
[0171] S304. When the verification result is fail, reject the establishment of a communication link between the intelligent box and the server and generate an alarm feedback.
[0172] If the verification result of step S302 or S303 fails, the intelligent box refuses to establish a communication link with the server. Specifically, the communication module of the intelligent box terminates the TLS handshake request and marks the status as "verification failed". At the same time, generate an alarm feedback: construct an alarm message containing the timestamp, device identifier, and failure reason (such as "certificate expired" or "consensus not passed"), and record or report it through a predefined channel (such as local log or sending to the management terminal) to ensure that the exception is traceable.
[0173] S305. Input the verification result into the artificial intelligence-based memory model of the intelligent trunk, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result;
[0174] Regardless of whether the verification result is passed or not, the verification result is input into the memory model through artificial intelligence for analysis. The memory model can be a classification model based on machine learning (such as Naive Bayes or neural network), which is pre-trained to identify patterns of communication behavior. The input data includes the verification result (boolean value), verification time, and context information (such as the number of network devices). The model analyzes the communication behavior corresponding to the verification result, such as the frequency or time distribution of verification failures, and outputs an analysis result. The analysis result may be a class label (such as "normal", "suspicious") or an anomaly probability value (for example, 0.8 indicates an 80% probability of anomaly).
[0175] Specifically, when the intelligent trunk refuses to establish a communication link with the server and generates an alarm feedback, the verification result (such as "verification failed") will be input into the artificial intelligence-based memory model built in the intelligent trunk. The memory model uses advanced deep learning technologies, such as Recurrent Neural Network (RNN) or Long Short-Term Memory Network (LSTM), to effectively process the time-series data of communication behavior. The input data of the model includes but is not limited to the following features: Verification result: such as the status of "verification failed". Timestamp: The time when the verification occurred. Communication frequency: The number of communication attempts per unit time. Historical communication records: Communication behavior data in the past period. By analyzing these input data, the memory model can capture the time-series characteristics and potential patterns of communication behavior, such as abnormal verification failure frequency or abnormal communication attempt intervals. After the analysis is completed, the model outputs an analysis result, which may be one of the following forms: Classification label: such as "high-risk attempt", "device failure suspected". Anomaly probability score: such as 0.85 (indicating an 85% probability of abnormal behavior).
[0176] S306. Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior;
[0177] Parse the analysis result of step S305 to identify abnormal behavior. Specifically, if the analysis result is "suspicious" or the anomaly probability exceeds a preset threshold (such as 0.7), abnormal features are extracted, such as "continuous multiple verification failures" or "abnormal concentration of verification time". The intelligent trunk queries the locally stored processing strategy table according to the abnormal behavior. The table predefines the mapping relationship between abnormal types and processing methods. For example, if the anomaly is "multiple verification failures", the corresponding processing method may be "suspend communication attempts for 10 minutes"; if there is no matching item, go to the next step. The processing method is recorded in the form of text or instructions.
[0178] Specifically, after obtaining the analysis result of S305, the intelligent suitcase inputs the analysis result into artificial intelligence to further analyze the abnormal behavior therein by using artificial intelligence technology. Specifically, artificial intelligence uses technologies such as natural language processing (NLP) or decision trees to extract key abnormal behavior features from the analysis result. For example: "5 consecutive verification failures"; "multiple attempts to communicate during non-working hours". Subsequently, the intelligent suitcase dynamically generates or selects corresponding processing methods according to the extracted abnormal behavior features through an AI-driven decision engine. The decision engine can be one of the following two forms: Rule-based expert system: Preset the mapping relationship between rules and abnormal behaviors. Reinforcement learning model: Dynamically optimize the processing strategy according to historical data and real-time feedback. For example: If the abnormal behavior is "high-frequency verification failure", the decision engine may output the processing method as "temporarily lock the device for 30 minutes". If the abnormal behavior is "suspected device failure", then "initiate device self-check" is output. The processing method is output in the form of instructions or policy descriptions.
[0179] S307. If the processing method is successfully obtained, add a processing label to the verification result;
[0180] If the processing method is successfully obtained in step S306, the intelligent suitcase adds a processing label to the verification result. The label is additional metadata, such as "suspend communication for 10 minutes" or "require manual review", and is stored in the local memory or log bound to the verification result. Specifically, the verification result is updated to structured data (such as JSON format), including the original result (passed / failed) and the processing label. After adding the label, the intelligent suitcase performs corresponding operations according to the label, such as suspending the activities of the communication module.
