Mobile terminal-based financial device encryption method

By establishing a key store between the mobile terminal and the financial device, and using the mobile terminal for dual encryption verification and communication control, the problems of financial devices being easily tampered with and having insufficient processing capabilities are solved, thereby improving encryption security and efficiency, and making it suitable for high-risk mobile financial interaction scenarios.

CN120751375BActive Publication Date: 2026-03-24GUANGDONG PRODATA ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, financial devices are vulnerable to hardware attacks due to their immobility and limited processing capabilities, making them unable to handle large amounts of data decryption, resulting in insufficient encryption security and timeliness.

Method used

By establishing a key store between the mobile terminal and financial equipment, and using the mobile terminal as the key determination subject, dual encryption verification and shallow and deep communication are performed to control communication permissions and avoid hardware tampering and processing capability limitations.

Benefits of technology

It enhances encryption security and controllability, effectively avoids hardware tampering attacks, improves encryption security and efficiency, and is suitable for high-risk mobile financial interaction scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751375B_ABST
    Figure CN120751375B_ABST
Patent Text Reader

Abstract

The application relates to the field of financial equipment encryption technology, in particular to a financial equipment encryption method based on a mobile terminal, which comprises the following steps: a mobile terminal initiates a communication request, a financial equipment responds to the communication request, acquires corresponding financial equipment keys, and sends response data to the mobile terminal by using shallow communication; in response to the response data, corresponding mobile terminal keys are called and encrypted to form encrypted information; the encrypted information is sent to the corresponding financial equipment, the financial equipment performs secondary encryption on the encrypted information by using the financial equipment keys, forms communication consent information, and feeds back to the mobile terminal; the communication consent information is verified, and deep communication is built according to the verification result; the mobile terminal is used to open or close corresponding communication, and the decryption permission is distributed to the mobile terminal, so that the cracking behavior caused by the immobility of the financial equipment is effectively avoided, and the security of the encryption is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial device encryption technology, and in particular to a method for encrypting financial devices based on mobile terminals. Background Technology

[0002] Mobile devices such as mobile phones and computers are deeply intertwined with our daily lives and work. Currently, encryption methods for financial devices based on mobile devices mainly include static symmetric encryption, device fingerprinting technology, and hardware-level security architecture.

[0003] However, static encryption is simple to implement but vulnerable to replay attacks, and hardware-level security architectures are costly.

[0004] Chinese Patent Publication No. CN113537982B discloses a security verification method, device, equipment, and storage medium for financial equipment, belonging to the field of verification and testing technology. The method includes: acquiring relevant verification numerical information; processing it and converting it into binary content to be encrypted; based on a quantum encryption algorithm, polarizing the content to be encrypted according to a preset polarization direction to generate first ciphertext; decrypting the first ciphertext based on a quantum decryption algorithm; obtaining a verification value and performing a first verification; generating a transaction certificate image; generating a first encrypted image based on a chaotic encryption algorithm; and decrypting the first encrypted image based on a chaotic decryption algorithm to obtain a first decrypted image and performing a second verification. This invention directly performs security verification on financial equipment, helping to ensure the security and performance stability of financial equipment by verifying both data and images separately.

[0005] However, the above methods have the following problems: In scenarios where encryption is used for verification, financial devices are used as the judgment subject. Because they are immobile, they are relatively easy to be attacked from the outside by means of hardware tampering. At the same time, the processing power of financial devices is limited, making it difficult to handle scenarios that require processing large amounts of data, such as decryption, which leads to problems with the timeliness and security of encryption. Summary of the Invention

[0006] To address this, the present invention provides a method for encrypting financial devices based on mobile terminals, which overcomes the problems in existing technologies where financial devices are used as the judgment subject. Because these devices are immobile, they are easily compromised from the outside by means of hardware tampering. Furthermore, financial devices have limited processing capabilities and cannot handle scenarios that require processing large amounts of data, such as decryption, which leads to a decrease in encryption security.

[0007] To achieve the above objectives, on the one hand, the present invention provides a method for encrypting financial devices based on mobile terminals, which includes a key library, wherein in the communication between the mobile terminal and the financial device, a pair of financial device keys and a mobile terminal key corresponding to the financial device keys are selected.

