[go: up one dir, main page]

CN101231737A - A system and method for enhancing the security of online banking transactions - Google Patents

A system and method for enhancing the security of online banking transactions Download PDF

Info

Publication number
CN101231737A
CN101231737A CNA200810100872XA CN200810100872A CN101231737A CN 101231737 A CN101231737 A CN 101231737A CN A200810100872X A CNA200810100872X A CN A200810100872XA CN 200810100872 A CN200810100872 A CN 200810100872A CN 101231737 A CN101231737 A CN 101231737A
Authority
CN
China
Prior art keywords
user
audio
information
unit
input
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CNA200810100872XA
Other languages
Chinese (zh)
Other versions
CN101231737B (en
Inventor
陆舟
于华章
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Feitian Technologies Co Ltd
Original Assignee
Beijing Feitian Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Feitian Technologies Co Ltd filed Critical Beijing Feitian Technologies Co Ltd
Priority to CN200810100872.XA priority Critical patent/CN101231737B/en
Publication of CN101231737A publication Critical patent/CN101231737A/en
Application granted granted Critical
Publication of CN101231737B publication Critical patent/CN101231737B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明涉及通信安全领域,特别涉及一种增强网上银行交易安全性的系统及方法。该系统包括:信号输入输出装置、支持音频处理的客户端信息安全装置、计算机终端与网上银行服务器连接。本发明的方法:通过信息安全装置与计算机建立连接,通过信息安全装置将用户输入的交易数据以音频播放的方式输出,以音频输入的方式向信息安全装置中输入音频确认信息,信息安全装置进行声纹识别,在确认身份合法后,用户端信息安全装置才能对用户输入的所有信息进行加密或执行数字签名操作,并将其以密文的形式发送到网上银行服务器端。认证信息以音频形式存储,且为执行确认命令,具有唯一性和不可抵赖性,使用本方法,可增强网上银行交易安全性。

Figure 200810100872

The invention relates to the field of communication security, in particular to a system and method for enhancing the security of online banking transactions. The system includes: a signal input and output device, a client information security device supporting audio processing, and a computer terminal connected to an online bank server. The method of the present invention: establish a connection with the computer through the information security device, output the transaction data input by the user through the information security device in the form of audio playback, input audio confirmation information into the information security device in the form of audio input, and the information security device performs Voiceprint recognition, after confirming that the identity is legal, the user terminal information security device can encrypt or perform digital signature operations on all the information input by the user, and send it to the online banking server in the form of ciphertext. The authentication information is stored in the form of audio and is unique and non-repudiable for the execution of the confirmation command. Using this method can enhance the security of online banking transactions.

Figure 200810100872

Description

一种增强网上银行交易安全性的系统及方法 A system and method for enhancing the security of online banking transactions

技术领域technical field

本发明涉及通信安全领域,特别涉及一种通过在信息安全装置中对数据信息进行音频处理及声纹识别来增强网上银行交易安全性的系统及方法。The invention relates to the field of communication security, in particular to a system and method for enhancing the security of online banking transactions by performing audio processing and voiceprint recognition on data information in an information security device.

背景技术Background technique

随着计算机技术的飞速发展,信息网络已经成为社会发展的重要保证。在这一趋势下,网上银行业务正日益深入人心,并已经成为当今最具潜力的网络应用领域。“网上银行”是以互联网为媒介,为客户提供金融服务的电子银行产品。网上银行是信息时代的产物,它的诞生,使原来必须到银行柜台办理业务的客户,通过互联网便可直接进入银行,随意进行账务查询、转账、外汇买卖、银行转账、网上购物、账户挂失等业务,客户真正做到足不出户办妥一切银行业务。网上银行服务系统的开通,对银行和客户来说,都将大大提高工作效率,让资金创造最高效益,从而降低生产经营成本。With the rapid development of computer technology, information network has become an important guarantee for social development. Under this trend, online banking business is becoming more and more popular, and has become the most potential network application field today. "Online banking" is an electronic banking product that provides financial services to customers through the Internet as a medium. Online banking is a product of the information age. With its birth, customers who had to go to the bank counter to handle business can directly enter the bank through the Internet, and conduct account inquiries, transfers, foreign exchange transactions, bank transfers, online shopping, and report loss of accounts at will. and other businesses, customers can truly handle all banking business without leaving home. The opening of the online banking service system will greatly improve work efficiency for banks and customers, allow funds to create the highest efficiency, and thus reduce production and operation costs.

然而,在普通大众及企业享受网上银行带来便利的同时,其安全问题也逐渐浮出水面。由于网络私人信息以及企业机密信息被泄密或遭到监听,给个人和企业带来了不可估量的损失的事例不在少数。因此在网上银行数据通信的实际应用中,随时都可能由于信息泄露和泄密而带来严重后果和不良影响,现有技术中,越来越多的网上银行用户通过选择使用智能密钥设备来确保其在进行网上银行交易过程中的操作安全性。However, while the general public and enterprises are enjoying the convenience brought by online banking, its security issues have gradually surfaced. There are many cases where personal and business confidential information has been leaked or monitored, causing immeasurable losses to individuals and businesses. Therefore, in the actual application of online banking data communication, serious consequences and adverse effects may be caused at any time due to information leakage and leaks. In the prior art, more and more online banking users use smart key devices to ensure Its operational security during online banking transactions.

智能密钥设备(又称信息安全装置)是一种带有处理器和存储器的小型硬件装置,它采用双因子认证模式,使用简单、成本较低。它内置单片机或智能卡芯片,可以存储用户的密钥或数字证书,利用智能密钥设备内置的密码算法实现对用户身份的认证。智能密钥设备具有电子邮件加密、数字签名、安全证书、安全网络登录和访问SSL安全网络等功能,并且具有保证用户的私钥永远不离开硬件的特征,还具有物理上防攻击的特性,安全性极高。A smart key device (also known as an information security device) is a small hardware device with a processor and a memory. It adopts a two-factor authentication mode, which is easy to use and low in cost. It has a built-in single-chip microcomputer or smart card chip, which can store the user's key or digital certificate, and use the built-in cryptographic algorithm of the smart key device to authenticate the user's identity. The smart key device has functions such as email encryption, digital signature, security certificate, secure network login, and access to the SSL secure network. It also has the feature of ensuring that the user's private key never leaves the hardware. It also has the feature of physically preventing attacks and is safe. Sex is extremely high.

然而上述过程并不能完全保证需数字签名或加密数据的安全性,因为计算机本身也是存在安全隐患的,例如,当计算机中了木马病毒时,需数字签名或加密的数据就会被底层木马所篡改,然后被传输至智能密钥设备进行数字签名或加密,用户无法判断出智能密钥设备中需数字签名或加密的数据是否正确,这严重影响了智能密钥设备的安全性,使智能密钥设备丧失了其存在的价值,同时,也必然会给用户带来不必要的损失。However, the above process cannot fully guarantee the security of digitally signed or encrypted data, because the computer itself also has security risks. For example, when the computer is infected with a Trojan horse virus, the data that requires digital signature or encryption will be tampered with by the underlying Trojan horse , and then transmitted to the smart key device for digital signature or encryption, the user cannot judge whether the data to be digitally signed or encrypted in the smart key device is correct, which seriously affects the security of the smart key device, making the smart key The equipment loses the value of its existence, and at the same time, it will inevitably bring unnecessary losses to users.

