Smart card sector management method and system

Through the smart card sector management method and system, the problem of missing key security control in multiple application scenarios is solved, the application selection and access control are realized, and the management efficiency and user experience of smart card are improved.

CN115827001BActive Publication Date: 2025-08-19CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211434347.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-16
Publication Date
2025-08-19
Estimated Expiration
2042-11-16

AI Technical Summary

Technical Problem

The existing technology cannot effectively manage the M1 sector of smart card in multiple application scenarios, resulting in the lack of key security control. Especially when multiple non-connection applications coexist, non-connection parameters such as UID conflict or disorder, affecting the card swiping experience.

Method used

Through the collaborative work of the secondary management platform and the primary management platform, we can judge the installation status of the application in the M1 area of the smart card, establish an exclusive application download and installation channel, perform version updates or key changes, and allocate M1 sectors to new applications, generate dedicated access control rules, and use static or dynamic key algorithms for security management.

Benefits of technology

It realizes accurate application selection and access control in multiple application concurrency scenarios, improves the management flexibility and convenience of smart cards, avoids UID conflicts, and improves the card swipe experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115827001B_ABST
    Figure CN115827001B_ABST
Patent Text Reader

Abstract

The present invention discloses a smart card sector management method and system, the method comprising: an application system sends an application installation request for a contactless application to a primary management platform via a secondary management platform; the primary management platform obtains information of the smart card based on the application installation request, and determines whether the contactless application is a new application not installed in the M1 area of the smart card; if the contactless application is an application already installed in the M1 area of the smart card, the primary management platform generates authorization information and sends it to the application system, and establishes a dedicated application download and installation channel so that the application system completes the version update or key change of the contactless application through the dedicated application download and installation channel; and if the contactless application is a new application not installed in the M1 area of the smart card, the primary management platform generates authorization information and notifies the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector. Utilizing the method of the present invention, precise application selection and access control in multi-application concurrent scenarios can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a smart card sector management method and system. Background Art

[0002] With the increasing intelligence and ubiquity of mobile Internet, smart cards, especially SIM cards, are playing an increasingly critical role in terminal security due to their unique hardware security and connectivity advantages. The types and number of applications carried on them have also increased significantly. They have evolved from traditional menu methods such as STK in the early days to intelligent, diversified, and platform-based methods. Smart SIM cards have become an indispensable hardware encryption machine inside terminals. Their security, storage, computing and other capabilities play an important role in enhancing the security of mobile applications.

[0003] However, the card applications in smart SIM cards, especially the carrying and management methods of key configuration data, have not been upgraded accordingly. In particular, for M1 smart cards with contactless functions such as NFC, default keys are mostly used, there is no multi-level iteration mechanism, and the users lack a coordinated planning for the occupation of M1 sectors, resulting in a lack of key security management. Especially when multiple contactless applications coexist, contactless parameters such as UID will conflict or become disordered, causing conflicts when carrying multiple services, seriously affecting the user experience of contactless functions such as card swiping. Summary of the Invention

[0004] The existing technology is unable to comprehensively plan the M1 sector configuration in multiple application scenarios, and cannot achieve accurate application selection and access control in multiple concurrent application scenarios.

[0005] In order to solve the above problems, the present invention provides a smart card sector management method and system.

[0006] A smart card sector management method, the method comprising:

[0007] The application system sends an application installation request for a contactless application to the primary management platform through the secondary management platform;

[0008] The primary management platform obtains information of the smart card according to the application installation request, and determines whether the contactless application is a new application that has not been installed in the M1 area of the smart card;

[0009] If the contactless application is an application that has been installed in the M1 area of the smart card, the primary management platform generates authorization information and sends it to the application system, and establishes a dedicated application download and installation channel, so that the application system completes the version update or key change of the contactless application through the dedicated application download and installation channel; and

[0010] If the contactless application is a new application not installed in the M1 area of the smart card, the primary management platform generates authorization information to notify the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector.

[0011] In the method, the first-level management platform can query the configuration data of the smart card according to the UID in the application installation request, obtain the information of the smart card, and send an application identification request to the terminal where the smart card is located. After receiving the application identification request, the terminal forwards the application identification request to the smart card through the card reading SDK. After receiving the application identification request, the smart card queries the sector usage of the M1 area of the smart card, obtains the list of installed contactless applications, and compares it with the AID of the contactless application requested to be installed, so as to determine whether the contactless application is a new application that has not been installed.

