Intelligent POS terminal system and secure payment method thereof
Through the system architecture of Android-Linux+Protected VM (AVF)+Trust Zone+SE, the problem of the difficulty of intelligent POS terminal systems passing GMS and PCI PTS authentication at the same time is solved, and the security and flexibility are improved, and are suitable for intelligent POS terminal systems.
Patent Information
- Application Number
- CN202510336924.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-08
AI Technical Summary
The existing smart POS terminal system is difficult to pass GMS and PCI PTS certification at the same time, resulting in limited security and flexibility.
The system architecture adopts Android-Linux+Protected VM (AVF)+Trust Zone+SE, and divides the system into a secure world and a non-secure world. The secure world includes TEE module and SE module. The non-secure world includes REE module. The security-related services are performed through the Protected VM module. The TEE module renders the security interface, and the SE module executes security algorithms to ensure security; the REE module in the non-secure world executes non-confidential business logic and retains the functions of the native system.
It has achieved GMS and PCI PTS certification at the same time, ensuring the security and flexibility of the intelligent POS terminal system, avoiding the transformation of Android native systems, and improving development efficiency and market competitiveness.
Smart Images

Figure CN120279639A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent payment terminals, and in particular, to an intelligent POS terminal system and a secure payment method thereof. Background Art
[0002] With the rapid development of mobile payment and intelligent devices, intelligent POS terminal systems are increasingly widely used in fields such as retail, catering, and finance. An intelligent POS terminal system not only needs to support multiple payment methods (such as bank cards, QR code payment, etc.), but also needs to meet the high security requirements of the payment industry. Currently, intelligent POS terminal systems are usually built based on the Android-Linux operating system, and with its rich application ecosystem and mature development framework, diverse payment functions can be quickly realized.
[0003] Researchers have found that most intelligent POS terminals on the market currently pass the PCI PTS certification. However, the PCI PTS certification has relatively high security requirements for POS terminals. In order to meet the security requirements, many device manufacturers modify some native Android functions, such as trimming ADB instructions, modifying the APK signature and verification mechanism, etc. These modifications will result in failure to pass the GMS certification, making it impossible for intelligent POS terminals to pass the GMS + PCI PTS certification simultaneously. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: The present invention provides an intelligent POS terminal system and a secure payment method thereof to solve the problem that it is relatively difficult for existing intelligent POS terminal systems to pass the GMS + PCI PTS certification simultaneously.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is: An intelligent POS terminal system, which includes a secure world module and a non-secure world module. The non-secure world module includes an REE module, and the REE module is used to execute non-confidential business logic and render non-security-related interfaces; the secure world module includes a TEE module, a Protected VM module, and an SE module. The TEE module is used to render security-related interfaces, the Protected VM module is used to execute the first security service that does not involve rendering security-related interfaces, and the SE module is used to execute the second security service; wherein, the REE module is respectively communicatively connected with the Protected VM module and the TEE module, and the TEE module is communicatively connected with the SE module.
[0006] Further, in the intelligent POS terminal system of the present invention, the REE module includes a first application module and an application program module, and the first application module is communicatively connected to the application program module and the Protected VM module respectively.
[0007] Further, in the intelligent POS terminal system of the present invention, the first application module includes a system service module, an AIDL service module, and a client application module. The system service module is communicatively connected to the AIDL service module and the Protected VM module respectively, and the client application module is communicatively connected to the AIDL service module and the TEE module respectively.
[0008] Further, in the intelligent POS terminal system of the present invention, the Protected VM module includes a second application module. The second application module is communicatively connected to the system service module, and the second application module is used to execute a first security service that does not involve rendering a security-related interface display.
[0009] Further, in the intelligent POS terminal system of the present invention, the TEE module includes a Trusty OS module, a trusted application program module, and a Trusted UI module. The Trusty OS module is communicatively connected to the SE module, and the trusted application program module is communicatively connected to the client application module.
