CN103716320A

Security downloading method and system of TMK

Abstract

The invention discloses a security downloading method of a TMK. The security downloading method comprises the steps that a KMS produces a public key Pu and a private key Pr, and the public key Pu is sent to a POS terminal; the POS terminal produces a TK, and the TK is encrypted through the public key Pu and sent to the KMS, wherein the TK is composed of a TEK and an AUK; the KMS and the POS terminal use the AUK for conducting bidirectional authentication, and if the KMS and the POS terminal pass through the authentication, the KMS sends the TMK to the POS terminal after using the TEK for encrypting the TMK; after receiving master key ciphertext Ctmk_tk sent by the KMS, the POS terminal uses the TEK for decrypting the master key ciphertext Ctmk_tk to obtain the TMK and stores the TMK in a PIN pad. The security downloading method and system of the TMK have the advantages that the TMK is downloaded remotely by uploading the TK through the POS terminal, the TK comprises the TEK and the AUK, and therefore security downloading of the TMK is guaranteed effectively.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

10 claims: 2 independent, 8 dependent

  1. 1
    1 Terminal main key TMK safety downloading method, comprising a characterised, comprising steps:System SUKMS call hardware encryption device of generate key Pu and private key Pr, respectively Pu key to POS terminal password keyboard, a Nd 52, P0S terminal transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu;and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK;a 53 Rd, the KMS system call hardware encryption device using private key Pr deciphers transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key;AUK 54 Ohm;the KMS system and POS terminal using transmission authentication key AUK and mutual authentication, and authentication is KMS, system and call hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK of the main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal;55 Ohm, wherein the POS terminal receiving KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphers main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard. 1.一种终端主密钥TMK安全下载方法,其特征在于,包括步骤: SUKMS系统调用硬件加密机产生公钥Pu和私钥Pr,将公钥Pu发送至POS终端密码键盘中; 52、P0S终端调用密码键盘随机产生传输密钥TK并使用公钥Pu加密传输密钥TK生成传输密钥密文Ctk_Pu,然后将传输密钥密文Ctk_Pu发送至KMS系统,其中,传输密钥TK由传输加密密钥TEK和传输认证密钥AUK构成; 53、KMS系统调用硬件加密机使用私钥Pr解密传输密钥密文Ctk_Pu获得传输加密密钥TEK和传输认证密钥AUK ; 54、KMS系统与POS终端使用传输认证密钥AUK进行双向认证,如果认证通过,KMS系统调用硬件加密机使用传输加密密钥TEK加密终端主密钥TMK生成主密钥密文Ctmk_tk并将主密钥密文发送至POS终端; 55、POS终端接收到KMS系统发送的主密钥密文Ctmk_tk后使用传输加密密钥TEK解密主密钥密文Ctmk_tk获得终端主密钥TMK并将终端主密钥TMK存储在密码键盘中。
  2. 6
    1 Terminal main key TMK safety downloading system, comprising a characterised, comprising a KMS system, and KMS communication system is connected with POS terminal, and hardware encryption device;The POS terminal and mutual authentication a module comprises a TK generate module and decryption module, the KMS system comprises male private generate key module and TK receiving module, encryption module and mutual authentication current module;The male private generate key module is used to transfer hardware encryption device of generate key Pu and a private key Pr, respectively Pu key to POS terminal password keyboard, a The TK generate module is used to transfer password keyboard random generate transmitting key TK and using public key Pu encryption transmitting key TK for transmitting key scrambled message Ctk_Pu;and transmitting key scrambled message sending Ctk_Pu to the KMS, system, transmitting key TK of encrypted transmitting key TEK transmission and authentication key AUK;a The TK receiving module is used;when received transmitting key scrambled message Ctk_Pu, transferred hardware encryption device using private key Pr to a transmitting key scrambled message Ctk_Pu to obtain encryption transmitting key TEK transmission and authentication key;AUK The mutual authentication a module and a mutual authentication current module is used in KMS system POS front end of TMK, using transmission authentication key AUK disposed on the KMS system and a mutual authentication between POS terminals;The encryption module are provided, which comprises a mutual authentication function, wherein hardware encryption device using encryption transmitting key TEK encryption terminal main key TMK to generate main key scrambled message Ctmk_tk and a advocate the key scrambled message from a POS terminal;The decryption module are provided, wherein after the POS terminal received the KMS system for main key scrambled message Ctmk_tk, using encryption transmitting key TEK deciphered main key scrambled message Ctmk_tk to obtain terminal main key TMK and terminal main key TMK storage the password keyboard. 6.一种终端主密钥TMK安全下载系统,其特征在于,包括KMS系统、与KMS系统通信连接的POS终端、以及硬件加密机;所述POS终端包括TK产生模块、解密模块以及双向认证A模块,所述KMS系统包括公私钥产生模块、TK接收模块、加密模块以及双向认证B模块; 所述公私钥产生模块用于调用硬件加密机产生公钥Pu和私钥Pr,将公钥Pu发送至POS终端密码键盘中; 所述TK产生模块用于调用密码键盘随机产生传输密钥TK并使用公钥Pu加密传输密钥TK生成传输密钥密文Ctk_Pu,然后将传输密钥密文Ctk_Pu发送至KMS系统,其中,传输密钥TK由传输加密密钥TEK和传输认证密钥AUK构成; 所述TK接收模块用于当接收到传输密钥密文Ctk_Pu时,调用硬件加密机使用私钥Pr解密传输密钥密文Ctk_Pu获得传输加密密钥TEK和传输认证密钥AUK ; 所述双向认证A模块与双向认证B模块用于在KMS系统向POS终端传送TMK之前,使用传输认证密钥AUK进行KMS系统与POS终端之间的双向认证; 所述加密模块用于当双向认证通过后,调用硬件加密机使用传输加密密钥TEK加密终端主密钥TMK生成主密钥密文Ctmk_tk并将主密钥密文发送至POS终端; 所述解密模块用于当POS终端接收到KMS系统发送的主密钥密文Ctmk_tk后,使用传输加密密钥TEK解密主密钥密文Ctmk_tk获得终端主密钥TMK并将终端主密钥TMK存储在密码键盘中。