[0012] In the method, when the contactless application is an application that has been installed in the M1 area of the smart card and only the version is updated, the application system can send a new version of the application installation package to the smart card through the exclusive application download and installation channel. After the smart card receives the new version of the application installation package from the exclusive application download and installation channel, it queries the sector where the application is located in the M1 area of the smart card, unpacks the application according to the application installation instructions, and updates the corresponding sector data block. After the update is completed, it sends an installation completion notification to the first-level management platform, and the first-level management platform closes the exclusive application download and installation channel.

[0013] In the method, when the contactless application is an application that has been installed in the M1 area of the smart card and only involves a key change, the application system can send a new key to the smart card through the exclusive application download and installation channel. The smart card changes the data in the sector control block where the application is located in the M1 area of the smart card according to the new key. After the change to the control block is completed, a new access control key is generated for it according to the new key and the AID of the contactless application, and the new access control key is synchronized to the application system for subsequent contactless function call authentication. At the same time, the first-level management platform is notified to close the exclusive application download and installation channel.

[0014] In the method, when the contactless application is an application installed in the M1 area of the smart card and involves both version update and key change, the application system can simultaneously send the new version application installation package and the new key to the smart card through the exclusive application download and installation channel. After receiving the data, the smart card first updates the version of the application and then changes the key. After completion, the local application and key database are updated, the installation completion information is synchronized to the first-level management platform, and the key update information is synchronized to the application system. After receiving the installation completion information and the key update information, the first-level management platform closes the exclusive application download and installation channel.

[0015] In the method, when the contactless application is a new application that has not been installed in the M1 area of the smart card, after receiving a new contactless application installation request, the smart card can first query the usage status of the M1 area of the smart card. If the sectors have not been divided twice, a list of currently idle sectors is obtained in order of priority, and the sector X with the highest sequence number is selected for allocation to the current application. The key is installed in the control block of sector X, and the dedicated M1 access control rules agreed upon by the application system and the primary management platform are configured in the corresponding byte area of the control block.

[0016] The method may further comprise:

[0017] The smart card, the first-level management platform and the application system jointly agree to generate application access control, and the application key is managed by the business party or the first-level management platform. For low-sensitivity contactless applications, a key is used, and a first-level dispersion algorithm is used in combination with the AID of the contactless application to generate a contactless access application key as agreed. For high-sensitivity contactless applications, a multi-level dispersion algorithm is used in combination with the AID of the contactless application, information of the smart card, and authentication information to generate a dynamic contactless access application key as agreed.

[0018] The method may further comprise:

[0019] The first-level management platform and the smart card jointly complete the sector configuration management of the M1 area of the smart card. When the M1 area of the smart card has no secondary area division, the M1 sector is allocated to each application in the order of installation. When the M1 area of the smart card has secondary area division, the M1 sector is allocated to the application according to the level of different sectors.

[0020] A smart card sector management system, the system comprising:

[0021] The application system sends an application installation request for a contactless application to the primary management platform via the secondary management platform; and

[0022] The first-level management platform obtains the information of the smart card according to the application installation request, and determines whether the contactless application is a new application that has not been installed in the M1 area of the smart card. If the contactless application is an application that has been installed in the M1 area of the smart card, the first-level management platform generates authorization information and sends it to the application system, and establishes an exclusive application download and installation channel so that the application system completes the version update or key change of the contactless application through the exclusive application download and installation channel. If the contactless application is a new application that has not been installed in the M1 area of the smart card, the first-level management platform generates authorization information and notifies the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector.

[0023] In the system, the first-level management platform can query the configuration data of the smart card according to the UID in the application installation request, obtain the information of the smart card, and send an application identification request to the terminal where the smart card is located. After receiving the application identification request, the terminal forwards the application identification request to the smart card through the card reading SDK. After receiving the application identification request, the smart card queries the sector usage of the M1 area of the smart card, obtains the list of installed contactless applications, and compares it with the AID of the contactless application requested to be installed, so as to determine whether the contactless application is a new application that has not been installed.

[0024] In the system, when the contactless application is an application that has been installed in the M1 area of the smart card and only the version is updated, the application system can send a new version of the application installation package to the smart card through the exclusive application download and installation channel. After the smart card receives the new version of the application installation package from the exclusive application download and installation channel, it queries the sector where the application is located in the M1 area of the smart card, unpacks the package according to the application installation instructions, and updates the corresponding sector data block. After the update is completed, it sends an installation completion notification to the first-level management platform, and the first-level management platform closes the exclusive application download and installation channel.

