NFC-based transaction method, device, user identification device and terminal

By receiving and processing terminal messages, using routing tables to determine applications and instruct NFC transactions, the problems of multi-SE management and control are solved, and the effective forwarding of NFC contactless transactions is realized, and business conflicts are avoided.

CN114386960BActive Publication Date: 2025-08-22CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011118307.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-19
Publication Date
2025-08-22
Estimated Expiration
2040-10-19

AI Technical Summary

Technical Problem

Existing terminals and SWP-SIM cards cannot support the management and control of multiple SEs, resulting in traditional CLEs being unable to forward NFC contactless transactions, resulting in business conflicts.

Method used

By receiving the first message sent by the terminal, the currently stored routing table determines whether the corresponding application is installed, and a first reply message is sent to the terminal to instruct the terminal to send a second message to the target user identity identification device or the embedded security element eSE to realize NFC transactions.

Benefits of technology

It avoids the inability of traditional CLE to forward NFC contactless transactions, solves the problem of business conflicts, and implements the NFC-based transaction method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114386960B_ABST
    Figure CN114386960B_ABST
Patent Text Reader

Abstract

The present invention provides an NFC-based transaction method, apparatus, user identification device, and terminal, relating to the field of communications technology. The method comprises: receiving a first message from a terminal, the first message used for application verification; sending a first response message to the terminal based on the first message and a currently stored routing table; the first response information instructing the terminal to send a second message to a target user identification device or embedded secure element (eSE). The solution of the present invention solves the problem of traditional CLEs being unable to forward NFC contactless transactions, resulting in service conflicts.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular to an NFC-based transaction method, apparatus, user identification device, and terminal. Background Art

[0002] Currently, the process of a terminal conducting a Near Field Communication (NFC) transaction event is as follows: the terminal conducts an NFC contactless transaction in an NFC acceptance environment; the terminal's contactless front-end (CLF) forwards the contactless transaction to the secure element (SE) of the Single Wire Management-Subscriber Identity Module (SWP-SIM) card. The SE transfers the service request to the corresponding service application based on the service identifier of the NFC acceptance environment. The CLF and the SE of the SWP-SIM card have a one-to-one transaction forwarding relationship.

[0003] However, with the development of business needs and the update of terminal technology, dual-SIM terminals, host-based card emulation (HCE) terminals and dual-SIM HCE terminals have gradually appeared on the market. However, existing terminals and SWP-SIM cards do not support the management and control of multiple SEs, making it impossible for traditional CLE to forward NFC contactless transactions, resulting in business conflicts. Summary of the Invention

[0004] The purpose of the present invention is to provide a transaction method, apparatus, user identification device and terminal based on NFC, which solves the problem that traditional CLE cannot forward NFC contactless transactions and causes service conflicts.

[0005] To achieve the above objectives, an embodiment of the present invention provides an NFC-based transaction method, which is applied to a user identification device and includes:

[0006] receiving a first message sent by a terminal, where the first message is used for application verification;

[0007] According to the first message and the currently stored routing table, a first response message is sent to the terminal; the first response information is used to instruct the terminal to send a second message to a target user identity device or an embedded security element eSE.

[0008] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0009] Optionally, the first response message includes one of the following:

[0010] Application information;

[0011] Target SE identification information;

[0012] Error message.

[0013] Optionally, the routing table includes: a correspondence between a secure element SE location, a SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0014] Optionally, sending a first response message to the terminal according to the first message and a currently stored routing table includes:

[0015] In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information;

[0016] The first response message is sent to the terminal according to the SE location, the SE activation state and the AID priority; the first response message includes the application information or target SE identification information.

[0017] Optionally, sending a first response message to the terminal according to the first message and a pre-stored routing table includes:

[0018] In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0019] The first response message is sent to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0020] Optionally, sending a first response message to the terminal according to the first message and a currently stored routing table includes:

[0021] When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

[0022] Optionally, after sending the first response message to the terminal, the method further includes:

[0023] receiving a third message, wherein the third message includes transaction information;

[0024] A third response message is sent, where the third response message includes the transaction result.

[0025] Optionally, the method further includes:

[0026] receiving a fourth message sent by a terminal, where the fourth message includes the routing table;

[0027] A fourth response message is sent to the terminal, where the fourth response message includes a writing result of the routing table.

[0028] Optionally, the method further includes:

[0029] receiving a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0030] A fifth response message is sent to the terminal, where the fifth response message includes: a writing result of the SE information.

[0031] To achieve the above objectives, an embodiment of the present invention provides an NFC-based transaction method, which is applied to a terminal and includes:

[0032] Sending a first message to a first user identity identification device, where the first message is used for application verification;

[0033] receiving a first response message sent by a first user identity identification device;

[0034] A second message is sent to the target user identity device or embedded security element eSE according to the first response message.

[0035] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information;

[0036] Optionally, the first response message includes one of the following:

[0037] Application information;

[0038] Target SE identification information;

[0039] Error message.

[0040] Optionally, sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes:

[0041] In a case where the first response message includes application information, a second message including transaction information is sent to a target user identification device; wherein the target user identification device is the first user identification device.

[0042] Optionally, sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes:

[0043] In the case where the first response message includes the target SE identification information, sending a second message to the target user identity device;

[0044] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0045] Optionally, sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes:

[0046] In a case where the first response message includes error prompt information, the second message is sent to the eSE; wherein the second message includes: AID information or Mifare application information.

[0047] Optionally, before sending the first message to the first subscriber identity module SIM card, the method further includes:

[0048] Receive the routing table sent by the Trusted Service Management TSM system;

[0049] Sending a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0050] A second response message sent by the plurality of SIM cards is received, where the second response message includes a routing table writing result.

[0051] Optionally, the method further includes:

[0052] Receive SE information sent by the Trusted Service Management TSM system, where the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0053] sending a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0054] Receive a third response message sent by each of the SIM cards, where the third response message includes: a SE information writing result.

[0055] To achieve the above-mentioned object, an embodiment of the present invention provides a user identity recognition device, including a transceiver;

[0056] The transceiver is used to receive a first message sent by a terminal, where the first message is used for application verification;

[0057] The transceiver is further configured to send a first response message to the terminal based on the first message and the currently stored routing table; the first response information is configured to instruct the terminal to send a second message to a target user identity device or an embedded security element eSE.

[0058] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0059] Optionally, the first response message includes one of the following:

[0060] Application information;

[0061] Target SE identification information;

[0062] Error message.

[0063] Optionally, the routing table includes: a correspondence between a secure element SE location, a SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0064] Optionally, when the transceiver is configured to send a first response message to the terminal according to the first message and a currently stored routing table, the transceiver is specifically configured to:

[0065] In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information;

[0066] The first response message is sent to the terminal according to the SE location, the SE activation state and the AID priority; the first response message includes the application information or target SE identification information.

[0067] Optionally, when the transceiver is configured to send the first response message to the terminal according to the first message and a pre-stored routing table, the transceiver is specifically configured to:

[0068] In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0069] The first response message is sent to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0070] Optionally, when the transceiver is configured to send a first response message to the terminal according to the first message and a currently stored routing table, the transceiver is specifically configured to:

[0071] When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

[0072] Optionally, the transceiver is further configured to:

[0073] receiving a third message, wherein the third message includes transaction information;

[0074] A third response message is sent, where the third response message includes the transaction result.

