A server and a mobile intelligent terminal based on an information security transmission verification method for electronic cards

Through the two-way verification and QR code information interaction between the mobile smart terminal and the server, the problem of electronic card verification relying on a dedicated network in the existing technology is solved, and electronic card information verification and secure transmission in the internal network environment is realized.

CN114900832BActive Publication Date: 2025-06-13YILIANZHONG INTELLIGENT (XIAMEN) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210445502.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-01-30
Publication Date
2025-06-13
Estimated Expiration
2039-01-30

AI Technical Summary

Technical Problem

The existing electronic card verification method relies on a dedicated network and cannot be verified in an internal network environment. The dedicated network fails or the server is busy, which affects business processing.

Method used

Through the mobile smart terminal and server, the information exchange is performed by two-way verification and information transmission, and the QR code is used to communicate directly on the Internet, and information segmented encrypted transmission is realized.

Benefits of technology

The electronic card information verification can be completed without a dedicated network, avoiding network failures and information acquisition failures caused by busy servers, and improving the efficiency and security of electronic card information transmission verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114900832B_ABST
    Figure CN114900832B_ABST
Patent Text Reader

Abstract

A server and a mobile intelligent terminal based on an information security transmission and verification method for an electronic card communicate through the user's mobile intelligent terminal and the server. Bidirectional information interaction is carried out between the mobile intelligent terminal and the electronic card reading device through a two-dimensional code. Information interaction can be realized between the electronic card reading device and the server without direct network communication, improving the drawback that the traditional electronic card verification method requires information transmission and parsing through a dedicated line. Moreover, the information is encrypted and transmitted in segments to ensure that all information can be effectively transmitted and the security of information transmission at the same time. The server and the mobile intelligent terminal based on the information security transmission and verification method for an electronic card provided by the present invention can avoid the situation that relevant electronic card information cannot be obtained due to the disconnection of the dedicated network or the server being busy and unable to respond in time, and improve the efficiency and security of electronic card information transmission and verification.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with the application date of January 30, 2019, the application number of 201910093593.3, and the invention title of "A Secure Transmission Verification Method for Electronic Card Information". Technical Field

[0002] The present invention relates to the field of information transmission verification methods, and particularly to a server and a mobile intelligent terminal based on a secure transmission verification method for electronic card information. Background Art

[0003] Currently, for many electronic cards such as electronic health cards and electronic social security cards, after being scanned by an electronic card reading device, the computer connected to the electronic card reading device generally needs to transmit the scanned information to the corresponding server through a dedicated network. The server decodes to obtain user-related information, and then returns the user information to the electronic card reading device through the dedicated network to achieve the verification of the electronic card. The process can be referred to Figure 1 .

[0004] The existing electronic card verification methods have certain limitations. They can only perform transmission verification by accessing the server through a dedicated network. However, for the electronic card business handling terminals in many scenarios such as government departments and hospitals, there is only an internal network, which is not of the same type as the network of the electronic card server, and they cannot connect to the corresponding external server to verify the electronic card information, resulting in the inability of the business handling terminal to parse the electronic card information. Even in some scenarios where there is corresponding external network access permission and they can access the external server through a dedicated network, when the dedicated network line is disconnected or the server is busy, the business handling terminal cannot continue to perform information verification and acquisition, seriously affecting the on-site business handling of users.

[0005] Therefore, this case provides a server and a mobile intelligent terminal based on a secure transmission verification method for electronic card information to solve the above problems. Summary of the Invention

[0006] To solve the deficiencies mentioned in the above-mentioned prior art, the present invention provides a server and a mobile intelligent terminal based on a secure transmission verification method for electronic card information, which complete the two-way verification and information transmission between the electronic card business handling terminal and the server through the mobile intelligent terminal, so as to break the limitation of the dedicated network, avoid the inability to identify and obtain the electronic card information due to the failure of the dedicated network or the busyness of the server, and ensure the security and reliability of the electronic card information transmission.

