A CPU card security authentication system

By combining IoT and blockchain technologies, a CPU card security authentication system was designed, which solves the problems of high cost and complexity of CPU cards in low-to-mid-end scenarios, and achieves higher security and wider applicability, suitable for smart community and other scenarios.

CN120856303BActive Publication Date: 2025-12-02SHENZHEN QINLIN TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511355298.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-22
Publication Date
2025-12-02
Estimated Expiration
2045-09-22

AI Technical Summary

Technical Problem

Existing CPU card security authentication technologies are costly and complex to apply in low- to mid-range scenarios such as smart communities and smart parks, making them difficult to widely promote.

Method used

By employing IoT technology, key segmentation technology, and blockchain technology, combined with a consortium blockchain, distributed asset management and end-to-end encryption are achieved, forming a CPU card security authentication system. This system includes a property cloud, an M2M soft bus, card issuing devices, and card reading devices, and ensures communication security through dedicated encryption technology.

Benefits of technology

It achieves improved security and wide applicability of CPU cards without increasing hardware costs, and is suitable for low- to mid-range scenarios such as smart communities and smart parks. It effectively prevents simulated replay attacks and communication eavesdropping, and reduces the difficulty of cracking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856303B_ABST
    Figure CN120856303B_ABST
Patent Text Reader

Abstract

This invention discloses a CPU card security authentication system, relating to the field of CPU card security encryption technology. It includes a consortium blockchain, property management cloud, M2M soft bus, card issuing device, and card reading device. The system constructs a distributed asset management technology based on blockchain, managing device assets, card assets, and key assets separately. It shares keys through the blockchain and achieves network-independent direct communication via the M2M soft bus. This is applied to CPU card issuing and synchronization operations, ensuring end-to-end encrypted communication is not intercepted or cracked by any third party. This invention combines IoT technology, key segmentation technology, and blockchain technology to achieve distributed asset management and end-to-end encryption, thereby achieving secure authentication of CPU cards at a lower cost and solving the problem of widespread CPU card application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of CPU card security encryption technology, and more particularly to a CPU card security authentication system. Background Technology

[0002] The security authentication technologies of existing CPU cards on the market are mainly based on multi-layered encryption mechanisms, dynamic authentication protocols, and hardware protection designs, combined with international standards and industry specifications, forming a comprehensive security system.

[0003] CPU card security authentication technology combines cryptography, hardware protection, and dynamic policies to form a multi-layered security barrier. With the development of quantum computing and AI technologies, post-quantum encryption, biometric fusion, and edge intelligence will become key directions for future development. When selecting a CPU card, it is necessary to match the appropriate security standards (such as EMV, PBOC) and algorithms (such as national cryptographic standards, post-quantum) according to the application scenario (such as finance, transportation, and identity authentication), while also paying attention to the manufacturer's technological updates and compliance.

[0004] However, these technologies are rarely used in residential community access control systems; they are more often applied in scenarios with higher security requirements. This is because:

[0005] High cost: Encryption technology, even quantum encryption technology, will lead to a sharp increase in the cost of CPU cards.

[0006] Complex to use: Biometric and multimodal fusion technologies cause users to linger at access control points for longer periods, which is not suitable for high-frequency usage scenarios.

[0007] Therefore, how to design CPU cards suitable for low- to mid-range scenarios such as smart communities, smart parks, community canteens for the elderly, community renovation and upgrading, and smart card systems for old communities to improve regional security is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0008] To address the aforementioned issues, this invention provides a CPU card security authentication system that combines IoT technology, key segmentation technology, and blockchain technology to achieve distributed asset management and end-to-end encryption. This enables secure authentication of CPU cards at a lower cost, thereby solving the problem of widespread CPU card application.

[0009] To achieve the above objectives, the technical solution adopted by the present invention is: to provide a CPU card security authentication system, comprising:

[0010] Consortium blockchains are used to implement key tamper-proofing, key distribution, device asset management, and access card asset management, managing device assets, card assets, and key assets.

