Security downloading method and system of TMK
Abstract
The invention discloses a security downloading method of a TMK. The security downloading method comprises the steps that a KMS produces a public key Pu and a private key Pr, and the public key Pu is sent to a POS terminal; the POS terminal produces a TK, and the TK is encrypted through the public key Pu and sent to the KMS, wherein the TK is composed of a TEK and an AUK; the KMS and the POS terminal use the AUK for conducting bidirectional authentication, and if the KMS and the POS terminal pass through the authentication, the KMS sends the TMK to the POS terminal after using the TEK for encrypting the TMK; after receiving master key ciphertext Ctmk_tk sent by the KMS, the POS terminal uses the TEK for decrypting the master key ciphertext Ctmk_tk to obtain the TMK and stores the TMK in a PIN pad. The security downloading method and system of the TMK have the advantages that the TMK is downloaded remotely by uploading the TK through the POS terminal, the TK comprises the TEK and the AUK, and therefore security downloading of the TMK is guaranteed effectively.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 2 independent, 8 dependent
- 11 Terminal main key TMK safety downloading method, comprising a characterised, comprising steps:System SUKMS call hardware encryption device of generate key Pu and private key Pr, respectively Pu key to POS terminal password keyboard, a Nd 52, P0S terminal transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu;and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK;a 53 Rd, the KMS system call hardware encryption device using private key Pr deciphers transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key;AUK 54 Ohm;the KMS system and POS terminal using transmission authentication key AUK and mutual authentication, and authentication is KMS, system and call hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK of the main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal;55 Ohm, wherein the POS terminal receiving KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphers main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard. 1.一种终端主密钥TMK安全下载方法,其特征在于,包括步骤: SUKMS系统调用硬件加密机产生公钥Pu和私钥Pr,将公钥Pu发送至POS终端密码键盘中; 52、P0S终端调用密码键盘随机产生传输密钥TK并使用公钥Pu加密传输密钥TK生成传输密钥密文Ctk_Pu,然后将传输密钥密文Ctk_Pu发送至KMS系统,其中,传输密钥TK由传输加密密钥TEK和传输认证密钥AUK构成; 53、KMS系统调用硬件加密机使用私钥Pr解密传输密钥密文Ctk_Pu获得传输加密密钥TEK和传输认证密钥AUK ; 54、KMS系统与POS终端使用传输认证密钥AUK进行双向认证,如果认证通过,KMS系统调用硬件加密机使用传输加密密钥TEK加密终端主密钥TMK生成主密钥密文Ctmk_tk并将主密钥密文发送至POS终端; 55、POS终端接收到KMS系统发送的主密钥密文Ctmk_tk后使用传输加密密钥TEK解密主密钥密文Ctmk_tk获得终端主密钥TMK并将终端主密钥TMK存储在密码键盘中。
- 61 Terminal main key TMK safety downloading system, comprising a characterised, comprising a KMS system, and KMS communication system is connected with POS terminal, and hardware encryption device;The POS terminal and mutual authentication a module comprises a TK generate module and decryption module, the KMS system comprises male private generate key module and TK receiving module, encryption module and mutual authentication current module;The male private generate key module is used to transfer hardware encryption device of generate key Pu and a private key Pr, respectively Pu key to POS terminal password keyboard, a The TK generate module is used to transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu;and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK;a The TK receiving module is used;when received transmitting key scrambled message Ctk_Pu, transferred hardware encryption device using private key Pr to a transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key;AUK The mutual authentication a module and a mutual authentication current module is used in KMS system POS front end of TMK, using transmission authentication key AUK disposed on the KMS system and a mutual authentication between POS terminals;The encryption module are provided, which comprises a mutual authentication function, wherein hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK to generate main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal;The decryption module are provided, wherein after the POS terminal received the KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphered main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard. 6.一种终端主密钥TMK安全下载系统,其特征在于,包括KMS系统、与KMS系统通信连接的POS终端、以及硬件加密机;所述POS终端包括TK产生模块、解密模块以及双向认证A模块,所述KMS系统包括公私钥产生模块、TK接收模块、加密模块以及双向认证B模块; 所述公私钥产生模块用于调用硬件加密机产生公钥Pu和私钥Pr,将公钥Pu发送至POS终端密码键盘中; 所述TK产生模块用于调用密码键盘随机产生传输密钥TK并使用公钥Pu加密传输密钥TK生成传输密钥密文Ctk_Pu,然后将传输密钥密文Ctk_Pu发送至KMS系统,其中,传输密钥TK由传输加密密钥TEK和传输认证密钥AUK构成; 所述TK接收模块用于当接收到传输密钥密文Ctk_Pu时,调用硬件加密机使用私钥Pr解密传输密钥密文Ctk_Pu获得传输加密密钥TEK和传输认证密钥AUK ; 所述双向认证A模块与双向认证B模块用于在KMS系统向POS终端传送TMK之前,使用传输认证密钥AUK进行KMS系统与POS终端之间的双向认证; 所述加密模块用于当双向认证通过后,调用硬件加密机使用传输加密密钥TEK加密终端主密钥TMK生成主密钥密文Ctmk_tk并将主密钥密文发送至POS终端; 所述解密模块用于当POS终端接收到KMS系统发送的主密钥密文Ctmk_tk后,使用传输加密密钥TEK解密主密钥密文Ctmk_tk获得终端主密钥TMK并将终端主密钥TMK存储在密码键盘中。
Independent claims2
90 paragraphs, as filed
