Intelligent POS terminal security payment system and security payment method thereof
Through the Android-Linux+Protected VM (AVF)+SE system architecture, the problem that smart POS terminals are difficult to pass GMS and PCI PTS authentication at the same time is solved, and a high security and flexibility POS terminal system is realized, which improves development efficiency.
Patent Information
- Application Number
- CN202510336952.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-22
AI Technical Summary
The existing smart POS terminal system is difficult to pass GMS and PCI PTS certification at the same time, and the Trust Zone technology is poor and the development efficiency is low.
The system architecture of Android-Linux+Protected VM (AVF)+SE is adopted to divide the system into a secure world and a non-secure world. The first security service that does not involve interface rendering is performed through the Protected VM module, and the second security service is performed by the SE module, and the interface rendering is logically separated from the processing logic of sensitive data input.
It realizes supporting GMS and PCI PTS authentication at the same time, improves the security and flexibility of smart POS terminals, reduces the transformation of Android native systems, and reduces development and maintenance costs.
Smart Images

Figure CN120355414A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent payment terminals, and in particular, to an intelligent POS terminal secure payment system and a secure payment method thereof. Background Art
[0002] With the rapid development of mobile payment and intelligent devices, the intelligent POS terminal system is increasingly widely used in fields such as retail, catering, and finance. The intelligent POS terminal system not only needs to support multiple payment methods (such as bank cards, QR code payment, etc.), but also needs to meet the high security requirements of the payment industry. Currently, the intelligent POS terminal system is usually built based on the Android-Linux operating system, and with its rich application ecosystem and mature development framework, it can quickly implement diverse payment functions.
[0003] Researchers have found that most of the intelligent POS terminals on the market currently pass the PCI PTS certification. However, the PCI PTS certification has relatively high security requirements for POS terminals. In order to meet the security requirements, many device manufacturers will make some modifications to the intelligent POS terminals, such as trimming ADB instructions, modifying the signature and verification mechanism of the APK. However, these practices are contrary to the GMS certification. Therefore, it is relatively difficult for intelligent POS terminals to pass the GMS + PCI PTS certification simultaneously. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: to provide an intelligent POS terminal secure payment system and a secure payment method thereof, so as to solve the problem that the existing intelligent POS terminal system is relatively difficult to pass the GMS + PCI PTS certification simultaneously.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is: an intelligent POS terminal secure payment system, which includes a secure world module and a non-secure world module. The non-secure world module includes a REE module, and the REE module is used to execute non-confidential business logic and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering; the secure world module includes a Protected VM module and an SE module. The Protected VM module is used to execute the first secure service that does not involve interface rendering, and the SE module is used to execute the second secure service; wherein, the REE module is communicatively connected to the Protected VM module, and the SE module is communicatively connected to the Protected VM module or the REE module. Further, in the intelligent POS terminal secure payment system of the present invention, the REE module includes a first application module and an application program module. The first application module includes a system service module and an AIDL service module, and the system service module is communicatively connected to the application program module and the AIDL service module respectively.
[0006] Further, in the intelligent POS terminal secure payment system of the present invention, the Protected VM module includes a Microdroid module. The Microdroid module includes a second application module, and the second application module is communicatively connected to the system service module. The second application module is used to execute a first security service that does not involve interface rendering.
[0007] Further, in the intelligent POS terminal secure payment system of the present invention, the SE module is communicatively connected to the second application module or the system service module.
[0008] Further, in the intelligent POS terminal secure payment system of the present invention, it further includes a security monitor module, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
[0009] Further, in the intelligent POS terminal secure payment system of the present invention, the second security service includes key management, certificate management, personal identification number input verification, and personal identification number encryption operation. The key management includes the storage of keys, and the keys include finance-related keys and non-finance-related keys. The certificate management includes the storage of certificates, and the certificates include finance-related certificates and non-finance-related certificates.
[0010] Correspondingly, the present invention further provides a secure payment method, which is applied to the intelligent POS terminal secure payment system as described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment application program in the REE module, the REE module renders and displays a PIN code input interface. S2: The PIN code input interface receives the PIN code input by the user and directly transfers the PIN code to the SE module or transfers the PIN code to the SE module through the Microdroid module. S3: The SE module encrypts the PIN code and transmits the encrypted PIN code to the bank card or the background payment system to determine whether the payment transaction is completed.
[0011] Further, in the secure payment method of the present invention, in step S1, the REE module renders and displays a PIN code input interface, including: The payment application starts the PIN input module in the REE module through an interface; after successful startup, the PIN input module renders the PIN input interface.