[0011] The property management cloud is connected to the consortium blockchain. The property management cloud is used to use the consortium blockchain as an asset database. When a card issuing device issues a card, the property management cloud initiates a query to the consortium blockchain. If a card issuing device, consortium blockchain, and card reading device that are not in the database are found, the card will be rejected.

[0012] The M2M soft bus is used to enable card issuing devices and card swiping devices in the same community to communicate with each other based on the property management cloud. The M2M soft bus adopts dedicated encryption technology, and the encryption key is distributed through the consortium blockchain to ensure that the property management cloud cannot parse the protocol packets, thus ensuring that the property management cloud cannot crack the end-to-end M2M communication.

[0013] A card issuing device, used to write encrypted content to a CPU card, wherein the card issuing device is connected to the property management cloud via an M2M soft bus;

[0014] A card reader is a device used to read CPU cards and verify their contents. The card reader is connected to the property management cloud via an M2M soft bus.

[0015] As a preferred option, when the CPU card leaves the factory, the asset data is provided by factory staff and then imported into the consortium blockchain by platform technicians.

[0016] After the card issuing device is started, it connects to the M2M soft bus and requests network access from the M2M soft bus;

[0017] The M2M soft bus retrieves information from the consortium blockchain and verifies the legitimacy of the device through the consortium blockchain's verification interface.

[0018] If the verification is successful, the device can be registered on the network normally; if the verification fails, the device will be forcibly taken offline.

[0019] Devices that fail to register with the network three times in a row will be blacklisted by the M2M soft bus management service, with the blacklist duration increasing with each subsequent failure.

[0020] As a preferred option, after the card issuing device and card reading device are started and successfully registered on the network, they retrieve the tenant key and project key.

[0021] When reading and writing cards, the device uses the tenant key and project key to calculate the final application key according to preset rules, and operates the card based on the application key;

[0022] When reading and writing cards, the card issuing device and the card reading device use the project asset UID list issued by the asset center to verify the card's UID. Cards not in the UID list will be rejected by the device for reading and writing.

[0023] Preferably, the CPU card is also used to store key asset data and provide verification and distribution capabilities. The key asset data includes device keys, card root keys, tenant keys, and project keys.

[0024] More preferably, the device key is used to verify the legitimacy of the device;

[0025] The card root key specifically refers to the card's root key, which is used when initializing the card;

[0026] Tenant keys exist as part of application keys, and each tenant is equipped with one key.

[0027] The project key exists as part of the application key, and each project is equipped with one key.

[0028] Preferably, when both the device asset and the card asset are successfully verified, the card issuing device distributes the card information to card issuing devices and card reading devices in the same project and the same tenant via the M2M soft bus when the card is successfully issued.

[0029] When a user performs status operations such as reporting a lost card, unblocking a card, checking for expiration, or renewing a card, the card issuing device, upon successful operation, distributes the card information to card issuing and reading devices within the same project and among the same tenant via the M2M soft bus.

[0030] As a preferred option, tenants must complete the following steps when registering on the platform:

[0031] Users can independently set their own account passwords for the consortium blockchain.

[0032] The tenant key is generated autonomously; wherein the tenant key is a 16-byte random string.

[0033] Bind the MFA verification code; thereafter, the tenant must verify the MFA verification code every time they log in.

[0034] Even better, when a tenant logs into the platform and starts the card issuing device, the card issuing device software will pull the tenant's key from the consortium blockchain and upload it to the consortium blockchain;

[0035] Each time the card issuing device and the card reading device are started, they pull the tenant key and the cell key from the consortium blockchain;

[0036] Tenant keys can only be accessed on accounts and devices authorized by the tenant.

[0037] The beneficial effects of this invention are as follows:

[0038] 1. Enhanced security:

[0039] Each device and each CPU card is documented at the factory, preventing unauthorized devices and cards from performing any operations in the system and effectively preventing simulated replay attacks.

[0040] Each CPU card can only be used in one project of one tenant, effectively ensuring the security of CPU card applications in scenarios such as access control and wallets within the project.