[0025] In the system, when the contactless application is an application that has been installed in the M1 area of the smart card and only involves a key change, the application system can send a new key to the smart card through the exclusive application download and installation channel. The smart card changes the data in the sector control block where the application is located in the M1 area of the smart card according to the new key. After the change to the control block is completed, a new access control key is generated for it according to the new key and the AID of the contactless application, and the new access control key is synchronized to the application system for subsequent contactless function call authentication, and at the same time, the first-level management platform is notified to close the exclusive application download and installation channel.

[0026] In the system, when the contactless application is an application installed in the M1 area of the smart card and involves version update and key change at the same time, the application system can send the new version application installation package and the new key to the smart card at the same time through the exclusive application download and installation channel. After receiving the data, the smart card first updates the version of the application, and then changes the key. After completion, it updates the local application and key database, synchronizes the installation completion information to the first-level management platform, and synchronizes the key update information to the application system. After receiving the installation completion information and the key update information, the first-level management platform closes the exclusive application download and installation channel.

[0027] In the system, when the contactless application is a new application that has not been installed in the M1 area of the smart card, after receiving a new contactless application installation request, the smart card can first query the usage status of the M1 area of the smart card. If the sectors have not been divided twice, a list of currently idle sectors is obtained in order of priority, and sector X with a higher sequence number is selected for allocation to the current application. The key is installed in the control block of sector X, and the dedicated M1 access control rules agreed upon by the application system and the primary management platform are configured in the corresponding byte area of the control block.

[0028] In the system, the smart card, the first-level management platform and the application system can jointly agree to generate application access control, and the application key is managed by the business party or the first-level management platform. For low-sensitivity contactless applications, a key is used, and a first-level dispersion algorithm is used in combination with the AID of the contactless application to generate a contactless access application key as agreed. For high-sensitivity contactless applications, a dynamic contactless access application key is generated as agreed by combining the AID of the contactless application, the information of the smart card, and the authentication information, and using a multi-level dispersion algorithm.

[0029] In the system, the first-level management platform and the smart card can jointly complete the sector configuration management of the M1 area of the smart card. When the M1 area of the smart card has no secondary area division, the M1 sector is allocated to each application in the order of installation. When the M1 area of the smart card has secondary area division, the M1 sector is allocated to the application according to the level of different sectors.

[0030] The present invention's smart card sector configuration management method and system can comprehensively plan M1 sector configurations across multiple application scenarios, enabling orderly configuration management. It also deeply integrates the smart card sector control block with the UID and AID calculations to generate dedicated access control rules for different contactless applications, enabling precise application selection and access control in multi-application concurrent scenarios. This method automatically identifies and manages configurations within the card, eliminating the need for manual user interface settings or configurations. This makes M1 sector management more flexible and effective, and the contactless card experience more convenient and accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Specific embodiments of the present invention will be described below with reference to the accompanying drawings, which embodiments are illustrative rather than restrictive.

[0032] Figure 1 is a functional module diagram constructed according to an embodiment of the present invention;

[0033] Figure 2 is a system architecture diagram constructed according to an embodiment of the present invention; and

[0034] Figure 3 is a flow chart of a method constructed according to an embodiment of the present invention. DETAILED DESCRIPTION

[0035] In order to clearly understand the technical solution of the present invention, the configuration parameters and strategies of the present invention are introduced below.

[0036] The system configuration parameters or nodes mainly include users, smart cards, applications, application systems, AID (application identification code), sectors, data blocks, control blocks, UID (unique identification code), keys (key A, key B), etc.

[0037] Users refer to smart card terminal users. Users can interact with the card management background through the terminal and install their personalized applications on their personal smart cards.

[0038] A smart card is a smart card 5 embedded in a user terminal, such as a smart SIM card embedded in a mobile phone. It has contactless communication functions such as NFC and is used in conjunction with contactless applications loaded inside it.

[0039] Applications refer to card applications that support contactless functions, such as public transportation card applications, campus card applications, park access control applications, financial payment applications (such as mobile wallets, supporting NFC payment functions), etc.

[0040] Application system refers to the application system used for application implementation and management, including but not limited to front-end equipment, management background, etc.

[0041] AID is an application ID set based on the application and is used to identify a specific application.

