CN104346723B - Security information interaction system, device and method - Google Patents
Security information interaction system, device and method Download PDFInfo
- Publication number
- CN104346723B CN104346723B CN201310324181.9A CN201310324181A CN104346723B CN 104346723 B CN104346723 B CN 104346723B CN 201310324181 A CN201310324181 A CN 201310324181A CN 104346723 B CN104346723 B CN 104346723B
- Authority
- CN
- China
- Prior art keywords
- information interaction
- safety information
- interaction request
- access code
- security information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Computer Security & Cryptography (AREA)
- Finance (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Telephonic Communication Services (AREA)
Abstract
本发明提出了安全性信息交互系统、设备和方法,所述方法包括:安全性信息交互终端基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器;数据处理服务器在判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。本发明所公开的安全性信息交互系统、设备和方法具有高的安全性。
The present invention proposes a security information interaction system, device and method. The method includes: a security information interaction terminal constructs a security information interaction request based on user instructions and determines to interact with the security information according to the security information interaction request. Requesting the associated access number, and then dialing the determined access number to transmit the security information interaction request to the data processing server in the form of a data message; An alarm message is generated when the actual access number of the security information interaction request is different from the access number associated with the security information interaction request determined by the security information interaction terminal. The safety information interaction system, device and method disclosed in the invention have high safety.
Description
技术领域technical field
本发明涉及信息交互系统、设备及方法,更具体地,涉及安全性信息交互系统、设备及方法。The present invention relates to an information interaction system, equipment and method, and more specifically, to a security information interaction system, equipment and method.
背景技术Background technique
目前,随着计算机和网络应用的日益广泛以及不同领域的业务种类的日益丰富,用于安全性信息交互(即对安全性要求较高的信息交互,例如金融领域中的交易处理过程)的系统、设备和方法变得越来越重要。At present, with the increasingly wide application of computers and networks and the increasing variety of businesses in different fields, systems for security information interaction (that is, information interaction with high security requirements, such as transaction processing in the financial field) , equipment and methods are becoming more and more important.
现有的技术方案的基本工作过程如下:安全性信息交互终端(例如POS机)基于用户指令构造安全性信息交互请求,并随后拨打与数据处理服务器(例如金融领域中的交易受理接入设备)相关联的接入号码以将所述安全性信息交互请求传送到数据处理服务器,从而完成后续的安全性信息交互过程。The basic working process of the existing technical solutions is as follows: a security information interaction terminal (such as a POS machine) constructs a security information interaction request based on user instructions, and then dials a data processing server (such as a transaction acceptance access device in the financial field) The associated access number is used to transmit the security information interaction request to the data processing server, so as to complete the subsequent security information interaction process.
然而,现有的技术方案存在如下问题:安全性信息交互终端可能会被异地非法使用,从而导致潜在的安全隐患,为了避免该情况的发生,当前通常采用对安全性信息交互终端所拨打的接入号码进行监控以发现上述非法使用情况的发生,然而,该方式存在如下问题:非法使用者可以通过截拨器和转拨器规避监控,例如,已移机(即异地)的安全性信息交互终端在拨打接入号码时,被设置在该安全性信息交互终端和电话网络之间的截拨器将接入请求转发到位于该安全性信息交互终端的原始注册地的转拨器,所述转拨器随后通过拨打该安全性信息交互终端的原始接入号码而将接入请求传送到与该原始接入号码相关联的数据处理服务器,由此规避对接入号码的监控。However, the existing technical solutions have the following problems: the security information interaction terminal may be illegally used in different places, resulting in potential security risks. However, this method has the following problems: illegal users can avoid monitoring through interceptors and diverters, for example, the security information exchange of mobile phones (that is, remote places) When the terminal dials the access number, the dialer set between the security information interaction terminal and the telephone network forwards the access request to the dialer located at the original registration place of the security information interaction terminal, the The diverter then transmits the access request to the data processing server associated with the original access number by dialing the original access number of the security information interaction terminal, thereby avoiding the monitoring of the access number.
因此,存在如下需求:提供具有高的安全性并且能够防止安全性信息交互终端的异地非法使用的安全性信息交互系统、设备及方法。Therefore, there is a need to provide a security information interaction system, device and method that have high security and can prevent illegal use of security information interaction terminals in different places.
发明内容Contents of the invention
为了解决上述现有技术方案所存在的问题,本发明提出了具有高的安全性并且能够防止安全性信息交互终端的异地非法使用的安全性信息交互系统、设备及方法。In order to solve the problems in the above prior art solutions, the present invention proposes a security information interaction system, device and method that have high security and can prevent illegal use of security information interaction terminals in different places.
