A testing method, system, and related components for contactless IC cards

By acquiring, processing, and outputting IC card data, and combining the card reading results to evaluate the security of the IC card, the problem of lack of security assessment in existing technologies is solved, and the security assessment and testing of IC cards is realized.

CN115828978BActive Publication Date: 2026-01-30HANGZHOU MAITANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211694100.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2026-01-30
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

The lack of specific performance analysis and testing schemes for IC card security in existing technologies makes it impossible to effectively assess the security of IC cards.

Method used

The first NFC device acquires the data within the IC card, processes it to generate output data, and outputs it to the card reader terminal via the second NFC device. The card reader receives the reading results to determine the security of the IC card, including identifying data differences, generating relay or replay attack data, and uploading the data to the cloud platform to assess the security of the IC card.

Benefits of technology

It enables security assessment of IC cards, and can identify and evaluate whether IC cards have potential risks of replay or relay attacks, ensuring that their security meets the requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115828978B_ABST
    Figure CN115828978B_ABST
Patent Text Reader

Abstract

This application discloses a testing method, system, and related components for contactless IC cards, relating to the field of near-field communication (NFC). The method includes: acquiring the card data of the IC card under test via a first NFC device; processing the card data to generate output data; outputting the output data to a card reader terminal via a second NFC device and receiving the card reading result from the card reader terminal; determining whether the card reading was successful based on the reading result; if successful, determining that the security of the IC card under test does not meet security requirements; otherwise, determining that the security of the IC card under test meets security requirements. This application acquires and processes the card data of the IC card under test to obtain the output data, determines whether the card reading was successful by observing the card reader terminal's reading result of the output data, and thus determines whether the card data of the IC card under test has sufficient security. This method can test and evaluate the security of various types of IC cards.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of near-field communication, and in particular to a testing method, system, and related components for contactless IC cards. Background Technology

[0002] Currently, the Internet of Things (IoT) comprises multiple physical devices connected via a network, also known as network-connected devices or smart devices, which can transmit data over the network through device interaction. This technology helps create new ways to manage devices and improve management efficiency. Near Field Communication (NFC) technology provides technical support for the connection, activation, and control of network-connected devices in smart networks, playing a crucial role in the implementation of the IoT.

[0003] Near Field Communication (NFC) technology is generally implemented through IC cards, such as various car keys, access cards for residential communities or hotels, etc. Current research on IC cards mainly focuses on the NFC recording function in mobile phones to make it more convenient for everyday users to use IC cards. However, there are currently no specific performance analysis and testing schemes to determine whether the security of finished IC cards is reliable enough.

[0004] Therefore, how to provide a solution to the above-mentioned technical problems is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a testing method, system, and related components for analyzing the performance and security of contactless IC cards. The specific solution is as follows:

[0006] A testing method for contactless IC cards, comprising:

[0007] The data stored in the IC card under test is obtained through the first NFC device;

[0008] The data in the card is processed to generate data to be output;

[0009] The second NFC device outputs the data to be output to the card reader terminal and receives the card reading result from the card reader terminal.

[0010] The card reading result determines whether the card reading was successful. If it was, the security of the IC card under test is determined to be unsatisfactory. If not, the security of the IC card under test is determined to be satisfactory.

[0011] Preferably, the process of acquiring the card data of the IC card under test through the first NFC device includes:

[0012] The data stored in the IC card under test is obtained multiple times through the first NFC device;

[0013] Accordingly, the process of processing the data in the card to generate the data to be output includes:

[0014] The card data is identified and compared multiple times to determine whether the two sets of card data are the same.

[0015] If not, process the data in the card to generate output data for relay attacks;

[0016] If so, the data in the card is processed to generate output data for replaying the attack.

[0017] Preferably, after processing the data in the card to generate the output data for replaying the attack, the method further includes:

[0018] Upload the data to be output to the cloud platform;

[0019] Accordingly, the process of outputting the data to be output to the card reader terminal via the second NFC device includes:

[0020] The data to be output is downloaded from the cloud platform and then output to the card reader terminal via the second NFC device.

[0021] Preferably, the process of processing the data in the card to generate output data for relay attacks includes:

[0022] Analyze the anti-replay data segment of the card data and / or determine the encryption logic of the IC card under test based on multiple data sets of the card data;

[0023] Based on the encryption logic, output data is generated for relay attacks.

[0024] Preferably, before processing the data in the card, the method further includes:

[0025] The data in the card is formatted to obtain the data in the card in a corresponding preset data format.

