Financial equipment encryption method based on mobile terminal

By using mobile terminals as key determination entities and utilizing double encryption and active security interruption mechanisms, the problems of financial devices being easily tampered with and having limited processing capabilities are solved, thereby improving the security and controllability of encryption.

CN120751375AActive Publication Date: 2025-10-03GUANGDONG PRODATA ELECTRONICS CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511236125.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-10-03
Estimated Expiration
2045-09-01

AI Technical Summary

Technical Problem

In the existing technology, financial devices are easily tampered with and attacked by hardware because they cannot be moved, and their processing capabilities are limited, resulting in reduced encryption timeliness and security.

Method used

The mobile terminal is used as the key determination subject, and the channel security is confirmed by decrypting the encrypted information sent by the financial device, and communication is established. Double encryption and active security interruption mechanism are used to control the issuance of communication permissions.

Benefits of technology

It effectively improves the security and controllability of encryption, avoids cracking caused by the immobility of financial devices, and improves the security and verification efficiency of encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751375A_ABST
    Figure CN120751375A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of financial equipment encryption, in particular to a financial equipment encryption method based on a mobile terminal, which comprises the following steps: the mobile terminal initiates a communication request, and the financial equipment responds to the communication request, acquires a corresponding financial equipment key and sends response data to the mobile terminal by utilizing shallow communication; responding to the response data, calling a corresponding mobile terminal key, and encrypting the mobile terminal key to form encrypted information; the encrypted information is sent to the corresponding financial equipment, and the financial equipment performs secondary encryption on the encrypted information by using the financial equipment key, forms communication agreement information and feeds back the communication agreement information to the mobile terminal; verifying the communication agreement information, and building deep communication according to a verification result; according to the method, the mobile terminal is utilized to open or close the corresponding communication, and the decryption permission is issued to the mobile terminal, so that a cracking behavior generated by utilizing the characteristic that financial equipment cannot move is effectively avoided, and the encryption security is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of financial device encryption, and in particular to a financial device encryption method based on a mobile terminal. Background Art

[0002] Mobile terminals such as mobile phones and computers are deeply integrated into our daily production and life. The current encryption methods for financial devices based on mobile terminals mainly include static symmetric encryption, device fingerprint technology and hardware-level security architecture.

[0003] However, static encryption is simple to implement but vulnerable to replay attacks, and hardware-level security architecture is costly.

[0004] Chinese Patent Authorization Announcement No. CN113537982B discloses a security verification method, apparatus, device, and storage medium for financial devices, belonging to the field of verification and testing technology. The method includes: obtaining relevant verification value information; processing it and converting it into binary content to be encrypted; based on a quantum encryption algorithm, polarizing the encrypted content according to a preset polarization direction to generate a first ciphertext; decrypting the first ciphertext based on a quantum decryption algorithm; obtaining a verification value and performing a first verification; generating a transaction voucher image; generating a first encrypted image based on a chaotic encryption algorithm; decrypting the first encrypted image based on a chaotic decryption algorithm, obtaining a first decrypted image, and performing a second verification. This invention directly verifies the security of financial devices, and by verifying both data and images separately, it helps to ensure the security and performance stability of financial devices.

[0005] However, the above method has the following problems: in scenarios where encryption is used for verification, etc., financial devices are used as the judgment subject. Because they cannot be moved, they are easier to break from the outside by tampering with the hardware. At the same time, the processing power of the financial devices themselves is limited, and it is difficult to handle scenarios such as decryption that require processing large amounts of data, which in turn affects the timeliness and security of encryption. Summary of the Invention

[0006] To this end, the present invention provides a financial device encryption method based on a mobile terminal to overcome the problem in the prior art of using financial devices as the judgment subject. Because the financial device itself cannot be moved, it is easier to break it from the outside by means of tampering with the hardware. At the same time, the processing power of the financial device itself is limited, and it is difficult to undertake scenarios such as decryption that require processing large amounts of data, which in turn leads to reduced encryption security.