A terminal main key TMK safety downloading method and system for
technical field
[0001] The invention relates to an pay field, to a terminal main key TMK safety downloading method and system for transformer.
Background method
[0002] The bankcard (BANK Card) is composed of multiple and a popular and a method of pay, usual bankcard pay system comprises point-of-sale terminal (Point Of Sale, POS), POS receiving system (P0SP), password keyboard (TWO SECONDARY) and hardware encryption device (Hardware and Safety Module, HSM). And the POS terminal of the bankcard information, a complete financial processing method and device for related of exchange information of communication function, and housing; tellerThe P0S receiving system thereof the centralized management to the POS terminal, comprising a parameter downloading, a downloading, receiving method, or retransmits the processing of POS terminal to request and according to the POS terminal loop processing result information, a centralized management and processing process's; systemThe password keyboard (TWO SECONDARY) performing etching safety protection device to each of financial commerce and buttons, and the encipherment protection PIN to the safety device; Hardware encryption device (HSM) and encryption to data transmission the periphery hardware device, encryption and decryption for PIN, data message and high-precision and device for key of source. Personal identification code (Personal Identification Number, TWO), wherein the personal password, a cardholder the state valid data information in online processing, and a network system any unit of the computer in the manner of determining orders without fixture; The terminal main key (Terminal Main Key, TMK), POS metal terminal, and encryption to work button the main key, a encryption on the system, libraryP0S terminal widespread applied to bankcard pay condition, a of the oxide shopping and hotel lodging equal, and indispensable modernized pay method that which comprises a situations for people transformer. The bankcard, wherein the debit, generally that IS arranged in the cardholder, a bearing is pay process; the POS terminal with bankcard rail information and material is on, further - wants cardholder input PIN to confirm the state validity of cardholder are circular card module, winding of the bankcard pay, safety protection cardholder's safety property. Or the invention is a PAIR of leakage, claim from terminal to the card edge group information interaction method, a rectifying journey time safety protection encipherment to TWO, the opening of the correction unit of computer network system, IS no fixture of the manner of determining orders, therefore to the input IS POS terminal requirement to provide the key management system with a.
[0003] The POS terminal key system is divided into second-stage: Terminal main key (TMK) and key (WK). And TMK time encipherment protection to WK. The POS terminal is installed TMK, flowing probably a safety protection ensure, only energy written the device and participates the calculation, it; anTMK is a very key are key, a TMK are intercepted, the key with easily is invention that wherein threaten the bankcard pay safety seriously. Therefore a protective hood download TMK to the POS terminal, wherein the full POS connection terminal key.
[0004] In turn to prevent leakage key risk, a downloading terminal main key flowing control unit is the administrative center's safety machine room, a manual centralized downloading terminal main key. Devices with the maintenance central machine room the load is large; The device for separating the device, and lower is connected to deploy the merchant to the administrative safety central machine room and key, a charging and rises; Centralized for taking off costume key, a lower the magnetism manpower and work position, the maintenance cost is big, and cycle long and problems.
invention content
[0005] For solving is an problems, a technical solution of the invention is used:
[0006] The terminal main key TMK safety downloading method, comprises steps: S1 and system KMS call hardware encryption device of generate key Pu and private key Pr, respectively Pu key to POS terminal password keyboard, aS2 and POS terminal transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu; and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK; aS3 and KMS system call hardware encryption device using private key Pr deciphers transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key; AUKS4 and KMS system and POS terminal using transmission authentication key AUK and mutual authentication, and authentication is KMS, system and call hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK of the main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal; The S5 and P0S terminal receiving KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphers main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard.
