Method for preventing POS from downloading third-party application
By using an OTP region in the POS security chip to store a non-modifiable public key and centralizing private key management, the method prevents unauthorized application downloads, improving transaction security and key management reliability while reducing hardware modification costs.
Patent Information
- Application Number
- CN202510482857.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-15
AI Technical Summary
The existing POS machines lack a strict application download verification mechanism, which leads to third-party applications downloading through copying legal agreements, causing risks of transaction data tampering and fund theft, and the existing solutions are unable to effectively resist hardware-level attacks.
Set up a one-time programmable (OTP) area in the security chip of the POS machine, solidify the public key of the asymmetric key pair, and sign and verify the application through a high-strength encryption algorithm, combining hardware fuse mechanism and key management to ensure that the public key is not tampered with and private keys are securely stored.
Completely block illegal downloads of third-party applications, realize closed-loop verification throughout the process, prevent "machine cutting" behavior, improve payment transaction security and key management reliability, and reduce hardware transformation costs.
Smart Images

Figure CN120316801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of payment technologies, and particularly to a method for preventing a POS from downloading third-party applications. Background Art
[0002] As a core device for financial transactions, a POS (Point of Sale) machine is widely used in bank card payment and electronic transaction scenarios. The application program (APP) of a traditional POS machine is usually developed by a manufacturer and bound to a specific payment channel (such as UnionPay or other authorized institutions) to ensure transaction compliance and security. In the prior art, POS machine manufacturers need to develop independent application program versions for different payment channels, and each version can only be used in its authorized payment channel.
[0003] However, such implementation methods have the following significant security risks:
[0004] (1) Due to the lack of a strict application program download verification mechanism in traditional POS machines, third-party developers can download unauthorized application programs to POS machines by imitating the communication protocols or interfaces of legitimate applications. This behavior (commonly known as "hijacking the machine") can cause the POS machine to deviate from the original payment channel, leading to major risks such as transaction data tampering and fund embezzlement.
[0005] (2) In the prior art, the legitimacy verification of application programs usually relies on simple software encryption or symmetric key mechanisms. The private key is easily leaked due to improper management. Once the private key is cracked or stolen, attackers can forge signatures to make illegal applications pass the verification. Moreover, some solutions do not provide hardware-level protection for the storage of public keys, and the public key may be tampered with or replaced, resulting in the failure of the verification mechanism.
[0006] (3) Some POS machines use rewritable storage areas to store verification keys. Attackers can modify the public key through physical or software means, thereby bypassing the signature verification process and achieving the implantation of malicious applications. This design flaw makes it difficult for the prior art to resist attacks at the hardware layer.
[0007] The above problems indicate that the prior art fails to achieve full-link protection from the hardware bottom layer to software verification. For example, some solutions attempt to enhance security through dynamic key updates, but still rely on software to store public keys and cannot resist hardware tampering attacks; other solutions adopt two-way authentication mechanisms but do not address the core challenges of centralized private key management and anti-leakage. Summary of the Invention
[0008] The present invention provides a method that combines the non-tamperable characteristics of hardware with high-strength encryption technology to fundamentally block the path of illegal downloading of third-party applications and ensure the security and reliability of key management.
[0009] The technical solution adopted by the present invention is as follows: A method for preventing a POS from downloading third-party applications, comprising the following steps:
[0010] Step 1: Set a one-time programmable (OTP) area in the security chip of the POS, and pre-store the public key of the asymmetric key pair in the OTP area, where the public key is only allowed to be written once and cannot be tampered with;
[0011] Step 2: The POS manufacturer uses the private key corresponding to the public key to digitally sign the application program to be downloaded, generating a signed application program;
[0012] Step 3: When downloading the application program to the POS, verify the signature of the signed application program through the public key in the OTP area;
[0013] Step 4: If the verification passes, allow the application program to be downloaded to the POS; if the verification fails, prohibit the download.