[0007] To achieve the above object, a server based on a secure transmission verification method for electronic card information provided by the present invention, the secure transmission verification method for electronic card information executed by the server includes the following steps:

[0008] S100: Receive a service request and verify the validity of the user service request information, where the request at least includes the user information bound to the electronic card;

[0009] S200: Verify the legitimacy of the electronic card reader device and return the legitimacy verification information of the electronic card reader device. If the verification is successful, execute step S300;

[0010] S300: Receive the operation random number, device ID, and PSAM card ID obtained after the mobile intelligent terminal scans the QR code. The generation steps of the QR code are as follows: First, generate an operation random number through the electronic card reader device and record it, and then generate a QR code including the operation random number, device ID, and PSAM card ID through a computer;

[0011] S400: Respond to the service request of the mobile intelligent terminal, retrieve the user information bound to the electronic card, and calculate the corresponding key according to the PSAM card ID obtained from step S300;

[0012] S500: After encrypting the user information, adding the operation random number, and performing segmentation processing, obtain the segmented message of the user information and send it to the mobile intelligent terminal respectively; the encryption is performed using the key calculated in step S400 during encryption;

[0013] S600: Send each segment of the message to the mobile intelligent terminal and successively convert each segment of the message into a QR code for display; the electronic card reader device scans and recognizes the QR code to obtain the segmented message; after all the segmented messages are received, decrypt and merge each segmented message, and verify whether the parsed operation random number is consistent with the operation random number stored in the electronic card reader device. If they are consistent, the verification passes, and then the user information is transmitted to the computer;

[0014] S700: After completing the verification of the electronic card user information, enable the business system in the computer to perform corresponding business operations according to the received user information;

[0015] Among them, the method for verifying the legitimacy of the electronic card reader device in step S200 specifically includes the following steps:

[0016] S201: Generate a verification random number and store it, then send the verification random number to the mobile intelligent terminal, and then display the verification random number in the form of a QR code through the mobile intelligent terminal. Subsequently, the electronic card reader device scans and recognizes the QR code on the mobile intelligent terminal to obtain the verification random number, and then encrypts the verification random number through the PSAM card installed inside the electronic card reader device to obtain the encrypted random number. Finally, the electronic card reader device sends the processed encrypted random number to the computer connected to the electronic card reader device and displays it in the form of a QR code on the computer monitor,

[0017] S202: Receive the data converted from the QR code scanned by the mobile intelligent terminal on the computer, then decrypt the encrypted random number, compare the obtained decrypted random number with the sent verification random number. If they are the same, it means the electronic card reader device is legal and the verification of the electronic card reader device is successful.

[0018] The method for returning the legality verification information of the electronic card reader device in step S200 specifically includes the following steps: Return the device verification information to the mobile intelligent terminal, then generate a corresponding QR code through the mobile intelligent terminal, and the electronic card reader device scans and identifies the QR code on the mobile intelligent terminal to obtain the returned legality verification information of the electronic card reader device.

[0019] In some embodiments, the specific steps for obtaining the segmented message of user information in step S500 can adopt any one of the following processing methods:

[0020] 1. First encrypt the user information, segment the encrypted user information, add an operation random number and a sequence number identifier to the header of each segment of the message, and add an end identifier to the last segment of the message; encrypt each segment of the message with the added operation random number again to obtain the segmented message of user information.

[0021] 2. First encrypt the user information, segment the encrypted user information, add an operation random number and a sequence number identifier to the header of each segment of the message, and add an end identifier to the last segment of the message to obtain the segmented message of user information.

[0022] 3. First add an operation random number to the header of the user information, encrypt the user information with the added operation random number, segment the encrypted user information, add a sequence number identifier to each segment of the message, and add an end identifier to the last segment of the message to obtain the segmented message of user information.

[0023] 4. First segment the user information, add an operation random number and a sequence number identifier to the header of each segment of the message, and add an end identifier to the last segment of the message; encrypt each segment of the information separately to obtain the segmented message of user information.

[0024] In some embodiments, in step S600, the electronic card reader device sequentially scans and identifies the QR code on the mobile intelligent terminal to obtain the segmented message. In addition, the electronic card reader device can be a multi-card mobile intelligent terminal.