[0007] To achieve the above-mentioned object, the present invention provides, on the one hand, a financial device encryption method based on a mobile terminal, which is provided with a key library. In the communication between the mobile terminal and the financial device, a paired financial device key and a mobile terminal key corresponding to the financial device key are selected; For a single mobile terminal, it includes: Initiate a communication request and select the corresponding financial device to establish shallow communication; The financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using the shallow communication; In response to the response data, retrieve a corresponding mobile terminal key, and encrypt the mobile terminal key to form encrypted information; The encrypted information is sent to the corresponding financial device, and the financial device uses the financial device key to re-encrypt the encrypted information, and forms a communication consent message and feeds it back to the mobile terminal; Verify the communication consent information and establish deep communication based on the verification result; wherein, in response to the communication consent information being verified, the mobile terminal establishes deep communication with the financial device; In response to the communication consent information failing to pass verification, the mobile terminal disconnects the shallow communication.

[0008] Furthermore, for a single communication request, when the mobile terminal broadcasts the communication request, financial devices that have not established shallow communication and / or deep communication with any mobile terminal respond to the communication request and form a response queue; The mobile terminal establishes the shallow communication in the order in the response queue, or designates a financial device.

[0009] Furthermore, for a single communication request, when the financial device responds to the communication request, it generates corresponding request information and sends it to the key library; The key library records the request information and retrieves the financial device key corresponding to the request information in the key library, as well as the retrieval information; Wherein, the request information is the corresponding information formed by the time of establishing the shallow communication; The retrieval information and the time when the key library receives the request information form corresponding information.

[0010] Furthermore, for a single communication request, when the shallow communication is established, the mobile terminal generates corresponding request information and sends it to the key library to retrieve the mobile terminal key; In response to receiving the response data, the key library sends the corresponding mobile terminal key and the retrieval information to the mobile terminal; The mobile terminal uses the retrieved information as an encryption key and encrypts the mobile terminal key to form the encrypted information.

[0011] Furthermore, when the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using the shallow communication, The financial device performs secondary encryption on the encrypted information according to the financial device key, and generates corresponding communication consent information; The financial device sends communication consent information to the mobile terminal using the shallow communication.

[0012] Further, when the mobile terminal obtains the corresponding communication consent information, the mobile terminal uses the request information and decrypts the communication consent information, and compares whether the decrypted information includes the mobile terminal key and the corresponding retrieval information; If the mobile terminal key does not match the retrieved information, or the mobile terminal key is inaccurate, or the retrieved information is inaccurate, The mobile terminal disconnects the shallow communication.

[0013] Furthermore, for a single communication request, when establishing the shallow communication, if the mobile terminal actively cuts off the shallow communication, the financial device transmits the cut-off information to the key library.

[0014] Furthermore, when the mobile terminal obtains the communication consent information of the single communication, the key library discards the mobile terminal key and the financial device key corresponding to the communication request for one issuance cycle; The issuance cycle is related to time, and in a single issuance cycle, the key library consumes no more than 70% of the total mobile terminal keys and financial device keys.

[0015] On the other hand, the present invention also provides a mobile terminal-based financial device encryption method for a single financial device, comprising: Broadcast reception request and detect mobile terminals entering the link range; Respond to the communication request sent by the mobile terminal, establish shallow communication with the mobile terminal and send response data; Stop broadcasting the reception request and obtain the financial device key; encrypting data received through shallow communication using the financial device key and returning the data to the shallow communication; In response to a shallow communication disconnection, broadcasting the receive request, or, In response to the deep communication request, corresponding deep communication is established with the corresponding mobile terminal.

[0016] Further, when the financial device responds to the disconnection of the shallow communication, the corresponding deep communication is disconnected; In response to the disconnection of the deep communication, the financial device disconnects the corresponding shallow communication.