[0010] Further, in the intelligent POS terminal system of the present invention, it further includes a security monitor module, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
[0011] Correspondingly, the present invention also provides a secure payment method for an intelligent POS terminal system, which is applied to the intelligent POS terminal system as described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the TEE module pops up a PIN code input interface; S2: The TEE module receives the PIN code input by the user on the PIN code input interface and sends the PIN code to the SE module; S3: The SE module encrypts the PIN code and transmits the encrypted PIN code to the bank card; S4: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program; S5: The payment program determines whether to complete the payment transaction according to the authorization result.
[0012] Furthermore, in the secure payment method of the present invention, in step S1, the TEE module pops up a PIN input interface, including: After receiving the request from the payment program to call the trusted application module, the TEE module loads the trusted application file of the trusted application module into the memory of the Trusty OS module; The Trusty OS module starts the trusted application module based on the trusted application file; The trusted application module starts the Trusted UI module to render and display the PIN input interface based on the Trusted UI module.
[0013] Furthermore, in the secure payment method of the present invention, in step S4, decrypting and verifying the encrypted PIN code to obtain an authorization result, including: Performing a verification operation on the decrypted PIN code to obtain a verification result; if the verification result is verification passed, it is determined that the authorization result is authorized payment; if the verification result is not passed, it is determined that the authorization result is unauthorized payment.
[0014] Furthermore, in the secure payment method of the present invention, the method further includes: In the case where the authorization results of the PIN code continuously exceed the preset number of times and are all unauthorized payments, an automatic locking operation is performed on the bank card.
[0015] The beneficial effects of the present invention are as follows: The present invention provides an intelligent POS terminal system that simultaneously supports GMS+PCI PTS authentication. Through the comprehensive mechanism of Android-Linux+Protected VM (AVF)+Trust Zone+SE, it can effectively ensure the security and flexibility of the intelligent POS terminal system; (1) For the services related to security, the present invention is implemented through a security environment (i.e., Protected VM module + TEE module + SE module). Specifically: the Microdroid module in the Protected VM module executes the first security service (such as interface call authentication, signature verification for application installation), and the SE module executes the second security service (such as PIN input / encryption, security algorithms). In addition, since the Microdroid module in the above-mentioned Protected VM module does not support interfaces, the present invention implements security-related interfaces such as the PIN input interface in the TEE module. In summary, the services related to security of the present invention can be implemented based on the security environment (i.e., Protected VM module + TEE module + SE module), so as to ensure the security requirements of the intelligent POS terminal system and successfully pass the PCI PTS certification without modifying some native Android functions; (2) For the non-security-related part, in the present invention, the non-secure world mainly refers to the native Google Android-Linux system, which executes non-confidential business logic and renders non-security-related interfaces through the applications in the REE module. Since the architecture of the present invention based on the Protected VM module + TEE module + SE module can ensure the security requirements of the intelligent POS terminal system, the present invention can achieve minimal modification to the native Android system. For example, it retains the native ADB (without trimming instructions), retains the original APK signature and signature verification mechanism, etc., so as to achieve passing the GMS certification. In summary, based on the Android-Linux + Protected VM (AVF) + Trust Zone + SE system architecture, the present invention can effectively support GMS + PCI PTS certification. Description of the Drawings
[0016] Figure 1 It is a system architecture diagram of the intelligent POS terminal system according to the present invention in an embodiment.
[0017] Figure 2 It is another system architecture diagram of the intelligent POS terminal system according to the present invention in an embodiment.
[0018] Figure 3 It is a step flowchart of the secure payment method of the intelligent POS terminal system according to the present invention in an embodiment. Detailed Embodiment
[0019] To describe the technical content, achieved objectives and effects of the present invention in detail, the following is described in conjunction with embodiments and accompanied by drawings.
[0020] Researchers found that the system architecture of intelligent POS (Point of Sale) terminals can adopt the Android-Linux + Trust Zone + SE architecture. In this architecture: the intelligent POS terminal uses the Android-Linux operating system, which divides the system into two parts: the Secure World module and the Non Secure World module. Among them, the Non Secure World module mainly refers to the Google-native Android-Linux system; the Secure World module includes Trust Zone technology. However, in actual use, there are many defects in the above system architecture, such as: (1) Due to the security requirements of PCI PTS certification, in order to prevent malicious attacks, intelligent POS terminals generally perform instruction trimming on ADB, modify the signature and signature verification mechanism of APK. However, these practices are contrary to GMS certification. Therefore, it is difficult for intelligent POS terminals to pass GMS + PCI PTS certification simultaneously (unless using dual CPUs at the cost of sacrificing costs).
