Card password generation method and device, card password jet printing method and device, card password verification method and device, terminal and storage medium

By generating and verifying card keys through a hardware security module, combined with OCR recognition and overwrite deletion, the security and accuracy issues in the card key generation and printing process are solved, achieving high security and high-quality card key production.

CN120910923AActive Publication Date: 2025-11-07SUZHOU JINHETONG SOFTWARE

Patent Information

Application Number
CN202511440339.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2025-11-07
Estimated Expiration
2045-10-10

AI Technical Summary

Technical Problem

The existing card generation and printing process has insufficient security, making cards easy to leak, and lacks an effective verification process, resulting in losses for enterprises and damage to consumer rights.

Method used

The card number and password are generated using a hardware security module. Combined with OCR recognition and comparison, the card password accuracy is ensured. After the comparison is consistent, the card is overwritten and deleted to avoid long-term storage.

Benefits of technology

This improves the security and accuracy of the card key, prevents information leakage, enhances product quality, and reduces subsequent processing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120910923A_ABST
    Figure CN120910923A_ABST
Patent Text Reader

Abstract

The invention discloses a card password generation, jet printing and verification method and device, a terminal and a storage medium, and the method comprises the steps: reading an enterprise code and a seed code corresponding to the enterprise code from a hardware security module, and enabling each enterprise to have a unique enterprise code; based on a hardware security module, generating a card number according to the enterprise code, the seed code and a preset card number generation algorithm, and generating a card password corresponding to the card number in combination with the card number and a preset card password generation algorithm; spraying and printing the generated card password on a card password area on the coupon corresponding to the card number through spraying and printing equipment; carrying out OCR (Optical Character Recognition) on the coupon to obtain a card password recognition result, and comparing the card password recognition result with the card password; and if the comparison result is consistent, covering the card password area and deleting the card password. According to the method, dynamic generation and verification of the card number and the card password are realized based on the hardware security module, and the card password is not stored after being generated, so that the effects of improving the card password security and the product quality and avoiding information leakage are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of electronic commerce, in particular to a card code generation, printing and verification method and device, a terminal and a storage medium. BACKGROUND

[0002] Card products or electronic tags are widely used in modern commercial activities. As a common form, card coupons play an important role in various promotion and marketing activities. The generation, printing and verification of the unique identification code (card code) on the card coupon are crucial to improving the production efficiency of the card coupon and ensuring product quality. With the increasing frequency and expanding scale of commercial activities, the efficiency of card coupon production and the security of card code are increasingly required. The card code processing link has become a key factor affecting the entire card coupon production process. It not only relates to the production efficiency and cost control of enterprises, but also directly affects the user experience of consumers and the business reputation of enterprises.

[0003] In the field of card coupon production, to solve the problems of card code generation, printing and verification, the conventional means mainly generate card codes based on fixed algorithms and store them in a database. In actual operation, when the card coupon needs to be printed, the card code information is directly called from the database. This method can ensure the production rate of the card coupon to a certain extent, so that the production line can operate efficiently to meet the needs of large-scale production.

[0004] However, the conventional means in the prior art have obvious security defects. The existing card code storage method has certain vulnerability. After generating the card code by a fixed algorithm, the card code is stored together with the card number in the database. Even if encrypted storage is used, the card code still has the possibility of being attacked, resulting in card code leakage. Moreover, the security of the card code generated by this method is not strong enough. The card code stored in the database can be directly seen by calling and querying, which may lead to information leakage. In addition, the process from card code generation to printing is open, and the card number and card code can be easily accessed by the staff of the production line. Moreover, the original card manufacturing process does not include an additional verification process, which may have errors. Once the card code is leaked or incorrect, it may cause serious losses to the enterprise, damage the rights and interests of consumers, and affect the business reputation and normal operation of the enterprise.

[0005] Under such circumstances, how to optimize the generation, printing and verification process of the card code has become a key problem for technical personnel in this field. SUMMARY

[0006] In order to optimize the entire process of card code generation in the existing card coupon manufacturing process, the present application provides a card code generation, printing and verification method, device, terminal and storage medium.

[0007] In a first aspect, the application provides a card code generation, jet printing and verification method, which adopts the technical solution as described below: A card code generation, jet printing and verification method based on a hardware security module, the method comprising the following steps: reading an enterprise code and a seed code corresponding to the enterprise code from the hardware security module, each enterprise having a unique enterprise code; generating a card number based on the hardware security module, according to the enterprise code, the seed code and a preset card number generation algorithm, and generating a card code corresponding to the card number in combination with the card number and a preset card code generation algorithm; jet printing the generated card code on a card code area of the card coupon corresponding to the card number by a jet printing device; performing OCR identification on the card coupon to obtain a card code identification result, comparing the card code identification result with the card code and obtaining a comparison result; if the comparison result is consistent, covering the card code area and deleting the card code.

[0008] By adopting the above technical solution, the enterprise code and the seed code are read based on the hardware security module to generate a card number and a corresponding card code, avoiding the traditional database storage card code mode and improving the security of the card number and the card code. The card code is jet printed on the card coupon and subjected to OCR identification and comparison, ensuring the accuracy of the card code. After the comparison is consistent, the card code area is covered and the card code is deleted, avoiding the security risks caused by long-term storage.