声纹识别(Voiceprint Recognition,VPR),也称为说话人识别(Speaker Recognition),每个人的音频声学特征既有相对稳定性,又有变异性,不是绝对的、一成不变的,这种变异可来自生理、病理、心理、模拟、伪装,也与环境干扰有关。尽管如此,由于每个人的发音器官都不尽相同,因此在一般情况下,人们仍能区别不同的人的声音或判断是否是同一人的声音。与语音识别不同,声纹识别的特征必须是“个性化”特征,而说话人识别的特征对说话人来讲必须是“共性特征”。与其他生物识别技术,诸如指纹识别、掌形识别、虹膜识别等相比较,声纹识别具有不会遗失和忘记、不需记忆、使用方便等优点,现在人们越来越多地依赖于口令和密码,随着不同场合的频繁应用其缺陷越发明显。在声纹识别过程中,每次发音都由随机产生的提示文本来控制,可有效地防止复制和剽窃,可以说,声纹识别技术与其他生物识别技术相比有着明显的优势,可以为日益发展的电子购物、电子商务、国际贸易保驾护航,且操作方便、简洁,很容易为广大计算机使用者接受。Voiceprint Recognition (VPR), also known as Speaker Recognition, the audio acoustic features of each person have both relative stability and variability, which are not absolute and invariable. This variation can come from Physiology, pathology, psychology, simulation, camouflage, are also related to environmental interference. Even so, since everyone's pronunciation organs are different, in general, people can still distinguish the voices of different people or judge whether they are the same person's voice. Different from speech recognition, the features of voiceprint recognition must be "personalized" features, while the features of speaker recognition must be "common features" for the speaker. Compared with other biometric technologies, such as fingerprint recognition, palm recognition, iris recognition, etc., voiceprint recognition has the advantages of not being lost and forgotten, no memory required, and easy to use. Now people are increasingly relying on passwords and Password, with the frequent application of different occasions, its defects become more and more obvious. In the process of voiceprint recognition, each pronunciation is controlled by a randomly generated prompt text, which can effectively prevent copying and plagiarism. It can be said that voiceprint recognition technology has obvious advantages compared with other biometric technologies, and can be used for increasingly The development of electronic shopping, e-commerce, and international trade is escorted, and the operation is convenient and simple, and it is easy to be accepted by the majority of computer users.

声纹识别系统多用声学层面的特征,表征一个人特点的特征应该是多层面的,包括:(1)与人类的发音机制的解剖学结构有关的声学特征(如频谱、倒频谱、共振峰、基音、反射系数等等)、鼻音、带深呼吸音、沙哑音、笑声等;(2)受社会经济状况、受教育水平、出生地等影响的语义、修辞、发音、言语习惯等;(3)个人特点或受父母影响的韵律、节奏、速度、语调、音量等特征。从利用数学方法可以建模的角度出发,声纹自动识别模型目前可以使用的特征包括:(1)声学特征(倒频谱);(2)词法特征(说话人相关的词n-gram,音素n-gram);(3)韵律特征(利用n-gram描述的基音和能量“姿势”);(4)语种、方言和口音信息;(5)通道信息(使用何种通道)等等。根据不同的任务需求,声纹识别还面临一个特征选择或特征选用的问题。例如,对“信道”信息,在刑侦应用上,希望不用,也就是说希望弱化信道对说话人识别的影响,因为我们希望不管说话人用什么信道系统它都可以辨认出来;而在银行交易上,希望用信道信息,即希望信道对说话人识别有较大影响,从而可以剔除录音、模仿等带来的影响。总之,较好的特征,应该能够有效地区分不同的说话人,但又能在同一说话人语音发生变化时保持相对的稳定;不易被他人模仿或能够较好地解决被他人模仿问题;具有较好的抗噪性能。当然,这些问题也可以通过模型方法去解决。对于模式识别,有以下几大类方法:(1)模板匹配方法:利用动态时间弯折(DTW)以对准训练和测试特征序列,主要用于固定词组的应用(通常为文本相关任务);(2)最近邻方法:训练时保留所有特征矢量,识别时对每个矢量都找到训练矢量中最近的K个,据此进行识别,通常模型存储和相似计算的量都很大;(3)神经网络方法:有很多种形式,如多层感知、径向基函数(RBF)等,可以显式训练以区分说话人和其背景说话人,其训练量很大,且模型的可推广性不好;(4)隐式马尔可夫模型(HMM)方法:通常使用单状态的HMM,或高斯混合模型(GMM),是比较流行的方法,效果比较好;(5)VQ聚类方法(如LBG):效果比较好,算法复杂度也不高,和HMM方法配合起来更可以收到更好的效果;(6)多项式分类器方法:有较高的精度,但模型存储和计算量都比较大;声纹识别需要解决的关键问题还有很多,诸如:短话音问题,能否用很短的语音进行模型训练,而且用很短的时间进行识别,这主要是声音不易获取的应用所需求的;声音模仿(或放录音)问题,要有效地区分开模仿声音(录音)和真正的声音;多说话人情况下目标说话人的有效检出;消除或减弱声音变化(不同语言、内容、方式、身体状况、时间、年龄等)带来的影响;消除信道差异和背景噪音带来的影响,此时需要用到其他一些技术来辅助完成,如去噪、自适应等技术。The voiceprint recognition system mostly uses the features of the acoustic level, and the features that characterize a person's characteristics should be multi-level, including: (1) acoustic features related to the anatomical structure of the human pronunciation mechanism (such as spectrum, cepstrum, formant, Fundamental tone, reflection coefficient, etc.), nasal sound, deep breathing sound, hoarse sound, laughter, etc.; (2) Semantics, rhetoric, pronunciation, speech habits, etc. affected by socioeconomic status, education level, place of birth, etc.; (3) ) Personal characteristics or characteristics such as rhythm, rhythm, speed, intonation, and volume influenced by parents. From the perspective of using mathematical methods to model, the current features that can be used in the voiceprint automatic recognition model include: (1) acoustic features (cepstrum); (2) lexical features (speaker-related word n-gram, phoneme n -gram); (3) prosodic features (using the pitch and energy "posture" described by n-gram); (4) language, dialect and accent information; (5) channel information (which channel to use) and so on. According to different task requirements, voiceprint recognition also faces a problem of feature selection or feature selection. For example, for "channel" information, in criminal investigation applications, it is hoped not to use it, that is to say, we hope to weaken the influence of the channel on speaker identification, because we hope that it can be identified no matter what channel system the speaker uses; while in bank transactions , it is hoped to use channel information, that is, it is hoped that the channel has a greater impact on speaker recognition, so that the impact of recording, imitation, etc. can be eliminated. In short, better features should be able to effectively distinguish between different speakers, but can also remain relatively stable when the voice of the same speaker changes; it is not easy to be imitated by others or can better solve the problem of being imitated by others; Good noise immunity. Of course, these problems can also be solved by model methods. For pattern recognition, there are the following categories of methods: (1) template matching method: use dynamic time warping (DTW) to align training and test feature sequences, mainly for the application of fixed phrases (usually text-related tasks); (2) Nearest neighbor method: keep all the feature vectors during training, and find the nearest K of the training vectors for each vector during recognition, and identify them accordingly. Usually, the amount of model storage and similar calculation is large; (3) Neural network method: There are many forms, such as multi-layer perception, radial basis function (RBF), etc., which can be explicitly trained to distinguish speakers from their background speakers. The amount of training is large, and the generalizability of the model is not good. Good; (4) Hidden Markov Model (HMM) method: usually using single-state HMM, or Gaussian Mixture Model (GMM), is a more popular method, and the effect is better; (5) VQ clustering method (such as LBG): The effect is better, the algorithm complexity is not high, and it can receive better results when combined with the HMM method; (6) Multinomial classifier method: has higher accuracy, but the model storage and calculation amount are relatively large Big; there are still many key problems to be solved in voiceprint recognition, such as: short speech, whether it is possible to use very short speech for model training, and use a short time for recognition, which is mainly required by applications where voice is not easy to obtain the sound imitation (or recording) problem, it is necessary to effectively distinguish the imitation sound (recording) from the real voice; the effective detection of the target speaker in the case of multiple speakers; eliminate or weaken the sound change (different language, content, method) , physical condition, time, age, etc.); to eliminate the influence of channel differences and background noise, some other technologies are needed to assist in this case, such as denoising, adaptive and other technologies.

现有的网上银行交易过程中,往往会出现网银用户抵赖交易历史,或者网上银行未能根据用户输入的交易数据执行有效操作的情况,从而导致交易的失败,或错误操作,一旦出现这种情况,双方很难在短时间内解决争端,找出责任方,因此必然会给用户或网上银行带来一定的时间损失和物质损失。In the existing online banking transaction process, it often happens that the online banking user denies the transaction history, or the online banking fails to perform effective operations according to the transaction data input by the user, which leads to the failure of the transaction or wrong operation. Once such a situation occurs , it is difficult for both parties to resolve the dispute in a short time and find out the responsible party, so it will inevitably bring certain time loss and material loss to the user or the online bank.