[0021] (2) The management of security-related matters such as intelligent POS terminal certificates and keys, terminal status, and lifecycle is achieved through TrustZone technology. And Trust Zone has certain disadvantages: ① Poor flexibility: Trust Zone can only run the same version of the Android system and application programs on the same platform; ② Low development efficiency: Trust Zone requires hardware configuration on the host system, resulting in low development efficiency. These disadvantages will bring certain difficulties to developers and increase the development and maintenance costs.
[0022] Therefore, please refer to Figure 1 and Figure 2 , the present invention provides an intelligent POS terminal system, which includes a Secure World module and a Non Secure World module. The Non Secure World module includes a REE module, and the REE module is used to execute non-confidential business logic and run (i.e., render) non-security-related interfaces; the Secure World module includes a TEE module, a ProtectedVM module, and an SE module. The TEE module is used to run (i.e., render) security-related interfaces, the Protected VM module is used to execute the first security service that does not involve rendering security-related interfaces, and the SE module is used to execute the second security service; among them, the REE module is respectively communicatively connected to the Protected VM module and the TEE module, and the TEE module is communicatively connected to the SE module (i.e., the SE chip module).
[0023] As can be seen from the above description, the beneficial effects of the present invention are as follows: The present invention provides an intelligent POS terminal system that simultaneously supports GMS+PCIPTS authentication. Through the comprehensive mechanism of Android-Linux+Protected VM (AVF)+Trust Zone+SE, it can effectively ensure the security and flexibility of the intelligent POS terminal system. Specifically: (1) For the security-related parts of the business, the present invention is implemented through a secure environment (i.e., the Protected VM module+TEE module+SE module). Specifically, the first security service (such as interface call authentication and signature verification for application installation) is executed through the Microdroid module in the Protected VM module, and the second security service (such as PIN input / encryption and security algorithms) is executed through the SE module. In addition, since the Microdroid module in the above Protected VM module does not support the interface, the present invention renders security-related interfaces such as the PIN input interface in the TEE module. To sum up, the security-related parts of the business of the present invention can be implemented based on a secure environment (i.e., the Protected VM module+TEE module+SE module), thereby ensuring the security requirements of the intelligent POS terminal system to successfully pass the PCI PTS authentication without the need to modify some native Android functions. (2) For the non-security-related parts, in the present invention, the non-secure world (i.e., the REE module) mainly refers to the native Android-Linux system of Google, which can be used to execute non-confidential business logic and render non-security-related interfaces. Since the architecture of the present invention based on the ProtectedVM module+TEE module+SE module can ensure the security requirements of the intelligent POS terminal system, the present invention can achieve minimal modification to the native Android system. For example, the native ADB (without cropping instructions) is retained, and the original APK signature and signature verification mechanism are retained, etc., so as to achieve GMS authentication. To sum up, based on the Android-Linux+Protected VM (AVF)+Trust Zone+SE system architecture, the present invention can effectively support GMS+PCI PTS authentication.
[0024] It should be noted that the GMS (Google Mobile Services Test Certification) is a certification system established by Google. This system aims to ensure that smart devices based on the Android system produced by global hardware manufacturers meet Google's standards in terms of compatibility, stability, and performance. Products that pass the GMS certification will obtain authorization to use Google services and related trademarks and can be displayed on Google's official website. The PCI PTS (Payment Card Industry PIN Transaction Security) certification is formulated by the PCI (Payment Card Industry PIN) Security Standards Council and aims to ensure the confidentiality and integrity of PIN data in payment card transactions. It is a security requirement for payment devices. Therefore, for a typical payment device such as a POS terminal, a series of security measures need to be taken, such as encrypting the transmission and storage of sensitive data, regularly updating and patching system vulnerabilities, restricting access permissions, etc., to ensure that payment data is not leaked or misused.
