Security detection method and apparatus for resource swap terminal, security base, and medium

By measuring the weight change of the POS machine using a secure base and combining it with a security chip and processor for rapid security testing, the complexity of physical protection methods for POS machines is solved, production difficulty and cost are reduced, and market competitiveness is improved.

WO2026011947A1PCT designated stage Publication Date: 2026-01-15PAX COMP TECH SHENZHEN
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/094853
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-12
Filing Date
2025-05-14
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

The diversity and complexity of existing POS machine physical protection methods increase production difficulty and cost, and make it difficult to meet the needs of different customers and complex attack scenarios.

Method used

By measuring the weight change of the resource-swapping terminal using a secure base, and using the weight difference and standard weight value to determine whether a physical attack has occurred, and combining the secure chip and processor for encrypted communication and detection, rapid security detection is achieved.

Benefits of technology

It reduces the difficulty and cost of POS machine production, expands the production scope, improves market competitiveness, and avoids the limitations of complex physical protection methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025094853_15012026_PF_FP_ABST
    Figure CN2025094853_15012026_PF_FP_ABST
Patent Text Reader

Abstract

The present application is applicable to the technical field of POS machines, and provides a security detection method and apparatus for a resource swap terminal, a security base, and a medium. The method is applied to the security base. The method comprises: acquiring a first weight measurement value of a resource swap terminal measured by a security base when the resource swap terminal is located on the security base; on the basis of an identifier of the resource swap terminal, acquiring a standard weight value corresponding to the resource swap terminal; and on the basis of a weight difference between the first weight measurement value and the standard weight value corresponding to the resource swap terminal and a physical attack weight range, determining whether the resource swap terminal is physically attacked. Security detection of the resource swap terminal can be quickly realized by detecting changes in the weight of the resource swap terminal via the security base that is independent of the resource swap terminal, thereby innovating a security protection means for resource swap terminals, conserving the resources of the resource swap terminals, and overcoming the limitations of current physical protection means.
Need to check novelty before this filing date? Find Prior Art

Description

Security testing methods, security base, devices and media for resource swapping terminals

[0001] This application claims priority to Chinese Patent No. 202410939384.7, filed on July 12, 2024, entitled "Security Detection Method, Security Base, Device and Medium for Resource Exchange Terminal", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application belongs to the field of POS machine technology, and in particular relates to a security detection method, security base, device and medium for resource exchange terminals. Background Technology

[0003] To protect POS machine data security from physical attacks, manufacturers often employ various physical protection measures during production, such as wiring overlays, tamper-proof switches, and security screws. However, the diversity and complexity of these physical protection methods necessitate the design and production of POS machines with different specifications and configurations to meet diverse customer needs and address various complex attack scenarios. This undoubtedly increases the difficulty and cost of POS machine production. Therefore, to overcome the limitations of current physical protection methods for POS machines, an innovative protection approach is urgently needed. Summary of the Invention

[0004] This application provides a security detection method, security base, device, and medium for resource-swapping terminals, offering an innovative security protection method for POS machines and overcoming the limitations of current physical protection methods used in POS machines.

[0005] In a first aspect, embodiments of this application provide a security detection method for a resource-swapping terminal, applied to a security base, the method comprising:

[0006] Acquire the first weight measurement value of the resource exchange terminal measured by the security base when the resource exchange terminal is located on the security base;

[0007] Obtain the standard weight value corresponding to the resource exchange terminal based on the terminal's identifier;

[0008] Based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource swapping terminal, as well as the weight range of the physical attack, it is determined whether the resource swapping terminal has been physically attacked.

[0009] In some embodiments, determining whether a resource-swapping terminal has been physically attacked based on the weight difference between a first weight measurement and a standard weight value corresponding to the resource-swapping terminal, and the weight range of a physical attack, includes:

[0010] If the weight difference is determined to be within the range of physical attack weight, then the resource swapping terminal is determined to have been physically attacked.

[0011] If the weight difference is determined to be outside the range of physical attack weight, then the resource swapping terminal is determined not to have been physically attacked.

[0012] In some embodiments, determining whether a resource-swapping terminal has been physically attacked based on the weight difference between a first weight measurement and a standard weight value corresponding to the resource-swapping terminal, and the weight range of a physical attack, includes:

[0013] If the weight difference is determined to be greater than or equal to the minimum weight value in the physical attack weight range, a verification request message is sent to the resource exchange terminal. The verification request message is used to trigger the resource exchange terminal to prompt a weight detection and verification of the security base.

[0014] After the weight detection verification is successful, the safety base uses its own weight detection device to remeasure the second weight measurement value of the resource exchange terminal.

[0015] If the weight difference between the second weight measurement and the standard weight value is determined to be greater than or equal to the minimum weight value in the physical attack weight range, then the resource swapping terminal is determined to be under physical attack.

[0016] In some embodiments, the method further includes:

[0017] If it is determined that the resource exchange terminal has been physically attacked, at least one of the following is encrypted and sent to the resource exchange terminal: weight difference, alarm information, and verification request information.

[0018] In some embodiments, the method further includes:

[0019] Check whether the resource exchange terminal is located on the security base;

[0020] If the resource exchange terminal is located on the security base, verify the legitimacy of the resource exchange terminal's identity based on its identifier.

[0021] If the identity of the resource-exchanging terminal is determined to be legitimate, a secure communication connection is established with the resource-exchanging terminal.

