NFC card encryption transaction process based on certificate exchange
Through the NFC card encryption transaction process based on certificate exchange, the security and applicability of existing NFC card encryption transactions are solved using temporary key pairs and dynamic AES session keys, and the security and applicability of existing NFC card encryption transactions are achieved, which is more secure and communication efficiency, and is suitable for many scenarios in intelligent transportation systems.
Patent Information
- Application Number
- CN202510550758.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-22
AI Technical Summary
The existing NFC card encryption transaction process has problems such as insufficient security, weak tamper protection and limited applicability, especially in key leakage, man-in-the-middle attack, replay attack, data tampering and system compatibility.
The NFC card encryption transaction process based on certificate exchange is adopted, and the security of data transmission and communication efficiency are ensured through the generation of temporary key pairs, the certificate-based key exchange mechanism and the dynamic generation of AES session keys.
It improves the security and communication efficiency of NFC card encryption transactions, enhances attack resistance, simplifies key management, supports multiple intelligent traffic scenarios, and reduces implementation costs.
Smart Images

Figure CN120358488A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of near-field communication, and in particular, to an NFC card encryption transaction process based on certificate exchange. Background Art
[0002] With the continuous development of intelligent transportation systems, NFC technology has been widely used in scenarios such as vehicle unlocking and payment. However, the existing NFC transaction processes have deficiencies in terms of security and privacy protection, mainly manifested in the following aspects:
[0003] Insufficient security: Existing technologies usually rely on fixed keys for data encryption and authentication, presenting the following risks:
[0004] Risk of key leakage: Once a fixed key is leaked, an attacker can easily forge or tamper with data, resulting in illegal intrusion into the vehicle system or payment system.
[0005] Man-in-the-Middle Attack: An attacker can intercept and tamper with communication data by stealing or forging a fixed key, thereby deceiving the system or users.
[0006] Replay Attack: An attacker can capture and resend legitimate data packets, pretending to be a legitimate user for operations.
[0007] Weak anti-tampering ability: In the data transmission process of existing technologies, there is a lack of an effective data integrity verification mechanism, resulting in:
[0008] Data tampering: An attacker can intercept and modify data during data transmission, causing the receiving party to obtain false information.
[0009] Forged data: An attacker can forge legitimate data packets to deceive the system or users.
[0010] Limited applicability: The existing NFC transaction processes are usually designed for specific scenarios and lack generality and flexibility:
[0011] Strong scenario dependence: The existing NFC transaction processes are usually optimized for specific application scenarios, such as vehicle unlocking or payment authentication, and it is difficult to adapt to other scenarios or systems.
[0012] Poor system compatibility: NFC devices and card readers from different manufacturers or systems may use different key management methods and communication protocols, resulting in ineffective compatibility between systems.
[0013] In addition, in the existing NFC card encryption transaction process, data encryption and authentication usually rely on fixed keys or pre-shared keys (PSKs), which have problems such as low security, complex key management, and low communication efficiency. Summary of the Invention
[0014] The technical problem to be solved by the present invention is how to improve the security, flexibility, and communication efficiency of NFC card encryption transactions to overcome the deficiencies in the prior art.
[0015] To solve the above technical problems, the present invention proposes an NFC card encryption transaction process based on certificate exchange, which ensures the security of data transmission through certificate signature verification, generation and verification of ephemeral key pairs, and AES session keys.
[0016] The technical solution of the present invention mainly includes the following aspects:
[0017] Use of ephemeral key pairs: Generate a pair of ephemeral keys for each transaction to avoid the use of fixed keys and enhance security.
[0018] Certificate-based key exchange mechanism: Verify identities through public key certificates to ensure the legitimacy of both communication parties.
[0019] Dynamic generation of AES session keys: Dynamically generate AES session keys through a key sharing protocol to improve communication efficiency.
