A social security card PIN reset method and system based on a standard interface and a medium

By adopting a social security card PIN reset method based on a standard interface, the limitations of the social security card data processing module are solved, a unified interface call is achieved, more comprehensive data processing needs are met, and the efficiency and universality of social security card information reading and PIN reset are improved.

CN114239006BActive Publication Date: 2026-04-14INSPUR FINANCIAL INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-22
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing social security card data processing methods can only use designated social security card data processing modules and special calling interfaces in the corresponding regions, which is quite limited and cannot meet the more comprehensive requirements for social security card data processing.

Method used

This paper provides a method for resetting the PIN of a social security card based on a standard interface. By configuring an encryption module, a first standard interface and a block encryption algorithm, setting data character positions, and performing information verification and identification code reset operations, the method utilizes the encryption module and standard interface to realize information reading, authentication and PIN reset, reducing the dependence on special interfaces.

Benefits of technology

It has implemented a unified standard interface for social security card data processing modules, reducing redundant development and enabling quick information reading, dual authentication, and PIN reset. This meets more comprehensive social security card data processing requirements and has high universality and application value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114239006B_ABST
    Figure CN114239006B_ABST
Patent Text Reader

Abstract

The application discloses a social security card PIN resetting method and system based on a standard interface and a medium, and the method comprises the following steps: configuring an encryption module, a first standard interface and a group encryption algorithm; setting data character bits; detecting a social security card PIN resetting requirement, performing an information reading operation based on the encryption module, the first standard interface, the data character bits and the social security card PIN resetting requirement, and obtaining resetting authentication information; and performing a PIN resetting operation based on the encryption module, the first standard interface, the group encryption algorithm, the data character bits and the resetting authentication information; the application can realize the unified standard interface of the social security card data processing module and calling, and the social security card information reading, information double authentication and PIN resetting can be realized without repeated development or repeated design of the port of the social security card data processing module, so that the more comprehensive social security card data processing requirements can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of social security card communication technology, and in particular to a method, system and medium for resetting the PIN of a social security card based on a standard interface. Background Technology

[0002] The existing social security card data processing methods specify different social security card data processing modules and developers for different social security application areas, and ultimately use different interface call methods to realize the data processing of social security cards within the region. This method has too much interface dependency, and can only use the specified social security card data processing modules and special call interfaces in the corresponding regions, which has great limitations and cannot meet the more comprehensive social security card data processing requirements. Summary of the Invention

[0003] The present invention mainly addresses the problem that existing social security card data processing methods can only use designated social security card data processing modules and special calling interfaces in certain regions, which has significant limitations and cannot meet the more comprehensive requirements for social security card data processing.

[0004] To solve the above-mentioned technical problems, one technical solution adopted by the present invention is to provide a social security card PIN reset method based on a standard interface, comprising the following steps:

[0005] Initial configuration steps:

[0006] Configure the encryption module, the first standard interface, and the block cipher algorithm; set the data character bits;

[0007] Information verification steps:

[0008] The system detects a social security card PIN reset request and performs an information reading operation based on the encryption module, the first standard interface, the data character bits, and the social security card PIN reset request to obtain reset authentication information.

[0009] Identification code reset steps:

[0010] A PIN reset operation is performed based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information.

[0011] As an improved solution, the encryption module is provided with a second standard interface, which includes: a data comparison interface, a data integration interface, a low-level authentication interface, and a PIN reset interface;

[0012] The first standard interface includes: a status query interface, a power-on interface, and an information reading interface;

[0013] The block encryption algorithm includes: a first algorithm and a second algorithm; the first algorithm is the DES algorithm; the second algorithm is either the SSF33 algorithm or the SM4 algorithm;

[0014] The data character positions include: a first character position and a second character position;

[0015] The social security card PIN reset requirement includes: a first requirement and a second requirement; the first requirement is that a first social security card exists and the PIN needs to be reset; the second requirement is that a first social security card does not exist and the PIN does not need to be reset.

[0016] As an improved solution, the step of performing an information reading operation based on the encryption module, the first standard interface, the data character bits, and the social security card PIN reset requirement to obtain reset authentication information further includes:

[0017] The system identifies the social security card PIN reset requirement. If the social security card PIN reset requirement is the first requirement, the system calls the status query interface to query the first status of the social security card recognition hardware on the terminal device. If the first status is that the social security card recognition hardware is normal, the system performs the information reading operation.

[0018] The information reading operation includes: first, calling the power-on interface to power on the first social security card; then controlling the social security card recognition hardware to call the information reading interface to read the basic authentication information of the first social security card; and performing information authentication steps based on the encryption module and the basic authentication information to obtain the reset authentication information.