[0017] Compared with the existing technology, the beneficial effect of the present invention is that it uses the mobile terminal as the judgment subject of the key, confirms whether the channel is secure by decrypting the encrypted information sent by the financial device, and establishes communication based on the confirmation result, thereby effectively avoiding the problem of device insecurity caused by the financial device's judgment of the encryption behavior. At the same time, the corresponding communication is opened or closed by the mobile terminal, and the decryption authority is issued to the mobile terminal, which effectively avoids the cracking behavior caused by the immobility of the financial device, thereby effectively improving the security of encryption.

[0018] Furthermore, by setting priorities, financial devices and mobile terminals are matched with each other. At the same time, by establishing shallow communication, other financial devices that can be connected to the mobile terminal are excluded, so that the encryption target can be clear. At the same time, the problem of financial device memory overflow caused by repeated connection to financial devices using several different mobile terminals is effectively avoided. While improving verification efficiency, the security of encryption is further improved.

[0019] Furthermore, the mobile terminal controls whether to maintain a connection with the financial device by controlling shallow communications. At the same time, the financial device chooses whether to maintain a connection with the mobile terminal by determining whether shallow communications are maintained. This effectively avoids the use of hardware to crack the financial device while improving the controllability of encrypted communications, thereby further improving the security of encryption.

[0020] Furthermore, the introduction of an active security interrupt mechanism and dual encryption verification enhances attack resistance, while simultaneously balancing security and system load through key issuance cycle limits. This effectively improves security, flexibility, and robustness, surpassing traditional static encryption or one-way authentication methods, making it particularly suitable for high-risk mobile financial interaction scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 This is an encryption flow chart of the mobile terminal of the present invention; Figure 2 This is the encryption flow chart of the financial device of the present invention; Figure 3 This is a diagram of the encryption process of an embodiment of the present invention. DETAILED DESCRIPTION

[0022] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.

[0023] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0024] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside", and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.

[0025] Furthermore, it should be noted that, in the description of the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0026] A financial device encryption method based on a mobile terminal is provided with a key library. In the communication between the mobile terminal and the financial device, a paired financial device key and a mobile terminal key corresponding to the financial device key are selected; See also Figure 1 As shown, it is an encryption flow chart of the mobile terminal of the present invention, including: Step Sy1: Initiate a communication request and select a corresponding financial device to establish shallow communication; Step Sy2: The financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using shallow communication; Step Sy3, in response to the response data, retrieve the corresponding mobile terminal key, and encrypt the mobile terminal key to form encrypted information; Step Sy4: Send the encrypted information to the corresponding financial device. The financial device uses the financial device key to re-encrypt the encrypted information, and forms communication consent information and feeds it back to the mobile terminal. Step Sy5: verify the communication consent information and establish deep communication based on the verification result; Wherein, in response to the communication consent information being verified, the mobile terminal establishes deep communication with the financial device; In response to the communication consent information not passing the verification, the mobile terminal disconnects the shallow communication.

[0027] Please cooperate Figure 1 See Figure 2As shown, it is an encryption flow chart of the financial device of the present invention, including: Step Sj1, broadcast receiving request and detect mobile terminals entering the link range; Step Sj2, responding to the communication request sent by the mobile terminal, establishing shallow communication with the mobile terminal and sending response data; Step Sj3, stop receiving the requested broadcast and obtain the financial device key; Step Sj4: encrypt the data received through shallow communication using the financial device key and return it to the shallow communication; Step Sj5, in response to the shallow communication disconnection, broadcast a receive request; In response to the deep communication request, corresponding deep communication is established with the corresponding mobile terminal.

[0028] Specifically, in step Sj5, the financial device responds to the disconnection of the shallow communication and disconnects the corresponding deep communication; The financial device responds to the disconnection of the deep communication and disconnects the corresponding shallow communication.