发明内容Contents of the invention

鉴于现有技术的不足,本发明提供了一种利用信息安全装置对用户输入的交易数据进行音频重放,供合法用户最终确认的方式实现用户端数据安全发送,以解决现有技术中因需要进行加密或签名的交易数据可能在发送前被篡改而导致信息安全装置安全性降低的问题,本发明还利用信息安全装置具有的声纹识别功能来鉴定用户者身份的合法性。In view of the deficiencies in the prior art, the present invention provides an audio replay of the transaction data input by the user using an information security device for final confirmation by the legal user to realize the safe transmission of data at the user end, so as to solve the problem in the prior art. Encrypted or signed transaction data may be tampered with before sending, resulting in reduced security of the information security device. The present invention also utilizes the voiceprint recognition function of the information security device to verify the legitimacy of the user's identity.

一种增强网上银行交易安全性的系统,包括:信号输入输出装置、支持音频处理的客户端信息安全装置、计算机终端和网上银行服务器;所述音频输入输出装置、客户端信息安全装置,计算机终端与网上银行服务器连接;A system for enhancing the security of online banking transactions, comprising: a signal input and output device, a client information security device supporting audio processing, a computer terminal and an online banking server; the audio input and output device, the client information security device, and the computer terminal Connect with the online banking server;

所述信号输入输出装置包括:用于用户输入音频信息的音频输入单元、通过音频播放的方式输出用户输入的交易数据音频输出单元;The signal input and output device includes: an audio input unit for the user to input audio information, and an audio output unit for outputting the transaction data input by the user through audio playback;

所述支持音频处理的客户端信息安全装置包括:信号输入单元、声纹识别单元、声控操作单元、第一存储单元、转换单元、信号输出单元、加密单元、数据传送单元;所述信号输入单元、声纹识别单元、声控操作单元、第一存储单元、加密单元、数据传输单元相连;所述数据传送单元又和第一存储单元、转换单元、信号输出单元连接;The client information security device supporting audio processing includes: a signal input unit, a voiceprint recognition unit, a voice-activated operation unit, a first storage unit, a conversion unit, a signal output unit, an encryption unit, and a data transmission unit; the signal input unit , the voiceprint recognition unit, the voice control operation unit, the first storage unit, the encryption unit, and the data transmission unit are connected; the data transmission unit is connected with the first storage unit, the conversion unit, and the signal output unit;

所述网上银行服务器由数据接收单元、第二存储单元、解密单元、交易执行单元组成。The online banking server is composed of a data receiving unit, a second storage unit, a decryption unit and a transaction execution unit.

所述支持音频处理的客户端信息安全装置还包括:The client information security device supporting audio processing also includes:

信号输入单元,包括:单个按钮、数字键、麦克风;用于用户输入交易数据以及身份验证信息;其中身份验证信息为:PIN码信息、用户自定义密码、用户音频信息。The signal input unit includes: a single button, a number key, and a microphone; it is used for the user to input transaction data and identity verification information; the identity verification information includes: PIN code information, user-defined password, and user audio information.

信号输出单元,包括:耳机、扬声器;用于通过音频的方式输出所述用户输入的交易数据。The signal output unit includes: an earphone and a loudspeaker; and is used to output the transaction data input by the user through audio.

所述客户端信息安全装置中:In the client information security device:

所述信息输入单元,用于接收用户输入的音频确认信息;The information input unit is configured to receive audio confirmation information input by the user;

所述第一存储单元,用于存储所述信号输入单元接收到的用户输入的音频确认信息、合法用户的音频信号、用户通过计算机输入的交易数据、用户输入的音频信息以及与所述网上银行服务器端进行密钥协商过程中的相关数据和密钥协商算法;The first storage unit is used to store the audio confirmation information input by the user received by the signal input unit, the audio signal of the legal user, the transaction data input by the user through the computer, the audio information input by the user, and the information related to the online bank. Relevant data and key agreement algorithm during the key agreement process on the server side;

所述转换单元,用于将所述用户通过计算机输入的交易数据转换成音频信号;The converting unit is configured to convert the transaction data input by the user through a computer into an audio signal;

所述信号输出单元,用于输出经过转换单元转换后的音频信号;The signal output unit is used to output the audio signal converted by the conversion unit;

所述声纹识别单元,用于对信号输入单元接收到的用户输入的音频确认信息进行识别,判断用户身份是否合法;The voiceprint recognition unit is used to identify the audio confirmation information input by the user received by the signal input unit, and determine whether the user's identity is legal;

所述声控操作单元,用于解析用户输入的音频信号,判断所述音频信号对应的操作指令,并依据所述操作指令执行相应的操作;The voice control operation unit is used to analyze the audio signal input by the user, judge the operation instruction corresponding to the audio signal, and execute the corresponding operation according to the operation instruction;

所述加密单元,用于对所述用户通过计算机输入的交易数据、用户输入的音频确认信息进行数字签名或加密处理;The encryption unit is used to digitally sign or encrypt the transaction data input by the user through the computer and the audio confirmation information input by the user;

所述数据传送单元,用于将用户输入的交易数据通过计算机传送给所述信息安全装置,以及将经过数字签名或加密处理后的交易数据和音频确认信息通过计算机发送给网上银行服务器。The data transmission unit is used to transmit the transaction data input by the user to the information security device through the computer, and send the digitally signed or encrypted transaction data and audio confirmation information to the online banking server through the computer.

所述操作指令包括:确认、取消、结束任务、返回。The operation instructions include: confirm, cancel, end task, and return.

所述网上银行服务器中:In the online banking server:

所述数据接收单元,用于接收所述客户端信息安全装置通过计算机发送的经过加密或数字签名后的交易数据以及用户音频确认信息;The data receiving unit is configured to receive encrypted or digitally signed transaction data and user audio confirmation information sent by the client information security device through a computer;

所述第二存储单元,用于存储用户账户信息、用户的音频确认信息、用户交易数据、用于与所述客户端信息安全装置进行密钥协商过程中的相关数据和密钥协商算法。The second storage unit is used to store user account information, user audio confirmation information, user transaction data, relevant data and key agreement algorithm for key agreement with the client information security device.

所述解密单元,用于对经过所述加密或数字签名后的交易数据进行解密;The decryption unit is configured to decrypt the encrypted or digitally signed transaction data;

所述交易执行单元,用于解密后的数据内容执行最终的交易操作。The transaction execution unit is used to execute the final transaction operation on the decrypted data content.

一种增强网上银行交易安全性的方法,具体包括以下步骤:A method for enhancing the safety of online banking transactions, specifically comprising the following steps:

步骤A:信息安全装置与计算机建立连接,所述计算机接收所述用户输入的数据并将所述数据传输至所述信息安全装置;Step A: the information security device establishes a connection with the computer, and the computer receives the data input by the user and transmits the data to the information security device;

步骤B:所述信息安全装置接收到所述计算机传输来的交易数据后,对所述交易数据进行数模转换,并通过音频播放的方式输出所述交易数据;Step B: After receiving the transaction data transmitted by the computer, the information security device performs digital-to-analog conversion on the transaction data, and outputs the transaction data through audio playback;

步骤C:所述信息安全装置等待接收所述用户确认信息,在确认交易数据无误后,通过音频输入的方式向所述信息安全装置发送执行所述交易的命令;Step C: The information security device waits to receive the user confirmation information, and after confirming that the transaction data is correct, sends an order to execute the transaction to the information security device through audio input;

步骤D:所述信息安全装置接收到所述用户输入的音频确认信息,通过声纹识别对所述用户进行身份认证和解析,认证成功后,执行相应操作。Step D: The information security device receives the audio confirmation information input by the user, authenticates and analyzes the identity of the user through voiceprint recognition, and executes corresponding operations after successful authentication.

所述步骤D还包括:Said step D also includes:

D1:所述信息安全装置内部对所述交易数据和所述用户输入的音频信息进行数字签名或加密并发送;D1: The information security device internally digitally signs or encrypts the transaction data and the audio information input by the user and sends them;

D2:所述网上银行服务器端接收所述信息安全装置发送的经过数字签名或加密后的交易数据以及用户音频确认信息,对所述数据和音频确认信息进行解密并存储;D2: The online banking server receives the digitally signed or encrypted transaction data and user audio confirmation information sent by the information security device, and decrypts and stores the data and audio confirmation information;

D3:所述网上银行服务器根据所述交易数据中的信息执行所述交易。D3: The online banking server executes the transaction according to the information in the transaction data.

