Methods for communication between POS systems and mobile terminals; methods and sets of encryption and POS systems.

TH125091BActive Publication Date: 2026-09-23INGENICO (FUJIAN) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TH1601006181
Authority / Receiving Office
TH · TH
Patent Type
Patents
Current Assignee / Owner
Priority Date
2015-01-09
Filing Date
2015-01-09
Publication Date
2026-09-23
Estimated Expiration
2035-01-08

AI Technical Summary

Technical Problem

There is a risk of information leakage in existing financial POS and mobile terminal wireless communications, and the use of DES encryption algorithm is inefficient, requires a lot of calculations, takes up a lot of software and hardware resources, and reduces the data transmission rate.

Method used

By generating a common temporary key K master, and using the Bluetooth address BD_ADDR of the mobile terminal to generate the encryption key K cipher, the XOR operation is used to encrypt and decrypt the plaintext data stream, simplifying key generation and encryption calculations, and reducing the need for software Hardware resource usage.

Benefits of technology

It achieves efficient data transmission rate and encryption security, ensuring the data transmission security of communication between financial POS and mobile terminals, while reducing resource occupation, and is suitable for limited software and hardware resource environments.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Disclosed is an encryption method for communication between a financial POS and a mobile terminal. The encryption method for communication comprises the steps: the financial POS and the mobile terminal generate a common temporary key Kmaster, the mobile terminal sends a Bluetooth address BD_ADDR to the financial POS, and the mobile terminal and the financial POS separately add the temporary key Kmaster and the Bluetooth address BD_ADDR of the mobile terminal into a key generation formula to generate an encryption key Kcipher; and the financial POS or the mobile terminal performs an exclusive OR operation on a plaintext data stream to be sent and the encryption key to generate an encrypted transmission ciphertext. The encryption method of the present invention enables data to be transmitted securely, provides a simple algorithm and occupies fewer software and hardware resources, thereby effectively ensuring a communication rate between the financial POS and the mobile terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field This invention relates to the field of encryption, and in particular to a communication method between a financial POS and a mobile terminal, a method and apparatus for encrypting communication, and a financial POS. Background Technology With the continuous development of online payments, communication between financial POS terminals and mobile devices to facilitate payments has become a trend. Financial POS terminals and mobile devices can communicate via wired or wireless methods. Wired methods include USB data cables and audio data cables; wireless methods include Wi-Fi, iBeacon Bluetooth, infrared, and acoustic communication. However, wired communication requires various data cables for connection, which is extremely inconvenient and therefore not widely accepted. On the other hand, wireless communication data is easily intercepted during transmission, compromising data confidentiality and security. Therefore, encrypting wirelessly transmitted data is imperative. Among existing communication encryption algorithms, DES encryption is a mature and widely used in many communication technologies. However, it lacks technical openness and flexibility in use, making it difficult to apply in the financial payment field. Furthermore, the DES encryption algorithm is complex and computationally intensive, requiring a significant amount of software and hardware resources. However, the software and hardware resources of financial POS terminals and mobile terminals are relatively limited. Therefore, if the DES encryption algorithm is used to encrypt the transmitted data, the transmission rate between financial POS terminals and mobile terminals will be greatly reduced. In the mobile payment field, convenience, speed, and security are paramount. Therefore, encryption must not only be secure and reliable, but also consider the ease of implementation on mobile hardware and software, and whether it will reduce data transmission rates. Consequently, existing technologies suffer from the following problems: The existing financial POS and mobile terminal wireless communication uses plaintext to send information, which poses a risk of information leakage; Using the DES encryption algorithm to encrypt data streams transmitted by financial POS terminals and mobile terminals is too inefficient, has a short password lifespan, low processing speed, is inflexible in use, and is limited in mobile terminal scenarios. Summary of the Invention To address the aforementioned technical problems, this invention provides an encryption method for communication between a financial POS terminal and a mobile terminal. This encryption method consumes fewer hardware and software resources and has a high communication transmission rate. An encryption method for communication between a financial POS terminal and a mobile terminal includes the following steps: The financial POS and mobile terminal generate a common temporary key K master; The mobile terminal sends the Bluetooth address BD_ADDR to the financial POS. The mobile terminal and the