[0029] By using the mobile terminal as the key determination subject, the security of the channel is confirmed by decrypting the encrypted information sent by the financial device, and communication is established based on the confirmation result, thereby effectively avoiding the problem of device insecurity caused by the financial device's judgment on the encryption behavior. At the same time, the corresponding communication is opened or closed by the mobile terminal, and the decryption authority is issued to the mobile terminal, which effectively avoids the cracking behavior caused by the immobility of the financial device, thereby effectively improving the security of encryption.

[0030] In practice, encryption can be performed as follows in the following scenarios: The mobile terminal broadcasts a request, the POS terminal responds and establishes shallow communication (such as Bluetooth / NFC).

[0031] Code logic (mobile terminal side): import uuid def initiate_connection(): #Generate communication request ID (simulate broadcast) request_id = str(uuid.uuid4()) print(f"[Mobile terminal] initiates communication request, request ID: {request_id}") #Simulate the selection of the first POS machine that responds (maybe filtered by signal strength) selected_pos = "POS_001" print(f"[Mobile terminal] Select financial device: {selected_pos}") return selected_pos pos_device = initiate_connection() The POS machine obtains its own device key (pos_key) from the key library and returns response data (including key identification) through shallow communication.

[0032] Code logic (POS machine side): class POSDevice: def __init__(self): self.pos_key = "K_POS_123" # Simulate the key obtained from the keystore def respond_to_request(self, request_id): print(f"[POS machine] received request {request_id}, returned response data (including key identifier)") return { "status": "ACK", "pos_key_id": "K_POS_123" # Do not transmit the key directly, only transmit the identifier } pos = POSDevice() response_data = pos.respond_to_request("REQ_123") The mobile terminal obtains the corresponding mobile_key from the key library according to the pos_key_id in the response data and encrypts it with the timestamp.

[0033] Code logic (mobile terminal side): from datetime import datetime import hashlib def encrypt_mobile_key(pos_key_id): #Simulate obtaining the mobile terminal key paired with the POS key from the keystore mobile_key = "K_MOBILE_456" #Generate call information (timestamp + random number) timestamp = datetime.now().strftime("%Y%m%d%H%M%S") nonce = str(uuid.uuid4())[:8] retrieval_info = f"{timestamp}_{nonce}" # Encrypt mobile_key with the retrieved information (example: simple hash) encrypted_key = hashlib.sha256(f"{mobile_key}_{retrieval_info}".encode()).hexdigest() print(f"[Mobile terminal] Encrypted mobile key: {encrypted_key}") return { "encrypted_key": encrypted_key, "retrieval_info": retrieval_info } encrypted_data = encrypt_mobile_key(response_data["pos_key_id"]) The POS machine uses pos_key to re-encrypt the encrypted mobile_key and generate communication consent information.

[0034] Code logic (POS machine side): def generate_agreement(encrypted_data, pos_key): # Simulate secondary encryption (may actually use AES, etc.) agreement_info = hashlib.sha256( f"{encrypted_data['encrypted_key']}_{pos_key}".encode() ).hexdigest() print(f"[POS machine] Generate communication consent information: {agreement_info}") return { "agreement": agreement_info, "retrieval_info": encrypted_data["retrieval_info"] } agreement_data = generate_agreement(encrypted_data, pos.pos_key) The mobile terminal verifies whether the communication consent information matches the locally calculated expected value.

[0035] Code logic (mobile terminal side): def verify_agreement(agreement_data, mobile_key): # Locally recalculate expected values expected_agreement = hashlib.sha256( f"{encrypted_data['encrypted_key']}_{mobile_key}".encode() ).hexdigest() # Verify consistency if agreement_data["agreement"] == expected_agreement: print("[Mobile terminal] Verification passed, deep communication established!") return True else: print("[Mobile terminal] Verification failed, disconnected!") return False is_verified = verify_agreement(agreement_data, "K_MOBILE_456") It is not difficult to understand that the above examples are limited to the connection code examples between the APP and several corresponding POS machines. In this solution, the above python code may not be used to complete the encryption corresponding to the solution described in this application.