[0025] The intelligent POS terminal system described in the present invention uses the Android-Linux operating system; it divides the system into two parts: the Secure World module and the Non Secure World module. Among them, the Non Secure World module mainly refers to the native Android-Linux operating system of Google; the Secure World module mainly refers to the ProtectedVM (AVF) module, the TEE (Trusted Execution Environment) module, and the external SE (Secure Element) module. The following will elaborate on the above intelligent POS terminal system in combination with Figure 2 , and elaborate on the above intelligent POS terminal system in detail.
[0026] In the present invention, the non-secure world module is the REE module, and the REE (Rich Execution Environment) module is a non-trusted rich execution environment, which is an open environment vulnerable to attacks. For example, events such as theft of sensitive data and embezzlement of mobile payments often occur. In the present invention, the REE module is built based on the Android - Linux system. Compared with the existing intelligent POS terminal system architecture, the present invention tries not to modify the Android native system as much as possible to retain functions such as native ADB (non-trimmed instructions), the original APK signature and verification mechanism, so as to ensure that the intelligent POS terminal can pass the GMS certification, and further enable the intelligent POS terminal to obtain authorization to use Google services (such as Google Play, Gmail, Google Maps, etc.).
[0027] In practical applications, the REE module may include an Applications module, a framework framework, a system service module, an AIDL (Android Interface Definition Language) service module, a CA (Client Application) module, and components of device manufacturers (such as financial-related modules), etc. As Figure 1 and Figure 2 shown, the REE module includes an application program module running on Android (i.e., Figure 1 the Applications module in / 2) and a first application module (i.e., Figure 1 the services module in), etc. The application program module may be an upper-layer APP application program, and the application program module may call relevant interfaces of the system service module through binder or JNI. The first application module includes a system service module (i.e., Figure 2 the System service module in), an AIDL service module, and a CA module. Among them, the system service module is communicatively connected to the application program module and the SecureModules module respectively, and the system service module is communicatively connected to the AIDL service module through Binder; the AIDL service module is communicatively connected to the CA module.
[0028] It should be noted that the Android native treble mechanism involves the system domain and the vendor domain. Among them, the system service module refers to the system services in the system domain, while the AIDL service module refers to the system services in the vendor domain (generally referring to the implementation services related to hardware). The system service module calls the relevant interfaces of the AIDL service module through binder. In addition, in the present invention, the system service module is the system service in the non-secure world, while the Secure Modules module is the system service in the secure world. The system service module can call the interfaces of the Secure Modules module through binder.
[0029] The first application module is used to execute non-confidential business logic and display non-security-related interfaces. The non-security-related interfaces refer to the interfaces in the intelligent POS terminal that do not involve the processing of sensitive data and are used for interaction with users, that is, the non-security-related interfaces refer to the ordinary user interaction interfaces that are not security-related, such as: (1) System upgrade interface: used to prompt the user whether the device needs to be upgraded and display the upgrade progress, which does not involve the processing of sensitive data (such as PIN codes, keys, etc.). (2) Sign-in interface of the POS machine: used for merchants to sign in the device at the POS terminal, which does not involve the processing of highly sensitive data (such as PIN codes, payment card information, etc.). (3) Status display interface: used for the user to select the transaction type (such as consumption, refund, query, etc.), which only involves the selection of the transaction type and does not involve the processing of sensitive data. The non-confidential business logic refers to the business logic in the system that does not involve the processing of sensitive data, that is, the non-security-related business, such as controlling the on and off of the LED light, controlling the buzzer, managing the power state of the device (such as sleep, wake-up, etc.).
[0030] The non-security world module in the present invention is introduced above. The security world module in the present invention is specifically introduced below. The security world module includes a Protected VM (AVF) module, a TEE module, and an external SE (Secure Element) module, where: (1) The Protected VM module is a protected virtual machine. The Protected VM module includes a Microdroid module. The Microdroid module is a mini version of the Android OS running in the Protected VM (Virtual Machine). The main use case of the Protected VM module is not to run an independent operating system, but to provide an isolated execution environment. In the Microdroid module, it includes a second application module (i.e., the Secure Modules module), and the second application module is communicatively connected to the above-mentioned system service module through Binder.
