Transaction platform safety early warning method, system, equipment and medium
By introducing a two-way authentication mechanism between security anchor points and terminals in financial transaction platforms, combined with biometric decryption and integrity verification, the quantum computing threat and hardware equipment security issues are resolved, achieving a safer full early warning of transactions.
Patent Information
- Application Number
- CN202510928582.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-10-17
Smart Images

Figure CN120806958A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of financial security, and in particular to a transaction platform security early warning method, system, device and medium. BACKGROUND
[0002] In today's digital age, the financial system, as the core of economic activities, its security and reliability are crucial. With the rapid development of Internet technology, the way of providing financial services is also evolving from traditional counter services to online transactions, and the digital transformation of the financial system has become an irreversible trend.
[0003] In this transformation process, the financial system relies more and more on data encryption technology. Data encryption technology is the cornerstone of protecting financial information security, which converts plaintext data into ciphertext through encryption algorithms to ensure the confidentiality of data in the process of transmission and storage. At present, the financial system mainly relies on self-generated keys (such as RSA key pairs), hardware security modules (SE) or trusted execution environment (TEE) internal keys, and user password-based key derivation to protect the security of financial information.
[0004] However, although the financial system has made significant progress in data encryption, it still faces some technical challenges in practical application. First, with the development of quantum computing technology, traditional encryption algorithms such as RSA may face the risk of being cracked, which poses a serious threat to the data security of the financial system. Second, when the financial system uses hardware SE / TEE internal keys, how to ensure the security and reliability of these hardware devices and how to prevent hardware devices from being maliciously attacked or tampered with are also important issues that the financial system needs to solve in data encryption. SUMMARY
[0005] The embodiments of the present application provide a transaction platform security early warning method, system, device and medium to realize a safer transaction platform security early warning.
[0006] In order to achieve the above purpose, the technical scheme adopted by the present application is as follows: In a first aspect, a method for security warning of a transaction platform is provided, which is applied to a security anchor point in a transaction security platform, and includes: receiving, by the security anchor point, an operation request message from a terminal, the operation request message indicating that a client requests to perform a first operation, the first operation being a transaction operation or a security modification operation for the transaction, and the client being a client corresponding to the transaction security platform on the terminal; in response to the client requesting to perform the first operation, triggering, by the security anchor point, two-way authentication between the security anchor point and the client; information used in the two-way authentication being determined based on a long-term key of the terminal, the long-term key being authorized to the transaction security platform by an operator to which the terminal belongs; in a case where the two-way authentication fails, determining, by the security anchor point, that there is a security risk, and rejecting to perform the first operation.
[0007] Optionally, the operation request message includes a hidden identifier of the client, and the method further includes: decrypting and integrity checking, by the security anchor point, the hidden identifier of the client; in a case where the decrypting and the integrity checking pass, obtaining a real identifier of the client, the real identifier of the client including a biological feature of a user of the client, the biological feature of the user being used to uniquely indicate the user; triggering, by the security anchor point, the two-way authentication between the security anchor point and the client, including: determining, by the security anchor point according to the biological feature of the user, whether the user is registered to the transaction security platform; if yes, triggering, by the security anchor point according to the biological feature of the user, the two-way authentication between the security anchor point and the client.
[0008] Optionally, the hidden identifier of the client includes a temporary public key and information that is encrypted and integrity protected, the temporary public key being derived based on the long-term key of the terminal, and the decrypting and the integrity checking, by the security anchor point, of the hidden identifier of the client include: determining, by the security anchor point according to the temporary public key in the hidden identifier, the temporary public key in the security anchor point locally; sending, by the security anchor point to the operator, the temporary public key and a first part of the biological feature of the user pre-stored in the security anchor point locally, obtaining a temporary confidentiality key and a temporary integrity key returned by the operator, the temporary confidentiality key and the temporary integrity key being derived by the operator based on the temporary public key, the first part of the biological feature of the user and a pre-stored private key of the operator; decrypting, by the security anchor point, the information that is encrypted and integrity protected using the temporary confidentiality key, and integrity checking, by the security anchor point, the information that is encrypted and integrity protected using the temporary integrity key; in a case where the decrypting and the integrity checking pass, obtaining a second part of the biological feature of the user; interlacing, by the security anchor point, the second part of the biological feature of the user and the first part of the biological feature of the user according to a preset rule to obtain the biological feature of the user; and determining, by the security anchor point according to the biological feature of the user, whether the user is registered to the transaction security platform, including: determining, by the security anchor point, whether the biological feature of the user is consistent with the biological feature of the user pre-stored in the security anchor point locally, if yes, indicating that the user is registered to the transaction security platform, otherwise, indicating that the user is not registered to the transaction security platform.
[0009] Optionally, a correlation between the second partial biometric feature of the user and the first partial biometric feature of the user is lower than a correlation lower limit value.