[0009] Preferably, the card number is generated according to the enterprise code, the seed code and a preset card number generation algorithm, specifically comprising the following steps: reading the enterprise code and the corresponding seed code from the encrypted storage area of the hardware security module, generating a 4-bit random factor by a true random number generator built-in the hardware security module, the enterprise code being a 6-digit pure number, the seed code being an 8-digit pure number, and the seed code being unique within the current enterprise; converting the random factor into a first intermediate value by a hardware adder, a hardware multiplier and a modulo operation circuit, the first intermediate value being 2 bits; judging the parity of the enterprise code by a parity detection circuit, selecting a corresponding second intermediate value combination path according to the parity using a multiplexer, and generating a second intermediate value in combination with the first intermediate value and the enterprise code, the second intermediate value being 8 bits; obtaining a first check code according to a bit shift register and the second intermediate value, and obtaining a second check code according to the enterprise code and the seed code; The card number is generated according to a preset encoding combination rule by combining the enterprise code, the seed code, the random factor, the first check code and the second check code and is stored in the hardware security module.

[0010] By using the above technical solution, the enterprise code is read from the encrypted storage area of the hardware security module, the seed code is called and the random factor is generated, so that the security and randomness of the data source are ensured; the intermediate value is generated by using the hardware adder, multiplier, modulo operation circuit, parity detection circuit and multiplexer, so that the efficiency and accuracy of the encoding generation are improved; the check code is obtained according to the shift register and the intermediate value, the enterprise code and the seed code, so that the reliability of the encoding is enhanced; finally, the card number is generated by combining each element according to the rule, so that the generated card number has more security, accuracy and reliability.

[0011] Preferably, after the card number is generated, the following steps are further included: A preset card number check algorithm is called to verify the card number read from the hardware security module, the card number check algorithm is bound with the card number generation algorithm, the verification process includes that the encoding structure of the card number is identified by the pattern matching circuit of the hardware security module, the generated card number is parsed according to the encoding structure, and the parsed enterprise code, seed code, first check code and second check code are obtained; The random factor for generating the current card number is obtained, the enterprise code and the seed code obtained after parsing are combined, the first verification code and the second verification code are generated according to the card number generation algorithm, when the first verification code is the same as the parsed first check code and the second verification code is the same as the parsed second check code, it is determined that the generated card number is valid, otherwise it is determined that the card number is invalid, and the subsequent card key generation process is terminated.

[0012] By using the above technical solution, after the card number is generated according to the seed code, the enterprise code and the preset card number generation algorithm, a card number check algorithm associated with the card number generation algorithm is called, the encoding structure of the card number is identified and stored by the pattern matching circuit of the hardware security module, and then the card number is checked, so that whether the card number is qualified can be determined, thereby avoiding the use of invalid card number to generate card key, improving the accuracy of card key generation, at the same time, the card key generation process of invalid card number is terminated, unnecessary waste of computing resources is reduced, and the overall efficiency of the system is improved.

[0013] Preferably, the combination of the card number and the preset card key generation algorithm to generate the card key corresponding to the card number specifically includes the following steps: The mode matching circuit of the hardware security module identifies the coding structure of the card number, and stores the identified coding structure into a corresponding security register, the coding structure including the enterprise code, the seed code, and a coupon verification code generated according to the first verification code and the second verification code; The card number is summed by a hardware accumulator, and a 1-bit first password verification code is obtained by combining a modulo operation circuit; The seed code and the coupon verification code are subjected to an exclusive OR operation by an exclusive OR gate array, and a 2-bit second password verification code is generated by combining a modulo operation circuit and a preset first password combination rule with the obtained result; The enterprise code, the second password verification code, and the coupon verification code are subjected to a bit shift operation by a bit shift register, and a 3-bit third password verification code is generated by combining a modulo operation circuit and a preset second password combination rule; The first password verification code, the second password verification code, and the third password verification code are combined in a preset order by a hardware splicing circuit to obtain a card secret, and the card secret and the corresponding card number are transmitted to an encryption buffer of the printing device through a hardware encryption interface.

[0014] By using the above technical solution, the mode matching circuit of the hardware security module is used to identify and store the card number coding structure, and the hardware circuits such as the hardware accumulator, the exclusive OR gate array, the bit shift register, and the hardware splicing circuit are used to generate the card secret by combining the modulo operation circuit and the preset rule, thereby improving the efficiency and security of the card secret generation. The card secret and the card number are transmitted to the encryption buffer of the printing device through the hardware encryption interface, further ensuring the security of the card secret during transmission.

[0015] Preferably, the card secret printed on the card secret area of the card corresponding to the card number is received by the printing device connected to the hardware security module, and the card secret is printed on the card corresponding to the card number according to a preset printing format, specifically on the card secret area of the card.

[0016] By using the above technical solution, the printing device is connected to the hardware security module, can receive the card secret and the card number transmitted by the hardware security module, and accurately print the card secret on the card secret area of the card according to the preset format, thereby ensuring the accuracy and standardization of the card secret printing position.