所述步骤D中,所述信息安全装置接收到所述用户音频确认信息,通过声纹识别对所述用户进行身份认证,具体包括:所述信息安全装置通过将接收到所述用户输入的音频确认信息后与其内部存储的合法用户的声纹模板信息进行比较,判断两者是否匹配,如果是,则认为所述用户身份合法,否则,认为所述用户身份不合法。In the step D, the information security device receives the user's audio confirmation information, and performs identity authentication on the user through voiceprint recognition, which specifically includes: the information security device receives the audio input from the user. After confirming the information, compare it with the voiceprint template information of the legal user stored inside to judge whether the two match, if yes, the user identity is considered legal, otherwise, the user identity is considered illegal.

所述步骤D中,所述信息安全装置对所述用户输入的音频确认信息进行解析具体包括:对音频信号的预处理、特征提取、模式匹配,所述预处理包括预滤波、采样和量化、加窗、端点检测、预加重。In the step D, the information security device analyzing the audio confirmation information input by the user specifically includes: preprocessing, feature extraction, and pattern matching of the audio signal, and the preprocessing includes prefiltering, sampling and quantization, Windowing, endpoint detection, pre-emphasis.

所述步骤B后还可执行以下操作:After the step B, the following operations can also be performed:

步骤C′:所述信息安全装置等待接收所述用户通过音频输入的方式向所述信息安全装置发送以下操作命令:取消、结束任务、返回、向上翻页、或向下翻页、复读操作。Step C': The information security device waits for the user to send the following operation commands to the information security device through audio input: cancel, end task, return, turn page up or down, and repeat operation.

本发明的有益效果在于:利用本发明提供的装置及方法,在用户利用信息安全装置进行网上银行交易前,通过信息安全装置将用户输入的交易数据以音频播放的方式输出,用户确认无误后,以音频输入的方式向信息安全装置中输入音频确认信息,信息安全装置又对用户输入的音频信息进行声纹识别,确认其身份是否合法,只有在交易数据无误,且用户身份合法的情况下,用户端信息安全装置才能对用户输入的所有信息进行加密或执行数字签名操作,并将其以密文的形式发送到网上银行服务器端;The beneficial effects of the present invention are: using the device and method provided by the present invention, before the user uses the information security device to conduct online banking transactions, the transaction data input by the user is output through the information security device in the form of audio playback, and after the user confirms that it is correct, Input audio confirmation information into the information security device through audio input, and the information security device performs voiceprint recognition on the audio information input by the user to confirm whether the identity is legal. Only when the transaction data is correct and the user's identity is legal, Only the information security device at the user terminal can encrypt or perform digital signature operations on all the information input by the user, and send it to the online banking server in the form of ciphertext;

网上银行服务器端在接收到客户端信息安全装置发送的交易数据和用户音频确认信息后,将用户音频确认信息进行有效存储,并按照用户输入的交易数据执行最终操作,由于网上应行服务器端存录了用户的音频确认信息,一旦在日后的交易过程中,出现用户抵赖交易历史的情况,或者网上银行未能根据用户输入的交易数据执行有效操作,均可方便地从网上银行服务器端的用户数据库中查询到历史音频确认信息,由于该确认信息是以音频形式存储的,且为执行交易数据的确认命令,具有唯一性和不可抵赖性,可以有效地判别出导致交易无效执行的责任方。After receiving the transaction data and user audio confirmation information sent by the client information security device, the online banking server will effectively store the user audio confirmation information, and execute the final operation according to the transaction data input by the user. Recorded the user's audio confirmation information, once the user denies the transaction history in the future transaction process, or the online bank fails to perform effective operations according to the transaction data input by the user, it can be conveniently accessed from the user database on the server side of the online bank The historical audio confirmation information is queried in . Since the confirmation information is stored in the form of audio and is a confirmation command for executing transaction data, it is unique and non-repudiable, and can effectively identify the responsible party that caused the invalid execution of the transaction.

附图说明Description of drawings

图1是本发明实施例1提高信息安全装置安全性的系统结构图;Fig. 1 is a system structure diagram for improving the security of an information security device in Embodiment 1 of the present invention;

图2是本发明实施例2提高信息安全装置安全性的方法流程图;2 is a flow chart of a method for improving the security of an information security device according to Embodiment 2 of the present invention;

图3是本发明实施例3提高信息安全装置安全性的方法流程图。Fig. 3 is a flowchart of a method for improving the security of an information security device according to Embodiment 3 of the present invention.

具体实施方式Detailed ways

下面结合附图和具体实施例对本发明作进一步说明,但本发明不局限于下面的实施例。在本发明具体实施例中,信息安全装置为USB Key,这是一种USB接口的信息安全装置。The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, but the present invention is not limited to the following embodiments. In a specific embodiment of the present invention, the information security device is a USB Key, which is an information security device with a USB interface.

实施例1Example 1

如图1所示,一种增强网上银行交易安全性的系统包括:As shown in Figure 1, a system to enhance the security of online banking transactions includes:

耳机100、话筒200、USB Key300、计算机400、网上银行服务器500,其中USB Key300包括:USB接口单元301、第一存储单元302、转换单元303、耳机接口单元304、话筒单元305、声纹识别单元306、声控操作单元307、加密单元308;网上银行服务器500包括:数据接收单元501、第二存储单元502、解密单元503、交易执行单元504。Earphone 100, microphone 200, USB Key 300, computer 400, online banking server 500, wherein USB Key 300 includes: USB interface unit 301, first storage unit 302, conversion unit 303, earphone interface unit 304, microphone unit 305, voiceprint recognition unit 306 , voice-activated operation unit 307 , encryption unit 308 ; the online banking server 500 includes: a data receiving unit 501 , a second storage unit 502 , a decryption unit 503 , and a transaction execution unit 504 .

在本实施例中,用户通过计算机400输入交易数据,USB Key300通过USB接口单元301接收用户输入的交易数据,并存储在第一存储单元302中,转换单元303将用户输入的交易数据转换成音频信号,并通过耳机接口单元304将经过转换单元303转换输出的音频信号传送到耳机100中;用户根据从耳机接收到的信息,通过话筒200输入音频信息,话筒接口单元305接收到话筒200发送的音频信息后,将该音频信息发送给声纹识别单元306,声纹识别单元306对用户输入的音频信息进行鉴别,以判断用户身份的合法性,若声纹识别单元306鉴别用户身份合法,则将该音频确认信息发送到声控操作单元307中,声控操作单元307对用户输入的音频信息进行解析,判断用户输入的音频信息所对应的操作指令,并依据该操作指令执行相应的操作,并将操作结果存储在第一存储单元302中。In this embodiment, the user inputs the transaction data through the computer 400, the USB Key300 receives the transaction data input by the user through the USB interface unit 301, and stores it in the first storage unit 302, and the conversion unit 303 converts the transaction data input by the user into audio signal, and transmit the audio signal converted and output by the conversion unit 303 to the earphone 100 through the earphone interface unit 304; the user inputs audio information through the microphone 200 according to the information received from the earphone, and the microphone interface unit 305 receives the audio signal sent by the microphone 200 After the audio information, the audio information is sent to the voiceprint recognition unit 306, and the voiceprint recognition unit 306 discriminates the audio information input by the user to judge the legitimacy of the user's identity. If the voiceprint recognition unit 306 identifies that the user's identity is legal, then Send the audio confirmation information to the voice control operation unit 307, the voice control operation unit 307 analyzes the audio information input by the user, judges the operation instruction corresponding to the audio information input by the user, and executes the corresponding operation according to the operation instruction, and sends The operation result is stored in the first storage unit 302 .

在本实施例中,用户输入的音频信息为确认执行操作命令。In this embodiment, the audio information input by the user is to confirm the execution of the operation command.