[0031] (2)The TEE module refers to the Trusted Execution Environment, which refers to the Figure 1 Trust Zone part in
[0032] It should be noted that although Protected VM and Trust Zone are both security technologies of the Android system, their purposes and implementation methods are different. Trust Zone is a hardware-level security technology that provides a secure execution environment for running secure code. Protected VM is a resource management technology that provides a secure and private execution environment for executing code, which is very suitable for security-oriented use cases that require a higher security level than that provided by the Android application sandbox, or even formally verified isolation guarantees.
[0033] Although the TEE module has high security, due to its poor flexibility and low development efficiency, in order to improve development efficiency and flexibility, the present invention mainly executes the security-related business logic (i.e., the first security service) through the Microdroid module in the Protected VM module. However, since the Microdroid module does not support interfaces, for security-related interfaces such as the PIN input interface, they still need to be implemented in the Trusted UI module of the TEE module. That is, the present invention renders security-related interfaces through the TEE module to display security-related interfaces and ensure security.
[0034] It should be specifically pointed out that the first security service refers to some security-related business logics, such as interface call authentication, signature verification for application installation, etc. The security-related interfaces refer to user interfaces related to security for processing or displaying sensitive data, such as the PIN (Personal Identification Number) input interface, biometric (such as fingerprint, face recognition) identification interface, payment card information display interface.
[0035] In summary, the present invention avoids executing the first security service through the TEE module, but executes the first security service through the Microdroid module (i.e., the second application module) of the Protected VM module, which can effectively improve the development efficiency and make the intelligent POS terminal system of the present invention more flexible. Specifically, compared with the TEE module, the main advantages of the Protected VM module are as follows: (1) More flexible: The Protected VM module can run different versions of the Android system and application programs on different platforms. This enables the Protected VM module to meet a wider range of application requirements. (2) Higher development efficiency: The Protected VM module can create an independent development environment, facilitating developers to develop and test application programs, which can effectively improve the development efficiency.
[0036] (3) The SE (Secure Element) module is an external security component, which is mainly responsible for payment industry-related peripherals and security-related functions, that is, for executing the second security service. For example, functions such as IC card readers, magnetic stripe card readers, key management, PIN input and encryption, and security algorithms. It should be noted that the SE module has extremely high security. By executing the second security service with relatively high security requirements through the above SE module, such as key management (such as the storage of keys, which includes the storage of various keys such as non-financial-related keys and financial-related keys), certificate management (such as the storage of certificates, which includes the storage of various certificates such as non-financial-related certificates and financial-related certificates), and PIN input, it can significantly enhance payment security. The high security and high performance of the SE module enable the intelligent POS terminal to meet the high security requirements of the payment industry and improve the user experience and market competitiveness. The financial-related keys and financial-related certificates refer to the keys and certificates directly used in security mechanisms such as financial transactions, payment verification, and identity authentication that involve capital flows or the protection of sensitive financial data. The non-financial-related keys and non-financial-related certificates refer to the encryption keys and certificates used in non-capital transaction or non-sensitive financial data scenarios. In practical applications, the SE module and the Trusty OS module can interact through serial communication protocols such as SPI / I2C / UART.
[0037] It should be noted in particular that the first security services executed by the above Microdroid module are mainly security services designed by some POS manufacturers themselves. For example, the life cycle management service of the POS (managing the state of the POS, such as the manufacturing state, repair state, usage state, development mode, etc.), data collection service, unified response service (functions such as setting configuration items), authentication service (interface call authentication), etc. The second security services executed by the above SE module are mainly security services related to PIN codes, keys, etc., such as security services related to functions such as reading bank card information, PIN code input and encryption, and key management.
[0038] In summary, in the present invention, applications (such as modules related to finance such as printing, EMV, magnetic cards, IC cards, contactless cards, pinpads, etc.) are developed and packaged in the form of APK (Android Application Package Androi, application program package) or APEX format (AVF application) and stored in the terminal, thereby forming applications running on Android (i.e., the first application module) and applications running on Microdroid within the Protected VM (i.e., the second application module) respectively, and the first application module and the second application module can interact through binder. Generally speaking, the applications (the applications in the present invention refer to modules) in the present invention are divided into two parts. The applications running on Android are mainly used to implement rendering to form non-security-related interfaces and execute non-confidential business logics, and create and manage the life cycle of the Protected VM. The applications running on Microdroid within the Protected VM are responsible for executing tasks that need to be securely executed.