[0020] The specific solution is as follows:
[0021] An NFC card encryption transaction process based on certificate exchange includes the following steps:
[0022] The central Bluetooth module CBM generates a pair of ephemeral key pairs, including an ephemeral private key eSK.OCE.ECKA and an ephemeral public key ePK.OCE.ECKA, and sends the ephemeral public key ePK.OCE.ECKA to the NFC card through the NFC communication module;
[0023] The NFC card generates a pair of ephemeral key pairs, including an ephemeral private key eSK.SD.ECKA and an ephemeral public key ePK.SD.ECKA;
[0024] The NFC card calculates the shared keys ShSes and ShSee through the elliptic curve Diffie-Hellman key exchange algorithm, where ShSes is calculated from the ephemeral public key ePK.OCE.ECKA of the CBM and the static private key SK.SD.ECKA of the NFC card, and ShSee is calculated from the ephemeral public key ePK.OCE.ECKA of the CBM and the ephemeral private key eSK.SD.ECKA of the NFC card;
[0025] The NFC card derives the AES session key from ShSes and ShSee through a key derivation function;
[0026] The NFC card generates a receipt int.SD_receipt and sends the temporary public key ePK.SD.ECKA and the receipt int.SD_receipt to the CBM;
[0027] The CBM calculates the shared keys ShSss and ShSee through the elliptic curve Diffie-Hellman key exchange algorithm, where ShSss is calculated from the static public key PK.SD.ECKA of the NFC card and the static private key SK.OCE.ECKA of the CBM, and ShSee is calculated from the temporary public key ePK.SD.ECKA of the NFC card and the temporary private key eSK.OCE.ECKA of the CBM;
[0028] The CBM derives the AES session key from ShSss and ShSee through a key derivation function;
[0029] The CBM verifies the legitimacy of the receipt int.SD_receipt sent by the NFC card;
[0030] If the receipt verification is successful, the CBM and the NFC card establish a secure communication channel through the AES session key.
[0031] Furthermore, the CBM and the NFC card establish a secure communication channel using the SCP02 secure messaging protocol.
[0032] Furthermore, after establishing the secure communication channel, the following steps are also included:
[0033] The CBM sends a card data request int.NFC_KeyDataReq to the NFC card through the secure channel;
[0034] The NFC card encrypts the card data int.NFC_KeyData using the AES session key and sends it to the CBM;
[0035] The CBM decrypts the card data using the AES session key to obtain the NFC card ID;
[0036] The CBM verifies the legitimacy of the NFC card ID.
[0037] Furthermore, the temporary key pair is generated based on the elliptic curve cryptography algorithm ECC.
[0038] Furthermore, the key derivation function is based on the SHA-256 algorithm and the X9.63 standard.
[0039] Further, the receipt int.SD_receipt is generated using the HMAC-SHA256 algorithm with the shared keys ShSes and ShSee as inputs.
[0040] Further, the steps for the CBM to verify the legitimacy of the receipt int.SD_receipt include:
[0041] The CBM uses the HMAC-SHA256 algorithm with the shared keys ShSss and ShSee as inputs to calculate the receipt receipt_CBM;
[0042] Compare whether receipt_CBM is equal to the receipt int.SD_receipt sent by the NFC card.
[0043] Further, after the CBM verifies the legitimacy of the NFC card ID, the following steps are also included:
[0044] If the NFC card ID is legitimate, the CBM sends an operation instruction to the corresponding control module to complete the predetermined operation.
[0045] Further, the predetermined operations are vehicle unlocking, vehicle starting, or payment authentication.
[0046] Preferably, a certificate-exchange-based NFC card encryption transaction system includes:
[0047] A central Bluetooth module CBM for generating a temporary key pair, sending a temporary public key, calculating a shared key, verifying a receipt, establishing a secure communication channel, sending a data request, decrypting card data, and verifying the card ID;
[0048] An NFC card reader for detecting the placement event of the NFC card and sending the event to the CBM;
[0049] An NFC card for generating a temporary key pair, calculating a shared key, generating a receipt, establishing a secure communication channel, encrypting card data, and responding to the data request of the CBM;
[0050] Among them, the central Bluetooth module CBM, the NFC card reader, and the NFC card communicate using the certificate-exchange-based NFC card encryption transaction process of any one of claims 1 to 9.
