Detailed description of the invention
Below in conjunction with the accompanying drawing in the embodiment of the present invention, the technical scheme in the embodiment of the present invention is clearly and completely described, it is clear that retouchedThe embodiment stated is only a part of embodiment of the present invention rather than whole embodiments.Based on embodiments of the invention, ordinary skill peopleThe every other embodiment that member is obtained under not making creative work premise, broadly falls into protection scope of the present invention.
In describing the invention, it is to be understood that term " " center ", " longitudinally ", " laterally ", " on ", D score, "front", "rear", " left ",The orientation of the instruction such as " right ", " vertically ", " level ", " top ", " end ", " interior ", " outward " or position relationship are to close based on orientation shown in the drawings or positionSystem, be for only for ease of describe the present invention and simplifying describe rather than instruction or the hint device of indication or element must have specific orientation, withSpecific azimuth configuration and operation, be therefore not considered as limiting the invention.Additionally, term " first ", " second " are only used for describing purpose,And it is not intended that indicate or imply relative importance or quantity or position.
In describing the invention, it should be noted that unless otherwise clearly defined and limited, term " is installed ", " being connected ", " connection " should doBroadly understood, connect for example, it may be fixing, it is also possible to be to removably connect, or be integrally connected;Can be to be mechanically connected, it is also possible to be electricityConnect;Can be to be joined directly together, it is also possible to be indirectly connected to by intermediary, can be the connection of two element internals.Common for this areaFor technical staff, above-mentioned term concrete meaning in the present invention can be understood with concrete condition.
Below in conjunction with accompanying drawing, the embodiment of the present invention is described in further detail.
The invention provides the framework of a kind of data interaction, both facilitate user to carry to provide, and the trading solution that safety is higher.These dataInterworking architecture includes: simulation card, cutting ferrule and Truth cards manager.
Wherein:
Simulation card, can include one or more, and this simulation card can be that separately fabricated card can also be for being reserved with simulation card functionTruth cards.This simulation card is identical with existing bank card dimensions, in notebook data interworking architecture, substitutes Truth cards and completes transaction.SimulationCard has contact and/or non-contact interface, in order to coordinate existing transaction terminal (such as ATM, POS, mass transit card top-up machines etc.)Complete transaction.Simulation card also has wave point, and simulation card can carry out data interaction by this wave point and cutting ferrule.Wherein, contactInterface can be contact etc., and non-contact interface can be NFC interface etc., and this wave point can be blue tooth interface, infrared interface, 2.4GHzInterface, WIFI interface, RFID interface etc..
Cutting ferrule, can include one or more cutting ferrule, and this cutting ferrule can manage one or more simulation card, and every simulation card can only belong to oneIndividual cutting ferrule is also managed by it.This cutting ferrule can be the separately fabricated equipment for card envelope shape, it is also possible to for having the card provided in notebook data frameworkThe mobile device of set function, including: smart mobile phone, panel computer (PAD), PDA (such as palm PC, learning machine), notebook computer,E-book reading device, wearable device (such as intelligent wristwatch, intelligent glasses etc.) etc..Cutting ferrule can have contact and/or non-contact interface,To coordinate the contact of simulation card and/or non-contact interface to carry out data interaction, cutting ferrule can also have wave point, in order to wireless by thisInterface carries out data interaction with the simulation corresponding interface of card, and wherein, contact interface can be contact etc., and non-contact interface can be NFCInterface etc., this wave point can be blue tooth interface, infrared interface, 2.4GHz interface, WIFI interface, RFID interface etc.;Cutting ferrule also has netNetwork interface, in order to carrying out data interaction by this network interface network interface corresponding with Truth cards manager, wherein, this network interface can beWIFI interface, mobile interchange network interface (such as 3G, 4G network) etc..It addition, cutting ferrule can also be the group of mobile device and electronic signature equipmentClosing, wherein the network interface of cutting ferrule realizes by means of the network interface of mobile device, other interfaces (such as wave point, contact and/or noncontactFormula interface etc.) can be respectively positioned in electronic signature equipment, or these other interfaces can also be respectively positioned in mobile device, or in the middle part of these other interfacesTap mouth is positioned in electronic signature equipment, and part of interface is positioned in mobile device;The process operation that cutting ferrule performs all performs in electronic signature equipment;Cutting ferrule can moreover be only electronic signature equipment.Wherein, electronic signature equipment can be key equipment, such as industrial and commercial bank's U-shield, and agricultural bank K is precious.
Truth cards manager, can manage multiple cutting ferrule, and this Truth cards manager have multiple contact (such as draw-in groove etc.) interface and/Or contactless (such as NFC etc.) interface, to facilitate Truth cards manager can connect different types of Truth cards by different modes,Wherein, Truth cards manager is connected with at least one Truth cards, and storage has Truth cards manager end Truth cards information list, trulyCard management device end Truth cards information list includes the Truth cards information of the Truth cards being connected with Truth cards manager, this Truth cards informationMay include that the information such as card number, card authentication information, this card authentication information is whether certification Truth cards is regular channel (such as bank, public affairsHand over to the collective or the state department etc.) card image issued;This Truth cards can be function card (such as mass transit card, mess card, purchase card, member card, accumulating card etc.)Or the bank card that bank issues;Optionally, what Truth cards manager could be arranged to preserve in connected Truth cards is all or part of trueThe Truth cards information of real card, in order to user makes different setting according to the security requirement of Truth cards, such as, can manage at Truth cardsThe Truth cards information not allowing to obtain some Truth cards is set on device, thus ensures the safety of these Truth cards.Truth cards manager is alsoThere is network interface, in order to carrying out data interaction by this network interface network interface corresponding with cutting ferrule, wherein, this network interface can be WIFIInterface, mobile interchange network interface (such as 3G, 4G network) etc..
In notebook data interworking architecture, simulation card and Truth cards are smart chip card.
Hereinafter, the term in the present invention is illustrated:
First process includes: encryption, and the second process includes: decryption processing;Specifically, simple encryption ensures data transmission security, is treatingWhen transmission data security levels requires higher, can process to use this kind of mode.Or
First process includes: verification calculating processes, and the second process includes: verification verifies that calculating processes;Specifically, simple verification ensures data transmissionIntegrity, prevents from distorting, and when treating integrity of data transmission requirement and being higher, can process to use this kind of mode.Or
First process includes: encrypts and verifies calculating and process, and the second process includes: deciphers and verifies checking calculating and process.Specifically, encryption is usedEnsure data transmission security and complete with verification hybrid mode, when data security levels to be transmitted is required the highest, can carry out to use this kind of modeProcess.
Based on above-mentioned data interaction framework, the present invention provides a kind of data interaction system, by this data interaction system, it is possible to achieve simulation card,Data interaction between cutting ferrule and Truth cards manager, to provide a kind of novel user that both facilitates to carry, and the transaction solution party that safety is higherCase.
Fig. 1 shows the structural representation of the data interaction system that the embodiment of the present invention provides, and sees Fig. 1, the data interaction system of the present invention, bagInclude: simulation card, cutting ferrule and Truth cards manager;
Cutting ferrule, for performing bindings with simulation card, and performs bindings, wherein, Truth cards manager with Truth cards managerIt is connected with at least one Truth cards, and storage has Truth cards manager end Truth cards information list, Truth cards manager end Truth cardsInformation list includes the Truth cards information of the Truth cards being connected with Truth cards manager;With simulation card set up secure connection, it is thus achieved that cutting ferrule withCarry out cutting ferrule end the first safe transmission key of Security Data Transmission between simulation card, and set up secure connection with Truth cards manager, it is thus achieved thatCutting ferrule end the second safe transmission key of Security Data Transmission is carried out between cutting ferrule and Truth cards manager;
Simulation card, for setting up secure connection with cutting ferrule, it is thus achieved that carries out the analog card bit end safety of Security Data Transmission between cutting ferrule and simulation cardTransmission key;
Truth cards manager, for setting up secure connection with cutting ferrule, it is thus achieved that carry out the true of Security Data Transmission between cutting ferrule and Truth cards managerReal card management device end safe transmission key;
Cutting ferrule, is additionally operable to obtain cutting ferrule end Truth cards information list;Prompting cutting ferrule end Truth cards information list;Receive Truth cards and select instruction,Determining the Truth cards chosen, wherein, cutting ferrule end Truth cards information list is that the Truth cards manager end obtained from Truth cards manager is trueReal card image list;
Simulation card, is additionally operable to receive the data that transaction terminal sends, and the data utilizing analog card bit end safe transmission double secret key to receive carry out theSend to cutting ferrule after one process;
Cutting ferrule, is additionally operable to receive the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive is carried out at secondAfter reason, the data after utilizing cutting ferrule end the second safe transmission double secret key second to process send to true card management device after carrying out the first process;
Truth cards manager, is additionally operable to receive the data that cutting ferrule sends, and utilizes the number that Truth cards manager end safe transmission double secret key receivesSend to the Truth cards chosen according to after carrying out the second process;Receive the data that the Truth cards chosen sends, and utilize Truth cards manager end to pacifyThe data that full transmission double secret key receives send to cutting ferrule after carrying out the first process, and wherein, the Truth cards chosen receives Truth cards manager end and sends outThe data sent, and the data transmission that will obtain after processing after processing is to true card management device;
Cutting ferrule, is additionally operable to receive the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive is carried outAfter second processes, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card, is additionally operable to receive the data that cutting ferrule sends, and the data utilizing analog card bit end safe transmission double secret key to receive is carried out at secondSend to transaction terminal after reason.
Hereinafter, for above-mentioned data interaction system, being described in detail, specifically, this data interaction system can comprise the following aspects:
One, binding:
1, cutting ferrule and simulation card execution bindings:
In the present invention, cutting ferrule can be bound in the following way with simulation card:
Cutting ferrule and simulation card mutual authentication the other side's certificate and the other side's identity, and after all certification is passed through both sides, each it is stored in verification process generationBinding factor.
Below, it is provided that a kind of cutting ferrule and the specific implementation simulating card execution bindings:
Fig. 2 shows that the data interaction system that the embodiment of the present invention provides realizes the flow chart of cutting ferrule and simulation card execution bindings, sees Fig. 2,Cutting ferrule performs bindings with simulation card and includes:
Cutting ferrule receives for indicating and simulate the trigger command that card carries out binding;Specifically, before cutting ferrule uses, can in advance cutting ferrule be performedPower-on operation, now, optionally, cutting ferrule prompting user inputs startup password, and receives the startup password that user inputs, opening of checking user's inputThe correctness of secret code, after the startup password of checking user's input is correct, performs power-on operation, and card covers into mode of operation.Use cutting ferrule withBefore simulation card carries out data interaction, optionally, cutting ferrule is bound with simulation card, the safety mutual to improve follow-up data.Wherein,What cutting ferrule received can be to be provided separately within the binding physical button generation that card puts for the trigger command indicating cutting ferrule and simulation card to carry out binding, or can be that the binding virtual key on the touch screen of cutting ferrule generates, or can be that start-up password verification generates the most afterwards, or permissibleFor generate after simulation card is inserted into cutting ferrule, or can be the menu of display to select binding function to generate on cutting ferrule screen, certainly,Can also generate for other any modes, the most not be restricted.
Cutting ferrule sends the first binding instruction to simulation card, and wherein, the first binding instruction includes: the first binding random factor, cutting ferrule that cutting ferrule generatesCertificate and cutting ferrule uniquely identify;Specifically, cutting ferrule can connect (by contact interface) to simulation card transmission the first binding by contactInstruction, cutting ferrule can also send the first binding instruction by contactless connection (by non-contact interface or wave point) to simulation card,The former can improve binding safety, and the latter can improve binding convenience.The first binding random factor is carried in first binding instruction and is possible to prevent weightPut attack, cutting ferrule certificate is carried in the first binding instruction so that cutting ferrule is authenticated by simulation card, cutting ferrule is carried in the first binding instruction and uniquely identifiesSo that simulation card knows which cutting ferrule is bound with it;Wherein, first binding random factor can be cutting ferrule generation random number, random character or itsCombination, certainly, after generating the first binding random factor, it is also possible to verify the randomness of the first binding random factor, tie up improving firstDetermine the randomness of random factor, prevent from being cracked;Cutting ferrule uniquely identify can be cutting ferrule serial number, EIC equipment identification code, MAC Address etc. arbitrary orA combination thereof is with unique mark identifying cutting ferrule.
Simulation card receives the first binding instruction, utilizes root certificate to verify cutting ferrule certificate;Specifically, simulation card prestores root certificate,This root certificate is utilized to complete the checking to cutting ferrule certificate, to ensure the safety of follow-up use cutting ferrule certificate.
After simulation card checking cutting ferrule certificate is legal, generate the second binding random factor;Specifically, the second binding random factor can be analog card sheetRandom number, random character or a combination thereof generated;Certainly, generate second binding random factor after, it is also possible to second binding random factor withMachine is verified, to improve the randomness of the second binding random factor, prevents from being cracked.
Simulation card utilizes the cutting ferrule PKI in cutting ferrule certificate that the first binding random factor and the second binding random factor are encrypted acquisition firstBinding ciphertext, utilizes simulation card private key that the first binding random factor and the second binding random factor are carried out signature and obtains the first binding signature;ToolBody ground, simulation card utilize cutting ferrule PKI be encrypted to ensure to the first binding random factor and the second binding random factor the first binding random because ofSon and second binding random factor transmission safety, simulation card utilize simulation card private key to first binding random factor and second binding withThe machine factor is signed, to ensure that the legitimacy of simulation card identity can be authenticated by follow-up cutting ferrule.
Simulation card sends the first binding response to cutting ferrule, and wherein, the first binding response includes: the first binding ciphertext, the first binding signature, simulationCard certificate and simulation card uniquely identify;Specifically, the first binding response that simulation card sends is carried simulation card certificate so that cutting ferrule pairSimulation card is authenticated, and carries simulation card and uniquely identify so that cutting ferrule knows which simulation card is bound with it in the first binding response;Wherein,It can be that analog card sheet serial number, EIC equipment identification code, MAC Address etc. are arbitrary or a combination thereof is with unique mark simulation card that simulation card uniquely identifiesMark.
Cutting ferrule receives the first binding response, utilizes root certificate to verify simulation card certificate;Specifically, cutting ferrule prestores root certificate, utilizesThis root certificate completes the checking to simulation card certificate, to ensure the follow-up safety using simulation card certificate.
After cutting ferrule checking simulation card certificate is legal, utilize cutting ferrule private key that the first binding ciphertext is decrypted, it is thus achieved that the first binding decryption random factorWith the second binding decryption random factor;Specifically, cutting ferrule private key is utilized to be decrypted, the first binding ciphertext if there occurs number in the data transmissionAccording to error of transmission, or there occurs in the data transmission and distort, then will cause cannot successful decryption, or the first binding decryption random decrypted because ofSon and the second binding decryption random factor are different from the first binding random factor and the second binding random factor.And added by cutting ferrule PKIClose, only cutting ferrule private key can be with successful decryption, thus it is also ensured that the safety of data deciphering.
Cutting ferrule utilizes the simulation card PKI in simulation card certificate, the first binding decryption random factor and the second binding decryption random factor pair firstBinding signature is verified;Specifically, the signature that cutting ferrule utilizes the simulation card PKI after being verified to send simulation card is verified, with reallyProtect the legitimate origin of data.
After cutting ferrule checking the first binding signature is correct, checking the first binding decryption random factor is the most identical with the first binding random factor;Specifically,The first binding random factor and the first binding decryption random factor that cutting ferrule checking generates self are identical, it is ensured that data are also not tampered with, and encryptionData Source really for cutting ferrule send first binding random factor object.
After cutting ferrule checking the first binding decryption random factor is identical with the first binding random factor, prompting simulation card uniquely identifies;Specifically, cutting ferruleCan show that simulation card uniquely identifies, it is also possible to speech play (such as loudspeaker are play or by headset earpiece broadcasting etc.) simulation card is uniquely markedKnow, in order to the verity of simulation card is confirmed by user, improve binding safety.
Cutting ferrule receives for confirming that simulating card uniquely identifies correct trigger command, utilizes cutting ferrule private key to tie up the first binding random factor and secondDetermine the decryption random factor to sign, it is thus achieved that the second binding signature, and storage simulation card uniquely identifies, simulates card certificate and cutting ferrule end theOne binding factor is to cutting ferrule end the first list of bindings, and wherein, cutting ferrule end the first binding factor is the second binding decryption random factor;Specifically, cutting ferruleReceiving can be to be provided separately within the confirmation physical button generation that card puts for confirming that simulation card uniquely identifies correct trigger command, orCan be that confirming on the touch screen of cutting ferrule selects in virtual key generation, or the menu shown on cutting ferrule screen to confirm what function generated, orCan be that the voice that the voice acquisition device (such as Mike) of cutting ferrule receives generates when confirming instruction and be verified rear, or can be cutting ferruleFingerprint acquisition device receive and generate after fingerprint identification indicates and is verified, or it is true to be that the iris collection device of cutting ferrule receives irisGenerate after recognizing instruction and being verified, it is, of course, also possible to generate for other any modes, the most it is not restricted;Utilize cutting ferrule privateFirst binding random factor and the second binding decryption random factor are signed so that the identity of cutting ferrule is authenticated by follow-up simulation card by key;WhenSo, cutting ferrule can also store cutting ferrule end the first list of bindings, and this cutting ferrule end first list of bindings is relevant to the simulation card of cutting ferrule binding for recordInformation, such as: simulation card uniquely identifies, simulates card certificate etc., ties up it addition, cutting ferrule end the first list of bindings is additionally operable to store cutting ferrule end firstDetermining cause, this cutting ferrule end first binding factor is the second binding random factor of ciphertext transmission, is ciphertext transmission based on the second binding random factor,Therefore, this cutting ferrule end first binding factor is safety and is not tampered with.
Cutting ferrule sends the second binding signature to simulation card;Specifically, cutting ferrule sends the second binding signature to simulation card, in order to simulation card is to cardSet identity is authenticated.
Simulation card receives the second binding signature, utilizes the cutting ferrule PKI in cutting ferrule certificate, the first binding random factor and the second binding random factorSecond binding signature is verified;Specifically, the signature that simulation card utilizes the cutting ferrule PKI after being verified to send cutting ferrule is verified, withGuarantee the legitimate origin of data.
After simulation card checking the second binding signature is correct, storage cutting ferrule uniquely identifies, cutting ferrule certificate and analog card bit end binding factor be to analog cardBit end list of bindings, wherein, analog card bit end binding factor is the second binding random factor.Specifically, simulation card can also store simulation cardEnd list of bindings, this analog card bit end list of bindings is for recording and simulate the relevant information of cutting ferrule of card binding, such as: cutting ferrule uniquely identifies,Cutting ferrule certificates etc., it addition, analog card bit end list of bindings is additionally operable to store analog card bit end binding factor, this analog card bit end binding factor is simulationThe second binding random factor that card generates.
As can be seen here, bind based on above-mentioned cutting ferrule and simulation card, it is ensured that the safety of data interaction between follow-up cutting ferrule and simulation card.
2, cutting ferrule and Truth cards manager execution bindings:
In the present invention, cutting ferrule can be bound in the following way with Truth cards manager:
Cutting ferrule and Truth cards manager mutual authentication the other side's certificate and the other side's identity, and after all certification is passed through both sides, each it is stored in verification processThe binding factor of middle generation.
Below, it is provided that a kind of cutting ferrule and the specific implementation of Truth cards manager execution bindings:
Fig. 3 shows that the data interaction system that the embodiment of the present invention provides realizes the flow chart of cutting ferrule and Truth cards manager execution bindings, ginsengSee that Fig. 3, cutting ferrule and Truth cards manager perform bindings and include:
Cutting ferrule reception carries out the trigger command bound for instruction and Truth cards manager;Specifically, before cutting ferrule uses, can be in advance to cardSet performs power-on operation, and now, optionally, cutting ferrule prompting user inputs startup password, and receives the startup password that user inputs, and checking user is defeatedThe correctness of the startup password entered, after the startup password of checking user's input is correct, performs power-on operation, and card covers into mode of operation.UsingBefore cutting ferrule and Truth cards manager carry out data interaction, optionally, cutting ferrule is bound with Truth cards manager, to improve follow-up dataMutual safety.Wherein, the trigger command being used for indicating cutting ferrule and Truth cards manager to carry out binding that cutting ferrule receives can be to be provided separately withinThe binding physical button that card puts generates, or can be that the binding virtual key on the touch screen of cutting ferrule generates, or can be that startup password is testedGenerate after card is correct, or can be the menu of display to select binding function to generate, it is, of course, also possible to be that other are any on cutting ferrule screenMode generates, and is not the most restricted.