第一存储单元302将接收到的用户音频确认信息以及用户通过计算机输入的交易数据发送到加密单元308中进行加密处理;加密单元308将经过加密后的数据通过USB接口单元301发送给主机,最后通过计算机网络将以密文形式存在的交易数据及音频信息发送给网上银行服务器500。The first storage unit 302 sends the received user audio confirmation information and the transaction data input by the user through the computer to the encryption unit 308 for encryption processing; the encryption unit 308 sends the encrypted data to the host through the USB interface unit 301, and finally Send the transaction data and audio information in encrypted form to the online banking server 500 through the computer network.

网上银行服务器500中,数据接收单元501接收到用户端发送的数据后将其存储于第二存储单元502中,并通过解密单元503对其进行解密,最后由交易执行单元504按照用户输入的交易数据执行最终的交易操作。In the online banking server 500, the data receiving unit 501 receives the data sent by the client and stores it in the second storage unit 502, and decrypts it through the decryption unit 503, and finally the transaction execution unit 504 executes the transaction according to the transaction input by the user. The data performs the final transaction operation.

在本实施例中,声纹识别单元306包括声纹识别芯片,该芯片主要用于音频信号采集、音频信号特征量的提取以及模式匹配。音频信号采集的任务是采集到连续稳定的音频信息;特征提取的任务是提取并选择对用户的声纹具有可分性强、稳定性高的特性的声学或语言特征。在提取特征量后,对所述将生物特征信息的变化量转换为生物特征向量,这主要是通过计算连续采集到的声音幅度/频率/相位波形图像,获得相对幅度/频率/相位差来实现。当声纹识别单元306判断用户的声纹信号与合法用户的声纹模板信号的匹配值达到一定程度时,判断该用户的身份合法,即该用户输入的音频确认信息有效。In this embodiment, the voiceprint recognition unit 306 includes a voiceprint recognition chip, which is mainly used for audio signal collection, audio signal feature extraction and pattern matching. The task of audio signal collection is to collect continuous and stable audio information; the task of feature extraction is to extract and select acoustic or language features that are highly separable and stable to the user's voiceprint. After the feature quantity is extracted, the change of the biological feature information is converted into a biological feature vector, which is mainly realized by calculating the continuously collected sound amplitude/frequency/phase waveform image and obtaining the relative amplitude/frequency/phase difference . When the voiceprint recognition unit 306 determines that the matching value between the user's voiceprint signal and the legitimate user's voiceprint template signal reaches a certain level, it determines that the user's identity is legal, that is, the audio confirmation information input by the user is valid.

在本实施例中,转换单元303为一个D/A(数字/模拟)转换芯片,用于将数字量的交易数据转换为模拟量的音频信号。In this embodiment, the conversion unit 303 is a D/A (digital/analog) conversion chip, which is used to convert digital transaction data into analog audio signals.

在本实施例中,第一存储单元302除用于存储用户交易数据,用户语音确认信息外,还用于存储与网上银行服务器500进行密钥协商过程中的相关数据和密钥协商算法;第二存储单元502,用于存储用户账户信息、用户的音频确认信息、用户交易数据、用于与USBKey300进行密钥协商过程中的相关数据和密钥协商算法;In this embodiment, the first storage unit 302 is not only used to store user transaction data and user voice confirmation information, but also used to store relevant data and key agreement algorithms in the process of key agreement with the online banking server 500; Two storage unit 502, for storing user account information, user's audio confirmation information, user transaction data, relevant data and key agreement algorithm used in the process of key agreement with USBKey300;

实施例2Example 2

参见图2,一种增强网上银行交易安全性的方法包括:Referring to Figure 2, one approach to enhancing the security of online banking transactions includes:

步骤201、USB Key与计算机建立连接;Step 201, USB Key establishes connection with computer;

步骤202、用户通过计算机将欲执行的交易数据输入到USB Key中;Step 202, the user inputs the transaction data to be executed into the USB Key through the computer;

步骤203、USB Key接收到客户端计算机传输来的数据后,对其进行模数转换,并通过音频播放的方式输出;Step 203, after the USB Key receives the data transmitted from the client computer, it performs analog-to-digital conversion and outputs it through audio playback;

在本实施例中,用户输入的交易数据包括:用户姓名、银行账号、交易日期、交易类别和交易金额;In this embodiment, the transaction data input by the user includes: user name, bank account number, transaction date, transaction category and transaction amount;

步骤204、用户判断步骤203中以音频播放的形式输出的交易数据是否为欲操作的数据,如果是,则执行步骤206,否则,执行步骤205;Step 204, the user judges whether the transaction data output in the form of audio playback in step 203 is the data to be operated, if yes, execute step 206, otherwise, execute step 205;

步骤205、用户判断步骤203中以音频播放的形式输出的交易数据不是欲操作的数据,以音频输入的形式向USB Key输入“取消操作”音频信号,USB Key执行用户以音频输入的形式输入的取消操作命令,取消本次操作;Step 205, the user judges that the transaction data output in the form of audio playback in step 203 is not the data to be operated, and inputs the "cancel operation" audio signal to the USB Key in the form of audio input, and the USB Key executes the user's input in the form of audio input. Cancel the operation command, cancel this operation;

步骤206、用户判断步骤203中以音频播放的形式输出的交易数据是欲操作的数据,以音频输入的形式向USB Key输入“确认”音频信号;Step 206, the user judges that the transaction data output in the form of audio playback in step 203 is the data to be operated, and inputs a "confirmation" audio signal to the USB Key in the form of audio input;

步骤207、USB Key接收到用户输入的“确认”音频信号后,其内部通过声纹识别的方式判断用户身份是否合法,若合法则执行步骤209,否则执行步骤208;Step 207, after the USB Key receives the "confirmation" audio signal input by the user, it internally judges whether the user's identity is legal through voiceprint recognition, and if it is legal, execute step 209, otherwise execute step 208;

步骤208、USB Key内部通过声纹识别的方式判断用户身份不合法,USB Key通过主机向用户提示出错信息;Step 208, the USB Key internally judges that the user's identity is illegal through voiceprint recognition, and the USB Key prompts the user for an error message through the host;

步骤209、USB Key内部通过声纹识别的方式判断用户身份合法,通过计算机与网上银行服务器端进行密钥协商,并用生成的会话密钥对用户输入的交易数据及用户输入的音频确认信息进行加密处理,并将加密后的数据通过计算机发送到网上银行服务器端;Step 209, the USB Key internally judges that the user's identity is legal through voiceprint recognition, conducts key negotiation with the online banking server through the computer, and uses the generated session key to encrypt the transaction data input by the user and the audio confirmation information input by the user process, and send the encrypted data to the online banking server through the computer;

步骤210:网上银行服务器端接收用户端USB Key发送的数据后,利用会话密钥对加密后的数据进行解密并存储;Step 210: After the online banking server receives the data sent by the USB Key of the client, it uses the session key to decrypt and store the encrypted data;

步骤211:网上银行服务器端根据解密后的数据内容执行后续的交易操作。Step 211: The online banking server executes subsequent transaction operations according to the decrypted data content.

实施例3Example 3

参见图3,一种增强网上银行交易安全性的方法包括:Referring to Figure 3, one approach to enhancing the security of online banking transactions includes:

步骤301、USB Key与计算机建立连接;Step 301, USB Key establishes connection with computer;

步骤302、用户通过计算机向USB Key中输入交易数据;Step 302, the user inputs transaction data into the USB Key through the computer;

步骤303、USB Key接收到客户端计算机传输来的数据后,对其进行模数转换,并通过音频播放的方式输出;Step 303, after the USB Key receives the data transmitted from the client computer, it performs analog-to-digital conversion and outputs it through audio playback;

在本实施例中,用户输入的交易数据包括:用户姓名、银行账号、交易日期、交易类别和交易金额;In this embodiment, the transaction data input by the user includes: user name, bank account number, transaction date, transaction category and transaction amount;

步骤304、用户接收到步骤303中USB Key以音频播放的形式输出的交易数据后,以音频输入的形式向USB Key输入“复读”音频信号,要求USB Key再次通过音频播放的方式输出步骤302中的交易数据;Step 304: After receiving the transaction data output by the USB Key in the form of audio playback in step 303, the user inputs a "repeat" audio signal to the USB Key in the form of audio input, and requests the USB Key to output the data in step 302 again by audio playback. transaction data;