[0025] To achieve the above object, the present invention also provides a mobile intelligent terminal based on the electronic card information security transmission verification method. The electronic card information security transmission verification method executed by the mobile intelligent terminal includes the following steps:

[0026] S100: Send a service request to the server to enable the server to verify the validity of the user service request information. The server verifies the legality of the electronic card reading device and returns the legality verification information of the electronic card reading device. If the verification is successful, execute step S200. Among them, the request includes at least the user information bound to the electronic card;

[0027] S200: After scanning the QR code, obtain the operation random number, device ID, and PSAM card ID. The generation steps of the QR code are as follows: First, generate an operation random number through the electronic card reading device and record it. Then, generate a QR code including the operation random number, device ID, and PSAM card ID through a computer;

[0028] S300: The service request sent is responded to by the server. The server retrieves the user information bound to the electronic card and calculates the corresponding key according to the PSAM card ID obtained from step S200;

[0029] S400: Receive the segmented message from the server. The generation steps of the segmented message are as follows: The server encrypts the user information, adds the operation random number, and performs segmentation processing to obtain the segmented message of the user information. Among them, the encryption is performed using the key calculated in step S300;

[0030] S500: Obtain each segment of the message from the server and successively convert each segment of the message into a QR code for display;

[0031] S600: The electronic card reading device scans and identifies the QR code to obtain the segmented message; after all the segmented messages are received, decrypt and merge each segmented message, and verify whether the parsed operation random number is consistent with the operation random number stored inside the electronic card reading device. If it is consistent, the verification passes, and then the user information is transmitted to the computer;

[0032] S700: Complete the verification of the electronic card user information. The business system in the computer performs corresponding business operations according to the received user information;

[0033] Among them, the method for verifying the legality of the electronic card reading device in step S100 specifically includes the following steps:

[0034] S101: Receive the verification random number from the server and display the verification random number in the form of a QR code. The verification random number is generated by the server and stored internally;

[0035] S102: The electronic card reading device scans and identifies the QR code on the mobile intelligent terminal to obtain the verification random number; encrypt the verification random number through the PSAM card installed inside the electronic card reading device to obtain the encrypted random number;

[0036] S103: The electronic card reader device sends the processed encrypted random number to the computer connected to the electronic card reader device and displays it in the form of a QR code on the computer monitor;

[0037] S104: Scan the QR code on the computer, convert it into data and send it to the server. The server decrypts the encrypted random number, compares the obtained decrypted random number with the sent verification random number. If they are the same, it means the electronic card reader device is legal and the verification of the electronic card reader device is successful;

[0038] Among them, the method for returning the legitimacy verification information of the electronic card reader device in step S100 specifically includes the following steps: receiving the device verification information sent by the server, generating a corresponding QR code, and having the electronic card reader device scan and identify the QR code on the mobile intelligent terminal to obtain the returned legitimacy verification information of the electronic card reader device.

[0039] A server and a mobile intelligent terminal for an electronic card information secure transmission verification method provided by the present invention communicate through the user's mobile intelligent terminal and the server. Bidirectional information interaction is carried out between the mobile intelligent terminal and the electronic card reader device through QR codes. Information interaction can be achieved between the electronic card reader device and the server without direct network communication, improving the drawback that the traditional electronic card verification method requires information transmission and parsing through a dedicated line; and encrypting and transmitting information in segments to ensure that all information can be effectively transmitted and at the same time ensure the security of information transmission. The secure transmission verification method for electronic card information provided by the present invention does not require the use of a dedicated network, can avoid the situation where the electronic card-related information cannot be obtained due to the disconnection of the dedicated network or the server being busy and unable to respond in time, and improves the efficiency and security of electronic card information transmission verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0041] Figure 1 It is a schematic diagram of the existing electronic card information transmission verification method;

[0042] Figure 2 It is a schematic diagram of the secure transmission verification method for electronic card information provided by the present invention;

[0043] Figure 3 It is a schematic flowchart of the secure transmission verification method for electronic card information provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0045] The embodiments of the present invention provide a server and a mobile intelligent terminal for a security transmission verification method based on electronic card information. The security transmission verification method executed by the server and the mobile intelligent terminal can be used by users of electronic cards such as electronic social security cards, electronic medical insurance cards, electronic identity cards, and electronic health cards to authenticate the electronic cards on a service handling terminal, so that the service handling terminal can securely obtain the user information of the electronic card from the server. The service handling terminal in the embodiments of the present invention can be a computer or a self-service machine connected with an electronic card reading device.

[0046] As Figure 2 、 Figure 3 shown, it is a schematic flowchart of the security transmission verification method for electronic card information provided by the embodiments of the present invention, including the following steps:

[0047] S100: The mobile intelligent terminal sends a service request to the server, and the request includes at least the user information bound to the electronic card.