[0017] Preferably, the card secret recognition result obtained by performing OCR identification on the card is compared with the card secret, specifically including the following steps: After the printing is completed, the card is imaged by a camera device to obtain image data, the image data is character segmented, a character recognition result of the card is obtained by using an OCR recognition engine, the character recognition result includes a card number and a card number, and the card number and the card number of the card number recognition result are compared with the card number and the card number received from the hardware security module by a security comparator of the hardware security module to obtain a comparison result.

[0018] By adopting the technical solution, after the printing is completed, the card is imaged, character segmented and recognized to obtain a card number recognition result, and the card number recognition result is compared with the card number received from the hardware security module by using the security comparator of the hardware security module, so that the card number printed on the card is ensured to be accurate, the product quality is improved, and the subsequent processing cost is reduced.

[0019] Preferably, when the comparison result is completely consistent, the comparison passes, a region full coverage command is triggered to physically cover the card number region, a register erasing instruction is executed by the hardware security module, and the temporarily stored card number is deleted.

[0020] By adopting the technical solution, when the card number comparison is consistent, the card number region is physically covered and the temporarily stored card number is deleted, so that the security risk caused by long-term storage of the card number is avoided, any form of information leakage is prevented, and the security of the card number is improved.

[0021] In a second aspect, the application provides a card number generation, printing and verification device, which adopts the following technical solution: A card number generation, printing and verification device includes the following modules: A data reading module is configured to read an enterprise code and a seed code corresponding to the enterprise code from the hardware security module, and each enterprise has a unique enterprise code; A card number generation module is configured to generate a card number based on the hardware security module, according to the enterprise code, the seed code and a preset card number generation algorithm, and generate a card number corresponding to the card number by combining the card number and a preset card number generation algorithm; A card number printing module is configured to print the generated card number in the card number area of the card corresponding to the card number; A card number verification module is configured to perform OCR recognition on the card to obtain a card number recognition result, compare the card number recognition result with the card number, and obtain a comparison result; A card number deletion module is configured to cover the card number region and delete the card number if the comparison result is consistent.

[0022] In a third aspect, the application provides an intelligent terminal, which adopts the following technical solution: An intelligent terminal comprises a memory and a processor, the memory storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, at least one program, code set or instruction set being loaded and executed by the processor to implement the card number generation, printing and verification method as described above.

[0023] In a fourth aspect, the present application provides a computer-readable storage medium, which adopts the following technical solution: A computer-readable storage medium, the readable storage medium storing at least one instruction, at least one program, a code set or an instruction set, the at least one instruction, at least one program, code set or instruction set being loaded and executed by a processor to implement the card number generation, printing and verification method as described above.

[0024] In summary, the present application at least includes the following beneficial effects: (1) The present application generates card numbers and card codes based on a hardware security module, avoiding the traditional database storage of card numbers and card codes, and significantly improving the security of card codes; (2) The present application performs OCR identification on the card and compares the identification result with the card code to ensure that the card code of each product is accurate and correct, improve product quality, and reduce subsequent processing costs; (3) In the present application, if the card code comparison result is consistent, the card code area is covered and the card code is deleted, and the card code is not stored, preventing any form of information leakage and ensuring the security of the card code. BRIEF DESCRIPTION OF DRAWINGS

[0025] Figure 1 is a flowchart of the embodiment card number generation, printing and verification method; Figure 2 is a structural diagram of the embodiment card number generation, printing and verification device. DETAILED DESCRIPTION

[0026] The present application provides a card number generation, printing and verification method, device, terminal and storage medium, in order to make the purpose, technical solution and advantages of the present application more clear, the following will be further detailed description of the embodiment of the present application.

[0027] The present application mainly adopts the card code dynamic generation and verification based on the hardware security module, which achieves the effect of improving the security of card code and product quality, and avoiding information leakage, the following is a further detailed description of the present application.

[0028] A card number generation, printing and verification method of the present application comprises the steps of data reading, card number generation, card code generation, card code printing, card code verification and card code deletion.

[0029] The steps are sequentially and orderly performed, the seed code and the enterprise code are read from the hardware security module first, the hardware security module integrates a true random number generator, an encryption engine and a special arithmetic logic unit (ALU) and the like.

[0030] Then, the card number and the card secret are generated according to the above information, the card secret is sprayed on the card, and then the card is identified by OCR and compared with the generated card secret. If the comparison is consistent, the card secret is overwritten and deleted, thereby avoiding the security risks of traditional database storage of card secret, significantly improving the security of card secret, ensuring the accuracy of each product card secret, improving product quality, and reducing subsequent processing costs. The reason is that the card secret is dynamically generated and verified and cleared in real time, and the card secret is verified twice.

[0031] The embodiments of the card secret generation, spraying and verification method of the present application are described in further detail below in conjunction with the drawings of the specification.

[0032] The card secret generation, spraying and verification method of the present application has a process as shown in Figure 1 The method is based on a hardware security module and includes the following steps: S1, read the enterprise code and the seed code corresponding to the enterprise code from the hardware security module, and each enterprise has a unique enterprise code.

[0033] Specifically, in the above data reading step, the hardware security module is a key component for storing card numbers and enterprise codes.