Cutting ferrule to Truth cards manager send second binding instruction, wherein, second binding instruction includes: cutting ferrule generate the 3rd binding random factor,Cutting ferrule certificate and cutting ferrule uniquely identify;Specifically, cutting ferrule can wirelessly (such as mobile network, WIFI etc.) to Truth cards pipeReason device sends the second binding instruction.Second binding instruction is carried the 3rd binding random factor and is possible to prevent Replay Attack, the second binding instruction is carriedCutting ferrule certificate, so that cutting ferrule is authenticated by Truth cards manager, carries cutting ferrule in the second binding instruction and uniquely identifies so that Truth cards manager obtainsKnow which cutting ferrule is bound with it;Wherein, the 3rd binding random factor can be random number, random character or a combination thereof that cutting ferrule generates, certainly,Generate the 3rd binding random factor after, it is also possible to the 3rd binding random factor randomness verify, with improve the 3rd binding random factor withMachine, prevents from being cracked;It can be that cutting ferrule serial number, EIC equipment identification code, MAC Address etc. are arbitrary or a combination thereof is with unique mark that cutting ferrule uniquely identifiesKnow the mark of cutting ferrule.
Truth cards manager receives the second binding instruction, utilizes root certificate to verify cutting ferrule certificate;Specifically, Truth cards manager is in advanceStorage root certificate, utilizes this root certificate to complete the checking to cutting ferrule certificate, to ensure the safety of follow-up use cutting ferrule certificate.
After Truth cards manager checking cutting ferrule certificate is legal, generate the 4th binding random factor;Specifically, the 4th binding random factor can be trueRandom number, random character or a combination thereof that real card management device generates;Certainly, after generating the 4th binding random factor, it is also possible to the 4th bindingThe randomness of random factor is verified, to improve the randomness of the 4th binding random factor, prevents from being cracked.
Truth cards manager utilizes the cutting ferrule PKI in cutting ferrule certificate that the 3rd binding random factor and the 4th binding random factor are encrypted and are obtainedObtain the second binding ciphertext, utilize Truth cards manager private key that the 3rd binding random factor and the 4th binding random factor are carried out signature acquisition the 3rdBinding signature;Specifically, Truth cards manager utilize cutting ferrule PKI to the 3rd binding random factor and the 4th binding random factor be encrypted withEnsureing the 3rd binding random factor and the safety of the 4th binding random factor transmission, Truth cards manager utilizes Truth cards manager private key pair3rd binding random factor and the 4th binding random factor are signed, to ensure that follow-up cutting ferrule can be to the legitimacy of Truth cards manager identityIt is authenticated.
Truth cards manager sends the second binding response to cutting ferrule, and wherein, the second binding response includes: second binding ciphertext, the 3rd binding signature,Truth cards manager certificate and Truth cards manager uniquely identify;Specifically, the second binding response that Truth cards manager sends is carriedTruth cards manager certificate, so that Truth cards manager is authenticated by cutting ferrule, carries Truth cards manager and uniquely identifies in the second binding responseSo that cutting ferrule knows which Truth cards manager is bound with it;Wherein, Truth cards manager uniquely identifies can be Truth cards manager sequenceNumber, EIC equipment identification code, MAC Address etc. are arbitrary or a combination thereof is with unique mark identifying Truth cards manager.
Cutting ferrule receives the second binding response, utilizes root certificate to verify Truth cards manager certificate;Specifically, cutting ferrule prestores root certificate,This root certificate is utilized to complete the checking to Truth cards manager certificate, to ensure the safety of follow-up use Truth cards manager certificate.
After cutting ferrule checking Truth cards manager certificate is legal, utilize cutting ferrule private key that the second binding ciphertext is decrypted, it is thus achieved that the 3rd binding RANDOM SOLUTIONThe close factor and the 4th binding decryption random factor;Specifically, cutting ferrule private key is utilized to be decrypted, the second binding ciphertext if sent out in the data transmissionGiven birth to data transmission fault, or there occurs in the data transmission and distort, then will cause cannot successful decryption, or the 3rd binding decrypted is randomDecryption factor and the 4th binding decryption random factor are different from the 3rd binding random factor and the 4th binding random factor.And entered by cutting ferrule PKIRow encryption, only cutting ferrule private key can be with successful decryption, thus it is also ensured that the safety of data deciphering.
Cutting ferrule utilizes the Truth cards manager PKI in Truth cards manager certificate, the 3rd binding decryption random factor and the 4th binding RANDOM SOLUTIONClose factor pair the 3rd binding signature is verified;Specifically, cutting ferrule utilizes the Truth cards manager PKI after being verified to Truth cards managerThe signature sent is verified, to guarantee the legitimate origin of data.
After cutting ferrule checking the 3rd binding signature is correct, checking the 3rd binding decryption random factor is the most identical with the 3rd binding random factor;Specifically,The 3rd binding random factor and the 3rd binding decryption random factor that cutting ferrule checking generates self are identical, it is ensured that data are also not tampered with, and encryptionData Source really for cutting ferrule send the 3rd binding random factor object.
After cutting ferrule checking the 3rd binding decryption random factor is identical with the 3rd binding random factor, prompting Truth cards manager uniquely identifies;Specifically,Cutting ferrule can show that Truth cards manager uniquely identifies, it is also possible to speech play (such as loudspeaker are play or by headset earpiece broadcasting etc.) is trueCard management device uniquely identifies, in order to the verity of Truth cards manager is confirmed by user, improves binding safety.
Cutting ferrule receives for confirming that Truth cards manager uniquely identifies correct trigger command, utilize cutting ferrule private key to the 3rd binding random factor andThe 4th binding decryption random factor is signed, it is thus achieved that the 4th binding signature, and storage Truth cards manager uniquely identifies, Truth cards managementDevice certificate and cutting ferrule end the second binding factor are to cutting ferrule end the second list of bindings, and wherein, cutting ferrule end the second binding factor is the 4th binding decryption randomThe factor;Specifically, what cutting ferrule received can be to be provided separately within what card put for confirming that Truth cards manager uniquely identifies correct trigger commandConfirm what physical button generated, or can be confirming in virtual key generation, or the menu shown on cutting ferrule screen on the touch screen of cutting ferruleSelect to confirm what function generated, or can be after the voice that the voice acquisition device (such as Mike) of cutting ferrule receives confirms to indicate and be verifiedShi Shengcheng's, or can be that the fingerprint acquisition device of cutting ferrule receives and generates after fingerprint identification indicates and is verified, or can be cutting ferruleIris collection device receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes, in the present inventionIn be not restricted;Cutting ferrule private key is utilized to sign so that follow-up Truth cards to the 3rd binding random factor and the 4th binding decryption random factorThe identity of cutting ferrule is authenticated by manager;Certainly, cutting ferrule can also store cutting ferrule end the second list of bindings, and this cutting ferrule end second list of bindings is used forThe relevant information of Truth cards manager of record and cutting ferrule binding, such as: Truth cards manager uniquely identifies, Truth cards manager certificate etc.,It addition, cutting ferrule end the second list of bindings is additionally operable to store cutting ferrule end the second binding factor, this cutting ferrule end second binding factor is that the 4th of ciphertext transmission is tied upDetermining random factor, be ciphertext transmission based on the 4th binding random factor, therefore, this cutting ferrule end second binding factor is safety and is not tampered with.
Cutting ferrule sends the 4th binding signature to Truth cards manager;Specifically, cutting ferrule sends the 4th binding signature to Truth cards manager, in order toCutting ferrule identity is authenticated by Truth cards manager.
Truth cards manager receive the 4th binding signature, utilize the cutting ferrule PKI in cutting ferrule certificate, the 3rd binding random factor and the 4th binding withMachine factor pair the 4th binding signature is verified;Specifically, Truth cards manager utilizes the signature that cutting ferrule is sent by the cutting ferrule PKI after being verifiedVerify, to guarantee the legitimate origin of data.
After Truth cards manager checking the 4th binding signature is correct, storage cutting ferrule uniquely identifies, cutting ferrule certificate and the binding of Truth cards manager endThe factor is to true card management device end list of bindings, and wherein, Truth cards manager end binding factor is the 4th binding random factor.Specifically, veryReal card management device can also store Truth cards manager end list of bindings, and this Truth cards manager end list of bindings is for record and Truth cardsThe relevant information of cutting ferrule of manager binding, such as: cutting ferrule uniquely identifies, cutting ferrule certificate etc., it addition, Truth cards manager end list of bindings is alsoFor storing Truth cards manager end binding factor, this Truth cards manager end binding factor be Truth cards manager generate the 4th binding withThe machine factor.
As can be seen here, bind based on above-mentioned cutting ferrule and Truth cards manager, it is ensured that data between follow-up cutting ferrule and Truth cards managerMutual safety.
Two, secure connection is set up:
1, secure connection set up by cutting ferrule and simulation card, it is thus achieved that the cutting ferrule end first carrying out Security Data Transmission between cutting ferrule and simulation card passes safelyDefeated key and analog card bit end safe transmission key:
In the present invention, cutting ferrule can set up secure connection in the following way with simulation card:
Mode one, cutting ferrule and simulation card mutual authentication the other side identity again (such as mutual authentication the other side signed data), and in mutual authentication againDuring the other side's identity, the binding factor comparing both sides' storage is the most identical, and the binding factor in relatively both sides storage is identical and mutual authentication againAfter the other side's identity is passed through, generate safe transmission key (cutting ferrule end the first safe transmission key carrying out Security Data Transmission between cutting ferrule and simulation cardWith analog card bit end safe transmission key).
Hereinafter, the one of presentation mode one of the present invention implements:
Fig. 4 shows that the data interaction system that the embodiment of the present invention provides realizes cutting ferrule and sets up the flow chart of safe connection mode one with simulation card, ginsengSee that Fig. 4, cutting ferrule set up secure connection with simulation card and include:
Cutting ferrule sends the first secure connection instruction setting up secure connection for instruction to simulation card, and wherein, the first secure connection instruction includes: cardSet utilizes the simulation card PKI in analog card sheet certificate to be encrypted the first connection random factor of cutting ferrule end the first binding factor and generation and obtainsThe the first connection ciphertext obtained, cutting ferrule utilizes cutting ferrule private key that cutting ferrule end the first binding factor and the first connection random factor are carried out the first of signature acquisitionConnect signature;Specifically, before using cutting ferrule to carry out data interaction with simulation card, optionally, between cutting ferrule and simulation card, safety is set upConnect, the safety mutual to improve follow-up data.Wherein, what cutting ferrule received is used for indicating the first secure connection instruction setting up secure connection permissibleThe connection physical button put for being provided separately within card generates, or can be that the virtual key that connects on the touch screen of cutting ferrule generates, or permissibleGenerate the most afterwards for start-up password verification, or can be that simulation card is generated after cutting ferrule is extracted, or can be aobvious on cutting ferrule screenSelecting linkage function to generate in the menu shown, or can be to obtain cutting ferrule end Truth cards information list at cutting ferrule, user therefrom selects truly to blockGenerate after sheet.It is, of course, also possible to generate for other any modes, the most it is not restricted.Wherein, the first connection random factor canThink random number, random character or a combination thereof that cutting ferrule generates, certainly, after generating the first connection random factor, it is also possible to connect random to firstThe randomness of the factor is verified, to improve the randomness of the first connection random factor, prevents from being cracked;Specifically, cutting ferrule utilizes simulation card publicKey connects random factor and is encrypted to ensure that cutting ferrule end the first binding factor and first connects at random cutting ferrule end the first binding factor and firstThe safety of factor transmission, cutting ferrule utilizes cutting ferrule private key that cutting ferrule end the first binding factor and first are connected random factor and signs, after ensureingThe legitimacy of cutting ferrule identity can be authenticated by continuous simulation card.Cutting ferrule end the first binding factor is sent to simulating card, in order to follow-up analog cardBinding factor that whether cutting ferrule end the first binding factor is stored by sheet with it is identical to be judged, thus judges whether this cutting ferrule is carried out with this simulation cardBinding.Optionally, before this step, after cutting ferrule detects simulation card, cutting ferrule may determine that whether simulation card is bound at cutting ferrule end firstIn list, such as: can judge in the following way: be fastened in after simulation card being detected, the simulation card image that simulation card sends is received(such as simulation card uniquely identifies and/or simulates card certificate etc.), according to the simulation card image received, it is judged that whether this simulation card is at cardIn set end the first list of bindings;And/or can also by simulation card judge cutting ferrule whether in analog card bit end list of bindings, such as: can pass through as followsMode judges: is fastened in after simulation card being detected, sends cutting ferrule information (such as cutting ferrule uniquely identify and/or cutting ferrule certificate etc.) to simulationCard, simulation card is according to the cutting ferrule information received, it is judged that whether this cutting ferrule is in analog card bit end list of bindings;Only judging that the other side is certainlyAfter in the list of bindings of body, just perform follow-up flow process, optimize flow process, improve efficiency.
Simulation card receives the first secure connection instruction, utilizes simulation card private key to connect ciphertext to first and is decrypted, it is thus achieved that cutting ferrule end first is boundDecryption factor and first connects the decryption random factor;Specifically, utilize simulation card private key to connect ciphertext to first to be decrypted, if in dataTransmission there occurs data transmission fault, or there occurs in the data transmission and distort, then will cause cannot successful decryption, or the cutting ferrule decryptedIt is different from cutting ferrule end the first binding factor and the first connection random factor that end the first binding decryption factor and first connects the decryption random factor.And lead toCrossing simulation card PKI to be encrypted, only simulation card private key can be with successful decryption, thus it is also ensured that the safety of data deciphering.
Simulation card utilizes the cutting ferrule PKI in cutting ferrule certificate, cutting ferrule end first to bind decryption factor and the first connection decryption random factor pair first connectsConnect signature to verify;Specifically, the signature that simulation card utilizes cutting ferrule PKI to send cutting ferrule is verified, to guarantee the legitimate origin of data.
After simulation card checking the first connection signature is correct, it is the most identical with analog card bit end binding factor that checking cutting ferrule end first binds decryption factor;Specifically, simulation card also verify the cutting ferrule end first decrypted bind decryption factor whether with the analog card bit end binding of simulation card self storage because ofSon is the most identical, if identical, then illustrate that this is fastened in and simulates before card sets up secure connection, has been completed the operation of binding, based on this,Simulation card may determine that whether cutting ferrule is bound with simulation card.
Simulation card checking cutting ferrule end first bind decryption factor identical with analog card bit end binding factor after, generate second connect random factor;SpecificallyGround, second connect random factor can be analog card sheet generate random number, random character or a combination thereof, certainly, generate second connect random because ofAfter son, it is also possible to the second randomness connecting random factor is verified, to improve the randomness of the second connection random factor, prevents from being cracked.
Simulation card utilizes the cutting ferrule PKI in cutting ferrule certificate to connect the decryption random factor to first and the second connection random factor is encrypted acquisitionSecond connects ciphertext, utilizes simulation card private key to connect the decryption random factor to first and the second connection random factor carries out signature and obtains the second connectionSignature;Specifically, simulation card utilizes cutting ferrule PKI to connect the decryption random factor and second to first to connect random factor and be encrypted to ensure theOne connects the decryption random factor and second connects the safety of random factor transmission, and simulation card utilizes simulation card private key to connect RANDOM SOLUTION to firstThe close factor and second connects random factor and signs, to ensure that the legitimacy of simulation card identity can be authenticated by follow-up cutting ferrule.
Simulation card sends the first secure connection response to cutting ferrule, and wherein, the first secure connection response includes: second connects ciphertext and second connectsSignature;Specifically, simulation card connects second ciphertext and second and connects signature transmission to cutting ferrule, in order to the data received are decrypted by cutting ferruleAnd checking.
Cutting ferrule receives the first secure connection response, utilizes cutting ferrule private key to connect ciphertext to second and is decrypted, it is thus achieved that the first connection RANDOM SOLUTION after decipheringThe close factor and second connects the decryption random factor;Specifically, utilize cutting ferrule private key to connect ciphertext to second to be decrypted, if sent out in the data transmissionGiven birth to data transmission fault, or there occurs in the data transmission and distort, then will cause cannot the first connection after successful decryption, or deciphering randomIt is different from the first connection random factor and the second connection random factor that decryption factor connects the decryption random factor with second.And added by cutting ferrule PKIClose, only cutting ferrule private key can be with successful decryption, thus it is also ensured that the safety of data deciphering.
Cutting ferrule utilizes the simulation card PKI in simulation card certificate, the first connection decryption random factor and second after deciphering to connect the decryption random factorConnect signature to second to verify;Specifically, the signature that cutting ferrule utilizes simulation card PKI to send simulation card is verified, to guarantee dataLegitimate origin.
After cutting ferrule checking the second connection signature is correct, it is the most identical that the first connection decryption random factor after checking deciphering is connected random factor with first;Specifically, the first connection random factor that cutting ferrule checking self generates is identical with the first connection decryption random factor after deciphering, it is ensured that data are alsoIt is not tampered with, and the Data Source of encryption sends the object of the first connection random factor really for cutting ferrule.
Cutting ferrule checking deciphering after first connection the decryption random factor with first connect random factor identical after, at least with second connection decryption random because ofSon generates cutting ferrule end the first safe transmission key between cutting ferrule and simulation card;Simulation card connects random factor at least with second and generates cutting ferrule and mouldIntend the analog card bit end safe transmission key between card.Specifically, cutting ferrule can utilize the second connection decryption random factor to generate cutting ferrule and simulation cardBetween cutting ferrule end the first safe transmission key, it is also possible to utilize the first connection random factor, second connect the decryption random factor and generate cutting ferrule and analog cardCutting ferrule end the first safe transmission key between sheet, it is also possible to utilize the first connection random factor, the second connection decryption random factor and cutting ferrule end firstBinding factor generates cutting ferrule end the first safe transmission key between cutting ferrule and simulation card;Same, simulation card can also utilize the second connection randomThe factor generate cutting ferrule and simulation card between analog card bit end safe transmission key, it is also possible to utilize the first connection decryption random factor, second connect withThe machine factor generates the analog card bit end safe transmission key between cutting ferrule and simulation card, it is also possible to utilize the first connection decryption random factor, the second connectionRandom factor and analog card bit end binding factor generate the analog card bit end safe transmission key between cutting ferrule and simulation card;If cutting ferrule and analog cardSheet uses the algorithm that identical parameter is identical to generate safe transmission key.As can be seen here, in the present invention, safe transmission cryptographic key factor is at cutting ferruleEnd can be the second connection decryption random factor, or second connects the decryption random factor and the first connection random factor;Safe transmission cryptographic key factorCan be the second connection random factor in analog card bit end, or second connects random factor and the first connection decryption random factor.It addition, safetyTransmission key can include encryption and decryption key and/or check key, uses encryption and decryption key can participate in data transmission and can ensure that the safety that data are transmittedProperty, use check key to participate in data transmission and can ensure that the integrity that data are transmitted, in the present invention it is possible to according to the safety etc. of transmission dataLevel optionally uses safe transmission key.
Certainly, in the present invention, simulation card connects random factor at least with second and generates the analog card bit end safe transmission between cutting ferrule and simulation cardThe step of key is not limited to the step in the manner one, it is also possible to generate analog card bit end after simulation card generates the second connection random factorSafe transmission key, it is also possible to after cutting ferrule verifies that the first connection decryption random factor after deciphering is identical with the first connection random factor, receive cutting ferruleAnalog card bit end safe transmission key is generated after the successful information sent.
As can be seen here, the secure connection set up with simulation card based on above-mentioned cutting ferrule, can improve the safety of data transmission, at the same time it can also be testWhether card both sides are bound, and further increase safety.
Additionally, the invention is not limited in that the foundation of secure connection initiated by above-mentioned cutting ferrule, it is also possible to triggered simulation card by cutting ferrule and initiate secure connectionSetting up, now, simulation card send the first secure connection and instruct to cutting ferrule, other flow processs are contrary with above-mentioned flow implementation main body can be realized,This repeats the most one by one.
Mode two, cutting ferrule and simulation card mutual authentication the other side identity again (such as mutual authentication the other side signed data), and in mutual authentication againSafe transmission cryptographic key factor is generated, after mutual authentication the other side identity is passed through again, at least with binding factor and the peace of storage during the other side's identityFull transmission cryptographic key factor generate carry out between cutting ferrule and simulation card Security Data Transmission safe transmission key (cutting ferrule end the first safe transmission key andAnalog card bit end safe transmission key), and verify that the safe transmission key that both sides generate is the most identical.
Hereinafter, the one of presentation mode two of the present invention implements:
Fig. 5 shows that the data interaction system that the embodiment of the present invention provides realizes cutting ferrule and sets up the flow chart of safe connection mode two with simulation card, ginsengSee that Fig. 5, cutting ferrule set up secure connection with simulation card and include:
Cutting ferrule receives to simulate the 3rd connection random factor of the simulation card generation that card sends and simulate card and uniquely identifies;Specifically, the 3rd evenConnecing random factor can be random number, random character or a combination thereof that analog card sheet generates, and certainly, after generating the 3rd connection random factor, also may be usedVerify with the randomness to the 3rd connection random factor, to improve the randomness of the 3rd connection random factor, prevent from being cracked.This step itBefore, simulation card generate the 3rd connection random factor, after cutting ferrule detects this simulation card, simulation card by the 3rd connect random factor andSimulation card uniquely identifies transmission to cutting ferrule.
