A Smart Security Protection Method and System for Anti-Prying of Payment Device Keyboard

By constructing a multi-dimensional, dynamic, and collaborative defense system, and combining virtual keyboards, user behavior, and environmental awareness, the shortcomings of existing payment device keyboard protection technologies in the face of multiple attack methods have been addressed, achieving effective defense against complex attacks and optimizing strategies.

CN120805203BActive Publication Date: 2025-11-14SHENZHEN JUSTTIDE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511304646.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-12
Publication Date
2025-11-14
Estimated Expiration
2045-09-12

AI Technical Summary

Technical Problem

Existing keyboard protection technologies for payment devices lack a coordinated mechanism when facing complex and ever-changing attack methods, making it difficult to effectively defend against various forms of spying attacks such as visual eavesdropping, software recording, physical device eavesdropping, and electromagnetic radiation leakage.

Method used

It adopts a multi-dimensional, dynamic, and collaborative defense system, combining randomly arranged virtual keyboards, user behavior biometric recognition, physical environment perception, and electromagnetic side-channel monitoring to generate dynamic security protection commands, including adjusting interference values, key layouts, and display colors, and selectively enabling measures such as viewing angle restrictions, blurring, or electromagnetic shielding layers.

Benefits of technology

It achieves comprehensive protection against complex attacks, has a high degree of adaptability, can proactively adjust protection strategies, increases the difficulty of attack prediction and bypass, and continuously optimizes protection strategies through a data-driven feedback loop mechanism, thereby improving security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805203B_ABST
    Figure CN120805203B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of computer input security technology, specifically disclosing an intelligent security protection method and system for preventing keyboard spying on payment devices. The method includes: generating a virtual keyboard with a random layout and assigning a time-varying interference value to each key, increasing the difficulty for attackers to capture accurate input information; constructing a high-dimensional user behavior profile to capture unique dynamic biometric features during user input, and then collecting the touch trajectory features of user input operations in real time and comparing them with a behavior model representing normal user input habits to effectively prevent automated script and imitation attacks; and collecting data from an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, and comparing it with an environmental model representing the state of the secure environment to achieve comprehensive perception and resist various forms of spying attacks such as visual eavesdropping, software recording, and electromagnetic theft.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer input security technology, and relates to a smart security protection method and system for preventing keyboard probing of payment devices. Background Technology

[0002] With the widespread adoption of electronic payments, payment terminals play a central role in various transaction scenarios. Among these, the virtual keyboard used for entering sensitive information such as passwords and verification codes is a crucial element in ensuring transaction security. To prevent the illegal theft of user information, the security protection technology of payment device keyboards is paramount. These technologies aim to protect users from various forms of spying attacks, including visual eavesdropping, software recording, and physical device eavesdropping, when entering information in public or semi-public environments. They are an important component of ensuring the security of the entire digital financial system.

[0003] Existing keyboard protection technologies for payment devices typically employ single or limited combinations of security measures. Common methods include displaying characters as asterisks when users enter their passwords, or using a randomized keyboard layout with fixed rules. Some more advanced methods incorporate ambient light sensors to determine ambient brightness and alert users to occlusion, or use simple behavioral analysis, such as detecting abnormal input speed, to identify automated attacks. However, these technologies often operate independently, lacking coordination mechanisms, making it difficult to form an effective defensive force.

[0004] Existing technical solutions have significant shortcomings when facing complex and ever-changing attack methods. For example, fixed disordered rules are easily cracked through repeated observation or recording; simple input speed detection cannot prevent machine learning attacks that mimic human behavior; relying solely on ambient light alerts is too passive and cannot effectively prevent well-prepared close-range spying or remote recording using high-definition cameras. In addition, these methods generally ignore the risk of more covert side-channel attacks such as electromagnetic radiation leakage, resulting in significant weaknesses in the protection system. Summary of the Invention

[0005] In order to overcome the above-mentioned defects of the prior art and to achieve the above objectives, the present invention proposes the following technical solution: a smart security protection method for preventing keyboard probing of payment devices, comprising: step 1, generating a virtual keyboard with a random layout, and assigning each key of the virtual keyboard an interference value that changes nonlinearly with time in a dynamic interference matrix.

[0006] Step 2: Collect the touch trajectory features generated by user input operations in real time, and compare the touch trajectory features with a behavior model that represents normal user input habits to generate behavior analysis results.

[0007] Step 3: Collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, including ambient light intensity values, environmental image streams, and electromagnetic radiation signals; and compare the environmental perception data with an environmental model representing the state of a safe environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals.

[0008] Step 4: Based on the behavioral analysis results and environmental risk analysis results, generate dynamic security protection instructions corresponding to the analysis results; the dynamic security protection instructions include adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer.

[0009] The second aspect of the present invention provides a payment device keyboard anti-spying intelligent security protection system, comprising: a keyboard generation module, used to generate a virtual keyboard with a random layout, and to assign an interference value that changes nonlinearly with time in a dynamic interference matrix to each key of the virtual keyboard.

[0010] The behavior analysis module is used to collect the touch trajectory features generated by user input operations in real time, and compare the touch trajectory features with a behavior model that represents normal user input habits to generate behavior analysis results.

[0011] The environmental analysis module is used to collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, including ambient light intensity values, environmental image streams, and electromagnetic radiation signals; and compare the environmental perception data with an environmental model that characterizes the state of a safe environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals.

[0012] The instruction generation module is used to generate dynamic security protection instructions corresponding to the analysis results based on the behavior analysis results and the environmental risk analysis results. The dynamic security protection instructions include adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer.