[0012] Further, in the secure payment method of the present invention, in step S3, the encrypted PIN is passed to the bank card or the background payment system to determine whether the payment transaction is completed, including: After receiving the encrypted PIN, the bank card decrypts and verifies the encrypted PIN, generates an authorization result, and sends the authorization result to the payment application; The payment application determines whether the payment transaction is completed according to the authorization result.
[0013] Further, in the secure payment method of the present invention, in step S3, the encrypted PIN is passed to the bank card or the background payment system to determine whether the payment transaction is completed, including: The SE module returns the encrypted PIN to the payment application through the PIN input module; The payment application then uploads the encrypted PIN to the background payment system. The background payment system online verifies the authorization result of the PIN input and sends the authorization result to the payment application; The payment application determines whether the payment transaction is completed according to the authorization result.
[0014] The beneficial effects of the present invention are as follows: The present invention provides an intelligent POS terminal secure payment system that simultaneously supports GMS+PCI PTS authentication. Through the comprehensive mechanism of Android-Linux+Protected VM (AVF)+SE, it can effectively support GMS+PCI PTS authentication on the basis of ensuring the security and flexibility of the intelligent POS terminal secure payment system: (1) For the services related to security, the present invention is implemented through a security environment (i.e., Protected VM module + SE module). Specifically: the Protected VM module executes the first security services that do not involve rendering the interface (such as interface call authentication, signature verification for application installation), and the SE module executes the second security services (such as key management, input / encryption of PIN codes, security algorithms). In addition, for the security-related interfaces, the present invention separates the interface rendering (non-sensitive operations) from the processing logic for sensitive data input after rendering (such as the business logic for PIN code input), that is, the interface rendering is handed over to the REE module, and the operations after interface rendering (such as the business logic for PIN input) are handed over to the Protected VM module / SE module for processing, so as to ensure that sensitive operations in running security interface-related services can be in a protected environment throughout the process, improving security.
[0015] That is to say, the present invention implements the services related to security through a security environment (i.e., Protected VM module + SE module), thereby ensuring the security requirements of the intelligent POS terminal secure payment system to successfully pass the PCI PTS certification without the need to modify some native Android functions.
[0016] (2) For the non-security-related part, in the present invention, the non-security world module (i.e., the REE module) mainly refers to the native Google Android-Linux system, which can be used to execute non-confidential business logic and perform interface rendering. As described above, the architecture of the above Protected VM module + SE module can effectively ensure the security requirements of the terminal control system. Therefore, the present invention can achieve minimal modification to the native Android system. For example, the native ADB (without trimming instructions) is retained, and the original APK signature and signature verification mechanism are retained, etc., so as to pass the GMS certification.
[0017] In summary, based on the Android-Linux + Protected VM (AVF) + SE system architecture, the present invention can effectively support GMS + PCI PTS certification. Brief Description of the Drawings
[0018] Figure 1 It is a system architecture diagram of the intelligent POS terminal secure payment system according to the present invention in an embodiment.
[0019] Figure 2 It is a module architecture diagram of the intelligent POS terminal secure payment system according to the present invention in an embodiment.
[0020] Figure 3This is a module architecture diagram of the intelligent POS terminal security payment system according to the present invention in another embodiment.
[0021] Figure 4 This is a step flowchart of the security payment method of the intelligent POS terminal security payment system according to the present invention in one embodiment. Specific embodiments
[0022] To describe in detail the technical content, achieved objectives and effects of the present invention, the following is described in conjunction with embodiments and with reference to the accompanying drawings.
[0023] Researchers have found that the system architecture of intelligent POS (Point of Sale) terminals can adopt the Android-Linux + Trust Zone + SE architecture. In this architecture: the intelligent POS terminal uses the Android-Linux operating system, which divides the system into two parts, the Secure World module and the Non Secure World module. Among them, the Non Secure World module mainly refers to the native Android-Linux system of Google; the Secure World module includes Trust Zone technology. However, in actual use, there are many defects in the above system architecture, such as: (1) Due to the security requirements of PCI PTS certification, in order to prevent malicious attacks, intelligent POS terminals generally perform command clipping on ADB, modify the signature and signature verification mechanism of APK. However, these practices are contrary to GMS certification. Therefore, it is difficult for intelligent POS terminals to pass GMS + PCI PTS certification simultaneously (unless using dual CPUs at the cost of sacrificing cost).
