Method for protecting safety of UKEY circuit, secret key downloading method and electronic equipment

By negotiating the line key between the client and the UKEY and encrypting the transmitted data, the security risks in the UKEY password transmission process are resolved, and secure transmission of data and instructions is achieved.

CN121508835APending Publication Date: 2026-02-10FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511874669.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, passwords stored in a U-key are easily leaked during transmission, posing a security risk. Furthermore, the U-key cannot verify whether the received instructions were sent by a legitimate client.

Method used

Before establishing a connection between the client and the UKEY, a line negotiation certificate is obtained and its legitimacy is verified by sending a line key negotiation request. The line key is then encrypted using the public key in the line negotiation certificate, and the negotiated line key is used for encryption when transmitting data.

Benefits of technology

The security of UKEY line transmission has been improved, ensuring the security of passwords and data during transmission, and guaranteeing that UKEY only receives instructions from legitimate clients, thus preventing password leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508835A_ABST
    Figure CN121508835A_ABST
Patent Text Reader

Abstract

The invention discloses a UKEY line security protection method, a secret key downloading method and electronic equipment, the method is applied to a security client, the security client is connected with a UKEY end, and the method comprises the following steps: sending a negotiation line secret key request to the UKEY end, and receiving a line negotiation certificate returned by the UKEY end; after verifying the legality of the line negotiation certificate, taking out the public key from the line negotiation certificate; generating a line key, calculating a first verification value of the line key, encrypting the line key through a public key to obtain an encryption key, and sending the first verification value and the encryption key to the UKEY end; driving the UKEY end to decrypt the encryption key, and verifying a decryption result according to the verification value to obtain a line key; and when the ciphertext data is sent to the UKEY end, encrypting the ciphertext data through the line key. And data transmission between the client and the UKEY end is encrypted based on the negotiated line key, so that the security of the transmission process is protected when the client inputs a password or transmits data, and the UKEY is ensured to only receive an instruction sent by a legal client.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of financial payment, in particular to a UKEY line security protection method, a key download method and an electronic device. BACKGROUND

[0002] In the related art, the key applied to the UKEY is used to encrypt and decrypt data and read sensitive data. When the UKEY is used, a password needs to be input in a login stage, and only after the password is correctly input, various functions in the UKEY can be used. However, the password is easily leaked in the use process, and there is a security risk. SUMMARY

[0003] The present application solves the technical problem of providing a UKEY line security protection method, a key download method and an electronic device to protect the security of the password in the transmission process.

[0004] To solve the above technical problem, one technical solution adopted by the present application is: A UKEY line security protection method applied to a secure client, wherein the secure client is connected with a UKEY end, and the method comprises the following steps: sending a negotiation line key request to the UKEY end, and receiving a line negotiation certificate returned by the UKEY end; verifying the legality of the line negotiation certificate, and taking a public key from the line negotiation certificate; generating a line key, calculating a first check value of the line key, and encrypting the line key by the public key to obtain an encrypted key, and sending the first check value and the encrypted key to the UKEY end; driving the UKEY end to decrypt the encrypted key, and verifying the decryption result according to the check value to obtain the line key; and encrypting ciphertext data sent to the UKEY end by the line key.

[0005] To solve the above technical problem, another technical solution adopted by the present application is: A UKEY line security protection method applied to a UKEY end, wherein the UKEY is connected with a secure client, and the method comprises the following steps: receiving a negotiation line key request sent by the secure client, and returning a line negotiation certificate to the secure client; instructing the secure client to generate a line key after verifying the legality of the line negotiation certificate, and obtaining a first check value and an encrypted key according to the line key and the line negotiation certificate; receiving the first check value and the encrypted key sent by the secure client; decrypting the encrypted key by a private key of the line negotiation certificate to obtain the line key, and calculating a second check value of the line key; if the second check value is consistent with the first check value, saving the line key; and decrypting ciphertext data sent by the secure client by the line key.

