Background technology
In recent years, online payment industry presents strong growth.The Ai Rui of mechanism seeks advice from the data of issue according to investigations, and domestic online payment industry size will reach 5,766 hundred million yuan in 2009, and be expected to reach 1 trillion yuan in 2010, and the online payment market outlook are very wide.Online payment greatly facilitates users, and the field of application comprises shopping online, online ticketing service, network manages money matters, donates on the net and public utilities is paid the fees etc.
Web bank as one of online transaction form of payment, provide to the client by Internet open an account, cancellation, inquiry, reconciliation, transfer accounts, traditional services project such as credit, Investment ﹠ Financing, emerging financial IC card business such as simultaneously can also realize paying the fees, on-line payment, stored value card (or electronic bankbook or electronic cash) circle are deposited, the fund that makes that the client is can be in 24 hours random times home-confined in just can safe and convenient ground management bank.
And meanwhile, all kinds of fishing websites, Malware also emerge in an endless stream, and payment has proposed great challenge and a difficult problem to secure network.The present major part of each big bank of China's Mainland is to adopt to give or go out a spot of expense to allow the client buy Net silver U shield, and when needs were paid, the prompting client inserted the U shield, and inputs correct U shield password and just can carry out the network payment activity.So, though improved the security of network payment greatly, but reliability and the security of U shield itself become new problem again, in case malicious user obtains other people U shield, be not difficult to crack out user key and all kinds of sensitive information, along with the development of technology, the EMV of bank card migration is also being accelerated propelling.Have the network payment equipment that are placed in family and the personal user's hand from now on occurs more, because the secure payment terminal is generally bank or other professional institutions provide, extremely important key and individual client's information have been preserved in inside, once obtained by the malice crowd, will cause great economic loss;
In addition; traditional anti-broken means of attacking are nothing but the complexities that structurally increases shell; perhaps utilize more solid material to make shell; such means are for this common location that is placed on of ATM; and the occasion of supporting various surveillance equipments is comparatively effective; in case having the people to break attacks; then there are security personnel and public security organ to participate in stoping immediately; but the utility model at be to be placed on the occasion that family or individual use; be difficult to the participation of security personnel and public security organ; in this state, key and the sensitive information of protection validated user are had higher requirement to equipment itself.And the utility model produces in order to address this problem just.
Under this background, design a kind of device that improves this type of device interior sensitive information safety and just seem most important.
The utility model content
Technical problem to be solved in the utility model provides a kind of data self-desttruction equipment of uncapping of secure payment terminal, this secure payment terminal uncap that the data self-desttruction equipment is easy to implement, safe, cost is low.
The technical solution of utility model is as follows:
A kind of data self-desttruction equipment of uncapping of secure payment terminal comprises microprocessor, storer and at least 2 contact points; The position corresponding with contact point scribbles conducting resinl on the fore shell of secure payment terminal and back cover;
Described contact point comprises two mutual disjunct pads; First pad ground connection of each contact point, second pad of each contact point connects positive source by first pull-up resistor (R11); Described second pad connects the first external interrupt port (Kdetect end) of microprocessor; Store memory contains the key for financial payment.
The data self-desttruction equipment of uncapping of described secure payment terminal also comprises at least one photosensitive tube testing circuit;
Described photosensitive tube testing circuit comprises photosensitive tube and N-MOS pipe (Q1); Photosensitive tube is made up of diode and triode (NPN triode); The positive pole of diode connects the positive pole of direct supply by second pull-up resistor (R3); The minus earth of diode;
The C utmost point of triode connects the positive pole of direct supply by the 3rd pull-up resistor (R2); The E utmost point of triode connects the G utmost point of N-MOS pipe; The E utmost point of triode is also through the 5th resistance (R4) ground connection; The D utmost point of N-MOS pipe connects the positive pole of direct supply through the 4th pull-up resistor (R1); The S utmost point ground connection of N-MOS pipe; The D utmost point of N-MOS pipe also joins with the second external interrupt port (SENSOR end) of microprocessor.
In the secure payment terminal, also be provided with backup battery and backup battery electric weight testing circuit.