[0008] For a single mobile terminal, including:

[0009] Initiate a communication request and select the corresponding financial device to establish shallow communication;

[0010] The financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using the shallow communication.

[0011] In response to the response data, the corresponding mobile terminal key is retrieved and encrypted to form encrypted information;

[0012] The encrypted information is sent to the corresponding financial device, which uses the financial device key to encrypt the encrypted information a second time, and forms a communication agreement information and sends it back to the mobile terminal.

[0013] The communication agreement information is verified, and deep communication is established based on the verification results;

[0014] In this process, upon successful verification of the communication consent information, the mobile terminal establishes deep communication with the financial device.

[0015] If the communication consent information fails to be verified, the mobile terminal disconnects the shallow communication.

[0016] Furthermore, for a single communication request, when the mobile terminal broadcasts the communication request, financial devices that have not established shallow and / or deep communication with any mobile terminal respond to the communication request and form a response queue.

[0017] The mobile terminal establishes the shallow communication either in the order of the response queue or by designating a financial device.

[0018] Furthermore, for a single communication request, when the financial device responds to the communication request, it generates corresponding request information and sends it to the key store;

[0019] The keystore records the request information and retrieves the financial device key corresponding to the request information from the keystore, as well as the retrieval information;

[0020] The request information is corresponding information formed by the time the shallow communication was established;

[0021] The information obtained corresponds to the time when the key repository receives the request information.

[0022] Furthermore, for a single communication request, when the shallow communication is established, the mobile terminal generates corresponding request information and sends it to the key store to retrieve the mobile terminal key;

[0023] In response to the receipt of the response data, the key library sends the corresponding mobile terminal key and the retrieval information to the mobile terminal.

[0024] The mobile terminal uses the retrieved information as an encryption key and encrypts the mobile terminal key to form the encrypted information.

[0025] Furthermore, when the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using the shallow communication,

[0026] The financial device performs secondary encryption on the encrypted information based on the financial device key, and forms corresponding communication consent information;

[0027] The financial device uses the shallow communication to send communication consent information to the mobile terminal.

[0028] Furthermore, when the mobile terminal obtains the corresponding communication consent information, the mobile terminal uses the request information and decrypts the communication consent information, and compares whether the decrypted information includes the mobile terminal key and the corresponding retrieval information.

[0029] If the mobile terminal key does not match the retrieved information, or if the mobile terminal key is inaccurate, or if the retrieved information is inaccurate,

[0030] The mobile terminal disconnects from the shallow communication.

[0031] Furthermore, for a single communication request, if the mobile terminal actively disconnects the shallow communication during the establishment of the shallow communication, the financial device will cut off the information transmission to the key store.

[0032] Furthermore, when the mobile terminal obtains the communication consent information for the single communication, the key store discards the mobile terminal key and the financial device key corresponding to the communication request for one issuance cycle.

[0033] The issuance cycle is time-related, and in a single issuance cycle, the key store consumes no more than 70% of the total number of mobile terminal keys and financial device keys.

[0034] On the other hand, the present invention also provides a mobile terminal-based encryption method for a single financial device, comprising:

[0035] Broadcasts receive requests and detects mobile terminals entering the link range;

[0036] Responding to communication requests from the mobile terminal, establishing shallow communication with the mobile terminal and sending response data;

[0037] Stop broadcasting the request to receive data and obtain the financial device key;

[0038] Data received via shallow communication is encrypted using the financial device key and returned to the shallow communication.

[0039] In response to a shallow communication disconnection, broadcast the receive request, or...

[0040] Respond to deep communication requests and establish corresponding deep communication with the corresponding mobile terminal.

[0041] Furthermore, when the financial device responds to the disconnection of the shallow communication, it also disconnects the corresponding deep communication;

[0042] When the deep communication is cut off, the financial device cuts off the corresponding shallow communication.

[0043] Compared with the prior art, the beneficial effects of the present invention are that by using a mobile terminal as the key determination subject, the security of the channel is confirmed by decrypting the encrypted information sent by the financial device, and communication is established based on the confirmation result. This effectively avoids the problem of device insecurity caused by the financial device's determination of encryption behavior. At the same time, by using the mobile terminal to open or close the corresponding communication and granting decryption permission to the mobile terminal, the cracking behavior caused by the immobility of the financial device is effectively avoided, thereby effectively improving the security of encryption.