[0075] Optionally, the transceiver is further configured to:

[0076] receiving a fourth message sent by a terminal, where the fourth message includes the routing table;

[0077] A fourth response message is sent to the terminal, where the fourth response message includes a writing result of the routing table.

[0078] Optionally, the transceiver is further configured to:

[0079] receiving a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0080] A fifth response message is sent to the terminal, where the fifth response message includes: a writing result of the SE information.

[0081] To achieve the above-mentioned object, an embodiment of the present invention further provides a terminal, including a transceiver; the transceiver is configured to:

[0082] Sending a first message to a first user identity identification device, where the first message is used for application verification;

[0083] receiving a first response message sent by a first user identity identification device;

[0084] A second message is sent to the target user identity device or embedded security element eSE according to the first response message.

[0085] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information;

[0086] Optionally, the first response message includes one of the following:

[0087] Application information;

[0088] Target SE identification information;

[0089] Error message.

[0090] Optionally, when the transceiver is configured to send a second message to a target user identity device or an embedded secure element eSE according to the first response message, the transceiver is specifically configured to:

[0091] In a case where the first response message includes application information, a second message including transaction information is sent to a target user identification device; wherein the target user identification device is the first user identification device.

[0092] Optionally, when the transceiver is configured to send a second message to a target user identity device or an embedded secure element eSE according to the first response message, the transceiver is specifically configured to:

[0093] In the case where the first response message includes the target SE identification information, sending a second message to the target user identity device;

[0094] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0095] Optionally, when the transceiver is configured to send a second message to a target user identity device or an embedded secure element eSE according to the first response message, the transceiver is specifically configured to:

[0096] In a case where the first response message includes error prompt information, the second message is sent to the eSE; wherein the second message includes: AID information or Mifare application information.

[0097] Optionally, the transceiver is further configured to:

[0098] Receive the routing table sent by the Trusted Service Management TSM system;

[0099] Sending a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0100] A second response message sent by the plurality of SIM cards is received, where the second response message includes a routing table writing result.

[0101] Optionally, the transceiver is further configured to:

[0102] Receive SE information sent by the Trusted Service Management TSM system, where the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0103] sending a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0104] Receive a third response message sent by each of the SIM cards, where the third response message includes: a SE information writing result.

[0105] To achieve the above objectives, an embodiment of the present invention further provides an NFC-based transaction device, which is applied to a user identification device and includes:

[0106] A first receiving module, configured to receive a first message sent by a terminal, where the first message is used for application verification;

[0107] The first sending module is used to send a first response message to the terminal according to the first message and the currently stored routing table; the first response information is used to instruct the terminal to send a second message to a target user identity device or an embedded security element eSE.

[0108] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0109] Optionally, the first response message includes one of the following:

[0110] Application information;

[0111] Target SE identification information;

[0112] Error message.

[0113] Optionally, the routing table includes: a correspondence between a secure element SE location, a SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0114] Optionally, the first sending module includes:

[0115] a first determining submodule, configured to, when the first message includes AID information and the AID list in the routing table includes the AID information, determine, according to the routing table, a SE position, a SE activation state, and an AID priority corresponding to the AID information;

[0116] The first sending submodule is configured to send the first response message to the terminal according to the SE location, the SE activation state, and the AID priority; the first response message includes the application information or target SE identification information.

[0117] Optionally, the first sending module includes:

[0118] A second determination submodule is configured to determine, when the first message includes Mifare application identification information and the Mifare application list in the routing table includes the Mifare application information, the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0119] The second sending submodule is used to send the first response message to the terminal according to the SE position, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0120] Optionally, the first sending submodule includes:

[0121] The third sending submodule is used to send a first response message including error prompt information to the terminal when the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list.

[0122] Optionally, the NFC-based transaction device further includes:

[0123] a second receiving module, configured to receive a third message, wherein the third message includes transaction information;

[0124] The second sending module is configured to send a third response message, where the third response message includes a transaction result.

[0125] Optionally, the NFC-based transaction device further includes:

[0126] A third receiving module, configured to receive a fourth message sent by the terminal, where the fourth message includes the routing table;

[0127] The third sending module is configured to send a fourth response message to the terminal, where the fourth response message includes a result of writing into the routing table.

[0128] Optionally, the NFC-based transaction device further includes:

[0129] a fourth receiving module, configured to receive a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0130] The fourth sending module is used to send a fifth response message to the terminal, where the fifth response message includes: a writing result of the SE information.

[0131] To achieve the above objectives, an embodiment of the present invention provides an NFC-based transaction device, applied to a terminal, comprising:

[0132] A first sending module, configured to send a first message to a first user identity identification device, where the first message is used for application verification;

[0133] A first receiving module, configured to receive a first response message sent by a first user identity identification device;

[0134] The second sending module is configured to send a second message to a target user identity device or an embedded security element eSE according to the first response message.

[0135] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0136] Optionally, the first response message includes one of the following:

[0137] Application information;

[0138] Target SE identification information;

[0139] Error message.

[0140] Optionally, the second sending module includes:

[0141] The first sending submodule is configured to send a second message including transaction information to a target user identification device when the first response message includes application information; wherein the target user identification device is the first user identification device.

[0142] Optionally, the second sending module includes:

[0143] A second sending submodule is configured to send a second message to a target user identity device when the first response message includes target SE identification information;

[0144] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0145] Optionally, the second sending module includes:

[0146] The third sending submodule is configured to send the second message to the eSE when the first response message includes error prompt information; wherein the second message includes: AID information or Mifare application information.

[0147] Optionally, the NFC-based transaction device further includes:

[0148] The second receiving module is used to receive the routing table sent by the trusted service management TSM system;

[0149] A third sending module, configured to send a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0150] The third receiving module is configured to receive second response messages sent by the plurality of SIM cards, where the second response messages include a routing table writing result.

[0151] Optionally, the NFC-based transaction device further includes:

[0152] A fourth receiving module is configured to receive SE information sent by a trusted service management (TSM) system, wherein the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0153] a fourth sending module, configured to send a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0154] The fifth receiving module is configured to receive a third response message sent by each of the SIM cards, wherein the third response message includes: a SE information writing result.

[0155] To achieve the above-mentioned purpose, an embodiment of the present invention also provides a user identity identification device, comprising: a transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; when the processor executes the program or instruction, the NFC-based transaction method as described above is implemented.

[0156] To achieve the above-mentioned objectives, an embodiment of the present invention further provides a terminal, comprising: a transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; when the processor executes the program or instruction, the NFC-based transaction method as described above is implemented.

[0157] To achieve the above-mentioned objectives, an embodiment of the present invention provides a readable storage medium having a program or instruction stored thereon, which, when executed by a processor, implements the steps of the NFC-based transaction method as applied to the user identification device as described above, or the steps of the NFC-based transaction method as applied to the terminal as described above.