[0010] Optionally, the security anchor triggers a mutual authentication between the security anchor and the client, including: the security anchor generates an authentication token AUTN and an expected response XRES according to the long-term key of the user and the second partial biometric feature of the user; the security anchor sends the AUTN and a random number RAND to the terminal; in a case that the terminal authenticates the security anchor through the AUTN, the security anchor receives a response RES from the terminal; if the terminal fails to authenticate the security anchor through the AUTN, it indicates that the mutual authentication fails; the security anchor determines whether the RES is consistent with the XRES, if yes, it indicates that the mutual authentication passes, otherwise, the mutual authentication fails.
[0011] Optionally, the security anchor generates an authentication token AUTN and an expected response XRES according to the long-term key of the user and the second partial biometric feature of the user, including: the security anchor performs an exclusive-OR operation on the second partial biometric feature of the user and an anonymous key pre-stored in the security anchor to obtain a hidden biometric feature, the anonymous key is used to hide the second partial biometric feature of the user; the security anchor uses an f1 algorithm to calculate a message authentication code MAC using the long-term key of the terminal, the RAND and the second partial biometric feature of the user as input parameters, the AUTN includes the hidden biometric feature and the MAC; and the security anchor uses an f2 algorithm to calculate the XRES using the long-term key of the terminal, the RAND and the first partial biometric feature of the user as input parameters.
[0012] In a second aspect, a security verification method is provided, applied to a terminal, including: the terminal sends an operation request message to a security anchor in a transaction security platform, the operation request message indicates that a client requests to perform a first operation, the first operation is a transaction operation or a security modification operation for a transaction, and the client is a client corresponding to the transaction security platform on the terminal; in response to the client requesting to perform the first operation, the terminal participates in performing mutual authentication between the security anchor and the client; information used in the mutual authentication is determined based on a long-term key of the terminal; in a case that the mutual authentication fails, the terminal is at a security risk, and refuses to perform a response of the security anchor to the first operation.
[0013] Optionally, the terminal further comprises a user identity module (USIM), and the method further comprises: the client obtaining a biometric feature of a user of the client from a system layer of the terminal by calling the system layer; the client deinterleaving the biometric feature of the user to obtain a first part of the biometric feature of the user and a second part of the biometric feature of the user; the client sending the first part of the biometric feature of the user and the second part of the biometric feature of the user to the USIM; the USIM encrypting the second part of the biometric feature of the user using a temporary confidentiality key and integrity protecting the second part of the biometric feature of the user using a temporary integrity key to obtain encrypted and integrity protected information, the temporary confidentiality key and the temporary integrity key being derived by the USIM based on a temporary private key, the first part of the biometric feature of the user, and a preset public key of an operator to which the terminal belongs, the temporary private key being derived by the USIM based on a long-term key of the terminal; the USIM sending the encrypted and integrity protected information and a temporary public key to the client, the temporary public key being derived by the USIM based on the long-term key of the terminal; and the client carrying a concealed identity of the client into an operation request message, the concealed identity of the client comprising the temporary public key and the encrypted and integrity protected information.
[0014] Optionally, the terminal participates in performing bidirectional authentication between the security anchor point and the client, comprising: the terminal receiving an authentication token (AUTN) and a random number (RAND) from the security anchor point; the terminal authenticating the security anchor point through the AUTN; in a case where the terminal authenticates the security anchor point through the AUTN successfully, the terminal generates a response (RES), wherein if the terminal fails to authenticate the security anchor point through the AUTN, it indicates that the bidirectional authentication fails; and the terminal sending the RES to the security anchor point.
[0015] Optionally, the terminal authenticates the security anchor point through the AUTN, comprising: the client sending the AUTN and the RAND to the USIM; the USIM performing an exclusive or operation on an anonymity key and a biometric feature hidden in the AUTN to obtain the second part of the biometric feature of the user; the USIM calculating a message authentication code (MAC) using an f1 algorithm with the long-term key of the terminal, the RAND, and the second part of the biometric feature of the user as input parameters, and determining whether the MAC is consistent with a MAC in the AUTN; if yes, it indicates that the terminal authenticates the security anchor point through the AUTN successfully, otherwise, the bidirectional authentication fails; and correspondingly, the terminal generates the response RES, comprising: the USIM calculating the RES using an f2 algorithm with the long-term key of the terminal, the RAND, and the first part of the biometric feature of the user as input parameters; and the USIM sending the RES to the client.
[0016] In a third aspect, a security device is provided, and the security device is configured to perform the method according to the first aspect or the second aspect.
[0017] In a fourth aspect, a security system is provided, comprising a security anchor for performing the method according to the first aspect, and / or a terminal for performing the method according to the second aspect.
[0018] In a fifth aspect, a computer-readable storage medium is provided, comprising a computer program or instructions, which, when executed on a computer, cause the method according to any possible implementation of the first aspect or the second aspect to be performed.