[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention achieves comprehensive protection against complex attacks by constructing a multi-dimensional, dynamically coordinated, and in-depth defense system. It organically integrates multiple mechanisms such as dynamically changing virtual keyboards, user behavior biometric recognition, physical environment perception, and electromagnetic side-channel monitoring to form a three-dimensional security network from the user interaction layer, the physical environment layer, to the electromagnetic signal layer. When a potential threat is detected in any dimension, the system can trigger a linkage response, effectively dealing with a variety of attack methods including shoulder spying, screen recording, imitation attacks, and electromagnetic theft.

[0014] (2) The present invention has a high degree of dynamic adaptation and countermeasure capabilities. It can not only passively defend against attacks, but also actively adjust the protection strategy based on real-time analysis results. This includes targeted interference based on the button position of abnormal operation, automatic activation of physical shielding layer based on environmental risks, and upgrading to active dynamic identity verification when encountering continuous attacks. This closed-loop mechanism enables the protection system to adapt to the constantly evolving attack methods, increasing the difficulty for attackers to predict and bypass.

[0015] (3) This invention constructs a security ecosystem with self-evolving capabilities through a data-driven strategy optimization mechanism. Each successful defense generates detailed encrypted logs and uploads them to the central security system. These logs contain multi-dimensional data, including attack characteristics, environmental data, and response measures, providing a data foundation for continuous optimization of the risk model and protection strategy in the background. This feedback loop mechanism enables the effectiveness of the entire protection system to continuously improve over time and with the accumulation of attack and defense experience, thus possessing the potential to cope with unknown threats in the future. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a schematic diagram of the implementation steps of the method of the present invention.

[0018] Figure 2 This is a schematic diagram of the system module connections of the present invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Example

[0020] Please see Figure 1 As shown, the present invention proposes an intelligent security protection method for preventing keyboard probing of payment devices, which includes: Step 1, generating a virtual keyboard with a random layout, and assigning each key of the virtual keyboard an interference value that changes nonlinearly with time in a dynamic interference matrix.

[0021] In a preferred embodiment, generating a virtual keyboard with a random layout and assigning each key of the virtual keyboard an interference value that changes non-linearly over time in a dynamic interference matrix includes: when the payment device is started or when the keyboard needs to be regenerated, calling a random number generator in combination with preset layout optimization rules to generate new key coordinates and arrangement order, and passing them to the virtual keyboard rendering unit to display the new keyboard layout on the screen.

[0022] The layout optimization rule refers to keeping certain keys that are highly related during the input process close to each other in the layout so that users can find and input them more quickly, such as the confirmation and cancel keys in the function keys.

[0023] Initialize a dynamic interference matrix that matches the number of virtual keyboard keys, and assign an initial interference value to each key.

[0024] Set a time trigger to periodically (e.g., every second or after each user input) recalculate the value of each element in the interference matrix to generate new interference values. The calculation uses a non-linear function, and the updated interference values ​​are then applied to the rendering and input processing logic of the virtual keyboard.

[0025] Specifically, a nonlinear function can be any mathematical function that produces a nonlinear effect, such as exponential functions, logarithmic functions, trigonometric functions, or more complex composite functions. Example of a nonlinear transformation: Suppose we have a simple nonlinear function... ,in This indicates the current interference value. , and These are preset parameters that adjust the degree and range of nonlinearity, determined empirically. This function will adjust the original interference value. Mapped to a new nonlinear value.

[0026] Step 2: Real-time acquisition of touch trajectory features generated by user input operations. These touch trajectory features are then compared with a behavioral model representing normal user input habits to generate behavioral analysis results. The behavioral model refers to a data model constructed by long-term collection and analysis of normal user input behavior data during the use of the payment device keyboard, capable of representing the user's unique input habits and biometric characteristics. This model includes data patterns across multiple dimensions, such as speed, direction, and pressure characteristics exhibited by the user during input, used to compare with the real-time acquired touch trajectory features, thereby identifying abnormal operations or potential attack behaviors.

[0027] In a preferred embodiment, the real-time acquisition of touch trajectory features generated by user input operations includes: when a user's finger touches the virtual keyboard of the payment terminal, the touch processing unit of the payment device records the position of the user's finger on the screen in real time at a preset high sampling frequency, forming a touch point coordinate sequence containing a timestamp.

[0028] Based on the touch point coordinate sequence, calculate the movement speed sequence and direction change rate sequence of the touch trajectory.

[0029] Movement speed can be calculated using the following formula: ,in Indicates the current sampling time Instantaneous movement speed, They represent the current sampling time. and the previous sampling time The coordinates of the obtained touch point.

[0030] The rate of change of direction is used to quantify the tortuosity of the user's finger movement path. For any three consecutive points in the touch point coordinate sequence, two connected displacement vectors can be formed. The rate of change of direction is the change of the angle between these two vectors over time, reflecting the smoothness of the user's operation and turning habits.

[0031] At the same time, the pressure sensor integrated into the payment device synchronously captures the vertical force applied by the user at each touch point, thereby obtaining pressure distribution data to generate a pressure value sequence.

[0032] The pressure distribution data is represented as a series of pressure values ​​synchronized with the touch point coordinate sequence, which fully records the force changes during a single touch from contact, pressing to lifting.

[0033] The movement speed sequence, direction change rate sequence, and pressure value sequence are aligned and integrated in time and space to form a unified, structured dataset, which forms the touch trajectory feature. This touch trajectory feature, as a whole, is used for subsequent abnormal operation comparison and identification, and can comprehensively describe the physical characteristics of a single input behavior.