本发明的目的是通过以下技术方案实现的:The purpose of the present invention is achieved through the following technical solutions:
一种安全性信息交互系统,所述安全性信息交互系统包括:A security information interaction system, the security information interaction system comprising:
安全性信息交互终端,所述安全性信息交互终端基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据;A security information interaction terminal, wherein the security information interaction terminal constructs a security information interaction request based on a user instruction and determines an access number associated with the security information interaction request according to the security information interaction request, and then dials The determined access number is used to transmit the security information interaction request to the data processing server in the form of a data packet, wherein the data packet includes the security information interaction request and the determined An access number associated with a security information interaction request, and the security information interaction request includes data associated with the security information interaction to be processed;
数据处理服务器,所述数据处理服务器解析接收到的数据报文以得到与所述安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。a data processing server, the data processing server parses the received data message to obtain the access number associated with the security information interaction request, and determines the actual access number used to transmit the security information interaction request Whether the number is the same as the access number associated with the security information interaction request determined by the security information interaction terminal, and when it is determined that the actual access number used to transmit the security information interaction request is the same as An alarm message is generated when the access numbers associated with the security information interaction request determined by the security information interaction terminal are different.
在上面所公开的方案中,优选地,所述安全性信息交互终端进一步包括:In the solution disclosed above, preferably, the security information interaction terminal further includes:
主控制器,所述主控制器基于用户指令构造安全性信息交互请求并向接入号码确定单元发送接入号码确定指令,以及在接收到所述接入号码确定单元传送回的接入号码后拨打所确定的接入号码以将所述安全性信息交互请求传送到数据处理服务器;a main controller, the main controller constructs a security information interaction request based on a user instruction and sends an access number determination instruction to the access number determination unit, and after receiving the access number sent back by the access number determination unit Dial the determined access number to transmit the security information interaction request to the data processing server;
接入号码确定单元,所述接入号码确定单元在接收到所述接入号码确定指令后根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,并将所确定的接入号码传送回所述主控制器。an access number determining unit, the access number determining unit determines the access number associated with the security information interaction request according to the security information interaction request after receiving the access number determination instruction, and The determined access number is communicated back to the master controller.
在上面所公开的方案中,优选地,所述接入号码确定单元以如下方式确定与所述安全性信息交互请求相关联的接入号码:(1)从所述安全性信息交互请求中提取与待处理的安全性信息交互相关联的数据的一部分并将其转换成连续的数字字符串;(2)使用预定的字符变换表对所述数字字符串进行变换;(3)将变换后的数字字符串进行移位操作;(4)基于移位后的数字字符串确定与所述安全性信息交互请求相关联的接入号码。In the solutions disclosed above, preferably, the access number determining unit determines the access number associated with the security information interaction request in the following manner: (1) extracting from the security information interaction request Part of the data associated with the security information interaction to be processed and converted into a continuous string of numbers; (2) Transform the string of numbers using a predetermined character conversion table; (3) Convert the converted performing a shift operation on the digital string; (4) determining the access number associated with the security information interaction request based on the shifted digital string.
在上面所公开的方案中,优选地,所述预定的字符变换表定义每个数字字符与变换字符之间的一一对应关系,并且其中,每个变换字符均不相同。In the solutions disclosed above, preferably, the predetermined character conversion table defines a one-to-one correspondence between each numeric character and the converted character, and wherein each converted character is different.
在上面所公开的方案中,优选地,所述接入号码确定单元存储预先设定的三个接入号码,并且以如下方式基于移位后的数字字符串随机地确定与所述安全性信息交互请求相关联的接入号码:对移位后的数字字符串所表示的数值进行模3运算,如果运算结果为0,则将第一接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为1,则将第二接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为2,则将第三接入号码确定为与所述安全性信息交互请求相关联的接入号码。In the solution disclosed above, preferably, the access number determining unit stores three preset access numbers, and randomly determines the number of access numbers related to the security information based on the shifted digital string in the following manner: The access number associated with the interaction request: perform a modulo 3 operation on the value represented by the shifted number string, and if the operation result is 0, determine the first access number as related to the security information interaction request If the operation result is 1, determine the second access number as the access number associated with the security information interaction request; if the operation result is 2, determine the third access number is the access number associated with the security information interaction request.
在上面所公开的方案中,优选地,所述主控制器以如下方式将所述安全性信息交互请求传送到所述数据处理服务器:(1)将所确定的接入号码和与待处理的安全性信息交互相关联的数据的一部分相连接以形成字符串;(2)将所述字符串加密;(3)构造包含经加密的字符串以及所述安全性信息交互请求的数据报文,并将所述数据报文传送到所述数据处理服务器。In the solution disclosed above, preferably, the main controller transmits the security information interaction request to the data processing server in the following manner: (1) combining the determined access number with the pending Connecting a part of the data associated with the security information exchange to form a character string; (2) encrypting the character string; (3) constructing a data message including the encrypted character string and the security information exchange request, And transmit the data packet to the data processing server.