[0019] In summary, the above method, device and system have the following technical effects: When the terminal initiates a transaction operation or a security modification operation for a transaction to the security anchor, i.e. a relatively sensitive financial operation, before performing the operation, the security anchor triggers a mutual authentication between the security anchor and the client, i.e. the security anchor needs to authenticate whether the terminal (or the client) is trustworthy, and the terminal (or the client) also needs to authenticate whether the security anchor (or the transaction security platform) is trustworthy. Only when both parties authenticate each other as trustworthy, the transaction operation or the security modification operation for a transaction is further performed, otherwise, in the case of a mutual authentication failure, such as the security anchor fails to authenticate the terminal, the security anchor determines that there is a security risk and refuses to perform the first operation, or such as the terminal fails to authenticate the security anchor, even if the security anchor replies to the response for the transaction operation or the security modification operation for a transaction, the terminal will reject the response to avoid further performing subsequent operations. As can be seen, the mutual authentication further improves the security, which can more safely and early warn the transaction. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 An architecture diagram of a security system provided by an embodiment of the present application is provided. Figure 2 A flow diagram of a transaction platform security warning method provided by an embodiment of the present application is provided. Figure 3 Figure 4 A structure diagram of a security device provided by an embodiment of the present application is provided. DETAILED DESCRIPTION
[0021] The technical solutions in the present application will be described below with reference to the accompanying drawings.
[0022] The present application will present various aspects, embodiments or features around a system which can include a plurality of devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all the devices, components, modules, etc. discussed in connection with the accompanying drawings. In addition, combinations of these solutions can also be used.
[0023] In addition, in the embodiments of the present application, the words "example", "for example", and the like are used herein to mean serving as an instance, illustration, or demonstration. Any embodiment or design solution described in the present application as "example" should not be interpreted as more preferred or having more advantages than other embodiments or design solutions. Rather, the word "example" is used in the sense of presenting a concept in a concrete manner.
[0024] In the embodiments of the present application, "information", "message", and "signaling" can be used interchangeably at times. It should be pointed out that when the distinction is not emphasized, the meanings expressed are matched. "Of", "corresponding", and "relevant" can be used interchangeably at times. It should be pointed out that when the distinction is not emphasized, the meanings expressed are matched. In addition, " / " mentioned in the present application can be used to represent the relationship of "or".
[0025] The architecture and business scenarios described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of the architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0026] To facilitate understanding of the embodiments of the present application, first, the security system shown in Figure 1 The security system shown in Figure 1 The architecture of a security system applicable to the method provided by the embodiments of the present application is shown in the figure.
[0027] As shown in Figure 1 , the security system includes a transaction security platform and a terminal.
[0028] The transaction security platform can be a third-party financial transaction platform, which can be an integration of multiple devices, such as being composed of a server cluster. A security anchor point is deployed in the transaction security platform, which can be deployed in a trusted execution environment of the transaction security platform to perform security-related functions. The security anchor point can be a functional entity, such as a virtual machine, a container, etc., that is, an entity integrated with software functions.
[0029] A terminal can also be referred to as a user device, mobile station, or mobile terminal. Terminal devices can be widely used in various scenarios. For example, a terminal can be a mobile phone, tablet computer, computer with wireless transceiver capabilities, wearable device, vehicle, aircraft, ship, robot, robotic arm, smart home appliance, etc. The functions of a terminal can also be performed by a module within the terminal (such as a chip or modem) or by a device that includes the functions of a terminal device. A terminal can consist of a client and a universal subscriber identity module (USIM). The client can be the client corresponding to the transaction security platform on the terminal, that is, it can be understood as the transaction security platform application (APP) installed on the terminal. The USIM module can be inserted or embedded in the terminal.
[0030] For ease of understanding, the following will be combined Figure 2 The interaction process between the various devices in the above security system is specifically described through a method embodiment. The transaction platform security warning method provided in the embodiment of the present application can be applied to the above security system, which is described in detail below.
[0031] Figure 2 The flowchart of the method for security early warning of a trading platform provided in an embodiment of the present application specifically relates to the interaction between the terminal and the security anchor point in the above-mentioned security system.
[0032] Specifically, such as Figure 2 As shown, the process of the trading platform security warning method is as follows: S201: The terminal sends an operation request message to a security anchor point in a transaction security platform, and the security anchor point receives the operation request message from the terminal.
[0033] The operation request message indicates that the client requests to perform a first operation, where the first operation is a transaction operation or a security modification operation for a transaction (such as modifying the user's account information, such as the user name and / or password, and / or modifying the user's private information, such as the bank card number, payment method, etc.).
[0034] The operation request message may also include the client's hidden identifier. This hidden identifier is achieved by securely protecting the user's biometrics, preventing direct transmission of clear text biometrics. The user can be understood as the user using the client. The user's biometrics uniquely identify the user and can include at least one of the user's facial information, voice characteristics, or fingerprint information.
[0035] Specifically, the client obtains the biological feature of the user using the client from the system layer of the terminal, that is, the biological feature of the user is input by the user to the terminal and saved to the system layer of the terminal. The client disentangles the biological feature of the user to obtain the first part of the biological feature of the user and the second part of the biological feature of the user, wherein the correlation between the second part of the biological feature of the user and the first part of the biological feature of the user is lower than the lower limit of the correlation, that is, the complete biological feature of the user is divided into two parts of decoupled biological features. Since the correlation is low, only one part of the biological feature cannot restore or infer the complete biological feature of the user, so as to ensure the privacy security of the user.