The method that this device is corresponding is:
Whether a kind of data self-destruction method of uncapping of secure payment terminal adopts the detection method detection secure payment terminal of uncapping based on conducting resinl to be opened;
The described detection method of uncapping based on conducting resinl refers in the front of the circuit board of secure payment terminal at least one contact point is set, and at the back side of the circuit board of secure payment terminal at least one contact point is set;
The position corresponding with contact point scribbles conducting resinl on the fore shell of secure payment terminal and back cover;
Described contact point comprises two mutual disjunct pads; When fore shell and back cover close (during normal condition), two pads of contact point are by the conducting resinl conducting, and this moment, contact point was conducting state; Otherwise when fore shell or back cover are opened, for opening circuit, this moment, contact point was off state between two pads of contact point;
If the microprocessor of secure payment terminal detects arbitrary contact point and is in off state, judge that then the protecgulum of secure payment terminal or bonnet are illegally opened, the microprocessor log-on data self-destruction operation in the secure payment terminal.
Whether the data self-destruction method of uncapping of described secure payment terminal also adopts the detection method detection secure payment terminal of uncapping based on Photoelectric Detection to be opened;
The described detection method of uncapping based on Photoelectric Detection is: be provided with photosensitive tube in the secure payment terminal; When the fore shell of secure payment terminal or back cover were opened, the state of photosensitive tube was by by becoming conducting; The microprocessor of secure payment terminal detects the state variation of photosensitive tube, then log-on data self-destruction operation.
Described timing microprocessor detects the electric weight of backup battery, if electric weight less than 15% of total electric weight, then microprocessor log-on data self-destruction operation.
Described data self-destruction operation comprises that automatic deletion is used for the key of financial payment.
Described data self-destruction operation also comprises " deadlock " state that makes the microprocessor of secure payment terminal enter.
Beneficial effect:
The data self-desttruction equipment of uncapping of secure payment terminal of the present utility model has shell and opens and break when attacking and to detect, and has mechanical key or button, when the be opened state of button then or button of shell namely is changed.And have and utilize light to change photosensitive tube as operation condition, in case shell is opened, then the photosensitive tube output state namely is changed, thus notice CPU learns that shell is opened or is attacked by broken.Learn by part 2 that equipment is opened or attacked by broken when equipment, can within 1 second, delete pass key-encrypting key and the sensitive data of inside.
The utility model utilizes the physical mechanical contact and uncaps the change of front and back light; whether the shell that can effectively detect equipment is opened or broken attacking; in case detect abnormality; then wake CPU at once up; and by pass key-encrypting key and all kinds of sensitive information removing of CPU with storage inside; and equipment entered software " locked " state; and before thoroughly exhausting, standby power supply can deletion close key-encrypting key; thereby effectively protected the sensitive information of validated user, potential destruction and stealer have been carried out effective strick precaution.
The utility model can adopt single protection mechanism (based on the protection mechanism of the detection method of uncapping of conducting resinl) or duplicate protection mechanism ((1) is based on the protection mechanism of the detection method of uncapping of conducting resinl and (2) protection mechanism based on the detection method of uncapping of Photoelectric Detection) or triple protection mechanism (namely increasing on the basis of duplicate protection based on the protection mechanism to the electric weight monitoring of backup battery) that the key message in the secure payment terminal is carried out omnibearing protection flexibly again, thereby improves the security of secure payment terminal.
The data self-desttruction equipment of uncapping of this secure payment terminal has improved traditional-family's e-Bank payment device ' significantly, can be widely used in the secure payment terminal of individual, family, trade company's use,
Embodiment
Below with reference to the drawings and specific embodiments the utility model is described in further details:
Embodiment 1:
A kind of data self-desttruction equipment of uncapping of secure payment terminal comprises microprocessor, storer and at least 2 contact points; Scribble conducting resinl (in other words: on the fore shell of secure payment terminal and back cover, be provided with the conduction rubber cushion with the corresponding position of contact point) in the position corresponding with contact point on the fore shell of secure payment terminal and the back cover;
Described contact point comprises two mutual disjunct pads; First pad of each contact point (i.e. first pad) ground connection, second pad of each contact point (i.e. second pad) draws electric positive R11 to connect positive source on first; Described second pad connects the first external interrupt port (Kdetect end) of microprocessor; Store memory contains the key for financial payment.
Fig. 2 is the circuit diagram that two contact points are detected.Each contact point just is equivalent to the switch (S1 or S2) among Fig. 2.
The data self-desttruction equipment of uncapping of secure payment terminal also comprises at least one photosensitive tube testing circuit; As shown in Figure 3.