[0036] Specifically, for a single communication request, in step Sy1, the mobile terminal broadcasts the communication request; The financial device that has not established shallow communication and / or deep communication with any mobile terminal responds to the communication request and forms a response queue; The mobile terminal responds in the order in the queue, or specifies a financial device to establish shallow communication.

[0037] Specifically, for a single communication request, in step Sy2, the financial device responds to the communication request, generates corresponding request information and sends it to the key library; The key library records the request information and retrieves the financial device key corresponding to the request information from the key library, as well as the retrieval information; The request information is the corresponding information formed at the time of establishing shallow communication; The correspondence between the retrieved information and the time when the key library receives the request information.

[0038] By setting priorities, financial devices and mobile terminals are matched with each other. At the same time, by establishing shallow communication, other financial devices that can be connected to the mobile terminal are excluded, so that the encryption target can be clear. At the same time, it effectively avoids the problem of financial device memory overflow caused by repeated connection to financial devices using several different mobile terminals. While improving verification efficiency, it further improves the security of encryption.

[0039] In implementation, the following operations and outputs can be performed: The mobile terminal sends a broadcast request, and all nearby unconnected POS terminals respond, forming a queue.

[0040] The mobile terminal selects a POS machine based on strategies (such as signal strength and queue order) to establish shallow communication.

[0041] import uuid from datetime import datetime #Simulate mobile terminal broadcast request def broadcast_request(): request_id = f"REQ_{uuid.uuid4().hex[:6]}" print(f"[Mobile terminal] Broadcast communication request, ID: {request_id}") return request_id #Simulate the response of a nearby POS machine (unconnected device) def get_available_pos_devices(): return ["POS_001", "POS_002", "POS_003"] # Returns a list of available POS machines # Mobile terminal selection strategy (Example: select the first device) def select_pos_device(available_pos_list): selected_pos = available_pos_list[0] # Actual possible selection based on RSSI (signal strength) print(f"[Mobile terminal] Select device: {selected_pos}") return selected_pos # Execution process request_id = broadcast_request() available_pos_list = get_available_pos_devices() selected_pos = select_pos_device(available_pos_list) The output is: [Mobile terminal] Broadcast communication request, ID: REQ_a1b2c3 [Mobile Terminal] Select device: POS_001 at this time, After receiving the request, the POS machine generates request information (including timestamp) and sends it to the key library.

[0042] The keystore records the request time and returns the financial device key and retrieval information (timestamp binding).

[0043] class KeyVault: def __init__(self): # Simulate the key stored in the keystore (POS_KEY -> corresponding device key) self.key_store = { "POS_001": {"key": "K_POS_123", "paired_mobile_key": "K_MOBILE_456"}, "POS_002": {"key": "K_POS_789", "paired_mobile_key": "K_MOBILE_012"}, } def request_key(self, pos_id, request_time): print(f"[Keystore] Received key request from POS machine {pos_id}, time: {request_time}") if pos_id in self.key_store: #Simulate information retrieval (request time + random number) retrieval_info = f"RET_{request_time}_{uuid.uuid4().hex[:4]}" print(f"[Keystore] Returns financial device key and retrieval information: {retrieval_info}") return { "pos_key": self.key_store[pos_id]["key"], "retrieval_info": retrieval_info } else: raise Exception("POS device not registered") # POS machine logic class POSDevice: def __init__(self, pos_id): self.pos_id = pos_id self.key_vault = KeyVault() def respond_to_request(self, request_id): request_time = datetime.now().strftime("%Y%m%d%H%M%S") # request time print(f"[POS machine {self.pos_id}] responds to request {request_id} and applies for a key from the keystore...") key_data = self.key_vault.request_key(self.pos_id, request_time) return { "status": "ACK", "pos_key_id": key_data["pos_key"], # Returns the key identifier (not the key itself) "retrieval_info": key_data["retrieval_info"] # Retrieval information } # Execution process pos = POSDevice("POS_001") response_data = pos.respond_to_request(request_id) The output is: [POS_001] Responds to request REQ_a1b2c3 and requests a key from the keystore... [Keystore] Received key request from POS machine POS_001, time: 20240529120000 [Keystore] Returns financial device key and retrieval information: RET_20240529120000_abcd See also Figure 3 As shown in FIG, it is an encryption process diagram of an embodiment of the present invention, in which: For a single communication request, in step Sy3, in response to the establishment of shallow communication, the mobile terminal generates a corresponding request message and sends it to the key library to retrieve the mobile terminal key; In response to the completion of step Sy2, the key library sends the corresponding mobile terminal key and the retrieval information to the mobile terminal; The mobile terminal uses the retrieved information as an encryption key and encrypts the mobile terminal key to form encrypted information.