[0051] Advantages of the present invention:
[0052] The use of temporary key pairs avoids the weaknesses of fixed keys and enhances the system's anti - attack ability. The certificate - based key exchange mechanism reduces the complexity of key configuration, supports dynamic key updates. Dynamically generating AES session keys shortens the key negotiation time and improves communication efficiency. Through the receipt verification mechanism, the legitimacy of both communication parties is ensured, preventing man - in - the - middle attacks. It is applicable to various intelligent transportation scenarios, such as vehicle unlocking, payment authentication, etc., and at the same time meets the requirements of the CAN / SecOC protocol. It uses the AES128 encryption algorithm and the SCP02 secure messaging protocol. These technologies are mature and consume less resources, making them suitable for implementation in embedded devices. Brief Description of the Drawings
[0053] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only those of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0054] Figure 1 It is a schematic diagram of the system architecture of the present invention;
[0055] Figure 2 It is a schematic diagram of the communication timing sequence of the present invention;
[0056] Figure 3 It is a schematic diagram of the key exchange process of the present invention;
[0057] Figure 4 It is a schematic diagram of the security implementation and application scenarios of the present invention;
[0058] Figure 5 It is a schematic diagram for a detailed explanation of the security mechanism of the present invention. Detailed Embodiments
[0059] The following will describe the present invention in detail in combination with the drawings and specific embodiments. At the same time, it should be noted here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments. For some well - known technologies, those skilled in the art can also adopt other alternative methods for implementation; moreover, the drawing part is only for a more specific description of the embodiments and is not intended to specifically limit the present invention.
[0060] It should be noted that in the specification, references to "one embodiment", "an embodiment", "exemplary embodiments", "some embodiments", etc. indicate that the described embodiments may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes that particular feature, structure, or characteristic. Additionally, when a particular feature, structure, or characteristic is described in connection with an embodiment, implementing such feature, structure, or characteristic in connection with other embodiments (whether or not explicitly described) should be within the knowledge of those skilled in the relevant art.
[0061] Generally, terms can be understood, at least in part, from their use in context. For example, depending at least in part on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in a singular sense, or can be used to describe a combination of features, structures, or characteristics in a plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey a set of exclusive factors, but rather, depending at least in part on the context, can alternatively allow for the existence of other factors that may not be explicitly described.
[0062] Refer to Figure 1
[0063] System architecture
[0064] The NFC card encryption transaction process based on certificate exchange of the present invention mainly involves two entities:
[0065] Server side: The central Bluetooth module, responsible for key generation, receipt verification, data request, and decryption.
[0066] Client side: The NFC card, responsible for key generation, receipt calculation, data encryption, and sending.
[0067] Refer to Figure 2
[0068] Communication process
[0069] The NFC card encryption transaction process based on certificate exchange of the present invention includes the following steps:
[0070] Initialize communication
[0071] When the NFC reader detects the placement event of the NFC card, the process starts:
[0072] The NFC reader detects the placement event of the NFC card and sends the event to the CBM.
[0073] The CBM generates a pair of temporary key pairs:
[0074] Temporary private key eSK.OCE.ECKA
[0075] Temporary public key ePK.OCE.ECKA
[0076] The logic of key pair generation is based on the elliptic curve algorithm, which is achieved by randomly generating a private key and calculating the corresponding public key.
[0077] The CBM sends the temporary public key ePK.OCE.ECKA to the NFC card through the NFC communication module.
[0078] Response and key negotiation of the NFC card
[0079] After receiving the temporary public key from the CBM, the NFC card performs the following operations:
[0080] The NFC card generates a temporary key pair:
[0081] Temporary private key eSK.SD.ECKA
[0082] Temporary public key ePK.SD.ECKA
[0083] Similar to the CBM, the NFC card generates a key pair through the elliptic curve algorithm.