[0181] It should be noted that if the abnormal behavior affects communication security (such as too many certificate verification failures), the device communication is immediately blocked; if the abnormal behavior affects device performance (such as frequent key update failures), delayed processing is performed and a warning message is sent.
[0182] S308. If the processing method is not obtained, retain the verification failure status of the verification result.
[0183] If no matching processing method is found in step S306, the intelligent suitcase retains the "verification failed" status of the verification result and does not perform additional processing. Specifically, the verification result remains as the boolean value "False", without attaching a label, and the intelligent suitcase maintains the state of rejecting communication. At the same time, this situation is recorded in the exception log, and the log entry includes the timestamp, device identifier, and a description of "no processing method found" for subsequent analysis or manual intervention.
[0184] S309. When the digital certificate is verified successfully, establish a communication link between the intelligent cash box and the server, and generate a session key, which is a temporary symmetric key generated based on the communication link;
[0185] S310. Perform two-way authentication on the intelligent cash box and the server through a zero-knowledge authentication method;
[0186] S311. When the authentication is passed, control the intelligent cash box to encrypt its own stored data with the session key to obtain private data;
[0187] S312. Generate verification data for the private data according to the data of the intelligent cash box, and the verification data is used to verify the legality and integrity of the private data;
[0188] S313. Split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0189] S314. Store the first encrypted data in the intelligent cash box, send the second encrypted data and the verification data to the server, and store the second encrypted data in the server through the server to complete the encryption.
[0190] Steps S309 to S314 in this embodiment are similar to steps S102 to S107 in the foregoing embodiment, and will not be elaborated here specifically.
[0191] Specifically, in this embodiment, through collaborative network device quantity detection, local or blockchain consensus verification of digital certificates, exception handling and feedback, and communication behavior analysis based on a memory model, dynamic verification and exception response of the digital certificate of the intelligent cash box are realized. A flexible verification mechanism is provided, which adapts to single-device and multi-device scenarios and enhances the adaptive ability of the system through analysis and processing. This implementation is applicable to an intelligent cash box network environment that requires high reliability and collaborative verification.
[0192] The above has described in detail the intelligent cash box encryption method based on digital certificates in the embodiments of the present application. Next, the intelligent cash box encryption system and device based on digital certificates will be described in detail.
[0193] Please refer to Figure 4 , an embodiment of the intelligent cash box encryption system based on digital certificates is provided in the embodiments of the present application, and this embodiment includes:
[0194] A first verification unit 401, which is used to start the intelligent cash box and verify the legality of the digital certificate of the intelligent cash box device;
[0195] A first establishment unit 402, configured to establish a communication link between the intelligent safe and the server and generate a session key when the digital certificate passes the verification, where the session key is a temporary symmetric key generated according to the communication link;
[0196] A second verification unit 403, configured to perform two-way authentication on the intelligent safe and the server by using a zero-knowledge authentication method;
[0197] An encryption unit 404, configured to, when the authentication passes, control the intelligent safe to encrypt its own stored data by using the session key to obtain private data;
[0198] A generation unit 405, configured to generate verification data for the private data according to the data of the intelligent safe, where the verification data is used to verify the legality and integrity of the private data;
[0199] A splitting unit 406, configured to split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0200] A first storage unit 407, configured to store the first encrypted data in the intelligent safe, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete the encryption.
[0201] In this embodiment, the functions of each unit correspond to the steps in the foregoing Figure 1 illustrated embodiment, and will not be elaborated here.
[0202] Please refer to Figure 5 , another embodiment of the intelligent safe encryption system based on a digital certificate is provided in an embodiment of the present application. This embodiment includes:
[0203] A first verification unit 501, configured to start the intelligent safe and verify the legality of the digital certificate of the intelligent safe device;
[0204] A first establishment unit 502, configured to establish a communication link between the intelligent safe and the server and generate a session key when the digital certificate passes the verification, where the session key is a temporary symmetric key generated according to the communication link;
[0205] A second storage unit 503, configured to store the session key in the security module and / or trusted execution environment of the intelligent safe;
[0206] A second establishment unit 504, configured to control the intelligent safe and the server to establish a connection according to a preset period and / or preset communication data volume, and obtain a new session key to replace the session key.