[0024] (2) The management of security-related aspects such as intelligent POS terminal certificates and keys, terminal status and lifecycle is achieved through TrustZone technology. Trust Zone has certain disadvantages: ① Poor flexibility: Trust Zone can only run the same version of the Android system and applications on the same platform; ② Low development efficiency: Trust Zone requires hardware configuration on the host system. Therefore, the development efficiency is low. These disadvantages will bring certain difficulties to developers and increase the development and maintenance costs.
[0025] Therefore, please refer to Figures 1 to 3, the present invention provides an intelligent POS terminal secure payment system, which includes a secure world module and a non-secure world module. The non-secure world module includes a REE module, and the REE module is used to execute non-confidential business logics and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering; the secure world module includes a Protected VM module and an SE module. The Protected VM module is used to execute a first secure service that does not involve interface rendering, and the SE module is used to execute a second secure service; wherein, the REE module is communicatively connected to the Protected VM module, and the SE module is communicatively connected to the Protected VM module or the REE module. As can be seen from the above description, the beneficial effects of the present invention are as follows: The present invention provides an intelligent POS terminal secure payment system that simultaneously supports GMS+PCIPTS authentication. Through the comprehensive mechanism of Android-Linux+Protected VM (AVF)+SE, it can effectively support GMS+PCI PTS authentication on the basis of ensuring the security and flexibility of the intelligent POS terminal secure payment system. Specifically: (1) For the services related to security, the present invention is implemented through a secure environment (i.e., the Protected VM module + SE module). Specifically: The first secure service that does not involve rendering the interface (such as interface call authentication and signature verification for application installation) is executed through the Protected VM module, and the second secure service (such as key management, PIN input / encryption, and security algorithms) is executed through the SE module. In addition, for the interfaces related to security, the present invention separates the interface rendering (non-sensitive operations) from the processing logic of sensitive data input after rendering (such as the business logic of PIN input), that is, the interface rendering is completed by the REE module, and the operations after interface rendering (such as the business logic of PIN input) are handed over to the Protected VM module and / or the SE module for processing, so as to ensure that the sensitive operations in the services related to the secure interface can be in a protected environment throughout the process and improve security.
[0026] That is to say, the present invention implements the services related to security through a secure environment (i.e., the Protected VM module + SE module), thereby ensuring the security requirements of the intelligent POS terminal secure payment system and successfully passing the PCI PTS authentication without modifying some native Android functions.
[0027] (2)For the non-security related parts, in the present invention, the non-security world module (i.e., the REE module) mainly refers to the Google-native Android-Linux system, which can be used to execute non-confidential business logics and perform interface rendering. As mentioned above, the architecture of the above-mentioned Protected VM module + SE module can effectively ensure the security requirements of the terminal control system. Therefore, the present invention can achieve minimizing the modification of the Android native system. For example, the native ADB (without trimming instructions) is retained, the original APK signature and signature verification mechanism are retained, etc., so as to achieve GMS certification.
[0028] In summary, based on the Android-Linux + Protected VM (AVF) + SE system architecture, the present invention can effectively support GMS + PCI PTS certification.
[0029] It should be noted that the GMS (Google Mobile Services Test Certification) is a certification system established by Google. This system aims to ensure that smart devices based on the Android system produced by global hardware manufacturers meet Google's standards in terms of compatibility, stability, and performance. Products that pass the GMS certification will obtain the authorization to use Google services and related trademarks and can be displayed on Google's official website. The PCI PTS (Payment Card Industry PIN Transaction Security) certification is formulated by the PCI (Payment Card Industry PIN) Security Standards Council and aims to ensure the confidentiality and integrity of PIN data in payment card transactions and is a security requirement for payment devices. Therefore, for a typical payment device such as a POS terminal, a series of security measures need to be taken, such as encrypting the transmission and storage of sensitive data, regularly updating and patching system vulnerabilities, restricting access permissions, etc., to ensure that payment data is not leaked or misused.
[0030] The intelligent POS terminal security payment system described in the present invention uses the Android-Linux operating system, which divides the system into two parts: the secure world module and the non-secure world module. Among them, the non-secure world module mainly refers to the Google-native Android-Linux operating system; the secure world module mainly refers to the Protected VM (AVF) module and the external SE (Secure Element) module. The following is combined with Figures 1 to 3, a detailed description of the above intelligent POS terminal secure payment system will be given.