[0019] As an improved solution, the basic authentication information includes: algorithm identifier, card identification code, first authentication factor, first authentication original information, and first authentication key address;

[0020] The information authentication steps include:

[0021] Set the identification code format parameters, call the encryption module to identify the first format parameters of the card identification code; control the encryption module to call the data comparison interface to compare whether the identification code format parameters match the first format parameters; if they match, control the encryption module to call the data integration interface to integrate the algorithm identifier, the first authentication factor, the first authentication original information and the first authentication key address to obtain the reset authentication information.

[0022] As an improved solution, the PIN reset operation includes:

[0023] Configure the key logic matching database, and perform underlying authentication steps based on the encryption module, the reset authentication information, and the key logic matching database to obtain the underlying authentication result;

[0024] Configure the social security card management terminal address database, and perform the first reset step based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, the reset authentication information, the key logic matching database, the underlying authentication result, and the social security card management terminal address database.

[0025] As an improved solution, the key logic matching database is configured with several authentication key addresses, several message calculation key addresses, several key calculation logics that match the several message calculation key addresses respectively, several key generation logics that match the several authentication key addresses respectively, and several key encryption logics.

[0026] The underlying authentication steps include:

[0027] The encryption module is invoked to extract the first authentication factor, the first authentication key address, and the first authentication key address from the reset authentication information;

[0028] The encryption module is invoked to identify the first key generation logic and the first key encryption logic that match the first authentication key address in the key logic matching database; the encryption module is then invoked to generate a second authentication factor based on the first key generation logic;

[0029] The encryption module is invoked to encrypt the first authentication original information according to the first key encryption logic and based on the second authentication factor to obtain the first encrypted authentication information; the encryption module is invoked to encrypt the first authentication original information according to the first key encryption logic and based on the first authentication factor to obtain the second encrypted authentication information.

[0030] The encryption module is controlled to call the underlying authentication interface to compare whether the first encrypted authentication information and the second encrypted authentication information match; if they match, the underlying authentication result is set as authentication successful; if they do not match, the underlying authentication result is set as authentication failed.

[0031] As an improved solution, the social security card management terminal address database is configured with several identification codes and several MAC addresses corresponding to the identification codes respectively;

[0032] The first reset step includes:

[0033] When the underlying authentication result is successful, the encryption module is invoked to extract the algorithm identifier and the card identification code from the reset authentication information; the information reading interface is invoked to read the security message calculation key address, security message calculation process factor, APDU command header and APDU command plaintext data of the first social security card;

[0034] The encryption module is invoked to identify the first key calculation logic that matches the address of the security message calculation key in the key logic matching database; the encryption module is then invoked to calculate the security message calculation process factor according to the first key calculation logic to obtain the calculated encrypted data;

[0035] The encryption module is invoked to identify the first MAC address that matches the card identification code in the address database of the social security card management terminal;

[0036] The encryption module is controlled to call the PIN reset interface to identify the algorithm identifier;

[0037] If the algorithm identifier is the first identifier, then the encryption module is invoked to use the first algorithm to concatenate and encrypt the APDU command header, the first MAC address and the calculated encryption data according to the first character position to obtain the first secure message;

[0038] If the algorithm identifier is the second identifier, then the encryption module is invoked to use the second algorithm to concatenate and encrypt the APDU command header, the first MAC address and the calculated encryption data according to the second character position to obtain the second secure message;

[0039] The encryption module is controlled to call the PIN reset interface to set the APDU command plaintext data to a new PIN code, and the encryption module is controlled to call the PIN reset interface to send the new PIN code and the first security message to the first MAC address, or the encryption module is controlled to call the PIN reset interface to send the new PIN code and the second security message to the first MAC address.

[0040] As an improved solution, the social security card PIN reset method based on a standard interface further includes:

[0041] Obtain the interface standard document, and when calling the first standard interface or the second standard interface, encapsulate the first standard interface or the second standard interface based on the interface standard document;

[0042] The interface standard document is Document No. 38 issued by the Ministry of Human Resources and Social Security; the first standard interface is designed and implemented based on the WOSA standard interface.

[0043] This invention also provides a social security card PIN reset system based on a standard interface, comprising:

[0044] Initial configuration module, information reading module, and identification code reset module;

[0045] The initial configuration module is used to configure the encryption module, the first standard interface, and the block cipher algorithm; the initial configuration module is also used to set the data character bits;

[0046] The information reading module is used to detect the social security card PIN reset requirement, and performs an information reading operation based on the encryption module, the first standard interface, the data character bits and the social security card PIN reset requirement to obtain reset authentication information;

[0047] The identification code reset module is used to perform a PIN reset operation based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information.

[0048] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the social security card PIN reset method based on a standard interface.

[0049] The beneficial effects of this invention are:

[0050] 1. The social security card PIN reset method based on a standard interface described in this invention can realize the design and calling of a unified standard interface for the social security card data processing module. This eliminates the need for repeated development or design of ports for the social security card data processing module, and quickly realizes the reading of social security card information, dual authentication of information, and PIN reset, meeting more comprehensive social security card data processing requirements. Moreover, the entire development logic is ingenious. Based on the logic of this unified standard interface, more functional interfaces can be designed to realize different social security card data processing functions. It has strong universality, makes up for the shortcomings of the prior art, and has high application value.