[0034] This invention constructs a high-dimensional user behavior profile, namely touch trajectory features, by real-time collection and combination of movement speed, direction change rate, and pressure distribution data. This multi-dimensional feature combination not only records the final position of the user's input but also captures the unique dynamic biometric features during the input process. Compared to methods that only analyze single-dimensional data, this method can more accurately distinguish between the natural, subconscious input habits of legitimate users and the mechanical operations imitated by attackers or executed by automated scripts. This greatly improves the accuracy and sensitivity of abnormal operation detection, providing a reliable data foundation for subsequent decisions of the entire protection system. Thus, without increasing the user's additional burden, it significantly enhances the inherent security of the payment process.

[0035] In a further preferred embodiment, the step of comparing the touch trajectory features with a behavior model that characterizes normal user input habits to generate behavior analysis results includes: separating and extracting three independent feature components from the composite touch trajectory feature data structure, namely, speed features representing the dynamic change of input rate, directional features describing the smoothness of finger movement path, and pressure features reflecting the user's pressing pressure. All three feature components are time-related sequence data.

[0036] These three feature components are compared with a pre-established user personal behavior pattern library, which includes a speed pattern library, a direction pattern library, and a pressure pattern library, to generate speed matching score, direction matching score, and pressure matching score.

[0037] The user personal behavior pattern library is a benchmark template formed by collecting a large amount of legitimate input operation data during the user's secure registration or long-term use, and then performing statistical analysis and feature modeling.

[0038] The comparison process employs sequence similarity matching algorithms, such as dynamic time warping, to calculate the similarity between the current input behavior sequence and standard template sequences in the user's personal behavior pattern library. This process generates three independent quantitative indicators: speed matching score (comparing speed features with a speed pattern library); direction matching score (comparing direction features with a direction pattern library); and stress matching score (comparing stress features with a stress pattern library). The matching score values ​​are typically normalized to represent the degree to which the current behavior conforms to the user's normal habits.

[0039] The calculated speed matching degree, direction matching degree, and pressure matching degree are compared with their respective preset thresholds. These thresholds are the minimum acceptable similarity standards set according to the safety policy. If any one or more of these three matching degrees are lower than their corresponding preset thresholds, it is determined that the input operation does not conform to the user's inherent behavior pattern, thereby generating a behavior analysis result containing an abnormal operation mark. This abnormal operation mark will serve as a trigger signal for subsequent safety response measures.

[0040] This invention constructs a three-dimensional behavior recognition model by decomposing a single user input action into three orthogonal physical dimensions—speed, direction, and pressure—for independent analysis and comprehensive judgment. The synergistic effect of this multi-dimensional comparison mechanism significantly increases the difficulty for attackers to mimic it. An attacker might be able to imitate one aspect of the user's input, such as key press speed, but simultaneously and accurately replicating the user's subtle jittering habits in the direction of movement and the unique curve of the pressure applied is virtually impossible. Therefore, as long as the attack behavior reveals a flaw in any dimension, the system can sensitively detect it and trigger an alarm, thus achieving recognition accuracy and robustness far exceeding that of single-dimensional detection. This effectively resists various threats, including automated robot attacks and highly skilled human imitation, achieving implicit and continuous verification of the user's identity.

[0041] Step 3: Collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit. This data includes ambient light intensity values, environmental image streams, and electromagnetic radiation signals. The environmental perception data is then compared with an environmental model representing the security state of the environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals. The environmental model refers to a pre-constructed data model that characterizes the security state of the environment in which the payment device operates. This model integrates and analyzes the security thresholds and normal fluctuation ranges of various environmental factors (such as light intensity, personnel distance, and electromagnetic radiation) to provide a reference benchmark for the payment device, used to assess whether potential security risks, such as visual spying and electromagnetic theft risks, exist in the current environment.

[0042] In a preferred embodiment, the step of comparing environmental perception data with an environmental model representing the state of a safe environment to generate environmental risk analysis results includes: calling the ambient light sensor built into the payment device to obtain a quantified ambient light intensity value in real time.

[0043] The payment device's miniature camera is activated to continuously capture a stream of images of the environment in front of the device at a set frame rate.

[0044] The system compares the real-time ambient light intensity value with a preset light threshold, which represents a standard of bright environment that is easily visible to others. Simultaneously, the image processing unit is activated, using human or face detection algorithms from computer vision to identify the outlines or facial features of other targets in the environmental image. When other targets are detected, the system further analyzes the pixel size occupied by the other targets in the image and estimates the physical distance between the person and the device, i.e., the person distance, based on pre-calibrated camera parameters. If the calculated person distance is less than a preset safe distance threshold, it is determined that there is a risk of close-range spying.

[0045] Person distance It can be estimated using the following simplified model: ,in It is the focal length of the camera, a known parameter; It is the preset average actual width of a face or shoulder, used as a baseline reference value; It is the pixel width of the face or shoulder contour detected in the environmental image, calculated in real time by the image processing unit.

[0046] When either the light intensity value is higher than the preset light threshold or the distance between people is less than the preset distance, an environmental risk analysis result containing visual spying risk signals is generated, thereby triggering and enabling the anti-spying mode.

[0047] This invention establishes a two-factor triggering mechanism by combining ambient light perception with vision-based personnel distance detection, enabling accurate prediction of visual spying risks. This mechanism avoids false alarms or missed alarms that may be caused by judging a single environmental factor.

[0048] In a further preferred embodiment, the step of comparing the environmental perception data with an environmental model representing the state of a safe environment to generate environmental risk analysis results further includes: continuously performing wide-spectrum scanning through an electromagnetic radiation monitoring unit integrated below the keyboard area of ​​the payment device to collect electromagnetic radiation signals leaked outward during device operation in real time. The monitoring unit consists of a high-sensitivity miniature antenna and a signal amplifier, and is specifically designed to capture changes in the electromagnetic field generated when electronic components are working.