[0039] In addition, as Figure 1 shown, the intelligent POS terminal system further includes a security monitor module, and the security monitor module is used to manage the switching between the security world module and the non-security world module.
[0040] In practical applications, the security monitor module (i.e., Figure 1 the Secure Monitor module in ) can switch and trigger a response. Specifically, when the system has a need to enter the security world from the non-security world to execute security-sensitive tasks, Secure Monitor will respond to this request. For example, when a payment application needs to perform security operations such as PIN code verification, the payment application will send a switching request to Secure Monitor, requesting to switch to the security world for processing. At this time, Secure Monitor will start the switching process.
[0041] The above content specifically introduces the main modules of the intelligent POS terminal security payment system in the present invention. Based on this, the following combinesFigure 1 Comprehensively elaborate on the system architecture of the intelligent POS terminal secure payment system.
[0042] As Figure 1 shown, in the Non Secure World module, it includes Android (Android operating system), Linux Kernel (i.e., the Linux kernel), and hypervisor (i.e., the virtual machine monitor). The Android is the basic system for the intelligent POS terminal to run, providing the running environment and basic services for the entire device. The Linux kernel is the core of the Android system, responsible for managing hardware resources, providing system services, implementing process scheduling, and memory management and other basic functions. The hypervisor is responsible for creating, managing, and monitoring virtual machines. In this Android, it includes: (1) Applications, that is, the application program module. (2) The services module, that is, the first application module. (3) Java API (Java application programming interface): provides an interface for calling system functions and implementing application program functions. (4) binder: an inter-process communication mechanism. (5) VirtualizationService: virtualization service, providing virtualization support for the operation of the Protected VM module, managing virtual resources, and implementing resource isolation and allocation. (6) crosvm: a lightweight Linux-based virtual machine monitor, used for allocating virtual machine memory, creating virtual CPU threads, and implementing the backend of virtual devices.
[0043] As Figure 1As shown, in the Secure World module, it includes the Protected VM (protected virtual machine) module, the TEE module (i.e., Trust Zone), and the SE module. Among them, the Protected VM module includes the Microdroid module and the Linux Kernel (i.e., Linux kernel). The Microdroid module includes: (1) apexed, zipfuse, authfs: apexed is a component related to the APEX container format, responsible for the management and operation of APEX files; zipfuse is used to mount compressed files in the form of a file system for convenient access; authfs is a unified file system used to securely share multiple files between Android and the Protected VM (host and guest). (2) NativeAPI, binder: Native API is a native application programming interface; binder is an inter-process communication mechanism used in this system for interaction between applications running on Android and applications running on Microdroid. (3) Secure Modules, that is, the above-mentioned second application module, which can also be called the security module. (4) microdroid_manager (i.e., Microdroid manager): responsible for managing lifecycle-related operations such as the startup, stop, and resource allocation of Microdroid. The Linux Kernel includes pvmfw, and pvmfw is the firmware of the protected virtual machine. The TEE module includes the Trusty OS module, the Trusted UI module, and the TA module.
[0044] Correspondingly, as Figure 3 shown, the present invention also provides a secure payment method for an intelligent POS terminal system, which is applied to the intelligent POS terminal system as described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the TEE module pops up a PIN code input interface; S2: The TEE module receives the PIN code input by the user on the PIN code input interface and sends the PIN code to the SE module; S3: The SE module encrypts the PIN code and passes the encrypted PIN code to the bank card; S4: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program; S5: The payment program determines whether to complete the payment transaction according to the authorization result.