在上面所公开的方案中,优选地,所述数据处理服务器在接收到所述数据报文后解密所述经加密的字符串以获取由安全性信息交互终端确定的接入号码,并将所述由安全性信息交互终端确定的接入号码与用于传送所述数据报文的实际的接入号码相比较,并且如果由安全性信息交互终端确定的接入号码与用于传送所述数据报文的实际的接入号码不相同,则产生告警信息。In the solutions disclosed above, preferably, after receiving the data message, the data processing server decrypts the encrypted character string to obtain the access number determined by the security information interaction terminal, and sends the The access number determined by the security information interaction terminal is compared with the actual access number used to transmit the data message, and if the access number determined by the security information interaction terminal is the same as the access number used to transmit the data message If the actual access numbers of the message are different, an alarm message will be generated.
本发明的目的也可以通过以下技术方案实现:The purpose of the present invention can also be achieved through the following technical solutions:
一种安全性信息交互终端,所述安全性信息交互终端能够基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据。A security information interaction terminal, wherein the security information interaction terminal is capable of constructing a security information interaction request based on a user instruction and determining an access number associated with the security information interaction request according to the security information interaction request, and then dialing the determined access number to transmit the security information interaction request to the data processing server in the form of a data message, wherein the data message includes the security information interaction request and the determined and The security information interaction request is associated with an access number, and the security information interaction request includes data associated with the security information interaction to be processed.
本发明的目的也可以通过以下技术方案实现:The purpose of the present invention can also be achieved through the following technical solutions:
一种数据处理服务器,所述数据处理服务器能够解析接收到的来自安全性信息交互终端的数据报文以得到与安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。A data processing server, the data processing server can analyze the received data message from the security information interaction terminal to obtain the access number associated with the security information interaction request, and determine the Whether the actual access number of the information interaction request is the same as the access number associated with the security information interaction request determined by the security information interaction terminal, and when it is determined that the access number used to transmit the security information interaction An alarm message is generated when the actual requested access number is different from the access number associated with the security information interaction request determined by the security information interaction terminal.
本发明的目的也可以通过以下技术方案实现:The purpose of the present invention can also be achieved through the following technical solutions:
一种安全性信息交互方法,所述方法包括下列步骤:A safety information interaction method, said method comprising the following steps:
(A1)安全性信息交互终端基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据;(A1) The security information interaction terminal constructs a security information interaction request based on user instructions, determines an access number associated with the security information interaction request according to the security information interaction request, and then dials the determined access number number to transmit the security information interaction request to the data processing server in the form of a data packet, wherein the data packet includes the security information interaction request and the determined information related to the security information interaction request. connected access number, and the security information interaction request includes data associated with the security information interaction to be processed;
(A2)所述数据处理服务器解析接收到的数据报文以得到与所述安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。(A2) The data processing server parses the received data message to obtain the access number associated with the security information interaction request, and determines the actual access number used to transmit the security information interaction request whether it is the same as the access number associated with the security information interaction request determined by the security information interaction terminal, and when it is determined that the actual access number used to transmit the security information interaction request An alarm message is generated when the access numbers determined by the security information interaction terminal and associated with the security information interaction request are different.
本发明所公开的安全性信息交互系统、设备和方法具有下列优点:由于能够及时地发现安全性信息交互终端是否存在正在被异地非法使用的可能,故具有显著提高的安全性。The security information interaction system, device and method disclosed in the present invention have the following advantages: since it is possible to find in time whether the security information interaction terminal is being illegally used in a different place, it has significantly improved security.
附图说明Description of drawings
结合附图,本发明的技术特征以及优点将会被本领域技术人员更好地理解,其中:With reference to the accompanying drawings, the technical features and advantages of the present invention will be better understood by those skilled in the art, wherein:
图1是根据本发明的实施例的安全性信息交互系统的示意性结构图;FIG. 1 is a schematic structural diagram of a security information interaction system according to an embodiment of the present invention;
图2是根据本发明的实施例的安全性信息交互方法的流程图。Fig. 2 is a flowchart of a security information interaction method according to an embodiment of the present invention.
具体实施方式Detailed ways
图1是根据本发明的实施例的安全性信息交互系统的示意性结构图。如图1所示,本发明所公开的安全性信息交互系统包括安全性信息交互终端1和数据处理服务器2。其中,所述安全性信息交互终端1基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器2,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据(例如金融领域中的交易信息)。所述数据处理服务器2解析接收到的数据报文以得到与所述安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端1确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端1确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。Fig. 1 is a schematic structural diagram of a security information interaction system according to an embodiment of the present invention. As shown in FIG. 1 , the security information interaction system disclosed in the present invention includes a security information interaction terminal 1 and a data processing server 2 . Wherein, the security information interaction terminal 1 constructs a security information interaction request based on user instructions, determines an access number associated with the security information interaction request according to the security information interaction request, and then dials the determined Access the number to transmit the security information interaction request to the data processing server 2 in the form of a data message, wherein the data message includes the security information interaction request and the determined The interaction requests an associated access number, and the security information interaction request includes data associated with the security information interaction to be processed (for example, transaction information in the financial field). The data processing server 2 parses the received data message to obtain the access number associated with the security information interaction request, and judges whether the actual access number used to transmit the security information interaction request is consistent with The access number associated with the security information interaction request determined by the security information interaction terminal 1 is the same, and when it is determined that the actual access number used to transmit the security information interaction request is the same as the access number associated with the security information interaction request An alarm message is generated when the access numbers associated with the security information interaction request determined by the security information interaction terminal 1 are different.