financial POS respectively use the temporary key K master and the mobile terminal's Bluetooth address BD_ADDR to generate the encryption key K cipher in the key generation formula. Financial POS or mobile terminals perform an XOR operation between the plaintext data stream to be sent and the encryption key to generate encrypted ciphertext for transmission. This invention also provides a communication method between a financial POS terminal and a mobile terminal, wherein the data transmitted in this communication is encrypted using the above-mentioned encryption method, and the encrypted data further includes the following steps: Financial POS or mobile terminals perform an XOR operation between the plaintext data stream to be transmitted and the binary encryption key K cipher bit stream to obtain the encrypted transmission ciphertext, and then send the encrypted transmission ciphertext. The mobile terminal or financial POS performs an XOR operation on the received transmitted ciphertext and the binary encryption key K cipher bit stream to generate a plaintext data stream. The present invention also provides an encryption device for communication between a financial POS and a mobile terminal. The device includes a mobile terminal and a financial POS. The financial POS includes a first temporary key K master generation module, a first encryption key K cipher generation module, and a first encryption module. The mobile terminal includes a second temporary key K master generation module, a second encryption key K cipher generation module, and a second encryption module. The first temporary key K master generation module and the second temporary key K master generation module are used for the financial POS and the mobile terminal to generate a common temporary key K master, respectively; The second encryption key K cipher generation module is used to send the Bluetooth address BD_ADDR to the financial POS, and to generate the encryption key K cipher by inputting the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula. The first encryption key K cipher generation module inputs the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula to generate the encryption key K cipher; The first encryption module and the second encryption module are respectively used by the financial POS and the mobile terminal to perform an XOR operation on the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext. The present invention also provides a financial POS, which includes a temporary key K master generation module, an encryption key K cipher generation module, and an encryption module; The temporary key K master generation module is used to generate the temporary key K master; The encryption key K cipher generation module is used to receive the Bluetooth address BD_ADDR sent by the mobile terminal, and to input the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula to generate the encryption key K cipher; The encryption module is used to perform an XOR operation between the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext. The beneficial effects of this invention are as follows: the encryption method for communication between the financial POS and the mobile terminal has short temporary key and encryption key lengths, low computational load for key generation and data encryption, and low hardware and software resource consumption, effectively ensuring the data transmission rate between the financial POS and the mobile terminal. Moreover, the encryption key corresponds to the Bluetooth address of the mobile terminal, ensuring high uniqueness of the encryption key. Attached Figure Description Figure 1 is a flowchart of an encryption method for communication between a financial POS and a mobile terminal according to an embodiment of the present invention; Figure 2 is a flowchart of a communication method between a financial POS and a mobile terminal according to an embodiment of the present invention; Figure 3 is a functional block diagram of an encryption device for communication between a financial POS and a mobile terminal according to an embodiment of the present invention. Figure 4 is a functional block diagram of a financial POS according to an embodiment of the present invention; Figure 5 is a schematic diagram of the encryption method for communication between a financial POS and a mobile terminal in an example of the present invention; Figure 6 is a schematic diagram of the encryption method for communication between a financial POS and a mobile terminal in an example of the present invention; Figure 7 is a schematic diagram of the key generation formula E0 generating the key in one embodiment of the present invention; Explanation of main labels: 1. First temporary key K master generation module; 20. First encryption key K cipher generation module; 30. First encryption module; 40. Second temporary key K master generation module; 50. Second encryption key K cipher generation module; 60. Second encryption module; 100. Temporary key K master generation module; 200. Encryption key K cipher generation module; 300. Encryption module. Detailed Implementation This invention enables financial POS terminals and mobile terminals to generate encryption keys using temporary keys. During the key generation process, only a portion of the data is transmitted, ensuring secure encryption. Furthermore, the encryption method of this invention features a simple algorithm, short key length, and minimal hardware and software resource consumption. To illustrate the technical content, structural