[0036] For example, the biological feature of the user is data of a preset length, such as 1536 bits of data, and the client can divide the biological feature of the user into M segments of sub-features, M is an even number greater than 5, such as 6, 8, 10, etc., such as 1024 bits of data divided into 6 segments, each segment of sub-feature is 256 bits of data. Then, the client can splice M / 2 segments of sub-features into one part of biological feature, and splice the remaining M-M / 2 segments of sub-features into another part of biological feature, and traverse all splicing modes. Taking M=6 as an example, including the first segment of sub-feature, the second segment of sub-feature, the third segment of sub-feature, the fourth segment of sub-feature, the fifth segment of sub-feature and the sixth segment of sub-feature. Mode 1: the first segment of sub-feature, the second segment of sub-feature and the third segment of sub-feature are spliced into one part of biological feature 1, and the fourth segment of sub-feature, the fifth segment of sub-feature and the sixth segment of sub-feature are spliced into another part of biological feature 1; mode 2: the first segment of sub-feature, the second segment of sub-feature and the fourth segment of sub-feature are spliced into one part of biological feature 2, and the third segment of sub-feature, the fifth segment of sub-feature and the sixth segment of sub-feature are spliced into another part of biological feature 2; mode 3: the first segment of sub-feature, the second segment of sub-feature and the fifth segment of sub-feature are spliced into one part of biological feature 3, and the third segment of sub-feature, the fourth segment of sub-feature and the sixth segment of sub-feature are spliced into another part of biological feature 3, and then the like is used. Traverse all splicing modes, that is, the principle of permutation and combination. Then, the client can calculate the correlation between one part of biological feature and another part of biological feature in each mode, such as Euclidean distance, cosine similarity, etc., so as to find the mode with the lowest correlation. The one part of biological feature in the mode with the lowest correlation is the first part of the biological feature of the user, and the other part of the biological feature is the second part of the biological feature of the user. At this time, the correlation between the second part of the biological feature of the user and the first part of the biological feature of the user is usually lower than the lower limit of the correlation.
[0037] Then, the client can send the first part of the biometric of the user and the second part of the biometric of the user to the USIM. The USIM can encrypt the second part of the biometric of the user using a temporary confidentiality key and integrity protect the second part of the biometric of the user using a temporary integrity key to obtain encrypted and integrity protected information. The temporary confidentiality key and the temporary integrity key are derived by the USIM based on a temporary private key, the first part of the biometric of the user and a pre-stored public key of an operator to which the terminal belongs. The temporary private key is derived by the USIM based on a long-term key of the terminal. For example, the USIM derives the temporary private key and the temporary public key as a temporary public-private key pair based on the long-term key of the terminal through an elliptic curve algorithm. The USIM can take the temporary private key, the first part of the biometric of the user and the pre-stored public key of the operator to which the terminal belongs (i.e. the home network of the terminal) as input parameters, calculate the input parameters through a key derivation algorithm, and derive the temporary confidentiality key and the temporary integrity key. It should be noted that the first part of the biometric of the user is used as the input parameter for key confusion.
[0038] Subsequently, the USIM can send the encrypted and integrity protected information and the temporary public key to the client, the temporary public key being derived by the USIM based on the long-term key of the terminal. Thus, the client can carry the hidden identifier of the client into the operation request message, the hidden identifier of the client including the temporary public key and the encrypted and integrity protected information, i.e. the client constructs the hidden identifier of the client based on the temporary public key and the encrypted and integrity protected information, and carries it into the operation request message.
[0039] S202, in response to the client requesting to perform the first operation, the security anchor triggers a mutual authentication between the security anchor and the client.
[0040] The information used in the mutual authentication is determined based on the long-term key of the terminal. The long-term key of the terminal is authorized by the operator to which the terminal belongs to the transaction security platform, such as being transmitted to the security anchor through a hardware security module (HSM) channel to ensure the security of the transmission.
[0041] Specifically, the security anchor point can decrypt and integrity check the hidden identity of the client. For example, the security anchor point determines the temporary public key in the security anchor point based on the temporary public key in the hidden identity. The security anchor point can derive the temporary public key and the temporary private key in advance based on the long-term key of the terminal using the same technical logic as the USIM. Thus, the security anchor point sends the temporary public key and the first part of the biometric feature of the user pre-stored in the security anchor point to the operator to obtain the temporary confidentiality key and the temporary integrity key returned by the operator, which are also derived by the operator based on the temporary public key, the first part of the biometric feature of the user, and the pre-stored private key of the operator. At this time, the information is also transmitted using the HSM channel to ensure the security of transmission. In other words, the pre-stored private key of the operator does not leave the operator to ensure security. The operator can derive the temporary confidentiality key and the temporary integrity key using the same technical logic as the USIM. The advantage of this design is that it can defend against more advanced attacks: for example, the security anchor point is invaded, but the security anchor point attacker only obtains the encrypted and integrity protected information and the long-term key of the terminal, but cannot decrypt the encrypted and integrity protected information (because the pre-stored private key of the operator is required). Conversely, the operator is invaded, and the attacker obtains the long-term key of the terminal and the first part of the biometric feature of the user, but because of the decoupling described above, the attacker cannot infer the complete biometric feature of the user.