[0051] 2. The social security card PIN reset system based on a standard interface described in this invention can achieve a unified standard interface for designing and calling the social security card data processing module through the cooperation of the initial configuration module, information reading module, and identification code reset module. This eliminates the need for repeated development or design of ports for the social security card data processing module, quickly realizing information reading, dual authentication, and PIN reset of the social security card, meeting more comprehensive social security card data processing requirements. Moreover, the entire development logic is ingenious. Based on the logic of this unified standard interface, more functional interfaces can be designed to realize different social security card data processing functions, which has strong universality, makes up for the shortcomings of the prior art, and has high application value.

[0052] 3. The computer-readable storage medium described in this invention enables the bootstrap initial configuration module, information reading module, and identification code reset module to work together, thereby realizing the design and calling of a unified standard interface for the social security card data processing module. This eliminates the need for repeated development or design of ports for the social security card data processing module, quickly realizing information reading, dual authentication, and PIN reset of the social security card, meeting more comprehensive social security card data processing requirements, and effectively improving the operability of the social security card PIN reset method based on the standard interface. Attached Figure Description

[0053] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0054] Figure 1 This is a flowchart of the social security card PIN reset method based on a standard interface as described in Embodiment 1 of the present invention;

[0055] Figure 2 This is a schematic diagram of the specific process of the social security card PIN reset method based on the standard interface described in Embodiment 1 of the present invention;

[0056] Figure 3 This is an architecture diagram of the social security card PIN reset system based on a standard interface as described in Embodiment 2 of the present invention. Detailed Implementation

[0057] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.

[0058] In the description of this invention, it should be noted that the embodiments described in this invention are only some embodiments of this invention, not all embodiments; based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0059] In the description of this invention, it should be noted that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0060] In the description of this invention, it should be noted that: PIN (Personal Identification Number) is an identification password; MAC (Media Access Control) is a media access control address; APDU (Application Protocol Data Unit) is an application protocol data unit; WOSA is an open system architecture.

[0061] Example 1

[0062] This embodiment provides a method for resetting a social security card PIN based on a standard interface, such as... Figure 1 and Figure 2 As shown, it includes the following steps:

[0063] S100, initial configuration steps, specifically including:

[0064] S110. Configure the encryption module, the first standard interface, and the block cipher algorithm; set the data character bits;

[0065] Specifically, the encryption module is equipped with a second standard interface, which includes, but is not limited to, a data comparison interface, a data integration interface, a low-level authentication interface, and a PIN reset interface. In this embodiment, the various functions of social security card data processing are mainly implemented based on the encryption module, the first standard interface, and the second standard interface, without the need to configure any special calling interfaces. All functions are implemented based on the interfaces configured in this method. Correspondingly, each interface in the second standard interface is an interface that can implement the corresponding function. For example, it also includes a PIN unlocking interface. It is conceivable that both the PIN unlocking interface and the PIN reset interface are used for PIN-related data processing, and the calling logic of the PIN unlocking interface and the PIN reset interface is similar. In this embodiment, the first standard interface and the second standard interface need to be called before they can be configured. The first and second standard interfaces are encapsulated according to the interface content defined in Document No. 38 of the Ministry of Human Resources and Social Security to meet the standard requirements. In this embodiment, the first standard interface is designed and implemented based on the WOSA standard interface, and includes: a status query interface, a power-on interface, and an information reading interface. The information reading interface is implemented based on the CHIPIO interface, and is mainly used for data interaction with the social security card. The block encryption algorithm includes: a first algorithm and a second algorithm. The first algorithm is the DES algorithm; the second algorithm is the SSF33 algorithm or the SM4 algorithm. The data character bits include: a first character bit and a second character bit. In this embodiment, the first character bit is 34 bits, the second character bit is 50 bits, and the data character bits represent the character length of the data. Step S100 provides the data foundation, hardware foundation, and architectural foundation for steps S200 and S300, and is an indispensable necessary step before the execution of steps S200 and S300. In this embodiment, this method is implemented based on the CEN-XFS architecture.

[0066] S200, Information Verification Steps, specifically include:

[0067] S210. Detect the social security card PIN reset requirement, and perform an information reading operation based on the encryption module, the first standard interface, the data character bits, and the social security card PIN reset requirement to obtain reset authentication information; In this embodiment, step S200 is mainly used to read social security card related information for verification to ensure the security of the social security card and the social security card data processing module, and at the same time complete the necessary authentication before social security card data processing, thereby activating the social security card and ensuring that subsequent steps can read the social security card;

[0068] Specifically, the social security card PIN reset requirement includes: a first requirement and a second requirement; the first requirement is that a first social security card exists and the PIN needs to be reset; the second requirement is that a first social security card does not exist and the PIN does not need to be reset.