[0158] The beneficial effects of the above technical solution of the present invention are as follows:

[0159] The method of the embodiment of the present invention first receives a first message sent by a terminal for application verification, and then determines whether an application corresponding to the first message is installed in a currently stored routing table based on the first message. Then, based on the determination result, a first response message is sent to the terminal, so that the terminal sends a second message to the target user identity identification device or embedded security element eSE based on the first response message to implement a transaction based on NFC, thereby avoiding the problem that traditional CLE cannot forward NFC contactless transactions and cause business conflicts. BRIEF DESCRIPTION OF THE DRAWINGS

[0160] Figure 1 This is a flowchart of a transaction method based on NFC applied to a user identification device according to an embodiment of the present invention;

[0161] Figure 2 This is a second flowchart of an NFC-based transaction method applied to a terminal according to an embodiment of the present invention;

[0162] Figure 3 This is one of the flow charts of interaction between a user identity recognition device and a terminal according to an embodiment of the present invention;

[0163] Figure 4 This is the second flow chart of interaction between the user identity recognition device and the terminal according to an embodiment of the present invention;

[0164] Figure 5 This is the third flow chart of the interaction between the user identity recognition device and the terminal according to an embodiment of the present invention;

[0165] Figure 6 A schematic diagram of an NFC transaction system to which the NFC-based transaction method according to an embodiment of the present invention is applied;

[0166] Figure 7 A structural diagram of a user identity recognition device according to an embodiment of the present invention;

[0167] Figure 8 is a structural diagram of a terminal according to an embodiment of the present invention;

[0168] Figure 9This is a structural diagram of an NFC-based transaction device according to an embodiment of the present invention;

[0169] Figure 10 is a structural diagram of an NFC-based transaction device according to another embodiment of the present invention;

[0170] Figure 11 A structural diagram of a user identity recognition device according to another embodiment of the present invention;

[0171] Figure 12 FIG. 4 is a structural diagram of a terminal according to another embodiment of the present invention. DETAILED DESCRIPTION

[0172] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0173] It should be understood that references throughout this specification to "one embodiment" or "an embodiment" mean that a particular feature, structure, or characteristic associated with the embodiment is included in at least one embodiment of the present invention. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout this specification do not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0174] In various embodiments of the present invention, it should be understood that the size of the serial numbers of the following processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0175] Additionally, the terms "system" and "network" are often used interchangeably herein.

[0176] In the embodiments provided herein, it should be understood that "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B based solely on A; B can also be determined based on A and / or other information.

[0177] like Figure 1 As shown, an NFC-based transaction method according to an embodiment of the present invention is applied to a user identification device, including:

[0178] Step 101: Receive a first message sent by a terminal, where the first message is used for application verification;

[0179] Step 102: Send a first response message to the terminal according to the first message and the currently stored routing table; the first response message is used to instruct the terminal to send a second message to a target user identity device or embedded secure element eSE.

[0180] According to the above steps, the method of the embodiment of the present invention is that the user identity identification device (SIM card) first receives the first message sent by the terminal for application verification to determine that an NFC-based transaction is currently required. Thereafter, based on the first message and the routing table currently stored on the user identity identification device, it is determined whether an application corresponding to the first message is installed thereon, and based on the determination result, a first response message is sent to the terminal to instruct the terminal to send a second message to the target user identity identification device or embedded security element eSE, so that the terminal sends transaction data to the user identity identification device or eSE corresponding to the first message, thereby avoiding the problem of business conflict caused by the inability of traditional CLF to forward NFC contactless transactions.

[0181] It should be noted that the terminal in the embodiment of the present invention may be a mobile terminal, such as a smart phone, a tablet computer, etc., and the mobile terminal is a mobile terminal with NFC function; the user identity identification device may be a SIM card installed in the mobile terminal.

[0182] In addition, the execution subject of the NFC-based transaction method of the embodiment of the present invention can be an "event processing chip" entity in the user identity recognition device, or it can be a functional module in the user identity recognition device.

[0183] In the case where the execution subject of the NFC-based transaction method in the embodiment of the present invention is the "event processing chip" entity, combined with Figure 6 The "event processing chip" is connected in series between the CLF chip of the terminal and the SE chip of the user identity identification device, and the "event processing chip" is connected to the CLF chip through the SWP interface and connected to the SE chip through the internal interface of the user identity identification device.

[0184] In this embodiment, optionally, the first message includes application identification (Aoolication Identifiers, AID) information or logical encryption card Mifare application information.

[0185] It should be noted that the content included in the first message is determined by the type of NFC device used to implement NFC-based transactions, wherein the NFC device may be an NFC card reader, such as a POS machine.

[0186] In this embodiment, optionally, the first response message includes one of the following:

[0187] Application information;

[0188] Target SE identification information;

[0189] Error message.

[0190] Among them, the application information can be the application identification code of the application installed in the user identity identification device, which is applicable to the first message; the target SE identification information can be the SE installed with the application applicable to this NFC-based transaction; the error prompt information is the information used by the user identity identification device to remind the terminal when the SE of the application applicable to this NFC-based transaction is not installed on multiple user identity identification devices installed on the terminal.

[0191] In this embodiment, optionally, the routing table includes: a correspondence between a secure element SE location, an SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0192] The SE location is the installation location of the SE, such as the first user identity device (SIM1) or the second user identity device (SIM2). Specifically, the routing table example is as shown in Table 1 below:

[0193] Table 1

[0194] SE location SE status AID List AID Priority Mifare Application Mifare Priority SIM1 activation 1234567890123456 01 ABCDEF 01 SIM2 Deactivation 2234567890123456 01 ABCDEF 02

[0195] In this embodiment, optionally, step 102, sending a first response message to the terminal according to the first message and the currently stored routing table, includes:

[0196] In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information;

[0197] The first response message is sent to the terminal according to the SE location, the SE activation state and the AID priority; the first response message includes the application information or target SE identification information.

[0198] In this embodiment, after receiving the first message, the user identity identification device first determines whether the first information included in the first message is AID information or Mifare application information. If the first message includes AID information, the user identity identification device determines the corresponding SE location, SE activation status, and AID priority based on the AID information, so as to generate a first response message based on the above three pieces of information. The following describes this embodiment in different situations:

[0199] Case 1: When it is determined that the SE location corresponding to the AID information is itself (the user identity identification device of the executor of this method) and the activation status of the SE is activated, if the AID priority is the highest priority, a first response message including application information is sent to the terminal to instruct the terminal to send a second message to itself.

[0200] Case 2: When it is determined that the SE position corresponding to the AID information is itself (the user identity identification device of the executor of this method) and the activation state of the SE is activated, if the SE state corresponding to the AID priority with a priority higher than the AID priority is deactivated, a first response message including application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0201] Case three: When it is determined that the SE location corresponding to the AID information is a user identity identification device other than itself (the user identity identification device of the executor of this method), and the activation status of the SE is inactivated, a first response message including application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0202] Case 4: When it is determined that the SE position corresponding to the AID information is a user identity identification device other than itself (the user identity identification device of the executor of this method), and the activation status of the SE is activated, but the AID priority is lower than the AID priority of this user identity identification device, a first response message including application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0203] Case 5: When it is determined that the SE position corresponding to the AID information is a user identity identification device other than itself (the user identity identification device of the executor of this method), the activation status of the SE is activated, and the AID priority is higher than the AID priority of this user identity identification device, a first response message including the target SE identification information is sent to the terminal to instruct the terminal to send a second message to the target SE.