[0014] As a further improvement of the present invention, the asymmetric key algorithm is selected from one of the RSA2048, ECC256, and DSA algorithms.
[0015] As a further improvement of the present invention, the OTP area is a physical read-only memory in the security chip, and the one-time writing is achieved through a hardware fusing mechanism.
[0016] As a further improvement of the present invention, the private key is centrally managed by the POS manufacturer, and leakage is prevented through an encrypted storage and access control mechanism.
[0017] As a further improvement of the present invention, the signed application program is uniformly stored by the POS manufacturer, and its distribution authority is restricted.
[0018] As a further improvement of the present invention, the signature verification includes the following steps:
[0019] S1: When a download request is triggered, extract the signature data in the signed application program;
[0020] S2: Use the public key in the OTP area to decrypt the signature data, generating a hash value;
[0021] S3: Perform a hash operation on the original data of the application program, generating a comparison hash value;
[0022] S4: When the hash value is consistent with the comparison hash value, determine that the verification passes.
[0023] As a further improvement of the present invention, before the POS leaves the factory, the public key is written into the OTP area through a secure communication protocol.
[0024] As a further improvement of the present invention, the application is a payment application bound to a specified payment channel, and the signature of the application is uniquely associated with the payment channel.
[0025] As a further improvement of the present invention, if the verification fails, the POS machine generates an alarm log and uploads it to the manufacturer's server.
[0026] Advantages of the present invention: (1) By solidifying the public key in the non-tamperable OTP area and using high-strength asymmetric algorithms such as RSA2048 and ECC256 for signature, the present invention completely eliminates the risks of public key tampering and signature forgery, and blocks the illegal download of third-party applications from both the hardware and encryption levels. (2) From the encrypted storage of the private key, application signature to download verification signature, the present invention realizes a full-process closed-loop verification. Combining the centralized management of keys and signature applications by the manufacturer, it ensures that only authorized applications can run, effectively preventing "machine cutting" behavior and abuse of payment channels. (3) The present invention implements the OTP mechanism based on the existing security chip architecture, reducing the hardware transformation cost. At the same time, by uploading the alarm log in real time when the verification fails, it helps the manufacturer quickly respond to security threats, taking into account both security and implementation economy. Description of the Drawings
[0027] Figure 1 It is a schematic diagram of a method for preventing a POS from downloading third-party applications according to the present invention. Detailed Embodiments
[0028] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0029] The present invention provides a method for preventing a POS from downloading third-party applications, including the following steps:
[0030] Step 1: Set a one-time programmable (OTP) area in the security chip of the POS machine, and pre-store the public key of the asymmetric key pair in the OTP area. The public key is only allowed to be written once and cannot be tampered with. The asymmetric key algorithm is selected from one of RSA2048, ECC256, and DSA algorithms. The OTP area is a physical read-only memory in the security chip, and the one-time writing is realized through a hardware fusing mechanism;
[0031] Step 2: The POS machine manufacturer uses the private key corresponding to the public key to digitally sign the application program to be downloaded, generating a signed application program. The private key is centrally managed by the POS machine manufacturer and is prevented from being leaked through an encrypted storage and access control mechanism;
[0032] Step 3: When downloading the application to the POS machine, verify the signature of the signed application through the public key in the OTP area. The signed application is uniformly stored by the POS machine manufacturer, and its distribution permission is restricted.
[0033] Step 4: If the verification passes, allow the application to be downloaded to the POS machine; if the verification fails, prohibit the download, and the POS machine generates an alarm log and uploads it to the manufacturer's server.
[0034] The signature verification in the present invention includes the following steps: (1) When the download request is triggered, extract the signature data from the signed application; (2) Use the public key in the OTP area to decrypt the signature data to generate a hash value; (3) Perform a hash operation on the original data of the application to generate a comparison hash value; (4) When the hash value is consistent with the comparison hash value, determine that the verification passes.