[0042] It should be understood that the security anchor point has the complete biometric feature of the user, i.e., the biometric feature of the user described above, and the security anchor point can also de-interleave to obtain the first part of the biometric feature of the user and the second part of the biometric feature of the user using the same technical logic as the client in advance and save them locally.
[0043] Thus, the security anchor point can decrypt the encrypted and integrity protected information using the temporary confidentiality key and integrity check the encrypted and integrity protected information using the temporary integrity key; in the case of successful decryption and integrity check, the real identity of the client is obtained, which includes the biometric feature of the user of the client, or in the case of successful decryption and integrity check, the second part of the biometric feature of the user is obtained. The security anchor point locally interlaces the second part of the biometric feature of the user (i.e., the second part of the biometric feature obtained by decryption and integrity check) and the first part of the biometric feature of the user (i.e., the first part of the biometric feature saved in the local in advance) according to a preset rule to obtain the biometric feature of the user.
[0044] The security anchor point can determine whether the user is registered to the transaction security platform according to the biometric feature of the user (i.e., the biometric feature of the user obtained by the above-mentioned interleaving), such as determining whether the biometric feature of the user obtained by the above-mentioned interleaving is consistent with the biometric feature of the user pre-stored in the security anchor point (or the biometric feature of the user pre-stored locally in the security anchor point). If consistent, it indicates that the user is registered to the transaction security platform, otherwise, the user is not registered to the transaction security platform, and the process ends.
[0045] In the bidirectional authentication process: the security anchor point can generate an authentication token (AUTN) and an expected response (XRES) according to the long-term key of the user and the second part of the biometric feature of the user. For example, the security anchor point can perform an exclusive or operation on the second part of the biometric feature of the user and the anonymous key pre-stored in the security anchor point to obtain a hidden biometric feature, and the anonymous key is used to hide the second part of the biometric feature of the user. The security anchor point can use the f1 algorithm to calculate the message authentication code (MAC) by taking the long-term key of the terminal, the random number (RAND) and the second part of the biometric feature of the user as input parameters, and the AUTN includes the hidden biometric feature and the MAC; and the security anchor point can use the f2 algorithm to calculate the XRES by taking the long-term key of the terminal, the RAND and the first part of the biometric feature of the user as input parameters. It can be seen that the security processing of the second part of the biometric feature of the user here is different from when the terminal provides the second part of the biometric feature of the user, that is, different security mechanisms are adopted to further improve security. It should be pointed out that the input parameters here include the second part of the biometric feature of the user and the first part of the biometric feature of the user in order to avoid confusion between the AUTN and XRES generated here and the AUTN and XRES generated in other scenarios. In addition, since the second part of the biometric feature of the user and the first part of the biometric feature of the user can represent the identity of the user, they are also used as input parameters in bidirectional authentication to further improve the accuracy of the authentication of the identity of the user.
[0046] Afterwards, the security anchor point can send the AUTN and the RAND to the terminal. For the terminal, in response to the client request to perform the first operation, the terminal participates in performing the mutual authentication between the security anchor point and the client. For example, the terminal can receive the AUTN and the RAND from the security anchor point. The terminal can authenticate the security anchor point through the AUTN. For example, the client can send the AUTN and the RAND to the USIM. The USIM performs an exclusive-OR operation on the anonymous key and the biometric feature hidden in the AUTN to obtain the second part of the biometric feature of the user. The USIM can use the f1 algorithm to calculate the MAC by taking the long-term key of the terminal, the RAND, and the second part of the biometric feature of the user as input parameters, and determine whether the MAC obtained at this time is consistent with the MAC in the AUTN; if consistent, it indicates that the terminal passes the authentication of the security anchor point through the AUTN, otherwise, the mutual authentication fails, at this time, the terminal can determine a high-risk warning, i.e., platform impersonation. In the case that the terminal passes the authentication of the security anchor point through the AUTN, the terminal generates a response RES. For example, the USIM can use the f2 algorithm to calculate the RES by taking the long-term key of the terminal, the RAND, and the first part of the biometric feature of the user as input parameters, and send the RES to the client.
[0047] Thus, the terminal can send the RES to the security anchor point. Correspondingly, in the case that the terminal passes the authentication of the security anchor point through the AUTN, the security anchor point receives the response RES from the terminal; wherein, if the terminal fails to pass the authentication of the security anchor point through the AUTN, it indicates that the mutual authentication fails; the security anchor point can determine whether the RES is consistent with the XRES, if consistent, it indicates that the mutual authentication passes, otherwise, the mutual authentication fails, at this time, the security anchor point can determine a medium-high risk warning (invalid credentials of any terminal / intermediate tampering).