[0006] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: A key download method is applied to a payment system, the payment system including a secure client, a UKEY terminal, a payment terminal, and a key server; the UKEY terminal, the payment terminal, and the key server are all connected to the client; the method includes: the secure client establishing a connection with the UKEY terminal using a method for protecting the UKEY line security as described above; or the UKEY terminal establishing a connection with the secure client using a method for protecting the UKEY line security as described above; the payment terminal importing a certificate through the secure client and the key server; the payment terminal sending a unique serial number and a certificate to the key server through the secure client; the key server checking the unique serial number and the certificate, and if both are valid, obtaining a unique identifier key corresponding to the unique serial number, and generating verification data based on the unique identifier key and the certificate; the key server sending the verification data to the payment terminal through the client; the payment terminal decrypting the verification data to obtain the unique identifier key, verifying the validity of the unique identifier key, and if the verification is successful, saving the unique identifier key.

[0007] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: An electronic device includes a memory, a processor, and a computer program stored in the memory and running on the processor. The electronic device can be used as a secure client or a U-key terminal. When used as a secure client, the processor executes the computer program to implement the steps of the secure client in the method for protecting the security of a U-key line as described above. When used as a U-key terminal, the processor executes the computer program to implement the steps of the U-key terminal in the method for protecting the security of a U-key line as described above.

[0008] The beneficial effects of this invention are as follows: Before establishing a connection between the client and the UKEY, the client sends a request to the UKEY to negotiate the line key, obtains a line negotiation certificate, and verifies its legitimacy. Then, the line key is encrypted using the public key in the line negotiation certificate. The encrypted key and the verification value are then sent to the UKEY for verification. Once the UKEY completes the verification, data transmission between the client and the UKEY can be encrypted based on the negotiated line key. This allows encryption of the password and transmitted data when the client enters the password or transmits data, protecting the security of the password and related data during transmission. It also ensures that the UKEY only receives instructions from legitimate clients, preventing password leakage during use and improving security. Attached Figure Description

[0009] Figure 1 This is a flowchart illustrating the steps of a method for protecting the security of a UKEY line applied to a secure client in an embodiment of the present invention. Figure 2 This is a flowchart illustrating the steps of a method for protecting the security of a UKEY line applied to the UKEY terminal in an embodiment of the present invention. Figure 3 This is a flowchart illustrating the steps of a key downloading method according to an embodiment of the present invention; Figure 4 This is an interactive schematic diagram of a payment system according to an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating the interaction between the security client and the UKEY terminal in a method for protecting the security of a UKEY line according to an embodiment of the present invention. Figure 6 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0010] Table 1. Glossary

[0011] The core functions of UKEY are shown in Table 2: Table 2. Core Functions of UKEY

[0012] To make the technical problems, technical solutions, and beneficial effects to be solved by this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and are not intended to limit the scope of this application.

[0013] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0014] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0015] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0016] The related technology requires the use of keys within the U-Key for data encryption / decryption and reading of sensitive data. When using a U-Key, a PIN code must be entered during login; only after correctly entering the PIN code can the various functions of the U-Key be used. However, the password and other data within the U-Key are transmitted in plaintext between the client and the U-Key. If a Trojan horse is implanted on the PC client, or if a listening device is implanted in the hardware where the U-Key is inserted, the PIN code will be leaked. That is, after the U-Key holder enters the correct PIN code, the Trojan program can begin operating the U-Key. The U-Key cannot verify whether the received instructions are from a legitimate client and can only passively be controlled by the Trojan program.

[0017] To address the aforementioned issues, this application provides a method for protecting the security of a UKEY line, a key download method, and an electronic device.

[0018] The following section details the method for protecting the security of the UKEY line as described in this application.

[0019] This application provides a method for protecting the security of a U-key connection. It is applied to a secure client connected to the U-key. The secure client can be a secure production PC or other verified PC tools running dedicated production tools (i.e., applications used to execute the method).

[0020] Please refer to Figure 1 The method includes steps 110-140: Step 110: Send a line key negotiation request to the UKEY terminal and receive the line negotiation certificate returned by the UKEY terminal. For example, after the secure PC sends a line key negotiation request to the UKEY terminal, the UKEY terminal returns a line negotiation certificate CERT_UKEY.