[0022] The detection prompt message is sent to the resource exchange terminal via a secure communication connection. The detection prompt message is used to trigger the resource exchange terminal to prompt that no external force should be applied when the resource exchange terminal is being security tested.

[0023] If the identity of the resource-swapping terminal is determined to be invalid, a communication prompt message is sent to remind the user to set a valid identity for the resource-swapping terminal in order to perform a security check.

[0024] Secondly, this application provides a safety base, the safety base comprising:

[0025] A weight measuring device is used to measure a first weight of the resource-exchange terminal when the resource-exchange terminal is located on a secure base, and to send the first weight measurement value to a secure chip.

[0026] The security chip is used to obtain the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal, and to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal and the physical attack weight range.

[0027] In some embodiments, the safety base further includes a processor for performing weight detection verification on the weight measuring device. The weight detection verification includes at least one of weight calibration, electrical parameter adjustment of the weight measuring device, and connection test between the weight measuring device and the safety chip.

[0028] In some embodiments, the security base also includes an encrypted communication bus for connecting a resource exchange terminal;

[0029] The security chip is also used to send at least one of the following to the resource-exchange terminal via encrypted communication: weight difference, alarm information, and verification request information.

[0030] Thirdly, this application provides a security detection device for a resource swapping terminal, applied to a security base, the device comprising:

[0031] The first acquisition module is used to acquire the first weight measurement value of the resource exchange terminal measured by the security base when the resource exchange terminal is located on the security base.

[0032] The second acquisition module is used to acquire the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal;

[0033] The determination module is used to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal, as well as the weight range of the physical attack.

[0034] In some embodiments, the apparatus further includes a sending module, configured to, in the event that the resource-exchanging terminal is subjected to a physical attack, encrypt and send at least one of a weight difference, an alarm message, and a verification request message to the resource-exchanging terminal.

[0035] As an example, the security detection device for the resource-swapping terminal can be a functional circuit, controller, or chip applied to the security base, or the security base itself can be the security detection device for the resource-swapping terminal; for example, the security detection device for the resource-swapping terminal can be a security chip in the security base. This application does not limit this aspect.

[0036] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the security detection method for the resource-swapping terminal described in any one of the first aspects.

[0037] Fifthly, embodiments of this application provide a computer program product that, when run on a computer device, causes the computer device to execute the security detection method for resource-swapping terminals described in any of the first aspects above.

[0038] The beneficial effects of this application embodiment compared to the prior art are as follows: The secure base measures the first weight of the resource-exchange terminal when it is positioned on the secure base. During security detection, the weight difference between the first weight measurement and the standard weight value corresponding to the resource-exchange terminal, and the range of physical attack weights, are used to determine whether the resource-exchange terminal has been physically attacked. Security detection of the resource-exchange terminal can be quickly achieved by detecting weight changes of the resource-exchange terminal independently of the secure base. This innovates the security protection method for resource-exchange terminals, such as POS machines, eliminating the need for diverse and complex physical protection methods, saving overall machine resources, significantly reducing the production difficulty and cost of resource-exchange terminals, such as POS machines, overcoming the limitations of current physical protection methods, expanding the production scope of POS machines, lowering industry barriers, and promoting healthy market competition.

[0039] It is understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0041] Figure 1 is a structural schematic diagram of a safety base according to an embodiment of this application;

[0042] Figure 2 is a flowchart illustrating a security detection method for a resource-swapping terminal provided in an embodiment of this application;

[0043] Figure 3 is a flowchart illustrating another security detection method for a resource swapping terminal provided in an embodiment of this application;

[0044] Figure 4 is a schematic diagram of the application scenario provided in the embodiments of this application;

[0045] Figure 5 is a flowchart illustrating another security detection method for a resource-swapping terminal provided in an embodiment of this application;

[0046] Figure 6 is a flowchart illustrating another security detection method for resource-swapping terminals provided in an embodiment of this application;

[0047] Figure 7 is a schematic diagram of the structure of a security device for a resource swapping terminal provided in an embodiment of this application. Detailed Implementation

[0048] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0049] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0050] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0051] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0052] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0053] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0054] Currently, protection against physical attacks on POS machines often involves covering the circuit boards with wiring and / or installing tamper-proof switches. Since POS machines are frequently used in transaction scenarios, these physically protected POS machines must also meet relevant data security standards at the physical level, such as the Payment Card Industry Data Security Standard (PCIDSS). This significantly increases the manufacturing difficulty and cost of POS machines with physical protection.

[0055] Considering that most physical attacks against POS machines cause changes in the machine's weight, this application proposes a security detection method for resource-swapping terminals. This method is applied to a secure base, which measures the weight of the resource-swapping terminal on the base. The difference between this weight measurement and the standard weight of the terminal determines whether it has been physically attacked. Thus, physical attack detection of one or more resource-swapping terminals can be achieved using only a single secure base. Furthermore, it avoids the need for physical protection measures that comply with relevant data security standards in resource-swapping terminals, such as POS machines, significantly reducing the production difficulty and cost of POS machines.

[0056] The safety base of this application will be introduced below. Figure 1 is a structural schematic diagram of a safety base according to an embodiment of this application. As shown in Figure 1, the safety base 100 includes a weight measuring device 110 and a safety chip 120.

[0057] The security chip 120, also known as the Trusted Platform Module (TPM), is an independent device capable of key generation, encryption, and decryption, and can store keys and data. The security chip 120 provides encryption and security authentication services to the security base 100. The weight measuring device 110 can be a load cell, such as a resistive load cell, an inductive load cell, or a piezoresistive load cell.