[0034] The hardware security module can use a chip with high security, such as an encryption chip, which has the feature of strong encryption function and can prevent data from being illegally acquired. It is connected with external devices through a specific interface to ensure the security of data transmission. When reading the card number and the enterprise code, the hardware security module will accurately read the data from its storage area according to the preset rules, and the enterprise code of each enterprise is unique, which ensures the accuracy and pertinence of the data.

[0035] S2, based on the hardware security module, generate a card number according to the enterprise code, the seed code and a preset card number generation algorithm, specifically including the following steps: S21, read the enterprise code and the corresponding seed code from the encryption storage area of the hardware security module, and generate a 4-bit random factor through the true random number generator built-in the hardware security module.

[0036] The true random number generator can use a random number generator based on physical phenomena, such as a random number generator based on quantum effects, which has the feature of generating truly random numbers to ensure the randomness of the random factor.

[0037] The enterprise code is 6 digits, and the seed code is 8 digits, and the seed code is unique in the current enterprise.

[0038] S22, convert the random factor into a first intermediate value through a hardware adder, a hardware multiplier and a modulo operation circuit, the first intermediate value being 2 bits.

[0039] In the embodiment, specifically, 4 bits of the random factor are converted into 2 bits, first, the first and last bits of the random factor are added, the result is taken modulo 10 to obtain the first bit of the first intermediate value; then, the middle 2 bits of the random factor are multiplied, the result is taken modulo 10 to obtain the last bit of the first intermediate value.

[0040] The hardware adder and the multiplier are basic operation units in integrated circuits, which can quickly and accurately perform addition and multiplication operations. The modulo operation circuit is used to perform the modulo operation.

[0041] For ease of understanding, the generation process of the first intermediate value is described below by taking a specific method as an example.

[0042] For example, after generating a 4-bit random factor, first, the first bit and the fourth bit of the random factor are extracted. The two numbers are stored in the register of the chip in binary form, and are added through the adder circuit inside the chip. The result of the addition is also temporarily stored in the register in binary form, and then the result is taken modulo 10. The modulo operation is realized through a specific hardware logic circuit. According to the characteristics of binary numbers, the hardware logic circuit quickly calculates the remainder after taking modulo 10, and this remainder is the first bit of the converted 2-bit first intermediate value. For example, if the random factor is 1234, the binary numbers corresponding to 1 and 4 are added in the adder, and the binary result is stored after passing through the modulo circuit.

[0043] Next, the second bit and the third bit of the random factor are extracted and stored in the register, and the multiplication operation is performed by using the multiplier circuit inside the chip. The binary result of the multiplication is stored in the register for the next step, and the modulo hardware logic circuit is also used to take modulo 10 of the multiplication result, and the remainder obtained is the last bit of the converted 2-bit first intermediate value. Taking the random factor 1234 as an example, the binary numbers corresponding to 2 and 3 are multiplied in the multiplier, and the binary product is obtained after passing through the modulo circuit, which corresponds to the binary representation of the last bit 6.

[0044] The intermediate data of the above operation process is only temporarily stored in the hardware register, and is automatically cleared after the operation is completed.

[0045] In this way, the simplified 2-bit random factor speeds up the data processing speed and improves the system operation efficiency without reducing the security, and the algorithm is combined with the hardware to realize fast operation by using the characteristics of the hardware, so that the process is more difficult to be cracked and the data security is enhanced.

[0046] S23, judging the parity of the enterprise code through the parity detection circuit, selecting the corresponding second intermediate value combination path according to the parity using the multiplexer, combining the first intermediate value and the enterprise code to generate the second intermediate value, and the second intermediate value is 8 bits.

[0047] The parity detection circuit can be realized by a logic circuit, which can judge the parity of the enterprise code according to the binary representation of the enterprise code. The multiplexer is a circuit that can select different input signals according to the control signal, which ensures the correct generation of the second intermediate value.

[0048] In the embodiment, the process of generating the second intermediate value is specifically that if the enterprise code is odd, the 2-bit first intermediate value is combined into an 8-bit second intermediate value through the multiplexer in the order of "first intermediate value first bit + enterprise code last 3 bits + first intermediate value last bit + enterprise code first 3 bits"; If the enterprise code is even, the 2-bit first intermediate value is combined into an 8-bit second intermediate value through the multiplexer in the order of "enterprise code first 3 bits + first intermediate value first bit + enterprise code last 3 bits + first intermediate value last bit"; The combination process is controlled by a hardware timing circuit, and the combination result is stored in a security register of the HSM.

[0049] S24, obtaining the first check code according to the shift register and the second intermediate value, and obtaining the second check code according to the enterprise code and the seed code; the shift register can perform shift operation on the data, and the first check code is obtained through the shift operation and the corresponding operation.

[0050] In the embodiment, the process of generating the first check code is specifically that the second intermediate value is shifted left bit by bit through the shift register, the sum of the shift results is calculated using a hardware accumulator, and the result is taken modulo 100 through a modulo operation circuit.

[0051] That is, each bit of the 8-bit second intermediate value and the corresponding bit index (1-8) performs a left shift operation through the shift register, the shift result is not input into the accumulator for summation, the summation result is taken modulo 100, and the 2-bit first check code is generated; if the result is 0, the backup summation circuit is started to add each bit of the 8-bit second intermediate value, and the addition result is taken modulo 10 to obtain a 1-bit number combined with 0 to form a 2-bit first check code.