[0021] Step 120: After verifying the validity of the line negotiation certificate, retrieve the public key from the line negotiation certificate. Specifically, after the secure PC verifies that the line negotiation certificate CERT_UKEY is a valid certificate, it will retrieve the public key Pub_ukey from the CERT_UKEY.

[0022] Step 130: Generate a line key, calculate the first checksum of the line key, and encrypt the line key using the public key to obtain the encryption key. Send the checksum and encryption key to the UKEY terminal. The UKEY terminal then decrypts the encryption key and verifies the decryption result based on the checksum to obtain the line key. For example, if the generated line key is SK1, encrypt the line key SK1 using the public key Pub_ukey to obtain the encryption key E(SK1, Pub_ukey); calculate the first checksum of the line key SK1; then, the UKEY terminal decrypts the encryption key E(SK1, Pub_ukey) using the private key Pri_ukey to obtain the line key SK1, and calculates whether the checksum of the line key SK1 matches the received first checksum. If they match, save the line key SK1, completing the negotiation of the line key SK1.

[0023] Step 140: When sending encrypted data to the UKEY, the encrypted data is encrypted using the line key. That is, after negotiating the line key SK1, the secure client and the UKEY encrypt the encrypted data using the line key SK1 for data transmission. Encrypted data refers to data that needs to be encrypted during transmission.

[0024] As described above, before establishing a connection between the client and the UKEY, the client sends a request to the UKEY to negotiate the line key, obtain a line negotiation certificate, and verify its legitimacy. Then, the client encrypts the line key using the public key in the line negotiation certificate and sends the encryption key and verification value to the UKEY for verification. Once the UKEY completes the verification, data transmission between the client and the UKEY can be encrypted based on the negotiated line key. This allows encryption of the password and transmitted data when the client enters the password or transmits data, protecting the security of the password and related data during transmission. Furthermore, it ensures that the UKEY only receives instructions from legitimate clients, preventing password leakage during use and improving security.

[0025] In one embodiment of this application, before sending the line key negotiation request to the UKEY terminal in step 110, step 100 is included: pre-setting the superior certificate in the secure client. That is, the superior certificate of the UKEY line negotiation certificate needs to be pre-set in the secure client; at the same time, the secure client has high security and can prevent the superior certificate of the UKEY line negotiation certificate from being obtained or modified.

[0026] Step 120, retrieving the public key from the line negotiation certificate, includes: verifying the validity and integrity of the line negotiation certificate through the superior certificate; if so, the line negotiation certificate is valid, and the public key is retrieved from the line negotiation certificate. That is, when verifying the line negotiation certificate, the validity and integrity of the line negotiation certificate CERT_UKEY are verified through the certificate chain of the superior certificate of the pre-set UKEY line negotiation certificate.

[0027] As can be seen from the above embodiments, by pre-installing a superior certificate in the secure client and verifying the validity and integrity of the line negotiation certificate through the certificate chain of the superior certificate, the legitimacy of the UKEY is ensured, and the secure client is guaranteed not to transmit passwords and other data to illegal entities.

[0028] In one embodiment of this application, generating the line key in step 130 includes: The system generates a random number of bytes with a preset length and uses this random number as the line key. For example, the secure client generates a 32-byte random number as the line key SK1. The number of bytes can be set to 16, 32, 64, or other values ​​depending on the actual requirements.

[0029] As can be seen from the above embodiments, by generating random numbers to generate the line key, the secure client and the UKEY terminal obtain the line key by generating random numbers each time they negotiate the line key, so that the line key negotiated each time is different. In this way, even if the line key is leaked in an interaction, it cannot be used for the next communication, thereby improving the security of data transmission.

[0030] In one embodiment of this application, encrypting the ciphertext data using the line key in step 140 includes: If the encrypted data is the input password, the encrypted password is obtained by encrypting the password using the line key and then sent to the UKEY. For example, after the user enters a PIN code on the secure client, the secure client will encrypt the PIN code using the line key SK1 to obtain the encrypted password E(PIN,SK1), and then send the encrypted password E(PIN,SK1) to the UKEY. Subsequently, the UKEY will decrypt the encrypted password E(PIN,SK1) using the same line key SK1 to obtain the PIN code.