[0007] The technical solution the invention claims an, a terminal main key TMK safety downloading system, comprising a KMS system, and KMS communication system is connected with POS terminal, and hardware encryption device; The POS terminal and mutual authentication a module comprises a TK generate module and decryption module, the KMS system comprises male private generate key module and TK receiving module, encryption module and mutual authentication current module; The male private generate key module is used to transfer hardware encryption device of generate key Pu and a private key Pr, respectively Pu key to POS terminal password keyboard, aThe TK generate module is used to transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu; and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK; aThe TK receiving module is used; when received transmitting key scrambled message Ctk_Pu, transferred hardware encryption device using private key Pr to a transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key; AUKThe mutual authentication a module and a mutual authentication current module is used in KMS system POS front end of TMK, using transmission authentication key AUK disposed on the KMS system and a mutual authentication between POS terminals; The encryption module are provided, which comprises a mutual authentication function, wherein hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK to generate main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal; The decryption module are provided, wherein after the POS terminal received the KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphered main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard.
[0008] The beneficial effects of this invention is: The invention is POS terminal uploaded transmitting key TK, comprising TK encryption terminal main key TMK downloads, wherein a realizes POS terminal remote downloading terminal main key TMK, exempts and charging and costs of KMS system for maintaining central machine room and a method and terminal main key TMK centralized downloading with branches. Further, the transmitting key TK and mutual authentication through AUK comprising a transmission authentication key AUK and encryption transmitting key TEK, POS terminal and KMS system, and authentication is; KMS system using TEK encryption terminal main key TMK rear-drive output to the POS terminal, wherein winding of the POS terminal KMS system legal, authentication realizing TMK safety download from the legitimate system KMS to the legitimate POS terminal.
brief description fo the drawings
[0009] Digital 1 is the invention embodiment the terminal main key TMK safety method for flow method, image
[0010] Digital 2) is mutual authentication a module structure, diagram
[0011] Digital 3 is a mutual authentication current module structure, diagram
[0012] Digital 4 is the invention embodiment a terminal main key TMK safety system downloads structure diagram.
[0013] Key unit: nomenclature
[0014] 10 =POS Terminals; 20 =KMS; System30: Hardware encryption device; : 101 TK generate module; 102: A module; 103: Mutual authentication a module; 201: Male private generate key module; : 202 TK receiving module; 203: Encrypting module; 204: Mutual authentication current module; 1031: First power of any of unit; 1032: The first data receiving and transmitting unit; 1033: First added deciphers unit; 1034: The charging unit; 2041: The second power of any of unit; 2042: The second data receiving and transmitting unit; 2043 The second added deciphers unit; 2044: The charging unit.
Performing is specifically
[0015] To explain detail the invention the technical content and structure, wherein of as and transistor, the following and coprocessing the auxiliary digital detailed to show the light of the embodiment.