[0207] The second verification unit 505 is configured to perform bidirectional authentication on the intelligent safe and the server by using a zero-knowledge authentication method;
[0208] The encryption unit 506 is configured to, when the authentication is passed, control the intelligent safe to encrypt its own stored data by using the session key to obtain private data;
[0209] The generation unit 507 is configured to generate verification data for the private data according to the data of the intelligent safe, and the verification data is used to verify the legality and integrity of the private data;
[0210] The splitting unit 508 is configured to split the private data according to a preset rule to obtain first encrypted data and second encrypted data;
[0211] The first storage unit 509 is configured to store the first encrypted data in the intelligent safe, send the second encrypted data and the verification data to the server, and store the second encrypted data by the server to complete encryption.
[0212] The first acquisition unit 510 is configured to, when the intelligent safe receives an opening instruction, control the intelligent safe to acquire the second encrypted data and the verification data from the server;
[0213] The second acquisition unit 511 is configured to acquire a first hash value of the second encrypted data calculated by the server, and calculate a second hash value of the second encrypted data by the intelligent safe;
[0214] The determination unit 512 is configured to, when the first hash value is consistent with the second hash value, determine that the second encrypted data is secure data, so that the intelligent safe recombines the private data by using the first encrypted data and the second encrypted data.
[0215] The recombination unit 513 is configured to recombine the first encrypted data and the second encrypted data into the complete private data according to the preset rule;
[0216] The third verification unit 514 is configured to verify the legality and integrity of the verification data;
[0217] The decryption unit 515 is configured to, if the verification data passes the verification, decrypt the private data by using the session key to obtain the original stored data of the intelligent safe;
[0218] The execution unit 516 is configured to control the intelligent safe to perform an opening operation according to the opening instruction.
[0219] In this embodiment, the third verification unit 514 is specifically configured to:
[0220] When the encryption method is a symmetric encryption algorithm with integrity protection, obtain a verification Tag from the verification data, and verify the integrity of the private data through the verification Tag and the session key;
[0221] When the encryption method is a digital signature algorithm, obtain a digital signature from the verification data, and verify the integrity of the digital signature through the public key of the intelligent safe.
[0222] In this embodiment, the first verification unit 501 is specifically configured to:
[0223] Obtain the number of devices of all intelligent safes in the collaborative network;
[0224] When the number of devices is 1, locally verify the digital certificate of the intelligent safe to obtain a verification result;
[0225] When the number of devices is not 1, execute a voting mechanism based on a blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent safe to obtain a verification result;
[0226] When the verification result is not passed, reject the intelligent safe and the server from establishing a communication link, and generate an alarm feedback.
[0227] In this embodiment, the first verification unit 501 is further specifically configured to:
[0228] Input the verification result into the artificial intelligence-based memory model of the intelligent safe, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result;
[0229] Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior;
[0230] If the processing method is successfully obtained, add a processing label to the verification result;
[0231] If the processing method fails to be obtained, retain the verification failure status of the verification result.
[0232] In this embodiment, the functions of each unit correspond to the steps in the foregoing Figure 2a 、 Figure 2b and Figure 3 The embodiments shown are not described herein again.
[0233] Please refer to Figure 6 This application embodiment provides another embodiment of an intelligent safe encryption device based on a digital certificate, including:
[0234] A processor 601, a memory 602, an input / output unit 603, and a bus 604;
[0235] The processor 601 is connected to the memory 602, the input / output unit 603, and the bus 604;
[0236] The processor 601 specifically executes Figures 1 to 3 the operations corresponding to the steps in the method, which will not be elaborated here specifically.
[0237] This application also relates to a computer-readable storage medium, on which a program is stored. It is characterized in that when the program runs on a computer, it causes the computer to execute any of the above methods.
[0238] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0239] In several embodiments provided by this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0240] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0241] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0242] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical discs.
Claims
1. An intelligent cash box encryption method based on digital certificates, characterized in that, The method includes: Starting the intelligent cash box and verifying the legality of the digital certificate of the intelligent cash box device; When the digital certificate is verified, establishing a communication link between the intelligent cash box and the server and generating a session key, where the session key is a temporary symmetric key generated according to the communication link; Performing two-way authentication on the intelligent cash box and the server through a zero-knowledge authentication method; When the authentication is passed, controlling the intelligent cash box to encrypt its own stored data through the session key to obtain private data; Generating verification data for the private data according to the data of the intelligent cash box, where the verification data is used to verify the legality and integrity of the private data; Splitting the private data according to a preset rule to obtain first encrypted data and second encrypted data; Storing the first encrypted data in the intelligent cash box, sending the second encrypted data and the verification data to the server, and storing the second encrypted data through the server to complete the encryption.