[0026] Preferably, after formatting the data in the card to obtain the data in the card corresponding to a preset data format, the method further includes:

[0027] Noisy data is filtered from the data in the card.

[0028] Accordingly, the process of processing the data in the card includes:

[0029] The data to be output is generated based on the filtered data in the card.

[0030] Preferably, the process of acquiring the card data of the IC card under test through the first NFC device includes:

[0031] Based on the anti-collision algorithm, the data of the IC card under test is obtained through the first NFC device.

[0032] Accordingly, this application also discloses a testing system for contactless IC cards, including:

[0033] The acquisition module is used to acquire the data stored in the IC card under test through the first NFC device;

[0034] The processing module is used to process the data in the card and generate data to be output;

[0035] The action module is used to output the data to be output to the card reader terminal via the second NFC device, and to receive the card reading result from the card reader terminal.

[0036] The analysis module is used to determine whether the card reading was successful based on the card reading result. If it was successful, the IC card under test is determined to have security that does not meet the security requirements. If it was not successful, the IC card under test is determined to have security that meets the security requirements.

[0037] Accordingly, this application also discloses an electronic device, including:

[0038] First NFC device and second NFC device;

[0039] Memory, used to store computer programs;

[0040] The processor, connected to the memory, the first NFC device, and the second NFC device, is used to execute the computer program to implement the steps of the contactless IC card testing method described in any of the above descriptions.

[0041] Accordingly, this application also discloses a readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the test method for the contactless IC card as described in any of the above claims.

[0042] This application discloses a testing method that acquires and processes the data within the IC card under test to obtain the data to be output. By observing the card reader terminal's reading result of the data to be output, the method determines whether the card reading was successful, thereby determining whether the data within the IC card under test has sufficient security. This method can test and evaluate the security of various types of IC cards. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0044] Figure 1 This is a flowchart illustrating the steps of a contactless IC card testing method according to an embodiment of the present invention.

[0045] Figure 2 This is a hardware diagram illustrating a testing method for a contactless IC card according to an embodiment of the present invention.

[0046] Figure 3 This is a structural distribution diagram of a test system for a contactless IC card according to an embodiment of the present invention. Detailed Implementation

[0047] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0048] Near Field Communication (NFC) technology is generally implemented through IC cards. Current research on IC cards mainly focuses on the NFC recording function in mobile phones to make it more convenient for everyday users to use IC cards. However, there are currently no specific performance analysis and testing schemes to determine whether the security of finished IC cards is reliable enough.

[0049] This application discloses a testing method that acquires and processes the data within the IC card under test to obtain the data to be output. By observing the card reader terminal's reading result of the data to be output, the method determines whether the card reading was successful, thereby determining whether the data within the IC card under test has sufficient security. This method can test and evaluate the security of various types of IC cards.

[0050] This invention discloses a testing method for contactless IC cards. See [link to relevant documentation]. Figure 1 As shown, it includes:

[0051] S1: Obtain the data stored in the IC card under test through the first NFC device;

[0052] S2: Process the data in the card to generate data to be output;

[0053] S3: Output the data to be output to the card reader terminal through the second NFC device, and receive the card reading result from the card reader terminal;

[0054] S4: Determine whether the card reading was successful based on the reading result. If yes, the IC card under test is deemed to have security requirements that are not met. If no, the IC card under test is deemed to have security requirements that are met.

[0055] Specifically, in this embodiment, the execution entity is a processor. Within the processor, the technical architecture can be Java, specifically JDK 1.8. The backend main framework is built using Spring Boot. A relational database of MySQL 8 is used for storing data within the card and / or data to be output. Nginx is chosen as the static server for load balancing and gateway processing. Redis is selected for NoSQL caching to perform data analysis and caching of data within the card and / or data to be output, thereby improving processing performance and accelerating response. Tomcat is chosen as the application server for application deployment. Of course, other types can also be chosen to implement the technical architecture of this embodiment, in addition to the above settings.

[0056] Furthermore, in this embodiment, the processor controls the first NFC device and the second NFC device. The first NFC device reads the data stored in the IC card under test, and the second NFC device outputs the data to be output to the card reader terminal. Therefore, the hardware relationship diagram is as follows: Figure 2 As shown.