[0069] Specifically, the social security card PIN reset request is identified. If the social security card PIN reset request is the first request, the status query interface is called to query the first status of the social security card recognition hardware on the terminal device. The first status includes, but is not limited to, power-on status and running status. The social security card recognition hardware is the card swiping area or contactless card reader on the terminal device. In this embodiment, the terminal device is a social security card terminal device, that is, a social security card data processing module. If the first status is that the social security card recognition hardware is normal, the effective execution of the following steps is further guaranteed, so the information reading operation is performed. In this embodiment, the first social security card is the social security card to be PIN reset.

[0070] The information reading operation includes: firstly, powering on the first social security card by calling the power-on interface; after the first social security card is powered on, the information in the first social security card can be read; then, controlling the social security card recognition hardware to call the information reading interface to read the basic authentication information of the first social security card; performing information authentication steps based on the encryption module and the basic authentication information to obtain the reset authentication information; the reset authentication information is used for subsequent underlying security authentication and random code authentication of the first social security card.

[0071] Specifically, the basic authentication information includes: algorithm identifier, card identification code, first authentication factor, first authentication original information, and first authentication key address; in this embodiment, the algorithm identifier is the identifier information of the encryption algorithm required by the subsequent message data of the first social security card; the card identification code is the identification code of the social security card; there are two copies of the first authentication factor, the first authentication original information, and the first authentication key address, one for internal authentication and one for external authentication. Additionally, the basic authentication information also includes: the administrative division code of the card-issuing region (usually the first 6 digits of the card identification code) and card reset information, etc.; in this embodiment, the first authentication factor and the first authentication original information are random character codes, and the generation of these random character codes is related to the first authentication key address, both being pre-set logical operations performed by the social security card itself after power-on identification;

[0072] The information authentication steps include:

[0073] The identification code format parameter is set, which is the length of the identification code or the character type at different positions. It is used to verify whether the card identification code of the first social security card is correct. If it is correct, it means that the relevant data processing operation can be performed through this social security card data processing module. Therefore, the encryption module is called to identify the first format parameter of the card identification code. The encryption module is controlled to call the data comparison interface to compare whether the identification code format parameter matches the first format parameter. That is, the data comparison function can be realized through the data comparison interface. The functional logic of the data comparison interface is designed and implemented based on the data comparison algorithm. If they match, the encryption module is controlled to call the data integration interface to integrate the algorithm identifier, the first authentication factor, the first authentication original information, and the first authentication key address to obtain the reset authentication information. If they do not match, an alarm is sent to the terminal device and the first social security card is powered off.

[0074] S300, identification code reset steps, specifically include:

[0075] S310. Perform a PIN reset operation based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information;

[0076] Specifically, the PIN reset operation includes:

[0077] A key logic matching database is configured, and underlying authentication steps are performed based on the encryption module, the reset authentication information, and the key logic matching database to obtain the underlying authentication result. Specifically, the key logic matching database is configured with several authentication key addresses, several message calculation key addresses, several key calculation logics that match the message calculation key addresses respectively, several key generation logics that match all of the authentication key addresses respectively, and several key encryption logics. In this embodiment, the authentication key addresses and message calculation key addresses are associated with the data encryption or verification logic contained in the social security card itself. It is conceivable that the several authentication key addresses and several message calculation key addresses correspond to the key addresses designed in different types of social security card chips. The key generation logic is used to generate encryption factors at the encryption module end, and the encryption factors are equivalent to the authentication factors. The key encryption logic is used to combine and encrypt the encryption factors and the original authentication information identified in the social security card chip to obtain relevant information for direct verification of the social security card. The key calculation logic is to calculate the message calculation process factors in the social security card chip to obtain relevant data for encrypting the social security card message data.

[0078] Configure the social security card management terminal address database, and perform a first reset step based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, the reset authentication information, the key logic matching database, the underlying authentication result, and the social security card management terminal address database. Specifically, the social security card management terminal address database is configured with several identification codes and several MAC addresses corresponding to each of the identification codes. Each identification code corresponds one-to-one with a social security card, which is the card identification code of the social security card. The MAC address is the network address where the data information, data change information, and data change log of the social security card corresponding to the identification code will be stored.