[0045] In practical applications, the above intelligent POS terminal system supports GMS + PCI PTS authentication, which can not only ensure the security of transactions and make them comply with the standards formulated by the PCI Security Standards Council, but also obtain authorization to use Google services and related trademarks and can be displayed on the official Google website. Based on this, the present invention provides a secure payment method. When making a card payment based on the above intelligent POS terminal system, its specific process can be as follows: (1) After inserting the bank card into the intelligent POS terminal, the SE chip module of the intelligent POS terminal will read the bank card information. The SE chip module can read the bank card information (such as card number, expiration date, etc.) through an IC card reader or a magnetic stripe card reader to obtain the basic information of the bank card, which is convenient for subsequent verification of the legality of the bank card, ensuring that the transaction can proceed correctly and improving data security.
[0046] (2) After the user inputs the amount to be paid in the payment program on the REE module side, the TEE module will pop up a PIN input interface (i.e., the bank card password input interface). Then, the user inputs the corresponding PIN code on the PIN input interface. It should be noted that in the secure payment method of the present invention, the PIN code generally refers to the bank card password.
[0047] (3) After receiving the PIN code input by the user on the PIN code input interface, the TEE module will transfer the PIN code to the SE module.
[0048] (4) After receiving the PIN code, the SE module encrypts the PIN code and transfers the encrypted PIN code to the bank card, that is, interacts with the bank card.
[0049] (5) The bank card itself contains a processor that can verify the PIN code transferred by the SE module. After receiving the encrypted PIN code, the bank card will decrypt and verify the encrypted PIN code to obtain a verification result; if the verification result is verification passed, it is determined that the authorization result is authorized payment; if the verification result is not passed, it is determined that the authorization result is unauthorized payment. After obtaining the authorization result, the bank card will send the authorization result to the payment program. The payment program determines whether to complete the payment transaction according to the authorization result. If the authorization result is authorized payment, the transaction is allowed; if the authorization result is unauthorized payment, the transaction is refused.
[0050] In addition, in practical applications, to prevent payment fraud, the bank card can also be locked when the PIN code fails to be verified multiple times. Specifically, when the authorization results of the PIN code exceed the preset number of times consecutively and are all unauthorized payments, that is, when the authorization results of multiple PIN codes continuously entered by the user are all unauthorized payments, an automatic locking operation is performed on the bank card, thereby temporarily prohibiting the use of the bank card for transactions, preventing the bank card from being used by others, and ensuring the security of transactions.
[0051] As described above, the PIN input interface is implemented by the above TEE module. The following describes how the TEE module pops up the PIN input interface in combination with the specific architecture of the above TEE module, which specifically includes the following steps: After receiving the request from the payment program to call the trusted application program module, the TEE module loads the trusted application program file of the trusted application program module into the memory of the Trusty OS module; The Trusty OS module starts the trusted application program module based on the trusted application program file; The trusted application program module starts the Trusted UI module to render and display the PIN input interface based on the Trusted UI module.
[0052] As described above, the TEE module includes a Trusty OS module, a TA module, and a Trusted UI module. When the user enters the amount to be paid in the payment program on the REE module side, the payment program running in the REE module will send a request to call the TA module to the TEE module through the TEEclient interface. After receiving the request, the TEE module will load the TA file corresponding to the TA module into the memory of the Trusty OS module. On this basis, the Trusty OS module starts the TA module based on the TA file. After the TA module is started, it will start the Trusted UI module according to the corresponding logic, thereby rendering and displaying the PIN input interface based on the Trusted UI module.
[0053] From the above description, it can be seen that by implementing the PIN input interface through the TEE module, since the TEE module has high security, sensitive interfaces such as PIN code input can be implemented in the Trusted UI of the TEE, effectively ensuring the security of transactions.
[0054] In addition, it should be noted that in the present invention, AVF (Android Virtualization Framework) is the Android virtualization framework; OS (Operating System) is the operating system; APEX (Android Pony Express) is a container format introduced in Android 10 and is used in the installation process of lower-level system modules.