[0058] It should be noted that the measuring range of the weight measuring device 110 can be set according to the factory weight of the resource exchange terminal that needs to be tested for security and the weight change caused by the physical attack. The accuracy of the weight measuring device 110 can be set according to the minimum weight value of the resource exchange terminal that needs to be tested for security after being physically attacked. The minimum weight value is the minimum difference between the current weight of each resource exchange terminal that needs to be tested for security and its own factory weight after being physically attacked. In this embodiment, the measuring range is 0-10 kg and the accuracy is 0.01 g.

[0059] The weight measuring device 110 is used to measure a first weight of the resource swapping terminal when the resource swapping terminal is located on the security base, and to send the first weight measurement value to the security chip 120.

[0060] The security chip 120 is used to obtain the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal, and to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal and the physical attack weight range.

[0061] In some embodiments, the security chip 120 further includes a first secure storage area and a second secure storage area. The first secure storage area is used to store the standard weight value of one or more resource-exchange terminals, the weight measurement value of one or more resource-exchange terminals, and the weight difference between the standard weight value and the weight measurement value of one or more resource-exchange terminals. The second secure storage area is used to store the weight range of physical attacks.

[0062] In some embodiments, the safety base 100 further includes a processor 130, which is used to perform weight detection verification on the weight measuring device. The weight detection verification includes at least one of weight calibration, electrical parameter adjustment of the weight measuring device, and connection testing between the weight measuring device and the safety chip. The processor 130 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor 130 may be any conventional processor.

[0063] In some embodiments, the safety base 100 further includes a main power supply 140 and a backup power supply 150. The processor 130 is also configured to detect the operating parameters of the main power supply 140, and, in the event of abnormal operating parameters, send a power supply command to the backup power supply 150 and a power-off command to the main power supply 140. Operating parameters include at least one of remaining power and operating status. Abnormal operating parameters include: the remaining power of the main power supply 140 being less than or equal to a preset lower power limit and / or the main power supply 140 being in a fault or power-off state.

[0064] The main power supply 140 is used to supply power to the safety base 100 and to stop supplying power to the safety base 100 in response to a received power-off command.

[0065] Backup power supply 150 is used to supply power to safety base 100 in response to a received power supply command.

[0066] In this way, on the one hand, the processor can control the main power supply and the backup power supply, avoiding the security chip from controlling other devices in the security base, thus saving the computing resources of the security chip. On the other hand, if the processor determines that the operating parameters of the main power supply are abnormal, it can control the backup power supply to power the security base, avoiding the situation where the security base will inevitably malfunction if the main power supply is abnormal, thereby improving the working stability of the security base.

[0067] In some embodiments, the security base 100 further includes a communication bus 160, which is used to transmit encrypted security detection data to a resource exchange terminal connected to the security base 100. The security detection data includes at least one of weight difference, alarm information, and verification request information. The communication standard of the communication bus 160 may be Universal Serial Bus (USB), Universal Asynchronous Receiver / Transmitter (UART), or Mobile Industry Processor Interface (MIPI), etc., and this application embodiment does not impose specific limitations.

[0068] In some embodiments, the weight measuring device 110 includes multiple measuring ranges and accuracies, such as 0-10kg, 0-5kg, 0.1g, 0.01g, etc. The processor 130 is further configured to send a setting command for the detected measuring range and accuracies to the weight measuring device 110. The weight measuring device 110 is further configured to, in response to the received setting command, select a target measuring range and target accuracies that match the setting command from the multiple measuring ranges and accuracies as the measuring range and accuracies when measuring the terminal for resource exchange.

[0069] In some embodiments, the safety base 100 may further include a display 170 and a processor 130 for displaying detection information when the resource exchange terminal is located on the safety base 100. The detection information is used to prompt the user to avoid applying external force to the resource exchange terminal and to ensure that the safety base is stable.

[0070] The following details the security detection method for the resource swapping terminal in this application.

[0071] Figure 2 is a flowchart illustrating a security detection method for a resource-swapping terminal according to an embodiment of this application. This method can be applied to a security base, which can be the security base 100 shown in the embodiment of Figure 1. As shown in Figure 2, the method includes the following steps:

[0072] Step S201: When the resource exchange terminal is located on the security base, the security base acquires the first weight measurement value of the resource exchange terminal measured by the security base.

[0073] The resource-swapping terminal can be any electronic payment tool, such as a mobile phone, tablet, or POS machine. This embodiment uses a POS machine as an example. When a user needs to perform security checks on the resource-swapping terminal, i.e., to check if the terminal has been physically attacked, the user can place the security base on a stable surface and then place the resource-swapping terminal stably on the weighing position of the security base. The security base can then detect changes in the voltage, resistance, and / or current of its own weight-measuring device to determine if a resource-swapping terminal is located on it. It then sends a message to the resource-swapping terminal reminding the user not to apply external force to the terminal, causing the terminal to display this message. This prevents the user from interfering with the terminal's weight, allowing the weight detection device in the security base to accurately measure the terminal's weight and obtain a first weight measurement value.

[0074] In step S202, the security base obtains the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal.

[0075] The standard weight value corresponding to the resource exchange terminal is the weight of the resource exchange terminal when it is not physically attacked. The security base stores the identifiers of one or more resource exchange terminals, as well as the standard weight value corresponding to each identifier. The identifier of the resource exchange terminal can be the serial number (SN) of the resource exchange terminal, or other characters or strings that can uniquely identify the resource exchange terminal. This application embodiment does not impose specific limitations.