features, objectives, and effects of the present invention in detail, the following description is provided in conjunction with the embodiments and accompanying drawings. Example 1 Please refer to Figure 1. This embodiment describes an encryption method for communication between a financial POS terminal and a mobile terminal, including the following steps: The financial POS and mobile terminal generate a common temporary key K master. The mobile terminal sends the Bluetooth address BD_ADDR to the financial POS. The mobile terminal and the financial POS respectively input the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula to generate the encryption key K cipher. Financial POS or mobile terminals perform an XOR operation between the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext. In this embodiment, the temporary key K_master and the encryption key K_cipher are both 128 bits long, which greatly reduces the computational load for key generation and data encryption. Therefore, it requires fewer hardware and software resources, which is beneficial for the communication transmission rate between financial POS terminals and mobile terminals (where hardware and software resources are limited and complex encryption algorithms would severely impact communication transmission rates). In this embodiment, the mobile terminal is a smartphone; in other embodiments, the mobile terminal may be a PDA, tablet computer, or other similar device. In this embodiment, the financial POS and the mobile terminal generate an encryption key using the mobile terminal's Bluetooth address BD_ADDR (each mobile terminal's Bluetooth address BD_ADDR is unique) and a shared temporary key Kmaster. This ensures that the encryption key Kcipher used for communication between the financial POS and each mobile terminal is different, and only the financial POS and the mobile terminal conducting this communication can possess the same encryption key Kcipher, thus effectively guaranteeing the security of encrypted data transmission during communication. In this embodiment, the mobile terminal's Bluetooth address BD_ADDR can be the mobile terminal's Bluetooth address BD_ADDR or another Bluetooth address BD_ADDR for the mobile terminal. In this embodiment, to improve the security of the generated common temporary key K master and prevent it from being intercepted, the step "the financial POS and the mobile terminal generate a common temporary key K master" specifically includes the following steps: The financial POS terminal and the mobile terminal verify a key value K1. The key value K1 can be sent from the financial POS terminal to the mobile terminal, or vice versa, with the holders of both the mobile terminal and the financial POS terminal verifying it in person. In other implementations, K1 can be verified using other methods, such as via SMS. The financial POS generates a first random number RAND1 and a second random number RAND2. These two random numbers are then used in a key generation formula to generate a temporary key Kmaster. The key generation formula is Kmaster = E1(RAND1, RAND2, 16), where E1 is {0,1} × {0,1} × {1,2 …… 16} → {0,1} 128 → A't(X,Y); The financial POS generates a third random number RAND and sends RAND to the mobile terminal. The financial POS and mobile terminal respectively input the third random number RAND and K1 into the key generation formula to generate the OVL value, wherein the key generation formula is OVL= E1(K1, RAND,16), and E1 is the same as above; The financial POS XORs the OVL value and K master to generate a temporary value C, and sends the temporary value C to the mobile terminal; The mobile terminal XORs the received temporary value C with the OVL value to generate a temporary key K master. In this embodiment, the temporary key K master that the financial POS and the mobile terminal generate together is calculated by transmitting the temporary C value and verifying K1. During the key generation process, only part of the key generation data is transmitted. Therefore, even if this data is intercepted, the temporary key K master will not be leaked, thus improving the security of the temporary key K master. In this embodiment, the step of "the mobile terminal sending the Bluetooth address BD_ADDR to the financial POS, and the mobile terminal and the financial POS respectively using the temporary key K master and the mobile terminal's Bluetooth address BD_ADDR into the key generation formula to generate the encryption key K cipher" specifically includes the following steps: The mobile terminal sends the device's Bluetooth address BD_ADDR to the financial POS to initiate a handshake. At the same time as sending the Bluetooth address BD_ADDR, the mobile terminal generates an acknowledgment word K2 and sends the acknowledgment word K2 to the financial POS. The holders of the mobile terminal and the financial POS verify whether the acknowledgment word K2 is consistent. If they are consistent, the handshake is successful. If the handshake is successful, the financial POS saves the received Bluetooth address BD_ADDR of the mobile terminal and generates a fourth random number EN_RAND A to send to the mobile terminal; otherwise, the mobile terminal repeatedly sends the handshake signal. The mobile terminal and the financial POS respectively input the mobile terminal Bluetooth address BD_ADDR, OVL value, temporary key K master, and fourth random number EN_RAND A into the key generation formula E0 to generate the encryption key K cipher, and save the encryption key K cipher.