[0044] Furthermore, by setting priorities, financial devices and mobile terminals are mapped to each other. At the same time, by establishing shallow communication, other financial devices that can connect to the mobile terminal are excluded. This makes the encryption target clear and effectively avoids the problem of financial device memory overflow caused by multiple different mobile terminals repeatedly connecting to financial devices. This improves verification efficiency and further enhances encryption security.

[0045] Furthermore, the mobile terminal controls whether to maintain a connection with the financial device by controlling shallow communication. At the same time, the financial device decides whether to maintain a connection with the mobile terminal by determining whether shallow communication is maintained. This effectively avoids hardware-based attacks on the financial device while improving the controllability of encrypted communication, thereby further enhancing encryption security.

[0046] Furthermore, the introduction of proactive security interruption mechanisms and dual encryption verification enhances resistance to attacks, while simultaneously balancing security and system load through key distribution cycle limitations. This approach outperforms traditional static encryption or one-way authentication methods in terms of significantly improved security, flexibility, and robustness, making it particularly suitable for high-risk mobile financial interaction scenarios. Attached Figure Description

[0047] Figure 1 This is a flowchart illustrating the encryption process of the mobile terminal of the present invention.

[0048] Figure 2 This is a flowchart illustrating the encryption process of the financial device of the present invention.

[0049] Figure 3 This is a diagram illustrating the encryption process in an embodiment of the present invention. Detailed Implementation

[0050] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0051] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0052] It should be noted that in the description of this invention, the terms "upper", "lower", "left", "right", "inner", "outer", etc., which indicate directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.

[0053] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0054] A method for encrypting financial devices based on mobile terminals includes a key library. During communication between the mobile terminal and the financial device, a pair of financial device keys and a mobile terminal key corresponding to the financial device key are selected.

[0055] Please see Figure 1 The diagram shown is an encryption flowchart for the mobile terminal of this invention, including:

[0056] Step Sy1: Initiate a communication request and select the corresponding financial device to establish shallow communication;

[0057] In step Sy2, the financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using shallow communication.

[0058] Step Sy3: Response response data, retrieve the corresponding mobile terminal key, and encrypt the mobile terminal key to form encrypted information;

[0059] Step Sy4: The encrypted information is sent to the corresponding financial device. The financial device uses its key to re-encrypt the encrypted information, generates a communication agreement, and sends it back to the mobile terminal.

[0060] Step Sy5: Verify the communication agreement information and build deep communication based on the verification results;

[0061] Among these, upon successful verification of the response communication consent information, the mobile terminal establishes deep communication with the financial device;

[0062] If the communication consent information fails to be verified, the mobile terminal disconnects the shallow communication.

[0063] Please cooperate. Figure 1 See Figure 2 The diagram shown is a flowchart of the encryption process of the financial device of the present invention, including:

[0064] Step Sj1: Broadcast the request to receive and detect mobile terminals entering the link range;

[0065] Step Sj2: Respond to the communication request sent by the mobile terminal, establish shallow communication with the mobile terminal and send response data;

[0066] Step Sj3: Stop receiving broadcast requests and obtain the financial device key;

[0067] Step Sj4: Encrypt the data received through shallow communication using the financial device key and return it to shallow communication;

[0068] Step Sj5: In response to the shallow communication disconnection, broadcast a receive request;

[0069] Respond to deep communication requests and establish corresponding deep communication with the corresponding mobile terminal.

[0070] Specifically, in step Sj5, the financial device responds to the disconnection of shallow communication by disconnecting the corresponding deep communication.

[0071] Financial devices respond to the disconnection of deep communication by disconnecting the corresponding shallow communication.

[0072] By using a mobile terminal as the key certifier, the security of the channel is confirmed by decrypting the encrypted information sent by the financial device, and communication is established based on the confirmation result. This effectively avoids the problem of device insecurity caused by the financial device's own judgment of encryption behavior. At the same time, by using the mobile terminal to enable or disable the corresponding communication, the decryption permission is granted to the mobile terminal, which effectively prevents cracking behavior caused by the immobility of the financial device, thereby effectively improving the security of encryption.