[0049] The electromagnetic radiation signal is analyzed by a signal processing unit to extract key frequency bands and intensity features. This process typically employs a Fast Fourier Transform (FFT) algorithm to convert the time-domain signal into a frequency-domain signal, resulting in a spectrum that shows the distribution of signal energy at different frequencies. From this spectrum, the system identifies several key frequency bands with concentrated energy and quantifies the signal intensity corresponding to these bands, forming a set of structured frequency band and intensity feature data.

[0050] The critical frequency bands refer to several frequency ranges in the spectrum where energy is relatively concentrated and amplitude is high. These frequency bands may be specific frequency components generated during normal operation of the equipment, or they may be interference or detection frequencies used by external attackers attempting to steal information. By identifying these critical frequency bands, the main frequency components in the electromagnetic radiation signal can be understood, thereby determining whether there are any abnormal or potential attack behaviors.

[0051] Intensity characteristics refer to the amplitude or energy of a signal in these key frequency bands, reflecting the signal's activity or influence at that frequency.

[0052] The extracted frequency band and intensity features are dynamically compared with a pre-stored electromagnetic radiation baseline to generate environmental risk analysis results that include electromagnetic theft risk signals.

[0053] The electromagnetic radiation baseline refers to a template library established under safe conditions by recording the standard electromagnetic radiation spectrum characteristics generated during a large number of normal key presses.

[0054] The core of the comparison is to check two aspects: first, whether there is any abnormal frequency band radiation in the current signal that is not present in the baseline, which may indicate the presence of external active detection equipment; second, whether the signal strength of certain known frequency bands in the baseline has undergone abrupt changes far exceeding the normal fluctuation range, which may indicate that an attacker is amplifying and stealing specific signals. If either of these situations occurs, the system determines that there is a risk of electromagnetic theft.

[0055] This invention combines hardware-level electromagnetic radiation monitoring with software-level dynamic interference mechanisms to construct a deep, multi-layered defense system. The introduction of electromagnetic radiation monitoring opens up a completely new, non-visual dimension of threat perception, enabling the detection of silent attacks carried out through physical side channels that are undetectable by traditional methods.

[0056] Step 4: Based on the behavioral analysis results and environmental risk analysis results, generate dynamic security protection instructions corresponding to the analysis results; the dynamic security protection instructions include adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer.

[0057] In a preferred embodiment, the step of generating dynamic security protection instructions corresponding to the analysis results based on the behavior analysis results and the environmental risk analysis results includes: Step 4-1, after generating the behavior analysis results containing abnormal operation markers, includes the following linkage adjustment steps for dynamic security protection instructions: based on the touch coordinate information attached to the abnormal operation markers in the touch trajectory features, mapping is performed on the current virtual keyboard layout to identify the key area directly corresponding to this abnormal input behavior, and the key area is defined as a set of one or more keys.

[0058] For the buttons within the key area, two parallel adjustment operations are performed. The first adjustment concerns internal security parameters: accessing and modifying the dynamic interference matrix. Specifically, for all buttons within the identified key area, the system selectively increases their corresponding interference values. This process can be represented by the following formula: ,in The updated interference value. For a specific key within the key area read from the dynamic interference matrix. The original interference value, This is a preset abnormal response enhancement factor greater than 1. This factor can be a fixed value or a variable that is dynamically adjusted according to the degree of deviation of the abnormal operation.

[0059] The second adjustment addresses real-time changes in the user interface: Identify all directly adjacent buttons in the button area, randomly swap or shift the layout of these adjacent buttons, and simultaneously change their display color to a set of preset high-contrast or visually confusing colors.

[0060] These two adjustments were designed to occur simultaneously, ensuring that the defensive posture has changed before the attacker's next attempt.

[0061] This instant response mechanism achieves a dynamic defense effect from both internal and external perspectives. Externally, the synchronized changes to the layout and color of adjacent keys directly disrupt the continuity of visual spying. Whether through human eye observation or camera recording, the attacker's established spatial memory of the keyboard layout becomes instantly invalid, exponentially increasing the difficulty of observing and inferring input. Internally, the targeted increase in interference values ​​in abnormal areas lays a data trap for potential subsequent machine learning-based attacks. This means that even if an attacker bypasses visual interference and collects touch coordinates, the internal trust or validity of the areas corresponding to these coordinates has been reduced. The system can use this increased interference value in the backend processing to further identify or discard suspicious inputs. The synergy of these two measures forms a dynamic and targeted "defense trap" that not only passively interferes with attacks but also actively counters detected attack behaviors, achieving an overall security enhancement effect far exceeding the sum of individual defense methods.

[0062] Step 4-2: Generate environmental risk analysis results containing visual spying risk signals, including the following dynamic security protection command linkage adjustment steps: In anti-spying mode, execute two synchronous display interface rendering operations: First, call the viewing angle limiting algorithm for the virtual keyboard display area. This algorithm adjusts the light emission characteristics of the screen pixels through software, so that the keyboard image is only clearly visible within a narrow angle directly facing the screen, while when viewed from the side, the image will appear as a large area of ​​black or severely distorted color blocks; Second, according to the user's touch input state, dynamically blur the non-current operation keys, that is, when the user's finger does not touch the keyboard, all keys are displayed in a blurred state; when the finger touches a key, only that key and a few adjacent keys are restored to clear display, while all other non-current operation keys remain blurred, thus forming a "clear focus" that follows the movement of the finger.