[0066] Wherein, the key generation formula E0 is: {0,1}128 × {0,1}128 × {0,1}96 × {0,1}48 → {0,1}128 masterA → HASH(K master, EN_RAND A, OVL, BD_ADDR,12). Similar to generating the temporary key K master, the generation of the encryption key K cipher also involves the transmission of some data between the financial POS and the mobile terminal, making the encryption key K cipher difficult to intercept. At the same time, each mobile terminal has a different Bluetooth address BD_ADDR, ensuring that each generated encryption key K cipher is unique and only possessed by the financial POS and the mobile terminal that have successfully completed the handshake, thereby further guaranteeing the security of the encryption key K cipher. In this embodiment, the step of "the financial POS or mobile terminal performing an XOR operation between the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext" specifically includes the following steps: Financial POS or mobile terminals will divide the plaintext data stream to be sent into segments according to a preset length. For some plaintext data to be sent with a length less than or equal to the preset length, no segmentation is required. The segmented plaintext data streams to be sent are filled into data payloads of different data structures respectively. The order of each part of the plaintext data stream to be sent in the plaintext data stream to be sent is filled into the first byte of the data payload. The data structure also includes data length and data type. The plaintext data stream to be sent in the data payload of each data structure is XORed with the encryption key to generate the encrypted transmission ciphertext. In this embodiment, the financial POS and the mobile terminal communicate via iBeacon. In other embodiments, the financial POS and the mobile terminal may communicate via acoustic wave communication, Bluetooth communication, or other wireless communication methods. The communication technology is a new communication method proposed by Apple Inc., which uses Bluetooth Low Energy (BLE) technology to send and receive information through broadcasting and scanning. Because the broadcasting and scanning process is very fast, the iBeacon communication method is very convenient and efficient. It is mainly used in scenarios that do not involve sensitive information, such as advertising push in shopping malls and indoor coordinate positioning and navigation. This means that messages can be transmitted in plaintext without encryption in such broadcast information transmission. In this embodiment, iBeacon technology is applied to communication between the mobile terminal and the financial POS, and the data to be transmitted is encrypted using the above-mentioned encryption method. Therefore, the convenience of iBeacon communication is fully utilized, while also satisfying the security requirements of communication. Example 2 Please refer to Figure 2. This invention also provides a communication method between a financial POS terminal and a mobile terminal. The data transmitted in this communication is encrypted using the encryption method described above, and the encrypted data further includes the following steps: Financial POS or mobile terminals perform an XOR operation between the plaintext data stream to be transmitted and the binary encryption key K cipher bit stream to obtain the encrypted transmission ciphertext, and then send the encrypted transmission ciphertext. Mobile terminals or financial POS systems XOR the received transmitted ciphertext with the binary encryption key K cipher bitstream to generate a plaintext data stream. The encryption key length of the data encryption method for communication between financial POS and mobile terminals in this embodiment is short, the algorithm is simple, and it consumes few hardware and software resources. Therefore, it is particularly suitable for applications such as financial POS and mobile terminals with limited hardware and software resources and small data transmission. This communication method can ensure the security of data transmission without affecting the transmission rate between financial POS and mobile terminals. Example 3 Referring to Figure 3, the present invention also provides an encryption device for communication between a financial POS and a mobile terminal. The encryption device includes a mobile terminal and a financial POS. The financial POS includes a first temporary key K master generation module 10, a first encryption key K cipher generation module 20, and a first encryption module 30. The mobile terminal includes a second temporary key K masterr generation module 40, a second encryption key K cipher generation module 50, and a second encryption module 60. The first temporary key K master generation module 10 and the second temporary key K master generation module 40 are respectively used for the financial POS and the mobile terminal to generate a common temporary key K master; The second encryption key K cipher generation module 50 is used to send the Bluetooth address BD_ADDR to the financial POS, and to generate the encryption key K cipher by inputting the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula; The first encryption key K cipher generation module 20 inputs the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula to generate the encryption key K cipher; The first encryption module 30 and the second encryption module 60 are respectively used by the financial POS and the mobile terminal to perform an XOR operation on the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext. Example 4 Please refer to Figure 4. The present invention also provides a financial POS, which includes a temporary key K master generation module 100, an encryption key K cipher generation module 200, and an encryption module 300. The temporary key K master generation module 100 is used to generate the temporary key K master; The encryption key K cipher generation module 200 is used to receive the Bluetooth address BD_ADDR sent by the mobile terminal, and input the temporary key K master and the Bluetooth address BD_ADDR of the mobile terminal into the key generation formula to generate the encryption key K cipher; The encryption module 300 is used to perform an XOR operation between the plaintext data stream to be sent and the encryption key to generate encrypted transmission ciphertext.