[0073] In practice, encryption can be performed in the following scenarios as follows:

[0074] The mobile terminal broadcasts a request, and the POS machine responds and establishes shallow communication (such as Bluetooth / NFC).

[0075] Code logic (mobile terminal side):

[0076] import uuid

[0077] def initiate_connection():

[0078] # Generate a communication request ID (simulate broadcast)

[0079] request_id = str(uuid.uuid4())

[0080] print(f"[Mobile terminal] initiated a communication request, request ID: {request_id}")

[0081] # Simulate selecting the first POS machine to respond (in reality, this might be done by filtering based on signal strength).

[0082] selected_pos = "POS_001"

[0083] print(f"[Mobile Terminal] Select Financial Device: {selected_pos}")

[0084] return selected_pos

[0085] pos_device = initiate_connection()

[0086] The POS machine obtains its own device key (pos_key) from the key store and returns response data (including key identifier) ​​through shallow communication.

[0087] Code logic (POS machine side):

[0088] class POSDevice:

[0089] def __init__(self):

[0090] self.pos_key = "K_POS_123" # Simulates obtaining a key from a keystore

[0091] def respond_to_request(self, request_id):

[0092] print(f"[POS machine] received request {request_id} and returned response data (including key identifier)")

[0093] return {

[0094] "status": "ACK",

[0095] "pos_key_id": "K_POS_123" # Only the identifier is transmitted, not the key.

[0096] }

[0097] pos = POSDevice()

[0098] response_data = pos.respond_to_request("REQ_123")

[0099] The mobile terminal retrieves the corresponding mobile key from the key store based on the pos_key_id in the response data and encrypts it with a timestamp.

[0100] Code logic (mobile terminal side):

[0101] import datetime from datetime

[0102] import hashlib

[0103] def encrypt_mobile_key(pos_key_id):

[0104] # Simulate retrieving a mobile terminal key paired with the POS key from a keystore.

[0105] mobile_key = "K_MOBILE_456"

[0106] # Generate retrieval information (timestamp + random number)

[0107] timestamp = datetime.now().strftime("%Y%m%d%H%M%S")

[0108] nonce = str(uuid.uuid4())[:8]

[0109] retrieval_info = f"{timestamp}_{nonce}"

[0110] # Encrypt the mobile_key with the retrieved information (Example: Simple Hash)

[0111] encrypted_key = hashlib.sha256(f"{mobile_key}_{retrieval_info}".encode()).hexdigest()

[0112] print(f"[Mobile Terminal] Encrypted Mobile Key: {encrypted_key}")

[0113] return {

[0114] "encrypted_key": encrypted_key,

[0115] "retrieval_info": retrieval_info

[0116] }

[0117] encrypted_data = encrypt_mobile_key(response_data["pos_key_id"])

[0118] The POS machine uses the pos_key to encrypt the encrypted mobile_key a second time to generate communication consent information.

[0119] Code logic (POS machine side):

[0120] def generate_agreement(encrypted_data, pos_key):

[0121] # Simulate secondary encryption (in practice, AES, etc. may be used)

[0122] agreement_info = hashlib.sha256(

[0123] f"{encrypted_data['encrypted_key']}_{pos_key}".encode()

[0124] ).hexdigest()

[0125] print(f"[POS machine] Generates communication agreement information: {agreement_info}")

[0126] return {

[0127] "agreement": agreement_info,

[0128] "retrieval_info": encrypted_data["retrieval_info"]

[0129] }

[0130] agreement_data = generate_agreement(encrypted_data, pos.pos_key)

[0131] The mobile terminal verifies whether the communication consent information matches the expected value calculated locally.

[0132] Code logic (mobile terminal side):

[0133] def verify_agreement(agreement_data, mobile_key):

[0134] # Recalculate expected value locally

[0135] expected_agreement = hashlib.sha256(

[0136] f"{encrypted_data['encrypted_key']}_{mobile_key}".encode()

[0137] ).hexdigest()

[0138] # Verify consistency

[0139] if agreement_data["agreement"] == expected_agreement:

[0140] print("[Mobile terminal] Authentication successful, deep communication established!")

[0141] return True

[0142] else:

[0143] print("[Mobile terminal] Verification failed, connection disconnected!")