[0057] Specifically, before step S1, the IC card under test needs to be woken up. The IC card under test is typically a Class A IC card. Once the IC card under test comes into contact with the effective range of the first NFC device in this embodiment, and the first NFC device has sufficient power, the IC card under test begins executing some preset programs and then enters an "idle state." While the IC card under test is in the "idle state," the first NFC device obtains the IC card under test's response word ATQA by sending a valid REQA command. Simultaneously, the IC card under test enters the READY state, at which point the wake-up process of the IC card under test ends.

[0058] Understandably, in step S1, the first NFC device typically acquires data from the card in the form of a socket.

[0059] Furthermore, if multiple IC cards to be tested exist within the range of the first NFC device, a "binary search tree" anti-collision algorithm can be activated by sending a SELECT command to select one IC card as the current IC card to be tested, and then the data within the IC card to be tested can be read. That is, the process of obtaining the data within the IC card to be tested through the first NFC device includes: obtaining the data within the IC card to be tested through the first NFC device according to the anti-collision algorithm.

[0060] In some specific embodiments, before processing the data in the card in step S2, the following steps are also included:

[0061] The data on the card is formatted to obtain the data in the card according to the preset data format.

[0062] Furthermore, after formatting the data on the card to obtain the data in the card according to the preset data format, it also includes:

[0063] Filter out noisy data in the card's data;

[0064] Accordingly, the process of processing the data on the card includes:

[0065] The data to be output is generated based on the filtered data in the card.

[0066] It is understandable that the purpose of formatting and filtering the card data obtained in step S1 is to remove redundant and noisy data from the complete card data to obtain the necessary valid data, and to generate the output data based on the valid data.

[0067] It is understandable that steps S2 and S3, which generate the data to be output and output the data to the card reader terminal, can either upload the data to the cloud platform and then download it from the cloud platform via the second NFC device and output it to the card reader terminal, or skip the process of uploading and downloading to the cloud platform and directly obtain the data to be output. However, different processing methods will result in different card reading results for IC cards of different types and security settings.

[0068] Specifically, in IC cards with simple security settings, the data inside the card generally does not change, and the data obtained multiple times is consistent. Therefore, after being uploaded to the cloud platform in step S2, the data to be output can be downloaded from the cloud platform by a second NFC device in a suitable scenario and then output to the card reader terminal. Regardless of the number of times, time, or scenario in step S3, the card reading result received by the card reader terminal is usually consistent. Such IC cards are vulnerable to replay attacks.

[0069] However, in IC cards with complex security settings, the data generated each time may change. For example, if the IC card under test contains anti-replay fields such as encryption algorithms, timestamps, and random numbers, the data obtained from different tests will be different. Taking timestamps as an example, if the time taken to send the output data generated from the card data to the card reader differs significantly from the time taken to directly output the card data to the card reader, the output data may fail the card reader's verification, resulting in a reading failure. Therefore, for IC cards with complex security settings, the output data is generally not downloaded from the cloud platform to the second NFC device multiple times before being output to the card reader, because repeated output will inevitably result in a reading failure, eliminating the risk of replay attacks. In this case, attention needs to be paid to relay attacks and the security of encryption algorithms.

[0070] To address the issue of relay attacks, the process involves skipping the upload and download on the cloud platform and directly sending the generated output data to the card reader via a second NFC device. This minimizes the time required for information transmission. The card reader's reading result is then observed to determine if there is a risk of a relay attack.

[0071] Regarding encryption algorithms, analysis can be performed on multiple data sets from the card or multiple output data sets. Attempts can be made to crack the encryption algorithm using methods such as brute-force attacks with a pre-set key library on the cloud platform and decryption of common encryption algorithms. The success or failure of the cracking determines whether the security of the IC card under test meets the security requirements. Specifically, the pre-set key library includes access cards for a specific model or product line, and common encryption algorithms include RSA and SM2. The appropriate pre-set key library and / or encryption algorithm can be selected based on the security level set during testing.

[0072] Based on the above analysis, the specific approach to the testing method for the IC card under test can be determined. Furthermore, step S1, which involves acquiring the data stored in the IC card under test through the first NFC device, may include:

[0073] The data stored in the IC card under test is obtained multiple times through the first NFC device;

[0074] Understandably, each acquisition requires a wake-up process.

[0075] Accordingly, step S2 processes the data in the card to generate the data to be output, including:

[0076] Identify and compare multiple sets of data from the card to determine whether the two sets of data are the same;

[0077] If not, process the data in the card to generate output data for relay attacks;

[0078] If so, process the data in the card to generate output data for replaying the attack.