[0016]Firstly, and key terminology the invention relates to a abbreviation time is defined and explain:
[0017] Abbreviation of AUK Authentication Key, namely authentication key, and mutual authentication key and managing system for KMS; PINPAD
[0018] CA: centreSo-called CA (Is Upper-stage centre), which is a metering with PKI Base (KeyInfrastructure) respectively key infrastructure method, providing network identity certification service special, a takes for signing and issuing and managing the digital certificates, and authoritative and fairness third-party trust mechanism, wherein a distribution credential to our true life of the connector; and passport handling, mechanism
[0019] Abbreviation of HSM: a High Safety Machine, high safety device, wherein system for hardware encryption device;
[0020] The abbreviation of MAK: Mac Key, wherein the RECEIVED calculation key, negotiating determining 24 bytes symmetrical keys with the user, and KMS system TK MAC value calculation between the MTMS; system
[0021] MTMS: The integrally-mounted title Material Tracking Management System, the backward management system, comprising generating at factory using the;
[0022] KMS: systemKey Management System, key management system, for office terminal main key; TMK
[0023] The abbreviation of PIK: Pin Key, wherein the Pin encryption key, comprising an operating key;
[0024] PINPAD: Password, keyboard
[0025] The abbreviation of PK =Protect Key, namely protecting key, negotiating confirm with the user, 24 bytes symmetrical keys. and KMS TK encryption transmission between MTMS/TCS;
[0026] Abbreviation of POS =Point Of Sale, namely pin terminal
[0027] SNpinpad: In series value of the password keyboard, PINPAD is externally, a POS terminal serial number of SNpos to;
[0028] SN: The serial number of pay terminal;
[0029] Abbreviation of TEK transmission Encrypt Key, wherein the encryption key, 24 bytes symmetrical keys, and a management system KMS TMK encryption transmission between PINPAD;
[0030] Abbreviation of TK transmitting Key, namely transmitting key. Transmitting key of encrypted transmitting key TEK and mutual authentication key AUK ring;
[0031] Abbreviation of TMS: Terminal Management System, namely terminal management system, a completing secret communication terminal information management, software and parameter configuration, remote downloading terminal and running state collecting of information management unit, and diagnosing other; functions
[0032] Abbreviation of TMK: Terminal Main Key, namely terminal main key, a paying terminal and pay receiving system for encrypting transmission of the key;
[0033] Safety: chamberWith a high safety rank, a storing unit room, a manometer needed the state to authenticate, which is in.
[0034] intelligent IC card: For CPU, an integrated - circuit of card a central processor CPU and ROM programmable READ-ONLY and random memory RAM and curing operating system C0S Chip (OperatingSystem) is clamped in the non-erasable memory ROM, wherein the clamping the data is divided into an external and internal processing component.
[0035] symmetrical key: The sending and receiving data two sides flowing using the different key in the encryption and decryption the operation to the determining and commands. Symmetrical key encryption algorithm mainly comprising: DES, 3DES, IDEA and FEAL, BLOffFISH equal.
[0036] Asymmetric key: The asymmetrical encryption algorithm lower two switches: Public key (private key Of key) and private key (key of Private key). The common key and a private key and a pair; and encrypts the data in the key base, only and a decryption with the corresponding private key; A encrypts the data with a private key, and is of with the corresponding public key. Are configured encryption and decryption using are different keys, therefore the algorithm of called asymmetrical encryption algorithm. The asymmetrical encryption algorithm for realizing processing unit of confidential exchange information is: The first party generating a pair of key and is a common to other ends and public key; Obtaining public key second party using key on the confidential information and encryption and output to the first party; The first party deciphers with the special key of encrypted information according oneself balanced a. The first party of using the second base party's key on the confidential information and encryption and output to the third party; The third party deciphers with for private spoon's of encrypted information and. The main algorithm with RSA, Elgamal and knapsack algorithm, Rabin, D-H and ECC (oval curve encryption) algorithm.
[0037] RSA: A non key algorithm. RSA public key encryption algorithm is one of 1977 Ron Rivest, AdiShamirh and Len Adleman in (Massachusetts claims of thunder) and. RSA are methods three's the back from and. RSA is in a layer of influential key encryption algorithm, wherein the energy counteract in a known are cryptoattacks, associated with a ISO recommendation is a common key data encrypting standard. RSA algorithm based on a very simple theory of numbers fact: Very easily two large prime of multiplications. The RSA algorithm first is a pulse is used to encrypt and digital signature algorithm, easily to understand and operation. RSA is studied the most widespread public key algorithm, thereby to improve image present's more than 30 years, experienced the testing of each of attacks, receiving for people gradually, generally according thinks is in a one of multiple outstanding public key machine.
[0038] TDES Triple-DES: DES is a symmetrical encryption algorithm, the key is 8 bytes. TDES based on for encrypting algorithm of DES, wherein key of bytes 16 or 24 bytes. TDES/3DES is English TripleDES (abbreviation i.e. triple data encrypting standard), DES is English Data Encrypting Standard (of encrypted standard) abbreviation. DES is a key are encryption algorithm, namely data encrypting key and a key different encryption algorithm. DES of IBM Corporation the 1970s and base, is the government using, and National local of Standards and The National Standard Associated (ANSI) acknowledgment. TDES/3DES is one way of DES encryption algorithm, wherein using 3 to 64 and buttons are three encrypting method based on to the data. Is DES the deformation of safety.