[0144] return False

[0145] is_verified = verify_agreement(agreement_data, "K_MOBILE_456")

[0146] It is easy to understand that the above example is limited to the code example of the connection between the APP and several corresponding POS machines. In this solution, the encryption corresponding to the solution described in this application can be completed without using the above Python code.

[0147] Specifically, for a single communication request, in step Sy1, the mobile terminal broadcasts the communication request;

[0148] Financial devices that have not established shallow and / or deep communication with any mobile terminal respond to communication requests and form a response queue;

[0149] The mobile terminal establishes shallow communication either in the order of the response queue or by specifying a financial device.

[0150] Specifically, for a single communication request, in step Sy2, the financial device responds to the communication request by generating corresponding request information and sending it to the keystore;

[0151] The keystore records the request information and retrieves the financial device key corresponding to the request information from the keystore, as well as the retrieved information;

[0152] The request information is the corresponding information formed by the time when shallow communication was established;

[0153] The corresponding information is formed by the time the information is retrieved and the time the keystore receives the request information.

[0154] By setting priorities, financial devices and mobile terminals are mapped to each other. At the same time, by establishing shallow communication, other financial devices that can connect to the mobile terminal are excluded. This makes the encryption target clear and effectively avoids the problem of financial device memory overflow caused by multiple different mobile terminals repeatedly connecting to financial devices. This improves verification efficiency and further enhances encryption security.

[0155] During implementation, the following operations and outputs can be performed:

[0156] The mobile terminal sends a broadcast request, and all nearby unconnected POS machines respond, forming a queue.

[0157] The mobile terminal selects a POS machine to establish shallow communication based on a strategy (such as signal strength and queue order).

[0158] import uuid

[0159] import datetime from datetime

[0160] # Simulate mobile terminal broadcast request

[0161] def broadcast_request():

[0162] request_id = f"REQ_{uuid.uuid4().hex[:6]}"

[0163] print(f"[Mobile Terminal] Broadcast Communication Request, ID: {request_id}")

[0164] return request_id

[0165] # Simulate a nearby POS machine response (unconnected device)

[0166] def get_available_pos_devices():

[0167] return ["POS_001", "POS_002", "POS_003"] # Returns a list of available POS machines

[0168] # Mobile device selection strategy (Example: Select the first device)

[0169] def select_pos_device(available_pos_list):

[0170] selected_pos = available_pos_list[0] # In practice, the selection may be based on RSSI (signal strength).

[0171] print(f"[Mobile Terminal] Selected Device: {selected_pos}")

[0172] return selected_pos

[0173] # Execution Process

[0174] request_id = broadcast_request()

[0175] available_pos_list = get_available_pos_devices()

[0176] selected_pos = select_pos_device(available_pos_list)

[0177] The output is:

[0178] [Mobile Terminal] Broadcast Communication Request, ID: REQ_a1b2c3

[0179] [Mobile Terminal] Select Device: POS_001

[0180] at this time,

[0181] After receiving the request, the POS machine generates request information (including a timestamp) and sends it to the key store.

[0182] The keystore records the request time and returns the financial device key and retrieval information (timestamp binding).

[0183] class KeyVault:

[0184] def __init__(self):

[0185] # Simulate the key stored in the key store (POS_KEY -> corresponding device key)

[0186] self.key_store = {

[0187] "POS_001": {"key": "K_POS_123", "paired_mobile_key": "K_MOBILE_456"},

[0188] "POS_002": {"key": "K_POS_789", "paired_mobile_key": "K_MOBILE_012"},

[0189] }

[0190] def request_key(self, pos_id, request_time):

[0191] print(f"[Keystore] received a key request from POS machine {pos_id}, time: {request_time}")

[0192] if pos_id in self.key_store:

[0193] # Simulate information retrieval (request time + random number)

[0194] retrieval_info = f"RET_{request_time}_{uuid.uuid4().hex[:4]}"

[0195] print(f"[Keystore] Returns financial device keys and retrieval information: {retrieval_info}")

[0196] return {

[0197] "pos_key": self.key_store[pos_id]["key"],

[0198] "retrieval_info": retrieval_info

[0199] }

[0200] else:

[0201] Raise an exception ("POS device not registered")

[0202] # POS machine logic

[0203] class POSDevice:

[0204] def __init__(self, pos_id):

[0205] self.pos_id = pos_id

[0206] self.key_vault = KeyVault()

[0207] def respond_to_request(self, request_id):

[0208] request_time = datetime.now().strftime("%Y%m%d%H%M%S") # Request time

[0209] print(f"[POS machine {self.pos_id}] responds to request {request_id}, requesting a key from the keystore...")