[0048] Specifically, in the present invention, the mobile intelligent terminal is a mobile intelligent terminal bound with an electronic card, which has at least the functions of display, camera, and communication, and can be a mobile phone, a laptop computer, or a PAD. The user holding the electronic card operates on the mobile intelligent terminal bound with the electronic card and sends a service request to the server, and the request includes at least obtaining the user information bound to the electronic card.

[0049] S200: The server verifies the validity of the user service request information.

[0050] Specifically, after receiving the service request sent by the mobile intelligent terminal, the server verifies the validity of the service request information, including whether it has the requested electronic card user information, whether the status of the electronic card user information allows the corresponding service request, etc. If the user service request information is invalid, an information indicating verification failure is returned. If the user service request information is valid, step S300 is executed.

[0051] S300: The server verifies the legality of the electronic card reading device and returns the legality verification information of the electronic card reading device. If the verification is successful, step S400 is executed.

[0052] Specifically, after the server validates the user service request information and before responding to the service request, it is necessary to first verify whether the electronic card reading device of the service handling terminal is legal. The specific verification method includes:

[0053] S301: The server generates a verification random number and stores it internally, and then sends it to the mobile intelligent terminal. Through the mobile intelligent terminal, the verification random number is displayed in the form of a two-dimensional code.

[0054] S302: The electronic card reading device scans and recognizes the two-dimensional code on the mobile intelligent terminal to obtain the verification random number; the verification random number is encrypted through the PSAM card installed inside the electronic card reading device to obtain an encrypted random number.

[0055] S303: The electronic card reading device sends the processed encrypted random number to the computer connected to the electronic card reading device and displays it in the form of a two-dimensional code on the computer monitor.

[0056] S304: The mobile intelligent terminal scans the two-dimensional code on the computer, converts it into data and sends it to the server. The server decrypts the encrypted random number and compares the obtained encrypted random number with the sent verification random number. If they are the same, it means that the electronic card reading device is legal and the verification of the electronic card reading device is successful.

[0057] After the server completes the verification of the legality of the electronic card reading device, it returns the device verification information to the mobile intelligent terminal. Then, through the mobile intelligent terminal, the verification information is generated into a corresponding two-dimensional code, and the electronic card reading device scans the two-dimensional code on the mobile intelligent terminal to obtain the returned legality verification information of the electronic card reading device. If the returned information is verification success, step S400 is executed; if the verification fails, it ends.

[0058] S400: The electronic card reading device generates an operation random number and records it, and then generates a two-dimensional code including the operation random number, device ID, and PSAM card ID through the computer. After being scanned by the mobile intelligent terminal, it is sent to the server.

[0059] Specifically, after the legitimacy verification of the electronic card reading device is successful, the electronic reading device will generate and record an operation random number, and then generate a QR code including information such as the operation random number, the device ID of the electronic reading device, and the PSAM card ID inside the electronic reading device through the computer. The mobile intelligent terminal scans the QR code to obtain the corresponding information and then sends it to the server. Preferably, the operation random number, device ID, and PSAM card ID obtained by the mobile intelligent terminal through scanning the QR code are encrypted before being sent to the server. The operation random number is a value used by the PSAM card to record the current operation, with a total of 32 bits. Each time an operation starts, it will be randomly generated until the operation is completed or abandoned midway. The operation random number is used to be added to the user information to be sent by the server to ensure that the user information sent by the server can only be used once, preventing someone from storing the user information sent by the server and using it multiple times. The device ID of the electronic reading device and the PSAM card ID are used to ensure that the server can perceive and record the on-site information of each business transaction, such as the location of the device used, etc.

[0060] S500: The server responds to the service request of the mobile intelligent terminal, retrieves the user information bound to the electronic card, and calculates the corresponding key based on the PSAM card ID obtained from step S400.

[0061] Specifically, after the server receives information such as the operation random number, the device ID of the electronic reading device, and the PSAM card ID inside the electronic reading device returned by the electronic card reading device, it retrieves the service request sent by the mobile intelligent terminal in step S100 and retrieves the user information bound to the corresponding electronic card; and calculates the key corresponding to the PSAM card based on the PSAM card ID obtained from step S400 (each PSAM card has its own unique key for decrypting the message).