[0079] Furthermore, after processing the data on the card to generate the output data for replaying the attack, the process also includes:

[0080] Upload the data to be output to the cloud platform;

[0081] Accordingly, step S3, which involves outputting the data to be output to the card reader terminal via the second NFC device, includes:

[0082] Download the data to be output from the cloud platform and output the data to the card reader terminal via the second NFC device.

[0083] Further processing of the data on the card to generate output data for relay attacks includes:

[0084] Analyze the anti-replay data segment of the card data and / or determine the encryption logic of the IC card under test based on multiple card data.

[0085] Based on the encryption logic, generate output data for relay attacks.

[0086] This application discloses a testing method for contactless IC cards, comprising: acquiring the card data of the IC card under test through a first NFC device; processing the card data to generate output data; outputting the output data to a card reader terminal through a second NFC device and receiving the card reading result from the card reader terminal; determining whether the card reading was successful based on the card reading result; if successful, determining that the security of the IC card under test does not meet the security requirements; if unsuccessful, determining that the security of the IC card under test meets the security requirements. This testing method discloses that acquires and processes the card data of the IC card under test to obtain output data, determines whether the card reading was successful by observing the card reading result of the card reader terminal, and thus determines whether the card data of the IC card under test has sufficient security. This method can test and evaluate the security of various types of IC cards.

[0087] Accordingly, this application also discloses a testing system for contactless IC cards, see [link to relevant documentation]. Figure 3 As shown, it includes:

[0088] Acquisition module 1 is used to acquire the card data of the IC card under test through the first NFC device;

[0089] Processing module 2 is used to process the data in the card and generate data to be output;

[0090] Action module 3 is used to output the data to be output to the card reader terminal through the second NFC device, and to receive the card reading result from the card reader terminal;

[0091] Analysis module 4 is used to determine whether the card reading was successful based on the card reading result. If it was successful, the security of the IC card under test is determined to be unsatisfactory. If it was unsatisfactory, the security of the IC card under test is determined to be satisfactory.

[0092] This application embodiment acquires and processes the data within the IC card under test to obtain the data to be output. By observing the card reader terminal's reading result of the data to be output, it determines whether the card reading was successful, and thus determines whether the data within the IC card under test has sufficient security. This allows for testing and evaluating the security of various types of IC cards.

[0093] In some specific embodiments, the process by which the acquisition module 1 acquires the data stored in the IC card under test through the first NFC device includes:

[0094] The data stored in the IC card under test is obtained multiple times through the first NFC device;

[0095] Accordingly, the processing module 2 processes the data in the card to generate the data to be output, including:

[0096] The card data is identified and compared multiple times to determine whether the two sets of card data are the same.

[0097] If not, process the data in the card to generate output data for relay attacks;

[0098] If so, the data in the card is processed to generate output data for replaying the attack.

[0099] In some specific embodiments, after the processing module 2 processes the data in the card to generate output data for replay attacks, it further includes:

[0100] Upload the data to be output to the cloud platform;

[0101] Correspondingly, the process by which the action module 3 outputs the data to be output to the card reader terminal via the second NFC device includes:

[0102] The data to be output is downloaded from the cloud platform and then output to the card reader terminal via the second NFC device.

[0103] In some specific embodiments, the process by which the processing module 2 processes the data in the card to generate output data for relay attacks includes:

[0104] Analyze the anti-replay data segment of the card data and / or determine the encryption logic of the IC card under test based on multiple data sets of the card data;

[0105] Based on the encryption logic, output data is generated for relay attacks.

[0106] In some specific embodiments, before the processing module 2 processes the data in the card, it further includes:

[0107] The data in the card is formatted to obtain the data in the card in a corresponding preset data format.

[0108] In some specific embodiments, after the processing module 2 formats the data in the card to obtain the data in the card corresponding to a preset data format, it further includes:

[0109] Noisy data is filtered from the data in the card.

[0110] Accordingly, the process by which the processing module 2 processes the data in the card includes:

[0111] The data to be output is generated based on the filtered data in the card.

[0112] In some specific embodiments, the process by which the acquisition module 1 acquires the data stored in the IC card under test through the first NFC device includes:

[0113] Based on the anti-collision algorithm, the data of the IC card under test is obtained through the first NFC device.

[0114] Accordingly, this application also discloses an electronic device, including:

[0115] First NFC device and second NFC device;

[0116] Memory, used to store computer programs;

[0117] The processor, connected to the memory, the first NFC device, and the second NFC device, is used to execute the computer program to implement the steps of the contactless IC card testing method described in any of the above descriptions.