[0210] key_data = self.key_vault.request_key(self.pos_id, request_time)

[0211] return {

[0212] "status": "ACK",

[0213] "pos_key_id": key_data["pos_key"], # Returns the key identifier (not the key itself)

[0214] "retrieval_info": key_data["retrieval_info"] # Retrieve information

[0215] }

[0216] # Execution Process

[0217] pos = POSDevice("POS_001")

[0218] response_data = pos.respond_to_request(request_id)

[0219] The output is:

[0220] [POS machine POS_001] responds to request REQ_a1b2c3, requesting a key from the keystore...

[0221] [Keystore] Received key request from POS machine POS_001, time: 20240529120000

[0222] [Keystore] Returns financial device key and retrieval information: RET_20240529120000_abcd

[0223] Please see Figure 3 As shown, this is a diagram of the encryption process in an embodiment of the present invention.

[0224] For a single communication request, in step Sy3, in response to the establishment of shallow communication, the mobile terminal generates the corresponding request information and sends it to the key store to retrieve the mobile terminal key.

[0225] In response to the completion of step Sy2, the key store sends the corresponding mobile terminal key and retrieval information to the mobile terminal.

[0226] The mobile terminal retrieves information as an encryption key and encrypts the mobile terminal key to form encrypted information.

[0227] Specifically, in step Sy4, when the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using shallow communication,

[0228] The financial device re-encrypts the encrypted information based on the financial device key, and forms the corresponding communication consent information;

[0229] Financial devices use shallow communication to send communication consent information to mobile terminals.

[0230] The mobile terminal controls whether to maintain a connection with the financial device by controlling shallow communication. At the same time, the financial device decides whether to maintain a connection with the mobile terminal by judging whether shallow communication is maintained. This effectively avoids hardware-based cracking of the financial device, improves the controllability of encrypted communication, and thus further enhances encryption security.

[0231] In implementation, when a mobile terminal retrieves and encrypts the key, it includes:

[0232] The mobile terminal requests the mobile_key from the keystore.

[0233] The keystore returns mobile_key + retrieval information (timestamp binding).

[0234] The mobile terminal uses the retrieved information to encrypt the mobile_key, thus forming encrypted information.

[0235] import hashlib

[0236] import datetime from datetime

[0237] MobileTerminal:

[0238] def __init__(self):

[0239] self.key_vault = KeyVault() # Referencing the previous keystore

[0240] def request_mobile_key(self, pos_key_id, retrieval_info):

[0241] # Retrieve the mobile_key paired with the POS key from the keystore

[0242] key_data = self.key_vault.get_mobile_key(pos_key_id)

[0243] mobile_key = key_data["mobile_key"]

[0244] # Encrypt the mobile_key with the retrieved information (Example: AES encryption, simplified to hash here)

[0245] encrypted_key = hashlib.sha256(

[0246] f"{mobile_key}_{retrieval_info}".encode()

[0247] ).hexdigest()

[0248] print(f"[Mobile Terminal] Encrypts mobile_key: {encrypted_key} using retrieved information")

[0249] return encrypted_key

[0250] # Execution flow (following the output of step Sy2)

[0251] mobile = MobileTerminal()

[0252] encrypted_data = mobile.request_mobile_key(

[0253] pos_key_id=response_data["pos_key_id"],

[0254] retrieval_info=response_data["retrieval_info"] )

[0256] [Mobile Terminal] Encrypt mobile_key: a1b2c3... (SHA256 hash value) using retrieved information.

[0257] Specifically, in step Sy5, when the mobile terminal obtains the corresponding communication consent information, the mobile terminal uses the request information and decrypts the communication consent information, and compares whether the decrypted information includes the mobile terminal key and the corresponding retrieval information.

[0258] If the mobile terminal key does not match the retrieved information, or if the mobile terminal key is inaccurate, or if the retrieved information is inaccurate.