[0041] The increased difficulty for attackers to obtain the final key has increased the time required to crack the CPU card by more than 300%, further ensuring the card's security.

[0042] 2. More reliable communication: End-to-end encryption technology ensures that user control commands to devices can only occur between tenants and devices, and between devices. Attackers cannot obtain communication keys, which can effectively prevent eavesdropping attacks and make the communication process of the M2M soft bus more reliable.

[0043] 3. Higher cost performance: The application of CPU cards is no longer limited to high-end scenarios, but is also applicable to mid-to-low-end scenarios. They can be widely used in smart communities, smart parks, community canteens for the elderly, community renovation and upgrading, and card-based systems for old communities. They can also be effectively integrated through application design.

[0044] Zero hardware cost: By utilizing software technologies such as consortium blockchain, security can be enhanced without increasing the cost of access control devices and CPU cards.

[0045] Wide applicability: It is suitable for any type of CPU card and any application scenario of CPU card, and future upgrades are also very simple.

[0046] Strong scalability: It is not only suitable for access control products, but also for wallet scenarios, and can be expanded to more applications. Attached Figure Description

[0047] Figure 1 This is a framework diagram of a CPU card security authentication system according to the present invention. Detailed Implementation

[0048] Please see Figure 1 As shown, the present invention provides a CPU card security authentication system, comprising:

[0049] Consortium blockchains are used to implement key tamper-proofing, key distribution, device asset management, and access card asset management, managing device assets, card assets, and key assets.

[0050] The property management cloud is connected to the consortium blockchain. The property management cloud is used to use the consortium blockchain as an asset database. When a card issuing device issues a card, the property management cloud initiates a query to the consortium blockchain. If a card issuing device, consortium blockchain, and card reading device that are not in the database are found, the card will be rejected.

[0051] The M2M soft bus is used to enable card issuing devices and card swiping devices in the same community to communicate with each other based on the property management cloud. The M2M soft bus adopts dedicated encryption technology, and the encryption key is distributed through the consortium blockchain to ensure that the property management cloud cannot parse the protocol packets, thus ensuring that the property management cloud cannot crack the end-to-end M2M communication.

[0052] A card issuing device, used to write encrypted content to a CPU card, wherein the card issuing device is connected to the property management cloud via an M2M soft bus;

[0053] A card reader is a device used to read CPU cards and verify their contents. The card reader is connected to the property management cloud via an M2M soft bus.

[0054] Consortium blockchain node configuration: It consists of a community property server (1 master node), an equipment manufacturer server (2 consensus nodes), and an owners' committee server (1 supervisory node). The node hardware uses an 8-core 16GB server and is equipped with a Hyperledger Fabric 2.4 architecture.

[0055] Consensus mechanism: The Raft consensus algorithm is used, the block generation interval is 5 seconds, and each node stores a complete copy of the ledger;

[0056] Smart Contracts: Deploy asset management contracts and key distribution contracts to support CRUD operations on device assets, card assets, and key assets.

[0057] The deployment environment of the property management cloud platform is as follows: It uses an Alibaba Cloud ECS instance (4 cores and 8GB) and is equipped with a Spring Cloud microservice architecture.

[0058] Core modules include: asset query module, card issuance approval module, device management module, and log auditing module;

[0059] Data interaction: Communicates with consortium blockchain nodes via RESTful API, using a TLS 1.3 encrypted transmission channel.

[0060] The communication protocol of the M2M soft bus is based on the MQTT protocol and extends the private communication frame format to support device discovery, connection establishment, and data transmission functions.

[0061] Deployment method: Integrated into the property cloud platform's message middleware (RabbitMQ), supporting 1000+ concurrent device connections;

[0062] Encryption module: Built-in national standard SM4 algorithm engine, supporting symmetric encryption with a key length of 256 bits.

[0063] Hardware configuration of the card issuing device: an industrial tablet equipped with an ARM Cortex-A53 processor, integrating an ISO 7816 standard card reader, a fingerprint recognition module, and a 4G communication module;

[0064] Security components: Built-in SM2 encryption chip (supports secure key storage and signature operations), equipped with a physical tamper-proof switch;

[0065] Software features: Includes card writing module, key management module, and M2M communication module, supporting offline caching and online synchronization.