[0039] Is an problems in solving background process, comprising a terminal main key TMK safety downloading system, comprising a KMS system 20, KMS system and 20 are connected with POS terminal 10, and hardware encryption device, 30The POS 10 terminal comprises a TK generate 101 module, a modules 102 and mutual authentication a module, 103
[0040] The KMS 20 system comprises a male private key module generate 201, TK receiving module 202, encryption module 203 and a mutual authentication current module 204, the
[0041] The male private key generate 201 module is used to transfer hardware encryption device of generate key Pu and a private key Pr, respectively Pu key to POS terminal 10 keyboards intervals; the
[0042] The TK generate 101 module is used to transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu; and transmitting key scrambled message sending Ctk_Pu to the KMS system 20, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK; a
[0043] The TK receiving module (202) are provided, which received transmitting key scrambled message Ctk_Pu, transferred hardware encryption device 30 using private keys Pr to a transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key; AUK
[0044] The mutual authentication to 103 and 204 are provided with a mutual authentication current module; the KMS system (20) is 10 TMK front POS terminal, using transmission authentication key AUK disposed on the KMS system 20 and POS terminal 10 between mutual authentication;
[0045] The encryption module (203) are provided, which comprises a mutual authentication function, wherein hardware encryption device 30 using encryption transmitting key TEK encryption terminal main key TMK to generate main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal 10, the
[0046] The decryption module (102) are provided, wherein after the POS terminal 10 received the KMS 20 system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphered main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard.
[0047] , Wherein POS terminal 10 farther comprising of the key modules;
[0048] The common the key module is used for terminal are connected SN and public key download request from the KMS system, 20The male private generate key module are provided, wherein after the common key download request, transferred hardware encryption device 30 generate of Pus key and a private keys, Pr public key Pu to output terminal of the SN corresponding POS terminal 10 keyboards password.
[0049] Connected with the common key module applied to the KMS system 20 know according to the KMS system 20 output terminal main key downloading requests the flowing electrically connected with the POS terminal 10 output of keys, the portable terminal POS 10 20 transmitting and receiving the common key on the KMS system.
[0050] , Wherein POS terminal 10 farther comprising TMK acknowledge receiving module;
[0051] The TMK acknowledge receiving module is used, wherein the back decryption module success storage the terminal main key TMK, a KMS system of acknowledge 20 success receiving terminal main key TMK information.
[0052] With the TMK acknowledge receiving module makes the KMS system 20 to know main key according TK clearly the top exited whether 10) is held in the POS terminal, wherein the KMS 20 system based on main key TMK ends of the TMK receiving module of acknowledge the acknowledge message judgement for exited, a side metallic and system KMS 20 pairs a on the TMK further operation, to a light TMK equal.
[0053] , Wherein a module 102 farther comprising TMK cutting storage module;
[0054] The back TMK cutting storage module is used TMK end of the cutting and a switching TMK to separately installed on the password different keyboard key area.
[0055] The TMK cutting storage device switching terminal main key TMK, and according to one of multiple storage the password different keyboard key area; when needed using TMK pressed to the order to TMK withdraw from the button areas the part and a synthesizing TMK. Therefore with the TMK cutting storage device for TMK is stolen the TMK improves safety device of the POS terminal.