[0048] S203, in the case that the mutual authentication fails, the security anchor point determines that there is a security risk, and refuses to perform the first operation, and in the case that the mutual authentication fails, the terminal determines that there is a security risk, and refuses to perform the response of the security anchor point to the first operation.
[0049] Conversely, in the case that the mutual authentication passes, the security anchor point and the terminal can derive a confidentiality protection key and an integrity protection key based on the long-term key of the terminal, respectively. The confidentiality protection key is used to encrypt sensitive transaction instructions and communication content, and the integrity protection key is used to guarantee the integrity of transaction instructions and key messages (calculate MAC).
[0050] In summary, when the terminal initiates a transaction operation or a security modification operation for a transaction to the security anchor point, i.e., a relatively sensitive financial operation, the security anchor point triggers a mutual authentication between the security anchor point and the client before performing the operation, i.e., the security anchor point needs to authenticate whether the terminal (or the client) is trusted, and the terminal (or the client) also needs to authenticate whether the security anchor point (or the transaction security platform) is trusted. Only when both parties authenticate each other as trusted, the transaction operation or the security modification operation for the transaction is further performed, otherwise, in the case of a mutual authentication failure, such as the security anchor point fails to authenticate the terminal, the security anchor point determines that there is a security risk and refuses to perform the first operation, or such as the terminal fails to authenticate the security anchor point, even if the security anchor point replies a response to the transaction operation or the security modification operation for the transaction, the terminal will reject the response to avoid continuing to perform subsequent operations. As can be seen, the mutual authentication further improves the security, which can more safely and early warn the transaction.
[0051] It should be further noted that in the present application, the long-term key of the terminal provided by the operator + biometric encryption + fusion authentication is a new security method, which can realize that the financial system completes biometric binding authentication by using the operator root key without obtaining the biometric plaintext. In addition, the user needs to perform the method of the present application every time the transaction is performed, which solves the problem of verifying the local biometric result by the remote system. In addition, it meets the "privacy design" requirement of the biometric feature (i.e., the plaintext cannot be accessed in transmission).
[0052] The above Figure 2 The method for transaction platform security warning provided by the embodiments of the present application is described in detail. The following Figure 3 and Figure 4 The security device for performing the method for transaction platform security warning provided by the embodiments of the present application is described in detail.
[0053] Figure 3 is the structure of the security device provided by the embodiments of the present application Figure 1 . For example, as Figure 3 shown, the security device 300 includes a transceiver module 301 and a processing module 302. For ease of description, Figure 3 only the main components of the security device are shown.
[0054] The security device 300 can be applied to Figure 1 the security system shown in the above method, and perform the functions of the terminal or the security anchor point in the above method.
[0055] For example, the transceiver module 301 can perform the transceiving functions of the terminal or the security anchor point described above, and the processing module 302 can perform other functions of the terminal or the security anchor point described above except the transceiving functions. Alternatively, the transceiver module 301 can include a sending module (Figure 3 Not shown) and the receiving module ( Figure 3 The sending module is used to implement the sending function of the security device 300, and the receiving module is used to implement the receiving function of the security device 300. Optionally, the security device 300 may further include a storage module ( Figure 3 (not shown in the figure), the storage module stores a program or instruction. When the processing module 302 executes the program or instruction, the security device 300 can perform the functions of the NSMS providing entity or the network slice management function providing entity in the above method. In addition, the technical effect of the security device 300 can be referred to Figure 2 The technical effects of the trading platform security warning method shown are not repeated here.
[0056] Figure 4 Schematic diagram of the structure of the safety device provided in the embodiment of the present application Figure 2 For example, the security device may be a terminal, or a chip (system) or other component or assembly that can be set in the terminal. Figure 4 As shown, the security device 400 may include a processor 401. Optionally, the security device 400 may further include a memory 402 and / or a transceiver 403. The processor 401 is coupled to the memory 402 and the transceiver 403, for example, via a communication bus.
[0057] The following combination Figure 4 The following describes in detail the components of the security device 400: Processor 401 is the control center of security device 400 and can be a single processor or a collective term for multiple processing elements. For example, processor 401 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0058] Optionally, the processor 401 can execute various functions of the security device 400 by running or executing the software program stored in the memory 402 and calling the data stored in the memory 402, such as executing the above Figure 2 The method of security warning of the trading platform is shown.
[0059] In particular implementations, as one example, the processor 401 can include one or more CPUs, such as the CPU0 and CPU1 shown in FIG. 4. Figure 4
[0060] In particular implementations, as one example, the security device 400 can also include multiple processors, such as the processor 401 and the processor 404 shown in FIG. 4. Each of these processors can be a single-CPU or a multi-CPU. A processor here can refer to one or more devices, circuits, and / or processing cores for processing data, such as computer program instructions. Figure 4
[0061] The memory 402 is configured to store software programs for implementing the solutions of the present application, and the processor 401 is configured to control the execution of the software programs. The specific implementation manners can refer to the above method embodiments, which will not be repeated here.