[0066] Hardware configuration of the card reader: Embedded access control terminal (ARM Cortex-M4 processor), integrating NFC card reader, relay control module, and WiFi module;

[0067] Security design: Employs a tamper-proof shell, stores critical data in encrypted Flash memory, and supports encrypted storage of local logs;

[0068] Working mode: Supports online verification (real-time network connection) and offline verification (caching the 1000 most recent verification records).

[0069] Distributed asset management technology is an asset management technology based on blockchain, primarily used to manage device assets, card assets, and key assets.

[0070] Equipment Assets: Stores asset data for two types of equipment: card issuing devices and card reading devices, and provides verification capabilities. Equipment Asset Verification Logic:

[0071] When the equipment leaves the factory, the asset data is provided by the factory staff and then imported into the consortium blockchain by the platform's technical staff.

[0072] After the device starts up, it connects to the M2M soft bus and requests network access from the M2M soft bus.

[0073] The M2M soft bus retrieves information from the consortium blockchain and verifies the legitimacy of the device through the consortium blockchain's verification interface.

[0074] If the verification is successful, the device can be registered on the network normally; if the verification fails, the device will be forcibly taken offline.

[0075] Devices that fail to register with the network three times in a row will be blacklisted by the M2M soft bus management service, with the blacklist duration increasing with each subsequent failure.

[0076] Card Assets: Stores card asset data and provides verification capabilities. Card Asset Verification Logic:

[0077] When the cards leave the factory, the asset data is provided by the factory staff and imported into the consortium blockchain by the platform's technical staff.

[0078] After the card issuing device and card reading device are started and successfully registered on the network, they retrieve two key segments: the tenant key and the project key.

[0079] When reading and writing cards, the device uses the tenant key and project key to calculate the final application key according to certain rules, and uses this key to operate the card.

[0080] When reading and writing cards, the device uses the project asset UID list issued by the asset center to verify the card's UID. Cards not in the UID list will be refused reading and writing by the device.

[0081] Key Assets: Stores key asset data and provides authentication and distribution capabilities. Key assets include device keys, card root keys, tenant keys, and project keys. Among them:

[0082] Device key: Used to verify the legitimacy of the device.

[0083] Card root key: Specifically refers to the root key of the card, which is used when initializing the card.

[0084] Tenant key: Each tenant has a key, which exists as part of the application key.

[0085] Project key: Each project has a unique key, which exists as part of the application key.

[0086] Distributed end-to-end encryption technology occurs between card issuing and reading devices. They share keys via blockchain and achieve direct communication independent of the network environment through an M2M soft bus. It is mainly applied in the following two scenarios:

[0087] Card issuance operation: When both the device asset and the card asset are successfully verified, the card issuing device will distribute the card information to other devices in the same project and the same tenant via the M2M soft bus when the card is successfully issued.

[0088] In a preferred embodiment, the key distribution process is as follows:

[0089] 1. During system initialization, the consortium blockchain master node generates a root key (32-byte SM4 key) and synchronizes it to all consensus nodes through an inter-node encrypted channel;

[0090] 2. Upon initial startup, the card issuing / reading device generates an RSA key pair (2048 bits) and sends the public key and device information to the consortium blockchain.

[0091] 3. After verifying the legitimacy of the device, the consortium blockchain encrypts the session key with the device's public key and writes it into the ledger via a smart contract;

[0092] 4. The device periodically (every 72 hours) sends a key update request to the consortium blockchain to obtain a new session key and destroy the old key.

[0093] Card issuing equipment operation procedure:

[0094] 1. The operator enters user information (name, room number, validity period) into the card issuing device and collects the user's fingerprint;

[0095] 2. The device generates CPU card data (including user information, permission list, and validity period) and encrypts it using the application key (obtained from the consortium blockchain);

[0096] 3. Write encrypted data to the CPU card using a card reader and generate a unique card identifier (cardId);

[0097] 4. Send the card issuance result (including cardId and encrypted card data digest) to the property management cloud.