[0084] The NFC card calculates the shared key:
[0085] Calculate ShSes: Calculate the shared key from the temporary public key ePK.OCE.ECKA of the CBM and the static private key SK.SD.ECKA of the NFC card.
[0086] Calculate ShSee: Calculate the shared key from the temporary public key ePK.OCE.ECKA of the CBM and the temporary private key eSK.SD.ECKA of the NFC card.
[0087] The NFC card derives the AES session key from ShSes and ShSee through the key derivation function (KDF):
[0088] The key derivation function (KDF) is based on the SHA-256 and X9.63 standards, and generates the session key by combining the shared key and additional shared information.
[0089] The NFC card sends the public key and receipt to the CBM:
[0090] The NFC card sends the temporary public key ePK.SD.ECKA and the receipt int.SD_receipt to the CBM.
[0091] CBM verification and session key generation
[0092] After receiving the temporary public key and receipt from the NFC card, the CBM performs the following operations:
[0093] The CBM calculates the shared key:
[0094] Calculate ShSss: Calculate the shared key from the static public key PK.SD.ECKA of the NFC card and the static private key SK.OCE.ECKA of the CBM.
[0095] Calculate ShSee: Calculate the shared key from the ephemeral public key ePK.SD.ECKA of the NFC card and the ephemeral private key eSK.OCE.ECKA of the CBM.
[0096] The CBM derives the AES session key from ShSss and ShSee through a key derivation function:
[0097] The logic of key derivation is similar to that of the NFC card, based on the SHA-256 and X9.63 standards.
[0098] The CBM verifies the receipt:
[0099] The CBM compares the calculated receipt with the receipt int.SD_receipt sent by the NFC card.
[0100] Verify the receipt match to confirm the legitimacy of both communication parties.
[0101] Establish a secure communication channel
[0102] If the receipt verification is successful, the CBM and the NFC card establish a secure communication channel:
[0103] The CBM and the NFC card establish a secure communication channel through the AES session key, using the SCP02 protocol.
[0104] The CBM sends the card data request int.NFC_KeyDataReq to the NFC card through the secure channel.
[0105] The NFC card encrypts the card data int.NFC_KeyData using the AES session key and sends it to the CBM.
[0106] The CBM decrypts the card data using the AES session key to obtain the NFC card ID.
[0107] The CBM verifies the legitimacy of the card ID to ensure the legal association between the NFC card and the vehicle.
[0108] Detailed description of key generation and verification
[0109] See Figure 3 、 Figure 4 and Figure 5 as shown
[0110] Ephemeral key pair generation
[0111] The generation of the ephemeral key pair is based on the Elliptic Curve Cryptography (ECC) algorithm, and the specific steps are as follows:
[0112] Select an appropriate elliptic curve parameter, such as NISTP-256 or BrainpoolP-256.
[0113] Generate a random number as the temporary private key (eSK).
[0114] Calculate the temporary public key (ePK) through elliptic curve point multiplication: ePK = eSK × G, where G is the base point of the elliptic curve.
[0115] Shared key calculation
[0116] The calculation of the shared key is based on the Elliptic Curve Diffie-Hellman (ECDH) key exchange algorithm, and the specific steps are as follows:
[0117] The NFC card calculates ShSes:
[0118] Input: The temporary public key ePK.OCE.ECKA of the CBM and the static private key SK.SD.ECKA of the NFC card
[0119] Calculate: ShSes = ECDH(SK.SD.ECKA × ePK.OCE.ECKA)
[0120] The NFC card calculates ShSee:
[0121] Input: The temporary public key ePK.OCE.ECKA of the CBM and the temporary private key eSK.SD.ECKA of the NFC card
[0122] Calculate: ShSee = ECDH(eSK.SD.ECKA × ePK.OCE.ECKA)
[0123] The CBM calculates ShSss:
[0124] Input: The static public key PK.SD.ECKA of the NFC card and the static private key SK.OCE.ECKA of the CBM
[0125] Calculate: ShSss = ECDH(SK.OCE.ECKA × PK.SD.ECKA)
[0126] The CBM calculates ShSee:
[0127] Input: The temporary public key ePK.SD.ECKA of the NFC card and the temporary private key eSK.OCE.ECKA of the CBM
[0128] Calculate: ShSee = ECDH(eSK.OCE.ECKA × ePK.SD.ECKA)
[0129] AES Session Key Derivation
[0130] The derivation of the AES session key is based on the Key Derivation Function (KDF), and the specific steps are as follows:
[0131] Connect ShSss and ShSee as the input material.