[0063] The combined application of viewpoint restriction and dynamic blurring, two visual protection methods, constitutes a multi-layered, in-depth defense. Viewpoint restriction provides a wide-area, passive physical layer of protection, effectively blocking peeping from the sides; while dynamic blurring actively interferes with and misleads the attacker's attention at the interaction level, greatly increasing the difficulty of inferring the input sequence through short, frontal glances. The combination of these two techniques transforms the originally static display interface into an intelligent security barrier capable of sensing the environment and dynamically adjusting visibility, significantly improving the security of payment operations in complex public places.

[0064] Step 4-3: Generate environmental risk analysis results containing electromagnetic theft risk signals, including the following dynamic security protection command linkage adjustment steps: After determining the existence of electromagnetic theft risk, a dual response mechanism is triggered: On the one hand, an activation command is sent to the integrated electromagnetic shielding layer. This shielding layer is usually a thin film of special material whose conductivity can be changed by electricity. After activation, it can form a local Faraday cage in the keyboard area, effectively attenuating or blocking the outward propagation of electromagnetic signals; on the other hand, the defense strategy of the upper-layer software is adjusted simultaneously, that is, the generation frequency of the dynamic interference matrix is ​​increased. This means that the basic interference value of each key on the virtual keyboard will be updated nonlinearly at a higher rate, making any residual electromagnetic signal patterns that may be leaked and related to key operations more chaotic and disordered, greatly increasing the difficulty of signal analysis and cracking.

[0065] The immediate activation of the electromagnetic shielding layer and the accelerated adjustment of the dynamic interference matrix generation frequency create a powerful synergistic effect. The shielding layer, acting as a physical barrier, directly weakens the signal energy available to attackers; while the accelerated interference matrix update injects high-frequency noise at the logical level, completely disrupting the stable correlation between the signal and the input content. This dual attack of physical attenuation and logical obfuscation provides a comprehensive protection effect far exceeding the simple sum of the two when applied independently. It can effectively counter high-level electromagnetic side-channel attacks, ensuring the ultimate security of user input information.

[0066] In a further preferred embodiment, the generation of environmental risk analysis results containing visual spying risk signals also includes the following linkage adjustment steps: while enabling viewpoint restriction processing and blurring processing, the screen recording attack detection unit is activated.

[0067] The screen recording attack detection unit specifically monitors the display interface area where the virtual keyboard is located. It samples the screen frames of this area at fixed time intervals and calculates an index that quantifies the current screen change, namely the pixel change frequency, by comparing the pixel data differences between two consecutive sampled frames. This frequency essentially reflects the number and magnitude of pixels that change on the display interface per unit time.

[0068] Record the time of each touch operation (including press and release events) performed by the user on the virtual keyboard to form a time sequence of user input operations.

[0069] Analyze the correlation between pixel change frequency and user input operation time series. If abnormal pixel synchronization changes that are not causally related to user input are detected, it is determined that a screen recording attack exists.

[0070] Specifically, the system synchronously compares the real-time generated pixel change frequency time series with the user input operation time series. Under normal operation, any significant pixel change should be strongly correlated with the user's input action in time, such as key highlighting or character echoing. These changes occur immediately after the user's touch event. The system seeks abnormal pixel synchronization changes, that is, one or more significant, unexpected peaks in the pixel change frequency within an extremely short time window without corresponding user input. This decoupling of change patterns from user behavior is a typical characteristic of screen recording software (such as the flashing of its recording indicator icon or periodic screen refreshes caused by its overlay) or malware performing screen capture operations in the background.

[0071] The correlation analysis detected this abnormal pixel synchronization change and confirmed that it did not conform to the normal user interaction model, so it was immediately determined that there was a screen recording attack.

[0072] In response to the screen recording attack, two mandatory measures are triggered: First, the keyboard display is frozen, that is, all rendering updates to the virtual keyboard display area are stopped, making it display a static image or a completely black screen, thereby cutting off the attacker's subsequent information acquisition channel; Second, a clear alert is issued to the user through an interface pop-up window or status bar icon, indicating that there is a security risk, and at the same time, the security event log is uploaded to the backend management system.

[0073] This invention effectively supplements traditional physical anti-spying methods by introducing correlation analysis between pixel change frequency and user input timing, extending protection capabilities from the physical space to the digital space. This method cleverly utilizes the judgment of "cause and effect," meaning that legitimate screen changes must have legitimate user operations as their "cause," thus accurately identifying malicious screen activities with no "cause" and no "effect." Combined with an environment-aware physical anti-spying mechanism, it forms a comprehensive, integrated hardware and software visual information security protection system, effectively responding to various complex visual theft attacks, from close-range human eye spying to remote malicious software screen recording, ensuring the confidentiality of user input information.

[0074] In a further preferred embodiment, the generation of environmental risk analysis results containing electromagnetic theft risk signals also includes the following linkage adjustment steps: while activating the electromagnetic shielding layer, increasing the update frequency of interference values ​​in the dynamic interference matrix.

[0075] If the electromagnetic theft risk signal indicates a continuous abnormal radiation state, the dynamic verification mechanism is triggered.

[0076] The dynamic verification mechanism generates personalized verification questions based on a user's historical input habit model, or calls a multimodal biometric recognition module for secondary identity verification, and pauses keyboard input function before the verification is successful.

[0077] Specifically, when the analysis results of the electromagnetic radiation monitoring unit show that the abnormal electromagnetic radiation is not a transient environmental fluctuation, but rather persists continuously within a preset time window or exhibits a periodic pattern, the system determines that it has encountered a persistent and continuous theft attempt. At this point, the system immediately triggers a dynamic verification mechanism as a response with a higher level of security.