Described photosensitive tube testing circuit comprises photosensitive tube and N-MOS pipe Q1; Photosensitive tube is made up of diode and triode (NPN triode); The positive pole of diode connects the positive pole of direct supply by the second pull-up resistor R3; The minus earth of diode;
The C utmost point of triode connects the positive pole of direct supply by the 3rd pull-up resistor R2; The E utmost point of triode connects the G utmost point of N-MOS pipe; The E utmost point of triode is also through the 5th resistance R 4 ground connection; The D utmost point of N-MOS pipe connects the positive pole of direct supply through the 4th pull-up resistor R1; The S utmost point ground connection of N-MOS pipe; The D utmost point of N-MOS pipe also joins with the second external interrupt port (SENSOR end) of microprocessor.
Also be provided with reserve battery and reserve battery electric weight testing circuit in the secure payment terminal, this part is existing mature technology.
Whether the data self-desttruction equipment of uncapping of secure payment terminal adopts the detection method detection secure payment terminal of uncapping based on conducting resinl to be opened; Referring to Fig. 4 and Fig. 5.
The described detection method of uncapping based on conducting resinl refers in the front of the circuit board of secure payment terminal at least one contact point is set, and at the back side of the circuit board of secure payment terminal at least one contact point is set; Circuit board comprises mainboard and keypad.
The position corresponding with contact point scribbles conducting resinl on the fore shell of secure payment terminal and back cover;
Described contact point comprises two mutual disjunct pads, as shown in Figure 6; When fore shell and back cover close (during normal condition), two pads of contact point are by the conducting resinl conducting, and this moment, contact point was conducting state; Otherwise when fore shell or back cover are opened, for opening circuit, this moment, contact point was off state between two pads of contact point;
If the microprocessor of secure payment terminal detects arbitrary contact point and is in off state, judge that then the protecgulum of secure payment terminal or bonnet are illegally opened, the microprocessor log-on data self-destruction operation in the secure payment terminal.
Also adopt the detection method detection secure payment terminal of uncapping based on Photoelectric Detection whether to be opened;
The described detection method of uncapping based on Photoelectric Detection is: be provided with photosensitive tube in the secure payment terminal; When the fore shell of secure payment terminal or back cover were opened, the state of photosensitive tube was by by becoming conducting; The microprocessor of secure payment terminal detects the state variation of photosensitive tube, then log-on data self-destruction operation.
Dependence diagram is with reference to Fig. 1.
Described timing microprocessor detects the electric weight of reserve battery, if electric weight less than 15% of total electric weight, then microprocessor log-on data self-destruction operation.
Described data self-destruction operation comprises that automatic deletion is used for the key of financial payment.
Described data self-destruction operation also comprises " deadlock " state that makes the microprocessor of secure payment terminal enter.
Specifically, the mechanism of uncap self-destruction key and critical data has comprised following 3 parts generally, and shell is opened or quilt is broken attacks in case detect, and then carries out the self-destruction action immediately.In case the reserve battery electric weight is about to exhaust, then carry out the self-destruction action immediately.
Part 1: standby power supply
Equipment at first must have reserce cell, this reserce cell is not powered to master cpu processor and monitoring module when equipment has external power supply, thereby the test section of the equipment of assurance and the normal operation of self-destruction partial circuit, this reserce cell needs to satisfy following two conditions at least:
1) chargeable
Battery can be recycled, when equipment inserts that external power source is normal and uses, can be to the action of charging of inner reserce cell, and the behavior safety that charges is reliable.
2) continue to use the date long
Reserce cell can use separately more than 3 years at least.(only supplying CPU and detection module).Can guarantee in the long time that so just CPU detects the shell state by detection module.
Take all factors into consideration, equipment must carry above lighium polymer rechargeable battery or a chargeable lithium button cell of 260mAH at least, can satisfy us to the demand of reserve battery.The lithium polymer battery charging is safe and reliable, and self-discharge rate is low.Be full of once electricity, can satisfy the testing time of equipment more than 3 years.
Part 2: detect the means of uncapping
The means that detection is uncapped are preconditions of self-destruction sensitive information and key, have only correct, sensitive detecting shell is opened or brokenly attack self-destruction two kinds of detection modes are arranged, and dual mode complements each other, and are jointly uncapped in the outside and broken the attacking of malice detected.