优选地,在本发明所公开的安全性信息交互系统中,所述安全性信息交互终端1进一步包括主控制器3和接入号码确定单元4。其中,所述主控制器3基于用户指令构造安全性信息交互请求并向接入号码确定单元4发送接入号码确定指令,以及在接收到所述接入号码确定单元4传送回的接入号码后拨打所确定的接入号码以将所述安全性信息交互请求传送到数据处理服务器2。所述接入号码确定单元4在接收到所述接入号码确定指令后根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,并将所确定的接入号码传送回所述主控制器3。Preferably, in the security information interaction system disclosed in the present invention, the security information interaction terminal 1 further includes a main controller 3 and an access number determination unit 4 . Wherein, the main controller 3 constructs a security information interaction request based on a user instruction and sends an access number determination instruction to the access number determination unit 4, and upon receiving the access number determination unit 4 sent back Then dial the determined access number to transmit the security information interaction request to the data processing server 2 . The access number determination unit 4 determines the access number associated with the security information interaction request according to the security information interaction request after receiving the access number determination instruction, and sends the determined access number to The number is sent back to the master controller 3.
优选地,在本发明所公开的安全性信息交互系统中,所述接入号码确定单元4以如下方式确定与所述安全性信息交互请求相关联的接入号码:(1)从所述安全性信息交互请求中提取与待处理的安全性信息交互相关联的数据的一部分(例如交易卡号的后4位以及交易时间的后4位)并将其转换成连续的数字字符串(例如将交易卡号的后4位以及交易时间的后4位链接成为一个数字字符串);(2)使用预定的字符变换表对所述数字字符串进行变换;(3)将变换后的数字字符串进行移位操作(例如将字符串末位移至字符串首位);(4)基于移位后的数字字符串确定与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction system disclosed in the present invention, the access number determination unit 4 determines the access number associated with the security information interaction request in the following manner: (1) from the security Extract part of the data associated with the security information interaction to be processed (such as the last 4 digits of the transaction card number and the last 4 digits of the transaction time) from the security information interaction request and convert it into a continuous digital string (such as the transaction The last 4 digits of the card number and the last 4 digits of the transaction time are linked to form a digital string); (2) Use the predetermined character conversion table to convert the digital string; (3) Shift the converted digital string Bit operation (for example, shifting the end of the character string to the first character of the character string); (4) determining the access number associated with the security information interaction request based on the shifted number character string.
优选地,在本发明所公开的安全性信息交互系统中,所述预定的字符变换表定义每个数字字符与变换字符之间的一一对应关系(例如,数字字符0对应的变换字符为3,数字字符2对应的变换字符为7等等),并且其中,每个变换字符均不相同。Preferably, in the security information interaction system disclosed in the present invention, the predetermined character conversion table defines a one-to-one correspondence between each numeric character and the converted character (for example, the converted character corresponding to the numeric character 0 is 3 , the transformation character corresponding to the number character 2 is 7, etc.), and wherein each transformation character is different.
优选地,在本发明所公开的安全性信息交互系统中,所述接入号码确定单元4存储预先设定的三个接入号码,并且以如下方式基于移位后的数字字符串随机地确定与所述安全性信息交互请求相关联的接入号码:对移位后的数字字符串所表示的数值进行模3运算(即除以3取余数),如果运算结果为0,则将第一接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为1,则将第二接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为2,则将第三接入号码确定为与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction system disclosed in the present invention, the access number determining unit 4 stores three pre-set access numbers, and randomly determines based on the shifted digital string in the following manner The access number associated with the security information interaction request: perform a modulo 3 operation on the value represented by the shifted number string (that is, divide by 3 to obtain a remainder), and if the operation result is 0, the first determining the access number as the access number associated with the security information interaction request, and if the operation result is 1, determining the second access number as the access number associated with the security information interaction request, If the calculation result is 2, determine the third access number as the access number associated with the security information interaction request.