[0076] During the communication process between the secure base and the resource-swapping terminal, the resource-swapping terminal sends its own identifier to the secure base, which then obtains the identifier. After obtaining the first weight measurement value of the resource-swapping terminal, the secure base can query the standard weight value corresponding to the identifier in the first secure storage area based on the obtained identifier, thus obtaining the standard weight value of the resource-swapping terminal.

[0077] In step S203, the security base determines whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal, as well as the weight range of the physical attack.

[0078] The physical attack weight range indicates the range of differences between the weight of a resource-swapping terminal after a physical attack and its standard weight. This range can be set based on the minimum and maximum weight values ​​recorded after a physical attack on a resource-swapping terminal requiring security testing. The minimum weight value is the minimum difference between the current weight of each resource-swapping terminal after a physical attack and its factory default weight. The maximum weight value is the maximum difference between the current weight of each resource-swapping terminal after a physical attack and its factory default weight.

[0079] The security base calculates the weight difference between the first weight measurement of the resource swapping terminal and the standard weight value, and determines whether the resource swapping terminal has been physically attacked based on whether the weight difference is within the range of physical attack weight.

[0080] It should be noted that, to enhance data security, the resource-exchange terminal is a terminal that uses software methods, i.e., software encryption, to strengthen data security. The security base must meet the relevant data security standards stipulated for resource-exchange terminals, such as POS machines, in daily use, such as the PCIDSS standard. In this way, a security base that meets the relevant data security standards can be used to perform security testing on a large number of resource-exchange terminals, eliminating the need for different physical protection measures on different resource-exchange terminals, thus standardizing the detection of cases involving resource-exchange terminals.

[0081] In this embodiment, the security base measures the first weight of the resource-swapping terminal when it is positioned on the base. During security testing, the weight difference between the first weight measurement and the standard weight of the resource-swapping terminal, along with the range of physical attack weights, determines whether the resource-swapping terminal has been physically attacked. Security testing of resource-swapping terminals can be rapidly achieved by detecting weight changes using a security base independent of the terminal itself. This innovative approach to security protection for resource-swapping terminals, such as POS machines, eliminates the need for diverse and complex physical protection methods, saving overall terminal resources and significantly reducing production difficulty and cost. It overcomes the limitations of current physical protection methods, expands the production scope of POS machines, lowers industry barriers, and promotes healthy market competition.

[0082] Figure 3 is a flowchart illustrating another security detection method for a resource-swapping terminal according to an embodiment of this application. This method can be applied to a security base, which can be the security base 100 shown in the embodiment of Figure 1. As shown in Figure 3, the method includes the following steps:

[0083] Steps S301 to S302.

[0084] For details of steps S301 and S302, please refer to steps S201 and S202 in the embodiment shown in Figure 2, which will not be repeated here.

[0085] In some implementations, the method further includes: the security base sends encrypted security detection request information to the resource exchange terminal based on a preset time period. The security detection request information is used to trigger the resource exchange terminal to prompt the resource exchange terminal to place the resource exchange terminal on the security base and avoid external interference so that the security base can perform security detection on the resource exchange terminal.

[0086] The preset time period can be set arbitrarily, and this embodiment does not impose specific limitations. The security base can periodically generate security detection request information based on the preset time period, and encrypt this security detection request information using a preset encryption algorithm before sending the encrypted security detection request information to the resource exchange terminal. This enables periodic reminders for security detection of the resource exchange terminal, facilitating timely detection of whether the resource exchange terminal has been physically attacked, thus preventing users from using attacked resource exchange terminals and improving the data security of the resource exchange terminal. The preset encryption algorithm can be a national cryptographic algorithm, a symmetric encryption algorithm, an asymmetric encryption algorithm, or a digital signature, or other algorithms that comply with security authentication; this embodiment does not impose specific limitations.

[0087] In the application, users will continuously place the resource-swapping terminal on the secure base. At this time, the weight of the resource-swapping terminal will change due to external interference. However, the resource-swapping terminal is not necessarily physically attacked. To improve the accuracy of security detection, the method also includes the following steps:

[0088] Step (1): The security base acquires the first weight measurement value of the resource swapping terminal in real time.

[0089] When the resource exchange terminal is continuously placed on the safety base, the weight measuring device of the safety base can weigh the resource exchange terminal in real time, and the safety base can obtain the first weight measurement value in real time.

[0090] Step (2): The safety base determines in real time whether the weight difference between the first weight measurement value and the standard measurement value corresponding to the resource exchange terminal is not equal to zero.

[0091] Step (3): If the weight difference is determined to be non-zero, an overweight information is sent to the resource exchange terminal. The overweight information is used to trigger the resource exchange terminal to prompt that the current weight is abnormal. The weight detection and verification of the safety base is required before the safety detection of the resource exchange terminal is performed.

[0092] When a resource-swapping terminal is continuously placed on a secure base, the weight difference between the terminal's initial weight measurement and a standard measurement is detected in real time by the secure base. However, instead of using this weight difference to determine whether the terminal has been physically attacked, an overweight message is sent to the terminal when the weight difference is not zero. This message prompts the user to verify the weight of the secure base before performing a security check on the terminal. This avoids errors caused by external interference or malfunctions of the secure base during security checks, thus improving the accuracy of security checks (i.e., physical attack detection) on resource-swapping terminals, such as POS machines.