步骤305、用户判断步骤303及步骤304中,USB Key以音频播放的形式输出的交易数据是否均为欲操作的数据,如果是,则执行步骤307,否则,执行步骤306;Step 305, the user judges in step 303 and step 304 whether the transaction data output by the USB Key in the form of audio playback is the data to be operated, if yes, then execute step 307, otherwise, execute step 306;

步骤306、用户判断步骤303或步骤304中以音频播放的形式输出的交易数据不是欲操作的数据,用户以音频输入的形式向USB Key输入“返回操作”音频信号,USB Key执行用户以音频输入的形式输入的返回操作命令,返回到步骤302;Step 306, the user judges that the transaction data output in the form of audio playback in step 303 or step 304 is not the data to be operated, the user inputs the "return operation" audio signal to the USB Key in the form of audio input, and the USB Key executes the user's audio input The return operation command input in the form of returning to step 302;

步骤307、用户判断步骤303及步骤304中以音频播放的形式输出的交易数据均为欲操作的数据,用户以音频输入的形式向USB Key输入“确认”音频信号;Step 307, the user judges that the transaction data output in the form of audio playback in step 303 and step 304 is the data to be operated, and the user inputs the "confirmation" audio signal to the USB Key in the form of audio input;

以上对本发明所提供的一种用于增强网上银行交易安全性的系统及方法进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。A system and method for enhancing the security of online banking transactions provided by the present invention has been introduced in detail above. In this paper, specific examples have been used to illustrate the principle and implementation of the present invention. The description of the above embodiments is only used To help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation and scope of application. In summary, this specification The content should not be construed as a limitation of the invention.

Claims (10)

1.一种增强网上银行交易安全性的系统,其特征在于,包括:信号输入输出装置、支持音频处理的客户端信息安全装置、计算机终端和网上银行服务器;所述音频输入输出装置、客户端信息安全装置,计算机终端与网上银行服务器连接;1. A system for enhancing the safety of online banking transactions, characterized in that, comprising: a signal input and output device, a client information security device that supports audio processing, a computer terminal and an online banking server; the audio input and output device, the client Information security device, the computer terminal is connected to the online banking server; 所述信号输入输出装置包括:用于用户输入音频信息的音频输入单元、通过音频播放的方式输出用户输入的交易数据的音频输出单元;The signal input and output device includes: an audio input unit for the user to input audio information, and an audio output unit for outputting the transaction data input by the user through audio playback; 所述支持音频处理的客户端信息安全装置包括:信号输入单元、声纹识别单元、声控操作单元、第一存储单元、转换单元、信号输出单元、加密单元、数据传送单元;所述信号输入单元、声纹识别单元、声控操作单元、第一存储单元、加密单元、数据传输单元相连;所述数据传送单元又和第一存储单元、转换单元、信号输出单元连接;The client information security device supporting audio processing includes: a signal input unit, a voiceprint recognition unit, a voice-activated operation unit, a first storage unit, a conversion unit, a signal output unit, an encryption unit, and a data transmission unit; the signal input unit , the voiceprint recognition unit, the voice control operation unit, the first storage unit, the encryption unit, and the data transmission unit are connected; the data transmission unit is connected with the first storage unit, the conversion unit, and the signal output unit; 所述网上银行服务器由数据接收单元、第二存储单元、解密单元、交易执行单元组成。The online banking server is composed of a data receiving unit, a second storage unit, a decryption unit and a transaction execution unit. 2.根据权利要求1所述的一种增强网上银行交易安全性的系统,其特征在于,所述支持音频处理的客户端信息安全装置还包括:2. A system for enhancing the security of online banking transactions according to claim 1, wherein the client information security device supporting audio processing also includes: 信号输入单元,包括:单个按钮、数字键、麦克风;用于用户输入交易数据以及身份验证信息;其中身份验证信息为:PIN码信息、用户自定义密码、用户音频信息;Signal input unit, including: a single button, a number key, a microphone; used for the user to input transaction data and identity verification information; where the identity verification information is: PIN code information, user-defined password, user audio information; 信号输出单元,包括:耳机、扬声器;用于通过音频的方式输出所述用户输入的交易数据。The signal output unit includes: an earphone and a loudspeaker; and is used to output the transaction data input by the user through audio. 3.根据权利要求1所述的一种增强网上银行交易安全性的系统,其特征在于,所述客户端信息安全装置中:3. a kind of system that strengthens online banking transaction security according to claim 1, is characterized in that, in described client information security device: 所述信息输入单元,用于接收用户输入的音频确认信息;The information input unit is configured to receive audio confirmation information input by the user; 所述第一存储单元,用于存储所述信号输入单元接收到的用户输入的音频确认信息、合法用户的音频信号模板信息、用户通过计算机输入的交易数据、用户输入的音频信息以及与所述网上银行服务器端进行密钥协商过程中的相关数据和密钥协商算法;The first storage unit is used to store the audio confirmation information input by the user received by the signal input unit, the audio signal template information of the legal user, the transaction data input by the user through the computer, the audio information input by the user, and the Relevant data and key agreement algorithm during the key agreement process performed by the online banking server; 所述转换单元,用于将所述用户通过计算机输入的交易数据转换成音频信号;The converting unit is configured to convert the transaction data input by the user through a computer into an audio signal; 所述信号输出单元,用于输出经过转换单元转换后的音频信号;The signal output unit is used to output the audio signal converted by the conversion unit; 所述声纹识别单元,用于对信号输入单元接收到的用户输入的音频确认信息进行识别,判断用户身份是否合法;The voiceprint recognition unit is used to identify the audio confirmation information input by the user received by the signal input unit, and determine whether the user's identity is legal; 所述声控操作单元,用于解析用户输入的音频信号,判断所述音频信号对应的操作指令,并依据所述操作指令执行相应的操作;The voice control operation unit is used to analyze the audio signal input by the user, judge the operation instruction corresponding to the audio signal, and execute the corresponding operation according to the operation instruction; 所述加密单元,用于对所述用户通过计算机输入的交易数据、用户输入的音频确认信息进行数字签名或加密处理;The encryption unit is used to digitally sign or encrypt the transaction data input by the user through the computer and the audio confirmation information input by the user; 所述数据传送单元,用于将用户输入的交易数据通过计算机传送给所述信息安全装置,以及将经过数字签名或加密处理后的交易数据和音频确认信息通过计算机发送给网上银行服务器。The data transmission unit is used to transmit the transaction data input by the user to the information security device through the computer, and send the digitally signed or encrypted transaction data and audio confirmation information to the online banking server through the computer. 4.根据权利要求3所述的一种增强网上银行交易安全性的系统,其特征在于,所述操作指令包括:确认、取消、结束任务、返回。4. A system for enhancing the security of online banking transactions according to claim 3, wherein the operation instructions include: confirm, cancel, end task, and return. 5.根据权利要求1所述的一种增强网上银行交易安全性的系统,其特征在于,所述网上银行服务器中:5. A system for enhancing the security of online banking transactions according to claim 1, wherein, in the online banking server: 所述数据接收单元,用于接收所述客户端信息安全装置通过计算机发送的经过加密或数字签名后的交易数据以及用户音频确认信息;The data receiving unit is configured to receive encrypted or digitally signed transaction data and user audio confirmation information sent by the client information security device through a computer; 所述第二存储单元,用于存储用户账户信息、用户的音频确认信息、用户交易数据、用于与所述客户端信息安全装置进行密钥协商过程中的相关数据和密钥协商算法;The second storage unit is used to store user account information, user audio confirmation information, user transaction data, relevant data and key agreement algorithm used in the key agreement process with the client information security device; 所述解密单元,用于对经过所述加密或数字签名后的交易数据进行解密;The decryption unit is configured to decrypt the encrypted or digitally signed transaction data; 所述交易执行单元,用于解密后的数据内容执行最终的交易操作。The transaction execution unit is used to execute the final transaction operation on the decrypted data content. 6.一种增强网上银行交易安全性的方法,其特征在于,具体包括以下步骤:6. A method for enhancing the security of online banking transactions, characterized in that it specifically comprises the following steps: 步骤A:信息安全装置与计算机建立连接,所述计算机接收所述用户输入的数据并将所述数据传输至所述信息安全装置;Step A: the information security device establishes a connection with the computer, and the computer receives the data input by the user and transmits the data to the information security device; 步骤B:所述信息安全装置接收到所述计算机传输来的交易数据后,对所述交易数据进行数模转换,并通过音频播放的方式输出所述交易数据;Step B: After receiving the transaction data transmitted by the computer, the information security device performs digital-to-analog conversion on the transaction data, and outputs the transaction data through audio playback; 步骤C:所述信息安全装置等待接收所述用户确认信息,在确认交易数据无误后,所述用户通过音频输入的方式向所述信息安全装置发送执行所述交易的命令;Step C: the information security device waits to receive confirmation information from the user, and after confirming that the transaction data is correct, the user sends an order to execute the transaction to the information security device through audio input; 步骤D:所述信息安全装置接收到所述用户输入的音频确认信息,通过声纹识别对所述用户进行身份认证和解析,认证成功后,执行相应操作。Step D: The information security device receives the audio confirmation information input by the user, authenticates and analyzes the identity of the user through voiceprint recognition, and executes corresponding operations after successful authentication. 7.根据权利要求6所述的一种增强网上银行交易安全性的方法,其特征在于,所述步骤D还包括:7. A kind of method for enhancing online banking transaction security according to claim 6, is characterized in that, described step D also comprises: D1:所述信息安全装置内部对所述交易数据和所述用户输入的音频信息进行数字签名或加密并发送;D1: The information security device internally digitally signs or encrypts the transaction data and the audio information input by the user and sends them; D2:所述网上银行服务器端接收所述信息安全装置发送的经过数字签名或加密后的交易数据以及用户音频确认信息,对所述数据和音频确认信息进行解密并存储;D2: The online banking server receives the digitally signed or encrypted transaction data and user audio confirmation information sent by the information security device, and decrypts and stores the data and audio confirmation information; D3:所述网上银行服务器根据所述交易数据中的信息执行所述交易。D3: The online banking server executes the transaction according to the information in the transaction data. 8.根据权利要求6所述的一种增强网上银行交易安全性的方法,其特征在于,所述步骤D中,所述信息安全装置接收到所述用户音频确认信息,通过声纹识别对所述用户进行身份认证,具体包括:所述信息安全装置通过将接收到所述用户输入的音频确认信息后与其内部存储的合法用户的声纹模板信息进行比较,判断两者是否匹配,如果是,则认为所述用户身份合法,否则,认为所述用户身份不合法。8. A method for enhancing the security of online banking transactions according to claim 6, characterized in that, in the step D, the information security device receives the audio confirmation information of the user, and recognizes the user by voiceprint recognition. The user performs identity authentication, which specifically includes: the information security device compares the voiceprint template information of the legal user stored in the internally stored audio confirmation information after receiving the audio confirmation information input by the user, and judges whether the two match, and if so, Then, the user identity is considered legal; otherwise, the user identity is considered illegal. 9.根据权利要求6所述的一种增强网上银行交易安全性的方法,其特征在于,所述步骤D中,所述信息安全装置对所述用户输入的音频确认信息进行解析具体包括:对音频信号的预处理、特征提取、模式匹配,所述预处理包括预滤波、采样和量化、加窗、端点检测、预加重。9. A method for enhancing the security of online banking transactions according to claim 6, characterized in that, in the step D, the information security device analyzing the audio confirmation information input by the user specifically includes: Audio signal preprocessing, feature extraction, pattern matching, the preprocessing includes pre-filtering, sampling and quantization, windowing, endpoint detection, pre-emphasis. 10.根据权利要求6所述的一种增强网上银行交易安全性的方法,其特征在于,所述步骤B后还可执行以下操作:10. A method for enhancing the security of online banking transactions according to claim 6, characterized in that, after the step B, the following operations can also be performed: 步骤C′:所述信息安全装置等待接收所述用户通过音频输入的方式向所述信息安全装置发送以下操作命令:取消、结束任务、返回、向上翻页、或向下翻页、复读。Step C': The information security device waits for the user to send the following operation commands to the information security device through audio input: cancel, end task, return, turn page up or down, and repeat.
CN200810100872.XA 2008-02-25 2008-02-25 Method and system for enhancing internet bank trade security Expired - Fee Related CN101231737B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200810100872.XA CN101231737B (en) 2008-02-25 2008-02-25 Method and system for enhancing internet bank trade security