[0098] 5. The property management cloud will synchronize the card issuance results to the consortium blockchain and update the card asset status.

[0099] Card reader verification process:

[0100] 1. When a user swipes their card, the card reader reads the encrypted data stored in the CPU card;

[0101] 2. The device uses the locally stored application key to decrypt the data and extract user information and permission lists;

[0102] 3. Generate a verification request (containing cardId, device ID, and current timestamp), encrypt it with the session key, and send it via the M2M soft bus;

[0103] 4. Upon successful verification, the relay is activated to open the access control system, and an operation log (including encrypted user information) is recorded.

[0104] 5. If verification fails (e.g., key mismatch, permission expired), trigger an audible and visual alarm and upload the abnormal record.

[0105] Card status synchronization: When a user performs status operations such as reporting a card as lost, unblocking it, checking for expiration, or renewing it, the card issuing device will distribute the card information to other devices in the same project and among the same tenants via the M2M soft bus upon successful operation.

[0106] Taking the card issuance scenario of the access control system as an example: when a resident successfully obtains a card, the access control card issuer will write the successful card UID, access permissions and card information, and push it to the access control equipment at the main gate of the resident's community and the access control equipment in the resident's building via the M2M soft bus.

[0107] Distributed end-to-end encryption technology refers to a key mutual recognition mechanism between the card issuing device and the card reading device, which is not known to the platform or third parties, and can only be communicated between devices within the same tenant.

[0108] This technology ensures that end-to-end encrypted communication is not intercepted or cracked by any third party through tenant key permission management on the consortium blockchain.

[0109] When a tenant registers on the platform, they need to complete the following three steps:

[0110] Users can independently set their own account passwords for the consortium blockchain.

[0111] Generate your own tenant key. The tenant key is a 16-byte random string.

[0112] Link the MFA verification code. Afterwards, each time a tenant logs in, they must verify the MFA to log in.

[0113] When a tenant logs into the platform and starts the card issuing device, the card issuing device software will retrieve the tenant's key from the consortium blockchain and upload it to the consortium blockchain.

[0114] Each time the card issuing device and the card reading device are started, they pull the tenant key and the cell key from the consortium blockchain.

[0115] Consortium blockchain authorization guarantee: Tenant keys can only be accessed on accounts and devices authorized by the tenant.

[0116] This invention can be applied in the following scenarios:

[0117] Financial payments: EMV chip cards significantly reduce the risk of fraudulent transactions through dynamic data authentication and online authorization; UnionPay QuickPass combines TEE and SE to achieve secure and fast mobile payments.

[0118] Transportation: Contactless CPU cards support fast passage (such as subway turnstiles) and combine national cryptographic algorithms to protect transaction data.

[0119] Identity Authentication: Electronic passports and government ID cards use asymmetric encryption and biometrics to ensure that identity information cannot be forged.

[0120] This invention also includes a security enhancement mechanism:

[0121] 1. Device Anomaly Detection: The consortium blockchain periodically verifies the device status and immediately freezes related assets when anomalies are detected (such as key leakage);

[0122] 2. Offline emergency solution: The card reader caches the key data of the last 72 hours, and can perform local verification when the network is disconnected;

[0123] 3. Key rotation mechanism: The root key is automatically rotated every 180 days, and the session key is automatically updated every 72 hours;

[0124] 4. Operation Audit: All card issuance and verification operations generate tamper-proof audit logs, which are stored on the consortium blockchain.

[0125] This embodiment uses a consortium blockchain to achieve tamper-proof management of assets and keys, establishes a device access mechanism with the help of a property cloud, and uses end-to-end encryption technology of M2M soft bus to ensure communication security, forming a security authentication system covering the entire life cycle of CPU cards, effectively preventing security risks such as counterfeit cards, illegal card issuance, and communication eavesdropping.

[0126] The above embodiments are merely descriptions of preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made by those skilled in the art to the technical solutions of the present invention without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.