[0132] Use the SHA-256 hash function and the X9.63 key derivation standard to generate the session key:
[0133] AES Session Key = KDF(ShSss||ShSee||SharedInfo)
[0134] Generate session keys for different purposes as needed, such as encryption keys, MAC keys, etc.
[0135] Receipt Generation and Verification
[0136] The generation and verification of the receipt are used to confirm whether the shared keys calculated by both communication parties are the same, and the specific steps are as follows:
[0137] The NFC card generates a receipt:
[0138] Input: ShSes, ShSee, and other auxiliary information
[0139] Calculation: int.SD_receipt = HMAC-SHA256(ShSes||ShSee, "NFC_Receipt")
[0140] The CBM verifies the receipt:
[0141] Input: ShSss, ShSee, and other auxiliary information
[0142] Calculation: receipt_CBM = HMAC-SHA256(ShSss||ShSee, "NFC_Receipt")
[0143] Verification: Check whether receipt_CBM is equal to int.SD_receipt
[0144] Establishment of a Secure Communication Channel
[0145] The establishment of the secure communication channel is based on the SCP02 secure messaging protocol, and the specific steps are as follows:
[0146] Initialize the SCP02 protocol using the derived AES session key.
[0147] According to the provisions of the SCP02 protocol, encrypt and MAC protect the data to be sent.
[0148] Decrypt the received data and perform MAC verification to ensure the confidentiality and integrity of the data.
[0149] Card ID Verification
[0150] 1. Card ID verification is used to confirm the legitimacy of the NFC card. The specific steps are as follows:
[0151] 2. CBM decrypts the int.NFC_KeyData sent by the NFC card using the AES session key to obtain the card ID.
[0152] 3. CBM looks up this ID in its internal card ID list to confirm its legitimacy.
[0153] 4. If the card ID is legitimate, CBM completes the verification process and allows subsequent operations (such as vehicle unlocking, payment, etc.).
[0154] Specific Implementation Example
[0155] The following is a specific implementation example, taking the vehicle unlocking scenario as an example:
[0156] 1. The user brings the NFC card close to the NFC reader of the vehicle.
[0157] 2. The NFC reader detects the card and triggers CBM to start the key exchange process.
[0158] 3. CBM generates a temporary key pair and sends the temporary public key to the NFC card.
[0159] 4. The NFC card generates a temporary key pair, calculates the shared keys ShSes and ShSee, and derives the AES session key.
[0160] 5. The NFC card sends the temporary public key and receipt to CBM.
[0161] 6. CBM calculates the shared keys ShSss and ShSee, derives the AES session key, and verifies the receipt.
[0162] 7. After successful receipt verification, CBM and the NFC card establish a secure communication channel.
[0163] 8. CBM requests the ID data of the NFC card through the secure channel.
[0164] 9. The NFC card encrypts the ID data and sends it to CBM.
[0165] 10. CBM decrypts the ID data and verifies the legitimacy of the card ID.
[0166] 11. If the card ID is legitimate, CBM sends an unlock command to the vehicle control system to complete vehicle unlocking.
[0167] Example 1: Vehicle Unlock Scenario
[0168] Hardware Configuration:
[0169] NFC Card: An intelligent card supporting ECC and AES algorithms
[0170] CBM: Vehicle Central Control Module, with NFC communication and key processing capabilities
[0171] NFC Reader: A reader module integrated into the door handle
[0172] Implementation Process:
[0173] 1. The user brings the NFC card close to the NFC reader on the door handle.