[0042] Sectors and data blocks are defined within the M1 area of the smart card. This area contains multiple sectors, 0, 1, 2, and so on, each corresponding to a card application. Sector 0, data block 0, is fixed to the card vendor's UID, serving as the card's unique identifier. Each sector contains four data blocks, with data blocks 0, 1, and 2 used for application data storage. Data block 4, also known as the control block, is used for application control data storage. It stores application keys A and B, as well as corresponding access control rules, including write, read, add, and modify.

[0043] The UID is located in sector 0 data block 0 and is used to identify the manufacturer of the card and the card's unique identifier. Each card's UID is fixed and unique and can be used as its unique identification number.

[0044] Keys include Key A and Key B, which are used to control access to application data. Initial keys are written by the card's primary management platform or pre-installed at the factory (for pre-installed applications). Later, they can be conveniently managed and used by the card application system after authorization from the primary management platform.

[0045] The working mechanism and process of the present invention are described below. Figure 1 It is a functional module diagram constructed according to an embodiment of the present invention. Figure 2 It is a system architecture diagram constructed according to an embodiment of the present invention.

[0046] 1) Existing application changes

[0047] Application system 4 (card application management backend) sends an application installation request to primary management platform 2 via secondary management platform 3 (facing business and primary management platform 2). The request includes an identifier indicating whether the application is a contactless application (whether the application requires the card contactless function). Upon receiving the request, primary management platform 2 first determines whether it is a contactless application. If not, it installs the application according to the normal application installation process.

[0048] For contactless applications, the target card information (UID) is further obtained, and it is determined whether the application is a new application installed for the first time by the card (user) (SIM card application installation and change reuse the same instruction, which needs to be distinguished according to the installation situation in the card). The target card information can be the UID of the smart card or other information of the smart card. The first-level management platform 2 queries the local card configuration data according to the UID in the request, obtains the target card information, and sends an application identification request to the terminal 1 where the target card is located. After receiving the request, the terminal 1 forwards the application identification information to the card through the card reading SDK (built into the terminal 1, provided or authorized for use by the card manager, such as the operator).

[0049] After receiving the identification request, the card queries the usage of the local M1 area sector, obtains the list of installed contactless applications, and compares it with the target application AID requested to be installed. If the card M1 has already installed the application, the card will feedback the analysis results to the first-level management platform 2. The first-level management platform 2 generates authorization information for the request, sends it to the application system 4, and establishes a dedicated application download and installation channel for it, entering the application system download and installation process.

[0050] If the application installation is merely a version update, Application System 4 sends the new application installation package to the card via a dedicated channel. Upon receiving the package, the card queries the local M1 region for the sector where the application resides, unpacks the package according to the application installation instructions, and updates the corresponding sector data block. Upon completion, an installation completion notification is sent to Level 1 Management Platform 2, which then closes the dedicated channel.

[0051] If the application installation does not involve a version change, but only a key (or algorithm, hereinafter referred to as key) change, application system 4 sends the new application key to the card via a dedicated channel. The card then uses the new key to modify the data in the control block of the sector where the application resides in the M1 region. Once the control block is modified, a new access control key is generated for the application based on the new key and the (unchanged) application AID, in accordance with the dedicated access control rules for application M1. This new access control key is then synchronized with application system 4 for subsequent contactless function call authentication. Simultaneously, the primary management platform 2 is notified to close the dedicated channel.

[0052] When installing a local application involves both a version change and a key change, Application System 4 sends the new application installation package and key to the card via a dedicated channel. Upon receiving this data, the card first updates the application version, then performs the key change according to the aforementioned process. After completion, the local application and key databases are updated. Once all operations are complete, the application installation completion information is synchronized with Level 1 Management Platform 2, and the key update information is synchronized with Application System 4. Upon receiving the installation completion information, Level 1 Management Platform 2 closes the dedicated channel.

[0053] 2) First installation of a new app

[0054] The application system 4 (card application management background) sends an application installation request to the first-level management platform 2 through the second-level management platform 3 (business-oriented and first-level management platform 2). The first-level management platform 2 forwards the application identification information to the card through the card reading SDK (built into the terminal 1, provided or authorized for use by the card manager, such as the operator).

[0055] After receiving the identification request, the card queries the usage of the local M1 area sector, obtains the list of installed contactless applications, and compares it with the target application AID requested to be installed. If the card M1 does not have the application installed, the card will feedback the analysis results to the first-level management platform 2. The first-level management platform 2 generates authorization information for the request, notifies the card to create an in-card security domain for the application, and allocates a suitable M1 sector.