[0095] In this embodiment, in order to improve the security of the temporary key K master generated by the financial POS, the temporary key K master generation module 100 includes a first unit, a second unit, a third unit, a fourth unit and a fifth unit; The first unit is used to verify a KEY value K1 with the mobile terminal; The second unit is used to generate a first random number RAND1 and a second random number RAND2, and to input the first random number RAND1 and the second random number RAND2 into the key generation formula to generate a temporary key K master; The third unit is used to generate a third random number RAND and send RAND to the mobile terminal; The fourth unit is used to generate an OVL value based on the third random number RAND and the KEY value K1; The fifth unit is used to XOR the OVL value and K master to generate a temporary value C, and then send the temporary value C to the mobile terminal. In this embodiment, to improve the security of the generated encryption key K cipher, the encryption key K cipher generation module 200 includes a sixth unit, a seventh unit, an eighth unit, and a ninth unit; The sixth unit is used to receive the device's Bluetooth address BD_ADDR and handshake signal sent by the mobile terminal; The seventh unit is used to save the received Bluetooth address BD_ADDR of the mobile terminal when the handshake with the mobile terminal is successful, and to generate a fourth random number EN_RAND A and send it to the mobile terminal. The eighth unit is used to input the mobile terminal Bluetooth address BD_ADDR, OVL value, temporary key K master, and fourth random number EN_RAND A into the key generation formula to generate encryption key K cipher, and save encryption key K cipher. In summary, the encryption method for communication between the financial POS and the mobile terminal in this invention features short temporary keys and encryption keys, low computational load for key generation and data encryption, and minimal hardware and software resource consumption. This effectively ensures the data transmission rate between the financial POS and the mobile terminal. Furthermore, the encryption key corresponds to the Bluetooth address of the mobile terminal, ensuring high uniqueness. Moreover, during the generation of the temporary key and encryption key, only a portion of the key generation data is transmitted, thus enhancing the security of the temporary key and encryption key. Example The present invention will be illustrated below through a specific example of a financial POS and mobile terminal communication encryption method. In this implementation, the financial POS and the mobile terminal transmit and receive data via iBeacon technology. To achieve bidirectional communication between the financial POS and the mobile terminal, the mobile terminal and the POS terminal respectively encapsulate a broadcast interface for filling in broadcast information and a scanning interface for obtaining broadcast information. Both the mobile terminal and the POS terminal enable data broadcasting threads and data scanning threads, allowing the financial POS and the mobile terminal to broadcast data by inserting the data to be sent into the UUID information broadcast by iBeacon, and to perform broadcast scanning by filtering the UUID information and obtaining the transmitted data from the UUID information. As shown in Figures 5 to 7, the main process of this example is as follows: Step 1) Set the financial POS as the broadcast end of iBeacon and the mobile terminal as the scanning end of iBeacon. The financial POS and the mobile terminal verify a common key value (K1). This key value can be verified face-to-face by the financial POS and the mobile terminal that needs to receive the information. Step 2) The broadcast end (financial POS) uses two 128-bit random numbers, RAND1 and RAND2, to calculate the K master; Step 3) The broadcast end (financial POS) transmits the third random number RAND to the receiving end (mobile terminal). Step 4) The broadcast end (financial POS) calculates the OVL from the RAND and the current key value; Step 5) The receiving end (mobile terminal) calculates the OVL from the RAND and the current key value; Step 6) The broadcast end (financial POS) XORs OVL and K master to generate C; Step 7) The broadcast end transmits (financial POS) C to the receiving end (mobile terminal); Step 8) The receiving end (mobile terminal) XORs OVL and C to generate K master (this ensures that only the end that needs to receive information has the same K master as the broadcast end). Step 9) Configure the financial POS as the iBeacon scanning terminal and the mobile terminal as the iBeacon broadcast terminal. The receiving terminal sends a confirmation number K2 and its own Bluetooth address to the broadcast terminal to perform a handshake to confirm the legitimacy of the receiving device. It waits for the broadcast terminal to confirm whether the number K2 matches (this can be verified by physically checking K2). If the broadcast terminal confirms correctly, encryption is required to continue, and the receiving terminal's Bluetooth address is saved for later use; if the broadcast terminal confirms incorrectly, the process terminates. Step 10) After a successful handshake, the broadcast end sends EN_RANDA to the receiving end;