[0062] Alternatively, the memory 402 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory 402 can be integrated with the processor 401 or exist independently and be coupled to the processor 401 through an interface circuit (not shown in FIG. 4) of the security device 400. The embodiments of the present application are not limited in this regard. Figure 4
[0063] The transceiver 403 is configured to communicate with other security devices. For example, the security device 400 is a terminal, and the transceiver 403 can be configured to communicate with a security anchor point or another terminal. For another example, the security device 400 is a security anchor point, and the transceiver 403 can be configured to communicate with a terminal or another security anchor point.
[0064] Optionally, the transceiver 403 can include a receiver and a transmitter (Figure 4 The receiver is configured to implement the receiving function, and the transmitter is configured to implement the transmitting function.
[0065] Optionally, the transceiver 403 can be integrated with the processor 401, or can exist independently, and is coupled with the processor 401 through an interface circuit (not shown in the figure) of the security device 400. The security device 400 can be connected to a network through the transceiver 403, and can communicate with other devices through the network. Figure 4 The security device 400 shown in the figure does not constitute a limitation on the security device, and the actual security device can include more or fewer components than shown in the figure, or combine certain components, or different component arrangements.
[0066] It can be understood that the structure of the security device 400 shown in the figure does not constitute a limitation on the security device, and the actual security device can include more or fewer components than shown in the figure, or combine certain components, or different component arrangements. Figure 4 The structure of the security device 400 shown in the figure does not constitute a limitation on the security device, and the actual security device can include more or fewer components than shown in the figure, or combine certain components, or different component arrangements.
[0067] In addition, the technical effects of the security device 400 can refer to the technical effects of the methods described in the above method embodiments, which will not be described here.
[0068] The above embodiments can be implemented in whole or in part by software, hardware (such as circuitry), firmware, or any combination thereof. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the flow or function described in the embodiments of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid state disk.
[0069] It should be understood that the term "and / or" in this document is merely used to describe associated relationship, and it can mean three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In addition, the character " / " in this document generally means that the associated objects before and after the " / " are in an "or" relationship, but can also mean an "and / or" relationship, which can be understood according to the context before and after.
[0070] In this application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or the like means any combination of the items, including a single item or any combination of multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be singular or plural.
[0071] It should be understood that in various embodiments of the present application, the size of the sequence number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0072] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0073] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the above-described system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0074] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be realized by other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed objects can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.
[0075] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e. may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0076] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.
[0077] The functions, if realized in the form of software functional units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.
[0078] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for security early warning of a trading platform, characterized in that: Security anchors used in the transaction security platform include: The security anchor receives an operation request message from a terminal, where the operation request message indicates that a client requests to perform a first operation, where the first operation is a transaction operation or a security modification operation for a transaction, and the client is a client corresponding to the transaction security platform on the terminal; In response to the client requesting to perform the first operation, the security anchor triggers a two-way authentication between the security anchor and the client; information used in the two-way authentication is determined based on a long-term key of the terminal, and the long-term key is authorized to the transaction security platform by the operator to which the terminal belongs; In the event that the two-way authentication fails, the security anchor point determines that there is a security risk and refuses to perform the first operation.
2. The method according to claim 1, characterized in that The operation request message includes a hidden identifier of the client, and the method further includes: The security anchor point decrypts and performs integrity verification on the hidden identifier of the client; If the decryption and integrity check pass, the real identification of the client is obtained, where the real identification of the client includes a biometric feature of a user using the client, and the biometric feature of the user is used to uniquely identify the user; The security anchor point triggers a two-way authentication between the security anchor point and the client, including: The security anchor determines, based on the biometrics of the user, whether the user is registered on the transaction security platform; If so, the security anchor point triggers a two-way authentication between the security anchor point and the client according to the biometric feature of the user.
3. The method according to claim 2, characterized in that The hidden identifier of the client includes a temporary public key and encrypted and integrity-protected information, where the temporary public key is derived from a long-term key of the terminal. The security anchor point decrypts and performs integrity verification on the hidden identifier of the client, including: The security anchor point determines the temporary public key locally in the security anchor point according to the temporary public key in the hidden identifier; The security anchor point sends the temporary public key and the first part of the user's biometric feature preset locally at the security anchor point to the operator, and obtains a temporary confidentiality key and a temporary integrity key returned by the operator, where the temporary confidentiality key and the temporary integrity key are derived by the operator based on the temporary public key, the first part of the user's biometric feature, and the operator's preset private key; The security anchor point decrypts the encrypted and integrity-protected information using the temporary confidentiality key, and performs integrity check on the encrypted and integrity-protected information using the temporary integrity key; If the decryption and integrity check pass, obtaining the second part of the user's biometric features; The security anchor point locally interweaves the second part of the user's biometric features with the first part of the user's biometric features according to a preset rule to obtain the user's biometric features; The security anchor point determines, based on the biometrics of the user, whether the user is registered on the transaction security platform, including: The security anchor point determines whether the user's biometric features are consistent with the biometric features preset by the user locally at the security anchor point. If they are consistent, it means that the user is registered with the transaction security platform. Otherwise, the user is not registered with the transaction security platform.