[0118] Accordingly, this application also discloses a readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the test method for the contactless IC card as described in any of the above claims.

[0119] For details regarding the testing methods for contactless IC cards, please refer to the relevant descriptions in the embodiments above, which will not be repeated here.

[0120] In this embodiment, the electronic device and the readable storage medium have the same technical effects as the contactless IC card testing method in the above embodiment, and will not be repeated here.

[0121] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0122] The present invention provides a detailed description of a testing method, system, and related components for a contactless IC card. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A test method of a non-contact IC card, characterized by, The method comprises the following steps: obtaining card internal data of an IC card to be tested through a first NFC device; processing the card internal data to generate output data to be outputted; outputting the output data to be outputted to a card reading terminal through a second NFC device and receiving a card reading result of the card reading terminal; judging whether the card reading is successful according to the card reading result, if yes, determining that the security of the IC card to be tested does not meet the security requirement, if no, determining that the security of the IC card to be tested meets the security requirement; the process of obtaining the card internal data of the IC card to be tested through the first NFC device comprises: obtaining the card internal data of the IC card to be tested through the first NFC device for multiple times; correspondingly, the process of processing the card internal data to generate the output data to be outputted comprises: identifying and comparing the card internal data for multiple times to determine whether the card internal data is the same; if no, processing the card internal data to generate the output data to be outputted for relay attack; if yes, processing the card internal data to generate the output data to be outputted for replay attack.

2. The test method of claim 1, wherein, after the process of processing the card internal data to generate the output data to be outputted for replay attack, the method further comprises: uploading the output data to be outputted to a cloud platform; correspondingly, the process of outputting the output data to be outputted to the card reading terminal through the second NFC device comprises: downloading the output data to be outputted from the cloud platform and outputting the output data to be outputted to the card reading terminal through the second NFC device.

3. The test method of claim 1, wherein, the process of processing the card internal data to generate the output data to be outputted for relay attack comprises: analyzing anti-replay data segments of the card internal data and / or determining encryption logic of the IC card to be tested according to the card internal data for multiple times; generating the output data to be outputted for relay attack according to the encryption logic.

4. The test method of claim 1, wherein, before the process of processing the card internal data, the method further comprises: performing format processing on the card internal data to obtain the card internal data corresponding to a preset data format.

5. The test method of claim 4, wherein, after the process of performing format processing on the card internal data to obtain the card internal data corresponding to the preset data format, the method further comprises: filtering noise data in the card internal data; correspondingly, the process of processing the card internal data comprises: generating the output data to be outputted according to the card internal data after filtering.

6. The test method according to any one of claims 1 to 5, characterized in that, the process of obtaining the card internal data of the IC card to be tested through the first NFC device comprises: obtaining the card internal data of an IC card to be tested through the first NFC device according to an anti-collision algorithm.

7. A testing system for contactless IC cards, characterized in that, The method comprises the following steps: an obtaining module is configured to obtain card internal data of an IC card to be tested through a first NFC device; a processing module is configured to process the card internal data to generate output data to be outputted; an action module is configured to output the output data to be outputted to a card reading terminal through a second NFC device and receive a card reading result of the card reading terminal; an analysis module is configured to judge whether the card reading is successful according to the card reading result, if yes, determine that the security of the IC card to be tested does not meet the security requirement, if no, determine that the security of the IC card to be tested meets the security requirement; the process of obtaining the card internal data of the IC card to be tested through the first NFC device by the obtaining module comprises: Acquiring card-in data of the IC card to be tested by the first NFC device for multiple times; Correspondingly, the process of the processing module processing the card-in data to generate data to be output includes: identifying and comparing the card-in data for multiple times to determine whether the card-in data is the same twice; if not, processing the card-in data to generate data to be output for relay attack; if yes, processing the card-in data to generate data to be output for replay attack.

8. An electronic device, comprising: comprise: a first NFC device and a second NFC device; a memory for storing a computer program; a processor connected with the memory, the first NFC device and the second NFC device, for executing the computer program to realize the steps of the test method of the contactless IC card according to any one of claims 1 to 6.

9. A readable storage medium, characterized by, The computer program is stored on the readable storage medium, and the computer program is executed by the processor to realize the steps of the test method of the contactless IC card according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Detection method of relay attack on smart card, read-write terminal and system

    CN107707527A

  • Noncontact IC card simulation and data real-time analysis system

    CN107862225A