[0052] In the embodiment, the process of generating the second check code is specifically that the 6-bit enterprise code and the 8-bit seed code are subjected to an exclusive-OR operation through a hardware exclusive-OR gate array, the exclusive-OR result is valued against 100, and a 2-bit second check code is generated; if the result is 0, the 4th bit of the seed code is combined with 0 as the second check code. The first check code and the second check code are combined into a 4-bit coupon check code checkCode through a hardware splicing circuit. The generated check code is stored in a secure FIFO queue of the HSM.

[0053] S25, in combination with the enterprise code, the seed code, the random factor, the first check code and the second check code, a card number is generated according to a preset encoding combination rule and stored in the hardware security module.

[0054] Specifically, the enterprise code and the seed code are read from the secure storage area, and the first check code and the second check code are read from the FIFO queue. In the embodiment, a 20-bit card number is generated through a hardware data splicing circuit according to the following encoding combination rule: enterprise code (6 bits) + second check code in reverse order (2 bits) + last 4 bits of seed code (4 bits) + first check code in normal order (2 bits) + first 4 bits of seed code (4 bits) + first and last two bits of random factor (2 bits).

[0055] Each enterprise can have different card number generation algorithms, and the above is only an example of one of them. In this process, MD5 and other asymmetric algorithms can also be added to participate in the generation of 4-bit coupon verification codes.

[0056] The encoding check algorithm is actually the same as the encoding production algorithm. According to the structure of the 20-bit encoding, the corresponding enterprise code, seed code, and check code are parsed, combined with the random factor when the enterprise code is generated, and then the check code is calculated according to the encoding production process. If the results are consistent, the encoding is valid, otherwise it is invalid. The above encoding check process belongs to the check process when the user uses the coupon and decrypts through the card password. This will not be described here.

[0057] S3, after generating the card number, a card number verification step is further included.

[0058] S31, a preset card number check algorithm is called to verify the card number read from the hardware security module. The card number check algorithm is bound to the card number generation algorithm, that is, the card number check algorithm is essentially the same as the card number generation algorithm corresponding to it.

[0059] S32, when the card number to be checked read from the hardware security module is input into the card number check algorithm, the algorithm will perform a series of operation verifications.

[0060] The verification process includes identifying the coding structure of the card number by a pattern matching circuit of the hardware security module, the pattern matching circuit can be implemented by a state machine circuit, which can accurately identify each component of the card number.

[0061] According to the coding structure, the generated card number is parsed to obtain the parsed enterprise code, seed code, first check code and second check code.

[0062] S33, obtain the random factor for generating the current card number from the hardware security module, combine the parsed enterprise code and seed code, and generate the first verification code and the second verification code according to the card number generation algorithm.

[0063] S34, when the first verification code is the same as the parsed first check code and the second verification code is the same as the parsed second check code, it is determined that the generated card number is valid, otherwise it is determined that the card number is invalid, and the subsequent card secret generation process is terminated.

[0064] This step is to determine whether the card number belongs to the valid card number generated by the algorithm authorized by the enterprise. When generating a batch of cards, the card number generation algorithm required for the batch of cards is specified and authorized, and only the card number that meets the requirements of the authorized card number generation algorithm is valid. The purpose is to ensure that only such generated card numbers can be used for card production in the current card production process, and not any card number can generate card secret. It is also to ensure the accuracy and security of the whole process.

[0065] S4, generate the card secret corresponding to the card number according to the preset card secret generation algorithm, specifically including the following steps: S41, identify the coding structure of the card number by the pattern matching circuit of the hardware security module, and store the identified coding structure into the corresponding security register. The security register is a storage unit with high security, which can prevent data loss and illegal tampering.

[0066] The coding structure includes enterprise code, seed code and card coupon check code, and the card coupon check code is generated according to the first check code and the second check code.

[0067] S42, sum the card number by the hardware accumulator, and obtain the first password check code (msk-a1) of 1 bit by combining the modulo operation circuit.

[0068] Specifically, the hardware accumulator is used to add the 20-bit card number bit by bit, and the addition result is taken modulo 10 by the modulo operation circuit to obtain the first password check code of 1 bit. The result is stored in the temporary register of the HSM.

[0069] S43, second password check code generation: through the XOR gate array, XOR operation is performed according to the seed code and the card coupon check code, and the obtained result is combined with the preset first password combination rule to generate a 2-bit second password check code (msk-b2).

[0070] In this embodiment, the first password combination rule is that the adjacent bits of the seed code are summed from left to right through the hardware adder, XOR operation is performed with the card coupon check code through the XOR gate array, and a 2-bit second password check code (msk-b2) is generated through the accumulator and the modulo operation circuit.

[0071] The specific process is that the 8-bit seed code is added from left to right through the addition array, the 4-bit card coupon check code is XORed from left to right through the XOR array, and the sum and the XOR result are added through the accumulator. The result is output as a 2-bit second password check code (msk-b2) through the modulo 100 circuit, and if the result is 0, the last digit of the enterprise code and 0 are taken to form a 2-bit second password check code (msk-b2).