Cutting ferrule sends the second secure connection instruction setting up secure connection for instruction to simulation card, and wherein, the second secure connection instruction includes: cardThe unique mark of set, cutting ferrule utilize the simulation card PKI in simulation card certificate to connect the 4th connection random factor of random factor and generation to the 3rdBe encrypted the 3rd connection ciphertext of acquisition, cutting ferrule utilizes cutting ferrule private key to connect random factor to the 3rd and the 4th connection random factor carries out signature and obtainsThe 3rd connection signature obtained;Specifically, before using cutting ferrule to carry out data interaction with simulation card, optionally, between cutting ferrule and simulation cardSet up secure connection, the safety mutual to improve follow-up data.Wherein, the second secure connection setting up secure connection for instruction that cutting ferrule receivesInstruction can be to be provided separately within the connection physical button generation that card puts, or can be that the virtual key that connects on the touch screen of cutting ferrule generates,Or can be that start-up password verification generates the most afterwards, or can be that simulation card is generated after cutting ferrule is extracted, or can be at cutting ferruleSelecting linkage function to generate on screen in the menu of display, or can be to obtain cutting ferrule end Truth cards information list at cutting ferrule, user therefrom selectsGenerate after selecting Truth cards.It is, of course, also possible to generate for other any modes, the most it is not restricted.Specifically, cutting ferrule utilizesSimulation card PKI connect the 3rd the 4th connection random factor of random factor and generation be encrypted to ensure the 3rd connection random factor andThe safety of the 4th connection random factor transmission generated, cutting ferrule utilizes cutting ferrule private key random to the 4th connection of the 3rd connection random factor and generationThe factor is signed, to ensure that the legitimacy of cutting ferrule identity can be authenticated by follow-up simulation card.It addition, the 4th connection random factor can beRandom number, random character or a combination thereof that cutting ferrule generates, certainly, after generating the 4th connection random factor, it is also possible to connect random factor to the 4thRandomness verify, with improve the 4th connection random factor randomness, prevent from being cracked;Optionally, before this step, cutting ferrule receivesTo simulation after card uniquely identifies, cutting ferrule uniquely can identify according to simulation card judge simulation card whether in cutting ferrule end the first list of bindings,Only after judging that simulation card is in cutting ferrule end the first list of bindings, just perform follow-up flow process, optimize flow process, improve efficiency.
Simulation card receives the second secure connection instruction, it is judged that cutting ferrule uniquely identifies whether in analog card bit end list of bindings;Specifically, analog cardSheet uniquely identifies according to the cutting ferrule received, it is judged that whether this cutting ferrule is in analog card bit end list of bindings;Only it is fastened in analog card bit end in judgementAfter in list of bindings, just perform follow-up flow process, optimize flow process, improve efficiency.
If cutting ferrule uniquely identifies in analog card bit end list of bindings, simulation card utilizes simulation card private key to connect ciphertext to the 3rd and is decrypted,Obtain the 3rd connection decryption random factor and the 4th and connect the decryption random factor;Specifically, utilize simulation card private key to connect ciphertext to the 3rd to carry outDeciphering, if there occurs data transmission fault in the data transmission, or there occurs in the data transmission and distorts, then will cause cannot successful decryption,Or obtain the 3rd connection the decryption random factor and the 4th connect the decryption random factor be connected with the 3rd random factor and the 4th connection random because ofSon is different.And be encrypted by simulation card PKI, only simulation card private key can be with successful decryption, thus it is also ensured that the peace of data decipheringQuan Xing.
Simulation card utilizes the cutting ferrule PKI in cutting ferrule certificate, the 3rd connection decryption random factor and the 4th to connect decryption random factor pair the 3rd connectionSignature is verified;Specifically, the signature that simulation card utilizes cutting ferrule PKI to send cutting ferrule is verified, to guarantee the legitimate origin of data.
After simulation card checking the 3rd connection signature is correct, it is the most identical that checking the 3rd connection decryption random factor is connected random factor with the 3rd;SpecificallyGround, it is identical that the 3rd connection random factor and the 3rd that simulation card checking generates self connects the decryption random factor, it is ensured that data are also not tampered with,And the Data Source of encryption sends the object of the 3rd connection random factor really for simulation card.
If it is identical that the 3rd connection decryption random factor connects random factor with the 3rd, simulation card utilizes simulation card private key to the 3rd connection RANDOM SOLUTIONThe close factor and the 4th connects the decryption random factor and carries out signature acquisition the 4th connection signature;Specifically, simulation card utilizes simulation card private key to theThe three connection decryption random factors and the 4th connect the decryption random factor and sign, to ensure that follow-up cutting ferrule can be to the legitimacy of simulation card identityIt is authenticated.
Simulation card sends the second secure connection response to cutting ferrule, and wherein, the second secure connection response includes: the 4th connects signature;Specifically, mouldIntend card and connect signature transmission by the 4th to cutting ferrule, in order to the data received are verified by cutting ferrule.
Cutting ferrule receive second secure connection response, utilize simulation card certificate in simulation card PKI, the 3rd connect random factor and the 4th connect withMachine factor pair the 4th connects signature and verifies;Specifically, the signature that cutting ferrule utilizes simulation card PKI to send simulation card is verified, with reallyProtect the legitimate origin of data.
After cutting ferrule checking the 4th connection signature is correct, connects random factor at least with the 4th and cutting ferrule end the first binding factor generates cutting ferrule and simulationCutting ferrule end the first safe transmission key between card;Simulation card connects the decryption random factor at least with the 4th and analog card bit end binding factor is rawBecome the analog card bit end safe transmission key between cutting ferrule and simulation card;Specifically, cutting ferrule can utilize the 4th connection random factor and cutting ferrule end theOne binding factor generates cutting ferrule end the first safe transmission key between cutting ferrule and simulation card, it is also possible to utilize the 3rd connection random factor, the 4th connectionRandom factor and cutting ferrule end the first binding factor generate cutting ferrule end the first safe transmission key between cutting ferrule and simulation card;Same, simulate cardThe analog card bit end that the 4th connection decryption random factor and analog card bit end binding factor can also be utilized to generate between cutting ferrule and simulation card passes safelyDefeated key, it is also possible to utilize the 3rd connection random factor, the 4th connection decryption random factor and analog card bit end binding factor to generate cutting ferrule and simulationAnalog card bit end safe transmission key between card;As long as the algorithm that the parameter that cutting ferrule is identical with simulation card employing is identical generates safe transmission key i.e.Can.As can be seen here, in the present invention, safe transmission cryptographic key factor cutting ferrule end can be the 4th connect random factor, or the 3rd connect random because ofSon and the 4th connects random factor;Safe transmission cryptographic key factor can be the 4th connection decryption random factor in analog card bit end, or the 3rd connectsRandom factor and the 4th connects the decryption random factor.It addition, safe transmission key can include encryption and decryption key and/or check key, use and add solutionDecryption key can participate in data transmission and can ensure that the safety that data are transmitted, and uses check key participation data transmission to can ensure that data are transmitted completeWhole property, in the present invention it is possible to optionally use safe transmission key according to the safety grades of transmission data.
Cutting ferrule utilizes cutting ferrule end the first safe transmission double secret key the 3rd to connect random factor and the 4th connection random factor carries out transmission after the first processTo simulating card;Simulation card utilizes analog card bit end safe transmission double secret key the 3rd to connect the decryption random factor and the 4th connection decryption random factorSend to cutting ferrule after carrying out the first process;Specifically, both sides utilize the safe transmission data key of each self-generating to send to right after carrying out the first processSide, in order to the other side verifies that the safe transmission key that both sides generate is the most identical.
Cutting ferrule receives the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, compareData after second process are connected random factor with the 3rd and the 4th connection random factor is the most identical;The data that simulation card receiving card set sends,And the data utilizing analog card bit end safe transmission double secret key to receive carry out the second process, compare the data after the second process and be connected RANDOM SOLUTION with the 3rdIt is the most identical that the close factor and the 4th connects the decryption random factor.Specifically, both sides utilize the data that the safe transmission double secret key of each self-generating receivesAfter carrying out the second process, each comparing the data after the second process the most identical with the data each sent, if identical, then explanation both sides generateSafe transmission key is identical, in order to ensure that the follow-up safe transmission key that can utilize each self-generating of both sides carries out Security Data Transmission.It addition, testingWhile safe transmission key that card both sides generate is identical, it is also possible to the binding factor of checking each storage is identical, and checking the other side is real furtherBound object, improves the safety of subsequent data transmission further.
Certainly, in the present invention, simulation card generates the step of analog card bit end safe transmission key and is not limited to the step in the manner two, also may be usedTo generate analog card bit end safe transmission key after deciphering obtains the 4th connection decryption random factor, it is also possible to send at cutting ferrule checking simulation cardAfter 4th connection signature is errorless, after receiving the successful information that cutting ferrule sends, generate analog card bit end safe transmission key;Cutting ferrule generates cutting ferrule end first pacifiesThe step of full transmission key is also not limited to the step in the manner two, it is also possible to generate cutting ferrule end first after cutting ferrule generates the 4th connection random factorSafe transmission key.
As can be seen here, the secure connection set up with simulation card based on above-mentioned cutting ferrule, can improve the safety of data transmission, at the same time it can also be testWhether card both sides are bound, and further increase safety.
Additionally, the invention is not limited in that the foundation of secure connection initiated by above-mentioned cutting ferrule, it is also possible to triggered simulation card by cutting ferrule and initiate secure connectionSetting up, now, simulation card send the second secure connection and instruct to cutting ferrule, other flow processs are contrary with above-mentioned flow implementation main body can be realized,This repeats the most one by one.
2, secure connection set up by cutting ferrule and Truth cards manager, it is thus achieved that carry out the cutting ferrule of Security Data Transmission between cutting ferrule and Truth cards managerHold the second safe transmission key and Truth cards manager end safe transmission key:
In the present invention, cutting ferrule and Truth cards manager can set up secure connection in the following way:
Mode one, cutting ferrule and Truth cards manager mutual authentication the other side identity again, and during mutual authentication the other side identity again, compareThe binding factor of both sides' storage is the most identical, and the binding factor in relatively both sides storage is identical and after mutual authentication the other side identity is passed through again, generates cardSafe transmission key (cutting ferrule end the second safe transmission key and the Truth cards manager of Security Data Transmission is carried out between set and Truth cards managerEnd safe transmission key).
The scheme that cutting ferrule and Truth cards manager use mode one to set up secure connection uses mode one to set up secure connection with cutting ferrule with simulation cardScheme differ only in:
One to be carried out main body different: in the scheme that cutting ferrule and Truth cards manager use mode one to set up secure connection, executive agent be cutting ferrule andTruth cards manager;Using mode one to set up in the scheme of secure connection at cutting ferrule and simulation card, executive agent is cutting ferrule and simulation card.ItsIn, it being fastened in this two schemes execution operation identical, it is identical that Truth cards manager performs operation with simulation card in this two schemes.
Two is the generating mode difference of secure connection instruction: use mode one to set up in the scheme of secure connection at cutting ferrule and Truth cards manager, theThree secure connection instructions can be to be provided separately within the connection physical button generation that card puts, or can be that the connection on the touch screen of cutting ferrule is virtual pressKey generates, or can be that start-up password verification generates the most afterwards, or can be that cutting ferrule is raw when Truth cards manager sends logging requestBecome, or can be the menu of display to select linkage function to generate on cutting ferrule screen.
Hereinafter, the scheme only using mode one to set up secure connection cutting ferrule and Truth cards manager is briefly described as follows, is not described in detail in this.
Fig. 6 shows that the data interaction system that the embodiment of the present invention provides realizes cutting ferrule and Truth cards manager and sets up the flow process of safe connection mode oneFigure, sees Fig. 6, and cutting ferrule is set up secure connection with Truth cards manager and included:
Cutting ferrule sends the 3rd secure connection instruction setting up secure connection for instruction, wherein, the 3rd secure connection instruction bag to Truth cards managerInclude: cutting ferrule utilize Truth cards manager PKI in Truth cards manager certificate to the 5th connection of cutting ferrule end the second binding factor and generation withThe machine factor is encrypted the 5th connection ciphertext of acquisition, and cutting ferrule utilizes cutting ferrule private key to enter cutting ferrule end the second binding factor and the 5th connection random factorThe 5th connection signature that row signature obtains;
Truth cards manager receives the 3rd secure connection instruction, utilizes Truth cards manager private key to connect ciphertext to the 5th and is decrypted, it is thus achieved that cardSet end second is bound decryption factor and the 5th and is connected the decryption random factor;
Truth cards manager utilizes the cutting ferrule PKI in cutting ferrule certificate, cutting ferrule end second to bind decryption factor and the 5th connection decryption random factor pair5th connects signature verifies;
After Truth cards manager checking the 5th connection signature is correct, checking cutting ferrule end second bind decryption factor and the binding of Truth cards manager end because ofSon is the most identical;
Truth cards manager checking cutting ferrule end second bind decryption factor identical with Truth cards manager end binding factor after, generate the 6th connect withThe machine factor;
Truth cards manager utilizes the cutting ferrule PKI in cutting ferrule certificate to connect the decryption random factor to the 5th and the 6th connection random factor addsClose acquisition the 6th connects ciphertext, utilizes Truth cards manager private key to connect the decryption random factor to the 5th and the 6th connection random factor is signedObtain the 6th connection signature;
Truth cards manager sends the 3rd secure connection response to cutting ferrule, and wherein, the 3rd secure connection response includes: the 6th connects ciphertext and theSix connect signature;
Cutting ferrule receives the 3rd secure connection response, utilizes cutting ferrule private key to connect ciphertext to the 6th and is decrypted, it is thus achieved that the 5th connection RANDOM SOLUTION after decipheringThe close factor and the 6th connects the decryption random factor;
Cutting ferrule utilizes the 5th connection decryption random factor and the 6th connection after the Truth cards manager PKI in Truth cards manager certificate, decipheringDecryption random factor pair the 6th connects signature and verifies;
After cutting ferrule checking the 6th connection signature is correct, it is the most identical that the 5th connection decryption random factor after checking deciphering is connected random factor with the 5th;
Cutting ferrule checking deciphering after the 5th connection the decryption random factor with the 5th connect random factor identical after, at least with the 6th connection decryption random because ofSon generates cutting ferrule end the second safe transmission key between cutting ferrule and Truth cards manager;Truth cards manager connects random factor at least with the 6thGenerate the Truth cards manager end safe transmission key between cutting ferrule and Truth cards manager.
Certainly, in the present invention, Truth cards manager connects, at least with the 6th, the true card that random factor generates between cutting ferrule and Truth cards managerThe step of sheet manager end safe transmission key is not limited to the step in the manner one, it is also possible to Truth cards manager generate the 6th connection withTruth cards manager end safe transmission key is generated, it is also possible to the 5th connection decryption random factor after cutting ferrule checking deciphering is with the after the machine factorAfter five connection random factors are identical, after receiving the successful information that cutting ferrule sends, generate Truth cards manager end safe transmission key.
As can be seen here, the secure connection set up with Truth cards manager based on above-mentioned cutting ferrule, can improve the safety of data transmission, meanwhile, alsoCan verify whether both sides are bound, further increase safety.
Additionally, the invention is not limited in that the foundation of secure connection initiated by above-mentioned cutting ferrule, it is also possible to triggered Truth cards manager by cutting ferrule and initiate safetyEstablishment of connection, now, is sent the 3rd secure connection by Truth cards manager and instructs to cutting ferrule, and other flow processs are contrary with above-mentioned flow implementation main bodyCan realize, this is no longer going to repeat them.
Mode two, cutting ferrule and Truth cards manager mutual authentication the other side identity again, and during mutual authentication the other side identity again, generate safetyTransmission cryptographic key factor, after mutual authentication the other side's identity is passed through, binding factor and safe transmission cryptographic key factor at least with storage generate cutting ferrule with trueSafe transmission key (cutting ferrule end the second safe transmission key and the Truth cards manager end safety of Security Data Transmission is carried out between real card management deviceTransmission key), and verify that the safe transmission key that both sides generate is the most identical.
The scheme that cutting ferrule and Truth cards manager use mode two to set up secure connection uses mode two to set up secure connection with cutting ferrule with simulation cardScheme differ only in:
One to be carried out main body different: in the scheme that cutting ferrule and Truth cards manager use mode two to set up secure connection, executive agent be cutting ferrule andTruth cards manager;Using mode two to set up in the scheme of secure connection at cutting ferrule and simulation card, executive agent is cutting ferrule and simulation card.ItsIn, it being fastened in this two schemes execution operation identical, it is identical that Truth cards manager performs operation with simulation card in this two schemes.
Two is the generating mode difference of secure connection instruction: use mode two to set up in the scheme of secure connection at cutting ferrule and Truth cards manager, theFour secure connection instructions can be to be provided separately within the connection physical button generation that card puts, or can be that the connection on the touch screen of cutting ferrule is virtual pressKey generates, or can be that start-up password verification generates the most afterwards, or can be that cutting ferrule is raw when Truth cards manager sends logging requestBecome, or can be the menu of display to select linkage function to generate on cutting ferrule screen.
Hereinafter, the scheme only using mode two to set up secure connection cutting ferrule and Truth cards manager is briefly described as follows, is not described in detail in this.
Fig. 7 shows that the data interaction system that the embodiment of the present invention provides realizes cutting ferrule and Truth cards manager and sets up the flow process of safe connection mode twoFigure, sees Fig. 7, and cutting ferrule is set up secure connection with Truth cards manager and included:
The 7th connection random factor and Truth cards manager that the Truth cards manager that cutting ferrule reception Truth cards manager sends generates uniquely are markedKnow;
Cutting ferrule sends the 4th secure connection instruction setting up secure connection for instruction, wherein, the 4th secure connection instruction bag to Truth cards managerInclude: cutting ferrule uniquely identifies, cutting ferrule utilizes the Truth cards manager PKI in Truth cards manager certificate to connect random factor and generation to the 7thThe 8th connection random factor be encrypted the 7th connection ciphertext, cutting ferrule of acquisition and utilize cutting ferrule private key to connect random factor and the 8th connection to the 7thRandom factor carries out the 7th connection signature that signature obtains;
Truth cards manager receives the 4th secure connection instruction, it is judged that cutting ferrule uniquely identifies whether in Truth cards manager end list of bindings;
If cutting ferrule uniquely identifies in Truth cards manager end list of bindings, Truth cards manager utilizes Truth cards manager private key to the 7thConnect ciphertext to be decrypted, it is thus achieved that the 7th connects the decryption random factor and the 8th connects the decryption random factor;
Truth cards manager utilizes the cutting ferrule PKI in cutting ferrule certificate, the 7th connects the decryption random factor and the 8th and connect decryption random factor pair theSeven connect signature verifies;
After Truth cards manager checking the 7th connection signature is correct, checking the 7th connection decryption random factor is connected random factor whether phase with the 7thWith;
If the 7th to connect the decryption random factor identical with the 7th connection random factor, Truth cards manager utilizes Truth cards manager private key to theThe seven connection decryption random factors and the 8th connection decryption random factor carry out signature acquisition the 8th connection and sign;
Truth cards manager sends the 4th secure connection response to cutting ferrule, and wherein, the 4th secure connection response includes: the 8th connects signature;
Cutting ferrule receives the 4th secure connection response, utilizes the Truth cards manager PKI in Truth cards manager certificate, the 7th connection random factorConnect random factor with the 8th the 8th connection signature is verified;
After cutting ferrule checking the 8th connection signature is correct, connects random factor at least with the 8th and cutting ferrule end the second binding factor generates cutting ferrule with trueCutting ferrule end the second safe transmission key between card management device;Truth cards manager connects the decryption random factor and Truth cards at least with the 8thManager end binding factor generates the Truth cards manager end safe transmission key between cutting ferrule and Truth cards manager;
Cutting ferrule utilizes cutting ferrule end the second safe transmission double secret key the 7th to connect random factor and the 8th connection random factor carries out transmission after the first processTo true card management device;Truth cards manager utilizes Truth cards manager end safe transmission double secret key the 7th to connect the decryption random factor and theThe eight connection decryption random factors send to cutting ferrule after carrying out the first process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive are carried out at secondReason, compare the data after the second process be connected with the 7th random factor and the 8th connection random factor the most identical;Truth cards manager receiving cardOverlap the data sent, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out the second process, after comparing the second processData are connected the decryption random factor with the 7th and the 8th connection decryption random factor is the most identical.
As can be seen here, the secure connection set up with Truth cards manager based on above-mentioned cutting ferrule, can improve the safety of data transmission, meanwhile, alsoCan verify whether both sides are bound, further increase safety.
Certainly, in the present invention, Truth cards manager generates the step of Truth cards manager end safe transmission key and is not limited in the manner twoStep, it is also possible to deciphering obtain the 8th connection the decryption random factor after generate Truth cards manager end safe transmission key, it is also possible at cutting ferruleChecking Truth cards manager send the 8th connection signature errorless after, receive cutting ferrule send successful information after generate Truth cards manager end safetyTransmission key;Cutting ferrule generates the step of cutting ferrule end the second safe transmission key and is also not limited to the step in the manner two, it is also possible to generate the at cutting ferruleEight connect generation cutting ferrule end the second safe transmission key after random factor.