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200810100872.XA CN101231737B (en) 2008-02-25 2008-02-25 Method and system for enhancing internet bank trade security

Publications (2)

Publication Number Publication Date
CN101231737A true CN101231737A (en) 2008-07-30
CN101231737B CN101231737B (en) 2014-06-04

Family

ID=39898184

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200810100872.XA Expired - Fee Related CN101231737B (en) 2008-02-25 2008-02-25 Method and system for enhancing internet bank trade security

Country Status (1)

Country Link
CN (1) CN101231737B (en)

Cited By (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101907975A (en) * 2010-08-10 2010-12-08 北京握奇数据系统有限公司 USBKey and method for controlling same
CN101997995A (en) * 2009-08-26 2011-03-30 华为技术有限公司 User identity identification method and device as well as call center system
CN102098159A (en) * 2010-07-28 2011-06-15 胡旭光 Secret key device and method for mobile phone
CN102412968A (en) * 2011-10-17 2012-04-11 中金金融认证中心有限公司 System and method for realizing PKI application by audio interface switching USB protocol equipment
CN102457845A (en) * 2010-10-14 2012-05-16 阿里巴巴集团控股有限公司 Wireless service identity authentication method, equipment and system
CN101562525B (en) * 2009-04-30 2012-06-27 飞天诚信科技股份有限公司 Method, device and system for signature
CN101409622B (en) * 2008-11-26 2012-10-31 飞天诚信科技股份有限公司 Digital signing system and method
CN102904718A (en) * 2011-07-25 2013-01-30 付洪军 Audio communication based information security equipment and communication method thereof
CN103218565A (en) * 2012-10-24 2013-07-24 东信和平科技股份有限公司 Novel USB (universal serial bus) key and transaction method adopting same
CN103532916A (en) * 2012-07-05 2014-01-22 百度在线网络技术(北京)有限公司 Method for acquiring information through voice, mobile terminal and voice information system
CN103873154A (en) * 2012-12-13 2014-06-18 恒银金融科技有限公司 Method for data reception of mobile phone audio frequency digital signature apparatus
CN103973326A (en) * 2013-01-24 2014-08-06 国民技术股份有限公司 Sound card
CN104144049A (en) * 2014-03-11 2014-11-12 腾讯科技(深圳)有限公司 Encryption communication method, system and device
CN104168117A (en) * 2014-08-20 2014-11-26 中国农业银行股份有限公司苏州分行 Voice digital signature method
CN104243451A (en) * 2014-08-19 2014-12-24 天地融科技股份有限公司 Information interaction method and system and smart key equipment
CN104394123A (en) * 2014-11-06 2015-03-04 成都卫士通信息产业股份有限公司 A data encryption transmission system and method based on an HTTP
CN104422922A (en) * 2013-08-19 2015-03-18 中兴通讯股份有限公司 Method and device for realizing sound source localization by utilizing mobile terminal
CN104599667A (en) * 2015-01-16 2015-05-06 联想(北京)有限公司 Information processing method and electronic device
CN104660408A (en) * 2013-11-25 2015-05-27 国民技术股份有限公司 Security authentication method and device
CN104660407A (en) * 2013-11-25 2015-05-27 国民技术股份有限公司 Security authentication method and device
CN104734855A (en) * 2015-02-12 2015-06-24 天地融科技股份有限公司 Communication methods and system of intelligent secret key device and intelligent secret key device
CN107066424A (en) * 2015-10-22 2017-08-18 通用电气公司 For the System and method for for the risk for determining operation turbine
CN107368724A (en) * 2017-06-14 2017-11-21 广东数相智能科技有限公司 Anti- cheating network research method, electronic equipment and storage medium based on Application on Voiceprint Recognition
CN107895256A (en) * 2017-11-08 2018-04-10 平安科技(深圳)有限公司 Bank account cancel loss report method for processing business, system, terminal and storage medium
CN110751947A (en) * 2018-11-13 2020-02-04 北京嘀嘀无限科技发展有限公司 Method for prompting user, electronic equipment and computer readable storage medium