[0204] In this embodiment, optionally, step 102, sending a first response message to the terminal according to the first message and a pre-stored routing table, includes:

[0205] In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0206] The first response message is sent to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0207] In this embodiment, after receiving the first message, the user identification device first determines whether the first information included in the first message is AID information or Mifare application information. If the first message includes Mifare application information, the user identification device determines the corresponding SE location, SE activation status, and Mifare priority based on the Mifare application information, so as to generate a first response message based on the above three pieces of information. The following describes this embodiment in different situations:

[0208] Case 1: When it is determined that the SE position corresponding to the Mifare application information is itself (the user identity identification device of the execution subject of this method) and the activation status of the SE is activated, if the Mifare priority is the highest priority, a first response message including the application information is sent to the terminal to instruct the terminal to send a second message to itself.

[0209] Case 2: When it is determined that the SE position corresponding to the Mifare application information is itself (the user identity identification device of the execution subject of this method) and the activation status of the SE is activated, if the SE status corresponding to the Mifare priority with a priority higher than the Mifare priority is deactivated, a first response message including the application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0210] Case three: When it is determined that the SE position corresponding to the Mifare application information is a user identity identification device other than itself (the user identity identification device of the execution subject of this method), and the activation status of the SE is inactivated, a first response message including the application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0211] Case 4: When it is determined that the SE position corresponding to the Mifare application information is a user identity identification device other than itself (the user identity identification device of the executor of this method), and the activation status of the SE is activated, but the Mifare priority is lower than the Mifare priority of this user identity identification device, a first response message including the application information is sent to the terminal; to instruct the terminal to send a second message to itself.

[0212] Case 5: When it is determined that the SE position corresponding to the Mifare application information is a user identity identification device other than itself (the user identity identification device of the execution subject of this method), the activation status of the SE is activated, and the Mifare priority is higher than the Mifare priority of this user identity identification device, a first response message including the target SE identification information is sent to the terminal to instruct the terminal to send a second message to the target SE.

[0213] In this embodiment, optionally, step 102: sending a first response message to the terminal according to the first message and the currently stored routing table includes:

[0214] When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

[0215] Since the routing table stored in the user identity identification device is the information on the user identity identification device installed on the terminal, therefore, when the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list, it is determined that the application currently participating in the NFC-based transaction is not installed on the user identity identification device. At this time, a first response message including an error prompt information needs to be sent to the terminal to instruct the terminal to send a second message to the component on which the application participating in the NFC-based transaction is installed. Specifically, it can be: sending a second message to the eSE on the terminal.

[0216] Next, combine Figure 5 The process of NFC-based transactions is described in detail:

[0217] Step 501: The terminal receives an application selection instruction initiated by the POS terminal;

[0218] Step 502: The terminal forwards a selection instruction (first message) to the first user identification device; wherein the first user identification device may be one of the user identification devices defaulted by the terminal; and the selection instruction complies with the definition of the ISO7816 standard;

[0219] Step 503: The first user identification device checks the routing table on the "event processing chip" / functional module executing the method. This step is used to determine whether there is information corresponding to the first message in the routing table.

[0220] Among them, when the selection instruction is a select AID instruction, when it is found that it does not have the application AID in the selection instruction, or when it is found that the priority corresponding to the application AID installed by itself is not "01" and the SE with the corresponding priority "01" is activated, it returns "9999+SEID+AID" to notify the terminal's CLF to reselect the AID on the corresponding SE;

[0221] When the selection instruction is a Mifare file selection instruction, if it is found that it does not have the Mifare file in the selection instruction, or if it is found that the priority corresponding to the Mifare file installed by itself is not "01" and the SE with the corresponding priority "01" is activated, it returns "9999+SEID+MIfare file name" to notify the terminal's CLF to reselect the AID on the corresponding SE;

[0222] Step 504: When it is determined that the SE location applicable to the first message is the second user identity device, a first response message including SE identification information corresponding to the AID is returned to the terminal;

[0223] Step 505: The terminal sends a selection instruction (first message) to the target user identification device according to the information fed back by the first user identification device;

[0224] Step 506: The target user identification device checks the routing table on the "event processing chip" / functional module thereon; this step is used to determine whether there is information corresponding to the first message in the routing table;

[0225] Step 507: The target user identification device returns the application selection result to the terminal;

[0226] Step 508: The terminal returns the application selection result to the POS terminal;

[0227] Step 510: The POS terminal sends a transaction instruction to the target user identification device. The transaction instruction may include: transaction details;

[0228] Step 511: The target user identification device returns the transaction result to the POS terminal.

[0229] It should be noted that this specific embodiment is described based on the situation that the default first user identity identification device is not the target user identity identification device. If the default first user identity identification device is the target user identity identification device, step 504 returns the application selection result, and then the command interaction between the POS machine, the terminal and the first user identity identification device occurs; if the application participating in the transaction is installed on the eSE, step 504 returns an error prompt message, and then the information interaction between the POS machine, the terminal and the eSE occurs.

[0230] In this embodiment, after step 102, sending the first response message to the terminal, the method further includes:

[0231] receiving a third message, wherein the third message includes transaction information;

[0232] A third response message is sent, where the third response message includes the transaction result.

[0233] It should be noted that, in this embodiment, the third message is a message sent by the POS machine participating in the NFC-based transaction, and the third response message is a message sent by the user identification device to the POS machine.

[0234] Specifically, this embodiment is the process after step 102 when the present user identity identification device is the target user identity identification device (the first message includes application information); that is: when the present user identity identification device determines that the application corresponding to the first message is installed in the SE of the present user identity identification device, the SE is in an activated state, and the priority is the highest priority or the SE corresponding to a priority higher than the priority is deactivated, the transaction instructions are interacted between the POS machine and the present user identity identification device.

[0235] At this point, a contactless transaction based on NFC is completed.

[0236] In the NFC-based transaction method of an embodiment of the present invention, when a POS machine conducts a contactless transaction with an NFC-enabled terminal, the POS machine first sends a selection instruction to the terminal. Based on the selection instruction, the terminal interacts with multiple user identity devices (SIM cards) installed on the terminal to determine the installation location of the target application's SE, thereby enabling the transmission of transaction data between the POS machine and the target user identity device or eSE to complete the transaction. By first determining the installation location of the target application's SE, service conflicts are avoided during the transaction process, improving transaction flexibility and achieving high-reliability management of SIM cards. In addition, this method does not require users to replace terminals, saving business development costs.

[0237] This embodiment further includes:

[0238] receiving a fourth message sent by a terminal, where the fourth message includes the routing table;

[0239] A fourth response message is sent to the terminal, where the fourth response message includes a writing result of the routing table.