[0044] Specifically, in step Sy4, when the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using shallow communication, The financial device re-encrypts the encrypted information according to the financial device key and generates corresponding communication consent information; The financial device uses shallow communication to send communication consent information to the mobile terminal.

[0045] The mobile terminal controls whether to maintain a connection with the financial device by controlling shallow communications. At the same time, the financial device chooses whether to maintain a connection with the mobile terminal by determining whether shallow communications are maintained. This effectively avoids the use of hardware to crack the financial device while improving the controllability of encrypted communications, thereby further improving the security of encryption.

[0046] In implementation, when the mobile terminal retrieves the key and encrypts it, it includes: The mobile terminal requests mobile_key from the keystore.

[0047] The keystore returns mobile_key + retrieval information (bound to timestamp).

[0048] The mobile terminal encrypts mobile_key with the retrieved information to form encrypted information.

[0049] import hashlib from datetime import datetime class MobileTerminal: def __init__(self): self.key_vault = KeyVault() # Reference the previous keystore def request_mobile_key(self, pos_key_id, retrieval_info): # Get the mobile_key paired with the POS key from the keystore key_data = self.key_vault.get_mobile_key(pos_key_id) mobile_key = key_data["mobile_key"] # Encrypt mobile_key with the retrieved information (example: AES encryption, simplified to hash here) encrypted_key = hashlib.sha256( f"{mobile_key}_{retrieval_info}".encode() ).hexdigest() print(f"[Mobile terminal] Encrypt mobile_key with retrieved information: {encrypted_key}") return encrypted_key # Execution flow (follow the output of step Sy2) mobile = MobileTerminal() encrypted_data = mobile.request_mobile_key( pos_key_id=response_data["pos_key_id"], retrieval_info=response_data["retrieval_info"] ) [Mobile terminal] Encrypt mobile_key with the retrieved information: a1b2c3... (SHA256 hash value) Specifically, in step Sy5, when the mobile terminal obtains the corresponding communication consent information, the mobile terminal uses the request information and decrypts the communication consent information, and compares whether the decrypted information includes the mobile terminal key and the corresponding retrieval information; If the mobile terminal key does not match the retrieved information, or the mobile terminal key is inaccurate, or the retrieved information is inaccurate, The mobile terminal disconnects the shallow communication.

[0050] Specifically, for a single communication request, in step Sy5, if the mobile terminal actively cuts off the shallow communication, the financial device will transmit the cut-off information to the key library.

[0051] Specifically, when a single communication request in step Sy4 is completed, the key library discards the mobile terminal key and financial device key corresponding to the communication request for one issuance cycle; Among them, the issuance cycle is related to time, and in a single issuance cycle, the mobile terminal keys and financial device keys consumed by the key library shall not exceed 70% of the total.