[0079] Specifically, the underlying authentication steps include:

[0080] The encryption module is invoked to extract the first authentication factor, the first authentication key address, and the first authentication key address from the reset authentication information; the encryption module is invoked to identify the first key generation logic and the first key encryption logic that match the first authentication key address in the key logic matching database; the encryption module is invoked to generate a second authentication factor based on the first key generation logic; the second authentication factor is the authentication factor corresponding to the first authentication factor, generated according to the first key generation logic, and used for subsequent social security card authentication; the encryption module is invoked to encrypt the first authentication original information according to the first key encryption logic and based on the second authentication factor to obtain the first encrypted authentication information, that is, to combine or concatenate and encrypt the second authentication factor and the first authentication original information using the first key encryption logic; the encryption module is invoked to encrypt the first authentication original information according to the first key encryption logic and based on the first authentication factor to obtain the second encrypted authentication information, the principle of which is the same as the principle of encrypting the first authentication original information based on the second authentication factor; the encryption module is controlled to call the underlying authentication interface to compare whether the first encrypted authentication information and the second encrypted authentication information match; if they match, the underlying authentication result is set as successful authentication; If there is no match, the underlying authentication result is set as authentication failure. Correspondingly, in this step, the encryption module and the underlying authentication interface adopt a method of simultaneous internal and external authentication between the module and the chip, thereby more accurately determining the security and operability of the social security card. The purpose of generating the second authentication factor, the first encrypted authentication information, and the second encrypted authentication information based on the above steps is that: when the first encrypted authentication information and the second encrypted authentication information match, the encryption key used by the first authentication factor to encrypt the first original authentication information and the encryption key used by the second authentication factor to encrypt the first original authentication information are the same first key encryption logic. Therefore, it must be stated that the first authentication factor and the second authentication factor are the same, indicating that the first authentication factor of the social security card chip must be generated through the first key generation logic of the social security card chip. This indicates that the first social security card and the terminal device where this encryption module is located are mutually authorized, and thus the authentication is successful. Conversely, if the underlying authentication is successful, the authentication will fail. Only when the underlying authentication is successful can subsequent data processing steps be carried out. In this step, the corresponding function is realized through the call of the encryption module and the underlying authentication interface, without relying on special interfaces, reducing the development and reuse of interfaces, and laying the groundwork for subsequent PIN reset. In this embodiment, the encryption module adopts an encryption machine.

[0081] The first reset step includes:

[0082] When the underlying authentication result indicates successful authentication, social security card data processing can proceed. The encryption module is invoked to extract the algorithm identifier and card identification code from the reset authentication information. The information reading interface is then invoked to read the security message calculation key address, security message calculation process factor, APDU command header, and APDU command plaintext data of the first social security card. In this embodiment, the APDU command header and APDU command plaintext data are the reset PIN-related data generated by the social security card chip when the user requests a PIN reset. Correspondingly, the APDU command plaintext data is the new PIN code that needs to be reset. To ensure data security and prevent leakage of social security card information during processing, the encryption module is invoked... The encryption module identifies a first key calculation logic matching the secure message calculation key address in the key logic matching database; the encryption module calculates the secure message calculation process factor according to the first key calculation logic to obtain encrypted data; the first key calculation logic includes, but is not limited to, data splitting and recombination, data obfuscation and encryption; correspondingly, the secure message calculation process factor is a random code generated by the key generation logic corresponding to the secure message calculation key address when the information reading interface in this step is read by the social security card chip; the encryption module identifies a first MAC address matching the card identification code in the social security card management terminal address database. Address; the first MAC address is the address where the PIN change of the first social security card takes effect and is saved; control the encryption module to call the PIN reset interface to identify the algorithm identifier; if the algorithm identifier is the first identifier (DES algorithm identifier, used to indicate that the encryption module uses a certain block cipher algorithm for encryption operation), then call the encryption module to use the first algorithm to concatenate and encrypt the APDU command header, the first MAC address and the calculated encryption data according to the first character position to obtain the first secure message, the first secure message generated according to the first character position must conform to the first character position length; the obtained first secure message consists of the APDU command header, the first MAC address and the calculated encryption data According to the concatenation structure, the total length of the first secure message is 34 bits, corresponding to the first algorithm. If the algorithm identifier is the second identifier (SSF33 / SM4 algorithm identifier, used to indicate that the encryption module uses a certain block cipher algorithm for encryption operation), then the encryption module is called to use the second algorithm to concatenate and encrypt the APDU command header, the first MAC address, and the calculated encryption data according to the second character position to obtain the second secure message. The second secure message generated according to the second character position must conform to the second character position length. The second secure message is composed of the APDU command header, the first MAC address, and the calculated encryption data, and the total length of the second secure message is 50 bits, corresponding to the second algorithm.The encryption module is controlled to call the PIN reset interface to set the APDU command plaintext data to a new PIN code. The encryption module is then controlled to call the PIN reset interface to send the new PIN code and the first security message to the first MAC address, or the encryption module is controlled to call the PIN reset interface to send the new PIN code and the second security message to the first MAC address; thereby resetting and making effective the PIN code of the first social security card. It is conceivable that in this embodiment, the object of data interaction generated by the interface is the chip of the first social security card. In this embodiment, this method can also be adapted to other similar integrated circuit cards. In this embodiment, it is conceivable that improvements to this method can lead to the development of interfaces adapted to different social security card data processing functions, thereby adapting to more social security card data processing functions, such as PIN unlocking, other data changes on the social security card, etc. Ultimately, this reduces the development of various special call interfaces for social security card data processing modules in different regions, reduces interface reuse, improves universality, and compensates for the shortcomings of existing technologies.