[0056] After receiving a request to install a new contactless application, the card first queries the usage of the local M1 area. If the sectors are not divided twice (each card application occupies the M1 sector in order), the card obtains a list of currently free sectors in order, selects the sector X with the highest sequence number for allocation to the current application, installs the key in the sector X control block, and configures the dedicated M1 access control rules agreed upon by the application system 4 and the first-level management platform 2 in the corresponding byte area of the control block.

[0057] 3) Application access control

[0058] Each contactless application's dedicated access control rules are set independently by each contactless application within M1. These rules are only valid for a specific application within a specified area on a specific card, primarily used to control access to a specific application within M1. These rules are jointly agreed upon and generated by the card, the primary management platform 2, and the application system 4. The primary management platform 2 and the card are primarily responsible for M1 area division and configuration, while the application system 4 is primarily responsible for application keys and contactless access and control requirements management. Together, these three parties are responsible for access control of the application within the designated card M1 sector. Application keys can be managed by the business entity itself or by the primary management platform 2.

[0059] Note that the dedicated M1 rules here are mainly used to stipulate the selection and retrieval of the entire M1 sector of the application when facing the contactless card swiping scenario (the reading and writing rules of the application data itself follow the existing mechanism).

[0060] Static key primary dispersion: For contactless card applications such as low-sensitivity, regular, or small-value payments, such as public transportation cards, campus cards, and general membership cards, Key A and Key B can be directly used. A primary dispersion algorithm is used in conjunction with the application AID to generate a contactless access key according to the agreement. This key is stored in the application control area and synchronized with the application system 4. When swiping the card, the application system 4 carries the target application AID and the key in the card swiping request. The card decrypts the key according to the agreement and compares it with the root key stored in the local M1 area of the target application. If they match, the target application contactless interface is called and the card swiping operation is executed.

[0061] Multi-level dynamic key dispersion: For high-sensitivity contactless applications such as large-value payments and secure area access control, if real-person or real-card access authentication is required, the application AID, card UID (for real-card authentication), user identity, account, fingerprint (for real-person authentication), and other authentication information can be combined simultaneously, and a multi-level dispersion algorithm can be used to generate a dynamic contactless access key according to the agreement. This key can be generated in real time or updated periodically according to demand. When the key is updated periodically, the updated key is stored in the card M1 area to which the application belongs according to the above method. When the card is swiped, the application system 4 sends the key to the card. The card parses it according to the above method and compares it with the local key. If the match is consistent, the application contactless interface is called and subsequent operations are allowed. When the key is generated in real time, the application system 4 generates a dynamic key in real time according to the agreed generation rules. When the card is swiped, the dynamic key is sent to the card. After receiving it, the card parses it according to the agreement and compares it with the local root key. If the match is consistent, the application contactless interface is called and the card swiping operation is allowed.

[0062] 4) M1 configuration management

[0063] Card M1 area configuration management is effective based on the designated card and is completed jointly by the first-level management platform 2 and the card. It is mainly used to constrain the sector configuration management of the card M1 area.

[0064] When M1 has no secondary area division, all applications within it share the area fairly, and M1 sectors are allocated to them in the order in which they are installed. When M1 has secondary area division, that is, different sectors are divided into levels within M1, such as sectors 1-4 are dedicated areas for high-sensitivity applications, and sectors 5-16 are shared areas for non-high-sensitivity applications. When a high-sensitivity application requests to be installed for the first time, it is first allocated a free sector in the high-sensitivity area within M1. If there is no free sector in the high-sensitivity area, it is allocated a sector in the shared area, and the sector is marked as a "high-sensitivity sector" and configured and managed using the high-sensitivity application access mechanism. When a regular application requests to be installed for the first time, it is first allocated a free sector in the front row of the shared area within M1 and managed according to normal access control rules. When a high-sensitivity application is downgraded to a regular application, the allocated sectors are not changed, but the corresponding sector attributes and its internal application management method are changed.