[0240] This embodiment is a process of writing a routing table into the user identification device of the terminal. Figure 4, the process of writing the routing table is described in detail:

[0241] Step 401: The client program sends a request message for installing the card application to the terminal;

[0242] Step 402: The terminal sends the request information to at least one user identity recognition device installed in the terminal;

[0243] Step 403: The user identification device installs the card application;

[0244] Step 404: The user identification device feeds back the installation result to the terminal;

[0245] Step 405: The terminal forwards the installation result to the client program;

[0246] Step 406: The client program sends an installation result feedback and a routing table update request to the Trusted Service Management (TSM) system, wherein the routing table update request includes at least one of the following: the identifier of the application installed on each user identification device, the routing policy, the priority of each application, etc.;

[0247] Step 407: The TSM system calculates and generates a routing table according to the routing table update request, or calculates and generates a routing table according to the routing table update request and the user's pre-configuration;

[0248] Step 408: The TSM system sends a routing table to the client program, wherein the routing table includes the content as described above;

[0249] Step 409: The client program sends a write routing table request to the terminal, where the write routing table request includes the routing table issued by the TSM system;

[0250] Step 410: The terminal writes the routing table into the eSE and forwards the request to write the routing table to each user identity device;

[0251] Step 411: Each user identification device is written into the routing table;

[0252] Step 412: Each user identification device feeds back the writing result to the terminal;

[0253] Step 413: The terminal forwards the writing result to the client program.

[0254] It should be noted that, in the embodiment of the present invention, the client program may be a bank's payment software or a third-party payment software installed on the terminal, and the user may make payments through the bank's payment software or the third-party payment software.

[0255] In this embodiment, further comprising:

[0256] receiving a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0257] A fifth response message is sent to the terminal, where the fifth response message includes: a writing result of the SE information.

[0258] This embodiment is a multi-SE registration process for a terminal. Figure 3 , the registration process is explained in detail:

[0259] Step 301: The user installs and opens the client program;

[0260] Step 302: The client program sends a request message to the terminal to obtain the terminal's International Mobile Equipment Identity (IMEI) and SIM card information;

[0261] Step 303: The terminal obtains IMIE and SIM card information;

[0262] Step 304: The terminal feeds back IMIE and SIM card information to the client program;

[0263] Step 305: The terminal sends a request to the TSM system to obtain the SE information corresponding to the terminal, where the request should at least include IMIE and SIM card information;

[0264] Step 306: The TSM system feeds back the SE information corresponding to the terminal to the client program;

[0265] Step 307: The client program sends a request to the terminal to write the terminal and SIM card SE information;

[0266] Step 308: The terminal forwards the received request to write the terminal and SIM card SE information to each user identity identification device;

[0267] Step 309: Each user identity identification device writes the SE information of the terminal and the SIM card; wherein the SE information written by each user identity identification device is multiple SE information on the terminal;

[0268] Step 310: Each user identity recognition device feeds back the writing result to the terminal;

[0269] Step 311: The terminal feeds back the received writing result to the client program.

[0270] Here, combined with Figure 6The working process of the embodiment of the present invention is described as follows: first, the NFC acceptance environment such as the POS machine first sends a selection instruction to the terminal through WIFI or Bluetooth, secondly, the terminal forwards the instruction to the default user identity identification device (NFC-SIM1), thirdly, the default user identity identification device feeds back the relevant information of the target SE to the terminal, and then the terminal sends the selection instruction to the target user identity identification device installed by the target SE, and then the target user identity identification device feeds back the application information to the terminal, and the terminal feeds back the application information to the POS machine, and finally, the POS machine and the target user identity identification device transmit transaction data to complete the transaction.

[0271] In summary, the method of the embodiment of the present invention, in order to avoid business conflicts during NFC contactless transactions, first registers multiple SEs of the terminal, so that the event processing chip / functional module of each user terminal includes SE information of multiple user identity identification modules; then, the card application updates the SE routing status; finally, when conducting NFC-based contactless transactions, the SE of the target application is selected to implement the interaction of transaction instructions between the POS machine and the specific user identity identification device, thereby avoiding business conflicts, making the terminal compatible with the traditional single CLF, and implementing the simplest NFC terminal mechanism, realizing different types of SE transaction systems, saving business development costs, eliminating the need for users to change mobile phones, and improving transaction flexibility and high-reliability management of SIM cards.

[0272] like Figure 2 As shown, an embodiment of the present invention provides an NFC-based transaction method, which is applied to a terminal and includes:

[0273] Step 201: Send a first message to a first user identity device, where the first message is used for application verification;

[0274] Step 202: Receive a first response message sent by the first user identification device;

[0275] Step 203: Send a second message to the target user identity device or embedded secure element eSE according to the first response message.

[0276] Here, the terminal may be a mobile terminal, such as a smart phone, a tablet computer, etc.

[0277] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0278] Optionally, the first response message includes one of the following:

[0279] Application information;

[0280] Target SE identification information;

[0281] Error message.

[0282] Optionally, step 203, sending a second message to a target user identity device or embedded secure element eSE according to the first response message, includes:

[0283] In a case where the first response message includes application information, a second message including transaction information is sent to a target user identification device; wherein the target user identification device is the first user identification device.

[0284] Optionally, step 203, sending a second message to a target user identity device or embedded secure element eSE according to the first response message, includes:

[0285] In the case where the first response message includes the target SE identification information, sending a second message to the target user identity device;

[0286] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0287] Optionally, step 203, sending a second message to a target user identity device or embedded secure element eSE according to the first response message, includes:

[0288] In a case where the first response message includes error prompt information, the second message is sent to the eSE; wherein the second message includes: AID information or Mifare application information.

[0289] Furthermore, before sending the first message to the first subscriber identity module SIM card, the method further includes:

[0290] Receive the routing table sent by the Trusted Service Management TSM system;

[0291] Sending a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0292] A second response message sent by the plurality of SIM cards is received, where the second response message includes a routing table writing result.

[0293] Furthermore, the method further comprises:

[0294] Receive SE information sent by the Trusted Service Management TSM system, where the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0295] sending a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0296] Receive a third response message sent by each of the SIM cards, where the third response message includes: a SE information writing result.

[0297] In this way, the embodiment of the present invention realizes the selection of the SE corresponding to the target application through the information interaction between the terminal and the user identity identification device, realizes the transmission of transaction data between the client program and the specified user identity identification device, and avoids the problem of business conflict caused by the traditional CLF being unable to forward NFC contactless transactions.

[0298] It should be noted that this method is applied to the terminal and cooperates with the above-mentioned method applied to the user identity identification device to realize NFC-based transactions. The implementation method of the terminal in the above-mentioned method embodiment applied to the user identity identification device is applicable to this method and can also achieve the same technical effect.

[0299] like Figure 7 As shown, an embodiment of the present invention provides a user identity recognition device 700, comprising: a transceiver 710;

[0300] The transceiver 710 is configured to receive a first message sent by a terminal, where the first message is used for application verification;

[0301] The transceiver 710 is further configured to send a first response message to the terminal based on the first message and the currently stored routing table; the first response message is configured to instruct the terminal to send a second message to a target user identity device or embedded security element eSE.

[0302] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0303] Optionally, the first response message includes one of the following:

[0304] Application information;

[0305] Target SE identification information;

[0306] Error message.