[0031] In the present invention, the non-secure world module is the REE (Rich Execution Environment) module. The REE module is a non-trusted rich execution environment, which is an open environment vulnerable to attacks. For example, events such as theft of sensitive data and embezzlement of mobile payments often occur. Therefore, in the present invention, security-related services are mainly executed by the Protected VM module and the SE module in the secure world module. In the present invention, the REE module is built based on the Android - Linux system. Compared with the existing intelligent POS terminal system architecture, the present invention tries not to modify the Android native system as much as possible to retain the native ADB (non-trimmed instructions), the original APK signature and verification mechanism, etc., so as to ensure that the intelligent POS terminal can pass the GMS certification, and further enable the intelligent POS terminal to obtain authorization to use Google services (such as Google Play, Gmail, Google Maps, etc.).
[0032] In practical applications, the REE module may include an application program module running on Android (i.e., Figure 1 the Applications module in Figure 1 / 2 / 3), the first application module (i.e., Figure 2 the services module in
[0033] As described above, interface rendering includes secure interface rendering and non-secure interface rendering. The secure interface rendering refers to the rendering of security-related interfaces, and the non-secure interface rendering refers to the rendering of non-security-related interfaces. In practical applications, the non-security-related interfaces refer to the user interaction interfaces in the intelligent POS terminal that do not involve the processing of sensitive data, that is, the non-security-related ordinary user interaction interfaces, such as: (1) System upgrade interface: used to prompt the user whether the device needs to be upgraded and display the upgrade progress, which does not involve the processing of sensitive data (such as PIN codes, keys, etc.). (2) Sign-in interface of the POS machine: used for merchants to sign in the device at the POS terminal, which does not involve the processing of highly sensitive data (such as PIN codes, payment card information, etc.). (3) Status display interface: used for the user to select the transaction type (such as consumption, refund, query, etc.), only involves the selection of the transaction type and does not involve the processing of sensitive data. The non-confidential business logic refers to the business logic in the system that does not involve the processing of sensitive data, that is, the non-security-related business, such as controlling the on and off of the LED lamp, controlling the buzzer, managing the power state of the device (such as sleep, wake-up, etc.). The security-related interfaces refer to the user interaction interfaces related to security, such as PIN (Personal identification number) input interface, biometric (such as fingerprint, face recognition) identification interface, payment card information display interface.
[0034] The non-security world module of the present invention is introduced above. The security world module of the present invention will be specifically introduced below. The security world module includes a Protected VM (AVF) module and an external SE module. Among them, the Protected VM module is connected to the above-mentioned REE module. There are two connection methods for the SE module, as Figure 2 shown, this SE module will be communicatively connected to the REE module, as Figure 3 shown, this SE module will be communicatively connected to the Protected VM module. The modules in the above-mentioned security world module will be specifically introduced below in combination with the above two connection methods.
[0035] (1) The main use case of the Protected VM (Protected Virtual Machine) module is not to run an independent operating system, but to provide an isolated execution environment. The Protected VM module includes the Microdroid module, which is a miniaturized AndroidOS running in the Protected VM (Virtual Machine). In the Microdroid module, there is a second application module (i.e., the Secure Modules module), which is communicatively connected to the above system service module through Binder. The Microdroid module (such as the second application module) is used to execute the first security service that does not involve interface rendering. The first security service refers to some security-related business logics, such as interface call authentication, signature verification for application installation, etc. It should be noted that this second application module can also be called the security module.
[0036] In practical applications, existing intelligent POS terminal systems basically use the Trust Zone technology (TEE environment). However, this technology has poor flexibility and low development efficiency. Therefore, the present invention replaces the TEE module with the Protected VM module to improve flexibility and development efficiency. It should be noted that although both Protected VM and Trust Zone are security technologies for the Android system, their purposes and implementation methods are different. Trust Zone is a hardware-level security technology that provides a secure execution environment for running secure code. Protected VM is a resource management technology that provides a secure and private execution environment to execute code, and is very suitable for security-oriented use cases that require a higher security level than that provided by the Android application sandbox, or even formally verified isolation guarantees. On this basis, the present invention can effectively improve the development efficiency by using the Protected VM module to replace the TEE module to execute the first security service, making the intelligent POS terminal security payment system of the present invention more flexible. Specifically, compared with the TEE module, the main advantages of the Protected VM module are: (1) Stronger flexibility: The Protected VM module can run different versions of the Android system and applications on different platforms. This enables the Protected VM module to meet a wider range of application requirements. (2) Higher development efficiency: The Protected VM module can create an independent development environment, facilitating developers to develop and test application programs, which can effectively improve the development efficiency.