[0031] The system receives response data from the UKEY and accesses the data stored in the UKEY based on the response data. For example, if the UKEY decrypts and obtains a PIN code, it compares the decrypted PIN code with the PIN code stored in the UKEY. If they match, the PIN code authentication is successful, allowing the secure client to begin using the sensitive data in the UKEY.

[0032] As can be seen from the above embodiments, the input password is encrypted using the line key negotiated between the secure client and the UKEY before being sent to the UKEY. This ensures that only the UKEY with the same line key can decrypt the encrypted password, thereby guaranteeing the security of the password during transmission.

[0033] In one embodiment of this application, encrypting the ciphertext data using the line key in step 140 includes: If the encrypted data is information data, it is encrypted using the line key to obtain encrypted data, which is then sent to the UKEY. For example, when the secure client needs to send some data, calculation instructions, or other information to the UKEY, it will encrypt the data using the line key SK1 before sending it to the UKEY. The UKEY will then decrypt the data and instructions using the line key SK1, process the data and instructions, and then send them back to the secure client using the line key.

[0034] As can be seen from the above embodiments, by encrypting the data and instructions transmitted from the security client to the UKEY before sending them to the UKEY, the data or instructions are prevented from being modified, thereby improving the security of the transmitted data and instructions.

[0035] In one embodiment of this application, step 140, which involves encrypting information data using a line key to obtain encrypted data and sending the encrypted data to the UKEY terminal, includes: The encrypted data is obtained by encrypting the private key calculation instruction in the information data using the line key and the original data, and then sent to the UKEY terminal. The UKEY terminal is then instructed to decrypt the encrypted data using the line key and encrypt the original data based on the private key calculation instruction. When the secure client sends the private key calculation instruction CMD and the original data DATA, it encrypts the data using the line key SK1 to obtain encrypted data E(CMD+DATA, SK1), and sends E(CMD+DATA, SK1) to the UKEY terminal. The UKEY terminal then decrypts E(CMD+DATA, SK1) using the line key SK1 to obtain the private key calculation instruction CMD and the original data DATA. Based on the private key calculation instruction CMD, it obtains the private key Pri (this private key Pri is not the private key Pri_ukey used during line negotiation, but is used as an example to sign data using the private key in the UKEY), encrypts the original data DATA to obtain data E(DATA, Pri). This encryption can refer to signing the original data DATA and then encrypting the data (DATA, Pri) using the line key SK1 to obtain E(E(DATA, Pri), SK1), which is then sent to the secure client.

[0036] As can be seen from the above embodiments, by encrypting the key calculation instructions and original data transmitted from the secure client to the UKEY before sending them to the UKEY, the key calculation instructions and original data are prevented from being modified, thereby improving the security of the transmitted data and instructions.

[0037] Another embodiment of this application provides a method for protecting the security of a U-key connection, applied to the U-key terminal, where the U-key is connected to a secure client. Please refer to... Figure 2 The method includes steps 210-240: Step 210: Receive the line key negotiation request sent by the security client and return the line negotiation certificate to the security client; instruct the security client to generate a line key after verifying the validity of the line negotiation certificate, and obtain the first verification value and encryption key based on the line key and the line negotiation certificate. That is, after receiving the line key negotiation request, the UKEY terminal will return the line negotiation certificate CERT_UKEY to the security client, and obtain the first verification value and encryption key E(SK1, Pub_ukey) based on the line negotiation certificate CERT_UKEY.

[0038] Step 220: Receive the first verification value and encryption key sent by the secure client; that is, receive the first verification value and encryption key E(SK1, Pub_ukey).

[0039] Step 230: Decrypt the encryption key using the private key of the line negotiation certificate to obtain the line key, and calculate the second check value of the line key; if the second check value matches the first check value, save the line key. The UKEY terminal uses the private key Pri_ukey to decrypt the encryption key E(SK1, Pub_ukey) to obtain the line key SK1, and calculates whether the second check value of the line key SK1 matches the received first check value. If they match, save the line key SK1, completing the negotiation of the line key SK1.

[0040] Step 240: Decrypt the encrypted data sent by the secure client using the line key SK1. That is, subsequent data transmissions to the secure client will be encrypted using the line key SK1.