[0307] Optionally, the routing table includes: a correspondence between a secure element SE location, a SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0308] Optionally, when the transceiver 710 is configured to send a first response message to the terminal according to the first message and the currently stored routing table, the transceiver 710 is specifically configured to:

[0309] In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information;

[0310] The first response message is sent to the terminal according to the SE location, the SE activation state and the AID priority; the first response message includes the application information or target SE identification information.

[0311] Optionally, when the transceiver 710 is configured to send a first response message to the terminal according to the first message and a pre-stored routing table, the transceiver 710 is specifically configured to:

[0312] In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0313] The first response message is sent to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0314] Optionally, when the transceiver 710 is configured to send a first response message to the terminal according to the first message and the currently stored routing table, the transceiver 710 is specifically configured to:

[0315] When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

[0316] Optionally, the transceiver 710 is further configured to:

[0317] receiving a third message, wherein the third message includes transaction information;

[0318] A third response message is sent, where the third response message includes the transaction result.

[0319] Optionally, the transceiver 710 is further configured to:

[0320] receiving a fourth message sent by a terminal, where the fourth message includes the routing table;

[0321] A fourth response message is sent to the terminal, where the fourth response message includes a writing result of the routing table.

[0322] Optionally, the transceiver 710 is further configured to:

[0323] receiving a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0324] A fifth response message is sent to the terminal, where the fifth response message includes: a writing result of the SE information.

[0325] like Figure 8 As shown, an embodiment of the present invention provides a terminal 800, including: a transceiver 810; the transceiver 810 is used to:

[0326] Sending a first message to a first user identity identification device, where the first message is used for application verification;

[0327] receiving a first response message sent by a first user identity identification device;

[0328] A second message is sent to the target user identity device or embedded security element eSE according to the first response message.

[0329] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information;

[0330] Optionally, the first response message includes one of the following:

[0331] Application information;

[0332] Target SE identification information;

[0333] Error message.

[0334] Optionally, when the transceiver 810 is configured to send the second message to the target user identity device or embedded secure element eSE according to the first response message, the transceiver 810 is specifically configured to:

[0335] In a case where the first response message includes application information, a second message including transaction information is sent to a target user identification device; wherein the target user identification device is the first user identification device.

[0336] Optionally, when the transceiver 810 is configured to send the second message to the target user identity device or embedded secure element eSE according to the first response message, the transceiver 810 is specifically configured to:

[0337] In the case where the first response message includes the target SE identification information, sending a second message to the target user identity device;

[0338] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0339] Optionally, when the transceiver 810 is configured to send the second message to the target user identity device or embedded secure element eSE according to the first response message, the transceiver 810 is specifically configured to:

[0340] In a case where the first response message includes error prompt information, the second message is sent to the eSE; wherein the second message includes: AID information or Mifare application information.

[0341] Optionally, the transceiver 810 is further configured to:

[0342] Receive the routing table sent by the Trusted Service Management TSM system;

[0343] Sending a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0344] A second response message sent by the plurality of SIM cards is received, where the second response message includes a routing table writing result.

[0345] Optionally, the transceiver 810 is further configured to:

[0346] Receive SE information sent by the Trusted Service Management TSM system, where the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0347] sending a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0348] Receive a third response message sent by each of the SIM cards, where the third response message includes: a SE information writing result.

[0349] like Figure 9 As shown, an embodiment of the present invention provides an NFC-based transaction device, which is applied to a user identification device, including:

[0350] A first receiving module 901 is configured to receive a first message sent by a terminal, where the first message is used for application verification;

[0351] The first sending module 902 is used to send a first response message to the terminal according to the first message and the currently stored routing table; the first response information is used to instruct the terminal to send a second message to the target user identity device or embedded security element eSE.

[0352] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0353] Optionally, the first response message includes one of the following:

[0354] Application information;

[0355] Target SE identification information;

[0356] Error message.

[0357] Optionally, the routing table includes: a correspondence between a secure element SE location, a SE activation state, an AID list, an AID priority, a Mifare application list, and a Mifare application priority.

[0358] Optionally, the first sending module 902 includes:

[0359] a first determining submodule, configured to, when the first message includes AID information and the AID list in the routing table includes the AID information, determine, according to the routing table, a SE position, a SE activation state, and an AID priority corresponding to the AID information;

[0360] The first sending submodule is configured to send the first response message to the terminal according to the SE location, the SE activation state, and the AID priority; the first response message includes the application information or target SE identification information.

[0361] Optionally, the first sending module 902 includes:

[0362] A second determination submodule is configured to determine, when the first message includes Mifare application identification information and the Mifare application list in the routing table includes the Mifare application information, the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table;

[0363] The second sending submodule is used to send the first response message to the terminal according to the SE position, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information.

[0364] Optionally, the first sending submodule includes:

[0365] The third sending submodule is used to send a first response message including error prompt information to the terminal when the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list.

[0366] Optionally, the NFC-based transaction device further includes:

[0367] a second receiving module, configured to receive a third message, wherein the third message includes transaction information;

[0368] The second sending module is configured to send a third response message, where the third response message includes a transaction result.

[0369] Optionally, the NFC-based transaction device further includes:

[0370] A third receiving module, configured to receive a fourth message sent by the terminal, where the fourth message includes the routing table;

[0371] The third sending module is configured to send a fourth response message to the terminal, where the fourth response message includes a result of writing into the routing table.

[0372] Optionally, the NFC-based transaction device further includes:

[0373] a fourth receiving module, configured to receive a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE;

[0374] The fourth sending module is used to send a fifth response message to the terminal, where the fifth response message includes: a writing result of the SE information.

[0375] The device receives a first message for application verification sent by the terminal through a first receiving module 901, and then determines whether an application corresponding to the first message is installed in a currently stored routing table based on the first message. Then, the first sending module 902 sends a first response message to the terminal based on the determination result, so that the terminal sends a second message to the target user identity identification device or embedded security element eSE based on the first response message to realize NFC-based transactions, avoiding the problem that traditional CLE cannot realize the forwarding of NFC contactless transactions and cause business conflicts.

[0376] like Figure 10 As shown, an embodiment of the present invention provides an NFC-based transaction device, applied to a terminal, including:

[0377] A first sending module 1001 is configured to send a first message to a first user identity identification device, where the first message is used for application verification;

[0378] A first receiving module 1002 is configured to receive a first response message sent by a first user identity identification device;

[0379] The second sending module 1003 is configured to send a second message to a target user identity device or an embedded secure element eSE according to the first response message.

[0380] Optionally, the first message includes application identification AID information or logical encryption card Mifare application information.

[0381] Optionally, the first response message includes one of the following:

[0382] Application information;

[0383] Target SE identification information;

[0384] Error message.

[0385] Optionally, the second sending module 1003 includes:

[0386] The first sending submodule is configured to send a second message including transaction information to a target user identification device when the first response message includes application information; wherein the target user identification device is the first user identification device.

[0387] Optionally, the second sending module 1003 includes:

[0388] A second sending submodule is configured to send a second message to a target user identity device when the first response message includes target SE identification information;

[0389] The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

[0390] Optionally, the second sending module 1003 includes:

[0391] The third sending submodule is configured to send the second message to the eSE when the first response message includes error prompt information; wherein the second message includes: AID information or Mifare application information.