4. The method according to claim 3, characterized in that The correlation between the second part of the user's biometric features and the first part of the user's biometric features is lower than a lower correlation limit.
5. The method according to claim 3 or 4, characterized in that The security anchor point triggers a two-way authentication between the security anchor point and the client, including: The security anchor generates an authentication token AUTN and an expected response XRES according to the long-term key of the user and the second part of the biometric feature of the user; The security anchor point sends the AUTN and the random number RAND to the terminal; In the case where the terminal authenticates the security anchor point through the AUTN, the security anchor point receives a response RES from the terminal; wherein, if the terminal fails to authenticate the security anchor point through the AUTN, it indicates that the two-way authentication fails; The security anchor point determines whether the RES is consistent with the XRES. If they are consistent, it means that the two-way authentication is passed; otherwise, the two-way authentication fails.
6. The method according to claim 5, characterized in that The security anchor generates an authentication token AUTN and an expected response XRES based on the user's long-term key and the second part of the user's biometrics, including: The security anchor performs an exclusive OR operation on the second part of the user's biometric feature and an anonymous key preset by the security anchor to obtain a hidden biometric feature, wherein the anonymous key is used to hide the second part of the user's biometric feature; The security anchor uses the f1 algorithm to calculate the long-term key of the terminal, the RAND, and the second part of the user's biometric characteristics as input parameters to obtain a message authentication code MAC, wherein the AUTN includes the hidden biometric characteristics and the MAC; and The security anchor point uses the f2 algorithm to calculate the long-term key of the terminal, the RAND and the first part of the biometric feature of the user as input parameters to obtain XRES.
7. A security verification method, characterized in that: Applied to terminals, including: The terminal sends an operation request message to a security anchor in the transaction security platform, wherein the operation request message indicates that the client requests to perform a first operation, where the first operation is a transaction operation or a security modification operation for a transaction, and the client is a client corresponding to the transaction security platform on the terminal; In response to the client requesting to perform the first operation, the terminal participates in performing a two-way authentication between the security anchor point and the client; information used in the two-way authentication is determined based on a long-term key of the terminal; In the case where the two-way authentication fails, the terminal has a security risk and refuses to execute the response of the security anchor point to the first operation.
8. The method according to claim 7, characterized in that The terminal further includes a user identity module (USIM), and the method further includes: The client acquires biometric features of a user using the client from the system layer by calling the system layer of the terminal; The client deinterleaves the biometric features of the user to obtain a first portion of the biometric features of the user and a second portion of the biometric features of the user; The client sends the first partial biometric feature of the user and the second partial biometric feature of the user to the USIM; The USIM encrypts the second part of the user's biometric feature using a temporary confidentiality key, and performs integrity protection on the second part of the user's biometric feature using a temporary integrity key, to obtain encrypted and integrity-protected information, where the temporary confidentiality key and the temporary integrity key are derived by the USIM based on a temporary private key, the first part of the user's biometric feature, and a preset public key of the operator to which the terminal belongs, and the temporary private key is derived by the USIM based on a long-term key of the terminal. The USIM sends the encrypted and integrity-protected information and a temporary public key to the client, where the temporary public key is derived by the USIM based on the long-term key of the terminal; The client carries the hidden identifier of the client into the operation request message, where the hidden identifier of the client includes the temporary public key and the encrypted and integrity-protected information.
9. The method according to claim 8, characterized in that The terminal participates in performing bidirectional authentication between the security anchor point and the client, including: The terminal receives the authentication token AUTN and the random number RAND from the security anchor point; The terminal authenticates the security anchor point through the AUTN; If the terminal passes the authentication of the security anchor point through the AUTN, the terminal generates a response RES, wherein if the terminal fails to authenticate the security anchor point through the AUTN, it indicates that the two-way authentication fails; The terminal sends the RES to the security anchor point.
10. The method according to claim 9, characterized in that The terminal authenticating the security anchor point through the AUTN includes: The client sends the AUTN and the RAND to the USIM; The USIM performs an XOR operation on the anonymous key and the biometric feature hidden in the AUTN to obtain a second part of the user's biometric feature; The USIM calculates using the f1 algorithm the long-term key of the terminal, the RAND, and the second part of the user's biometric features as input parameters to obtain a message authentication code (MAC), and determines whether the MAC is consistent with the MAC in the AUTN; if they are consistent, it indicates that the terminal has authenticated the security anchor point through the AUTN; otherwise, the two-way authentication fails; Accordingly, the terminal generates a response RES, including: The USIM uses the f2 algorithm to calculate the long-term key of the terminal, the RAND and the first part of the user's biometric characteristics as input parameters to obtain RES; The USIM sends the RES to the client.