[0083] Example 2

[0084] This embodiment is based on the same inventive concept as the social security card PIN reset method based on a standard interface described in Embodiment 1, and provides a social security card PIN reset system based on a standard interface, such as... Figure 3 As shown, it includes: an initial configuration module, an information reading module, and an identification code reset module;

[0085] In the social security card PIN reset system based on the standard interface, the initial configuration module is used to configure the encryption module, the first standard interface, and the block encryption algorithm; the initial configuration module is also used to set the data character bits.

[0086] Specifically, the encryption module is equipped with a second standard interface, which includes: a data comparison interface, a data integration interface, a low-level authentication interface, and a PIN reset interface; the first standard interface includes: a status query interface, a power-on interface, and an information reading interface; the block encryption algorithm includes: a first algorithm and a second algorithm; the first algorithm is the DES algorithm; the second algorithm is the SSF33 algorithm or the SM4 algorithm; the data character positions include: a first character position and a second character position;

[0087] Specifically, the initial configuration module obtains the interface standard document. When the first standard interface or the second standard interface is called, the initial configuration module encapsulates the first standard interface or the second standard interface based on the interface standard document. The interface standard document is Document No. 38 of the Ministry of Human Resources and Social Security. The first standard interface is designed and implemented based on the WOSA standard interface.

[0088] In the social security card PIN reset system based on the standard interface, the information reading module is used to detect the social security card PIN reset request, and performs an information reading operation based on the encryption module, the first standard interface, the data character bits and the social security card PIN reset request to obtain reset authentication information;

[0089] Specifically, the social security card PIN reset requirement includes: a first requirement and a second requirement; the first requirement is that a first social security card exists and the PIN needs to be reset; the second requirement is that a first social security card does not exist and the PIN does not need to be reset.

[0090] Specifically, the information reading module identifies the social security card PIN reset requirement. If the social security card PIN reset requirement is the first requirement, the information reading module calls the status query interface to query the first status of the social security card recognition hardware on the terminal device. If the first status is that the social security card recognition hardware is normal, the information reading module performs the information reading operation.

[0091] The information reading operation includes: the information reading module first calls the power-on interface to power on the first social security card, then the information reading module controls the social security card recognition hardware to call the information reading interface to read the basic authentication information of the first social security card; the information reading module performs information authentication steps based on the encryption module and the basic authentication information to obtain the reset authentication information.

[0092] Specifically, the basic authentication information includes: algorithm identifier, card identification code, first authentication factor, first authentication original information, and first authentication key address;

[0093] Specifically, the information authentication steps include: the information reading module sets the identification code format parameters; the information reading module calls the encryption module to identify the first format parameters of the card identification code; the information reading module controls the encryption module to call the data comparison interface to compare whether the identification code format parameters match the first format parameters; if they match, the information reading module controls the encryption module to call the data integration interface to integrate the algorithm identifier, the first authentication factor, the first authentication original information, and the first authentication key address to obtain the reset authentication information.

[0094] In the social security card PIN reset system based on the standard interface, the identification code reset module is used to perform a PIN reset operation based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information.

[0095] Specifically, the PIN reset operation includes: the identification code reset module configuring a key logic matching database; the identification code reset module performing underlying authentication steps based on the encryption module, the reset authentication information, and the key logic matching database to obtain an underlying authentication result; the identification code reset module configuring a social security card management terminal address database; and the identification code reset module performing a first reset step based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, the reset authentication information, the key logic matching database, the underlying authentication result, and the social security card management terminal address database.

[0096] Specifically, the key logic matching database is configured with several authentication key addresses, several message calculation key addresses, several key calculation logics that match the several message calculation key addresses respectively, several key generation logics that match the several authentication key addresses respectively, and several key encryption logics.

[0097] Specifically, the underlying authentication steps include: the identification code reset module calls the encryption module to extract the first authentication factor, the first authentication key address, and the first authentication key address from the reset authentication information; the identification code reset module calls the encryption module to identify the first key generation logic and the first key encryption logic that match the first authentication key address in the key logic matching database; the identification code reset module calls the encryption module to generate a second authentication factor based on the first key generation logic; the identification code reset module calls the encryption module to encrypt the first authentication original information according to the first key encryption logic and based on the second authentication factor to obtain first encrypted authentication information; the identification code reset module calls the encryption module to encrypt the first authentication original information according to the first key encryption logic and based on the first authentication factor to obtain second encrypted authentication information; the identification code reset module controls the encryption module to call the underlying authentication interface to compare whether the first encrypted authentication information and the second encrypted authentication information match; if they match, the identification code reset module sets the underlying authentication result as authentication successful; if they do not match, the identification code reset module sets the underlying authentication result as authentication failed.