优选地,在本发明所公开的安全性信息交互系统中,所述主控制器3以如下方式将所述安全性信息交互请求传送到所述数据处理服务器2:(1)将所确定的接入号码和与待处理的安全性信息交互相关联的数据的一部分(例如交易时间的后4位)相连接以形成字符串;(2)将所述字符串加密;(3)构造包含经加密的字符串以及所述安全性信息交互请求的数据报文,并将所述数据报文传送到所述数据处理服务器2。Preferably, in the security information interaction system disclosed in the present invention, the main controller 3 transmits the security information interaction request to the data processing server 2 in the following manner: (1) the determined interface (2) Encrypt the string; (3) Construct a string containing the encrypted character string and the data packet of the security information interaction request, and transmit the data packet to the data processing server 2.
优选地,在本发明所公开的安全性信息交互系统中,所述数据处理服务器2在接收到所述数据报文后解密所述经加密的字符串以获取由安全性信息交互终端1确定的接入号码,并将所述由安全性信息交互终端1确定的接入号码与用于传送所述数据报文的实际的接入号码相比较,并且如果由安全性信息交互终端1确定的接入号码与用于传送所述数据报文的实际的接入号码不相同,则产生告警信息(即安全性信息交互终端可能正在被异地非法使用)。Preferably, in the security information interaction system disclosed in the present invention, after receiving the data message, the data processing server 2 decrypts the encrypted character string to obtain the information determined by the security information interaction terminal 1. access number, and compare the access number determined by the security information interaction terminal 1 with the actual access number used to transmit the data message, and if the access number determined by the security information interaction terminal 1 If the access number is different from the actual access number used to transmit the data message, an alarm message will be generated (that is, the security information interaction terminal may be being illegally used in a different place).
由上可见,本发明所公开的安全性信息交互系统具有下列优点:由于能够及时地发现安全性信息交互终端是否存在正在被异地非法使用的可能,故具有显著提高的安全性。It can be seen from the above that the security information interaction system disclosed in the present invention has the following advantages: since it can promptly find out whether the security information interaction terminal is being illegally used in a different place, it has significantly improved security.
如图1所示,本发明公开了一种安全性信息交互终端1,所述安全性信息交互终端1能够基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器2,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据(例如金融领域中的交易信息)。As shown in Fig. 1, the present invention discloses a security information interaction terminal 1, the security information interaction terminal 1 can construct a security information interaction request based on user instructions and determine the An access number associated with the security information interaction request, and then dialing the determined access number to transmit the security information interaction request to the data processing server 2 in the form of a data message, wherein the data message including the security information interaction request and the determined access number associated with the security information interaction request, and the security information interaction request includes data associated with the security information interaction to be processed (such as transaction information in the financial field).
优选地,本发明所公开的安全性信息交互终端进一步包括主控制器3和接入号码确定单元4。其中,所述主控制器3基于用户指令构造安全性信息交互请求并向接入号码确定单元4发送接入号码确定指令,以及在接收到所述接入号码确定单元4传送回的接入号码后拨打所确定的接入号码以将所述安全性信息交互请求传送到数据处理服务器2。所述接入号码确定单元4在接收到所述接入号码确定指令后根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,并将所确定的接入号码传送回所述主控制器3。Preferably, the security information interaction terminal disclosed in the present invention further includes a main controller 3 and an access number determination unit 4 . Wherein, the main controller 3 constructs a security information interaction request based on a user instruction and sends an access number determination instruction to the access number determination unit 4, and upon receiving the access number determination unit 4 sent back Then dial the determined access number to transmit the security information interaction request to the data processing server 2 . The access number determination unit 4 determines the access number associated with the security information interaction request according to the security information interaction request after receiving the access number determination instruction, and sends the determined access number to The number is sent back to the master controller 3.
优选地,在本发明所公开的安全性信息交互终端1中,所述接入号码确定单元4以如下方式确定与所述安全性信息交互请求相关联的接入号码:(1)从所述安全性信息交互请求中提取与待处理的安全性信息交互相关联的数据的一部分(例如交易卡号的后4位以及交易时间的后4位)并将其转换成连续的数字字符串(例如将交易卡号的后4位以及交易时间的后4位链接成为一个数字字符串);(2)使用预定的字符变换表对所述数字字符串进行变换;(3)将变换后的数字字符串进行移位操作(例如将字符串末位移至字符串首位);(4)基于移位后的数字字符串确定与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction terminal 1 disclosed in the present invention, the access number determining unit 4 determines the access number associated with the security information interaction request in the following manner: (1) from the Extract part of the data associated with the security information interaction to be processed (such as the last 4 digits of the transaction card number and the last 4 digits of the transaction time) in the security information interaction request and convert it into a continuous digital string (such as the The last 4 digits of the transaction card number and the last 4 digits of the transaction time are linked into a digital string); (2) use the predetermined character conversion table to convert the digital string; (3) convert the converted digital string A shift operation (for example, shifting the end of the character string to the first character of the character string); (4) determining the access number associated with the security information interaction request based on the shifted number character string.