Additionally, the invention is not limited in that the foundation of secure connection initiated by above-mentioned cutting ferrule, it is also possible to triggered Truth cards manager by cutting ferrule and initiate safetyEstablishment of connection, now, is sent the 4th secure connection by Truth cards manager and instructs to cutting ferrule, and other flow processs are contrary with above-mentioned flow implementation main bodyCan realize, this is no longer going to repeat them.
It addition, set up secure connection at cutting ferrule of the present invention and Truth cards manager, it is thus achieved that carry out data safety between cutting ferrule and Truth cards managerBefore cutting ferrule end the second safe transmission key of transmission and Truth cards manager end safe transmission key, cutting ferrule sends to Truth cards manager and logs inRequest;Specifically, logging request can be to be provided separately within the login physical button generation that card puts, or can be stepping on the touch screen of cutting ferruleRecord virtual key generates, or can be that start-up password verification generates the most afterwards, or can be to select in the menu of display on cutting ferrule screenLogin feature generates;Logging request can include that cutting ferrule uniquely identifies, in order to which cutting ferrule request Truth cards manager knows logs in.
Sending logging request at cutting ferrule to Truth cards manager, secure connection set up by cutting ferrule and Truth cards manager, it is thus achieved that cutting ferrule and Truth cardsAfter carrying out cutting ferrule end the second safe transmission key and the Truth cards manager end safe transmission key of Security Data Transmission between manager:
Cutting ferrule sends to true card management device after carrying out the first process by the login password that cutting ferrule end the second safe transmission double secret key receives;SpecificallyGround, cutting ferrule can also point out user to input login password, after user have input login password, utilizes cutting ferrule end the second safe transmission double secret key to log inPassword sends after carrying out the first process to true card management device, can improve the safety of login password transmission.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondThe correctness of the data after the second process is verified after process;Specifically, Truth cards manager utilizes Truth cards manager end safe transmission double secret keyAfter the data that cutting ferrule sends carry out the second process, it is thus achieved that the login password of user's input, the legal login password stored with it compares, and only existsWhen the legal login password that stores with it of login password of user's input is identical, just allow cutting ferrule login Truth cards manager, raising login security,Ensure the safety of subsequent data transmission.If Truth cards manager possesses warning function in the present invention, then can be in advance at Truth cards managerIn legal login password and legal alarm cipher are set, now, Truth cards manager utilizes Truth cards manager end safe transmission double secret key to receiveTo data carry out the second process after, it is thus achieved that password to be verified;Truth cards manager judges whether password to be verified is alarm cipher;If it is to be testedCard password is alarm cipher, then Truth cards manager determines that password authentification to be verified is passed through, and performs operation of reporting to the police;If password to be verified is notAlarm cipher and be login password, then Truth cards manager determines that password authentification to be verified is passed through.Owing to being provided with alarm cipher, when user inputsLogin password when being alarm cipher, Truth cards manager can identify current login and there is security risk, and the operation that performs to report to the police is (the trueestReal card management device sends alarming short message, dials the police emergency number to law enforcement agency etc.).
After Truth cards manager data after checking the second process are passed through, cutting ferrule logs in Truth cards manager.
As can be seen here, before the secure connection set up between cutting ferrule and Truth cards manager, logging request initiated in advance by cutting ferrule, and sends at cutting ferruleTrigger the foundation of secure connection while logging request, and after secure connection is set up, login password is verified, flow process can be saved, improveProcessing speed.
Three, Truth cards information list generates and updates:
1, Truth cards manager end Truth cards information list generates and updates:
Truth cards manager carries out the generation of Truth cards manager end Truth cards information list, certainly, the present invention not office in the following wayIt is limited to this:
The Truth cards that Truth cards manager pair is connected with Truth cards manager detects;Specifically, Truth cards manager is arranged on whichContact interface and/or non-contact interface detect, to determine whether that Truth cards is attached with Truth cards manager, can be successivelyDetected whether connected Truth cards, it is also possible to detected whether connected Truth cards simultaneously.Optionally, Truth cards managerCould be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, in order to user is according to Truth cardsSecurity requirement make different setting, the Truth cards letter not allowing to obtain some Truth cards such as can be set on Truth cards managerBreath, thus ensure the safety of these Truth cards.
Truth cards manager after the Truth cards being connected with Truth cards manager being detected, obtain Truth cards Truth cards information, wherein,Truth cards information at least includes: card number;Specifically, Truth cards manager, when having detected that Truth cards is attached with it, reads and itThe Truth cards information of storage in the Truth cards connected, and finally obtain the Truth cards letter of the Truth cards being all connected with Truth cards managerBreath.Additionally, Truth cards information is except comprising card extra, it is also possible to the information such as issuer mark comprising card authentication information, Truth cards.
After Truth cards manager obtains the Truth cards information of Truth cards, generate Truth cards manager end Truth cards information list.Specifically,After Truth cards manager obtains the Truth cards information of connected Truth cards, generate Truth cards manager end Truth cards information rowTable, in order to follow-up cutting ferrule can obtain this Truth cards manager end Truth cards information list, facilitates follow-up use.Optionally, Truth cards pipeWhat reason device can get is, and user setup is the Truth cards information of Truth cards allowing to be acquired.
Additionally, Truth cards manager is in addition to generating Truth cards manager end Truth cards information list, also generate Truth cards manager end markKnow list, the mark in this Truth cards manager end identification list and the Truth cards information in Truth cards manager end Truth cards information listOne_to_one corresponding.Specifically, the mark in this Truth cards manager identification list can uniquely identify corresponding Truth cards, and this mark can be:(such as 1 represents and has Truth cards, and 0 represents without truly for the mark that shows whether to have Truth cards to connect at contact interface and/or non-contact interfaceCard), or this mark can be the issuer coding (when such as Truth cards is bank card, this is encoded to bank's coding) of Truth cards, trueThe tail number of the card number of card, Truth cards the information such as the check value (such as CRC check value etc.) of card number in one or its combination in any.VeryReal card management device generates this Truth cards manager end identification list, and follow-up cutting ferrule can be facilitated to carry out the renewal of Truth cards information list.
Certainly, Truth cards manager can detect and generate Truth cards manager end true after each Truth cards manager is started shooting the most againCard image list;Or can also be triggered true card by the function button (physical button or virtual key) that Truth cards manager providesAfter sheet detection, regenerate Truth cards manager end Truth cards information list;Or can also detect very at Truth cards manager every timeWhen real card carries out plugging or carrying out admission appearance, Truth cards information list performs to increase and/or delete the operation of Truth cards information.
Optionally, Truth cards manager could be arranged to preserve the Truth cards letter of all or part of Truth cards in connected Truth cardsBreath, in order to user according to the security requirement of Truth cards is made different setting, such as, can arrange on Truth cards manager and not allow to obtainThe Truth cards information of some Truth cards, thus ensure the safety of these Truth cards.
Specifically, contact interface and/or non-contact interface can be carried out subregion by Truth cards manager, according to the difference using safety coefficientIt is divided into conventional cards region and important card panel region.Such as: Truth cards less for the amounts of money involved such as the card with small amount of money of user, vice card, mass transit card is putPut in conventional cards region, and Truth cards bigger for the amounts of money involved such as the wholesale card of user, credit card main card is placed on important card panel region.
After Truth cards manager carries out subregion to contact interface and/or non-contact interface, can be to allowing to obtain the Truth cards of Truth cardsThe conventional cards region of information is read out, to obtain the Truth cards information of the Truth cards being attached in conventional cards region;And cannot be to notThe important card panel region obtaining the Truth cards information of Truth cards is allowed to be read out, it is impossible to obtain the true card being attached in important card panel regionThe Truth cards information of sheet.Thus, the Truth cards manager end Truth cards information list that Truth cards manager generates can only be included in commonThe Truth cards information of the Truth cards that card panel region connects, cutting ferrule can obtain the Truth cards letter of the Truth cards connected in conventional cards regionBreath, it is impossible to obtain the Truth cards information of Truth cards connected in important card panel region, such as: the Truth cards in conventional cards region forCutting ferrule is visible, and cutting ferrule can directly be attached using;Truth cards in important card panel region is invisible for cutting ferrule, and cutting ferrule cannotDirectly it is attached using, as the Truth cards in important card region need to be attached use, then needs a pair to be in the following way somebody's turn to doCard in important card panel region is configured, in order to cutting ferrule can be attached making with all or part of Truth cards in this important card panel regionWith:
Mode one, user are after input login password, and cutting ferrule only has the authority that the whole Truth cards in conventional cards region are attached use,Not there is the authority that the Truth cards in important card region is attached use, as being attached making to the Truth cards in important card regionWith, then physical button can be set on Truth cards manager or virtual key is set on Truth cards manager or at Truth cardsFunction menu is set on manager, in order to user can arrange cutting ferrule on Truth cards manager and carry out the Truth cards in important card region evenConnect the authority of use.Such as: user can press the option in physical button, virtual key or function menu manually, starts cardSet is attached the authority used to all or part of Truth cards in this important card panel region, so that cutting ferrule can be with this important card sectionIn territory, the Truth cards of open authority is attached using.
Mode two, user are after input login password, and cutting ferrule only has the authority that the whole Truth cards in conventional cards region are attached use,Not there is the authority that the Truth cards in important card region is attached use, as being attached making to the Truth cards in important card regionWith, then client can be set on Truth cards manager, or arrange be connected with Truth cards manager control terminal (such as: PC,Smart mobile phone, panel computer etc.), and client is set in control terminal, user carries out priority assignation by logging in client, with open or passClose the authority that all or part of Truth cards in important card region is attached using by cutting ferrule, in order to make the cutting ferrule can be with this important cardIn region, the Truth cards of open authority is attached using.
Mode three, user are after input login password, and cutting ferrule only has the authority that the whole Truth cards in conventional cards region are attached use,Not there is the authority that the Truth cards in important card region is attached use, as being attached making to the Truth cards in important card regionWith, then web-privilege password Web can be set on Truth cards manager, Truth cards manager can be initiated priority assignation by cutting ferrule by user asks,Truth cards manager is only receiving priority assignation request and is receiving the web-privilege password Web of user's input, and close in the authority of checking user's inputAfter code is correct, just with open or close cutting ferrule, all or part of Truth cards in important card region can be attached the authority of use, in order toMake cutting ferrule can be attached using by the Truth cards of open authority with in this important card panel region.Wherein, web-privilege password Web and login password and reportAlert password is different.Certainly, if the web-privilege password Web of Truth cards manager checking user's input is incorrect, the most do not perform in important card regionAll or part of Truth cards is attached the setting of the authority used.
2, cutting ferrule end Truth cards information list updates:
In the present invention, the cutting ferrule end Truth cards information list that cutting ferrule obtains is that the Truth cards manager end obtained from Truth cards manager is trueCard image list.
Cutting ferrule end Truth cards information list updates and can include following manner:
After mode one, cutting ferrule log in Truth cards manager, Truth cards manager judges whether to need to carry out cutting ferrule end Truth cards information listUpdate and operate:
A kind of implementation of mode one presented below:
Cutting ferrule end identification list searched by cutting ferrule;Specifically, cutting ferrule end identification list is the Truth cards management that cutting ferrule obtains from Truth cards managerDevice end identification list.
If cutting ferrule finds cutting ferrule end identification list, then after utilizing cutting ferrule end the second safe transmission double secret key cutting ferrule end identification list to carry out the first processSending to true card management device, Truth cards manager receives the data that cutting ferrule sends, utilizes Truth cards manager end safe transmission key to dockAfter the data received carry out the second process, it is judged that the Truth cards manager end identification list that the data after the second process store with Truth cards managerIt is the most identical, if it is not the same, then Truth cards manager utilizes Truth cards manager end safe transmission double secret key to update instruction and more new data entersRow first sends to cutting ferrule after processing, and cutting ferrule receives the data that Truth cards manager sends, and utilizes cutting ferrule end the second safe transmission double secret key to receiveTo data carry out the second process after, update cutting ferrule end Truth cards information list;Specifically, update cutting ferrule end Truth cards information list can lead toCross following manner to carry out: the renewal instruction that Truth cards manager sends includes increasing and/or deleting instruction, and more new data packets includes needs to be increased or deleteThe Truth cards information removed, is fastened in after receiving renewal instruction and more new data, believes cutting ferrule end Truth cards according to updating instruction and more new dataBreath list performs to increase and/or deletion action;Or the renewal instruction that Truth cards manager sends includes increasing and/or deleting instruction, more new dataIncluding the mark that the Truth cards information needing increase Truth cards information or needs to delete is corresponding, it is fastened in and receives renewal instruction and more new dataAfter, perform to increase and/or deletion action to cutting ferrule end Truth cards information list according to updating instruction and more new data;Or, Truth cards managerThe renewal instruction sent includes replacement instruction, and more new data packets includes up-to-date Truth cards manager end Truth cards information list, is fastened in and receivesAfter updating instruction and more new data, according to updating instruction and more new data, cutting ferrule end Truth cards information list is performed replacement operation.
If cutting ferrule does not finds cutting ferrule end identification list, then utilize cutting ferrule end the second safe transmission double secret key to preset after mark carries out the first process and sendTo true card management device, Truth cards manager receives the data that cutting ferrule sends, utilizes Truth cards manager end safe transmission double secret key to receiveData carry out the second process after, Truth cards manager determine the second process after data for indicating cutting ferrule end not store cutting ferrule end identification listTime, utilizing Truth cards manager end safe transmission double secret key to update after instruction carries out the first process with more new data and send to cutting ferrule, cutting ferrule receivesThe data that Truth cards manager sends, after the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process, update cutting ferrule endTruth cards information list.Specifically, update cutting ferrule end Truth cards information list can carry out in the following way: Truth cards manager sendsRenewal instruction include storage instruction, more new data packets includes up-to-date Truth cards manager end Truth cards information list, is fastened in and receives renewalAfter instruction and more new data, according to updating instruction and more new data, cutting ferrule end Truth cards information list is performed storage operation.
Above-mentioned implementation based on mode one, cutting ferrule carries out judging whether unanimously to true card management device by being sent by cutting ferrule end identification list,Owing to cutting ferrule end identification list data volume is much smaller than cutting ferrule end Truth cards information list, it therefore reduces the data volume of data transmission, improve numberAccording to transfer rate, also improve the judgement speed of Truth cards manager.If cutting ferrule is to use for the first time, then cutting ferrule itself does not store cutting ferrule endIdentification list, now, sends and presets mark to true card management device, in order to Truth cards manager issues Truth cards manager end identification listAnd Truth cards manager end Truth cards information list is to cutting ferrule, this default mark can be empty mark, predefined numerical value or predefined wordSymbol etc..
Certainly, the invention is not limited in the above-mentioned implementation of mode one, it is also possible to do not store identification list at cutting ferrule and Truth cards managerTime, realize one of in the following way the renewal of cutting ferrule end Truth cards information list:
Cutting ferrule end Truth cards information list is directly transmitted to Truth cards manager, in order to after Truth cards manager is compared, judgement is by cutting ferruleNo renewal;Or
The numbering of table of cutting ferrule end Truth cards information list is sent to Truth cards manager, in order to Truth cards manager comparison list is compiled by cutting ferruleNumber the most identical judging whether updates;Or
Received the renewal instruction of user's input by Truth cards manager after, Truth cards manager is by Truth cards manager end Truth cards informationList sends to cutting ferrule.
Certainly, after Truth cards manager judges that needs are updated, it is also possible to sending renewal inquiry and ask to cutting ferrule, this renewal pointed out by cutting ferruleInquiry request is to user, in order to user is confirmed whether to be updated.
After mode two, cutting ferrule log in Truth cards manager, cutting ferrule judges whether that needing to carry out the renewal of cutting ferrule end Truth cards information list operates:
After Truth cards manager utilizes true cutting ferrule manager end safe transmission double secret key Truth cards manager end identification list to carry out the first processSend to cutting ferrule;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, it is judged that the data after the second process are the most identical with the cutting ferrule end identification list that cutting ferrule stores;Specifically, if cutting ferrule uses for the first time or neverTruth cards manager end identification list is downloaded in success, and storage cutting ferrule end identification list, is not the most directly judged to difference.
If it is not the same, then cutting ferrule sends more newly requested to Truth cards manager;
Truth cards manager receives more newly requested, utilizes Truth cards manager end safe transmission double secret key to update instruction and more new data carries out firstSend to cutting ferrule after process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, update cutting ferrule end Truth cards information list.Specifically, update cutting ferrule end Truth cards information list can carry out in the following way: trueThe renewal instruction that card management device sends includes increasing and/or deleting instruction, and more new data packets includes the Truth cards information needing to increase or delete, cardIt is enclosed within after receiving renewal instruction and more new data, performs to increase and/or delete to cutting ferrule end Truth cards information list according to updating instruction and more new dataDivision operation;Or the renewal instruction that Truth cards manager sends includes increasing and/or deleting instruction, more new data packets includes to be needed to increase Truth cards letterBreath or need mark corresponding to Truth cards information deleted, is fastened in after receiving renewal instruction and more new data, according to updating instruction and updatingCutting ferrule end Truth cards information list is performed to increase and/or deletion action by data;Or, the renewal instruction that Truth cards manager sends includes replacingInstruction, more new data packets includes up-to-date Truth cards manager end Truth cards information list, is fastened in after receiving renewal instruction and more new data,According to updating instruction and more new data, cutting ferrule end Truth cards information list is performed replacement operation.
Above-mentioned implementation based on mode two, Truth cards manager is by judging the transmission of Truth cards manager end identification list to cutting ferruleThe most consistent, owing to Truth cards manager end identification list data volume is much smaller than Truth cards manager end Truth cards information list, therefore, subtractThe data volume of little data transmission, improves message transmission rate, also improves the judgement speed of cutting ferrule.If cutting ferrule is to use for the first time, then blockSet itself does not store cutting ferrule end identification list, now, receives after Truth cards manager issues Truth cards manager end identification list, directlySend more newly requested so that Truth cards manager sends Truth cards manager end Truth cards information list to cutting ferrule.
Certainly, the invention is not limited in the above-mentioned implementation of mode two, it is also possible to do not store identification list at cutting ferrule and Truth cards managerTime, realize one of in the following way the renewal of cutting ferrule end Truth cards information list:
Directly Truth cards manager end Truth cards information list is sent to cutting ferrule, in order to cutting ferrule directly stores by Truth cards manager;Or
The numbering of table of Truth cards manager end Truth cards information list is sent to cutting ferrule, in order to cutting ferrule comparison list is compiled by Truth cards managerNumber the most identical judging whether updates;Or
Received the renewal instruction of user's input by cutting ferrule after, cutting ferrule sends and updates request to Truth cards manager, in order to Truth cards manager is straightConnect and issue the transmission of Truth cards manager end Truth cards information list to cutting ferrule.
Certainly, after cutting ferrule judges that needs are updated, it is also possible to prompting user is confirmed whether to be updated, and after user confirms to be updated,Perform follow-up renewal to operate.
The cutting ferrule of the present invention, in addition to possessing normal mode of operation, also has heart beating park mode, and wherein, heart beating park mode is the non-of low-power consumptionMode of operation, i.e. closes some unnecessary power consumption programs etc..Specifically, cutting ferrule can enter heart beating dormancy mould after not operating in Preset TimeFormula, it is also possible to controlled to enter heart beating park mode by the operation of user.
It is fastened under heart beating park mode, it is also possible to judge whether the secure connection keeping setting up between cutting ferrule and Truth cards manager, in order at cardSet is by when recovering to mode of operation under phychology park mode, it is not necessary to again set up secure connection with Truth cards manager, improves convenience.
A kind of being fastened under heart beating park mode presented below judges whether to keep the tool of the secure connection of foundation between cutting ferrule and Truth cards managerBody implementation:
It is fastened under heart beating park mode, sends detection information every the first Preset Time to Truth cards manager;
Truth cards manager receives detection information, sends response message to cutting ferrule;
If not receiving response message in being fastened in the second Preset Time, then disconnect the secure connection between cutting ferrule and Truth cards manager;
If receiving response message in being fastened in the second Preset Time, then keep the secure connection that cutting ferrule is set up with Truth cards manager.
Do not receive response message in being fastened in the second Preset Time, may be the unstable networks between cutting ferrule and Truth cards manager, or trulyCard management device operation irregularity, the secure connection now disconnected between cutting ferrule and Truth cards manager ensure that safety;It is fastened in second when presettingIn receive response message, then cutting ferrule keep and Truth cards manager between secure connection, when cutting ferrule recovery mode of operation, it is not necessary to again buildVertical secure connection, convenient use.
Certainly, under heart beating park mode, user can also select manually to disconnect the secure connection between cutting ferrule and Truth cards manager, such as, makeCutting ferrule such as is logged off from Truth cards manager at the operation, or user performs power-off operation to cutting ferrule.
Above-mentioned first Preset Time can be identical from the second Preset Time or different.