[0098] Specifically, the social security card management terminal address database is configured with several identification codes and several MAC addresses corresponding to the identification codes respectively;

[0099] Specifically, the first reset step includes:

[0100] When the underlying authentication result is successful, the identification code reset module calls the encryption module to extract the algorithm identifier and the card identification code from the reset authentication information; the identification code reset module calls the information reading interface to read the security message calculation key address, security message calculation process factor, APDU command header and APDU command plaintext data of the first social security card;

[0101] The identification code reset module calls the encryption module to identify a first key calculation logic matching the address of the security message calculation key in the key logic matching database; the identification code reset module calls the encryption module to calculate the factors of the security message calculation process according to the first key calculation logic to obtain calculated encrypted data; the identification code reset module calls the encryption module to identify a first MAC address matching the card identification code in the social security card management terminal address database; the identification code reset module controls the encryption module to call the PIN reset interface to identify the algorithm identifier; if the algorithm identifier is the first identifier, the identification code reset module calls the encryption module to use the first algorithm to concatenate and encrypt the APDU command header, the first MAC address, and the calculated encrypted data according to the first character position. The system obtains a first security message; if the algorithm identifier is a second identifier, the identification code reset module calls the encryption module to use the second algorithm to concatenate and encrypt the APDU command header, the first MAC address, and the calculated encrypted data according to the second character position to obtain a second security message; the identification code reset module controls the encryption module to call the PIN reset interface to set the APDU command plaintext data to a new PIN code, and the identification code reset module controls the encryption module to call the PIN reset interface to send the new PIN code and the first security message to the first MAC address, or the identification code reset module controls the encryption module to call the PIN reset interface to send the new PIN code and the second security message to the first MAC address, thereby completing the reset of the first social security card PIN.

[0102] Example 3

[0103] This embodiment provides a computer-readable storage medium, including:

[0104] The storage medium is used to store computer software instructions used to implement the social security card PIN reset method based on the standard interface described in Embodiment 1. It includes a program for executing the program set for the social security card PIN reset method based on the standard interface. Specifically, the executable program can be built into the social security card PIN reset system based on the standard interface described in Embodiment 2. In this way, the social security card PIN reset system based on the standard interface can implement the social security card PIN reset method based on the standard interface described in Embodiment 1 by executing the built-in executable program.

[0105] Furthermore, the computer-readable storage medium in this embodiment can be any combination of one or more readable storage media, wherein the readable storage medium includes an electrical, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof.

[0106] Unlike existing technologies, the social security card PIN reset method, system, and medium based on a standard interface proposed in this application can realize the design and calling of a unified standard interface for the social security card data processing module. This eliminates the need for repeated development or design of ports for the social security card data processing module, quickly realizing information reading, dual authentication, and PIN reset of the social security card, meeting more comprehensive social security card data processing requirements. Moreover, the entire development logic is ingenious. Based on the logic of this unified standard interface, more functional interfaces can be designed to realize different social security card data processing functions, which has strong universality. This system provides effective technical support for this method, ultimately making up for the shortcomings of existing technologies and having high application value.