[0174] 2. The reader detects the card and notifies the CBM.
[0175] 3. The CBM and the NFC card complete key exchange and verification according to the above process.
[0176] 4. After successful verification, the CBM sends an unlock command to the door control module.
[0177] 5. The door unlocks, and the user can enter the vehicle.
[0178] Example 2: Payment Scenario
[0179] Hardware Configuration:
[0180] NFC Card: An intelligent card with payment function
[0181] CBM: Control module of the payment terminal
[0182] NFC Reader: The card reading area of the payment terminal
[0183] Implementation Process:
[0184] 1. The user brings the NFC card close to the NFC card reading area of the payment terminal.
[0185] 2. The reader detects the card and notifies the CBM.
[0186] 3. The CBM and the NFC card complete key exchange and verification according to the above process.
[0187] 4. After successful verification, the CBM requests payment authorization information.
[0188] 5. The NFC card encrypts and sends the payment authorization information.
[0189] 6. The CBM verifies the payment authorization and completes the transaction.
[0190] The NFC card encryption transaction process based on certificate exchange of the present invention has the following security features:
[0191] Forward secrecy: Even if an attacker obtains the current key material, they cannot decrypt previous communication content because each communication uses an ephemeral key pair.
[0192] Resistance to man-in-the-middle attacks: Through the receipt verification mechanism, it is ensured that the session keys calculated by both communication parties are consistent, preventing man-in-the-middle attacks.
[0193] Resistance to replay attacks: Each communication uses a new ephemeral key pair, making it impossible to reuse previously captured communication data.
[0194] Key isolation: Keys for different purposes (such as encryption keys, MAC keys) are generated separately through a key derivation function to ensure key isolation.
[0195] Authentication: Through card ID verification, it is ensured that only legitimate NFC cards can complete the transaction process.
[0196] The NFC card encryption transaction process based on certificate exchange proposed by the present invention significantly improves the security, flexibility, and communication efficiency of NFC card encryption transactions by introducing ephemeral key pairs, a certificate-based key exchange mechanism, and the dynamic generation of AES session keys. This solution is applicable to various scenarios in intelligent transportation systems, such as vehicle unlocking, payment, etc., and has broad application prospects.
[0197] Definitions of abbreviations and key terms in the above content:
[0198] AES: Advanced Encryption Standard
[0199] CBM: Central Bluetooth Module
[0200] CAN: Controller Area Network
[0201] ECC: Elliptic Curve Cryptography
[0202] ECDH: Elliptic Curve Diffie-Hellman Key Exchange
[0203] SecOC: Security Onboard Communication
[0204] SHA: Secure Hash Algorithm
[0205] SGW: Security Gateway
[0206] The present invention covers any alternatives, modifications, equivalent methods, and solutions made within the spirit and scope of the present invention. For the public to have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention. However, those skilled in the art can fully understand the present invention without such detailed descriptions. Additionally, well-known methods, processes, procedures, components, and circuits are not described in detail to avoid unnecessary confusion to the essence of the present invention.