[0035] Before the POS machine of the present invention leaves the factory, the public key is written into the OTP area through a secure communication protocol. The application is a payment application bound to a specified payment channel, and the signature of the application is uniquely associated with the payment channel.
[0036] Embodiment:
[0037] (1) Hardware configuration and key generation
[0038] Selection of security chip and setting of OTP area: Select the security chip with the model of Infineon SLM97. This chip has a built-in one-time programmable (OTP) storage area. Through the development tool provided by the chip manufacturer, divide the OTP area in the security chip and configure the hardware fuse mechanism to ensure that the public key is physically locked after being written and cannot be modified twice.
[0039] Generation of asymmetric key pair: The POS machine manufacturer uses the OpenSSL tool to generate an RSA2048 asymmetric key pair. The private key is encrypted and stored through a hardware security module (HSM), and access requires multi-factor authentication (such as biometric + dynamic password). The public key is transmitted to the POS machine production line through the secure file transfer protocol (SFTP).
[0040] (2) Pre-storage of public key and device initialization
[0041] Flash programming of public key: Before the POS machine leaves the factory, write the public key into the OTP area of the security chip through a dedicated flash programming device. The flash programming process uses an encrypted communication protocol (such as TLS1.3) to ensure the security of the transmission link. After the flash programming is completed, trigger the hardware fuse mechanism to make the OTP area enter the read-only state.
[0042] Function verification: Conduct functional tests on the POS machine with the public key written, including verification of the access permission of the OTP area and detection of the fuse state, to ensure that the public key cannot be tampered with.
[0043] (3) Application Signature and Distribution Management
[0044] Application Development and Signature: After a manufacturer develops a payment application for a certain payment channel (such as UnionPay), the following signature process is executed: (1) Generate a hash value for the application file using the SHA-256 algorithm; (2) Call the private key in the HSM to encrypt the hash value to generate a digital signature; (3) Bind the signature to the application file to generate a signed application package (format:.signed).
[0045] Storage of Signed Applications: The signed application packages are stored in the manufacturer's private cloud server, and the access rights are restricted to authorized administrators, and the distribution rights are managed through role-based access control (RBAC).
[0046] (4) Application Download and Verification Process
[0047] Triggering of Download Request: The merchant selects "UnionPay Payment Application Update" on the POS management interface, and the device sends a request to the manufacturer's server, including the device ID and the application version number.
[0048] Execution of Signature Verification: (1) Step S1: The POS receives the signed application package, parses and extracts the signature data; (2) Step S2: Call the public key in the OTP area of the security chip to decrypt the signature data to obtain the hash value H1; (3) Step S3: Perform the SHA-256 hash operation on the original application file to generate the comparison hash value H2; (4) Step S4: Compare H1 and H2: If they are the same, determine that the signature is valid and allow the application to be installed; if they are different, terminate the download and trigger an alarm.
[0049] Exception Handling and Monitoring: When the verification fails, the POS generates an alarm log (including timestamp, device ID, application hash value), uploads it to the manufacturer's security monitoring platform through an encrypted channel, and the platform automatically triggers the work order system to notify the technical staff to conduct a troubleshooting.
[0050] (5) Example of Actual Application Scenario
[0051] The POS of a certain chain supermarket needs to update the UnionPay payment application to version V2.0. The operation process is as follows: (1) The merchant initiates an update request, and the POS obtains the signed UnionPay application package (V2.0.signed) from the manufacturer's server; (2) The device automatically performs signature verification: decrypt the signature with the public key to get H1, calculate the hash value of the application file to get H2, and complete the installation after comparison; (3) If an attacker attempts to implant a forged application (such as "Third-party Payment Application.signed"), the download is prohibited because the signature cannot pass the OTP public key verification, and an alarm log is reported to the manufacturer's platform in real time, triggering the security response process.