Under heart beating park mode provided below, the mode that cutting ferrule end Truth cards information list updates:
After mode three, cutting ferrule log in Truth cards manager, cutting ferrule is under heart beating park mode, and it is true that cutting ferrule judges whether to need to carry out cutting ferrule endCard image list update operates:
Under heart beating park mode, also comprise renewal information if received in being fastened in the second Preset Time in response message, and response message,Then cutting ferrule storage updates information;Wherein, updating information is that Truth cards manager informs that cutting ferrule Truth cards manager has Truth cards pipeThe information that reason device end Truth cards information list updates.
After cutting ferrule is entered mode of operation by heart beating park mode, cutting ferrule sends to Truth cards manager and updates the request of triggering;Specifically, cutting ferrule canWith in the following way by heart beating park mode enter mode of operation: cutting ferrule receive renewal information after automatically into mode of operation, or card socketAfter receiving the operational order (such as user carries out the operational order etc. of key-press input) of user's input, enter mode of operation.
Truth cards manager receives and updates the request of triggering, utilizes Truth cards manager end safe transmission double secret key Truth cards manager end identity columnTable sends to cutting ferrule after carrying out the first process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, it is judged that the data after the second process are the most identical with the cutting ferrule end identification list that cutting ferrule stores;Specifically, if cutting ferrule uses for the first time or neverTruth cards manager end identification list is downloaded in success, and storage cutting ferrule end identification list, is not the most directly judged to difference.
If it is not the same, then cutting ferrule sends more newly requested to Truth cards manager;
Truth cards manager receives more newly requested, utilizes Truth cards manager end safe transmission double secret key to update instruction and more new data carries out firstSend to cutting ferrule after process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, update cutting ferrule end Truth cards information list.Specifically, update cutting ferrule end Truth cards information list can carry out in the following way: trueThe renewal instruction that card management device sends includes increasing and/or deleting instruction, and more new data packets includes the Truth cards information needing to increase or delete, cardIt is enclosed within after receiving renewal instruction and more new data, performs to increase and/or delete to cutting ferrule end Truth cards information list according to updating instruction and more new dataDivision operation;Or the renewal instruction that Truth cards manager sends includes increasing and/or deleting instruction, more new data packets includes to be needed to increase Truth cards letterBreath or need mark corresponding to Truth cards information deleted, is fastened in after receiving renewal instruction and more new data, according to updating instruction and updatingCutting ferrule end Truth cards information list is performed to increase and/or deletion action by data;Or, the renewal instruction that Truth cards manager sends includes replacingInstruction, more new data packets includes up-to-date Truth cards manager end Truth cards information list, is fastened in after receiving renewal instruction and more new data,According to updating instruction and more new data, cutting ferrule end Truth cards information list is performed replacement operation.
Above-mentioned implementation based on mode three, Truth cards manager is by judging the transmission of Truth cards manager end identification list to cutting ferruleThe most consistent, owing to Truth cards manager end identification list data volume is much smaller than Truth cards manager end Truth cards information list, therefore, subtractThe data volume of little data transmission, improves message transmission rate, also improves the judgement speed of cutting ferrule.If cutting ferrule is to use for the first time, then blockSet itself does not store cutting ferrule end identification list, now, receives after Truth cards manager issues Truth cards manager end identification list, directlySend more newly requested so that Truth cards manager sends Truth cards manager end Truth cards information list to cutting ferrule.
Certainly, the invention is not limited in the above-mentioned implementation of mode three, it is also possible to do not store identification list at cutting ferrule and Truth cards managerTime, realize one of in the following way the renewal of cutting ferrule end Truth cards information list:
Directly Truth cards manager end Truth cards information list is sent to cutting ferrule, in order to cutting ferrule directly stores by Truth cards manager;Or
The numbering of table of Truth cards manager end Truth cards information list is sent to cutting ferrule, in order to cutting ferrule comparison list is compiled by Truth cards managerNumber the most identical judging whether updates;Or
Received the renewal instruction of user's input by cutting ferrule after, cutting ferrule sends and updates request to Truth cards manager, in order to Truth cards manager is straightConnect and issue the transmission of Truth cards manager end Truth cards information list to cutting ferrule.
After mode four, cutting ferrule log in Truth cards manager, cutting ferrule is under heart beating park mode, and Truth cards manager judges whether that needs are carried outCutting ferrule end Truth cards information list updates and operates:
Being fastened under heart beating park mode, if received in being fastened in the second Preset Time, response message, and response message also comprising renewal prompting letterBreath, then cutting ferrule storage updates information;Wherein, updating information is that Truth cards manager informs that cutting ferrule Truth cards manager has true cardThe information that sheet manager end Truth cards information list updates.
Entering after mode of operation by heart beating park mode at cutting ferrule, cutting ferrule utilizes cutting ferrule end the second safe transmission double secret key cutting ferrule end identification list to carry out theSend to true card management device after one process;Specifically, cutting ferrule can be entered mode of operation by heart beating park mode in the following way: cutting ferrule is receivedTo updating after information automatically into mode of operation, or cutting ferrule receives the operational order of user's input, and (such as user carries out the operation of key-press inputInstruction etc.) after, enter mode of operation.If cutting ferrule is for using for the first time or from being not successfully downloaded Truth cards manager end identification list, then blockingNot storing cutting ferrule end identification list in set, now, cutting ferrule utilizes cutting ferrule end the second safe transmission double secret key to preset after mark carries out the first process and sendsTo true card management device.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondAfter process, it is judged that the data after the second process are the most identical with the Truth cards manager end identification list that Truth cards manager stores;Specifically,Truth cards manager receives presets mark, is also judged as differing.
If it is not the same, then Truth cards manager utilizes Truth cards manager end safe transmission double secret key to update instruction and more new data carries out firstSend to cutting ferrule after process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, update cutting ferrule end Truth cards information list.Specifically, update cutting ferrule end Truth cards information list can carry out in the following way: trueThe renewal instruction that card management device sends includes increasing and/or deleting instruction, and more new data packets includes the Truth cards information needing to increase or delete, cardIt is enclosed within after receiving renewal instruction and more new data, performs to increase and/or delete to cutting ferrule end Truth cards information list according to updating instruction and more new dataDivision operation;Or the renewal instruction that Truth cards manager sends includes increasing and/or deleting instruction, more new data packets includes to be needed to increase Truth cards letterBreath or need mark corresponding to Truth cards information deleted, is fastened in after receiving renewal instruction and more new data, according to updating instruction and updatingCutting ferrule end Truth cards information list is performed to increase and/or deletion action by data;Or, the renewal instruction that Truth cards manager sends includes replacingInstruction, more new data packets includes up-to-date Truth cards manager end Truth cards information list, is fastened in after receiving renewal instruction and more new data,According to updating instruction and more new data, cutting ferrule end Truth cards information list is performed replacement operation.
Above-mentioned implementation based on mode four, cutting ferrule carries out judging whether unanimously to true card management device by being sent by cutting ferrule end identification list,Owing to cutting ferrule end identification list data volume is much smaller than cutting ferrule end Truth cards information list, it therefore reduces the data volume of data transmission, improve numberAccording to transfer rate, also improve the judgement speed of Truth cards manager.If cutting ferrule is to use for the first time, then cutting ferrule itself does not store cutting ferrule endIdentification list, now, sends and presets mark to true card management device, in order to Truth cards manager issues Truth cards manager end identification listAnd Truth cards manager end Truth cards information list is to cutting ferrule, this default mark can be empty mark, predefined numerical value or predefined wordSymbol etc..
Certainly, the invention is not limited in the above-mentioned implementation of mode four, it is also possible to do not store identification list at cutting ferrule and Truth cards managerTime, realize one of in the following way the renewal of cutting ferrule end Truth cards information list:
Cutting ferrule end Truth cards information list is directly transmitted to Truth cards manager, in order to after Truth cards manager is compared, judgement is by cutting ferruleNo renewal;Or
The numbering of table of cutting ferrule end Truth cards information list is sent to Truth cards manager, in order to Truth cards manager comparison list is compiled by cutting ferruleNumber the most identical judging whether updates;Or
Received the renewal instruction of user's input by Truth cards manager after, Truth cards manager is by Truth cards manager end Truth cards informationList sends to cutting ferrule.
Optionally, it is attached using to all or part of Truth cards in important card region at the open or close cutting ferrule of Truth cards managerAuthority after, owing to Truth cards manager end Truth cards information list is updated, therefore, Truth cards manager can will open cutting ferruleThe Truth cards information of the authority that all or part of Truth cards in important card region is attached use sends to cutting ferrule, in order to cutting ferrule is moreNew cutting ferrule end Truth cards information list;Or at all or part of true in important card region of the open or close cutting ferrule of Truth cards managerAfter real card is attached the authority used, triggering the flow process that cutting ferrule end Truth cards information list updates, update mode is referred to aforesaid way oneWith the update mode of mode two, it is not described in detail in this.
In the more new data that above Truth cards manager sends in addition to comprising Truth cards manager end Truth cards information list, also comprise trueReal card management device end identification list, in order to cutting ferrule obtains up-to-date identification list.
Four, the Truth cards chosen is determined:
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, optionally, before this step, it is also possible to perform cutting ferrule start, cutting ferrule logs in trueThe operation of real card management device, does not repeats them here, and specifically may refer to the start of above-mentioned relevant cutting ferrule and cutting ferrule logs in the relevant of Truth cards managerDescribe.In this step, cutting ferrule obtains cutting ferrule end Truth cards information list, it is also possible to include that cutting ferrule updates cutting ferrule end Truth cards information listStep, also repeats no more at this, specifically may refer to above-mentioned cutting ferrule and updates the associated description of cutting ferrule end Truth cards information list.Cutting ferrule is from true cardAfter the Truth cards manager end Truth cards information list obtained in sheet manager, store it in the memory area of cutting ferrule, true as cutting ferrule endReal card image list, when cutting ferrule needs prompting (such as display or speech play etc.) cutting ferrule end Truth cards information list, can be from this localityDirectly obtain this cutting ferrule end Truth cards information list, improve the processing speed of cutting ferrule.
Cutting ferrule prompting cutting ferrule end Truth cards information list;Specifically, cutting ferrule utilizes the display device of self or by exterior display device display cardOverlap end Truth cards information list, or cutting ferrule utilizes the voice playing device of self or by external voice playing device speech play (such as loudspeakerPlay or by headset earpiece broadcasting etc.) cutting ferrule end Truth cards information list, select according to cutting ferrule end Truth cards information list for userSelect the Truth cards needing to use when being traded, facilitate user to select, strengthen Consumer's Experience.
Cutting ferrule receives Truth cards and selects instruction, determines the Truth cards chosen;Specifically, the Truth cards that cutting ferrule receives selects instruction can be singleSolely be arranged on what the selection physical button that card puts generated, or can be to select virtual key generation on the touch screen of cutting ferrule, or can beOn cutting ferrule screen, the menu of display is chosen and represent what the menu item of selection function generated.Cutting ferrule receives Truth cards and selects instruction, determines choose trueReal card, cutting ferrule realizes data transmission via Truth cards manager and the Truth cards chosen.Furthermore it is possible to realize in the following way determining choosingIn Truth cards: cutting ferrule receives Truth cards and selects instruction, obtains and chooses mark, wherein, chooses and identifies for the Truth cards chosen of instruction;Cutting ferrule will choose mark to send to true card management device;Truth cards manager is according to choosing the true card identified from being connected with Truth cards managerIn sheet, determine the Truth cards chosen corresponding with choosing mark;Wherein, choosing mark can be the part or all of information in Truth cards information,Such as: card number and/or Truth cards manager reading-writing port mark;Truth cards manager receives after choosing mark, can manage at Truth cardsDevice end Truth cards information list finds the Truth cards manager reading-writing port mark corresponding with choosing mark, in order to Truth cards manager is trueIts reading-writing port fixed, thus carry out data interaction by this reading-writing port with the Truth cards chosen.
Five, data interaction:
Simulation card receives the data that transaction terminal sends, and after the data utilizing analog card bit end safe transmission double secret key to receive carry out the first processSend to cutting ferrule;Specifically, in data exchange process, (such as ATM, POS, mass transit card are supplemented with money with transaction terminal will to simulate cardMachine etc.) it is attached (contact interface or non-contact interface), simulation card receives the data that transaction terminal sends, and these data can be to treatThe data (such as withdraw funds, deducted amount, Truth cards information acquisition request etc.) processed.
After cutting ferrule receives simulates the data that card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process;Specifically, card socketReceive the data that simulation card sends, and after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, it is also possible to prompting theTwo process after data, and receive for instruction second process after data correct confirmation instruction after, utilize cutting ferrule end the second safe transmission double secret keyData after second process send to true card management device after carrying out the first process;Based on this, cutting ferrule can also show pending data, it is possible toWith the data that speech play (such as loudspeaker are play or by headset earpiece broadcasting etc.) is pending, whether confirm these pending data for userCorrectly, only after correct, after what reception user inputted indicates the confirmation instruction that pending data are correct, just by this pending data transmission extremelyTruth cards manager;If user confirms that these pending data are incorrect, then can directly cancel this secondary data mutual, with this, improve dataMutual safety.Cutting ferrule receive for instruction second process after data correct confirm instruction can be to be provided separately within the confirmation thing that card putsReason button generates, or can be that confirming on the touch screen of cutting ferrule selects really in virtual key generation, or the menu shown on cutting ferrule screenRecognize what function generated, or can be the voice that the voice acquisition device (such as Mike) of cutting ferrule receives generation when confirming instruction and be verified rear, or can be that the fingerprint acquisition device of cutting ferrule receives and generates after fingerprint identification indicates and is verified, or can be that the iris of cutting ferrule is adoptedAcquisition means receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes, the most notIt is restricted.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out theSend to the Truth cards chosen after two process;Specifically, pending data are sent to the Truth cards chosen by Truth cards manager, in order toPending data are processed by the Truth cards chosen.
The Truth cards chosen receives the data that Truth cards manager end sends, and the data that will obtain after processing after processing send to truly blockingSheet manager;Specifically, pending data are processed by the Truth cards chosen, and this is processed as the scheme of process of existing smart card, at thisRepeat no more.
Truth cards manager receives the data that the Truth cards chosen sends, and utilizes Truth cards manager end safe transmission double secret key to receiveData send to cutting ferrule after carrying out the first process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card overlaps the data sent, and the data utilizing analog card bit end safe transmission double secret key to receive carry out transmission after the second processTo transaction terminal.Specifically, after transaction terminal receives the data after Truth cards processes, can be according to implementing at the demand of sceneReason, note output of such as withdrawing the money, transfer accounts, swipe the card and withhold, supplement operation etc. with money.
Based on above-mentioned data interaction flow process, can be realized the function of multiple different types of Truth cards by a simulation card, user is carried outDuring data interaction, only need to carry simulation card and cutting ferrule, it is not necessary to carry Truth cards and i.e. can complete, improve convenience and safety.
Cutting ferrule can be pointed out needing the information confirmed in data exchange process, and thus, needing in data exchange process can be confirmed by userInformation confirm after perform mutual again, thus ensure the verity of data interaction, improve safety.
In data transmission procedure, simulation card, carry out data interaction between cutting ferrule and Truth cards manager and all added by safe transmission keyDeciphering and/or verification operation, thus ensure safety and the integrity that data transmit.
Additionally, due to can select to use the Truth cards mated with transaction terminal, user in prior art can be solved and do not carry and transaction terminalThe Truth cards joined and the unnecessary expense expenditure (such as bank's inter-bank withdraw the money the fee etc.) that produces.
Certainly, above-mentioned implementing only discloses from transaction terminal to Truth cards, and the single data interaction of Truth cards to transaction terminal, in realityIn application, it is understood that there may be repeatedly data interaction, interaction flow is similar to above-mentioned single data interaction, in repeatedly data interaction, and can be according to alternatelyData the need of confirming to be arranged at cutting ferrule and whether point out mutual data to ensure the verity of interaction data.
Six, transaction:
Utilize the data interaction framework of the present invention, it is also possible to realize the operations such as transaction (such as ATM withdraw the money transfer accounts, POS is swiped the card), withFacilitate user only to carry the cutting ferrule of the present invention and simulation card i.e. can realize the transaction of multiple variety classes Truth cards, facilitate user to carry, it is to avoidTruth cards loses the loss of assets caused.
The following provide a kind of particular transactions flow process, but the invention is not limited in this:
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, optionally, before this step, it is also possible to perform cutting ferrule start, cutting ferrule logs in trueThe operation of real card management device, does not repeats them here, and specifically may refer to the start of above-mentioned relevant cutting ferrule and cutting ferrule logs in the relevant of Truth cards managerDescribe.In this step, cutting ferrule obtains cutting ferrule end Truth cards information list, it is also possible to include that cutting ferrule updates cutting ferrule end Truth cards information listStep, also repeats no more at this, specifically may refer to above-mentioned cutting ferrule and updates the associated description of cutting ferrule end Truth cards information list.Cutting ferrule is from true cardAfter the Truth cards manager end Truth cards information list obtained in sheet manager, store it in the memory area of cutting ferrule, true as cutting ferrule endReal card image list, when cutting ferrule needs prompting (such as display or speech play etc.) cutting ferrule end Truth cards information list, can be from this localityDirectly obtain this cutting ferrule end Truth cards information list, improve the processing speed of cutting ferrule.
Cutting ferrule prompting cutting ferrule end Truth cards information list;Specifically, cutting ferrule utilizes the display device of self or by exterior display device display cardOverlap end Truth cards information list, or cutting ferrule utilizes the voice playing device of self or by external voice playing device speech play (such as loudspeakerPlay or by headset earpiece broadcasting etc.) cutting ferrule end Truth cards information list, select according to cutting ferrule end Truth cards information list for userSelect the Truth cards needing to use when being traded, facilitate user to select, strengthen Consumer's Experience.
Cutting ferrule receives Truth cards and selects instruction, determines the Truth cards chosen;And simulation card receives the data that transaction terminal sends, and utilizeThe data that analog card bit end safe transmission double secret key receives send to cutting ferrule after carrying out the first process;Specifically, the Truth cards that cutting ferrule receives selectsInstruction can be to be provided separately within the selection physical button generation that card puts, or can be that the virtual key that selects on the touch screen of cutting ferrule generates,Or can be the menu of display to be chosen to represent that the menu item selecting function generates on cutting ferrule screen.Cutting ferrule receives Truth cards and selects instruction,Determining the Truth cards chosen, cutting ferrule realizes data transmission via Truth cards manager and the Truth cards chosen.It addition, in process of exchange,Simulation card is attached (contact interface or non-contact interface) with transaction terminal (such as ATM, POS etc.), simulates cardReceiving the data that transaction terminal sends, these data can be pending transaction data (such as withdraw funds, deducted amount etc.), in order to follow-up useFamily confirms that this pending transaction data is the most correct.Additionally, before simulation card receives the pending transaction data that transaction terminal sends, mouldIntending card and can also receive the Truth cards information request of Truth cards that the acquisition that transaction terminal sends is chosen, cutting ferrule receives the number that simulation card sendsAccording to, and after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, recycle cutting ferrule end the second safe transmission double secret keyData after second process send after carrying out the first process to true card management device, and Truth cards manager receives the data that cutting ferrule sends, and utilizesThe data that Truth cards manager end safe transmission double secret key receives send to the Truth cards chosen, the Truth cards chosen after carrying out the second processReceiving the data that Truth cards manager end sends, and send the Truth cards information obtained to true card management device, Truth cards manager connectsReceive the data that the Truth cards chosen sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out the first process after send outDeliver to cutting ferrule, cutting ferrule receive data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out theAfter two process, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process, analog cardSheet receive cutting ferrule send data, and the data utilizing analog card bit end safe transmission double secret key to receive carry out the second process after send to end of concluding the businessEnd, thus, transaction terminal gets the Truth cards information of the Truth cards chosen, in order to follow-up be traded for this Truth cards.
After cutting ferrule receives simulates the data that card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, carryShow the data after the second process, and after receiving the confirmation instruction that the data after instruction the second process are correct, utilize cutting ferrule end the second safe transmission closeKey sends to true card management device after the data after the second process are carried out the first process;Specifically, cutting ferrule can show pending transaction data,Can also the pending transaction data of speech play (such as loudspeaker play or by headset earpiece broadcasting etc.), confirm that this is pending for userThis most correctly, only after correct, after the confirmation indicating pending transaction data correct of reception user's input instructs, is just treated by transaction dataThe transaction data processed sends to true card management device;If user confirms that this pending transaction data is incorrect, then can directly cancel this penTransaction, with this, improves the safety of transaction.What cutting ferrule received be used for the correct confirmation of the data after instruction second processes to instruct can be to be separately providedCard set recognizes what physical button generated really, or can be that the confirmation virtual key on the touch screen of cutting ferrule generates, or aobvious on cutting ferrule screenThe menu shown selects confirm what function generated, or can be that the voice that the voice acquisition device (such as Mike) of cutting ferrule receives confirms to indicate alsoGenerate when being verified rear, or can be that the fingerprint acquisition device of cutting ferrule receives generation after fingerprint identification indicates and is verified, or canThink that the iris collection device of cutting ferrule receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes,The most it is not restricted.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out theSend to the Truth cards chosen after two process;Specifically, pending transaction data is sent to the Truth cards chosen by Truth cards manager,So that pending transaction data is processed by the Truth cards chosen.