[0062] S600: After the server encrypts the user information, adds the operation random number, and performs segmented processing, it obtains segmented messages of the user information and sends them to the mobile intelligent terminal respectively; during encryption, the key calculated in step S500 is used for encryption.

[0063] Specifically, after the server retrieves the corresponding user information, it encrypts the user information, adds the operation random number, and performs segmented processing; any one of the following processing methods can be specifically adopted:

[0064] 1. First, encrypt the user information, segment the encrypted user information, add the operation random number and sequence number identifier to the header of each segment message, and add an end identifier to the last segment message; encrypt each segment message with the added operation random number again to obtain the segmented message of the user information.

[0065] 2. First, encrypt the user information, segment the encrypted user information, add an operation random number and a sequence number identifier to the header of each segment of the message, and add an end identifier to the last segment of the message to obtain the segmented message of the user information.

[0066] 3. First, add an operation random number to the header of the user information, encrypt the user information with the added operation random number, segment the encrypted user information, add a sequence number identifier to each segment of the message, and add an end identifier to the last segment of the message to obtain the segmented message of the user information.

[0067] 4. First, segment the user information, add an operation random number and a sequence number identifier to the header of each segment of the message, and add an end identifier to the last segment of the message; encrypt each segment of information separately to obtain the segmented message of the user information.

[0068] Among them, the segmentation process is to divide the data of the user information into several segments according to the set data length. For example, if the total data of the user information is 1024 bytes, the data length of each segment is set to 400 bytes. Then the user can be divided into 3 segments of messages in total, and the part with insufficient length is filled with 0.

[0069] After the user information is encrypted, the operation random number is added, and the segmentation process is performed, multi-segment segmented messages are formed and sent to the mobile intelligent terminal respectively.

[0070] S700: The mobile intelligent terminal obtains each segment of the message from the server and converts each segment of the message into a two-dimensional code for display successively;

[0071] Specifically, the mobile intelligent terminal obtains each segment of the message of the user information generated in step S600 from the server, and according to the sequence number identifier and the end identifier in each segmented message, converts each segment of the message into a two-dimensional code for display successively.

[0072] S800: The electronic card reading device scans and identifies the two-dimensional code on the mobile intelligent terminal successively to obtain the segmented message; after all the segmented messages are received, decrypt and merge each segmented message, and verify whether the parsed operation random number is consistent with the operation random number stored in the electronic card reading device internally. If they are consistent, the verification passes, and then the user information is transmitted to the computer;

[0073] Specifically, the electronic card reading device sequentially scans and identifies the two-dimensional codes containing each segment of the message on the mobile intelligent terminal, obtains the segmented message data therein. After all the segmented messages are received, the electronic card reading device decrypts the obtained segmented messages, and then merges the segmented messages according to the sequence identifiers and end identifiers in each segmented message, or first merges the segmented messages according to the sequence identifiers and end identifiers in each segmented message, and then decrypts them to obtain the complete user information and the operation random number added in step S600; the specific order of decryption and merging can be adjusted according to the generation method of each segment of the message of the user information adopted in step S600; and verify whether the operation random number carried in the parsed message is consistent with the operation random number recorded in step S400; if they are consistent, it is considered that the user information is valid, and then the user information is transmitted to the computer.

[0074] S900: Complete the verification of the electronic card user information, and the business system in the computer performs corresponding business operations according to the received user information.

[0075] Specifically, the computer receives the user information sent by the electronic card reading device, completes the verification of the electronic card user information, and the user can perform corresponding business operations through the business system in the computer.

[0076] The secure transmission verification method for electronic card information provided by the embodiments of the present invention communicates between the user's mobile intelligent terminal and the server. The mobile intelligent terminal and the electronic card reading device perform two-way information interaction through two-dimensional codes. The electronic card reading device and the server can achieve information interaction without direct network communication, improving the drawbacks of the traditional electronic card verification method that requires information transmission and parsing through dedicated lines; and encrypts and transmits the information in segments to ensure the effective transmission of all information and the security of information transmission at the same time. The secure transmission verification method for electronic card information provided by the embodiments of the present invention does not require the use of a dedicated network, and can avoid the situation where the relevant electronic card information cannot be obtained due to the disconnection of the dedicated network or the server being busy and unable to respond in time, improving the efficiency and security of the electronic card information transmission verification.