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1905445B (en) * 2005-07-27 2012-02-15 国际商业机器公司 System and method of speech identification using mobile speech identification card
CN1815484A (en) * 2006-03-06 2006-08-09 覃文华 Digitalized authentication system and its method
CN100470572C (en) * 2007-01-08 2009-03-18 北京飞天诚信科技有限公司 Method and device for improving data input security

Cited By (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101409622B (en) * 2008-11-26 2012-10-31 飞天诚信科技股份有限公司 Digital signing system and method
CN101562525B (en) * 2009-04-30 2012-06-27 飞天诚信科技股份有限公司 Method, device and system for signature
CN101997995A (en) * 2009-08-26 2011-03-30 华为技术有限公司 User identity identification method and device as well as call center system
CN102098159A (en) * 2010-07-28 2011-06-15 胡旭光 Secret key device and method for mobile phone
CN101907975A (en) * 2010-08-10 2010-12-08 北京握奇数据系统有限公司 USBKey and method for controlling same
CN102457845A (en) * 2010-10-14 2012-05-16 阿里巴巴集团控股有限公司 Wireless service identity authentication method, equipment and system
CN102904718A (en) * 2011-07-25 2013-01-30 付洪军 Audio communication based information security equipment and communication method thereof
CN102412968A (en) * 2011-10-17 2012-04-11 中金金融认证中心有限公司 System and method for realizing PKI application by audio interface switching USB protocol equipment
CN103532916A (en) * 2012-07-05 2014-01-22 百度在线网络技术(北京)有限公司 Method for acquiring information through voice, mobile terminal and voice information system
CN103532916B (en) * 2012-07-05 2017-04-05 百度在线网络技术(北京)有限公司 Method, mobile terminal and the voice message system of information are obtained by voice
CN103218565A (en) * 2012-10-24 2013-07-24 东信和平科技股份有限公司 Novel USB (universal serial bus) key and transaction method adopting same
CN103873154A (en) * 2012-12-13 2014-06-18 恒银金融科技有限公司 Method for data reception of mobile phone audio frequency digital signature apparatus
CN103973326A (en) * 2013-01-24 2014-08-06 国民技术股份有限公司 Sound card
CN103973326B (en) * 2013-01-24 2016-06-01 国民技术股份有限公司 A kind of audio card
CN104422922A (en) * 2013-08-19 2015-03-18 中兴通讯股份有限公司 Method and device for realizing sound source localization by utilizing mobile terminal
CN104660408A (en) * 2013-11-25 2015-05-27 国民技术股份有限公司 Security authentication method and device
CN104660407A (en) * 2013-11-25 2015-05-27 国民技术股份有限公司 Security authentication method and device
US10412061B2 (en) 2014-03-11 2019-09-10 Tencent Technology (Shenzhen) Company Limited Method and system for encrypted communications
CN104144049B (en) * 2014-03-11 2016-02-17 腾讯科技(深圳)有限公司 A kind of encryption communication method, system and device
CN104144049A (en) * 2014-03-11 2014-11-12 腾讯科技(深圳)有限公司 Encryption communication method, system and device
US10164949B2 (en) 2014-03-11 2018-12-25 Tencent Technology (Shenzhen) Company Limited Method and system for encrypted communications
CN104243451A (en) * 2014-08-19 2014-12-24 天地融科技股份有限公司 Information interaction method and system and smart key equipment
CN104243451B (en) * 2014-08-19 2018-04-13 天地融科技股份有限公司 A kind of information interacting method, system and intelligent cipher key equipment
CN104168117B (en) * 2014-08-20 2018-11-27 中国农业银行股份有限公司苏州分行 A kind of speech digit endorsement method
CN104168117A (en) * 2014-08-20 2014-11-26 中国农业银行股份有限公司苏州分行 Voice digital signature method
CN104394123A (en) * 2014-11-06 2015-03-04 成都卫士通信息产业股份有限公司 A data encryption transmission system and method based on an HTTP
CN104599667A (en) * 2015-01-16 2015-05-06 联想(北京)有限公司 Information processing method and electronic device
CN104599667B (en) * 2015-01-16 2019-03-08 联想(北京)有限公司 Information processing method and electronic equipment
CN104734855A (en) * 2015-02-12 2015-06-24 天地融科技股份有限公司 Communication methods and system of intelligent secret key device and intelligent secret key device
CN107066424A (en) * 2015-10-22 2017-08-18 通用电气公司 For the System and method for for the risk for determining operation turbine
CN107066424B (en) * 2015-10-22 2021-11-30 通用电气公司 System and method for determining risk of operating a turbomachine
CN107368724A (en) * 2017-06-14 2017-11-21 广东数相智能科技有限公司 Anti- cheating network research method, electronic equipment and storage medium based on Application on Voiceprint Recognition
CN107895256A (en) * 2017-11-08 2018-04-10 平安科技(深圳)有限公司 Bank account cancel loss report method for processing business, system, terminal and storage medium
WO2019091000A1 (en) * 2017-11-08 2019-05-16 平安科技(深圳)有限公司 Bank account report/unlock service processing method, system, terminal, and storage medium
CN110751947A (en) * 2018-11-13 2020-02-04 北京嘀嘀无限科技发展有限公司 Method for prompting user, electronic equipment and computer readable storage medium
CN110751947B (en) * 2018-11-13 2021-05-07 北京嘀嘀无限科技发展有限公司 Method for prompting user, electronic equipment and computer readable storage medium

Also Published As

Publication number Publication date
CN101231737B (en) 2014-06-04

Similar Documents

Publication Publication Date Title
CN101231737A (en) A system and method for enhancing the security of online banking transactions
CN113168437B (en) Voice authentication
US8812319B2 (en) Dynamic pass phrase security system (DPSS)
Liu et al. An MFCC‐based text‐independent speaker identification system for access control
CN104217149B (en) Biometric authentication method and equipment based on voice
CN105913850B (en) Text correlation vocal print method of password authentication
US20030200447A1 (en) Identification system
US20190238535A1 (en) Voiceprint security with messaging services
CN105933272A (en) Voiceprint recognition method capable of preventing recording attack, server, terminal, and system
Saquib et al. A survey on automatic speaker recognition systems
US20230290354A1 (en) Systems and apparatus for multifactor authentication using bone conduction and audio signals
Chang et al. My voiceprint is my authenticator: A two-layer authentication approach using voiceprint for voice assistants
Saquib et al. Voiceprint recognition systems for remote authentication-a survey
CN112201254B (en) Non-inductive voice authentication method, device, equipment and storage medium
US20130339245A1 (en) Method for Performing Transaction Authorization to an Online System from an Untrusted Computer System
Zhang et al. Volere: Leakage resilient user authentication based on personal voice challenges
Kuznetsov et al. Methods of countering speech synthesis attacks on voice biometric systems in banking
VS et al. A review of automatic speaker verification systems with feature extractions and spoofing attacks
CN107454044A (en) A kind of e-book reading protection of usage right method and system
Sigona Voice biometrics technologies and applications for healthcare: an overview
Chen et al. Personal threshold in a small scale text-dependent speaker recognition
Can et al. A Review of Recent Machine Learning Approaches for Voice Authentication Systems
US20250005123A1 (en) System and method for highly accurate voice-based biometric authentication
US20250046317A1 (en) Methods and systems for authenticating users
EP4506838A1 (en) Methods and systems for authenticating users

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C53 Correction of patent of invention or patent application
CB02 Change of applicant information

Address after: 100085 Beijing city Haidian District Xueqing Road No. 9 Ebizal building B block 17 layer

Applicant after: Feitian Technologies Co.,Ltd.

Address before: 100083, Haidian District, Xueyuan Road, No. 40 research, 7 floor, 5 floor, Beijing

Applicant before: FEITIAN TECHNOLOGIES Co.,Ltd.

COR Change of bibliographic data

Free format text: CORRECT: APPLICANT; FROM: BEIJING FEITIAN CHENGXIN TECHNOLOGY CO., LTD. TO: FEITIAN TECHNOLOGIES CO., LTD.

C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20140604