[0056] , Wherein mutual authentication a module (103) comprises a first power of any of unit 1031, wherein the first data receiving and transmitting unit (1032), a added to the decryption unit 1033 and a first charging unit, 1034
[0057] The mutual authentication B 204 module comprises a second power of any of unit 2041, the data receiving and transmitting unit (2042), and is added decryption unit 2043 and a second charging unit 2044, the
[0058] First power of any of unit 1031 is used for generate first any of Rndl; The first data receiving and transmitting unit 1032 is used for generate first any of Rndl output to the KMS system, 20The second data receiving and transmitting unit (2042) are used to the first any of Rndl; The second power of any of unit 2041 is used for receiving first any of Rndl, generate to the second; Rnd2The second added deciphers unit 2043 is used for receiving the first any of Rndl, wherein hardware encryption device 30 using transmission authentication key AUK encryption first any of Rndl to obtain the first any of message scrambled, CrndlThe second data receiving and transmitting unit are 2042 first made of any scrambled message Crndl and second any of Rnd2 output to the POS terminal 10, the
[0059] First added deciphers unit 1033 is used for receiving the first any of scrambled message Crndl and second any of Rnd2, a random of scrambled message Crndl for using transmission authentication key AUK for obtaining third any of Rndl' Wherein the first unit and 1034 are used for judgement third any of Rndl” and first any of Rndl; the same
[0060] First added deciphers unit (1033) are provided, when the first charging unit and third any of Rndl'与 first any of Rndl — time, using transmission authentication key AUK encrypted second any of Rnd2 to generate second any of message scrambled, Crnd2The first data receiving and transmitting unit (1032) and uses a second any of scrambled message sending Crnd2 to the KMS system, 20
[0061] The second added deciphers unit 2043 is used for receiving and emitting to scrambled message Crnd2, wherein the number of scrambled message Crnd2 of the hardware encryption device 30 using transmission authentication key AUK a receiving to obtain fourth any of Rnd2', wherein the second unit and 2044 are useful in judgement fourth any of Rnd2'与 the second any of Rnd2 same, and work and fourth and any of Rnd2'与 second any of Rnd2 wherein, when confirmed by the KMS system and a mutual authentication between POS and terminal.
[0062] The invention is POS terminal 10 uploaded transmitting key TK, comprising TK encryption terminal main key TMK downloads, wherein a realizes POS terminal 10 remote downloading terminal main key TMK, exempts and charging and costs of KMS 20 system for maintaining central machine rooms the method and terminal main key TMK centralized downloading with branches. Further, the transmitting key TK 10 to 20 and mutual authentication with the KMS system is AUK comprising a transmission authentication key AUK and encryption transmitting key TEK, POS terminal, and authentication is; KMS system 20 TEK using encryption terminal main key TMK rear-drive output to the POS terminal 10, wherein winding of the POS terminal 10KMS system legal 20, identities of the TMK safety 20 download from the legitimate system KMS to the legitimate POS 10 terminal.
[0063] Please of the digital 2, comprising a invention embodiment terminal main key TMK safety downloading method for flow position, the method comprises the steps:
[0064] System SUKMS call hardware encryption device of generate key Pu and private key Pr, respectively Pu key to POS terminal password keyboard, a
[0065] S2 and POS terminal transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu; and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK; a
[0066] S3 and KMS system call hardware encryption device using private key Pr deciphers transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key; AUK
[0067] S4 and KMS system and POS terminal using transmission authentication key AUK and mutual authentication, and authentication is KMS, system and call hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK of the main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal;
[0068] The S5 and P0S terminal receiving KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphers main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard.
[0069] , The front of the SI farther comprising POS terminal and terminal are connected SN and public key download request from the KMS system, wherein the invention SI concretely is: When the receiving the common key download request, the KMS system call hardware encryption device of generate key Pu and a private Pr key, a common Pu to output terminal of the SN corresponding POS terminal password keyboard.
[0070] Connected with the POS terminal to support according to the KMS system for downloading public key of the KMS system know the flowing electrically connected with the POS terminal for public key, a convenient POS terminal and KMS system for transmitting and receiving the common key.
(0071), Wherein the invention S5 farther comprising POS terminal success storage to the terminal main key TMK backward KMS system of acknowledge success receiving terminal main key TMK information.
[0072] Connected with the POS terminal acknowledge success receiving terminal main key TMK information to enable the KMS system is know main key according TK clearly the top exited there is held in the POS terminal, wherein the KMS system to the main key TMK ends of the TMK receiving module of acknowledge the acknowledge message judgement for exited, the portable KMS system is TMK time further operation, a to output TMK equal.
[0073] , Wherein the S5 the wire is a POS terminal based on cutting and a switching TMK to separate the back of the password keyboard TMK the terminal main key TMK storage battery via the password different keyboard key area.
[0074] Switching terminal main key TMK, and according to one of multiple storage the password different keyboard key area; and lower using TMK according to the order to TMK withdraw from the button areas the part and a synthesizing TMK. Therefore with the TMK cutting storage device for TMK is stolen the TMK improves safety device of the POS terminal.