The Truth cards chosen receives the data that Truth cards manager end sends, and the data transmission that will obtain after trading processing after carrying out trading processingTo true card management device;Specifically, pending transaction data is traded processing by the Truth cards chosen, and this trading processing is existing intelligenceThe scheme of the trading processing of card, does not repeats them here.
Truth cards manager receives the data that the Truth cards chosen sends, and utilizes Truth cards manager end safe transmission double secret key to receiveData send to cutting ferrule after carrying out the first process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card overlaps the data sent, and the data utilizing analog card bit end safe transmission double secret key to receive carry out transmission after the second processTo transaction terminal.Specifically, after transaction terminal receives the data after Truth cards trading processing, can be completed this according to existing transaction flowTransaction, note output of such as withdrawing the money, transfer accounts, swipe the card and withhold.
Based on above-mentioned transaction flow, can be realized the function of multiple different types of Truth cards by a simulation card, user is tradedTime, only need to carry simulation card and cutting ferrule, it is not necessary to carry Truth cards and i.e. can complete transaction, improve transaction convenience and safety.
Cutting ferrule can be pointed out needing the information confirmed in process of exchange, and thus, the information needing to confirm in process of exchange can be entered by userRow performs transaction again after confirming, thus ensures the verity of transaction, improves safety.
In data transmission procedure, simulation card, carry out data interaction between cutting ferrule and Truth cards manager and all added by safe transmission keyDeciphering and/or verification operation, thus ensure safety and the integrity that data transmit.
Additionally, due to can select to use the Truth cards mated with transaction terminal, user in prior art can be solved and do not carry and transaction terminalThe Truth cards joined and the unnecessary expense expenditure (such as bank's inter-bank withdraw the money the fee etc.) that produces.
Certainly, above-mentioned implementing only discloses from transaction terminal to Truth cards, and the single data interaction of Truth cards to transaction terminal, in realityIn application, it is understood that there may be repeatedly data interaction, interaction flow is similar to above-mentioned single data interaction, in repeatedly data interaction, and can be according to alternatelyData the need of confirming to be arranged at cutting ferrule and whether point out mutual data to ensure the verity of interaction data.
Seven, application program update:
1, cutting ferrule application program update:
In the present invention, the application program that self can also have been installed by cutting ferrule is updated or installs new opplication program, in order to expand cutting ferruleTypes of applications or existing application to cutting ferrule upgrade:
The present invention provides the specific implementation of a kind of cutting ferrule application program update, but the invention is not limited in this:
Fig. 8 shows that the data interaction system that the embodiment of the present invention provides realizes the flow chart of cutting ferrule application program update, sees Fig. 8, and cutting ferrule is appliedProgram updates and includes:
Cutting ferrule sends to updating platform to major general's cutting ferrule certificate;Specifically, safe renewal platform it is separately provided to complete cutting ferrule application program moreNewly.Cutting ferrule certificate is sent to updating platform by cutting ferrule, in order to updates platform and knows which cutting ferrule needs to update, can also verify the body of cutting ferrule simultaneouslyPart;Cutting ferrule can also by need the application program identification updated or other inform that updating platform needs the information of application program updating or downloading to send outDeliver to update platform, in order to renewal platform is known to be needed to send which application program installation kit to cutting ferrule.
Update platform and generate the first renewal encryption key;Specifically, platform self generation is updated close for the renewal encryption encrypting application program installation kitKey, carries out the renewal encryption key of generation during application program update every time and can be the same or different, and difference is then possible to prevent to be cracked, and improves peaceQuan Xing.
Updating platform utilizes the first renewal encryption key that cutting ferrule application program installation kit is encrypted acquisition the first installation kit ciphertext;Specifically, updatePlatform utilizes the renewal encryption keys cutting ferrule application program installation kit generated, thus ensures the safety that cutting ferrule application program installation kit transmits.
Updating platform utilizes renewal platform private key that the first installation kit ciphertext carries out signature acquisition the first installation kit signature;Specifically, platform is updated to theOne installation kit ciphertext is signed, in order to the identity updating platform is verified by follow-up cutting ferrule.
Updating platform utilizes the cutting ferrule public key encryption first in cutting ferrule certificate to update encryption key, it is thus achieved that first updates encryption key ciphertext;Specifically,Updating platform utilizes cutting ferrule public key encryption to update encryption key, it is ensured that update the safety of encryption key transmission, simultaneously, it is ensured that only cutting ferrule isRenewal encryption key can be decrypted, improve the safety of application program installation kit transmission.
Update platform by cutting ferrule more fresh information send to cutting ferrule, wherein, cutting ferrule more fresh information includes: update platform credential, the first installation kit ciphertext,First installation kit signature and first updates encryption key ciphertext;Specifically, update platform send more fresh information in carry renewal platform credential so thatCutting ferrule is authenticated updating platform, carries the first installation kit ciphertext and ensure the safety of application program installation kit transmission, more fresh information in more fresh informationIn carry first installation kit signature with ensure follow-up cutting ferrule can to update platform identity legitimacy be authenticated, more fresh information carries renewal encryptionKey ciphertext ensures to update the safety of encryption key transmission.
Cutting ferrule receives cutting ferrule and updates information, utilizes root certification authentication to update platform credential;Specifically, cutting ferrule prestores root certificate, utilizes this root to demonstrate,proveBook completes the checking updating platform credential, to ensure the follow-up safety using renewal platform credential.
After cutting ferrule checking renewal platform credential is passed through, utilize the renewal platform PKI updated in platform credential that the first installation kit signature is carried out sign test;ToolBody ground, cutting ferrule utilizes the platform PKI that updates in the renewal platform credential after being verified to verify the signature updating platform transmission, to guarantee numberAccording to legitimate origin.
After cutting ferrule verifies that the first installation kit signature is correct, utilize cutting ferrule private key deciphering the first renewal encryption key ciphertext, it is thus achieved that the first decruption key;ToolBody ground, cutting ferrule utilizes cutting ferrule private key to decrypt decruption key, in order to subsequent decryption installation kit ciphertext obtains cutting ferrule application program installation kit.
Cutting ferrule utilizes first decryption key decryption the first installation kit ciphertext, it is thus achieved that cutting ferrule application program installation kit;
The data form of cutting ferrule checking cutting ferrule application program installation kit is the most correct;Specifically, the data of cutting ferrule application program installation kit also verified by cutting ferruleForm is the most correct, if the data form of cutting ferrule application program installation kit is incorrect, does not the most perform to install operation, if cutting ferrule application program is installedThe data form of bag is correct, then perform installation.
If the data form of cutting ferrule checking cutting ferrule application program installation kit is correct, cutting ferrule is installed according to cutting ferrule application program installation kit.Specifically,If cutting ferrule is to be updated the application program installed, then can cover mounted application program, or mounted application program is enteredThe installation of new application program is carried out again, if cutting ferrule is newly installed application program, then after row upgrading, or the mounted application program of leading unloadingThis application program can be mounted directly.
The cutting ferrule based on the present invention renewal to application program, both can update mounted application program, it is also possible to download new application program and pacifyDress, has expanded the function of cutting ferrule, has been user-friendly to.
2, simulation card application program update:
In the present invention, the application program that self can also have been installed by simulation card is updated or installs new opplication program, in order to expandThe types of applications of simulation card or the existing application to simulation card are upgraded:
The present invention provides a kind of specific implementation simulating card application program update, but the invention is not limited in this:
Fig. 9 shows that the data interaction system that the embodiment of the present invention provides realizes the flow chart of simulation card application program update, sees Fig. 9, simulationCard application program update includes:
Cutting ferrule obtains simulation card certificate from simulation card, sends to updating platform to major general's analog card sheet certificate;Specifically, cutting ferrule can pass throughFollowing manner obtains simulation card certificate from simulation card: after cutting ferrule is by contact or non-contact detection to simulation card, to simulating cardSend the request obtaining simulation card certificate, after simulation card receives the request that cutting ferrule sends, simulation card certificate is sent to cutting ferrule;Or cardAfter overlapping by contact or non-contact detection to simulation card, simulation card actively will simulation card certificate transmission to cutting ferrule.Optional alternativeCase: after cutting ferrule is by contact or non-contact detection to simulation card, sends to simulation card and obtains simulation card uniquely identified and ask, mouldAfter intending the request that card receives cutting ferrule transmission, uniquely being identified by simulation card and send to cutting ferrule, cutting ferrule receives after simulation card uniquely identifies also may be usedWith according to this simulation card uniquely identify from locally stored cutting ferrule end the first list of bindings obtain simulation card uniquely identify correspondence simulation cardCertificate;Or after cutting ferrule is by contact or non-contact detection to simulation card, simulation card is actively uniquely identified transmission and extremely blocks by simulation cardSet, cutting ferrule receives after simulation card uniquely identifies and uniquely can also identify from locally stored cutting ferrule end the first list of bindings according to this simulation cardObtain simulation card and uniquely identify the simulation card certificate of correspondence.It addition, be separately provided safe renewal platform to complete to simulate card application programRenewal.Simulation card certificate is sent to updating platform by cutting ferrule, in order to updates platform and knows which simulation card needs to update, simultaneously can alsoThe identity of checking simulation card;Cutting ferrule can also by need update application program identification or other inform update platform need update or downloadThe information of application program sends to updating platform, in order to renewal platform is known to be needed to send which application program installation kit to simulating card.
Update platform and generate the second renewal encryption key;Specifically, platform self generation is updated close for the renewal encryption encrypting application program installation kitKey, carries out the renewal encryption key of generation during application program update every time and can be the same or different, and difference is then possible to prevent to be cracked, and improves peaceQuan Xing.
Updating platform utilizes the second renewal encryption key that simulation card application program installation kit is encrypted acquisition the second installation kit ciphertext;Specifically,Update platform and utilize the renewal encryption keys simulation card application program installation kit generated, thus ensure to simulate the transmission of card application program installation kitSafety.
Updating platform utilizes renewal platform private key that the second installation kit ciphertext carries out signature acquisition the second installation kit signature;Specifically, platform is updated to theTwo installation kit ciphertexts are signed, in order to the identity updating platform is verified by follow-up simulation card.
Updating platform utilizes the simulation card public key encryption second in simulation card certificate to update encryption key, it is thus achieved that second updates encryption key ciphertext;Specifically, updating platform utilizes simulation card public key encryption to update encryption key, it is ensured that updates the safety of encryption key transmission, protects meanwhileCard only simulation card just can decrypt renewal encryption key, improves the safety of application program installation kit transmission.
Updating platform to send simulation card renewal information to cutting ferrule, wherein, simulation card updates information and includes: update platform credential, the second installationBag ciphertext, the second installation kit signature and second update encryption key ciphertext;Specifically, update in the more fresh information of platform transmission and carry renewal platformCertificate, so that simulation card is authenticated updating platform, carries the second installation kit ciphertext and ensures the safety of application program installation kit transmission in more fresh informationProperty, carrying the second installation kit signature in more fresh information can be authenticated the legitimacy updating platform identity with the follow-up simulation card of guarantee, updates letterBreath carries and updates the safety that encryption key ciphertext ensures that renewal encryption key transmits.
Cutting ferrule receives simulation card and updates information, utilizes cutting ferrule end the first safe transmission double secret key simulation card to update after information carries out the first process and sendsTo simulating card;Specifically, cutting ferrule utilizes the safe transmission double secret key simulation card generated when setting up secure connection between cutting ferrule and simulation card to updateInformation is transmitted after processing, and can improve the safety of data transmission.
The data that simulation card receiving card set sends, after the data utilizing analog card bit end safe transmission double secret key to receive carry out the second process, it is thus achieved thatSimulation card updates information;
Simulation card utilizes root certification authentication to update platform credential;Specifically, simulation card prestores root certificate, utilizes this root certificate to complete moreThe checking of new platform credential, to ensure the follow-up safety using renewal platform credential.
After simulation card checking renewal platform credential is passed through, utilize the renewal platform PKI updated in platform credential that the second installation kit signature is testedSign;Specifically, simulation card utilizes the platform PKI that updates in the renewal platform credential after being verified to verify the signature updating platform transmission,To guarantee the legitimate origin of data.
After simulation card verifies that the second installation kit signature is correct, utilize simulation card private key deciphering the second renewal encryption key ciphertext, it is thus achieved that the second decipheringKey;Specifically, simulation card utilizes simulation card private key to decrypt decruption key, in order to subsequent decryption installation kit ciphertext obtains simulation card applicationProgram installation kit.
Simulation card utilizes second decryption key decryption the second installation kit ciphertext, it is thus achieved that simulation card application program installation kit;
The data form of simulation card checking simulation card application program installation kit is the most correct;Specifically, simulation card application also verified by simulation cardThe data form of program installation kit is the most correct, if the data form of simulation card application program installation kit is incorrect, does not the most perform to install operation,If the data form of simulation card application program installation kit is correct, then perform installation.
If the data form of simulation card checking simulation card application program installation kit is correct, simulation card is according to simulation card application program installation kitInstall.Specifically, if simulation card is to be updated the application program installed, then mounted application program can be covered, orMounted application program is upgraded by person, or carries out the installation of new application program after the mounted application program of leading unloading again, if mouldIntending card is newly installed application program, then can be mounted directly this application program.
The renewal of simulation card correspondence program based on the present invention, both can update mounted application program, it is also possible to download new application programAnd install, expand the function of simulation card, be user-friendly to.
3, Truth cards manager application updates:
In the present invention, the application program that self can also have been installed by Truth cards manager is updated or installs new opplication program, withJust expand the types of applications of Truth cards manager or the existing application to Truth cards manager upgraded:
The present invention provides the specific implementation that a kind of Truth cards manager application updates, but the invention is not limited in this:
Figure 10 shows that the data interaction system that the embodiment of the present invention provides realizes the flow chart that Truth cards manager application updates, and sees figure10, Truth cards manager application updates and includes:
Truth cards manager sends to updating platform to major general's Truth cards manager certificate;Specifically, be separately provided safe renewal platform so thatComplete the renewal of Truth cards manager application.Truth cards manager certificate is sent to updating platform by Truth cards manager, in order to updatePlatform knows which Truth cards manager needs to update, and can also verify the identity of Truth cards manager simultaneously;Truth cards manager also may be usedWith by need the application program identification updated or other inform and update platform to need the information of the application program updating or downloading to send to updating flatPlatform, in order to renewal platform is known to be needed to send which application program installation kit to true card management device.
Update platform and generate the 3rd renewal encryption key;Specifically, platform self generation is updated close for the renewal encryption encrypting application program installation kitKey, carries out the renewal encryption key of generation during application program update every time and can be the same or different, and difference is then possible to prevent to be cracked, and improves peaceQuan Xing.
Updating platform utilizes the 3rd renewal encryption key that Truth cards manager application installation kit is encrypted acquisition the 3rd installation kit ciphertext;ToolBody ground, updates platform and utilizes the renewal encryption keys Truth cards manager application installation kit generated, thus ensure Truth cards managerThe safety of application program installation kit transmission.
Updating platform utilizes renewal platform private key that the 3rd installation kit ciphertext carries out signature acquisition the 3rd installation kit signature;Specifically, platform is updated to theThree installation kit ciphertexts are signed, in order to the identity updating platform is verified by follow-up Truth cards manager.
Updating platform utilizes the Truth cards manager public key encryption the 3rd in Truth cards manager certificate to update encryption key, it is thus achieved that the 3rd renewal addsDecryption key ciphertext;Specifically, updating platform utilizes Truth cards manager public key encryption to update encryption key, it is ensured that update encryption key transmissionSafety, simultaneously, it is ensured that only Truth cards manager just can decrypt renewal encryption key, improves the safety of application program installation kit transmissionProperty.
Updating platform to send Truth cards manager more fresh information to true card management device, wherein, Truth cards manager more fresh information includes:Update platform credential, the 3rd installation kit ciphertext, the 3rd installation kit signature and the 3rd renewal encryption key ciphertext;Specifically, update what platform sentMore fresh information carries renewal platform credential so that Truth cards manager is authenticated updating platform, more fresh information carries the 3rd installation kit ciphertextEnsure the safety of application program installation kit transmission, more fresh information carries the 3rd installation kit signature to ensure that follow-up Truth cards manager can be to moreThe legitimacy of new platform identity is authenticated, and carries and update the safety that encryption key ciphertext ensures that renewal encryption key transmits in more fresh information.
Truth cards manager receives Truth cards manager more fresh information, utilizes root certification authentication to update platform credential;Specifically, Truth cards pipeReason device prestores root certificate, utilizes this root certificate to complete the checking updating platform credential, to ensure the follow-up safety using renewal platform credential.
The checking of Truth cards manager updates after platform credential passes through, utilize the renewal platform PKI updated in platform credential the 3rd installation kit is signed intoRow sign test;Specifically, the renewal platform PKI during Truth cards manager utilizes the renewal platform credential after being verified is to updating the label that platform sendsName is verified, to guarantee the legitimate origin of data.
After Truth cards manager checking the 3rd installation kit signature is correct, utilize Truth cards manager private key deciphering the 3rd renewal encryption key ciphertext,Obtain the 3rd decruption key;Specifically, Truth cards manager utilizes Truth cards manager private key to decrypt decruption key, in order to subsequent decryption is pacifiedDress bag ciphertext obtains Truth cards manager application installation kit.
Truth cards manager utilizes the 3rd decryption key decryption the 3rd installation kit ciphertext, it is thus achieved that Truth cards manager application installation kit;
The data form of Truth cards manager checking Truth cards manager application installation kit is the most correct;Specifically, Truth cards managerThe also data form of checking Truth cards manager application installation kit is the most correct, if the data of Truth cards manager application installation kitForm is incorrect, does not the most perform to install operation, if the data form of Truth cards manager application installation kit is correct, then performs installation.
If the data form of Truth cards manager checking Truth cards manager application installation kit is correct, Truth cards manager is according to trueCard management device application program installation kit is installed.Specifically, if Truth cards manager is to be updated the application program installed,Then can cover mounted application program, or mounted application program is upgraded, or after the mounted application program of leading unloading againCarry out the installation of new application program, if Truth cards manager is newly installed application program, then can be mounted directly this application program.
The Truth cards manager based on the present invention renewal to application program, both can update mounted application program, it is also possible to download new answeringBy program and install, expand the function of Truth cards manager, be user-friendly to.
Eight, the application scenarios that data interaction framework is suitable for:
1, to account charging:
In a kind of application scenarios that the present embodiment provides, user is based on above-mentioned data interaction framework, it is possible to achieve supplement third party's account with money, exampleAs to Alipay account charging.
Realization to this application scene is specifically described below, but the invention is not limited in this:
Cutting ferrule passes through network entry account platform;Specifically, cutting ferrule passes through wireless network logon account platform, in order to by the data interaction of the present inventionCutting ferrule and Truth cards manager in framework complete to supplement account with money.Wherein, account platform can be virtual third party's account platform, such as:E-commerce website account platform (such as Alipay etc.), paying electric charge platform, network finance platform (such as fund etc.).
Charging request is sent to account platform by cutting ferrule, and wherein, charging request includes: charging information;Specifically, charging request is sent extremely by cutting ferruleAccount platform, in order to account platform supplements bag with money according to charging request feedback.Wherein, charging information includes: recharge amount etc., optionally, it is also possible toIncluding account to be supplemented with money, in order to account platform is known and for which account supplemented with money.
Cutting ferrule receives and supplements bag with money, wherein, supplements bag with money and is generated after receiving charging request by payment platform;Specifically, it is fastened in charging request transmissionWhile account platform or again after it, also this charging request is sent to payment platform, or, after account platform receives charging request,Charging request is sent to payment platform, just pays with payment platform.After this payment platform receives charging request, also generate and supplement bag with money, itsIn, to supplement bag with money and include: the information such as recharge amount, account to be supplemented with money, payment platform will be supplemented bag with money and be sent to cutting ferrule, or payment platform will supplement bag with moneySend to account platform, then by account platform will supplement with money bag send to cutting ferrule, in order to user carry out on cutting ferrule confirmation supplement with money wrap the most errorless.Wherein,Payment platform is the transaction platform corresponding with Truth cards, such as Net silver etc..