[0392] Optionally, the NFC-based transaction device further includes:

[0393] The second receiving module is used to receive the routing table sent by the trusted service management TSM system;

[0394] A third sending module, configured to send a third message to multiple SIM cards of the terminal, where the third message includes the routing table;

[0395] The third receiving module is configured to receive second response messages sent by the plurality of SIM cards, where the second response messages include a routing table writing result.

[0396] Optionally, the NFC-based transaction device further includes:

[0397] A fourth receiving module is configured to receive SE information sent by a trusted service management (TSM) system, wherein the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE;

[0398] a fourth sending module, configured to send a fourth message to at least one SIM card of the terminal respectively, wherein the fourth message includes: SE information of the SIM card receiving the fourth message;

[0399] The fifth receiving module is configured to receive a third response message sent by each of the SIM cards, wherein the third response message includes: a SE information writing result.

[0400] In this way, the device realizes the selection of the SE corresponding to the target application through the information interaction between the terminal and the user identification device, realizes the transmission of transaction data between the client program and the specified user identification device, and avoids the problem of business conflict caused by the inability of traditional CLF to forward NFC contactless transactions.

[0401] A user identification device according to another embodiment of the present invention, such as Figure 11As shown, it includes a transceiver 1110, a processor 1100, a memory 1120, and a program or instruction stored in the memory 1120 and executable on the processor 1100; when the processor 1100 executes the program or instruction, the NFC-based transaction method as described above is implemented.

[0402] The transceiver 1110 is configured to receive and send data under the control of the processor 1100 .

[0403] Among them, Figure 11 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by processor 1100 and memory represented by memory 1120, which are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 1110 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. For different user devices, the user interface 1130 may also be an interface capable of connecting external or internal devices as required, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc.

[0404] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store data used by the processor 1100 when performing operations.

[0405] A terminal according to another embodiment of the present invention is as follows: Figure 12 As shown, it includes: a transceiver 1210, a processor 1200, a memory 1220, and a program or instruction stored in the memory 1220 and executable on the processor 1200; when the processor 1200 executes the program or instruction, the NFC-based transaction method as described above is implemented.

[0406] The transceiver 1210 is configured to receive and send data under the control of the processor 1200 .

[0407] Among them, Figure 12In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by the processor 1200 and various circuits of the memory represented by the memory 1220. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 1210 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. For different user devices, the user interface 1230 may also be an interface capable of connecting external or internal devices as required, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc.

[0408] The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 can store data used by the processor 1200 when performing operations.

[0409] A readable storage medium according to an embodiment of the present invention stores a program or instruction thereon, which, when executed by a processor, implements the steps of the NFC-based transaction method applied to a user identification device, or the steps of the NFC-based transaction method applied to a terminal, and can achieve the same technical effect. To avoid repetition, the description is omitted here. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0410] It should be further noted that the terminals described in this specification include but are not limited to smartphones, tablet computers, etc., and many functional components described are referred to as modules in order to more particularly emphasize the independence of their implementation methods.

[0411] In embodiments of the present invention, modules can be implemented in software so that they can be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions, for example, which can be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but can include different instructions stored in different locations, which, when logically combined together, constitute the module and achieve the specified purpose of the module.

[0412] In fact, executable code module can be a single instruction or many instructions, and can even be distributed on a plurality of different code segments, distributed in the middle of different programs, and distributed across a plurality of memory devices.Similarly, operating data can be identified in the module, and can be implemented and organized in the data structure of any appropriate type according to any appropriate form.Described operating data can be collected as a single data set, or can be distributed in different locations (including on different storage devices), and can only be present on a system or network as an electronic signal at least in part.

[0413] When a module can be implemented using software, given the current state of hardware technology, those skilled in the art can build corresponding hardware circuits to implement the corresponding functions of the module, regardless of cost. The hardware circuits may include conventional very large scale integration (VLSI) circuits or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules may also be implemented using programmable hardware devices, such as field programmable gate arrays, programmable array logic, or programmable logic devices.

[0414] The above exemplary embodiments are described with reference to the accompanying drawings. Many different forms and embodiments are possible without departing from the spirit and teachings of the present invention. Therefore, the present invention should not be construed as limited to the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided so that this disclosure will be complete and perfect and will convey the scope of the invention to those skilled in the art. In the drawings, component sizes and relative sizes may be exaggerated for clarity. The terminology used herein is for the purpose of describing specific exemplary embodiments only and is not intended to be limiting. As used herein, the singular forms "a," "an," and "the" are intended to include plural forms, unless the context clearly indicates otherwise. It will be further understood that the terms "comprising" and / or "including," when used in this specification, indicate the presence of stated features, integers, steps, operations, components, and / or elements, but do not preclude the presence or addition of one or more other features, integers, steps, operations, components, elements, and / or groups thereof. Unless otherwise indicated, when stated, a range of values ​​includes the upper and lower limits of that range and any subranges therebetween.

[0415] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A transaction method based on NFC, applied to a user identification device, characterized in that: include: Receiving a first message sent by a terminal, the first message being used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information, the AID information or the Mifare application information being determined based on the type of NFC device implementing the NFC transaction; Sending a first response message to the terminal based on the first message and the currently stored routing table; the first response message is used to instruct the terminal to send a second message to a target user identity device or embedded secure element eSE; wherein the first response message includes: Application information, where the application information is an application identification code of an application installed in the user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority; The step of sending a first response message to the terminal according to the first message and the currently stored routing table includes: In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information; Sending the first response message to the terminal according to the SE location, the SE activation state, and the AID priority; the first response message includes the application information or the target SE identification information; or, In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table; Sending the first response message to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information; or, When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

2. The method according to claim 1, characterized in that After sending the first response message to the terminal, the method further includes: receiving a third message, wherein the third message includes transaction information; A third response message is sent, where the third response message includes the transaction result.

3. The method according to claim 1, characterized in that The method further comprises: receiving a fourth message sent by a terminal, where the fourth message includes the routing table; A fourth response message is sent to the terminal, where the fourth response message includes a writing result of the routing table.

4. The method according to claim 1, wherein The method further comprises: receiving a fifth message sent by the terminal, where the fifth message includes the SE identification information and an application identification AID of an application installed on the SE; A fifth response message is sent to the terminal, where the fifth response message includes: a writing result of the SE information.

5. A transaction method based on NFC, applied to a terminal, characterized in that: include: Sending a first message to a first user identity device, where the first message is used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information; receiving a first response message sent by a first user identity identification device; Sending a second message to the target user identity device or embedded security element eSE according to the first response message; The first response message includes: Application information, where the application information is an application identification code of an application installed in the first user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; Wherein, when the first message includes AID information and the AID list in the routing table includes the AID information, the first user identity identification device sends the first response message to the terminal based on the SE position, SE activation state, and AID priority corresponding to the AID information determined according to the routing table, including the application information or the target SE identification information; In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, the first user identity identification device sends the first response message to the terminal including the application information or the target SE identification information based on the SE position, SE activation state and Mifare application priority corresponding to the Mifare application information determined by the routing table; When the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list, the first response message sent by the first user identity identification device to the terminal includes the error prompt information; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority.