[0041] As can be seen from the above embodiments, before establishing a connection between the client and the UKEY, the client sends a request to the UKEY to negotiate the line key, obtains the line negotiation certificate, and verifies its legitimacy. Then, the client encrypts the line key using the public key in the line negotiation certificate and sends the encryption key and the verification value to the UKEY for verification. Once the UKEY completes the verification, the data transmission between the client and the UKEY can be encrypted based on the negotiated line key. This allows the password and transmitted data to be encrypted when the client enters the password or transmits data, protecting the security of the password and related data during transmission and ensuring that the UKEY only receives instructions from legitimate clients.

[0042] In one embodiment of this application, before performing step 210, the method further includes: pre-setting a verification password and a pre-setting UKEY line negotiation certificate within the UKEY terminal. For example, if the PIN code for logging into the UKEY terminal is LD123456, then the pre-set verification password is LD123456.

[0043] In step 240, the encrypted data sent by the secure client is decrypted using the line key, including: Receives encrypted passwords and access requests sent by the secure client. The encrypted password is obtained by encrypting the password entered by the client using the line key; for example, the secure client sends an encrypted password of E (LD123456, SK1).

[0044] The encrypted password is decrypted using the line key to obtain the decrypted password; the decrypted password is then verified against the verification password. If they match, the access request is allowed. Specifically, the UKEY terminal decrypts the encrypted password E (LD123456, SK1) using the line key SK1 to obtain password LD123456, and compares it with the verification password LD123456. If they match, the client's access request is allowed.

[0045] As can be seen from the above embodiments, by pre-setting a verification password in the UKEY, the PIN code can be decrypted using the line key and compared with the PIN code stored in the UKEY to determine the validity of the input PIN code, thereby improving the security of accessing the UKEY.

[0046] Another embodiment of this application provides a key download method applied to a payment system. The payment system includes a secure client, a U-KEY terminal, a payment terminal, and a key server; the U-KEY terminal, payment terminal, and key server are all connected to the client. The payment terminal can be a POS machine, cash register, or other similar device. The key server has CA and RA functions and includes a key download server and a key database.

[0047] Please refer to Figure 3 as well as Figure 4The system interaction includes the following steps: Step 310: The secure client establishes a connection with the UKEY terminal. Specifically, the secure client establishes a connection with the UKEY terminal through steps 110-140 of the method for protecting the UKEY line security described above; or the UKEY terminal establishes a connection with the secure client through steps S210-240 of the method for protecting the UKEY line security described above. This corresponds to step 1.1 in the diagram.

[0048] Step 320: The payment terminal imports the certificate through the secure client and key server. This corresponds to step 2.1 in the diagram.

[0049] Step 330: The payment terminal sends a unique serial number (SN) and certificate to the key server through a secure client. This corresponds to step 3.1 in the diagram.

[0050] Step 340: The key server checks the unique serial number and certificate. If both are valid, it obtains the unique identification key corresponding to the unique serial number and generates verification data based on the unique identification key and certificate. This corresponds to steps 4.1-4.3 in the diagram. For example, after the key download server verifies the validity of the SN and certificate, and whether the SN is within the whitelist maintained in the background, it sends the SN to the key database to obtain the unique identification key. The key database then obtains the unique identification key and generates the verification data.

[0051] Step 350: The key server sends the verification data to the payment terminal through the client. This corresponds to steps 5.1-5.3 in the diagram, where the key download database sequentially sends the verification data to the POS terminal through the key download server and the PC client.

[0052] Step 360: The payment terminal decrypts the verification data to obtain the unique identification key and verifies the validity of the unique identification key. If the verification is successful, the unique identification key is saved. That is, proceed to step 6.1.

[0053] As described above, by first establishing a secure connection between the client and the UKEY, and then through the interaction between the client, the UKEY, and the key server, the certificate import and unique key download of the POS are completed, thereby improving the security of the POS obtaining the unique key.