[0052] See Table 1 for an example keystore:

[0053] Financial Device ID Financial device keys Mobile terminal key Whether to abandon Pairing status POS_001 A3F7E29B1C8D5E0F4A9B6C3D2E1F8A7 5B8D3E0F1A2C7D9E4F6B8A9C0D1E2F3 no efficient POS_002 9C4D2E8F1A0B3C6D5E7F8A9B0C1D2E3 F6E1D8C9B7A0F3E2D4C5B6A7D8E9F0 no efficient POS_003 2B5A8D0E7F1C3D9E6F4A7B8C9D0E1F2 3E9F0A8B7C6D5E4F3A2B1C0D9E8F7 no efficient POS_004 D1E6F3A8B9C0D7E2F5A4B3C2D8E1F0 7C8A9B0C1D2E3F4A5B6C7D8E9F0A1 yes Expired POS_005 4F7E2A9B8C1D0E3F6A5B4C3D2E1F8A B0C1D2E3F4A5B6C7D8E9F0A1B2C3 no efficient POS_006 E3F8A9B0C1D2E7F4A5B6C3D9E0F1A2 6D7E8F9A0B1C2D3E4F5A6B7C8D9E no efficient POS_007 1A2B3C4D5E6F7A8B9C0D1E2F3A4B5C 9F0E1D2C3B4A5F6E7D8C9B0A1F2E yes Deprecated POS_008 6C7D8E9F0A1B2C3D4E5F6A7B8C9D0E 3A4B5C6D7E8F9A0B1C2D3E4F5A6B no efficient POS_009 F2A3B4C5D6E7F8A9B0C1D2E3F4A5B 8C9D0E1F2A3B4C5D6E7F8A9B0C1D no efficient POS_010 0D1E2F3A4B5C6D7E8F9A0B1C2D3E4F 5E6F7A8B9C0D1E2F3A4B5C6D7E8F yes Deprecated POS_011 9A0B1C2D3E4F5A6B7C8D9E0F1A2B3 2C3D4E5F6A7B8C9D0E1F2A3B4C5 no efficient POS_012 4B5C6D7E8F9A0B1C2D3E4F5A6B7C8 D9E0F1A2B3C4D5E6F7A8B9C0D1E no efficient POS_013 3E4F5A6B7C8D9E0F1A2B3C4D5E6F7 A8B9C0D1E2F3A4B5C6D7E8F9A0B no efficient POS_014 2D3E4F5A6B7C8D9E0F1A2B3C4D5E6 F7A8B9C0D1E2F3A4B5C6D7E8F9A yes Expired POS_015 1C2D3E4F5A6B7C8D9E0F1A2B3C4D5 E6F7A8B9C0D1E2F3A4B5C6D7E8F no efficient Of the 15 key pairs mentioned above, 4 are discarded and expired, and 11 are usable. The consumption is less than 70%, and the key library does not need to be reset.

[0054] The introduction of an active security interrupt mechanism and dual encryption verification enhances attack resistance, while simultaneously balancing security and system load through key issuance cycle limits. This effectively improves security, flexibility, and robustness, surpassing traditional static encryption or one-way authentication modes, making it particularly suitable for high-risk mobile financial interaction scenarios.

[0055] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0056] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A mobile terminal-based financial device encryption method, comprising a key library, wherein during communication between the mobile terminal and the financial device, a paired financial device key and a mobile terminal key corresponding to the financial device key are selected; It is characterized in that For a single mobile terminal, it includes: Initiate a communication request and select the corresponding financial device to establish shallow communication; The financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using the shallow communication; In response to the response data, retrieve a corresponding mobile terminal key, and encrypt the mobile terminal key to form encrypted information; The encrypted information is sent to the corresponding financial device, and the financial device uses the financial device key to re-encrypt the encrypted information, and forms a communication consent message and feeds it back to the mobile terminal; Verify the communication consent information and establish deep communication based on the verification result; wherein, in response to the communication consent information being verified, the mobile terminal establishes deep communication with the financial device; In response to the communication consent information failing to pass verification, the mobile terminal disconnects the shallow communication.