[0093] In step S303, if the security base determines that the weight difference between the first weight measurement value and the standard weight value of the resource exchange terminal is within the range of physical attack weight, then it determines that the resource exchange terminal has been physically attacked; if it determines that the weight difference between the first weight measurement value and the standard weight value of the resource exchange terminal is less than the minimum weight value in the range of physical attack weight, then it determines that the resource exchange terminal has not been physically attacked.

[0094] In some embodiments, when the security base measures the weight of the resource-swapping terminal, if the weight of the resource-swapping terminal exceeds the maximum range of the security base, the security base will send an over-range information to the resource-swapping terminal to trigger a warning from the resource-swapping terminal indicating that it is overweight and may be subject to physical attack, so that the user can take timely measures. The range of the security base is also the range of the weight measuring device.

[0095] Optionally, the method provided in this application embodiment may further include the following after step S303:

[0096] In step S304, if the security base determines that the resource exchange terminal has been physically attacked, it sends at least one of the following to the resource exchange terminal in encrypted form: weight difference, alarm information, and verification request information.

[0097] The alarm message triggers the resource-swapping terminal to indicate that it may be under physical attack, while the verification request message triggers the resource-swapping terminal to request a weight check and verification of the security base. The security base can generate alarm messages and / or verification request messages when it determines that the resource-swapping terminal has been under physical attack, and encrypt at least one of the weight difference, alarm messages, and verification request messages using the aforementioned encryption algorithm.

[0098] In some embodiments, the safety base also includes a power source and a backup power source, and the safety base can also use the power source or the backup power source to provide charging services to the resource exchange terminal.

[0099] In one application scenario, as shown in Figure 4, the resource exchange terminal is a POS machine with software encryption. The weight of the POS machine when it is not physically attacked is D, which is the standard weight value. The physical attack is to steal the magnetic head data (i.e., account data) of the POS machine. The processor of the security base is the core CPU, and the security chip and weight detection device are integrated into the processor.

[0100] Attackers would add an extra magnetic head to the POS machine. Without affecting the normal operation of the POS machine, when the POS machine swipes a card using the original magnetic head, the newly added magnetic head would also read the magnetic head data. Then, a chip would be used to record the read data, and a transmitting chip would be used to send the stolen data to the attacker.

[0101] Therefore, in order to successfully steal data from the POS machine's magnetic head, attackers would need to add a data recording chip, a new magnetic head, and a transmitting chip (such as a Bluetooth or Wi-Fi chip) to the POS machine. To ensure these chips function properly, circuit connections and power supplies are required, necessitating a PCB board to integrate them and enable data theft. These chips also require electrical power. While using the POS machine's existing power supply to power these chips eliminates the need for a new power source, it does require connecting the existing power supply to the chips via jumper wires.

[0102] Therefore, the weight change X of the POS machine during this physical attack is calculated as follows: weight of the detection chip (data recording chip + new read / write head) + weight of the transmitting chip + weight of the PCB board + weight of the jumper wires. Even without using a new read / write head to steal data, the weight change X becomes the weight of the detection chip (data recording chip) + weight of the transmitting chip + weight of the PCB board + weight of the jumper wires. Based on this weight change, it can be determined whether the POS machine has been physically attacked.

[0103] As shown in Figure 4, the security base periodically sends encrypted security detection request information to the POS machine via the communication bus, which is the POS machine presence detection (prompt presence) in Figure 4. This triggers the POS machine to prompt the resource swapping terminal to be placed on the security base, avoiding external interference so that the security base can perform security detection on the resource swapping terminal. The user places the security base and the POS machine stably on it, avoiding any external interference. In this way, the security base can use the weight detection device in the core CPU to measure the first weight of the POS machine at fixed time intervals, i.e., reading the weighing data at fixed time intervals as shown in Figure 4, and encrypting the weight measurement.

[0104] If a POS machine is physically attacked, a weight change X will occur. The initial weight measurement of the POS machine will fall within the range of the total weight D+Xmin and the total weight D+Xmax. At this time, the security platform will calculate the weight difference between the initial weight measurement and the total weight D, which is the standard weight of the POS machine. If this difference is within the physical attack weight range (Xmin, Xmax), it is determined that the POS machine has been physically attacked. The security platform will encrypt and send at least one of the following to the POS machine via the communication bus: the weight difference, an alarm message, and a verification request message. In this way, the user can be aware that the POS machine may have been physically attacked and take appropriate measures to mitigate losses in time.

[0105] Sometimes the POS machine will be placed on the safety stand for a period of time. At this time, the safety stand will provide an overweight reminder service. The safety stand can use a weight measuring device to measure the first weight measurement value of the POS machine in real time, which is the real-time reading of the weighing data in Figure 4, and determine whether the weight difference between the first weight measurement value and the standard weight value is not equal to zero. If so, the overweight information is sent to the POS machine in encrypted form through the communication bus.

[0106] It is understood that in the application scenario shown in Figure 4, the accuracy of the weight measuring device of the security base should be less than Xmin, and the range of the weight measuring device should be greater than the total weight D+Xmax of the POS machine. Xmin is the minimum weight change of the POS machine after being physically attacked, which is the minimum weight value in the aforementioned embodiment, and Xmax is the maximum weight change of the POS machine after being physically attacked, which is the maximum weight value in the aforementioned embodiment.