[0075] , Via a KMS system and POS terminal using transmission authentication key AUK time mutual authentication of comprises the steps:
[0076] POS terminal generate first any of Rndl and first any of Rndl output to the KMS; system
[0077] The KMS system for first any of Rndl, generate to the second Rnd2, wherein hardware encryption device using transmission authentication key AUK encryption first any of Rndl to obtain the first any of scrambled message Crndl, a random of scrambled message Crndl and second any of Rnd2 output to the POS terminal;
[0078] First any of scrambled message Crndl of the POS terminal using transmission authentication key AUK for obtaining third any of Rndl', wherein the third judgement any of Rndl'与 the first any of Rndl: the same
[0079] A third any of Rndl 'a first of any one Rndl, POS terminal using transmission authentication key AUK encrypts second any of Rnd2 to generate second any of scrambled message Crnd2, and second any of scrambled message sending Crnd2 to the KMS; system
[0080] A random of scrambled message Crnd2 of the KMS system call hardware encryption device using transmission authentication key AUK for obtaining fourth any of Rnd2', wherein the judgement fourth any of Rnd2'与 the second any of Rnd2; the same
[0081] A fourth any of Rnd2'与 second any of Rnd2, wherein the KMS system and POS terminal authentication communication.
[0082] The invention, transmitting key TK generate calculating TK initial value; and each time memory, transmission or using TK checking DC transformer TK first value; and each through examining, and using TK. Verifying through TK value can prevent storage device abnormal for storing the data error, determining the key is a correcting.
[0083] The summary, the invention is POS terminal uploaded transmitting key TK, comprising TK encryption terminal main key TMK downloads, wherein a realizes POS terminal remote downloading terminal main key TMK, exempts and charging and costs of KMS system for maintaining central machine room and a method and terminal main key TMK centralized downloading with branches. Further, the opening of enlightened ruler key TMK is a KMS generating system, convenient KMS system while maintaining and managing the main key TMK. The transmitting key TK and mutual authentication through AUK comprising a transmission authentication key AUK and encryption transmitting key TEK, POS terminal and KMS system, a authenticated is; KMS system using TEK encryption terminal main key TMK rear-drive output to the POS terminal, wherein winding of the POS terminal KMS system legal, authentication realizes the TMK safety download from the legitimate system KMS to the legitimate POS terminal.
[0084] The is installed in the embodiment of this invention, therefore limited the invention by means of the patent domain, everything is equivalent structurally or the equivalent DC conversion for the invention on the edges and auxiliary digital content plug, or directly or being of the related an fields indirectly, the likewise comprises the invention range of patent protection.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN106603496A | Cited by | China | Search report |
| WO2018120938A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN108513704A | Cited by | China | Search report |
| CN101425208A | Cites | China | Search report |
| CN101686225A | Cites | China | Search report |
| CN101930644A | Cites | China | Search report |
| CN102013982A | Cites | China | Search report |
| CN103237005A | Cites | China | Search report |
| US6134431A | Cites | United States of America | Search report |
18 priority claims, no other members on record
Priority claims18
| Document | Office | Kind | Date |
|---|---|---|---|
| 201310084397 | China | A | |
| 2013100843972 | China | – | |
| 201310084653 | China | A | |
| 2013100846538 | China | – | |
| 201310084671 | China | A | |
| 2013100846716 | China | – | |
| 201310084673 | China | A | |
| 2013100846735 | China | – | |
| 201310740158 | China | A | |
| 2013100843972 | – | – | – |
| 2013100846538 | – | – | – |
| 2013100846716 | – | – | – |
| 2013100846735 | – | – | – |
| CN20131740158 | – | – | – |
| CN2013184397 | – | – | – |
| CN2013184653 | – | – | – |
| CN2013184671 | – | – | – |
| CN2013184673 | – | – | – |
Numbers
- Publication
- 103716320
- Publication, DOCDB
- 103716320
- Publication, EPODOC
- CN103716320
- Application
- 107401588
- Application, DOCDB
- 201310740158
- Application, EPODOC
- CN201310740158
Titles3
- English
- The terminal main key TMK safety downloading method and system
- Chinese
- 一种终端主密钥TMK安全下载方法及系统
- English
- Security downloading method and system of TMK
Classification
- CPC, 6
- H04L9/321
- G06Q20/20
- H04L9/0825
- G06Q20/3829
- H04L9/083
- H04L63/061
- IPC, 3
- H04L29 06
- H04L9 32
- H04L9 08