Claims

1. A CPU card security authentication system, characterized in that, include: Consortium blockchains are used to implement key tamper-proofing, key distribution, device asset management, and access card asset management, managing device assets, card assets, and key assets. The property management cloud is connected to the consortium blockchain. The property management cloud is used to use the consortium blockchain as an asset database. When a card issuing device issues a card, the property management cloud initiates a query to the consortium blockchain. If a card issuing device, consortium blockchain, and card reading device that are not in the database are found, the card will be rejected. The M2M soft bus is used to enable card issuing devices and card swiping devices in the same community to communicate with each other based on the property management cloud. The M2M soft bus adopts a dedicated encryption technology, and the encryption key is distributed through the consortium blockchain to ensure that the property management cloud cannot parse the protocol packets and the end-to-end M2M communication cannot be cracked by the property management cloud. A card issuing device, used to write encrypted content to a CPU card, wherein the card issuing device is connected to the property management cloud via an M2M soft bus; A card reader is a device used to read CPU cards and verify their contents. The card reader is connected to the property management cloud via an M2M soft bus.

2. The CPU card security authentication system according to claim 1, characterized in that, When the CPU card leaves the factory, the asset data is provided by the factory staff and imported into the consortium blockchain by the platform's technical staff. After the card issuing device is started, it connects to the M2M soft bus and requests network access from the M2M soft bus; The M2M soft bus retrieves information from the consortium blockchain and verifies the legitimacy of the device through the consortium blockchain's verification interface. If the verification is successful, the device can be registered on the network normally; if the verification fails, the device will be forcibly taken offline. Devices that fail to register with the network three times in a row will be blacklisted by the M2M soft bus management service, with the blacklist duration increasing with each subsequent failure.

3. The CPU card security authentication system according to claim 1, characterized in that, After the card issuing device and card reading device are started and successfully registered on the network, they retrieve the tenant key and project key. When reading and writing cards, the device uses the tenant key and project key to calculate the final application key according to preset rules, and operates the card based on the application key; When reading and writing cards, the card issuing device and the card reading device use the project asset UID list issued by the asset center to verify the card's UID. Cards not in the UID list will be rejected by the device for reading and writing.

4. The CPU card security authentication system according to claim 1, characterized in that, The CPU card is also used to store key asset data and provide verification and distribution capabilities. Key asset data includes device keys, card root keys, tenant keys, and project keys.

5. A CPU card security authentication system according to claim 4, characterized in that, The device key is used to verify the legitimacy of the device; The card root key specifically refers to the card's root key, which is used when initializing the card; Tenant keys exist as part of application keys, and each tenant is equipped with one key. The project key exists as part of the application key, and each project is equipped with one key.

6. The CPU card security authentication system according to claim 1, characterized in that, If both the device asset and the card asset are successfully verified, the card issuing device will distribute the card information to other card issuing devices and card reading devices in the same project and among the same tenants via the M2M soft bus when the card is successfully issued. When a user reports a card as lost, unblocks it, checks its expiration date, or renews it, the card issuing device, upon successful operation, distributes the card information to other card issuing and reading devices within the same project and tenant via the M2M soft bus.

7. A CPU card security authentication system according to claim 1, characterized in that, When registering on the platform, tenants need to complete the following steps: Users can independently set their own account passwords for the consortium blockchain. The tenant key is generated autonomously; wherein the tenant key is a 16-byte random string. Bind the MFA verification code; thereafter, the tenant must verify the MFA verification code every time they log in.

8. A CPU card security authentication system according to claim 7, characterized in that, When a tenant logs into the platform and starts the card issuing device, the card issuing device software will retrieve the tenant's key from the consortium blockchain and upload it to the consortium blockchain. Each time the card issuing device and the card reading device are started, they pull the tenant key and the cell key from the consortium blockchain; Tenant keys can only be accessed on accounts and devices authorized by the tenant.

Citation Information

Patent Citations

  • Internet of Things communication encryption system for CPU card management

    CN120811791A