[00121] Step 11) The broadcast end uses encryption rule E0, where the receiving device's Bluetooth address (BD_ADDR), OVL value, encryption key K master, and a random number EN_RANDA are taken as input, and then the encryption key K cipher is output. Where E0 is: {0,1} 128 × {0,1} 128 × {0,1} 96 × {0,1} 48 → {0,1} 128 masterA → HASH(K master, EN_RAND A, OVL, BD_ADDR,12); Step 12) The receiving end also uses encryption rule E0, where the receiving device's Bluetooth address (BD_ADDR), OVL value, encryption key K master, and a random number EN_RANDA are taken as input, and the encryption key K cipher is output. In this way, the encryption keys of the broadcast end and the receiving end are consistent; Step 13) The broadcast end performs an XOR operation on the plaintext data stream and the binary key stream K cipher to generate an encrypted data stream; Step 14) The broadcast end sends an encrypted data stream to the receiving end; Step 15) The receiving end receives the encrypted data stream, performs an XOR operation on the encrypted data stream and the binary key stream K cipher, and generates a plaintext data stream. The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

------22 / 05 / 2561------(OCR) Page 1 of 4 Claims 1. The encryption method for communication between a POS (Point of Sale) system and a mobile terminal consists of the following steps: The POS system and the mobile terminal generate a temporary Kmaster key; the mobile terminal sends its Bluetooth address BDADDR to the POS system and the mobile terminal; and the POS system separately adds the temporary Kmaster key and the mobile terminal's Bluetooth address BDADDR into the key generation formula to create a Kcipher encryption key; the POS system or the mobile terminal performs an exclusive OR operation on the plain text data stream to be transmitted and the encryption key to generate the encrypted transmission message; the step in which 'POS system and mobile terminal generate temporary Kmaster key' includes only the following sub-steps: The POS system and mobile terminal verify the KEYK value;The POS (Point of Sale) system generates a first random number, RAND1, and a second random number, RAND2, and adds them to the key generation formula to create a temporary Kmaster key. The POS then generates a third random number, RAND, and sends it to the mobile terminal. The POS and mobile terminal, respectively, add the third random number, RAND, and K to the key generation formula to create an OVL value. The POS then performs an exclusive OR operation on the OVL and K values ​​to generate a temporary C value and sends this temporary C value to the mobile terminal. The mobile terminal then performs an exclusive OR operation on the received temporary C value and the OVL value to create a temporary Kmaster key.The process, in which the mobile terminal sends its Bluetooth address BDADDR to the POS (Point of Sale) system, and the POS system separately adds the temporary key Kmastcr and the Bluetooth address page 2 of the mobile terminal's 4-digit BDADDR number into the key generation formula to create a Kcipher encryption key, consists specifically of the following sub-steps: The mobile terminal sends its Bluetooth address BDADDR to the POS system for connection; if the connection is successful, the POS system records the received Bluetooth address BDADDR from the mobile terminal and generates and sends a random four-digit ENRANDA number to the mobile terminal; if not, the mobile terminal repeats the connection transmission;The mobile terminal and the financial POS, respectively, add the mobile terminal's Bluetooth address BDADDR, the OVL value, the temporary key Kmastcr, and the fourth random number ENRANDA to the key generation formula to generate the Kcipher encryption key and record the Kcipher encryption key.

2. The encryption method for communication between the financial POS and the mobile terminal under claim1, which is characterized by a procedure in which the 'financial POS or mobile terminal performs an exclusive OR operation on the plain text data stream to be transmitted and the encryption key to generate the encrypted transmission message', consists specifically of the following sub-steps: The financial POS or mobile terminal splits the plain text data stream to be transmitted to a predetermined length;The segmented portions of the plain text data stream to be transmitted are appended to a data payload with different data structures, and the sequence of segmented portions of the plain text data stream to be transmitted is appended to the first byte of the data payload, where the data structure also includes the data length and data type; an exclusive OR operation is performed on the plain text data stream to be transmitted in the data payload with the data structure and encryption key to generate the encrypted transmission message.