[0037] It should be noted that since the Microdroid module does not support interfaces, in the present invention, security-related interfaces such as the PIN input interface are rendered through the REE module, and the business logic after rendering is taken over by the Protected VM module or the SE module to ensure security.
[0038] (2) The SE module is an external security component, which is mainly responsible for payment industry-related peripherals and security-related functions, that is, for performing second security services. For example, functions such as IC card readers, magnetic stripe card readers, key management, PIN input and encryption, and security algorithms. It should be noted that the SE module has extremely high security. By using the above SE module to perform second security services with relatively high security requirements, such as key management, certificate management, PIN input verification, PIN code encryption operations, and security algorithms, it can significantly improve payment security, enhance the user experience and market competitiveness. Among them, the key management refers to the full life cycle management of keys, including generation, storage, distribution, rotation, backup, and destruction. PIN input verification refers to the process of confirming that the PIN code entered by the user is consistent with the legitimate PIN code stored in the system to prevent unauthorized access. The PIN code encryption operation refers to the process of converting the PIN code into ciphertext to ensure that it cannot be stolen or tampered with during transmission and storage. In practical applications, the certificates and keys of the present invention are both stored in the SE module, which includes finance-related keys, finance-related certificates, non-finance-related keys, non-finance-related certificates, etc. The finance-related keys and finance-related certificates refer to the keys and certificates directly used in security mechanisms involving financial transactions, payment verification, identity authentication, etc., which are related to the protection of fund flows or sensitive financial data. The non-finance-related keys and non-finance-related certificates refer to encryption keys and certificates used in non-fund transaction or non-sensitive financial data scenarios.
[0039] As described above, in the intelligent POS terminal security payment system of the present invention, there are two module connection methods for the SE module. The first module connection method: The SE module is communicatively connected to the REE module. As Figure 2 shown, the SE module is communicatively connected to the system service module in the REE module. In practical applications, it can interact through serial communication protocols such as SPI / I2C / UART. The second connection method: The SE module is communicatively connected to the Protected VM module. As Figure 3 shown, the SE module is communicatively connected to the Secure Modules module in the Protected VM module. In practical applications, it can interact through serial communication protocols such as SPI / I2C / UART.
[0040] In summary, in the present invention, applications (such as modules related to finance, such as printing, EMV, magnetic cards, IC cards, contactless cards, pinpads, etc.) are developed and packaged in the form of APK (Android Application Package) or APEX format (AVF application) and stored in the terminal, thereby respectively forming an application running on Android (i.e., the first application module) and an application running on the Microdroid module in the Protected VM module (i.e., the second application module), and the first application module and the second application module can interact through binder. Among them, the application running on Android is mainly responsible for interface rendering and executing non-confidential business logic; the application running on the Microdroid module in the Protected VM module is responsible for the first security service that does not involve interface rendering. In addition, the application running on Android can also be used to create and manage the life cycle of the Protected VM module.
[0041] As described above, the first application module (i.e., the application running on Android) is used to execute non-confidential business logic and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering. The secure interface rendering refers to the rendering of security-related interfaces, and the non-secure interface rendering refers to the rendering of non-security-related interfaces. In practical applications, for security-related interfaces, the present invention separates the interface rendering from the processing logic of sensitive data input after rendering (such as the business logic of PIN code input), that is, the first application module only performs the operation of interface rendering, and the operation after interface rendering is taken over by the Protected VM module / SE module, so as to complete the business after interface rendering through the Protected VM module / SE module. For non-security-related interfaces, both the interface rendering and the operation after rendering (such as the processing logic of corresponding data input) are completed by the first application module. Among them, for non-security-related interfaces, the operation after interface rendering belongs to non-confidential business logic, and for security-related interfaces, the operation after interface rendering belongs to the business of the security-related part. It should be noted that the above-mentioned processing logic of sensitive data input after rendering refers to the full-process control strategy in the intelligent POS terminal to ensure the confidentiality, integrity, and availability of data during input, transmission, processing, and storage for the sensitive data input by the user (such as PIN codes, keys, etc.) through specific system architecture design and security mechanisms.
[0042] It should be specifically noted that the first security service executed by the above Microdroid module is mainly some security services independently designed by POS manufacturers. For example, the life cycle management service of the POS (managing the status of the POS, such as the manufacturing state, repair state, usage state, development mode, etc.), data collection service, unified response service (functions such as setting configuration items), authentication service (interface call authentication), etc. The second security service executed by the above SE module is mainly security services related to PIN codes, keys, etc., such as security services related to functions such as reading bank card information, PIN code input and encryption, and key management.