[0107] In this embodiment, the security base quickly determines whether a resource-swapping terminal has been physically attacked by checking whether the weight difference between the first weight measurement value of the resource-swapping terminal and the standard weight value corresponding to the resource-swapping terminal is within the range of a physical attack weight. This ensures the physical security of the resource-swapping terminal while enabling rapid detection of physical attacks. It also avoids the need for physical protection measures such as wiring coverage on resource-swapping terminals, such as POS machines, significantly reducing the production difficulty and cost of POS machines. Furthermore, upon determining that the resource-swapping terminal has been physically attacked, it promptly sends at least one of the following encrypted messages to the resource-swapping terminal: the weight difference, an alarm message, and a verification request message. This timely alerts the user to take measures to minimize potential losses.

[0108] It is understandable that by avoiding wiring coverage on resource-swapping terminals, such as POS machines, it is also possible to avoid interference with signals in resource-swapping terminals caused by traditional wiring coverage, thereby improving the power integrity (PI) and signal integrity (SI) of resource-swapping terminals and thus improving the overall performance of resource-swapping terminals.

[0109] Figure 5 is a flowchart illustrating another security detection method for a resource-swapping terminal according to an embodiment of this application. This method can be applied to a security base, which can be the security base 100 shown in the embodiment of Figure 1. As shown in Figure 5, the method includes the following steps:

[0110] Steps S501 to S502.

[0111] For details of steps S501 and S502, please refer to steps S301 and S302 in the embodiment shown in Figure 3, which will not be repeated here.

[0112] In step S503, if the security base determines that the weight difference between the first weight measurement value and the standard weight value of the resource swapping terminal is greater than or equal to the minimum weight value in the physical attack weight range, it sends a verification request message to the resource swapping terminal.

[0113] The verification request information is used to trigger the resource exchange terminal to prompt a weight detection verification of the security base. After the security base sends the verification request information to the resource exchange terminal, the user can clearly indicate through the resource exchange terminal that a weight detection verification of the security base is required. Then, different items with weight standards (e.g., weights) can be placed on the security base so that the weight measuring device of the security base can measure the weight. The processor of the security base can then perform at least one of the following processing operations: weight calibration, electrical parameter adjustment, and connection test between the weight measuring device and the security chip, to determine whether the weight detection verification of the weight measuring device is successful.

[0114] In step S504, after the weight detection verification is successful, the safety base uses its own weight detection device to remeasure the second weight measurement value of the resource swapping terminal.

[0115] After successful weight detection and verification, the security base will remeasure the weight of the resource-swapping terminal using its own weight detection device to obtain a second weight measurement. If the weight detection and verification fails, the security base will send a base replacement message to the resource-swapping terminal. This message triggers the resource-swapping terminal to prompt for a replacement of the security base.

[0116] Step S505: If it is determined that the weight difference between the second weight measurement value and the standard weight value is greater than or equal to the minimum weight value in the physical attack weight range, then the security base determines that the resource swapping terminal has been physically attacked.

[0117] The security base will recalculate the weight difference between the second weight measurement and the standard weight value. If the weight difference is greater than or equal to the minimum weight value in the physical attack weight range, the security base determines that the resource swapping terminal has been physically attacked. If the weight difference is less than the minimum weight value in the physical attack weight range, the security base determines that the resource swapping terminal has not been physically attacked.

[0118] Optionally, if the security base determines that the resource-swapping terminal has been physically attacked, the method provided in this application embodiment, as shown in Figure 5, may further include:

[0119] In step S506, if the security base determines that the resource exchange terminal has been physically attacked, it sends at least one of the following to the resource exchange terminal in encrypted form: weight difference, alarm information, and verification request information.

[0120] For details of step S506, please refer to step S304 in the embodiment shown in Figure 3, which will not be repeated here.

[0121] In some embodiments, the security base may include a first measurement mode and a second measurement mode. The first measurement mode is used to quickly detect whether the resource-swapping terminal has been physically attacked, and its detection process is shown in the embodiment of Figure 3. The second measurement mode is used to accurately detect whether the resource-swapping terminal has been physically attacked, and its detection process is shown in the embodiment of Figure 5. The security base can determine its own measurement mode in response to an input measurement mode selection command, thereby determining the specific detection process for the resource-swapping terminal.

[0122] As an example, when the resource exchange terminal is located on the security base, the security base can prompt the user to select a measurement mode. Assuming that the security base determines that the first measurement mode is triggered, the security base can determine whether the resource exchange terminal has been physically attacked through the embodiment shown in Figure 3. If the second measurement mode is triggered, the security base can determine whether the resource exchange terminal has been physically attacked through the embodiment shown in Figure 5.

[0123] As another example, the security dock defaults to using the first measurement mode to detect whether the resource-swapping terminal has been physically attacked. In some embodiments, the security dock can also respond to an input weight detection verification command by using its own processor to perform weight detection verification on the weight detection device.

[0124] Referring to Figure 4, the secure base can provide mechanical verification services, that is, weight detection verification services. When the secure base determines that the weight difference between the first weight measurement value and the total weight D, which is the standard weight value of the POS machine, is greater than or equal to Xmin, it will send a verification request message to the POS machine via the communication bus in encrypted form. The user performs weight detection verification, i.e., mechanical verification, on the secure base according to the prompts of the POS machine. After the weight detection verification is successful, the secure base re-determines the weight difference between the second weight measurement value of the POS machine and the total weight D, which is the standard weight value of the POS machine. Then, based on the weight difference and the weight range of physical attacks, it determines whether the POS machine is under physical attack.