[0065] Figure 3 FIG. 1 is a flow chart of a method according to an embodiment of the present invention. In this embodiment of the present invention, a smart card sector management method includes the following steps:

[0066] S1: The application system sends an application installation request for a contactless application to the primary management platform through the secondary management platform;

[0067] S2: The primary management platform obtains the smart card information according to the application installation request and determines whether the contactless application is a new application that is not installed in the M1 area of the smart card;

[0068] S3: If the contactless application is an application that has been installed in the M1 area of the smart card, the primary management platform generates authorization information and sends it to the application system, and establishes a dedicated application download and installation channel so that the application system can complete the version update or key change of the contactless application through the dedicated application download and installation channel; and

[0069] S4: If the contactless application is a new application that is not installed in the M1 area of the smart card, the primary management platform generates authorization information and notifies the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector.

[0070] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media generally embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A smart card sector management method, the method comprising: The application system sends an application installation request for a contactless application to the primary management platform through the secondary management platform; The primary management platform obtains information of the smart card according to the application installation request, and determines whether the contactless application is a new application that is not installed in the M1 area of the smart card; If the contactless application is an application that has been installed in the M1 area of the smart card, the primary management platform generates authorization information and sends it to the application system, and establishes a dedicated application download and installation channel, so that the application system completes the version update or key change of the contactless application through the dedicated application download and installation channel; as well as If the contactless application is a new application that is not installed in the M1 area of the smart card, the primary management platform generates authorization information and notifies the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector; When the contactless application is a new application that has not been installed in the M1 area of the smart card, after receiving the new contactless application installation request, the smart card first queries the usage status of the M1 area of the smart card. If the sectors have not been divided twice, the smart card obtains a list of currently idle sectors in order, selects the sector X with the highest sequence number to allocate for the current application, installs the key in the control block of sector X, and configures the dedicated M1 access control rules agreed upon by the application system and the primary management platform into the corresponding byte area of the control block.

2. The method according to claim 1, wherein The first-level management platform queries the configuration data of the smart card according to the UID in the application installation request, obtains the information of the smart card, and sends an application identification request to the terminal where the smart card is located. After receiving the application identification request, the terminal forwards the application identification request to the smart card through the card reading SDK. After receiving the application identification request, the smart card queries the sector usage of the M1 area of the smart card, obtains the list of installed contactless applications, and compares it with the AID of the contactless application requested to be installed, so as to determine whether the contactless application is a new application that has not been installed.

3. The method according to claim 1 or 2, wherein: When the contactless application is an application that has been installed in the M1 area of the smart card and only the version is updated, the application system sends the new version application installation package to the smart card through the exclusive application download and installation channel. After the smart card receives the new version application installation package from the exclusive application download and installation channel, it queries the sector where the application is located in the M1 area of the smart card, unpacks the package according to the application installation instructions, and updates the corresponding sector data block. After the update is completed, it sends an installation completion notification to the first-level management platform, and the first-level management platform closes the exclusive application download and installation channel.

4. The method according to claim 1 or 2, wherein: When the contactless application is an application installed in the M1 area of the smart card and only involves a key change, the application system sends a new key to the smart card through the exclusive application download and installation channel. The smart card changes the data in the sector control block where the application is located in the M1 area of the smart card according to the new key. After the change to the control block is completed, a new access control key is generated for it according to the new key and the AID of the contactless application, and the new access control key is synchronized to the application system for subsequent contactless function call authentication. At the same time, the first-level management platform is notified to close the exclusive application download and installation channel.

5. The method according to claim 1 or 2, wherein: When the contactless application is an application installed in the M1 area of the smart card and involves version update and key change at the same time, the application system sends the new version application installation package and the new key to the smart card through the exclusive application download and installation channel. After receiving the data, the smart card first updates the application version and then changes the key. After completion, the local application and key database are updated, the installation completion information is synchronized to the primary management platform, and the key update information is synchronized to the application system. After receiving the installation completion information and the key update information, the primary management platform closes the exclusive application download and installation channel.

6. The method according to claim 1 or 2, further comprising: The smart card, the first-level management platform and the application system jointly agree to generate application access control, and the application key is managed by the business party or the first-level management platform. For low-sensitivity contactless applications, a key is used, and a first-level dispersion algorithm is used in combination with the AID of the contactless application to generate a contactless access application key as agreed. For high-sensitivity contactless applications, a multi-level dispersion algorithm is used in combination with the AID of the contactless application, information of the smart card, and authentication information to generate a dynamic contactless access application key as agreed.

7. The method according to claim 1 or 2, further comprising: The first-level management platform and the smart card jointly complete the sector configuration management of the M1 area of the smart card. When the M1 area of the smart card has no secondary area division, the M1 sector is allocated to each application in the order of installation. When the M1 area of the smart card has secondary area division, the M1 sector is allocated to the application according to the level of different sectors.