3. The encryption method for communication between a financial POS and a mobile terminal according to claim 1, which is characterized by the length of the Kmaster temporary key and the Kcipher encryption key being 128 bits, page 3 of 4, page 4. The financial POS, which is characterized by the inclusion of a Kmaster temporary key generation module, a Kcipher encryption key generation module, and an encryption module; the Kmaster temporary key generation module is used to generate the Kmaster temporary key;The Kcipher key generation module is used to receive the Bluetooth address BDADDR sent by the mobile device and adds the temporary Kmaster key and the mobile device's Bluetooth address BDADDR to the key generation formula to generate the Kcipher key; the encryption module is used to perform the exclusive OR operation on the plain text data stream to be transmitted and the encryption key to generate the encrypted transmission message. The Kmaster temporary key generation module consists of units one, two, three, four, and five; unit one is used to verify the KEYK1 value with the mobile device; unit two is used to generate the first random number RAND1 and the second random number RAND2 and adds them to the key generation formula to generate the temporary Kmaster key; unit three is used to generate the third random number RAND and send that RAND to the mobile device; unit four is used to generate the OVL value based on the third random number RAND and the KEYK value.The fifth unit will be used to perform an exclusive OR operation on the OVL and Kmaster values ​​to generate a temporary C value and send this temporary C value to the mobile terminal; the Kcipher key generation module will consist of the sixth, seventh, eighth, and ninth units; the sixth unit will be used to receive the device's Bluetooth address BDADDR and the mobile terminal's connection signal; the seventh unit will be used to record the received Bluetooth address BDADDR of the mobile terminal and generate and send a random fourth ENRANDA number to the mobile terminal when the connection to the mobile terminal is successfully established; on page 4 of the four-page unit eight, it will be used to add the mobile terminal's Bluetooth address BDADDR, the OVL value, the temporary Kmaster key, and the random fourth ENRANDA number into the key generation formula to generate the Kcipher key and save the Kcipher key.------------ 1. The cryptographic method for communication between a POS (Point of Sale) system and a mobile terminal consists of the following steps: The POS system and the mobile terminal jointly generate a temporary Kmaster key;The mobile terminal sends the Bluetooth address BD_ADDR to the POS (Point of Sale) device and the mobile terminal. The POS device then separately adds the temporary key Kmaster and the mobile terminal's Bluetooth address BD_ADDR to the key generation formula to generate the cryptographic key Kcipber. The POS device or mobile terminal performs an XOR operation on the plaintext data stream to be sent and the cryptographic key to create the encrypted message for transmission.

2. The cryptographic method for communication between the POS device and the mobile terminal according to claim 1, which is characterized by the process of 'POS device and mobile terminal jointly generating temporary key Kmaster', specifically consists of the following sub-steps: The POS device and mobile terminal verify the value of KEYK1; the POS device generates a first random number RANDI and a second random number RAND2 and adds these two numbers to the key generation formula to generate the temporary key Kmaster;The POS (Point of Sale) financial system generates a third random RAND number and sends the RAND to the mobile terminal; the POS and mobile terminal respectively add the third random RAND number and K1 to the key generation formula to create the OVL value; the POS and financial system perform an XOR operation on the OVL value and Kmaster to generate a temporary value C and send this temporary value C to the mobile terminal;The mobile terminal performs an XOR operation on the received temporary value C and the OVL value to generate a temporary Kmaster key.

3. The cryptographic method for communication between the financial POS and the mobile terminal, as per claim 2, is characterized by a procedure in which the mobile terminal sends the Bluetooth address BD_ADDR to the financial POS, and the mobile terminal and the financial POS separately add the temporary Kmaster key and the mobile terminal's Bluetooth address BD_ADDR to the key generation formula to create the Kmaster cryptographic key. Specifically, it consists of the following sub-steps: The mobile terminal sends its Bluetooth address BD_ADDR to the financial POS for connection; if the connection is successful, the financial POS records the received Bluetooth address BD_ADDR from the mobile terminal and generates and sends a random number EN_RANDA to the mobile terminal; if not, the mobile terminal resends the connection signal;The mobile terminal and the financial POS, respectively, add the mobile terminal's Bluetooth address (BD_ADDR), the OVL value, the temporary key code (Kmaster), and a fourth random number (EN_RANDA) to the key generation formula to generate the Kmaster cryptographic key and record the Kmaster cryptographic key.