[0125] In this embodiment, after determining that the first weight measurement value of the resource-swapping terminal is greater than or equal to the minimum weight value in the physical attack weight range between the standard weight value and the first weight measurement value of the resource-swapping terminal, a verification request message is first sent to the resource-swapping terminal to perform weight detection verification on the security base. After the weight detection verification is successful, the second weight measurement value of the resource-swapping terminal is remeasured to determine whether the resource-swapping terminal has been physically attacked based on the new measurement value. This avoids the situation where the judgment is wrong due to the inaccuracy of the security base itself, and improves the reliability and accuracy of the security detection of the resource-swapping terminal.

[0126] Before performing security testing on the resource-swapping terminal, the security base needs to establish a communication connection with the resource-swapping terminal to facilitate data transmission during the security testing. Furthermore, to improve the accuracy of the security testing, after establishing the communication connection, the method provided in this embodiment can also detect whether the resource-swapping terminal is located on the security base, thus completing the in-situ detection of the resource-swapping terminal and reminding the user to avoid external interference with the resource-swapping terminal. The specific process is shown in Figure 6. Another method for security testing of a resource-swapping terminal in this embodiment further includes the following steps:

[0127] Step S601: The security base detects whether the resource swapping terminal is located on the security base.

[0128] The safety base can use its own processor to detect whether the operating parameters of its weight detection device have changed. If a change is detected, the safety base can determine whether the resource exchange terminal is located on the safety base; otherwise, it determines that the resource exchange terminal is not located on the safety base. The operating parameters include at least one of voltage, resistance, and current.

[0129] Step S602: If the resource exchange terminal is located on the security base, the security base verifies whether the identity of the resource exchange terminal is legitimate based on the identifier of the resource exchange terminal.

[0130] If the security base determines that the resource-exchanging terminal is located on the security base, it can use its own processor to send an identification request to the resource-exchanging terminal, so that the resource-exchanging terminal can return its own identification to the security base. The security base stores the identifications of one or more legitimate resource-exchanging terminals. The security base can query the received identification among the legitimate resource-exchanging terminal identifications. If the identification is found, the identity of the resource-exchanging terminal is determined to be legitimate; if the identification is not found, the identity of the resource-exchanging terminal is determined to be illegitimate.

[0131] Step S603: If the identity of the resource exchange terminal is determined to be legitimate, the secure base establishes a secure communication connection with the resource exchange terminal.

[0132] The secure base can establish a secure communication connection between itself and the resource exchange terminal through software encryption. The secure communication connection is used by the secure base to send and / or transmit at least one of the following to the resource exchange terminal in encrypted form: weight difference, alarm information, and verification request information.

[0133] Step S604: Send a detection prompt message to the resource exchange terminal via a secure communication connection.

[0134] The detection prompt message is used to trigger the resource swapping terminal to remind users not to apply external force when performing security checks on the resource swapping terminal.

[0135] In step S605, if it is determined that the identity of the resource swapping terminal is invalid, the security base sends a communication prompt message.

[0136] The notification message is used to prompt users to set up a legitimate identity for the resource-swapping terminal for security checks. When the security base determines that the resource-swapping terminal's identity is invalid, it can send a communication notification message to the preset user terminal to remind the user to set up a legitimate identity for the resource-swapping terminal in the security base for security checks.

[0137] In some embodiments, the method further includes: the secure base receiving a legitimate identity setting request; and setting the identity of the resource-swapping terminal indicated by the identifier of the resource-swapping terminal in the legitimate identity setting request to legitimate.

[0138] In this embodiment, when the security base detects that the resource-swapping terminal is located on the security base, its identity is determined based on the terminal's identifier. A secure communication connection is then established to facilitate secure data transmission during subsequent security testing of the resource-swapping terminal. Once the secure communication connection is established, a detection prompt message is sent to the resource-swapping terminal to promptly remind the user to avoid external interference during testing, thereby improving the accuracy of the security testing.

[0139] Corresponding to the security detection method for resource-swapping terminals described in the above embodiments, Figure 7 shows a structural block diagram of the security detection device for resource-swapping terminals provided in the embodiments of this application. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0140] Referring to Figure 7, the device includes:

[0141] The first acquisition module 710 is used to acquire the first weight measurement value of the resource exchange terminal measured by the security base when the resource exchange terminal is located on the security base.

[0142] The second acquisition module 720 is used to acquire the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal;

[0143] The determination module 730 is used to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal, as well as the weight range of the physical attack.

[0144] For example, the first acquisition module 710 can be integrated into the aforementioned weight detection device.

[0145] For example, the second acquisition module 720 and the determination module 730 can be integrated into the aforementioned security chip.

[0146] In some embodiments, the determining module 730 is further configured to:

[0147] If the weight difference is determined to be within the range of physical attack weight, then the resource swapping terminal is determined to have been physically attacked.

[0148] If the weight difference is determined to be less than the minimum weight value within the range of physical attack weights, then it is determined that the resource swapping terminal has not been physically attacked.

[0149] In some embodiments, the determining module 730 is further configured to:

[0150] If the weight difference is determined to be greater than or equal to the minimum weight value in the physical attack weight range, a verification request message is sent to the resource exchange terminal. The verification request message is used to trigger the resource exchange terminal to prompt a weight detection and verification of the security base.