8. A smart card sector management system, the system comprising: The application system sends an application installation request for a contactless application to the primary management platform via the secondary management platform; as well as The first-level management platform obtains information of the smart card according to the application installation request and determines whether the contactless application is a new application not installed in the M1 area of the smart card. If the contactless application is an application already installed in the M1 area of the smart card, the first-level management platform generates authorization information and sends it to the application system, and establishes a dedicated application download and installation channel so that the application system completes the version update or key change of the contactless application through the dedicated application download and installation channel. If the contactless application is a new application not installed in the M1 area of the smart card, the first-level management platform generates authorization information and notifies the smart card to create an intra-card security domain for the contactless application and allocate an M1 sector. When the contactless application is a new application that has not been installed in the M1 area of the smart card, after receiving the new contactless application installation request, the smart card first queries the usage status of the M1 area of the smart card. If the sectors have not been divided twice, the smart card obtains a list of currently idle sectors in order, selects the sector X with the highest sequence number to allocate for the current application, installs the key in the control block of sector X, and configures the dedicated M1 access control rules agreed upon by the application system and the primary management platform into the corresponding byte area of the control block.

9. The system according to claim 8, wherein: The first-level management platform queries the configuration data of the smart card according to the UID in the application installation request, obtains the information of the smart card, and sends an application identification request to the terminal where the smart card is located. After receiving the application identification request, the terminal forwards the application identification request to the smart card through the card reading SDK. After receiving the application identification request, the smart card queries the sector usage of the M1 area of the smart card, obtains the list of installed contactless applications, and compares it with the AID of the contactless application requested to be installed, so as to determine whether the contactless application is a new application that has not been installed.

10. The system according to claim 8 or 9, wherein: When the contactless application is an application that has been installed in the M1 area of the smart card and only the version is updated, the application system sends the new version application installation package to the smart card through the exclusive application download and installation channel. After the smart card receives the new version application installation package from the exclusive application download and installation channel, it queries the sector where the application is located in the M1 area of the smart card, unpacks the package according to the application installation instructions, and updates the corresponding sector data block. After the update is completed, it sends an installation completion notification to the first-level management platform, and the first-level management platform closes the exclusive application download and installation channel.

11. The system according to claim 8 or 9, wherein: When the contactless application is an application installed in the M1 area of the smart card and only involves a key change, the application system sends a new key to the smart card through the exclusive application download and installation channel. The smart card changes the data in the sector control block where the application is located in the M1 area of the smart card according to the new key. After the change to the control block is completed, a new access control key is generated for it according to the new key and the AID of the contactless application, and the new access control key is synchronized to the application system for subsequent contactless function call authentication. At the same time, the first-level management platform is notified to close the exclusive application download and installation channel.

12. The system according to claim 8 or 9, wherein: When the contactless application is an application installed in the M1 area of the smart card and involves version update and key change at the same time, the application system sends the new version application installation package and the new key to the smart card through the exclusive application download and installation channel. After receiving the data, the smart card first updates the application version and then changes the key. After completion, the local application and key database are updated, the installation completion information is synchronized to the primary management platform, and the key update information is synchronized to the application system. After receiving the installation completion information and the key update information, the primary management platform closes the exclusive application download and installation channel.

13. The system according to claim 8 or 9, wherein: The smart card, the first-level management platform and the application system jointly agree to generate application access control, and the application key is managed by the business party or the first-level management platform. For low-sensitivity contactless applications, a key is used, and a first-level dispersion algorithm is used in combination with the AID of the contactless application to generate a contactless access application key as agreed. For high-sensitivity contactless applications, a multi-level dispersion algorithm is used in combination with the AID of the contactless application, information of the smart card, and authentication information to generate a dynamic contactless access application key as agreed.

14. The system according to claim 8 or 9, wherein: The first-level management platform and the smart card jointly complete the sector configuration management of the M1 area of the smart card. When the M1 area of the smart card has no secondary area division, the M1 sector is allocated to each application in the order of installation. When the M1 area of the smart card has secondary area division, the M1 sector is allocated to the application according to the level of different sectors.

Citation Information

Patent Citations

  • Application downloading system and method

    CN101819696A

  • Local Trusted Services Manager For A Contactless Smart Card

    CN104504806A