Bag is supplemented in cutting ferrule prompting with money, receives and supplements, for confirmation, the confirmation instruction that bag is errorless with money;Specifically, it is fastened in after receiving and supplementing bag with money, also will supplement with moneyBag carries out showing or speech play, in order to the information supplemented with money in bag is confirmed by user, if user confirms errorless, confirms on cutting ferruleOperation (such as pressing confirmation button, select the modes such as the confirmation option in menu) generates supplements the confirmation instruction that bag is errorless, card socket with money for confirmationReceive this confirmation instruction, in order to cutting ferrule continues executing with subsequent operation;Certainly, if user confirms to supplement the problem of being surrounded by with money, then can take on cutting ferruleDisappear operation, in order to cancels this pen and supplements with money.What cutting ferrule received is used for confirming that the confirmation instruction supplementing bag with money errorless can be to be provided separately within the confirmation that card putsPhysical button generates, or can be that confirming on the touch screen of cutting ferrule selects in virtual key generation, or the menu shown on cutting ferrule screenConfirm what function generated, or can be the voice that the voice acquisition device (such as Mike) of cutting ferrule receives life when confirming instruction and be verified rearBecome, or can be that the fingerprint acquisition device of cutting ferrule receives generation after fingerprint identification indicates and is verified, or can be the iris of cutting ferruleHarvester receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes, the most alsoIt is not restricted.Certainly, while this step or before this step, cutting ferrule also needs to log in Truth cards manager, and is chosen as account and entersThe Truth cards that row is supplemented with money, cutting ferrule logs in the operation of Truth cards manager and selects the operation of Truth cards to be referred to above-mentioned associated description,This no longer describes in detail.
Cutting ferrule utilizes cutting ferrule end the second safe transmission double secret key to supplement with money after bag carries out the first process and sends to true card management device, wherein, and cutting ferrule endTwo safe transmission keys are cutting ferrule to be generated when setting up secure connection with Truth cards manager, Truth cards manager and at least one Truth cards phaseConnect, and storage has Truth cards manager end Truth cards information list, Truth cards manager end Truth cards information list include and truly blockThe Truth cards information of the Truth cards that sheet manager connects;Specifically, cutting ferrule receives supplements bag with money, and supplement with money bag confirm errorless after, will supplement with moneyBag sends after carrying out the first process to true card management device, improves and supplements bag transmission security with money, in order to Truth cards manager will supplement bag with money reallyTransmission to Truth cards processes.It addition, Truth cards manager end Truth cards information list includes true with what Truth cards manager was connectedThe Truth cards information of card, this Truth cards information may include that the information such as card number, card authentication information, and this card authentication information is that certification is trueWhether real card is the card image that regular channel (such as bank, public transport company etc.) is issued;This Truth cards can be the bank card that bank issuesOr function card (such as mass transit card, mess card, purchase card, member card, accumulating card etc.).Additionally, the life that cutting ferrule end the second safe transmission key isOne-tenth mode is referred to the associated description of the generation of above-mentioned cutting ferrule end the second safe transmission key, is not described in detail in this.Optionally, Truth cards managementDevice could be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, in order to user is according to true cardDifferent setting is made in the security requirement of sheet, such as, can arrange the Truth cards letter not allowing to obtain some Truth cards on Truth cards managerBreath, thus ensure the safety of these Truth cards.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out theSending to the Truth cards chosen after two process, wherein, Truth cards manager end safe transmission key is that cutting ferrule sets up peace with Truth cards managerGenerating during full connection, the Truth cards chosen is: cutting ferrule prompting cutting ferrule end Truth cards information list, and receives after Truth cards selects instruction trueFixed Truth cards, cutting ferrule end Truth cards information list is the Truth cards manager end Truth cards information row obtained from Truth cards managerTable;Specifically, after Truth cards manager receives the data that cutting ferrule sends, the data received are carried out the second process, by true and complete numberAccording to sending to Truth cards, it is ensured that the authenticity and integrity of the data that Truth cards processes, thus ensure the safety supplemented with money.Wherein, truly blockThe generating mode of sheet manager end safe transmission key is referred to the description of the generating mode of above-mentioned Truth cards manager end safe transmission key,This no longer describes in detail.The selection of the Truth cards chosen can refer to the associated description of the selection of above-mentioned Truth cards, is not described in detail in this.
The Truth cards chosen receives the data that Truth cards manager sends, and is traded the data received processing, it is thus achieved that supplement process bag with money;Specifically, after the Truth cards chosen receives the true and complete data that Truth cards manager sends, the data received are traded placeReason, in order to confirming to complete transaction, the process that the Truth cards chosen is traded processing is referred to existing smart card and is traded processFlow process, is not described in detail in this.
The Truth cards chosen will be supplemented process bag with money and be sent to true card management device;
Truth cards manager utilizes Truth cards manager end safe transmission double secret key to supplement with money after process bag carries out the first process and sends to cutting ferrule;
Cutting ferrule receives the data that Truth cards manager sends, after the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processSend to payment platform;Specifically, cutting ferrule receives the data after the Truth cards through choosing processes and sends it to payment platform, in order toPay platform to pay.
Account platform receives the payment successful information that payment platform sends, and performs to supplement operation with money, and wherein, paying successful information is payment platform receiving cardGenerate after overlapping the data after the second process sent and performing trading processing operation.Specifically, payment platform, after completing to pay, generates and pays intoMerit information, and this payment successful information is sent to account platform, in order to account platform is known payment and is completed, thus completes to supplement operation with money.Certainly,This payment successful information can also comprise checking information, in order to account platform is verified, only after being verified, just paying successful informationComplete to supplement with money, improve safety.
Based on aforesaid way, the data interaction framework of the present invention can complete to supplement account platform with money, extends answering of data interaction framework of the present inventionWith, it is user-friendly to.
2, supplement with money to Truth cards:
In a kind of application scenarios that the present embodiment provides, user is based on above-mentioned data interaction framework, it is possible to achieve supplement Truth cards with money, such asSupplement with money to mass transit card.
Realization to this application scene is briefly described below, but the invention is not limited in this:
Cutting ferrule, from the Truth cards being connected with Truth cards manager, determines the Truth cards chosen;
Supplement platform with money and obtained the card image of the Truth cards chosen, wherein, card image by simulation card, cutting ferrule and Truth cards managerIncluding: the card number of the Truth cards chosen, card authentication information;
Supplement with money after platform determines successful payment, generate and supplement bag with money and send true to choose by simulation card, cutting ferrule and Truth cards managerCard, wherein, supplements bag with money and points out through cutting ferrule and confirm;
The Truth cards chosen receives the data that Truth cards manager sends, and performs to supplement operation with money.
Based on above-mentioned brief description, a kind of specific implementation presented below, but the invention is not limited in this:
Cutting ferrule logs in Truth cards manager, and wherein, Truth cards manager is connected with at least one Truth cards, and storage has Truth cards pipeReason device end Truth cards information list, the Truth cards that Truth cards manager end Truth cards information list includes being connected with Truth cards managerTruth cards information;Specifically, above-mentioned cutting ferrule login step is referred to the associated description that above-mentioned cutting ferrule logs in, and is not described in detail in this.Optionally,Truth cards manager could be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, is formed trueCard management device end Truth cards information list, in order to user, such as can be truly according to the security requirement of Truth cards is made different settingThe Truth cards information not allowing to obtain some Truth cards is set on card management device, thus ensures the safety of these Truth cards.
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, how cutting ferrule obtains Truth cards information list and is referred to the acquisition of above-mentioned cutting ferrule trulyThe associated description of card image list, is not described in detail in this.
Cutting ferrule prompting cutting ferrule end Truth cards information list;
Cutting ferrule receives Truth cards and selects instruction, determines the Truth cards chosen;Specifically, cutting ferrule determines that the Truth cards chosen is card to be supplemented with money,Such as mass transit cards etc., now, the simulation card in notebook data interworking architecture can use as card to be supplemented with money (such as mass transit card).
Simulation card receives supplements the card image acquisition request that platform sends with money, and card image obtains the card of the Truth cards that request at least includes choosingNumber, card authentication information;Specifically, simulation card is attached with supplementing platform with money by user by contact or contactless mode, and this is supplemented with moneyPlatform can include that processing platform is supplemented on front end top-up machines and backstage with money, such as: mass transit card supplements platform etc. with money, and simulation card receives supplements what platform sent with moneyCard image obtains request, in order to obtain the Truth cards information of the Truth cards chosen.
Simulation card utilizes analog card bit end safe transmission double secret key card image to obtain after request carries out the first process and sends to cutting ferrule, wherein, and simulationCard-terminal safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receive card image obtain pleaseAfter asking, utilize the safe transmission double secret key card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, improve data transmission peaceQuan Xing.The generation process of analog card bit end safe transmission key is referred to the relevant of generation process of above-mentioned analog card bit end safe transmission key and retouchesState, be not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains card image and obtains request.Cutting ferrule end firstSafe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safe transmissionThe associated description of key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule sets up safety with Truth cards managerGenerate during connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send to the Truth cards chosen after carrying out the second process, in order toThe Truth cards chosen obtains card image and obtains request, thus card image is returned.The generation of Truth cards manager end safe transmission keyJourney is referred to the associated description of the generation process of above-mentioned Truth cards manager end safe transmission key, is not described in detail in this.
The card image of the Truth cards chosen is sent to true card management device by the Truth cards chosen;
Truth cards manager utilizes the card image of the Truth cards chosen that Truth cards manager end safe transmission double secret key receives to carry outSend to cutting ferrule after one process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toSupplement platform with money;Specifically, the card image got is sent to supplementing platform with money by simulation card, thus ensures that supplementing platform with money is known as which and truly blocksSheet is supplemented with money.
Supplement with money after platform determines successful payment, generate and supplement bag with money and will supplement bag transmission with money to simulating card;Specifically, supplementing platform with money can be by as followsMode determines successful payment: collecting cash, collect check, POS completes, the any-mode such as transfer accounts.Supplement with money after platform determines successful payment,Bag is supplemented in generation with money, in order to the Truth cards chosen carries out supplementing operation with money according to supplementing bag with money.Wherein supplement bag with money at least to include: recharge amount.
Simulation card receive supplement that platform sends with money supplement bag with money, utilize analog card bit end safe transmission double secret key to supplement with money after bag carries out the first process to send toCutting ferrule;
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, promptingData after second process;
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are errorless, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the Truth cards chosen;
The Truth cards chosen receives the data after the second process that Truth cards manager sends, and performs to supplement operation with money.Specifically, that chooses is trueCard gets after supplementing bag with money, supplements operation with money according to supplementing bag execution with money, thus completes to supplement with money.
Based on above-mentioned brief description, the present invention also provides for a kind of specific implementation supplemented with money by swiping the card, but the invention is not limited in this:
Cutting ferrule logs in Truth cards manager, and wherein, Truth cards manager is connected with at least one Truth cards, and storage has Truth cards pipeReason device end Truth cards information list, the Truth cards that Truth cards manager end Truth cards information list includes being connected with Truth cards managerTruth cards information;Specifically, above-mentioned cutting ferrule login step is referred to the associated description that above-mentioned cutting ferrule logs in, and is not described in detail in this.Optionally,Truth cards manager could be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, is formed trueCard management device end Truth cards information list, in order to user, such as can be truly according to the security requirement of Truth cards is made different settingThe Truth cards information not allowing to obtain some Truth cards is set on card management device, thus ensures the safety of these Truth cards.
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, how cutting ferrule obtains Truth cards information list and is referred to the acquisition of above-mentioned cutting ferrule trulyThe associated description of card image list, is not described in detail in this.
Cutting ferrule prompting cutting ferrule end Truth cards information list;
Cutting ferrule receives the first Truth cards and selects instruction, determines the first Truth cards chosen;Specifically, cutting ferrule determines the first Truth cards chosenFor card of withholing, such as bank card etc., now, the simulation card in notebook data interworking architecture can use as card of withholing (such as bank card).
Simulation card receives the first card image acquisition request that payment platform sends, and the first card image obtains request and at least includes that choose first is trueThe card number of real card and card authentication information;Specifically, simulation card is carried out with payment platform by user by contact or contactless modeConnecting, this payment platform comprises terminal of withholing (such as POS etc.) and payment processes platform (such as bank backstage), will simulate card and be somebody's turn to doTerminal of withholing is connected, in order to withhold, and simulation card receives the first card image that payment platform sends and obtains request, in order to obtain the chosenThe Truth cards information of one Truth cards.
Simulation card utilizes analog card bit end safe transmission double secret key the first card image to obtain after request carries out the first process and sends to cutting ferrule, wherein,Analog card bit end safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receives the first card letterAfter breath obtains request, utilize safe transmission double secret key the first card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, carryHigh data transmission security.The generation process of analog card bit end safe transmission key is referred to the generation of above-mentioned analog card bit end safe transmission keyThe associated description of journey, is not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains the first card image and obtains request.Cutting ferrule endFirst safe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safetyThe associated description of transmission key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the first Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule is set up with Truth cards managerGenerate during secure connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send after carrying out the second process to first chosen truly blocksSheet, in order to the first Truth cards chosen obtains the first card image and obtains request, thus card image is returned.Truth cards manager end safetyThe generation process of transmission key is referred to the associated description of the generation process of above-mentioned Truth cards manager end safe transmission key, the most detailed at thisState.
The card image of the first Truth cards chosen is sent to true card management device by the first Truth cards chosen;
Truth cards manager utilizes the card image of the first Truth cards chosen that Truth cards manager end safe transmission double secret key receives to enterRow first sends to cutting ferrule after processing;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toPayment platform;Specifically, the card image of the first Truth cards got is sent to payment platform by simulation card, thus platform of guaranteeing payment obtainsKnow which Truth cards of use is withholdd.
Simulation card receives the request of withholing that payment platform sends, and utilizes the analog card bit end safe transmission double secret key request of withholing to send out after carrying out the first processDeliver to cutting ferrule;Specifically, the request of withholing can at least include deducted amount.
Cutting ferrule receives the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, and by theData after two process are pointed out;Specifically, the request of withholing can be shown or speech play by cutting ferrule, in order to user is in the request of withholingInformation confirm.
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are correct, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;Specifically, if user confirms errorless, cutting ferrule is carried out confirm operation (such asPress confirmation button, select the modes such as the confirmation option in menu) generate for confirming the confirmation instruction that the request of withholing is errorless, cutting ferrule receives this confirmationInstruction, in order to cutting ferrule continues executing with subsequent operation;Certainly, if user confirms that the request of withholing is problematic, then can carry out cancelling operation on cutting ferrule,To cancel this transaction.What cutting ferrule received be used for the correct confirmation of the data after instruction second processes to instruct can be to be provided separately within card to put reallyRecognize what physical button generated, or can be that confirming on the touch screen of cutting ferrule selects in virtual key generation, or the menu shown on cutting ferrule screenSelect and confirm what function generated, or can be that the voice that the voice acquisition device (such as Mike) of cutting ferrule receives is when confirming indicate and be verified rearGenerate, or can be that the fingerprint acquisition device of cutting ferrule receives generation after fingerprint identification indicates and is verified, or can be the rainbow of cutting ferruleFilm harvester receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes, in the present inventionIt is not restricted.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the first Truth cards chosen;
Choose first Truth cards receive Truth cards manager send data, and the data received are traded process after by trading processingThe data of rear acquisition send to true card management device;Specifically, the first Truth cards chosen receive that Truth cards manager sends true andAfter complete data, it is traded the data received processing, in order to confirming to complete transaction, the first Truth cards chosen is traded placeThe process of reason is referred to the flow process that existing smart card is traded processing, and is not described in detail in this.
Truth cards manager receives the data that the first Truth cards chosen sends, and utilizes Truth cards manager end safe transmission double secret key to receiveTo data carry out the first process after send to cutting ferrule;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card overlaps the data sent, and the data utilizing analog card bit end safe transmission double secret key to receive carry out transmission after the second processOperation of withholing is carried out to payment platform;Specifically, the number after payment platform receives the first Truth cards trading processing chosen that simulation card sendsAccording to, and the operation that performs to withhold after being verified, certainly, after payment platform has performed to withhold operation, it is also possible to generation payment successful information, in order toInform that user pays successfully.
Cutting ferrule prompting cutting ferrule end Truth cards information list;Specifically, supplementing with money after platform determines successful payment, user may select card (example to be supplemented with moneySuch as bank card), in order to supplement with money for card to be supplemented with money.
Cutting ferrule receives the second Truth cards and selects instruction, determines the second Truth cards chosen;Specifically, cutting ferrule determines the second Truth cards chosenFor card to be supplemented with money, such as mass transit card etc., now, the simulation card in notebook data interworking architecture can be as card to be supplemented with money (such as mass transit card)Use.
Simulation card receives supplements the second card image acquisition request that platform sends with money, and the second card image obtains request and at least includes that choose second is trueThe real card number of card, card authentication information;Specifically, simulation card is carried out even with supplementing platform with money by user by contact or contactless modeConnecing, this supplements platform with money can include that processing platform is supplemented on front end top-up machines and backstage with money, such as: mass transit card supplements platform etc. with money, and simulation card receives supplements with moneyThe second card image that platform sends obtains request, in order to obtain the Truth cards information of the second Truth cards chosen.
Simulation card utilizes analog card bit end safe transmission double secret key the second card image to obtain after request carries out the first process and sends to cutting ferrule, wherein,Analog card bit end safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receives the second card letterAfter breath obtains request, utilize the safe transmission double secret key card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, improve numberAccording to transmission security.The generation process of analog card bit end safe transmission key is referred to the generation process of above-mentioned analog card bit end safe transmission keyAssociated description, is not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains card image and obtains request.Cutting ferrule end firstSafe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safe transmissionThe associated description of key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the second Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule is set up with Truth cards managerGenerate during secure connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send to the Truth cards chosen after carrying out the second process,So that the second Truth cards chosen obtains card image and obtains request, thus card image is returned.Truth cards manager end safe transmission keyGeneration process be referred to the associated description of generation process of above-mentioned Truth cards manager end safe transmission key, be not described in detail in this.
The card image of the Truth cards chosen is sent to true card management device by the second Truth cards chosen;
Truth cards manager utilizes the card image of the second Truth cards chosen that Truth cards manager end safe transmission double secret key receives to enterRow first sends to cutting ferrule after processing;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toSupplement platform with money;Specifically, the card image of the second Truth cards got is sent to supplementing platform with money by simulation card, thus ensures that supplementing platform with money obtainsKnow and for which Truth cards supplement with money.
Simulation card receive supplement with money platform generate supplement bag with money;Specifically, supplement platform with money determine successful payment and get the second Truth cards chosenCard image after, generate supplement bag with money, in order to the second Truth cards chosen can carry out supplementing operation with money according to supplementing bag with money.Wherein supplement bag with money at least to wrapInclude: recharge amount.
Simulation card utilizes analog card bit end safe transmission double secret key to supplement with money after bag carries out the first process and sends to cutting ferrule;
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, promptingData after second process;
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are errorless, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the second Truth cards chosen;
The second Truth cards chosen receives the data after the second process that Truth cards manager sends, and performs to supplement operation with money.Specifically, chooseSecond Truth cards gets after supplementing bag with money, supplements operation with money according to supplementing bag execution with money, thus completes to supplement with money.
Based on aforesaid way, the data interaction framework of the present invention can complete to supplement Truth cards with money, extends answering of data interaction framework of the present inventionWith, it is user-friendly to.
3, the second Truth cards is that the first Truth cards is supplemented with money:
In a kind of application scenarios that the present embodiment provides, user is based on above-mentioned data interaction framework, it is possible to achieve Truth cards is filled by Truth cardsValue, such as being swiped the card by bank card is supplemented with money to mass transit card or swiped the card by bank card supplements with money to electricity card.In this application scene, the second Truth cardsDifferent from the first Truth cards type, the second Truth cards is the Truth cards that can withhold, and the first Truth cards is Truth cards to be supplemented with money.
Realization to this application scene is briefly described below, but the invention is not limited in this:
Cutting ferrule, from the Truth cards being connected with Truth cards manager, determines the first Truth cards chosen;
Supplement platform with money and obtained the card image of the first Truth cards chosen, wherein, card by simulation card, cutting ferrule and Truth cards managerInformation includes: the card number of the first Truth cards chosen, card authentication information;
Cutting ferrule, from the Truth cards being connected with Truth cards manager, determines the second Truth cards chosen;
Payment platform carries out, with the second Truth cards chosen, process of withholing by cutting ferrule, Truth cards manager;
Cutting ferrule, from the Truth cards being connected with Truth cards manager, determines the first Truth cards chosen;
Supplement platform generation with money supplement bag with money and sent to the Truth cards chosen by simulation card, cutting ferrule and Truth cards manager, wherein, supplement with moneyBag is pointed out through cutting ferrule and confirms;
The Truth cards chosen receives the data that Truth cards manager sends, and performs to supplement operation with money.
Based on above-mentioned brief description, a kind of specific implementation presented below, but the invention is not limited in this:
Cutting ferrule logs in Truth cards manager, and wherein, Truth cards manager is connected with at least one Truth cards, and storage has Truth cards pipeReason device end Truth cards information list, the Truth cards that Truth cards manager end Truth cards information list includes being connected with Truth cards managerTruth cards information;Specifically, above-mentioned cutting ferrule login step is referred to the associated description that above-mentioned cutting ferrule logs in, and is not described in detail in this.Optionally,Truth cards manager could be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, is formed trueCard management device end Truth cards information list, in order to user, such as can be truly according to the security requirement of Truth cards is made different settingThe Truth cards information not allowing to obtain some Truth cards is set on card management device, thus ensures the safety of these Truth cards.