[0072] S44, third password check code generation: through the bit shift register, the enterprise code, the second password check code and the card coupon check code are executed bit shift operation, combined with the modulo operation circuit and the preset second password combination rule to generate a 3-bit third password check code.

[0073] In this embodiment, the second password combination rule is that the enterprise code and the combination of the "second password check code + card coupon check code" are executed left shift operation through the shift register, and the result is output as a 3-bit third password check code (msk-c3) through the accumulator and the modulo 1000 circuit. If the result is a 1-digit number, it is completed through the data selector by referring to the specific bit of the enterprise code and the seed code.

[0074] The specific process is that the 6-bit enterprise code is left shifted from left to right with each bit of the combination of "2-bit msk-b2 and 4-bit checkCode", and the result is added and taken modulo 1000. If the result is a 1-digit number, the middle bit (2nd) of the enterprise code and the middle bit (4th) of the seed code are referred to in the first two bits of the result, respectively, to obtain a 3-bit third password check code msk-c3; finally, a 6-bit card password is obtained.

[0075] S45, the first password check code, the second password check code and the third password check code are combined in a predetermined order through the hardware splicing circuit to obtain the card password. The hardware splicing circuit can accurately splice different password check codes together.

[0076] In this embodiment, the splicing order of the card key is (msk-c3) + (msk-a1) + (msk-b2), a total of 6 bits. The card key and the corresponding card number are transmitted to the encryption buffer of the printing equipment through the hardware encryption interface. Among them, the hardware encryption interface ensures the security of data transmission, and the encryption buffer temporarily stores the data.

[0077] S5, printing the generated card key on the card key area of the card number corresponding card through the printing equipment.

[0078] Specifically, through the printing equipment connected with the hardware security module, the card key and the card number transmitted by the hardware security module are received, and the card key is printed on the card corresponding to the card number according to the preset printing format, specifically, the card key area of the card.

[0079] The printing equipment can adopt an inkjet printer or a laser printer, which has the construction feature of accurately printing the card key on the specified position. It obtains the card key and card number information through data interaction with the hardware security module, and prints according to the preset format.

[0080] S6, obtaining the card key recognition result by performing OCR identification on the card, and comparing the card key recognition result with the card key, specifically including the following steps.

[0081] S61, after printing, the image data is obtained by image acquisition of the card through the camera equipment. The camera equipment can adopt a high-definition camera, which can clearly collect the image information on the card.

[0082] S62, character segmentation is performed on the image data, and the card key recognition result of the card is obtained by using the OCR recognition engine for character recognition. The card key recognition result includes the card number and the card key identified. The OCR recognition engine adopts an advanced optical character recognition algorithm, which can accurately identify the characters in the image.

[0083] S63, the card number and the card key of the card key recognition result are compared with the card number and the card key received from the hardware security module through the security comparator of the hardware security module, and the comparison result is obtained. Among them, the security comparator is a circuit that can accurately compare whether two data are consistent.

[0084] S6, if the comparison result is consistent, the card key area is covered and the card key is deleted.

[0085] When the comparison result is completely consistent, the comparison passes, triggering the area full coverage command to physically cover the card key area, at the same time, the hardware security module executes the register erasing instruction to delete the temporarily stored card key. Physical covering can adopt coating and other ways to ensure that the card key cannot be read again. The register erasing instruction can completely clear the temporarily stored card key in the hardware security module, preventing information leakage.

[0086] If the comparison result is inconsistent, the system will start the alarm mechanism, and the error or problem card will be sent to the waste processing flow.

[0087] The embodiment realizes dynamic generation, instant verification and instant deletion of card numbers and card codes by integrating a series of hardware modules and algorithms on a card production line. The security risks of traditional database storage of card codes are avoided, and the security of card codes is improved. At the same time, through secondary verification, it is ensured that each product card code is accurate, the product quality is improved, and the subsequent processing cost is reduced. And according to the actual demand, the production line can be flexibly configured, and the production efficiency is improved.

[0088] Based on the same inventive concept, the embodiment of the application also discloses a card code generation, printing and verification device, which has the architecture as shown in Figure 2 The device comprises the following modules: The data reading module is configured to read the enterprise code and the seed code corresponding to the enterprise code from the hardware security module, and each enterprise has a unique enterprise code; The card code generation module is configured to generate a card number based on the hardware security module, according to the enterprise code, the seed code and a preset card number generation algorithm, and generate a card code corresponding to the card number in combination with the card number and a preset card code generation algorithm; The card code printing module is configured to print the generated card code in the card code area of the card corresponding to the card number; The card code verification module is configured to obtain a card code recognition result by performing OCR identification on the card, and compare the card code recognition result with the card code; The card code deletion module is configured to, if the comparison result is consistent, cover the card code area and delete the card code.

[0089] In a specific implementable scheme, the following modules are further included: The card number verification module is configured to call a preset card number verification algorithm to verify the card number read from the hardware security module, the card number verification algorithm is bound with the card number generation algorithm, and the verification process comprises: identifying the coding structure of the card number by the pattern matching circuit of the hardware security module, analyzing the generated card number according to the coding structure to obtain the analyzed enterprise code, seed code, first verification code and second verification code; Obtaining a random factor for generating the current card number, combining the analyzed enterprise code and seed code, generating the first verification code and the second verification code according to the card number generation algorithm, when the first verification code is the same as the analyzed first verification code and the second verification code is the same as the analyzed second verification code, it is determined that the generated card number is valid, otherwise it is determined that the card number is invalid, and the subsequent card code generation process is terminated.