[0055] In summary, the intelligent POS terminal system and its secure payment method provided by the present invention are as follows: (1) Through comprehensive mechanisms such as ProtectedVM, TEE, and SE, the security of certificates, keys, and sensitive information is ensured, and flexibility and development efficiency are also improved. (2) Support GMS+PCI PTS authentication. For the security-related parts, the security-related business logic is executed in the Microdroid module within the Protected VM module. For sensitive interfaces such as the PIN input interface, they are implemented in the TEE module. Key management, PIN input and encryption, security algorithms, etc. are implemented in the SE chip module. Thus, the security-related parts are implemented through Protected VM+TEE+SE, etc., and the security-related parts are all implemented through a secure environment (Protected VM module+TEE module+SE module) to pass the PCI PTS authentication. For the non-security-related parts, the Android native system is not modified as much as possible. For example, the original ADB (without trimming instructions) is retained, and the original APK signature and verification mechanism are retained, etc., in order to pass the GMS authentication. Therefore, the Android-Linux+Protected VM (AVF)+Trust Zone+SE system architecture of the present invention supports GMS+PCI PTS authentication. (3) The intelligent POS terminal system of the present invention supports the GMS+PCI PTS authentication system, is applicable to Android intelligent POS terminals, and the financial security-related parts are executed in a secure environment (Protected VM (AVF)+Trust Zone+SE). The security-related parts without interfaces are implemented in Protected VM (AVF), and the security-related parts with interfaces are implemented in Trust Zone to improve flexibility and development efficiency.
[0056] The above are only embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent transformation made using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, shall be included in the patent protection scope of the present invention by the same token.
Claims
1. An intelligent POS terminal system, characterized in that, It includes a secure world module and a non-secure world module. The non-secure world module includes a REE module, and the REE module is used to execute non-confidential business logics and render non-security-related interfaces. The secure world module includes a TEE module, a Protected VM module, and an SE module. The TEE module is used to render security-related interfaces. The Protected VM module is used to execute a first security service that does not involve rendering security-related interfaces. The SE module is used to execute a second security service. Among them, the REE module is communicatively connected to the Protected VM module and the TEE module respectively, and the TEE module is communicatively connected to the SE module.
2. The intelligent POS terminal system according to claim 1, wherein The REE module includes a first application module and an application program module. The first application module is communicatively connected to the application program module and the Protected VM module respectively.
3. The intelligent POS terminal system according to claim 2, characterized in that, The first application module includes a system service module, an AIDL service module, and a client application module. The system service module is communicatively connected to the AIDL service module and the Protected VM module respectively. The client application module is communicatively connected to the AIDL service module and the TEE module respectively.
4. The intelligent POS terminal system according to claim 3, wherein The Protected VM module includes a second application module. The second application module is communicatively connected to the system service module, and the second application module is used to execute a first security service that does not involve presenting security-related interface displays.
5. The intelligent POS terminal system according to claim 3, wherein The TEE module includes a Trusty OS module, a trusted application module, and a Trusted UI module. The Trusty OS module is communicatively connected to the SE module, and the trusted application module is communicatively connected to the client application module.
6. The intelligent POS terminal system according to claim 3, wherein It further includes a security monitor module, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
7. A secure payment method for an intelligent POS terminal system, which is applied to the intelligent POS terminal system according to any one of claims 1-6, characterized in that, It includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the TEE module pops up a PIN code input interface. S2: The TEE module receives the PIN code input by the user on the PIN code input interface and sends the PIN code to the SE module. S3: The SE module encrypts the PIN code and passes the encrypted PIN code to the bank card. S4: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program. S5: The payment program determines whether to complete the payment transaction according to the authorization result.
8. The secure payment method according to claim 7, wherein In step S1, when the TEE module pops up the PIN code input interface, it includes: After the TEE module receives the request from the payment program to call the trusted application module, it loads the trusted application program file of the trusted application module into the memory of the Trusty OS module. The Trusty OS module starts the trusted application module based on the trusted application file; The trusted application module starts the Trusted UI module to render and display the PIN input interface based on the Trusted UI module.
9. The secure payment method according to claim 7, wherein In step S4, decrypt and verify the encrypted PIN code to obtain an authorization result, including: Perform a verification operation on the decrypted PIN code to obtain a verification result; if the verification result is verification passed, determine that the authorization result is authorized payment; if the verification result is not passed, determine that the authorization result is unauthorized payment.
10. The secure payment method according to claim 9, wherein The method further includes: In the case where the authorization results of the PIN code exceed the preset number of times continuously and are all unauthorized payments, perform an automatic locking operation on the bank card.