[0054] Please refer to Figure 5 This application provides a specific embodiment, which details the interaction process between the secure client and the UKEY terminal. Before the interaction, the upper-level certificate of the UKEY line negotiation certificate needs to be pre-installed in the secure client; the UKEY line negotiation certificate and the UKEY line negotiation private key need to be pre-installed in the UKEY terminal. The interaction process includes the following steps: 1.1 The secure client sends a request to negotiate the line key to the UKEY terminal.

[0055] 2.1 The UKEY returns the CERT_UKEY line negotiation certificate to the secure client. When the secure client is the primary agent, steps 1.1-2.1 are equivalent to step 110 above. Similarly, when the UKEY is the primary agent, steps 1.1-2.1 are equivalent to step 210 above.

[0056] 3.1 Secure Client: 3.1.1 After verifying the validity of the line negotiation certificate CERT_UKEY, retrieve the public key Pub_ukey from the line negotiation certificate CERT_UKEY; that is, execute step 120 above. 3.1.2 Randomly generate a line key SK1, encrypt it with Pub_ukey, and generate an encryption key E(SK1, Pub_ukey); 3.1.3 Calculate the key verification value of SK1.

[0057] 3.2 Send the key verification value and encryption key E (SK1, Pub_ukey) to the UKEY terminal.

[0058] 4.1 UKEY End: 4.1.1 Decrypt the cached SK1 using the private key Pri_ukey in the UKEY line negotiation certificate CERT_UKEY to negotiate the line key SK1 between the UKEY end and the secure client. 4.1.2 Calculate the checksum of SK1 and compare it with the received checksum.

[0059] 4.2 The UKEY terminal returns the verification result to the security client. Steps 3.1.2-4.2 refer to steps 130 or 220-230 described above.

[0060] 5.1 The secure client encrypts the instructions and data for calculating the private key using the line key SK1 to generate encrypted data E(CMD+DATA, SK1), and then sends the encrypted data E(CMD+DATA, SK1) to the UKEY terminal.

[0061] 6.1. The UKEY terminal decrypts E(CMD+DATA, SK1) using the line key SK1 to obtain the private key calculation instruction CMD and the original data DATA. It then executes the private key calculation instruction CMD to obtain the private key Pri, calculates the original data DATA to obtain data E(DATA, Pri), and then encrypts the data (DATA, Pri) using the line key SK1 to obtain E(E(DATA, Pri), SK1), which is then sent to the secure client. Steps 5.1-6.1 are equivalent to executing steps 140 or 240 above.

[0062] Please refer to Figure 6Another embodiment of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor. The electronic device can be used as a secure client or a U-key terminal. When used as a secure client, the processor executes the computer program to implement steps 110-140 of the method for protecting the security of a U-key line as described above. When used as a U-key terminal, the processor executes the computer program to implement steps 210-240 of the method for protecting the security of a U-key line as described above. The corresponding technical effects have been disclosed in the above sections and will not be repeated here.

[0063] In summary, this invention provides a method for protecting UKEY line security, a key download method, and an electronic device. Before establishing a connection between the client and the UKEY, the client sends a line key negotiation request to the UKEY to obtain a line negotiation certificate and verify its legitimacy. Then, the line key is encrypted using the public key in the line negotiation certificate. The encrypted key and verification value are then sent to the UKEY for verification. Once the UKEY completes verification, data transmission between the client and the UKEY is encrypted based on the negotiated line key. This allows encryption of passwords and transmitted data when the client enters a password or transmits data, protecting the security of passwords and related data during transmission and ensuring that the UKEY only receives instructions from legitimate clients. Furthermore, by establishing a secure connection between the client and the UKEY beforehand, and then interacting with the client, UKEY, and key server to import the POS certificate and download the unique key, the security of obtaining the unique key for the POS is improved.

[0064] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for protecting the security of a U-key circuit, characterized in that, Applied to a secure client, the secure client being connected to a UKEY, the method includes: Send a line key negotiation request to the UKEY terminal and receive the line negotiation certificate returned by the UKEY terminal; After verifying the validity of the line negotiation certificate, the public key is retrieved from the line negotiation certificate; Generate a line key, calculate a first check value for the line key and encrypt the line key using the public key to obtain an encryption key, send the first check value and the encryption key to the UKEY terminal; instruct the UKEY terminal to decrypt the encryption key, and verify the decryption result based on the check value to obtain the line key; When sending encrypted data to the UKEY terminal, the encrypted data is encrypted using the line key.