优选地,在本发明所公开的安全性信息交互终端中,所述预定的字符变换表定义每个数字字符与变换字符之间的一一对应关系(例如,数字字符0对应的变换字符为3,数字字符2对应的变换字符为7等等),并且其中,每个变换字符均不相同。Preferably, in the security information interaction terminal disclosed in the present invention, the predetermined character conversion table defines a one-to-one correspondence between each numeric character and the converted character (for example, the converted character corresponding to the numeric character 0 is 3 , the transformation character corresponding to the number character 2 is 7, etc.), and wherein each transformation character is different.
优选地,在本发明所公开的安全性信息交互终端中,所述接入号码确定单元4存储预先设定的三个接入号码,并且以如下方式基于移位后的数字字符串随机地确定与所述安全性信息交互请求相关联的接入号码:对移位后的数字字符串所表示的数值进行模3运算(即除以3取余数),如果运算结果为0,则将第一接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为1,则将第二接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为2,则将第三接入号码确定为与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction terminal disclosed in the present invention, the access number determining unit 4 stores three preset access numbers, and randomly determines based on the shifted digital string in the following manner The access number associated with the security information interaction request: perform a modulo 3 operation on the value represented by the shifted number string (that is, divide by 3 to obtain a remainder), and if the operation result is 0, the first determining the access number as the access number associated with the security information interaction request, and if the operation result is 1, determining the second access number as the access number associated with the security information interaction request, If the calculation result is 2, determine the third access number as the access number associated with the security information interaction request.
优选地,在本发明所公开的安全性信息交互终端1中,所述主控制器3以如下方式将所述安全性信息交互请求传送到所述数据处理服务器2:(1)将所确定的接入号码和与待处理的安全性信息交互相关联的数据的一部分(例如交易时间的后4位)相连接以形成字符串;(2)将所述字符串加密;(3)构造包含经加密的字符串以及所述安全性信息交互请求的数据报文,并将所述数据报文传送到所述数据处理服务器2。Preferably, in the security information interaction terminal 1 disclosed in the present invention, the main controller 3 transmits the security information interaction request to the data processing server 2 in the following manner: (1) the determined The access number is concatenated with a part of the data associated with the security information interaction to be processed (for example, the last 4 digits of the transaction time) to form a string; (2) encrypt the string; (3) construct a string containing The encrypted character string and the data packet of the security information exchange request, and transmit the data packet to the data processing server 2 .
如图1所示,本发明公开了一种数据处理服务器2,所述数据处理服务器2解析接收到的来自安全性信息交互终端1的数据报文以得到与安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端1确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端1确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息(即安全性信息交互终端可能正在被异地非法使用)。As shown in FIG. 1 , the present invention discloses a data processing server 2. The data processing server 2 parses the received data message from the security information interaction terminal 1 to obtain the interface associated with the security information interaction request. and determine whether the actual access number used to transmit the security information interaction request is the same as the access number associated with the security information interaction request determined by the security information interaction terminal 1, and generated when it is determined that the actual access number used to transmit the security information interaction request is different from the access number associated with the security information interaction request determined by the security information interaction terminal 1 Warning information (that is, the security information interaction terminal may be being illegally used in a different place).
图2是根据本发明的实施例的安全性信息交互方法的流程图。如图2所示,本发明所公开的安全性信息交互方法包括下列步骤:(A1)安全性信息交互终端基于用户指令构造安全性信息交互请求并根据所述安全性信息交互请求确定与所述安全性信息交互请求相关联的接入号码,以及随后拨打所确定的接入号码以将所述安全性信息交互请求以数据报文的形式传送到数据处理服务器,其中,所述数据报文包括所述安全性信息交互请求以及所确定的与所述安全性信息交互请求相关联的接入号码,并且所述安全性信息交互请求包括与待处理的安全性信息交互相关联的数据(例如金融领域中的交易信息);(A2)所述数据处理服务器解析接收到的数据报文以得到与所述安全性信息交互请求相关联的接入号码,并判断用于传送所述安全性信息交互请求的实际的接入号码是否与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码相同,以及当判断出用于传送所述安全性信息交互请求的实际的接入号码与由所述安全性信息交互终端确定的与所述安全性信息交互请求相关联的接入号码不相同时产生告警信息。Fig. 2 is a flowchart of a security information interaction method according to an embodiment of the present invention. As shown in FIG. 2 , the security information interaction method disclosed in the present invention includes the following steps: (A1) The security information interaction terminal constructs a security information interaction request based on user instructions and determines the connection with the security information interaction request according to the security information interaction request. An access number associated with the security information interaction request, and then dialing the determined access number to transmit the security information interaction request to the data processing server in the form of a data message, wherein the data message includes The security information interaction request and the determined access number associated with the security information interaction request, and the security information interaction request includes data associated with the security information interaction to be processed (such as financial transaction information in the field); (A2) the data processing server parses the received data message to obtain the access number associated with the security information interaction request, and determines the access number used to transmit the security information interaction Whether the actual requested access number is the same as the access number associated with the security information interaction request determined by the security information interaction terminal, and when it is determined that the An alarm message is generated when the actual access number is different from the access number associated with the security information interaction request determined by the security information interaction terminal.