(1) equipment designs two contact points respectively at protecgulum and bonnet, the shell place of contact point top opposite position leaves conducting resinl, have when equipment closes and cover and accomplish fluently screw, then the conducting resinl at shell place is by tightly pressing, please referring to accompanying drawing two, this contact point by the state of conducting resinl pressing under, the CPU pin senses to level be low level.Can determine, when shell is in closure state always, the detection pin detects always and is low level, in this case, for power saving, CPU is in dormant state always, power consumption is at microampere order, prolong the service time of back-up source to greatest extent, in case shell is illegally opened by external force, the electric silica gel on the shell leaves the contact, can produce one from the low rising edge external interrupt wakeup CPU that uprises and notify the CPU shell to be opened at the detection pin, this detection means simple structure, cost is low, and difficulty of processing is low, can tackle the conventional shell means of tearing open, as: normally the equipment screw is opened, protecgulum or bonnet are taken away, just can detect very easily in this way and uncap.If but potential malicious persons is through groping after a while, after perhaps tearing several equipment open, found the position of electric silica gel, so, can tear tractor driver's section normally open fully, and then with broken mode of attacking, just can directly avoid the detection of uncapping of this mode such as above chip, directly opening " skylight ".In this case, in order effectively to survey the outside the broken of equipment attacked, it is just necessary that equipment increases the detection means 2 of uncapping simultaneously.
(2) since sensitive information and master control key be positioned within the safety chip; in order to protect near the shell the safety chip can effectively be detected after attacking by malice is broken; introduce photosensitive tube (SG-2BC); photosensitive tube always has 4 pin; inside is equivalent to have a photosensitive diode and a triode; please referring to accompanying drawing three; its principle is: the photodiode pin of photosensitive tube inside has the power supply supply; and when the light irradiation is arranged; control inner triode saturation conduction; when not having the light irradiation; triode is cut-off state; owing to introduced photosensitive tube; when shell is attacked when opening by malice is broken; device interior has light state from unglazed becoming; the photosensitive tube state changes; thereby cause that triode becomes conducting state from cut-off state in the photosensitive tube; the grid of outside Q1N-MOS pipe is at ordinary times owing to ending of triode keeps low level; Q1 is cut-off state; triode in photosensitive tube becomes conducting state from ending; can introduce a high level by Q1N-MOS tube grid externally; make Q1N-MOS become conducting state from ending; so just can become low level to the level that CPU surveys on the SENSOR pin from high level; thereby in the external interrupt that produces a negative edge; this interruption will wake dormant CPU up, be attacked by malice is broken thereby allow CPU detect shell.
Part 3: self-destruction
When CPU is known by the detection means of part 2 that present shell has been opened or attacked by broken, effective or electric power is sufficient as the standby power supply of fruit part 1, equipment enters duty immediately, (less than 1 second) deletes the pass key-encrypting key of its storage inside in the extremely short time, customer information, bank's private information, transaction record and other sensitive information, and in program, enter " deadlock " state, namely to any normal instruction in outside, the state that operation is not all responded, (chip itself does not have the hardware locking state, realize by software, in fact just in software, add a zone bit, if enter " deadlock ", in software is handled, just no longer comprehend any external command so), if having human-computer interaction interface such as display screen, then prompting, equipment is self-destruction, please return factory and office's reason.The equipment master cpu has AD measuring ability and time clock feature, can start an AD measuring ability every 1 day the standby power supply electric weight of part 1 is done one-time detection, if having approached, electric weight exhausts (less than 15% electric weight), prove that so the user had not used this equipment or frequency of utilization extremely to hang down near 3 years and caused the back-up source electric weight to exhaust, CPU directly deletes key and enters software " deadlock " state after with self-starting so, after preventing that back-up source because of part 1 from thoroughly not having electricity, all self check measures were lost efficacy.Reveal client's crucial sensitive information and key.
When equipment has carried out the self-destruction operation, the client has only the bank that returns delivery apparatus again, burned key and all kinds of sensitive information again, and utilize special instrument to withdraw from software " deadlock " state by equipment, could continue to use.
The secure payment terminal has the equipment backup battery, and backup battery adopts lithium polymer battery or lithium button cell.After backup battery is full of electricity, but continuous working (only supplied CPU and detection module) more than 3 years.
Have the silica gel push-button that is associated with shell and printed board copper foil circuit etc. on the circuit board of secure payment terminal.In case protecgulum or the bonnet of shell are opened, this type of on-off circuit will produce level to be changed, thereby wakes CPU deletion key up.
In case the backup battery electric weight is lower than to a certain degree, then the secure payment terminal is deleted responsive key and data automatically, in order to avoid after backup battery thoroughly exhausted, every detection means can't be carried out, thereby causes sensitive information to be revealed.