Mobile Terminal Key Protection via Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In online banking, the lack of verification of the terminal device by the bank server during public key certificate transmission leads to potential interception and theft of user public key certificates, compromising security.
Innovation Solution
A key protection method where a mobile terminal generates and manages user public and private keys, with the mobile bank server and comprehensive pre-position bank server verifying the terminal's identity, and sending the public key to a third-party e-business verification server to generate and store a public key certificate, ensuring secure communication and protecting the private key through updated protection parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the bank server sends the user's public key certificate to the terminal without terminal verification, then the transmission process is simple and fast, but the security is compromised and the certificate may be intercepted or stolen
Solution Approach 1:
The patent applies preliminary action by performing terminal identity verification before the actual transmission of the public key certificate. The bank server verifies the terminal's identity (through device identifiers, installed applications, or other terminal characteristics) before sending the certificate, ensuring that only authorized terminals receive the certificate. This preliminary verification step prevents interception and theft while maintaining a relatively simple overall process.
2Reliability
If the bank server verifies terminal identity before sending the public key certificate, then the security is improved, but the verification process becomes more complex and time-consuming
Solution Approach 1:
The verification of terminal identity is performed as a preliminary action before the actual certificate transmission. By checking terminal characteristics (device identifiers, installed applications, etc.) in advance, the system ensures security without requiring complex real-time verification during the transmission process itself, thus minimizing time loss.
3Reliability
If the private key is stored without updated protection parameters, then the storage process is simple, but the security of the private key is compromised
Solution Approach 1:
The patent applies dynamics by implementing an updated protection mechanism for the private key. Instead of using static protection, the system dynamically updates protection parameters (such as encryption keys or security policies) based on verification results and security requirements. This dynamic approach enhances security while maintaining manageable complexity through automated updates.
4Reliability
If the mobile bank server performs identity verification on the mobile terminal, then the safety of communication is secured and simulated terminals are prevented, but the verification process becomes more complex
Solution Approach 1:
The patent applies self-service by having the mobile terminal provide its own identity information (device identifiers, installed applications, terminal characteristics) for verification. The bank server uses this self-provided information to verify authenticity, reducing the need for complex active verification mechanisms while maintaining high security. The terminal essentially verifies itself by presenting its unique characteristics.
Data Source
AI summary
Proposed are a key protection method and system. The method comprises: a: receiving by a mobile terminal a registration instruction, generating a user's public key and private key, and sending the user's public key to a third-party e-business verification server, if the mobile terminal respectively passes identity verifications of the mobile bank server and a comprehensive pre-position bank server; b: performing a verification by the mobile bank server on user's trade information, and performing a trade by the comprehensive pre-position bank server if the verification is successful; c: generating by the mobile terminal an updated parameter for protecting a private key after the trade is performed, sending to the mobile bank server, receiving a successful updating result from the mobile bank server and encrypting and storing the user's private key. The present invention can increase the difficulty of an attack, and improve security.