[0077] Although terms such as electronic card, electronic card reading device, business handling terminal, server, mobile intelligent terminal, etc. are used more in this article, the possibility of using other terms is not excluded. Using these terms is only to more conveniently describe and explain the essence of the present invention; interpreting them as any additional limitation is contrary to the spirit of the present invention.

[0078] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A server based on an electronic card information security transmission verification method, characterized in that: The electronic card information security transmission verification method executed by the server includes the following steps: S100: Receive a service request and verify the validity of the user service request information, where the request at least includes the user information bound to the electronic card; S200: Verify the legitimacy of the electronic card reading device and return the electronic card reading device legitimacy verification information. If the verification is successful, execute step S300; S300: Receive the operation random number, device ID, and PSAM card ID obtained after the mobile intelligent terminal scans the two-dimensional code. The generation steps of the two-dimensional code are as follows: First, generate an operation random number through the electronic card reading device and record it, and then generate a two-dimensional code including the operation random number, device ID, and PSAM card ID through a computer; S400: Respond to the service request of the mobile intelligent terminal, retrieve the user information bound to the electronic card, and calculate the corresponding key according to the PSAM card ID obtained from step S300; S500: After encrypting the user information, adding the operation random number, and performing segmentation processing, obtain the segmented message of the user information and send it to the mobile intelligent terminal respectively; where the encryption is performed using the key calculated in step S400; S600: Send each segment of the message to the mobile intelligent terminal and successively convert each segment of the message into a two-dimensional code for display; the electronic card reading device scans and recognizes the two-dimensional code to obtain the segmented message; after all the segmented messages are received, decrypt and merge each segmented message, and verify whether the parsed operation random number is consistent with the operation random number stored in the internal memory of the electronic card reading device. If they are consistent, the verification passes, and then the user information is transmitted to the computer; S700: After completing the verification of the electronic card user information, enable the service system in the computer to perform corresponding service operations according to the received user information; Among them, the method for verifying the legitimacy of the electronic card reading device in step S200 specifically includes the following steps: S201: Generate a verification random number and store it, then send the verification random number to the mobile intelligent terminal, and then display the verification random number in the form of a two-dimensional code through the mobile intelligent terminal. Subsequently, the electronic card reading device scans and recognizes the two-dimensional code on the mobile intelligent terminal to obtain the verification random number, and then encrypts the verification random number through the PSAM card installed inside the electronic card reading device to obtain the encrypted random number. Finally, the electronic card reading device sends the processed encrypted random number to the computer connected to the electronic card reading device and displays it in the form of a two-dimensional code on the computer monitor, S202: Receive the data converted from the two-dimensional code scanned by the mobile intelligent terminal on the computer, decrypt the encrypted random number, and compare the obtained decrypted random number with the sent verification random number. If they are the same, it means that the electronic card reading device is legitimate and the electronic card reading device verification is successful; The method for returning the legality verification information of the electronic card reading device in step S200 specifically includes the following steps: Return the device verification information to the mobile intelligent terminal, then generate a corresponding two-dimensional code through the mobile intelligent terminal, and the electronic card reading device scans and identifies the two-dimensional code on the mobile intelligent terminal to obtain the returned legality verification information of the electronic card reading device.

2. The server for an electronic card information security transmission verification method according to claim 1, wherein: The specific steps for obtaining the segmented message of the user information in step S500 include: First, encrypt the user information, segment the encrypted user information, add an operation random number and a sequence number identifier to the header of each segment, and add an end identifier to the last segment; encrypt each segment of the message with the added operation random number again to obtain the segmented message of the user information; Or, first encrypt the user information, segment the encrypted user information, add an operation random number and a sequence number identifier to the header of each segment, and add an end identifier to the last segment to obtain the segmented message of the user information; Or, first add an operation random number to the header of the user information, encrypt the user information with the added operation random number, segment the encrypted user information, add a sequence number identifier to each segment, and add an end identifier to the last segment to obtain the segmented message of the user information; Or, first segment the user information, add an operation random number and a sequence number identifier to the header of each segment, and add an end identifier to the last segment; encrypt each segment of information separately to obtain the segmented message of the user information.

3. The server for an electronic card information security transmission verification method according to claim 1, wherein: In step S600, the electronic card reading device scans and identifies the two-dimensional code on the mobile intelligent terminal one by one to obtain the segmented message.