6. The method according to claim 5, characterized in that Sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes: In a case where the first response message includes application information, a second message including transaction information is sent to a target user identification device; wherein the target user identification device is the first user identification device.

7. The method according to claim 5, characterized in that Sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes: In the case where the first response message includes the target SE identification information, sending a second message to the target user identity device; The second message includes AID information or Mifare application information, and the target user identity device is the SIM card where the SE corresponding to the target SE identification information is located.

8. The method according to claim 5, characterized in that Sending a second message to a target user identity device or an embedded secure element eSE according to the first response message includes: In a case where the first response message includes error prompt information, the second message is sent to the eSE; wherein the second message includes: AID information or Mifare application information.

9. The method according to claim 5, characterized in that Before sending the first message to the first user identification device, the method further includes: Receive the routing table sent by the Trusted Service Management TSM system; Sending a third message to multiple user identity identification devices of the terminal, wherein the third message includes the routing table; A second response message sent by the plurality of user identity identification devices is received, where the second response message includes a routing table writing result.

10. The method according to claim 5, characterized in that The method further comprises: Receive SE information sent by the Trusted Service Management TSM system, where the SE information includes the SE identification information of each SIM card and the AID of the application installed by the SE; sending a fourth message to at least one user identity identification device of the terminal respectively, wherein the fourth message includes: SE information of the user identity identification device receiving the fourth message; Receive a third response message sent by each of the user identity identification devices, where the third response message includes: a SE information writing result.

11. A user identification device, characterized in that: Including transceiver; The transceiver is used to receive a first message sent by the terminal, the first message being used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information, the AID information or the Mifare application information being determined based on the type of NFC device implementing the NFC transaction; The transceiver is further configured to send a first response message to the terminal based on the first message and the currently stored routing table; the first response message is used to instruct the terminal to send a second message to a target user identity device or an embedded secure element (eSE); wherein the first response message includes: Application information, where the application information is an application identification code of an application installed in the user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority; When the transceiver is configured to send a first response message to the terminal according to the first message and the currently stored routing table, the transceiver is specifically configured to: In a case where the first message includes AID information and the AID list in the routing table includes the AID information, determining, according to the routing table, a SE location, a SE activation state, and an AID priority corresponding to the AID information; Sending the first response message to the terminal according to the SE location, the SE activation state, and the AID priority; the first response message includes the application information or the target SE identification information; or, In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, determining the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table; Sending the first response message to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information; or, When the first message includes AID information and the AID information is not in the AID list, or when the first message includes Mifare application information and the Mifare application information is not in the Mifare application list, a first response message including error prompt information is sent to the terminal.

12. A terminal, characterized in that: include: transceiver; The transceiver is used for: Sending a first message to a first user identity device, where the first message is used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information; receiving a first response message sent by a first user identity identification device; Sending a second message to the target user identity device or embedded security element eSE according to the first response message; The first response message includes: Application information, where the application information is an application identification code of an application installed in the first user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; Wherein, when the first message includes AID information and the AID list in the routing table includes the AID information, the first user identity identification device sends the first response message to the terminal based on the SE position, SE activation state, and AID priority corresponding to the AID information determined according to the routing table, including the application information or the target SE identification information; In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, the first user identity identification device sends the first response message to the terminal including the application information or the target SE identification information based on the SE position, SE activation state and Mifare application priority corresponding to the Mifare application information determined by the routing table; When the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list, the first response message sent by the first user identity identification device to the terminal includes the error prompt information; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority.

13. A transaction device based on NFC, applied to a user identification device, characterized in that: include: A first receiving module is configured to receive a first message sent by a terminal, the first message being used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information, the AID information or the Mifare application information being determined based on the type of NFC device implementing the NFC transaction; a first sending module, configured to send a first response message to the terminal based on the first message and the currently stored routing table; the first response message is used to instruct the terminal to send a second message to a target user identity device or an embedded secure element (eSE); wherein the first response message includes: Application information, where the application information is an application identification code of an application installed in the user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority; Wherein, the first sending module includes: a first determining submodule, configured to, when the first message includes AID information and the AID list in the routing table includes the AID information, determine, according to the routing table, a SE position, a SE activation state, and an AID priority corresponding to the AID information; A first sending submodule, configured to send the first response message to the terminal according to the SE location, the SE activation state, and the AID priority; the first response message includes the application information or the target SE identification information; or, A second determination submodule is configured to determine, when the first message includes Mifare application identification information and the Mifare application list in the routing table includes the Mifare application information, the SE position, SE activation state, and Mifare application priority corresponding to the Mifare application information according to the routing table; A second sending submodule is configured to send the first response message to the terminal according to the SE location, the SE activation state and the Mifare application priority; the first response message includes the application information or the target SE identification information; or, The third sending submodule is used to send a first response message including error prompt information to the terminal when the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list.

14. A transaction device based on NFC, applied to a terminal, characterized in that: include: A first sending module is configured to send a first message to a first user identity identification device, where the first message is used for application verification; wherein the first message includes application identification AID information or logical encryption card Mifare application information; A first receiving module, configured to receive a first response message sent by a first user identity identification device; A second sending module is configured to send a second message to a target user identity device or an embedded security element eSE according to the first response message; The first response message includes: Application information, where the application information is an application identification code of an application installed in the first user identification device and applicable to the first message; Target SE identification information, where the target SE identification information is the identification information of the SE that has installed the application applicable to this NFC-based transaction; Error prompt information, where the error prompt information is information for reminding the SE that the application for the NEC-based transaction is not installed on any of the multiple user identity identification devices installed on the terminal; Wherein, when the first message includes AID information and the AID list in the routing table includes the AID information, the first user identity identification device sends the first response message to the terminal based on the SE position, SE activation state, and AID priority corresponding to the AID information determined according to the routing table, including the application information or the target SE identification information; In a case where the first message includes Mifare application identification information and the Mifare application list of the routing table includes the Mifare application information, the first user identity identification device sends the first response message to the terminal including the application information or the target SE identification information based on the SE position, SE activation state and Mifare application priority corresponding to the Mifare application information determined by the routing table; When the first message includes AID information and the AID information is not included in the AID list, or when the first message includes Mifare application information and the Mifare application information is not included in the Mifare application list, the first response message sent by the first user identity identification device to the terminal includes the error prompt information; The routing table includes: the correspondence between the secure element SE location, SE activation status, AID list, AID priority, Mifare application list and Mifare application priority.

15. A user identification device, comprising: A transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; wherein the processor implements the NFC-based transaction method according to any one of claims 1 to 4 when executing the program or instruction.

16. A terminal comprising: A transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; wherein the processor implements the NFC-based transaction method according to any one of claims 5 to 10 when executing the program or instruction.

17. A readable storage medium having a program or instruction stored thereon, characterized in that: When the program or instruction is executed by a processor, the steps of the NFC-based transaction method according to any one of claims 1 to 4 or the steps of the NFC-based transaction method according to any one of claims 5 to 10 are implemented.

Citation Information

Patent Citations

  • Near field communication payment method and terminal

    CN107251069A