[0207] The above description is only a preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements can be made without departing from the principle of the present invention, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. An NFC card encryption transaction process based on certificate exchange, characterized in that, Including the following steps: The Central Bluetooth Module (CBM) generates a pair of temporary key pairs, including a temporary private key eSK.OCE.ECKA and a temporary public key ePK.OCE.ECKA, and sends the temporary public key ePK.OCE.ECKA to the NFC card via the NFC communication module; The NFC card generates a pair of temporary key pairs, including a temporary private key eSK.SD.ECKA and a temporary public key ePK.SD.ECKA; The NFC card calculates the shared keys ShSes and ShSee through the Elliptic Curve Diffie-Hellman key exchange algorithm, where ShSes is calculated from the temporary public key ePK.OCE.ECKA of the CBM and the static private key SK.SD.ECKA of the NFC card, and ShSee is calculated from the temporary public key ePK.OCE.ECKA of the CBM and the temporary private key eSK.SD.ECKA of the NFC card; The NFC card derives the AES session key from ShSes and ShSee through a key derivation function; The NFC card generates a receipt int.SD_receipt and sends the temporary public key ePK.SD.ECKA and the receipt int.SD_receipt to the CBM; The CBM calculates the shared keys ShSss and ShSee through the Elliptic Curve Diffie-Hellman key exchange algorithm, where ShSss is calculated from the static public key PK.SD.ECKA of the NFC card and the static private key SK.OCE.ECKA of the CBM, and ShSee is calculated from the temporary public key ePK.SD.ECKA of the NFC card and the temporary private key eSK.OCE.ECKA of the CBM; The CBM derives the AES session key from ShSss and ShSee through a key derivation function; The CBM verifies the legitimacy of the receipt int.SD_receipt sent by the NFC card; If the receipt verification is successful, the CBM and the NFC card establish a secure communication channel through the AES session key.
2. The NFC card encrypted transaction process based on certificate exchange according to claim 1, wherein The CBM and the NFC card establish the secure communication channel using the SCP02 secure messaging protocol.
3. The NFC card encryption transaction process based on certificate exchange according to claim 1, characterized in that, After establishing the secure communication channel, the following steps are further included: The CBM sends a card data request int.NFC_KeyDataReq to the NFC card through the secure channel; The NFC card encrypts the card data int.NFC_KeyData using the AES session key and sends it to the CBM; The CBM decrypts the card data using the AES session key to obtain the NFC card ID; The CBM verifies the legitimacy of the NFC card ID.
4. The NFC card encrypted transaction process based on certificate exchange according to claim 1, wherein The temporary key pair is generated based on the Elliptic Curve Cryptography (ECC) algorithm.
5. The NFC card encryption transaction process based on certificate exchange according to claim 1, characterized in that, The key derivation function is based on the SHA-256 algorithm and the X9.63 standard.
6. The NFC card encryption transaction process based on certificate exchange according to claim 1, characterized in that, The receipt int.SD_receipt is generated using the HMAC-SHA256 algorithm, with the shared keys ShSes and ShSee as inputs.
7. The NFC card encrypted transaction process based on certificate exchange according to claim 1, characterized in that, The steps for the CBM to verify the legality of the receipt int.SD_receipt include: The CBM uses the HMAC-SHA256 algorithm, with the shared keys ShSes and ShSee as inputs, to calculate the receipt receipt_CBM; Compare whether the receipt_CBM is equal to the receipt int.SD_receipt sent by the NFC card.
8. The NFC card encrypted transaction process based on certificate exchange according to claim 3, wherein After the CBM verifies the legality of the NFC card ID, the following steps are further included: If the NFC card ID is legal, the CBM sends an instruction to the corresponding control module to complete a predetermined operation.
9. The NFC card encryption transaction process based on certificate exchange according to claim 8, wherein The predetermined operation is vehicle unlocking, vehicle starting, or payment authentication.
10. An NFC card encryption transaction system based on certificate exchange, characterized in that, Include: The central Bluetooth module CBM, which is used to generate a temporary key pair, send a temporary public key, calculate a shared key, verify a receipt, establish a secure communication channel, send a data request, decrypt card data, and verify the card ID; The NFC reader, which is used to detect the placement event of the NFC card and send the event to the CBM; The NFC card, which is used to generate a temporary key pair, calculate a shared key, generate a receipt, establish a secure communication channel, encrypt card data, and respond to the data request of the CBM; Wherein, the central Bluetooth module CBM, the NFC reader, and the NFC card communicate using the NFC card encryption transaction process based on certificate exchange described in any one of claims 1 to 9.
Citation Information
Cited By
Intelligent glasses voiceprint anti-counterfeiting recognition method and system based on NFC (Near Field Communication)
CN121054002A