[0090] In a specific implementable scheme, the card code generation module comprises the following units: The card number generation unit is configured to read the enterprise code and the corresponding seed code from the encrypted storage area of the hardware security module, generate a 4-bit random factor through a true random number generator built in the hardware security module, the enterprise code is a 6-digit pure number, and the seed code is an 8-digit pure number, and the seed code is unique in the current enterprise; The random factor is converted into a first intermediate value through a hardware adder, a hardware multiplier, and a modulo operation circuit, the first intermediate value is 2 bits; the parity of the enterprise code is judged through a parity detection circuit, a multiplexer is used to select a corresponding second intermediate value combination path according to the parity, and a second intermediate value is generated in combination with the first intermediate value and the enterprise code, the second intermediate value is 8 bits; A first check code is obtained according to the shift register and the second intermediate value, and a second check code is obtained according to the enterprise code and the seed code; In order to combine the enterprise code, the seed code, the random factor, the first check code, and the second check code, the card number is generated according to a preset encoding combination rule and stored in the hardware security module.

[0091] The card number generation unit is configured to read the enterprise code and the corresponding seed code from the encrypted storage area of the hardware security module, generate a 4-bit random factor through a true random number generator built in the hardware security module, the enterprise code is a 6-digit pure number, and the seed code is an 8-digit pure number, and the seed code is unique in the current enterprise; The card number is summed through a hardware accumulator, and a 1-bit first password check code is obtained in combination with a modulo operation circuit; An exclusive OR gate array is used to perform exclusive OR operation according to the seed code and the coupon check code, and a 2-bit second password check code is generated in combination with a modulo operation circuit and a preset first password combination rule; A shift register is used to perform a shift operation on the enterprise code, the second password check code, and the coupon check code, and a 3-bit third password check code is generated in combination with a modulo operation circuit and a preset second password combination rule; The first password check code, the second password check code, and the third password check code are combined in a preset order through a hardware splicing circuit to obtain a card secret, and the card secret and the corresponding card number are transmitted to the encryption buffer area of the printing device through a hardware encryption interface.

[0092] In one specific implementation, the card secret printing module includes the following units: The card secret printing unit is configured to receive the card secret and the card number transmitted by the hardware security module through a printing device connected with the hardware security module, and print the card secret on the card corresponding to the card number according to a preset printing format, specifically in a preset card secret area on the card.

[0093] In one specific implementation, the card secret verification module includes the following units: The card number verification unit is configured to capture an image of the card after the printing is completed by using a camera to obtain image data, perform character segmentation on the image data, and use an OCR recognition engine to recognize characters to obtain a card number recognition result of the card, which includes a recognized card number and card number. The card number and card number of the card number recognition result are compared with the card number and card number received from the hardware security module by using a security comparator of the hardware security module to obtain a comparison result.

[0094] In a specific implementation, the card number deletion module includes the following units: The card number deletion unit is configured to trigger a region full coverage command to physically cover the card number region when the comparison result is completely consistent, and at the same time, the hardware security module executes a register erasing instruction to delete the temporarily stored card number.

[0095] In the above device, the card number verification module and the card number generation module are in communication.

[0096] Based on the same inventive concept, the embodiments of the present application also disclose a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set. The at least one instruction, at least one program, code set or instruction set can be loaded and executed by a processor to implement the card number generation, printing and verification method provided by the above method embodiments.

[0097] Also based on the same inventive concept, the embodiments of the present application also disclose a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set. The at least one instruction, at least one program, code set or instruction set can be loaded and executed by a processor to implement the card number generation, printing and verification method provided by the above method embodiments.

[0098] Those skilled in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or by a program instructing related hardware to complete. The program can be stored in a computer readable storage medium, which includes, for example, a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0099] The above is only an optional embodiment of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for card key generation, printing and verification, characterized in that, The method is based on a hardware security module, and the method comprises the following steps: reading an enterprise code and a seed code corresponding to the enterprise code from the hardware security module, and each enterprise having a unique enterprise code; generating a card number based on the hardware security module, the enterprise code, the seed code, and a preset card number generation algorithm, and generating a card password corresponding to the card number in combination with the card number and a preset card password generation algorithm; spraying the generated card password on the card password area of the card corresponding to the card number through a spraying device; performing OCR identification on the card to obtain a card password identification result, comparing the card password identification result with the card password, and obtaining a comparison result; if the comparison result is consistent, covering the card password area and deleting the card password.

