Secret key management method of IC card terminal
A technology of key management and terminal management system, which is applied in the direction of code identification card or credit card start-up, electrical components, transmission system, etc., which can solve the problems of unfavorable networking and high cost of update and maintenance, so as to improve versatility and reduce Maintenance update cost, effect of improving security
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2012-07-04
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the field of network information security certification, in particular to a key management method of an IC card terminal. Background technique
[0002] At present, the IC card system used for micropayment generally adopts off-line processing. In the IC card consumption terminal, the PSAM card is used to complete the security authentication of the IC card offline consumption transaction, and in the IC card recharge terminal, the ISAM card is used to complete the security authentication of the IC card offline recharge transaction, that is, the IC card recharge The key is held in the ISAM card.
[0003] IC card recharge means to increase the amount data in the IC card, and to modify this data, two-way authentication must be passed first. Two-way authentication is that the IC card generates a random number, combined with other key information to form a data packet, uses the key in the IC card to encrypt and calculate a result, an...
Examples
specific Embodiment approach
[0021] refer to figure 2 , is a flowchart of an embodiment of the present invention, specifically including the following steps:
[0022] Step 201: The terminal device reads the public information of the IC card and transmits it to the terminal management system host in an encrypted manner, hereinafter referred to as the management host.
[0023] The encrypted data transmitted between the terminal equipment and the management host in the present invention uses different process keys each time. The specific method is: for each transaction, the built-in security module of the terminal device generates a random number and a transaction sequence number to form a process factor, and uses the public key A agreed with the management host to disperse the process factor to generate a process key, and uses the process key Encrypt the transmission information to obtain the information ciphertext, and then use the public key B agreed with the management host to encrypt the process facto...