[0078] The mechanism employs two parallel, selectable verification paths: the first path generates a personalized verification question. The system accesses a user history input habit archive, built with user authorization and stored in an encrypted manner. This archive records the user's non-sensitive actions, such as the merchant type of recent transactions, habitually entered phrases, or specific operational sequences. The system randomly selects one or more behavioral features from this archive and automatically generates a question that only a real user could answer based on their recent memory or long-term habits, such as "What was the recipient category you last entered?" or "Please enter three letters in your usual order."

[0079] The second approach requires the user to perform multimodal biometric identification. The system will activate at least two different biometric acquisition units integrated into the device, such as a fingerprint sensor and a front-facing camera, and prompt the user to complete secondary identity verification operations such as fingerprint scanning and facial recognition simultaneously or sequentially. The system will then compare the real-time biometric data with pre-stored encrypted templates in the device's secure area.

[0080] During the entire dynamic verification process, regardless of the path taken, the system immediately suspends normal input functionality of the virtual keyboard and forcibly switches the screen to a dedicated, isolated verification interface. This interface contains only the elements necessary for answering questions or performing biometric authentication, thus completely eliminating the possibility of attackers continuing any input attempts or interfering with the verification process during this time. Only after the user successfully passes any one or a combination of the above verifications will the system unlock and restore keyboard input functionality.

[0081] This invention, by introducing this dynamic verification step, forms a deep synergy with the preceding electromagnetic radiation monitoring and shielding measures in terms of defense logic, constituting the final line of defense against persistent, high-intensity attacks. When initial physical shielding and signal interference are insufficient to completely eliminate the threat, this mechanism forces the attacker from an "invisible" thief into an "intruder" requiring direct interaction with the user. The personalized questions and multimodal biometric verification requirements posed are completely unacceptable to remote electromagnetic thieves. This strategy upgrade from "passive defense" to "active interrogation" is far more effective than simply increasing shielding strength or interference frequency. It establishes a highly deterministic identity verification barrier, capable of confirming the operator's true identity with extremely high confidence even in the most dangerous situations, thereby fundamentally ending the attack chain and ensuring the ultimate security of the transaction.

[0082] In a further preferred embodiment, the method further includes: after executing the dynamic security protection command, collecting behavioral analysis results, environmental risk analysis results, dynamic interference matrix adjustment records, and the types of physical layer protection measures enabled, to form a multi-dimensional security event data set.

[0083] Encrypt the multidimensional security event data set to generate an encrypted security log.

[0084] The encrypted security logs are uploaded to a security management system, which then updates the behavioral and environmental models based on the encrypted security logs.

[0085] Specifically, after a complete security protection process is completed, this method automatically executes a systematic logging and archiving procedure. The system first aggregates all relevant data generated during the event in the device's temporary secure memory. This data is organized into a structured security event log with a unique event ID and timestamp. This log mainly includes the following aspects: First, abnormal operation characteristics, i.e., the specific behavioral data that triggered the response, such as touch speed, direction, or pressure sequences deviating from the normal range; second, interference matrix adjustment records, detailing the specific modifications made to the dynamic interference matrix during the response process, including the affected key areas and the interference values ​​before and after the adjustment; third, environmental risk data, including the light intensity value when the anti-peeping mode is triggered and the distance to suspicious personnel estimated through image analysis; fourth, advanced threat detection results, including the conclusion of the screen recording attack and the abnormal frequency bands and intensity characteristics found in the electromagnetic radiation theft analysis; and finally, a list of all protective measures taken, such as enabling viewing angle restriction, executing keyboard display freeze, activating the electromagnetic shielding layer, or initiating a dynamic verification mechanism.

[0086] After data collection is complete, the system invokes the encryption module to perform high-strength encryption on the entire structured security event record, thereby generating a single, tamper-proof encrypted log data packet. This encryption process typically employs an asymmetric encryption algorithm, using the public key of the security management system pre-deployed within the device for encryption. This ensures that only the security management system with the corresponding private key can decrypt and read the log content, thus guaranteeing the confidentiality and integrity of the logs during storage and transmission.

[0087] Finally, the device proactively uploads the generated encrypted log to a remote security management system via a pre-defined secure communication channel, such as an HTTPS connection based on the TLS protocol. This system, acting as a central data analysis and decision-making center, is responsible for receiving and decrypting the encrypted logs from all terminal devices, using them for subsequent in-depth risk assessments and optimization of protection strategies.

[0088] This invention, by establishing a closed-loop security log generation and uploading mechanism, transforms each isolated endpoint protection event into valuable data nourishment for the continuous evolution of the entire security ecosystem. Through big data analysis of massive, multi-dimensional encrypted logs, the security management system can discover new, cross-device attack patterns and trends, achieving macro-level threat awareness. More importantly, based on these analysis results, the system can quantitatively evaluate the effectiveness of various protection strategies and, accordingly, push more precise policy updates to all endpoint devices. This includes adjusting preset thresholds for various risk assessments, optimizing the dynamic interference matrix generation algorithm, or upgrading the logic of personalized verification questions. This data-driven self-optimization and evolution capability enables the entire protection system to dynamically adapt to future unknown threats, and its overall security effectiveness continuously enhances over time and with ongoing offensive and defensive confrontations. Example

[0089] Please see Figure 2 As shown, based on Embodiment 1, the second aspect of the present invention provides an intelligent security protection system for preventing keyboard probing of payment devices, comprising: a keyboard generation module, a behavior analysis module, an environment analysis module, and an instruction generation module.

[0090] The keyboard generation module is connected to the behavior analysis module and the environment analysis module, respectively, and the instruction generation module is connected to the behavior analysis module and the environment analysis module, respectively.