2. The method according to claim 1, characterized in that, After storing the first encrypted data in the intelligent cash box, sending the second encrypted data and the verification data to the server, and storing the second encrypted data through the server to complete the encryption, the method further includes: When the intelligent cash box receives an opening instruction, controlling the intelligent cash box to obtain the second encrypted data and the verification data from the server; Recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rule; Verifying the legality and integrity of the verification data; If the verification data is verified, decrypting the private data using the session key to obtain the original stored data of the intelligent cash box; Controlling the intelligent cash box to perform an opening operation according to the opening instruction.
3. The method according to claim 2, wherein The verifying the legality and integrity of the verification data includes: When the encryption method is a symmetric encryption algorithm with integrity protection, obtaining a verification Tag from the verification data and verifying the integrity of the private data through the verification Tag and the session key; When the encryption method is a digital signature algorithm, obtaining a digital signature from the verification data and verifying the integrity of the digital signature through the public key of the intelligent cash box.
4. The method according to claim 2, wherein Before recombining the first encrypted data and the second encrypted data into the complete private data according to the preset rule, the method further includes: Obtaining a first hash value of the second encrypted data calculated by the server and calculating a second hash value of the second encrypted data by the intelligent cash box; When the first hash value and the second hash value are the same, determining that the second encrypted data is secure data, so that the intelligent cash box recombines the private data through the first encrypted data and the second encrypted data.
5. The method according to any one of claims 1 to 4, characterized in that, After verifying the digital certificate, establishing a communication link between the intelligent cash box and the server, and generating a session key, the method further includes: Store the session key in the security module and / or trusted execution environment of the intelligent cash box; Control the intelligent cash box and the server to establish a connection according to a preset period and / or preset communication data volume, obtain a new session key, and replace the session key.
6. The method according to any one of claims 1 to 4, characterized in that, The verification of the legality of the digital certificate of the intelligent cash box device includes: Obtain the number of devices of all intelligent cash boxes in the collaborative network; When the number of devices is 1, locally verify the digital certificate of the intelligent cash box to obtain a verification result; When the number of devices is not 1, execute a voting mechanism based on the blockchain consensus algorithm through other devices to verify the digital certificate of the intelligent cash box to obtain a verification result; When the verification result is not passed, reject the establishment of a communication link between the intelligent cash box and the server, and generate an alarm feedback.
7. The method according to claim 6, characterized in that, After rejecting the establishment of a communication link between the intelligent cash box and the server and generating an alarm feedback, the method further includes: Input the verification result into the artificial intelligence-based memory model of the intelligent cash box, and analyze the communication behavior corresponding to the verification result through the memory model to obtain an analysis result; Parse the abnormal behavior in the analysis result through the artificial intelligence, and obtain the corresponding processing method according to the abnormal behavior; If the processing method is successfully obtained, add a processing label to the verification result; If the processing method fails to be obtained, retain the verification failure status of the verification result.
8. An intelligent cashbox encryption system based on digital certificates, characterized in that, The system includes: A first verification unit for starting the intelligent cash box and verifying the legality of the digital certificate of the intelligent cash box device; A establishing unit for establishing a communication link between the intelligent cash box and the server and generating a session key when the digital certificate is verified, where the session key is a temporary symmetric key generated according to the communication link; A second verification unit for performing two-way authentication on the intelligent cash box and the server through a zero-knowledge identity authentication method; An encryption unit for controlling the intelligent cash box to encrypt its own stored data through the session key to obtain private data when the authentication is passed; A generating unit for generating verification data of the private data according to the data of the intelligent cash box, where the verification data is used to verify the legality and integrity of the private data; A splitting unit for splitting the private data according to a preset rule to obtain first encrypted data and second encrypted data; A storage unit for storing the first encrypted data in the intelligent cash box, sending the second encrypted data and the verification data to the server, and storing the second encrypted data by the server to complete encryption.
9. An intelligent cash box encryption device based on digital certificates, characterized in that, The device includes: A processor, a memory, an input / output unit, and a bus; The processor is connected to the memory, the input / output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a program stored thereon, the program, when executed on a computer, performing the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Smart contract authentication data privacy protection method based on zero knowledge proof
CN109614820A
Bank entity management method and device and computer readable storage medium
CN116091190A