[0151] After the weight detection verification is successful, the safety base uses its own weight detection device to remeasure the second weight measurement value of the resource swapping terminal.

[0152] If the weight difference between the second weight measurement and the standard weight value is determined to be greater than or equal to the minimum weight value in the physical attack weight range, then the resource swapping terminal is determined to be under physical attack.

[0153] In some embodiments, the device further includes:

[0154] The sending module is used to send at least one of the following to the resource exchange terminal in encrypted form: a weight difference, an alarm message, and a verification request message, if it is determined that the resource exchange terminal has been physically attacked.

[0155] In some embodiments, the device further includes:

[0156] The detection module is used to detect whether the resource exchange terminal is located on the security base;

[0157] The verification module is used to verify the legitimacy of the resource exchange terminal's identity based on its identifier if the resource exchange terminal is located on the security base.

[0158] The module establishes a secure communication connection with the resource exchange terminal if the identity of the resource exchange terminal is determined to be legitimate.

[0159] The sending module is also used to send a communication prompt message if it is determined that the identity of the resource exchange terminal is invalid. The prompt message is used to prompt the user to set the legitimate identity of the resource exchange terminal for security testing.

[0160] For example, the detection module, verification module, and establishment module can be integrated into the aforementioned processor. The transmission module can be integrated into the communication interface of the security base.

[0161] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0162] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0163] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.

[0164] This application provides a computer program product that, when run on a secure base, enables the secure base to perform the steps described in the above-described method embodiments.

[0165] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0166] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0167] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0168] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0169] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0170] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A security detection method for a resource-swapping terminal, characterized in that, Applied to a safety base, the method includes: Obtain the first weight measurement value of the resource exchange terminal measured by the security base when the resource exchange terminal is located on the security base; Obtain the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal; Based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal, as well as the weight range of physical attacks, it is determined whether the resource exchange terminal has been physically attacked.

2. The method as described in claim 1, characterized in that, The step of determining whether the resource-swapping terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource-swapping terminal, and the weight range of physical attacks, includes: If it is determined that the weight difference is within the range of the physical attack weight, then it is determined that the resource swapping terminal has been physically attacked. If the weight difference is determined to be less than the minimum weight value in the range of physical attack weights, then it is determined that the resource swapping terminal has not been physically attacked.

3. The method as described in claim 1, characterized in that, The step of determining whether the resource-swapping terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource-swapping terminal, and the weight range of physical attacks, includes: If it is determined that the weight difference is greater than or equal to the minimum weight value in the range of physical attack weights, a verification request message is sent to the resource exchange terminal. The verification request message is used to trigger the resource exchange terminal to prompt the weight detection and verification of the security base. After the weight detection verification is successful, the security base uses its own weight detection device to remeasure the second weight measurement value of the resource exchange terminal; If the weight difference between the second weight measurement and the standard weight value is determined to be greater than or equal to the minimum weight value in the physical attack weight range, then the resource swapping terminal is determined to be under physical attack.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: If it is determined that the resource exchange terminal has been physically attacked, then at least one of the following is encrypted and sent to the resource exchange terminal: the weight difference, the alarm information, and the verification request information.

5. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Detect whether the resource swapping terminal is located on the security base; If the resource exchange terminal is located on the security base, the identity of the resource exchange terminal is verified based on its identifier. If the identity of the resource exchange terminal is determined to be legitimate, a secure communication connection is established with the resource exchange terminal. The detection prompt information is sent to the resource exchange terminal via the secure communication connection. The detection prompt information is used to trigger the resource exchange terminal to prompt that no external force should be applied when the resource exchange terminal is being security tested. If the identity of the resource-swapping terminal is determined to be invalid, a communication prompt message is sent. The prompt message is used to prompt the user to set a valid identity for the resource-swapping terminal for security testing.

6. A safety base, characterized in that, The safety base includes: A weight measuring device is used to measure a first weight measurement value of the resource exchange terminal when the resource exchange terminal is located on the security base, and to send the first weight measurement value to the security chip. The security chip is used to obtain the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal, and to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal and the physical attack weight range.

7. The safety base according to claim 6, characterized in that, The safety base also includes a processor, which is used to perform weight detection and verification on the weight measuring device. The weight detection and verification includes at least one of weight calibration, electrical parameter adjustment of the weight measuring device, and connection test between the weight measuring device and the safety chip.

8. A security detection device for a resource swapping terminal, characterized in that, Applied to a safety base, the device includes: The first acquisition module is used to acquire the first weight measurement value of the resource exchange terminal measured by the security base when the resource exchange terminal is located on the security base; The second acquisition module is used to acquire the standard weight value corresponding to the resource exchange terminal based on the identifier of the resource exchange terminal; The determination module is used to determine whether the resource exchange terminal has been physically attacked based on the weight difference between the first weight measurement value and the standard weight value corresponding to the resource exchange terminal, as well as the weight range of the physical attack.

9. The apparatus as claimed in claim 8, characterized in that, The device further includes a sending module, configured to, in the event that the resource exchange terminal is subjected to a physical attack, encrypt and send at least one of the weight difference, alarm information, and verification request information to the resource exchange terminal.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Payment terminal detecting device, system and method

    CN106651406A

  • Security detection method of resource exchange terminal, security base, device and medium

    CN118802345A

  • Sensing element protection mechanism and payment equipment

    CN206497459U

  • Safety cabinet for preventing physical attacks

    CN210781780U

  • Method For Protecting A Payment Terminal

    US20210281398A1