[0091] The keyboard generation module is used to generate a virtual keyboard with a random layout and assign each key of the virtual keyboard an interference value that changes non-linearly with time in a dynamic interference matrix.

[0092] The behavior analysis module is used to collect the touch trajectory features generated by user input operations in real time, and compare the touch trajectory features with a behavior model that represents normal user input habits to generate behavior analysis results.

[0093] The environmental analysis module is used to collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, including ambient light intensity values, environmental image streams, and electromagnetic radiation signals; and compare the environmental perception data with an environmental model that characterizes the state of a safe environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals.

[0094] The instruction generation module is used to generate dynamic security protection instructions corresponding to the analysis results based on the behavior analysis results and the environmental risk analysis results. The dynamic security protection instructions include adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer.

[0095] The above content is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, and all such modifications and additions should fall within the protection scope of the present invention.

Claims

1. A smart security protection method for preventing keyboard probing in payment devices, characterized in that, include: Step 1: Generate a virtual keyboard with a random layout, and assign each key of the virtual keyboard an interference value that changes non-linearly with time in the dynamic interference matrix; Step 2: Collect the touch trajectory features generated by user input operations in real time, and compare the touch trajectory features with a behavior model that represents normal user input habits to generate behavior analysis results; Step 3: Collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, including ambient light intensity values, environmental image streams, and electromagnetic radiation signals; and compare the environmental perception data with an environmental model that characterizes the state of a safe environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals. Step 4: Based on the behavioral analysis results and environmental risk analysis results, generate dynamic safety protection instructions corresponding to the analysis results; The dynamic security protection command includes adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer; The dynamic security protection instructions corresponding to the analysis results are generated based on the behavior analysis results and the environmental risk analysis results. In step 4-1, after generating the behavior analysis results containing abnormal operation markers, the following linkage adjustment steps for dynamic security protection instructions are included: based on the touch coordinate information attached to the abnormal operation markers in the touch trajectory features, the current virtual keyboard layout is mapped to identify the key area directly corresponding to this abnormal input behavior. For the buttons within the button area, two parallel adjustment operations are performed. The first adjustment is for internal security parameters: accessing and modifying the dynamic interference matrix. The second adjustment is for real-time changes in the user interface: identifying all directly adjacent buttons in the button area, randomly swapping or shifting the layout positions of these adjacent buttons, and simultaneously changing their display colors to a set of preset high-contrast or visually confusing colors. Step 4-2: Generate environmental risk analysis results containing visual spying risk signals, including the following dynamic security protection command linkage adjustment steps: In anti-spying mode, perform two synchronous display interface rendering operations: First, call the view limitation algorithm for the virtual keyboard display area; Second, dynamically blur the non-current operation keys according to the user's touch input state. Step 4-3: Generate environmental risk analysis results containing electromagnetic theft risk signals, including the following dynamic security protection command linkage adjustment steps: After determining that there is an electromagnetic theft risk, trigger a dual response mechanism: on the one hand, send an activation command to the integrated electromagnetic shielding layer; on the other hand, synchronously adjust the defense strategy of the upper-layer software, that is, increase the generation frequency of the dynamic interference matrix.

2. The intelligent security protection method for preventing keyboard probing of payment devices according to claim 1, characterized in that, The process of generating a virtual keyboard with a random layout and assigning each key of the virtual keyboard an interference value that changes non-linearly over time in a dynamic interference matrix includes: When the payment device is started or the keyboard needs to be regenerated, a random number generator is invoked in conjunction with preset layout optimization rules to generate new key coordinates and arrangement order, and then passed to the virtual keyboard rendering unit to display the new keyboard layout on the screen. Initialize a dynamic interference matrix that matches the number of virtual keyboard keys, and assign an initial interference value to each key; Set a time trigger to periodically recalculate the value of each element in the interference matrix to generate new interference values. The calculation uses a non-linear function, and the updated interference values ​​are then applied to the rendering and input processing logic of the virtual keyboard.

3. The intelligent security protection method for preventing keyboard probing of payment devices according to claim 1, characterized in that, The real-time acquisition of touch trajectory features generated by user input operations includes: When a user's finger touches the virtual keyboard of the payment terminal, the touch processing unit of the payment device records the position of the user's finger on the screen in real time, forming a sequence of touch point coordinates containing a timestamp; Based on the touch point coordinate sequence, calculate the movement speed sequence and direction change rate sequence of the touch trajectory; At the same time, the pressure sensor integrated into the payment device synchronously captures the vertical force applied by the user at each touch point to generate a pressure value sequence; The movement speed sequence, direction change rate sequence, and pressure value sequence are integrated to form touch trajectory features.

4. The intelligent security protection method for preventing keyboard probing of payment devices according to claim 3, characterized in that, The step of comparing touch trajectory features with a behavioral model representing normal user input habits to generate behavioral analysis results includes: Based on touch trajectory features, speed features, direction features, and pressure features are separated and extracted, and then compared with a pre-established user personal behavior pattern database to generate speed matching degree, direction matching degree, and pressure matching degree. The calculated speed matching degree, direction matching degree, and pressure matching degree are compared with their respective preset thresholds. If any one or more of these three matching degrees are lower than their respective preset thresholds, it is determined that the input operation does not conform to the user's inherent behavior pattern, thereby generating a behavior analysis result containing abnormal operation markers.