[0259] The mobile terminal disconnects from shallow communication.

[0260] Specifically, for a single communication request, in step Sy5, if the mobile terminal actively cuts off shallow communication, the financial device will cut off the information transmission to the key store.

[0261] Specifically, when a single communication request is completed in step Sy4, the key store will discard the mobile terminal key and financial device key corresponding to that communication request for one issuance cycle.

[0262] The issuance cycle is time-related, and in a single issuance cycle, the mobile terminal keys and financial device keys consumed by the key store do not exceed 70% of the total.

[0263] Please refer to Table 1, which provides an example of a keystore:

[0264] Financial Equipment ID Financial device key Mobile terminal key Should it be abandoned? Pairing status POS_001 A3F7E29B1C8D5E0F4A9B6C3D2E1F8A7 5B8D3E0F1A2C7D9E4F6B8A9C0D1E2F3 no efficient POS_002 9C4D2E8F1A0B3C6D5E7F8A9B0C1D2E3 F6E1D8C9B7A0F3E2D4C5B6A7D8E9F0 no efficient POS_003 2B5A8D0E7F1C3D9E6F4A7B8C9D0E1F2 3E9F0A8B7C6D5E4F3A2B1C0D9E8F7 no efficient POS_004 D1E6F3A8B9C0D7E2F5A4B3C2D8E1F0 7C8A9B0C1D2E3F4A5B6C7D8E9F0A1 yes Expired POS_005 4F7E2A9B8C1D0E3F6A5B4C3D2E1F8A B0C1D2E3F4A5B6C7D8E9F0A1B2C3 no efficient POS_006 E3F8A9B0C1D2E7F4A5B6C3D9E0F1A2 6D7E8F9A0B1C2D3E4F5A6B7C8D9E no efficient POS_007 1A2B3C4D5E6F7A8B9C0D1E2F3A4B5C 9F0E1D2C3B4A5F6E7D8C9B0A1F2E yes Abandoned POS_008 6C7D8E9F0A1B2C3D4E5F6A7B8C9D0E 3A4B5C6D7E8F9A0B1C2D3E4F5A6B no efficient POS_009 F2A3B4C5D6E7F8A9B0C1D2E3F4A5B 8C9D0E1F2A3B4C5D6E7F8A9B0C1D no efficient POS_010 0D1E2F3A4B5C6D7E8F9A0B1C2D3E4F 5E6F7A8B9C0D1E2F3A4B5C6D7E8F yes Abandoned POS_011 9A0B1C2D3E4F5A6B7C8D9E0F1A2B3 2C3D4E5F6A7B8C9D0E1F2A3B4C5 no efficient POS_012 4B5C6D7E8F9A0B1C2D3E4F5A6B7C8 D9E0F1A2B3C4D5E6F7A8B9C0D1E no efficient POS_013 3E4F5A6B7C8D9E0F1A2B3C4D5E6F7 A8B9C0D1E2F3A4B5C6D7E8F9A0B no efficient POS_014 2D3E4F5A6B7C8D9E0F1A2B3C4D5E6 F7A8B9C0D1E2F3A4B5C6D7E8F9A yes Expired POS_015 1C2D3E4F5A6B7C8D9E0F1A2B3C4D5 E6F7A8B9C0D1E2F3A4B5C6D7E8F no efficient

[0265] Of the 15 key pairs mentioned above, 4 pairs are obsolete or expired, and 11 pairs are still usable. The consumption rate is less than 70%, so the key store does not need to be reset.

[0266] The introduction of proactive security interruption mechanisms and dual encryption verification enhances resistance to attacks, while key distribution cycle limits balance security and system load. It outperforms traditional static encryption or one-way authentication methods in terms of significantly improved security, flexibility, and robustness, making it particularly suitable for high-risk mobile financial interaction scenarios.