[0107] The embodiment numbers disclosed in the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0108] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing related hardware to implement the program, which can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0109] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for resetting a social security card PIN based on a standard interface, characterized in that, Includes the following steps: Initial configuration steps: Configure the encryption module, the first standard interface, and the block cipher algorithm; set the data character bits; Information verification steps: The system detects a social security card PIN reset request and performs an information reading operation based on the encryption module, the first standard interface, the data character bits, and the social security card PIN reset request to obtain reset authentication information. Identification code reset steps: A PIN reset operation is performed based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information. The PIN reset operation includes: Configure the key logic matching database, and perform underlying authentication steps based on the encryption module, the reset authentication information, and the key logic matching database to obtain the underlying authentication result; The key logic matching database is configured with several authentication key addresses, several message calculation key addresses, several key calculation logics that match the message calculation key addresses respectively, several key generation logics that match the authentication key addresses respectively, and several key encryption logics. The underlying authentication steps include: calling the encryption module to extract the first authentication factor, the first authentication key address, and the first authentication key address from the reset authentication information; calling the encryption module to identify the first key generation logic and the first key encryption logic that match the first authentication key address in the key logic matching database; calling the encryption module to generate a second authentication factor based on the first key generation logic; calling the encryption module to encrypt the first authentication original information according to the first key encryption logic and based on the second authentication factor to obtain first encrypted authentication information; calling the encryption module to encrypt the first authentication original information according to the first key encryption logic and based on the first authentication factor to obtain second encrypted authentication information; controlling the encryption module to call the underlying authentication interface to compare whether the first encrypted authentication information and the second encrypted authentication information match; if they match, the underlying authentication result is set as authentication successful; if they do not match, the underlying authentication result is set as authentication failed. Configure the social security card management terminal address database, and perform the first reset step based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, the reset authentication information, the key logic matching database, the underlying authentication result, and the social security card management terminal address database; The social security card management terminal address database is configured with several identification codes and several MAC addresses corresponding to the identification codes; The first reset step includes: when the underlying authentication result is successful, calling the encryption module to extract the algorithm identifier and card identification code from the reset authentication information; calling the information reading interface to read the security message calculation key address, security message calculation process factor, APDU command header, and APDU command plaintext data of the first social security card; calling the encryption module to identify the first key calculation logic matching the security message calculation key address in the key logic matching database; calling the encryption module to calculate the security message calculation process factor according to the first key calculation logic to obtain encrypted calculation data; calling the encryption module to identify the first MAC address matching the card identification code in the social security card management terminal address database; controlling the encryption module to call the PIN reset interface to identify the algorithm identifier; if the algorithm identifier... If the identifier is the first identifier, the encryption module is invoked to use the first algorithm to concatenate and encrypt the APDU command header, the first MAC address, and the calculated encrypted data according to the first character position, to obtain a first secure message; if the algorithm identifier is the second identifier, the encryption module is invoked to use the second algorithm to concatenate and encrypt the APDU command header, the first MAC address, and the calculated encrypted data according to the second character position, to obtain a second secure message; the encryption module is controlled to call the PIN reset interface to set the APDU command plaintext data to a new PIN code, and the encryption module is controlled to call the PIN reset interface to send the new PIN code and the first secure message to the first MAC address, or the encryption module is controlled to call the PIN reset interface to send the new PIN code and the second secure message to the first MAC address.

2. The social security card PIN reset method based on a standard interface according to claim 1, characterized in that: The encryption module is equipped with a second standard interface; The second standard interface includes: a data comparison interface, a data integration interface, an underlying authentication interface, and a PIN reset interface; The first standard interface includes: a status query interface, a power-on interface, and an information reading interface; The block encryption algorithm includes: a first algorithm and a second algorithm; the first algorithm is the DES algorithm; the second algorithm is either the SSF33 algorithm or the SM4 algorithm; The data character positions include: a first character position and a second character position; The social security card PIN reset requirement includes: a first requirement and a second requirement; the first requirement is that a first social security card exists and the PIN needs to be reset; the second requirement is that a first social security card does not exist and the PIN does not need to be reset.

3. The social security card PIN reset method based on a standard interface according to claim 2, characterized in that: The step of performing an information reading operation based on the encryption module, the first standard interface, the data character bits, and the social security card PIN reset requirement to obtain reset authentication information further includes: The system identifies the social security card PIN reset requirement. If the social security card PIN reset requirement is the first requirement, the system calls the status query interface to query the first status of the social security card recognition hardware on the terminal device. If the first status is that the social security card recognition hardware is normal, the system performs the information reading operation. The information reading operation includes: first, calling the power-on interface to power on the first social security card; then controlling the social security card recognition hardware to call the information reading interface to read the basic authentication information of the first social security card; and performing information authentication steps based on the encryption module and the basic authentication information to obtain the reset authentication information.

4. The social security card PIN reset method based on a standard interface according to claim 3, characterized in that: The basic authentication information includes: algorithm identifier, card identification code, first authentication factor, first authentication original information, and first authentication key address; The information authentication steps include: Set the identification code format parameters, call the encryption module to identify the first format parameters of the card identification code; control the encryption module to call the data comparison interface to compare whether the identification code format parameters match the first format parameters; if they match, control the encryption module to call the data integration interface to integrate the algorithm identifier, the first authentication factor, the first authentication original information and the first authentication key address to obtain the reset authentication information.

5. A method for resetting a social security card PIN based on a standard interface according to claim 2, characterized in that: The social security card PIN reset method based on a standard interface also includes: Obtain the interface standard document, and when calling the first standard interface or the second standard interface, encapsulate the first standard interface or the second standard interface based on the interface standard document.

6. A social security card PIN reset system based on a standard interface, based on any one of claims 1 to 5, characterized in that: include: Initial configuration module, information reading module, and identification code reset module; The initial configuration module is used to configure the encryption module, the first standard interface, and the block cipher algorithm; the initial configuration module is also used to set the data character bits; The information reading module is used to detect the social security card PIN reset requirement, and performs an information reading operation based on the encryption module, the first standard interface, the data character bits and the social security card PIN reset requirement to obtain reset authentication information; The identification code reset module is used to perform a PIN reset operation based on the encryption module, the first standard interface, the block encryption algorithm, the data character bits, and the reset authentication information.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the social security card PIN reset method based on a standard interface as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Server authentication in non-secure channel card pin reset methods and computer implemented processes

    US20050289652A1