2. The card key generation, printing and verification method of claim 1, wherein, The card number is generated based on the enterprise code, the seed code, and a preset card number generation algorithm, and specifically comprises the following steps: reading the enterprise code and the corresponding seed code from the encrypted storage area of the hardware security module, generating a 4-bit random factor through a true random number generator built in the hardware security module, the enterprise code being a 6-digit pure number, the seed code being an 8-digit pure number, and the seed code being unique in the current enterprise; converting the random factor into a first intermediate value through a hardware adder, a hardware multiplier, and a modulo operation circuit, the first intermediate value being 2 bits; judging the parity of the enterprise code through a parity detection circuit, selecting a corresponding second intermediate value combination path through a multiplexer according to the parity, and generating a second intermediate value in combination with the first intermediate value and the enterprise code, the second intermediate value being 8 bits; obtaining a first check code according to a bit shift register and the second intermediate value, and obtaining a second check code according to the enterprise code and the seed code; generating a card number according to a preset encoding combination rule in combination with the enterprise code, the seed code, the random factor, the first check code, and the second check code, and storing the card number in the hardware security module.

3. The card key generation, printing and verification method of claim 2, wherein, After the card number is generated, the following steps are further included: calling a preset card number verification algorithm to verify the card number read from the hardware security module, the card number verification algorithm being bound with the card number generation algorithm, the verification process comprising identifying the encoding structure of the card number through a pattern matching circuit of the hardware security module, analyzing the generated card number according to the encoding structure to obtain an analyzed enterprise code, seed code, first check code, and second check code; obtaining the random factor for generating the current card number, combining the analyzed enterprise code and seed code, and generating a first verification code and a second verification code according to the card number generation algorithm, and when the first verification code is the same as the analyzed first check code and the second verification code is the same as the analyzed second check code, it is determined that the generated card number is valid, otherwise it is determined that the card number is invalid, and the subsequent card password generation process is terminated.

4. The card key generation, printing and verification method of claim 2, wherein, The card password corresponding to the card number is generated in combination with the card number and a preset card password generation algorithm, and specifically comprises the following steps: The mode matching circuit of the hardware security module identifies the coding structure of the card number, and stores the identified coding structure into a corresponding security register. The coding structure includes the enterprise code, the seed code, and a coupon verification code generated according to the first verification code and the second verification code; The hardware accumulator is used to sum the card number, and a 1-bit first password verification code is obtained through a modulo operation circuit; An XOR gate array is used to perform an XOR operation on the seed code and the coupon verification code, and a 2-bit second password verification code is generated through a modulo operation circuit and a preset first password combination rule; A bit shift register is used to perform a bit shift operation on the enterprise code, the second password verification code, and the coupon verification code, and a 3-bit third password verification code is generated through a modulo operation circuit and a preset second password combination rule; A hardware splicing circuit is used to combine the first password verification code, the second password verification code, and the third password verification code in a preset order to obtain a card secret, and the card secret and the corresponding card number are transmitted to the encryption buffer of the printing device through a hardware encryption interface.

5. The card key generation, printing and verification method of claim 1, wherein, The printing device connected to the hardware security module receives the card secret and the card number transmitted by the hardware security module, and prints the card secret on the card coupon corresponding to the card number according to a preset printing format. Specifically, the card secret is printed on the card secret area of the card coupon.

6. The card key generation, printing and verification method of claim 1, wherein, The card secret is identified through OCR recognition of the card coupon, and the card secret recognition result is compared with the card secret to obtain a comparison result. Specifically, the following steps are included: After printing, the image data is obtained by image acquisition of the card coupon through a camera device, character segmentation is performed on the image data, character recognition is performed using an OCR recognition engine to obtain the card secret recognition result of the card coupon, the card secret recognition result includes the recognized card number and card secret, and the card number and card secret of the card secret recognition result are compared with the card number and card secret received from the hardware security module through a security comparator of the hardware security module to obtain a comparison result.

7. The card key generation, printing and verification method of claim 1, wherein, When the comparison result is completely consistent, the comparison passes, a region full coverage command is triggered to physically cover the card secret area, a register erasing instruction is executed by the hardware security module, and the temporarily stored card secret is deleted.

8. A card key generation, printing and verification apparatus, characterized by, The following modules are included: A data reading module configured to read an enterprise code and a seed code corresponding to the enterprise code from a hardware security module. Each enterprise has a unique enterprise code. A card secret generation module configured to generate a card number based on the hardware security module according to the enterprise code, the seed code, and a preset card number generation algorithm, and generate a card secret corresponding to the card number based on the card number and a preset card secret generation algorithm. A card secret printing module for printing the generated card secret on the card secret area of the card coupon corresponding to the card number. A card secret verification module configured to perform OCR recognition on the card coupon to obtain a card secret recognition result, compare the card secret recognition result with the card secret, and obtain a comparison result. A card number deleting module configured to cover and delete the card number region if the comparison result is consistent.

9. A smart terminal, characterized in that A computer readable storage medium storing at least one instruction, at least one program, a code set or an instruction set, which are loaded and executed by a processor to implement the card number generating, printing and verifying method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A computer readable storage medium storing at least one instruction, at least one program, a code set or an instruction set, which are loaded and executed by a processor to implement the card number generating, printing and verifying method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Two-dimensional code dynamic encryption and decryption algorithm

    CN105426765A

  • System, Apparatus And Method For Providing Randomly Generated Codes In A User Anonymous Manner

    CN107636713A

  • Random key and card number generation method and device

    CN114024665A

  • Cloud key management method and system based on intelligent IC card security authentication

    CN114172649A

  • Password printing system and method

    CN114553406A

Cited By

  • Dynamic verification and redemption methods and systems for coupons and cards

    CN122415160A