2. The mobile terminal-based financial device encryption method according to claim 1, characterized in that: For a single communication request, when the mobile terminal broadcasts the communication request, financial devices that have not established shallow communication and / or deep communication with any mobile terminal respond to the communication request and form a response queue; The mobile terminal establishes the shallow communication in the order in the response queue, or designates a financial device.

3. The mobile terminal-based financial device encryption method according to claim 2, characterized in that: For a single communication request, when the financial device responds to the communication request, it generates corresponding request information and sends it to the key library; The key library records the request information and retrieves the financial device key corresponding to the request information in the key library, as well as the retrieval information; Wherein, the request information is the corresponding information formed by the time of establishing the shallow communication; The retrieval information and the time when the key library receives the request information form corresponding information.

4. The mobile terminal-based financial device encryption method according to claim 3, characterized in that: For a single communication request, when the shallow communication is established, the mobile terminal generates a corresponding request message and sends it to the key library to retrieve the mobile terminal key; In response to receiving the response data, the key library sends the corresponding mobile terminal key and the retrieval information to the mobile terminal; The mobile terminal uses the retrieved information as an encryption key and encrypts the mobile terminal key to form the encrypted information.

5. The mobile terminal-based financial device encryption method according to claim 4, characterized in that: When the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using the shallow communication, The financial device performs secondary encryption on the encrypted information according to the financial device key, and generates corresponding communication consent information; The financial device sends communication consent information to the mobile terminal using the shallow communication.

6. The mobile terminal-based financial device encryption method according to claim 5, characterized in that: When the mobile terminal obtains the corresponding communication consent information, the mobile terminal uses the request information and decrypts the communication consent information, and compares whether the decrypted information includes the mobile terminal key and the corresponding retrieval information; If the mobile terminal key does not match the retrieved information, or the mobile terminal key is inaccurate, or the retrieved information is inaccurate, The mobile terminal disconnects the shallow communication.

7. The mobile terminal-based financial device encryption method according to claim 5, characterized in that: For a single communication request, when establishing the shallow communication, if the mobile terminal actively cuts off the shallow communication, the financial device will transmit the cut-off information to the key library.

8. The mobile terminal-based financial device encryption method according to claim 6 or 7, characterized in that: When the mobile terminal obtains the communication consent information of the single communication, the key library discards the mobile terminal key and the financial device key corresponding to the communication request for one issuance cycle; The issuance cycle is related to time, and in a single issuance cycle, the key library consumes no more than 70% of the total mobile terminal keys and financial device keys.

9. A mobile terminal-based financial device encryption method, comprising a key library, wherein during communication between the mobile terminal and the financial device, a paired financial device key and a mobile terminal key corresponding to the financial device key are selected; It is characterized by: For a single financial device, this includes: Broadcast reception request and detect mobile terminals entering the link range; Respond to the communication request sent by the mobile terminal, establish shallow communication with the mobile terminal and send response data; Stop broadcasting the reception request and obtain the financial device key; encrypting data received through shallow communication using the financial device key and returning the data to the shallow communication; In response to a shallow communication disconnection, broadcasting the receive request, or, In response to the deep communication request, corresponding deep communication is established with the corresponding mobile terminal.

10. The mobile terminal-based financial device encryption method according to claim 9, characterized in that: When the financial device responds to the disconnection of the shallow communication, disconnecting the corresponding deep communication; In response to the disconnection of the deep communication, the financial device disconnects the corresponding shallow communication.

Citation Information

Patent Citations

  • Security verification methods, devices, equipment and storage media for financial devices

    CN113537982B

  • User authentication module setting method and system

    CN101958026A

  • Communication method, encryption method and device for POS and mobile terminal and POS

    CN103929297A

  • Security authentication method and system for mobile financial equipment, terminal and storage medium

    CN107104968A

  • Tamper-proof method and device for POS machine

    CN117789379A