优选地,在本发明所公开的安全性信息交互方法中,所述步骤(A1)进一步包括:以如下方式确定与所述安全性信息交互请求相关联的接入号码:(1)从所述安全性信息交互请求中提取与待处理的安全性信息交互相关联的数据的一部分(例如交易卡号的后4位以及交易时间的后4位)并将其转换成连续的数字字符串(例如将交易卡号的后4位以及交易时间的后4位链接成为一个数字字符串);(2)使用预定的字符变换表对所述数字字符串进行变换;(3)将变换后的数字字符串进行移位操作(例如将字符串末位移至字符串首位);(4)基于移位后的数字字符串确定与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction method disclosed in the present invention, the step (A1) further includes: determining the access number associated with the security information interaction request in the following manner: (1) from the Extract part of the data associated with the security information interaction to be processed (such as the last 4 digits of the transaction card number and the last 4 digits of the transaction time) in the security information interaction request and convert it into a continuous digital string (such as the The last 4 digits of the transaction card number and the last 4 digits of the transaction time are linked into a digital string); (2) use the predetermined character conversion table to convert the digital string; (3) convert the converted digital string A shift operation (for example, shifting the end of the character string to the first character of the character string); (4) determining the access number associated with the security information interaction request based on the shifted number character string.
优选地,在本发明所公开的安全性信息交互方法中,所述预定的字符变换表定义每个数字字符与变换字符之间的一一对应关系(例如,数字字符0对应的变换字符为3,数字字符2对应的变换字符为7等等),并且其中,每个变换字符均不相同。Preferably, in the security information interaction method disclosed in the present invention, the predetermined character conversion table defines a one-to-one correspondence between each numeric character and the converted character (for example, the converted character corresponding to the numeric character 0 is 3 , the transformation character corresponding to the number character 2 is 7, etc.), and wherein each transformation character is different.
优选地,在本发明所公开的安全性信息交互方法中,所述步骤(A1)进一步包括:存储预先设定的三个接入号码,并且以如下方式基于移位后的数字字符串随机地确定与所述安全性信息交互请求相关联的接入号码:对移位后的数字字符串所表示的数值进行模3运算(即除以3取余数),如果运算结果为0,则将第一接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为1,则将第二接入号码确定为与所述安全性信息交互请求相关联的接入号码,如果运算结果为2,则将第三接入号码确定为与所述安全性信息交互请求相关联的接入号码。Preferably, in the security information interaction method disclosed in the present invention, the step (A1) further includes: storing three preset access numbers, and randomly Determine the access number associated with the security information interaction request: perform a modulo 3 operation on the value represented by the shifted digital string (that is, divide by 3 to obtain a remainder), and if the operation result is 0, then An access number is determined as the access number associated with the security information interaction request, and if the operation result is 1, a second access number is determined as the access number associated with the security information interaction request , if the operation result is 2, determine the third access number as the access number associated with the security information interaction request.
优选地,在本发明所公开的安全性信息交互方法中,所述步骤(A1)进一步包括:以如下方式将所述安全性信息交互请求传送到所述数据处理服务器:(1)将所确定的接入号码和与待处理的安全性信息交互相关联的数据的一部分(例如交易时间的后4位)相连接以形成字符串;(2)将所述字符串加密;(3)构造包含经加密的字符串以及所述安全性信息交互请求的数据报文,并将所述数据报文传送到所述数据处理服务器。Preferably, in the security information interaction method disclosed in the present invention, the step (A1) further includes: transmitting the security information interaction request to the data processing server in the following manner: (1) the determined The access number and a part of the data associated with the security information interaction to be processed (for example, the last 4 digits of the transaction time) are concatenated to form a string; (2) encrypt the string; (3) construct a string containing The encrypted character string and the security information exchange request data packet, and transmit the data packet to the data processing server.
优选地,在本发明所公开的安全性信息交互方法中,所述步骤(A2)进一步包括:在接收到所述数据报文后,所述数据处理服务器解密所述经加密的字符串以获取由安全性信息交互终端确定的接入号码,并将所述由安全性信息交互终端确定的接入号码与用于传送所述数据报文的实际的接入号码相比较,并且如果由安全性信息交互终端确定的接入号码与用于传送所述数据报文的实际的接入号码不相同,则产生告警信息(即安全性信息交互终端可能正在被异地非法使用)。Preferably, in the security information interaction method disclosed in the present invention, the step (A2) further includes: after receiving the data message, the data processing server decrypts the encrypted character string to obtain the access number determined by the security information interaction terminal, and compare the access number determined by the security information interaction terminal with the actual access number used to transmit the data message, and if determined by the security If the access number determined by the information interaction terminal is different from the actual access number used to transmit the data message, an alarm message will be generated (that is, the security information interaction terminal may be being illegally used in a different place).