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, how cutting ferrule obtains Truth cards information list and is referred to the acquisition of above-mentioned cutting ferrule trulyThe associated description of card image list, is not described in detail in this.
Cutting ferrule prompting cutting ferrule end Truth cards information list;
Cutting ferrule receives the first Truth cards and selects instruction, determines the first Truth cards chosen;Specifically, cutting ferrule determines the first Truth cards chosenFor card to be supplemented with money, such as mass transit card etc., now, the simulation card in notebook data interworking architecture can be as card to be supplemented with money (such as mass transit card)Use.
Simulation card receives supplements the first card image acquisition request that platform sends with money, and the first card image obtains request and at least includes that choose first is trueThe card number of real card and card authentication information;Specifically, simulation card is carried out with supplementing platform with money by user by contact or contactless modeConnecting, this supplements platform with money can include that processing platform is supplemented on front end top-up machines and backstage with money, such as: mass transit card supplements platform with money or platform etc. supplemented with money by electricity card,Simulation card is connected with this front end top-up machines, simulates card and receive the first card image acquisition request supplementing platform transmission with money, in order to acquisition is chosenThe Truth cards information of the first Truth cards.
Simulation card utilizes analog card bit end safe transmission double secret key the first card image to obtain after request carries out the first process and sends to cutting ferrule, wherein,Analog card bit end safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receives the first card letterAfter breath obtains request, utilize safe transmission double secret key the first card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, carryHigh data transmission security.The generation process of analog card bit end safe transmission key is referred to the generation of above-mentioned analog card bit end safe transmission keyThe associated description of journey, is not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains the first card image and obtains request.Cutting ferrule endFirst safe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safetyThe associated description of transmission key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the first Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule is set up with Truth cards managerGenerate during secure connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send after carrying out the second process to first chosen truly blocksSheet, in order to the first Truth cards chosen obtains the first card image and obtains request, thus card image is returned.Truth cards manager end safetyThe generation process of transmission key is referred to the associated description of the generation process of above-mentioned Truth cards manager end safe transmission key, the most detailed at thisState.
The card image of the first Truth cards chosen is sent to true card management device by the first Truth cards chosen;
Truth cards manager utilizes the card image of the first Truth cards chosen that Truth cards manager end safe transmission double secret key receives to enterRow first sends to cutting ferrule after processing;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toSupplement platform with money;Specifically, the card image of the first Truth cards got is sent to supplementing platform with money by simulation card, thus ensures that supplementing platform with money obtainsKnow and for which Truth cards supplement with money.
Cutting ferrule receives the mark of supplementing with money supplementing platform transmission with money, display cutting ferrule end Truth cards information list;Specifically, cutting ferrule receives and supplements platform transmission with moneySupplement mark with money, supplement with money being shown to be any card, prompting user is chosen as the second Truth cards that the first Truth cards (treating rechargeable card) is supplemented with money simultaneously(card of withholing).This supplements mark with money can comprise that the first Truth cards card number to be supplemented with money, order number, recharge amount etc. are a kind of or a combination thereof.
Cutting ferrule receives the second Truth cards and selects instruction, determines the second Truth cards chosen;Specifically, cutting ferrule determines the second Truth cards chosenFor card of withholing, such as bank card etc..
Simulation card receives the second card image acquisition request that payment platform sends, and the second card image obtains request and at least includes that choose second is trueThe card number of real card and card authentication information;Specifically, simulation card is carried out with payment platform by user by contact or contactless modeConnecting, this payment platform comprises terminal of withholing (such as POS etc.) and payment processes platform (such as bank backstage), will simulate card and be somebody's turn to doTerminal of withholing is connected, in order to withhold, and simulation card receives the second card image that payment platform sends and obtains request, in order to obtain the chosenThe Truth cards information of two Truth cards.
Simulation card utilizes analog card bit end safe transmission double secret key the second card image to obtain after request carries out the first process and sends to cutting ferrule, wherein,Analog card bit end safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receives the second card letterAfter breath obtains request, utilize safe transmission double secret key the second card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, carryHigh data transmission security.The generation process of analog card bit end safe transmission key is referred to the generation of above-mentioned analog card bit end safe transmission keyThe associated description of journey, is not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains the second card image and obtains request.Cutting ferrule endFirst safe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safetyThe associated description of transmission key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the second Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule is set up with Truth cards managerGenerate during secure connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send after carrying out the second process to second chosen truly blocksSheet, in order to the second Truth cards chosen obtains the second card image and obtains request, thus card image is returned.Truth cards manager end safetyThe generation process of transmission key is referred to the associated description of the generation process of above-mentioned Truth cards manager end safe transmission key, the most detailed at thisState.
The card image of the second Truth cards chosen is sent to true card management device by the second Truth cards chosen;
Truth cards manager utilizes the card image of the second Truth cards chosen that Truth cards manager end safe transmission double secret key receives to enterRow first sends to cutting ferrule after processing;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toPayment platform;Specifically, the card image of the second Truth cards got is sent to payment platform by simulation card, thus platform of guaranteeing payment obtainsKnow which Truth cards of use is withholdd.
Simulation card receives the request of withholing that payment platform sends, and utilizes the analog card bit end safe transmission double secret key request of withholing to send out after carrying out the first processDeliver to cutting ferrule;Specifically, the request of withholing can at least include deducted amount and the first Truth cards card number.
Cutting ferrule receives the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, and by theData after two process are pointed out;Specifically, the request of withholing can be shown or speech play by cutting ferrule, in order to user is in the request of withholingInformation confirm.
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are correct, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;Specifically, if user confirms errorless, cutting ferrule is carried out confirm operation (such asPress confirmation button, select the modes such as the confirmation option in menu) generate for confirming the confirmation instruction that the request of withholing is errorless, cutting ferrule receives this confirmationInstruction, in order to cutting ferrule continues executing with subsequent operation;Certainly, if user confirms that the request of withholing is problematic, then can carry out cancelling operation on cutting ferrule,To cancel this transaction.What cutting ferrule received be used for the correct confirmation of the data after instruction second processes to instruct can be to be provided separately within card to put reallyRecognize what physical button generated, or can be that confirming on the touch screen of cutting ferrule selects in virtual key generation, or the menu shown on cutting ferrule screenSelect and confirm what function generated, or can be that the voice that the voice acquisition device (such as Mike) of cutting ferrule receives is when confirming indicate and be verified rearGenerate, or can be that the fingerprint acquisition device of cutting ferrule receives generation after fingerprint identification indicates and is verified, or can be the rainbow of cutting ferruleFilm harvester receives generation after iris confirms instruction and is verified, it is, of course, also possible to generate for other any modes, in the present inventionIt is not restricted.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the second Truth cards chosen;
Choose second Truth cards receive Truth cards manager send data, and the data received are traded process after by trading processingThe data of rear acquisition send to true card management device;Specifically, the second Truth cards chosen receive that Truth cards manager sends true andAfter complete data, it is traded the data received processing, in order to confirming to complete transaction, the second Truth cards chosen is traded placeThe process of reason is referred to the flow process that existing smart card is traded processing, and is not described in detail in this.
Truth cards manager receives the data that the second Truth cards chosen sends, and utilizes Truth cards manager end safe transmission double secret key to receiveTo data carry out the first process after send to cutting ferrule;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second processAfter, the data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card overlaps the data sent, and the data utilizing analog card bit end safe transmission double secret key to receive carry out transmission after the second processTo payment platform;
Simulation card utilizes analog card bit end safe transmission double secret key to pay after successful information carries out the first process and sends to cutting ferrule, wherein, pays successfullyInformation is to generate after payment platform successful execution pays;Specifically, payment platform number after receiving the second Truth cards trading processing chosenAccording to, after being verified, performing to withhold operation, after the operation that performed to withhold, generate payment successful information, this payment successful information can include selectingIn the first Truth cards card number or other be expressed as which information of supplementing with money of card, as long as supplementing with money, platform is follow-up to be known for withholing into which card is supplemented with moneyMerit performs.
Cutting ferrule receives the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, cue cardSet end Truth cards information list;
Cutting ferrule receives the first Truth cards and selects instruction, determines the first Truth cards chosen;Specifically, user chooses the first Truth cards again,To complete the first Truth cards is supplemented with money operation.
Simulation card receive supplement with money platform send supplement bag with money, wherein, supplement with money bag by supplement with money platform receive payment successful information after generate;Specifically,Payment successful information can also directly be sent to supplementing platform with money by payment platform, or payment successful information is sent to supplementing platform with money by cutting ferrule, in order to fillsValue platform is known and is paid successfully, and generates and supplement bag with money, in order to supplements this with money bag and sends to the first Truth cards chosen and complete to supplement with money.
Simulation card utilizes analog card bit end safe transmission double secret key to supplement with money after bag carries out the first process and sends to cutting ferrule;
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, promptingData after second process;
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are errorless, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the first Truth cards chosen;
First Truth cards receives the data that Truth cards manager sends, and performs to supplement operation with money.Specifically, the first Truth cards chosen getsAfter supplementing bag with money, supplement operation with money according to supplementing bag execution with money, thus complete to supplement with money.
Based on aforesaid way, the data interaction framework of the present invention can complete to utilize the second Truth cards to supplement the first Truth cards with money, extends thisThe application of invention data interaction framework, is user-friendly to.
4, account is supplemented with money to Truth cards:
In a kind of application scenarios that the present embodiment provides, user is based on above-mentioned data interaction framework, it is possible to achieve Truth cards is supplemented with money by account,Such as supplemented with money to mass transit card by Alipay or Net silver.
Realization to this application scene is briefly described below, but the invention is not limited in this:
Cutting ferrule, from the Truth cards being connected with Truth cards manager, determines the Truth cards chosen;
Supplement platform with money and obtained the card image of the Truth cards chosen, wherein, card image by simulation card, cutting ferrule and Truth cards managerIncluding: the card number of the Truth cards chosen, card authentication information;
Cutting ferrule logs in payment platform, and payment platform obtains after supplementing mark with money and carries out process of withholing;
After supplementing the payment successful information that platform receives payment platform generation with money, generate and supplement bag with money and managed by simulation card, cutting ferrule and Truth cardsDevice sends to the Truth cards chosen, and wherein, supplements bag with money and points out through cutting ferrule and confirm;
The Truth cards chosen receives the data that Truth cards manager sends, and performs to supplement operation with money.
Based on above-mentioned brief description, a kind of specific implementation presented below, but the invention is not limited in this:
Cutting ferrule logs in Truth cards manager, and wherein, Truth cards manager is connected with at least one Truth cards, and storage has Truth cards pipeReason device end Truth cards information list, the Truth cards that Truth cards manager end Truth cards information list includes being connected with Truth cards managerTruth cards information;Specifically, above-mentioned cutting ferrule login step is referred to the associated description that above-mentioned cutting ferrule logs in, and is not described in detail in this.Optionally,Truth cards manager could be arranged to preserve the Truth cards information of all or part of Truth cards in connected Truth cards, is formed trueCard management device end Truth cards information list, in order to user, such as can be truly according to the security requirement of Truth cards is made different settingThe Truth cards information not allowing to obtain some Truth cards is set on card management device, thus ensures the safety of these Truth cards.
Cutting ferrule obtains cutting ferrule end Truth cards information list, and wherein, cutting ferrule end Truth cards information list is the true of acquisition from Truth cards managerReal card management device end Truth cards information list;Specifically, how cutting ferrule obtains Truth cards information list and is referred to the acquisition of above-mentioned cutting ferrule trulyThe associated description of card image list, is not described in detail in this.
Cutting ferrule prompting cutting ferrule end Truth cards information list;
Cutting ferrule receives Truth cards and selects instruction, determines the Truth cards chosen;Specifically, cutting ferrule determines that the Truth cards chosen is card to be supplemented with money,Such as mass transit cards etc., now, the simulation card in notebook data interworking architecture can use as card to be supplemented with money (such as mass transit card).
Simulation card receives supplements the card image acquisition request that platform sends with money, and card image obtains the card of the Truth cards that request at least includes choosingNumber, card authentication information;Specifically, simulation card is attached with supplementing platform with money by user by contact or contactless mode, and this is supplemented with moneyPlatform can include that processing platform is supplemented on front end top-up machines and backstage with money, such as: mass transit card supplements platform etc. with money, and simulation card receives supplements what platform sent with moneyCard image obtains request, in order to obtain the Truth cards information of the Truth cards chosen.
Simulation card utilizes analog card bit end safe transmission double secret key card image to obtain after request carries out the first process and sends to cutting ferrule, wherein, and simulationCard-terminal safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card;Specifically, simulation card receive card image obtain pleaseAfter asking, utilize the safe transmission double secret key card image between cutting ferrule to obtain after request carries out the first process and send to cutting ferrule, improve data transmission peaceQuan Xing.The generation process of analog card bit end safe transmission key is referred to the relevant of generation process of above-mentioned analog card bit end safe transmission key and retouchesState, be not described in detail in this.
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, then profitData after processing with cutting ferrule end the second safe transmission double secret key second send to true card management device after carrying out the first process, wherein, and cutting ferrule end theOne safe transmission key is that cutting ferrule generates with simulating when secure connection set up by card, and cutting ferrule end the second safe transmission key is cutting ferrule and Truth cards pipeReason device generates when setting up secure connection;Specifically, cutting ferrule sends, to simulation card, the data come and carries out the second process, and sends out after carrying out the first processDeliver to Truth cards manager, it is provided that data transmission security, and so that Truth cards manager obtains card image and obtains request.Cutting ferrule end firstSafe transmission key and cutting ferrule end the second safe transmission key are referred to above-mentioned cutting ferrule end the first safe transmission key and cutting ferrule end the second safe transmissionThe associated description of key generation process, is not described in detail in this.
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSending after process to the Truth cards chosen, wherein, Truth cards manager end safe transmission key is that cutting ferrule sets up safety with Truth cards managerGenerate during connection;Specifically, the data that cutting ferrule is sent by Truth cards manager send to the Truth cards chosen after carrying out the second process, in order toThe Truth cards chosen obtains card image and obtains request, thus card image is returned.The generation of Truth cards manager end safe transmission keyJourney is referred to the associated description of the generation process of above-mentioned Truth cards manager end safe transmission key, is not described in detail in this.
The card image of the Truth cards chosen is sent to true card management device by the Truth cards chosen;
Truth cards manager utilizes the card image of the Truth cards chosen that Truth cards manager end safe transmission double secret key receives to carry outSend to cutting ferrule after one process;
Cutting ferrule receives the data that Truth cards manager sends, and the data utilizing cutting ferrule end the second safe transmission double secret key to receive carry out the second process,Data after the second process of recycling cutting ferrule end the first safe transmission double secret key send to simulating card after carrying out the first process;
Simulation card receiving card set send data, the data utilizing analog card bit end safe transmission double secret key to receive send after carrying out the second process toSupplement platform with money;Specifically, the card image got is sent to supplementing platform with money by simulation card, thus ensures that supplementing platform with money is known as which and truly blocksSheet is supplemented with money.
Cutting ferrule logs in payment platform;Specifically, cutting ferrule can log in payment platform, and this payment platform can be Alipay, or Net silver, in order to completeBecome withhold operation, such as user to log in Alipay directly to withhold from Alipay, or user logs in Net silver and directly withholds from Net silver, or user logs inAlipay is also withholdd by the Net silver bound with Alipay.
Cutting ferrule receives the payment successful information that payment platform sends, and wherein, pays successful information and is generated after performing delivery operation by payment platform;ToolBody ground, payment platform can generate payment successful information after completing to pay, and this payment successful information is sent to cutting ferrule, in order to user knows paymentSuccess.Payment platform, before performing delivery operation, also obtains and supplements mark with money, and this is supplemented mark with money and can obtain in the following way: mode one, mouldIntend card receive supplement that platform sends with money supplement mark with money, utilize analog card bit end safe transmission double secret key to supplement mark with money and carry out sending to card after the first processSet, cutting ferrule receives the data that simulation card sends, and the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process and supplemented with moneyMark, and sent to payment platform by cutting ferrule.Wherein, supplement with money to be designated and supplement what platform generated after receiving the data after simulation card second processes with money,Specifically, after supplementing the card image that platform gets the first Truth cards that simulation card sends with money, can generate and supplement mark with money, so which to be designated asTruth cards carries out supplementing with money and recharge amount, and this supplements mark with money can be that this supplements the order number etc. of generation with money.Mode two, supplement with money platform receiveGenerate after data after the second process of simulation card and supplement mark with money, directly supplement this with money mark and send to payment platform.It addition, payment platform is according to fillingValue mark pays, in order to knows and for which Truth cards carries out paying and payment.
Simulation card receive supplement with money platform send supplement bag with money, wherein, supplement with money wrap by supplement with money platform receive payment platform generate payment successful informationRear generation;Specifically, payment successful information is also sent to supplementing platform with money by payment platform, or payment platform will pay successful information and send to cutting ferrule,And sent to supplementing platform with money by cutting ferrule, in order to supplement platform with money and know and pay successfully, and generate and supplement bag with money, in order to supplement this with money bag and send true to chooseReal card completes to supplement with money.
Simulation card utilizes analog card bit end safe transmission double secret key to supplement with money after bag carries out the first process and sends to cutting ferrule;
Cutting ferrule receives the data that simulation card sends, after the data utilizing cutting ferrule end the first safe transmission double secret key to receive carry out the second process, promptingData after second process;
Cutting ferrule receives the confirmation instruction that the data after instruction the second process are errorless, after utilizing cutting ferrule end the second safe transmission double secret key second to processData send after carrying out the first process to true card management device;
Truth cards manager receives the data that cutting ferrule sends, and the data utilizing Truth cards manager end safe transmission double secret key to receive carry out secondSend after process to the Truth cards chosen;
Truth cards receives the data that Truth cards manager sends, and performs to supplement operation with money.Specifically, the Truth cards chosen gets after supplementing bag with money,Supplement operation with money according to supplementing bag execution with money, thus complete to supplement with money.
Based on aforesaid way, the data interaction framework of the present invention can complete to utilize account to supplement Truth cards with money, extend data interaction of the present inventionThe application of framework, is user-friendly to.
In all embodiments of the invention, all of normal data interaction between cutting ferrule and simulation card, simulation card is respectively positioned on having of cutting ferruleIn effect communication range, if cutting ferrule detects the simulation card efficient communication scope beyond cutting ferrule, then cutting ferrule can be pointed out, or cutting ferrule willInformation sends and points out to user terminal (such as smart mobile phone, panel computer etc.) place, in order to prompting user simulates the position of card to be occurredAbnormal, thus improve simulation card safety in utilization.
In flow chart or at this, any process described otherwise above or method description are construed as, and represent and include that one or more is for realityThe module of code, fragment or the part of the executable instruction of the step of existing specific logical function or process, and the model of the preferred embodiment of the present inventionEnclose and include other realization, wherein can not by order that is shown or that discuss, including according to involved function by basic mode simultaneously or by phaseAnti-order, performs function, and this should be understood by embodiments of the invention person of ordinary skill in the field.
Should be appreciated that each several part of the present invention can realize by hardware, software, firmware or combinations thereof.In the above-described embodiment, multipleStep or method can realize with software or the firmware that storage in memory and is performed by suitable instruction execution system.Such as, if using hardwareRealize, with the most the same, can realize by any one in following technology well known in the art or their combination: there is useIn the discrete logic of the logic gates that data signal is realized logic function, there is the special IC of suitable combination logic gate circuit,Programmable gate array (PGA), field programmable gate array (FPGA) etc..
Those skilled in the art are appreciated that realizing all or part of step that above-described embodiment method carries can be by programThe hardware that instruction is relevant completes, program can be stored in a kind of computer-readable recording medium, this program upon execution, including embodiment of the methodOne or a combination set of step.
Additionally, each functional unit in each embodiment of the present invention can be integrated in a processing module, it is also possible to be the independent physics of unitExist, it is also possible to two or more unit are integrated in a module.Above-mentioned integrated module both can realize to use the form of hardware, it is possible toTo use the form of software function module to realize.If integrated module realizes using the form of software function module and as independent production marketing or makeUsed time, it is also possible to be stored in a computer read/write memory medium.
Storage medium mentioned above can be read only memory, disk or CD etc..
In the description of this specification, reference term " embodiment ", " some embodiments ", " example ", " concrete example " or " some examples "Deng description means to combine this embodiment or example describes specific features, structure, material or feature be contained at least one embodiment of the present inventionOr in example.In this manual, the schematic representation to above-mentioned term is not necessarily referring to identical embodiment or example.And, the tool of descriptionBody characteristics, structure, material or feature can combine in any one or more embodiments or example in an appropriate manner.
Although above it has been shown and described that embodiments of the invention, it is to be understood that above-described embodiment is exemplary, it is impossible to it is right to be interpreted asThe restriction of the present invention, those of ordinary skill in the art in the case of without departing from the principle of the present invention and objective within the scope of the invention can onState embodiment to be changed, revise, replace and modification.The scope of the present invention is limited by claims and equivalent thereof.