[0043] In addition, as Figure 1 shown, the intelligent POS terminal security payment system further includes a security monitor module, and the security monitor module is used to manage the switching between the secure world module and the non-secure world module.
[0044] In practical applications, the security monitor module (i.e., Figure 1 the Secure Monitor module in
[0045] can switch and trigger a response. Specifically, when the system has a need to enter the secure world from the non-secure world to execute security-sensitive tasks, Secure Monitor will respond to this request. For example, when the payment application needs to perform security operations such as PIN code verification, the payment application will send a switching request to Secure Monitor, asking to switch to the secure world for processing. At this time, Secure Monitor will start the switching process. Figure 1 The above content specifically introduces the main modules of the intelligent POS terminal security payment system in the present invention. Based on this, the system architecture of the intelligent POS terminal security payment system will be comprehensively described below in combination with
[0046] As Figure 1As shown, in the Non Secure World module, it includes Android (the Android operating system), Linux Kernel (i.e., the Linux kernel), and hypervisor (i.e., the virtual machine monitor). The Android is the basic system for the intelligent POS terminal to run, providing the running environment and basic services for the entire device. The Linux kernel is the core of the Android system, responsible for managing hardware resources, providing system services, and implementing basic functions such as process scheduling and memory management. The hypervisor is responsible for creating, managing, and monitoring virtual machines. In this Android, it includes: (1) Applications, i.e., the application module. (2) The services module, i.e., the first application module. (3) Java API (Java Application Programming Interface): provides interfaces for calling system functions and implementing application functions. (4) binder: an inter-process communication mechanism. (5) VirtualizationService: the virtualization service, providing virtualization support for the operation of the Protected VM module, managing virtual resources, and implementing resource isolation and allocation. (6) crosvm: a lightweight Linux-based virtual machine monitor, used for allocating virtual machine memory, creating virtual CPU threads, and implementing the backend of virtual devices.
[0047] In the Secure World module, it includes the Protected VM (protected virtual machine) module and the SE module. Among them, the Protected VM module includes the Microdroid module and the Linux Kernel (i.e., the Linux kernel). The Linux Kernel includes pvmfw, and pvmfw is the firmware of the protected virtual machine. The Microdroid module includes: (1) apexed, zipfuse, authfs: apexed is a component related to the APEX container format, responsible for the management and operation of APEX files; zipfuse is used to mount compressed files in the form of a file system for convenient access; authfs is a unified file system for securely sharing multiple files between Android and the Protected VM (host and guest). (2) Native API, binder: The Native API is the native application programming interface; binder is an inter-process communication mechanism, which is used in this system for the interaction between applications running on Android and applications running on Microdroid. (3) microdroid_manager (i.e., the Microdroid manager): Responsible for managing the life cycle related operations of Microdroid, such as startup, shutdown, and resource allocation.
[0048] Correspondingly, as Figure 4 shown, the present invention also provides a secure payment method for an intelligent POS terminal secure payment system, which is applied to the intelligent POS terminal secure payment system as described above, and includes the following steps: S1: After the user inputs the transaction amount into the payment program in the REE module, the REE module renders and displays a PIN code input interface; S2: The PIN code input interface receives the PIN code input by the user and directly passes the PIN code to the SE module or passes it to the SE module through the Microdroid module; S3: The SE module encrypts the PIN code and passes the encrypted PIN code to the bank card; S4: The bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment program; S5: The payment program determines whether to complete the payment transaction according to the authorization result.
[0049] In practical applications, when making a card payment based on the above intelligent POS terminal secure payment system, its specific process can be as follows: (1)After inserting the bank card into the intelligent POS terminal, the SE chip module of the intelligent POS terminal reads the bank card information. The SE chip module can read the bank card information (such as card number, expiration date, etc.) through an IC card reader or a magnetic stripe card reader to obtain the basic information of the bank card, facilitating subsequent legal verification of the bank card, ensuring that the transaction can proceed correctly, and improving data security.
[0050] (2)After the user inputs the transaction amount into the payment program in the REE module, the REE module renders and displays the PIN code input interface (i.e., the bank card password input interface). In practical applications, payment programs in the REE module, such as Cloud QuickPass, Shouqianba, etc., when the PIN code needs to be input, these payment programs call the pinpad module interface (i.e., the password keyboard module interface) to start the PIN_ENTRY module (i.e., the personal identification number input module). After the PIN_ENTRY module is started, it performs the rendering operation of the PIN code input interface, that is, renders the PIN code input interface through the PIN_ENTRY module. After the PIN code input interface is displayed, the user can operate the PIN code input interface to input the PIN code. It should be noted that in the secure payment method described in the present invention, the PIN code usually refers to the bank card password.