2. The method for protecting the security of a UKEY line according to claim 1, characterized in that, Before sending the line key negotiation request to the UKEY terminal, the following steps are included: The security client has a pre-installed superior certificate. Retrieving the public key from the line negotiation certificate includes: The validity and completeness of the line negotiation certificate are verified by the superior certificate. If they are valid, the line negotiation certificate is legitimate, and the public key is retrieved from the line negotiation certificate.

3. The method for protecting the security of a UKEY line according to claim 1, characterized in that, The generated line key includes: A random number of bytes is randomly generated, and the random number is used as the line key.

4. The method for protecting the security of a UKEY line according to claim 1, characterized in that, The encryption of the ciphertext data using the line key includes: If the encrypted data is the input password, then the password is encrypted using the line key to obtain an encrypted password, and the encrypted password is sent to the UKEY terminal; Receive the response data from the UKEY terminal, and access the data in the UKEY terminal based on the response data.

5. The method for protecting the security of a UKEY line according to claim 1, characterized in that, The encryption of the ciphertext data using the line key includes: If the encrypted data is information data, the information data is encrypted using the line key to obtain encrypted data, and the encrypted data is sent to the UKEY terminal.

6. The method for protecting the security of a UKEY line according to claim 5, characterized in that, The step of encrypting the information data using the line key to obtain encrypted data and sending the encrypted data to the UKEY terminal includes: The encrypted data is obtained by encrypting the private key calculation instruction and the original data in the information data using the line key, and then sending the encrypted data to the UKEY terminal; after the UKEY terminal decrypts the encrypted data using the line key, it encrypts the original data based on the private key calculation instruction.

7. A method for protecting the security of a U-key circuit, characterized in that, Applied to a UKEY terminal, wherein the UKEY is connected to a secure client, the method includes: The system receives a line key negotiation request sent by the security client and returns a line negotiation certificate to the security client; it instructs the security client to generate a line key after verifying the validity of the line negotiation certificate, and obtains a first verification value and an encryption key based on the line key and the line negotiation certificate. Receive the first verification value and encryption key sent by the security client; The encryption key is decrypted using the private key of the line negotiation certificate to obtain the line key, and a second verification value of the line key is calculated; if the second verification value matches the first verification value, the line key is saved. The encrypted data sent by the secure client is decrypted using the line key.

8. A method for protecting the security of a UKEY line according to claim 7, characterized in that, The UKEY terminal has a pre-set verification password; The process of decrypting the encrypted data sent by the secure client using the line key includes: The system receives an encrypted password and access request sent by the secure client, wherein the encrypted password is obtained by the client encrypting the password entered using the line key; The encrypted password is decrypted using the line key to obtain the decrypted password; the decrypted password is then verified to be consistent with the verification password, and if so, the access request is allowed.

9. A key download method, characterized in that, The method is applied to a payment system, which includes a secure client, a U-key terminal, a payment terminal, and a key server; the U-key terminal, payment terminal, and key server are all connected to the client; the method includes: The security client establishes a connection with the UKEY terminal using a method for protecting the security of the UKEY line as described in any one of claims 1-6; or the UKEY terminal establishes a connection with the security client using a method for protecting the security of the UKEY line as described in any one of claims 7-8. The payment terminal imports the certificate through the security client and the key server; The payment terminal sends a unique serial number and certificate to the key server through the security client; The key server checks the unique serial number and the certificate. If both are valid, it obtains the unique identification key corresponding to the unique serial number and generates verification data based on the unique identification key and the certificate. The key server sends the verification data to the payment terminal through the client; The payment terminal decrypts the verification data to obtain the unique identification key and verifies the legality of the unique identification key. If the verification is successful, the unique identification key is saved.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, The electronic device can be used as a security client or a UKEY terminal; when used as the security client, the processor executes the computer program to implement each step of the method for protecting the security of a UKEY line as described in any one of claims 1-6; when used as the UKEY terminal, the processor executes the computer program to implement each step of the method for protecting the security of a UKEY line as described in any one of claims 7-8.