[0052] Verification of Technical Effects
[0053] (1) Tamper - proof ability test: Attempt to modify the public key in the OTP area through physical attacks. Due to the fusing mechanism locking, the attack fails.
[0054] (2) Signature forgery test: Use the leaked ECC256 private key to forge a signature. Since the private key is centrally managed in the HSM and not leaked, the forged signature cannot pass the verification.
[0055] (3) Economic verification: Based on the OTP function of existing security chips, the hardware transformation cost is reduced by about 30%, and it is compatible with mainstream POS models.
[0056] As can be seen from the above embodiments, the method of the present invention fundamentally improves the security protection ability of the POS machine, effectively resists the risks of illegal downloading and tampering of third - party applications. Through actual test verification, this method not only enhances the security of payment transactions, but also ensures the reliability and efficiency of key management. Specifically, the tamper - proof ability test shows that the hardware fusing mechanism in the OTP area effectively prevents the illegal modification of the public key, ensuring the authenticity and integrity of the public key. The signature forgery test further proves the security of the centralized management of the private key in the HSM. Even if the private key is at risk of leakage, attackers cannot forge a valid signature and thus cannot pass the verification process. In addition, the economic verification results show that this method is implemented based on the OTP function of existing security chips, reducing the hardware transformation cost, while being compatible with mainstream POS models, which is easy to promote and apply. In summary, the method of the present invention improves the security protection ability of the POS machine while taking into account economy and implementation feasibility, providing a new solution for security protection in the payment technology field.
[0057] In summary, a method for preventing a POS from downloading third - party applications of the present invention not only realizes the full - link protection from the hardware bottom layer to software verification, but also significantly improves the security of payment transactions and the reliability of key management. Through actual application scenario examples and technical effect verification, it fully demonstrates the excellent performance of this method in preventing illegal downloading of third - party applications on POS machines. In the future, with the continuous development of the payment industry and the increasing security requirements, the method of the present invention is expected to provide solid security guarantees for more merchants and payment institutions, promoting the healthy development of the payment industry.
[0058] The above embodiments are only used to illustrate the technical solutions of the present invention, not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for preventing a POS from downloading third-party applications, characterized in that, It includes the following steps: Step 1: Set a one-time programmable (OTP) area in the security chip of the POS machine, and pre-store the public key of the asymmetric key pair in the OTP area. The public key is only allowed to be written once and cannot be tampered with; Step 2: The POS machine manufacturer uses the private key corresponding to the public key to digitally sign the application to be downloaded, generating a signed application; Step 3: When downloading the application to the POS machine, verify the signature of the signed application through the public key in the OTP area; Step 4: If the verification passes, allow the application to be downloaded to the POS machine; if the verification fails, prohibit the download.
2. The method for preventing a POS from downloading third-party applications according to claim 1, wherein The asymmetric key algorithm is selected from one of the RSA2048, ECC256, and DSA algorithms.
3. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, The OTP area is a physical read-only memory in the security chip and realizes one-time writing through a hardware fusing mechanism.
4. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, The private key is centrally managed by the POS machine manufacturer and is prevented from leaking through an encryption storage and access control mechanism.
5. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, The signed application is uniformly stored by the POS machine manufacturer, and its distribution permissions are restricted.
6. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, The signature verification includes the following steps: S1: When a download request is triggered, extract the signature data in the signed application; S2: Use the public key in the OTP area to decrypt the signature data, generating a hash value; S3: Perform a hash operation on the original data of the application, generating a comparison hash value; S4: When the hash value is consistent with the comparison hash value, determine that the verification passes.
7. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, Before the POS machine leaves the factory, the public key is written into the OTP area through a secure communication protocol.
8. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that The application is a payment application bound to a specified payment channel, and the signature of the application is uniquely associated with the payment channel.
9. A method for preventing a POS from downloading third-party applications according to claim 1, characterized in that, If the verification fails, the POS machine generates an alarm log and uploads it to the manufacturer's server.