[0267] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

[0268] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for encrypting financial devices based on mobile terminals, comprising a key library, wherein in communication between the mobile terminal and the financial device, a pair of financial device keys and a mobile terminal key corresponding to the financial device keys are selected; Its features are, For a single mobile terminal, including: Initiate a communication request and select the corresponding financial device to establish shallow communication; The financial device responds to the communication request, obtains the corresponding financial device key, and sends response data to the mobile terminal using the shallow communication. In response to the response data, the corresponding mobile terminal key is retrieved and encrypted to form encrypted information; The encrypted information is sent to the corresponding financial device, which uses the financial device key to encrypt the encrypted information a second time, and forms a communication agreement information and sends it back to the mobile terminal. The communication agreement information is verified, and deep communication is established based on the verification results; In this process, upon successful verification of the communication consent information, the mobile terminal establishes deep communication with the financial device. If the communication consent information fails to be verified, the mobile terminal disconnects the shallow communication.

2. The encryption method for financial devices based on mobile terminals according to claim 1, characterized in that, For a single communication request, when the mobile terminal broadcasts the communication request, financial devices that have not established shallow and / or deep communication with any mobile terminal respond to the communication request and form a response queue. The mobile terminal establishes the shallow communication either in the order of the response queue or by designating a financial device.

3. The encryption method for financial devices based on mobile terminals according to claim 2, characterized in that, For a single communication request, when the financial device responds to the communication request, it generates corresponding request information and sends it to the key store; The keystore records the request information and retrieves the financial device key corresponding to the request information from the keystore, as well as the retrieval information; The request information is generated when the shallow communication is established; The retrieval information is generated when the keystore receives the request information.

4. The encryption method for financial devices based on mobile terminals according to claim 3, characterized in that, For a single communication request, when the shallow communication is established, the mobile terminal generates corresponding request information and sends it to the key store to retrieve the mobile terminal key. In response to the receipt of the response data, the key library sends the corresponding mobile terminal key and the retrieval information to the mobile terminal. The mobile terminal uses the retrieved information as an encryption key and encrypts the mobile terminal key to form the encrypted information.

5. The encryption method for financial devices based on mobile terminals according to claim 4, characterized in that, When the financial device completes the retrieval of the financial device key and obtains the encrypted information sent by the mobile terminal using the shallow communication, The financial device performs secondary encryption on the encrypted information based on the financial device key, and forms corresponding communication consent information; The financial device uses the shallow communication to send communication consent information to the mobile terminal.

6. The encryption method for financial devices based on mobile terminals according to claim 5, characterized in that, When the mobile terminal obtains the corresponding communication consent information, the mobile terminal compares whether the communication consent information generated by the financial device includes the mobile terminal key and the corresponding retrieval information. If the mobile terminal key does not match the retrieved information, or if the mobile terminal key is inaccurate, or if the retrieved information is inaccurate, The mobile terminal disconnects from the shallow communication.

7. The encryption method for financial devices based on mobile terminals according to claim 5, characterized in that, For a single communication request, if the mobile terminal actively disconnects the shallow communication during the establishment of the shallow communication, the financial device will cut off the information transmission to the key store.

8. The encryption method for financial devices based on mobile terminals according to claim 6 or 7, characterized in that, When the mobile terminal obtains the communication consent information for the single communication, the key store discards the mobile terminal key and the financial device key corresponding to the communication request for one issuance cycle. The issuance cycle is time-related, and in a single issuance cycle, the key store consumes no more than 70% of the total number of mobile terminal keys and financial device keys.

9. The encryption method for financial devices based on mobile terminals according to claim 8, characterized in that, For a single financial device, including: Broadcasts receive requests and detects mobile terminals entering the link range; Responding to communication requests from the mobile terminal, establishing shallow communication with the mobile terminal and sending response data; Stop broadcasting the request to receive data and obtain the financial device key; Data received via shallow communication is encrypted using the financial device key and returned to the shallow communication. In response to a shallow communication disconnection, broadcast the receive request, or... Respond to deep communication requests and establish corresponding deep communication with the corresponding mobile terminal.

10. The encryption method for financial devices based on mobile terminals according to claim 9, characterized in that, When the financial device responds to the disconnection of the shallow communication, it also disconnects the corresponding deep communication; When the deep communication is cut off, the financial device cuts off the corresponding shallow communication.

Citation Information

Patent Citations

  • Security verification methods, devices, equipment and storage media for financial devices

    CN113537982B

  • User authentication module setting method and system

    CN101958026A

  • Wireless based methods and systems for federated key management, asset management, and financial transactions

    US20190205874A1