4. The cryptographic method for communication between the financial POS and the mobile terminal according to claim 1, which is characterized by a procedure in which the 'financial POS or mobile terminal performs an XOR operation on the plaintext data stream to be sent and the cryptographic key to generate the encrypted message for transmission,' specifically consists of the following sub-steps: The financial POS or mobile terminal splits the plaintext data stream to be sent to a predetermined length;The segmented portion of the plain text data stream to be sent sequentially is appended to the actual data in a different data structure, and the sequence of segmented portions of the plain text data stream to be sent is appended to the first byte of the actual data in the data structure, where the data structure also includes the data length and data type;The XOR operation is performed on the plain text data stream to be transmitted, incorporating the actual data structure and cryptographic key to create the encrypted message for transmission.

5. The cryptographic method for communication between a POS (Point of Sale) financial system and a mobile terminal, as per claim 1, is characterized by the length of the temporary key (Kmaster) and the cryptographic key (Kcipher) being 128 bits.

6. The method for communication between a POS (Point of Sale) financial system and a mobile terminal is characterized by the data transmitted being encrypted using one of the cryptographic methods specified in claims 1 through 5, and after encryption, the method consists of the following steps: The POS (Point of Sale) financial system or mobile terminal performs the XOR operation on the plain text data stream to be transmitted and the binary cryptographic key (Kcipher) stream to receive the encrypted message for transmission and send the encrypted message for transmission;The mobile terminal or POS (Point of Sale) performs XOR operations on the received encrypted message and the key stream using binary Kcipher encryption to create a plain text data stream.

7. The encryption method for communication between the POS and the mobile terminal consists of the mobile terminal and the POS, and is characterized by the POS consisting of a first Kmaster temporary key generator module, a first Kcipher temporary key generator module, and a first encryption module, while the mobile terminal consists of a second Kmaster temporary key generator module, a second Kcipher temporary key generator module, and a second encryption module; where the first Kmaster temporary key generator module and the second Kmaster temporary key generator module are respectively used by the POS and the mobile terminal to generate a joint Kmaster temporary key;The second Kcipher key generation module will be used to add the Bluetooth address BD_ADDR to the financial POS and inject the temporary key Kmaster and the mobile terminal's Bluetooth address BD_ADDR into the key generation formula to create the Kcipher key; the first Kcipher key generation module will be used to add the temporary key Kmaster and the mobile terminal's Bluetooth address BD_ADDR into the key generation formula to create the Kcipher key; the first and second encryption modules, respectively, will then be used by the financial POS and mobile terminal to perform XOR operations on the plaintext data stream to be sent and the encryption key to create the encrypted message for transmission.

8. The financial POS, which is characterized by the inclusion of the temporary key generation Kmaster module, the Kcipher key generation module, and the encryption module; where the temporary key generation Kmaster module is used to generate the temporary key Kmaster;The Kcipher key generation module is used to receive the Bluetooth address BD_ADDR sent by the mobile device and add the temporary key Kmaster and the mobile device's Bluetooth address BD_ADDR to the key generation formula to generate the Kcipher key; the cryptography module is used to perform the XOR operation on the plain text data stream to be transmitted and the cryptography key to create the encrypted message for transmission.

9. Financial POS according to claim 8, which has the specific characteristics of the Kmaster temporary key generation module, consists of units one, two, three, four, and five; where unit one is used to verify the KEYK1 value with the mobile device; unit two is used to generate the first random number RAND1 and the second random number RAND2 and add them to the key generation formula to generate the temporary key Kmaster; unit three is used to generate the third random number RAND and send the RAND to the mobile device;The fourth unit will be used to generate the OVL value based on the third random RAND number and the KEYK1 value; the fifth unit will be used to perform the XOR operation on the OVL and Kmaster values ​​to generate the temporary C value and send the temporary C value to the mobile terminal.

10. The financial POS system under claim 9, which is characterized by a Kcipher encryption key generation module, will consist of the sixth, seventh, eighth, and ninth units; where the sixth unit will be used to receive the Bluetooth address of the device BD_ADDR and the connection signal of the mobile terminal; the seventh unit will be used to record the received Bluetooth address BD_ADDR of the mobile terminal and generate and send the fourth random EN_RANDA number to the mobile terminal when the connection to the mobile terminal is successful; the eighth unit will be used to add the Bluetooth address BD_ADDR of the mobile terminal, the OVL value, the temporary Kmaster key, and the fourth random EN_RANDA number into the key generation formula to generate the Kcipher encryption key and save the Kcipher encryption key;