[0051] In view of the system architecture of the present invention as described above, it can be seen that the second security service related to the PIN code in the present invention is all handled by the SE module. However, referring to Figure 2 and Figure 3 it can be seen that there are two connection methods between the modules of the present invention, and their differences mainly lie in the connection between the SE module and other modules. Therefore, to transfer the PIN code input into the PIN code input interface to the SE module, it can include two transfer methods: The first transfer method: As Figure 2 shown, directly transfer it to the SE module. That is, when the user operates the PIN code input interface, the REE module transfers the control right of the touch screen to the SE module through a secure communication mechanism; after the SE module takes over the control right of the touch screen, it receives and parses the user input data through the PIN input interface to obtain the PIN code input by the user. In this case, the SE module needs to verify the validity of the REE application program to prevent other applications from communicating with the SE module.
[0052] The second transfer method: As Figure 3As shown in the figure, it is first passed to the Secure Modules module in the Protected VM, and then the PIN code is passed to the SE module via the Secure Modules module. Specifically: when the user operates the PIN code input interface, the REE module transfers the control right of the touch screen to the Microdroid module through the secure communication mechanism; after the Microdroid module takes over the control right of the touch screen, it receives and parses the input data of the user through the PIN input interface to obtain the PIN code input by the user; then, the Microdroid module sends the PIN code to the SE module.
[0053] (3)After the SE module receives the PIN code, it encrypts the PIN code. In actual applications, this payment process may be an online payment or an offline payment. For different payment scenarios, the payment verification methods used are also different. Specifically: For offline payment, it is completed by interacting with the bank card. For example, after the SE module encrypts the PIN code, it will send the encrypted PIN code to the bank card. Since the bank card (smart card) itself contains a processor inside, which can verify the PIN code passed in by the SE, therefore, after the bank card receives the encrypted PIN code, it will decrypt and verify the encrypted PIN code to generate an authorization result. Among them, if the verification result is passed, it is determined that the authorization result is authorized payment; if the verification result is not passed, it is determined that the authorization result is unauthorized payment. On this basis, the bank card will send the authorization result to the payment application. The payment application determines whether to complete the payment transaction according to the authorization result. If the authorization result is authorized payment, the transaction is allowed; if the authorization result is unauthorized payment, the transaction is rejected, thus preventing the bank card from being used by others. It should be noted that the interaction of the PIN code is carried out using ciphertext.
[0054] For online payment, its verification method can be as follows: After the SE module encrypts the PIN code, it will return the encrypted PIN code to the payment application through the personal identification number input module, that is, it will return the encrypted PIN code to the PIN_ENTRY module in the REE module. After that, the PIN_ENTRY module will return the encrypted PIN code to the payment application. After receiving it, the payment application will upload the encrypted PIN code to the background payment system, and the background payment system will verify online whether the PIN input is legal to obtain the authorization result of the PIN input. After the background payment system obtains the authorization result, it will send the authorization result to the payment application; the payment application will determine whether to complete the payment transaction according to the authorization result. If the authorization result is authorized payment, the transaction is allowed. If the authorization result is unauthorized payment, the transaction is refused, thus preventing the bank card from being used by others.
[0055] In addition, in actual applications, to prevent payment fraud, the bank card can also be locked when the PIN code is verified failed multiple times. Specifically: in the case where the authorization results of the PIN code continuously exceed the preset number of times and are all unauthorized payments, that is, when the authorization results of multiple PIN codes continuously input by the user are all unauthorized payments, an automatic locking operation is performed on the bank card, thus temporarily prohibiting the use of the bank card for transactions, preventing the bank card from being used by others, and ensuring the security of transactions.