4. A mobile intelligent terminal for an electronic card information security transmission verification method, wherein: The electronic card information security transmission verification method executed by the mobile intelligent terminal includes the following steps: S100: Send a service request to the server to enable the server to verify the validity of the user service request information, the server verifies the legality of the electronic card reading device, and returns the legality verification information of the electronic card reading device. If the verification is successful, execute step S200, where the request at least includes the user information bound to the electronic card; S200: After scanning the two-dimensional code, obtain the operation random number, device ID, and PSAM card ID. The generation steps of the two-dimensional code are: first, generate an operation random number through the electronic card reading device and record it, and then generate a two-dimensional code including the operation random number, device ID, and PSAM card ID through a computer; S300: The service request sent is responded to by the server. The server retrieves the user information bound to the electronic card and calculates the corresponding key according to the PSAM card ID obtained from step S200; S400: Receive the segmented message from the server. The generation steps of the segmented message are as follows: After the server encrypts the user information, adds the operation random number, and performs segmentation processing, the segmented message of the user information is obtained, where the encryption is performed using the key deduced in step S300; S500: Obtain each segment of the message from the server and successively convert each segment of the message into a QR code for display; S600: The electronic card reading device scans and identifies the QR code to obtain the segmented message; after all the segmented messages are received, decrypt and merge each segmented message, and verify whether the operation random number parsed out is consistent with the operation random number stored inside the electronic card reading device. If they are consistent, the verification passes, and then the user information is transmitted to the computer; S700: Complete the verification of the electronic card user information, and the business system in the computer performs corresponding business operations according to the received user information; Among them, the method for verifying the legitimacy of the electronic card reading device in step S100 specifically includes the following steps: S101: Receive the verification random number from the server and display the verification random number in the form of a QR code. The verification random number is generated and stored inside the server; S102: The electronic card reading device scans and identifies the QR code on the mobile intelligent terminal to obtain the verification random number; encrypt the verification random number through the PSAM card installed inside the electronic card reading device to obtain the encrypted random number; S103: The electronic card reading device sends the processed encrypted random number to the computer connected to the electronic card reading device and displays it in the form of a QR code on the computer display; S104: Scan the QR code on the computer, convert it into data and send it to the server. The server decrypts the encrypted random number, and compares the obtained decrypted random number with the sent verification random number. If they are the same, it means that the electronic card reading device is legitimate and the verification of the electronic card reading device is successful; Among them, the method for returning the verification information of the legitimacy of the electronic card reading device in step S100 specifically includes the following steps: Receive the device verification information sent from the server and generate the corresponding QR code. The electronic card reading device scans and identifies the QR code on the mobile intelligent terminal to obtain the returned verification information of the legitimacy of the electronic card reading device.

5. The mobile intelligent terminal according to claim 4, a method for verifying the secure transmission of electronic card information, characterized in that: The generation steps of the segmented message in step S400 include: The server first encrypts the user information, segments the encrypted user information, adds the operation random number and the serial number identifier to the header of each segment of the message, and adds the end identifier to the last segment of the message; encrypt each segment of the message with the added operation random number again to obtain the segmented message of the user information; Or, the server first encrypts the user information, segments the encrypted user information, adds the operation random number and the serial number identifier to the header of each segment of the message, and adds the end identifier to the last segment of the message to obtain the segmented message of the user information; Alternatively, the server first adds an operation random number to the user information header, encrypts the user information with the operation random number added, segments the encrypted user information, adds a sequence number identifier to each segment of the message, and adds an end identifier to the last segment of the message to obtain segmented messages of the user information; Alternatively, the server first segments the user information, adds an operation random number and a sequence number identifier to the header of each segment of the message, and adds an end identifier to the last segment of the message; encrypts each segment of information separately to obtain segmented messages of the user information.

6. The mobile intelligent terminal according to a method for verifying secure transmission of electronic card information as claimed in claim 4, characterized in that: In step S600, the electronic card reading device sequentially scans and identifies the two-dimensional code on the mobile intelligent terminal to obtain segmented messages.

Citation Information

Patent Citations

  • Verification method, system, user equipment and server based on interactive operation

    CN105681351A

  • System and Method for Quickly Obtaining Medical Information

    US20140070012A1