5. The intelligent security protection method for preventing keyboard probing of payment devices according to claim 1, characterized in that, The step of comparing environmental perception data with an environmental model representing a safe environmental state to generate environmental risk analysis results includes: The payment device's built-in ambient light sensor is used to obtain quantified ambient light intensity values ​​in real time. Activate the payment device's miniature camera to continuously capture a stream of ambient images in front of the device at a set frame rate; The system compares the real-time ambient light intensity value with a preset light threshold. Simultaneously, it identifies the outlines or facial features of other target personnel in the environmental image. When other target personnel are detected, it further analyzes the pixel size occupied by the other target personnel in the image and estimates the physical distance between the personnel and the device, i.e., the personnel distance, based on the pre-calibrated camera parameters. When either the light intensity value is higher than the preset light threshold or the distance between people is less than the preset distance, an environmental risk analysis result containing visual spying risk signals is generated, thereby triggering and enabling the anti-spying mode.

6. The intelligent security protection method for preventing keyboard probing of payment devices according to claim 5, characterized in that, The step of comparing environmental perception data with an environmental model representing a safe environmental state to generate environmental risk analysis results also includes: The electromagnetic radiation monitoring unit, integrated below the keyboard area of ​​the payment device, collects electromagnetic radiation signals leaked outward during device operation in real time. The electromagnetic radiation signal is analyzed by the signal processing unit to extract key frequency bands and intensity features; The extracted frequency band and intensity features are dynamically compared with a pre-stored electromagnetic radiation baseline to generate environmental risk analysis results that include electromagnetic theft risk signals.

7. A smart security protection method for preventing keyboard probing in payment devices according to claim 1, characterized in that, The generation of environmental risk analysis results containing visual spying risk signals also includes the following linkage adjustment steps: While enabling view restriction processing and blurring processing, the screen recording attack detection unit is activated; The screen recording attack detection unit is used to calculate an index that quantifies the changes in the current screen, namely the pixel change frequency. Record the time of each touch operation by the user on the virtual keyboard to form a time sequence of user input operations; Analyze the correlation between pixel change frequency and user input operation time series. If abnormal pixel synchronous changes that are not causally related to user input are detected, it is determined that a screen recording attack exists. In response to the screen recording attack, two mandatory measures are triggered: first, the keyboard display is frozen, that is, all rendering updates to the virtual keyboard display area are stopped; second, a clear alert is issued to the user through an interface pop-up or status bar icon.

8. A smart security protection method for preventing keyboard probing in payment devices according to claim 1, characterized in that, The generation of environmental risk analysis results containing electromagnetic theft risk signals also includes the following linkage adjustment steps: While activating the electromagnetic shielding layer, the update frequency of interference values ​​in the dynamic interference matrix is ​​increased; If the electromagnetic theft risk signal indicates a continuous abnormal radiation state, the dynamic verification mechanism is triggered. The dynamic verification mechanism generates personalized verification questions based on a user's historical input habit model, or calls a multimodal biometric recognition module for secondary identity verification, and pauses keyboard input function before the verification is successful.

9. A smart security protection system for preventing keyboard probing in payment devices, characterized in that, include: The keyboard generation module is used to generate a virtual keyboard with a random layout and assign each key of the virtual keyboard an interference value that changes non-linearly over time in a dynamic interference matrix. The behavior analysis module is used to collect the touch trajectory features generated by user input operations in real time, and compare the touch trajectory features with a behavior model that represents normal user input habits to generate behavior analysis results; The environmental analysis module is used to collect environmental perception data generated by a multi-dimensional environmental sensor group consisting of an ambient light sensor, a miniature camera, and an electromagnetic radiation monitoring unit, including ambient light intensity values, environmental image streams, and electromagnetic radiation signals; and compare the environmental perception data with an environmental model that characterizes the state of a safe environment to generate environmental risk analysis results, including visual spying risk signals and electromagnetic theft risk signals. The instruction generation module is used to generate dynamic security protection instructions corresponding to the analysis results based on the behavioral analysis results and the environmental risk analysis results. The dynamic security protection command includes adjusting the interference value of the dynamic interference matrix, the key layout and display color of the virtual keyboard, and selectively enabling one or more physical layer protection measures such as viewing angle restriction processing, blurring processing, or electromagnetic shielding layer; The dynamic security protection instructions corresponding to the analysis results are generated based on the behavior analysis results and the environmental risk analysis results. In step 4-1, after generating the behavior analysis results containing abnormal operation markers, the following linkage adjustment steps for dynamic security protection instructions are included: based on the touch coordinate information attached to the abnormal operation markers in the touch trajectory features, the current virtual keyboard layout is mapped to identify the key area directly corresponding to this abnormal input behavior. For the buttons within the button area, two parallel adjustment operations are performed. The first adjustment is for internal security parameters: accessing and modifying the dynamic interference matrix. The second adjustment is for real-time changes in the user interface: identifying all directly adjacent buttons in the button area, randomly swapping or shifting the layout positions of these adjacent buttons, and simultaneously changing their display colors to a set of preset high-contrast or visually confusing colors. Step 4-2: Generate environmental risk analysis results containing visual spying risk signals, including the following dynamic security protection command linkage adjustment steps: In anti-spying mode, perform two synchronous display interface rendering operations: First, call the view limitation algorithm for the virtual keyboard display area; Second, dynamically blur the non-current operation keys according to the user's touch input state. Step 4-3: Generate environmental risk analysis results containing electromagnetic theft risk signals, including the following dynamic security protection command linkage adjustment steps: After determining that there is an electromagnetic theft risk, trigger a dual response mechanism: on the one hand, send an activation command to the integrated electromagnetic shielding layer; on the other hand, synchronously adjust the defense strategy of the upper-layer software, that is, increase the generation frequency of the dynamic interference matrix.

Citation Information

Patent Citations

  • Anti-peep input method and intelligent terminal

    CN103021080A

  • Virtual keyboard management method and device, computer equipment, readable storage medium and program product

    CN119475321A