[0056] In summary, the smart POS terminal secure payment system and secure payment method provided by the present invention: (1) Based on the Android-Linux+Protected VM (AVF)+SE system architecture, it supports GMS+PCI PTS certification. Among them, for the security-related parts: the security-related business logic is executed in the Microdroid module in the Protected VM module; for sensitive interfaces such as the PIN input interface, the REE module is only responsible for rendering, and after rendering, the business logic of the PIN input is handed over to the Protected VM module or the SE module for processing; key management, PIN input and encryption, security algorithms, etc. are implemented in the SE module (i.e., SE chip). In general, the present invention implements the security-related parts through a secure environment (i.e., Protected VM module + SE module) to pass the PCI PTS certification. For the non-security-related parts: try not to change the Android native system, for example, retain the native ADB (do not cut instructions), retain the original APK signature and signature verification mechanism, etc., to pass the GMS certification. Therefore, the Android-Linux+Protected VM (AVF)+SE system architecture of the present invention supports GMS+PCI PTS certification. (2) The smart POS terminal security payment system of the present invention is a system architecture (Android-Linux+Protected VM+SE) that supports GMS+PCI PTS certification at the same time, which is suitable for Android smart POS terminals. The present invention executes the security-related parts in the ProtectedVM (AVF)+SE security environment, and the non-security-related parts in the Android-Linux open source environment. At present, the smart POS terminal security payment systems on the market basically use Trust Zone technology (TEE environment), which has poor flexibility and low development efficiency. Therefore, the system architecture of this patent uses the Protected VM module to replace the TEE module, which greatly improves flexibility and development efficiency. It should be noted that the above-mentioned AVF (Android Virtualization Framework) is the Android virtualization framework.
[0057] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent transformations made using the contents of the present invention's specification and drawings, or directly or indirectly applied in related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. An intelligent POS terminal secure payment system, characterized in that, It includes a secure world module and a non-secure world module. The non-secure world module includes an REE module, and the REE module is used to execute non-confidential business logics and interface rendering. The interface rendering includes secure interface rendering and non-secure interface rendering. The secure world module includes a Protected VM module and an SE module. The Protected VM module is used to execute a first secure service that does not involve interface rendering, and the SE module is used to execute a second secure service. Among them, the REE module is communicatively connected to the Protected VM module, and the SE module is communicatively connected to the Protected VM module or the REE module.
2. The intelligent POS terminal secure payment system according to claim 1, wherein The REE module includes a first application module and an application program module. The first application module includes a system service module and an AIDL service module. The system service module is communicatively connected to the application program module and the AIDL service module respectively.
3. The intelligent POS terminal secure payment system according to claim 2, characterized in that, The Protected VM module includes a Microdroid module. The Microdroid module includes a second application module. The second application module is communicatively connected to the system service module, and the second application module is used to execute a first secure service that does not involve interface rendering.
4. The intelligent POS terminal security payment system according to claim 3, characterized in that, The SE module is communicatively connected to the second application module or the system service module.
5. The intelligent POS terminal secure payment system according to claim 3, characterized in that It further includes a security monitor module, and the security monitor module is responsible for managing the switching between the secure world module and the non-secure world module.
6. The intelligent POS terminal secure payment system according to claim 1, characterized in that, The second secure service includes key management, certificate management, personal identification number input verification, and personal identification number encryption operation. The key management includes the storage of keys. The keys include finance-related keys and non-finance-related keys. The certificate management includes the storage of certificates. The certificates include finance-related certificates and non-finance-related certificates.
7. A secure payment method for an intelligent POS terminal secure payment system, which is applied to the intelligent POS terminal secure payment system according to any one of claims 1-6, characterized in that, It includes the following steps: S1: After the user inputs a transaction amount into the payment application program in the REE module, the REE module renders and displays a PIN code input interface. S2: The PIN code input interface receives the PIN code input by the user and directly passes the PIN code to the SE module or passes the PIN code to the SE module through the Microdroid module. S3: The SE module encrypts the PIN code and passes the encrypted PIN code to a bank card or a background payment system to determine whether the payment transaction is completed.
8. The secure payment method according to claim 7, wherein In step S1, the REE module renders and displays a PIN code input interface, including: The payment application program starts a personal identification number input module in the REE module through an interface. After successful startup, the personal identification number input module renders the PIN code input interface.
9. The secure payment method according to claim 7, wherein In step S3, passing the encrypted PIN code to a bank card or a background payment system to determine whether the payment transaction is completed, including: After receiving the encrypted PIN code, the bank card decrypts and verifies the encrypted PIN code, generates an authorization result, and sends the authorization result to the payment application; The payment application determines whether to complete the payment transaction according to the authorization result.
10. The secure payment method according to claim 8, wherein, In step S3, the encrypted PIN code is passed to the bank card or the background payment system to determine whether to complete the payment transaction, including: The SE module returns the encrypted PIN code to the payment application through the personal identification number input module; The payment application then uploads the encrypted PIN code to the background payment system. The background payment system online verifies the authorization result of the PIN input and sends the authorization result to the payment application; The payment application determines whether to complete the payment transaction according to the authorization result.