由上可见,本发明所公开的安全性信息交互方法具有下列优点:由于能够及时地发现安全性信息交互终端是否存在正在被异地非法使用的可能,故具有显著提高的安全性。It can be seen from the above that the security information interaction method disclosed in the present invention has the following advantages: since it can be found in time whether the security information interaction terminal is being illegally used in a different place, it has significantly improved security.
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不局限于上述的实施方式。应该认识到:在不脱离本发明主旨和范围的情况下,本领域技术人员可以对本发明做出不同的变化和修改。Although the present invention has been described through the above-mentioned preferred embodiments, its implementation forms are not limited to the above-mentioned embodiments. It should be appreciated that those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention.
Claims (7)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310324181.9A CN104346723B (en) | 2013-07-30 | 2013-07-30 | Security information interaction system, device and method |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310324181.9A CN104346723B (en) | 2013-07-30 | 2013-07-30 | Security information interaction system, device and method |
Publications (2)
Publication Number | Publication Date |
---|---|
CN104346723A CN104346723A (en) | 2015-02-11 |
CN104346723B true CN104346723B (en) | 2018-06-22 |
Family
ID=52502277
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310324181.9A Active CN104346723B (en) | 2013-07-30 | 2013-07-30 | Security information interaction system, device and method |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN104346723B (en) |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2000029996A1 (en) * | 1998-11-17 | 2000-05-25 | Sony Corporation | Terminal, charging system, and data processing method |
CN101114399A (en) * | 2007-09-14 | 2008-01-30 | 杭州华三通信技术有限公司 | Management method of POS machine and management equipment |
CN102737452A (en) * | 2012-06-28 | 2012-10-17 | 福建联迪商用设备有限公司 | Terminal mobile machine monitoring method and system |
-
2013
- 2013-07-30 CN CN201310324181.9A patent/CN104346723B/en active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2000029996A1 (en) * | 1998-11-17 | 2000-05-25 | Sony Corporation | Terminal, charging system, and data processing method |
EP1071031A4 (en) * | 1998-11-17 | 2005-08-17 | Sony Corp | Terminal, charging system, and data processing method |
CN101114399A (en) * | 2007-09-14 | 2008-01-30 | 杭州华三通信技术有限公司 | Management method of POS machine and management equipment |
CN102737452A (en) * | 2012-06-28 | 2012-10-17 | 福建联迪商用设备有限公司 | Terminal mobile machine monitoring method and system |
Also Published As
Publication number | Publication date |
---|---|
CN104346723A (en) | 2015-02-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN104602238B (en) | A kind of wireless network connecting method, device and system | |
CN107786331B (en) | Data processing method, device, system and computer readable storage medium | |
CN112511514A (en) | HTTP encrypted transmission method and device, computer equipment and storage medium | |
CN112823503B (en) | Data access method, data access device and mobile terminal | |
CN107590396B (en) | Data processing method and device, storage medium and electronic equipment | |
CN109040076A (en) | A kind of data processing method, system, device, equipment and medium | |
CN105634737A (en) | Data transmission method, terminals and system thereof | |
CN113923655B (en) | Data decryption receiving method and device based on adjacent nodes | |
CN106411501B (en) | Rights token generation method, system and its equipment | |
CN108959990A (en) | A kind of verification method and device of two dimensional code | |
CN116508044A (en) | Payment method and device using ultra-wideband communication | |
CN116488919B (en) | Data processing method, communication node and storage medium | |
CN105978693B (en) | A kind of method and system of terminal association | |
CN107707562A (en) | Method and device for asymmetric dynamic token encryption and decryption algorithm | |
CN113343269A (en) | Encryption method and device | |
CN106656993A (en) | Dynamic verification code verifying method and apparatus | |
WO2025139068A1 (en) | Ranging positioning method, positioning system, chip and storage medium | |
WO2015188564A1 (en) | Implement method and apparatus for service delivery platform charging and third party charging | |
CN104346723B (en) | Security information interaction system, device and method | |
WO2021027145A1 (en) | Non-application payment method and apparatus, and computing device and storage medium | |
CN103873245A (en) | Virtual machine system data encryption method and apparatus | |
CN116471088A (en) | Verification method, client platform, service platform, system and medium for privacy data | |
CN205910754U (en) | Off -line machine of lining up and system | |
CN113609366A (en) | Data acquisition method and device, terminal equipment and readable storage medium | |
CN106385684A (en) | Method and device for sharing wireless network and accessing wireless network |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant |