Card writing data processing method based on multiple encryption and card writing method and system
By processing card writing data with multiple encryption algorithms, the security and compatibility issues of card writing via WeChat Mini Programs are resolved, achieving secure data transmission and compatibility with card systems from multiple vendors.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2026-03-17
AI Technical Summary
Existing technologies using WeChat mini-programs for card writing pose a risk of leaking encrypted parameters and are incompatible with card systems from multiple vendors.
Personalized data is processed using multiple encryption algorithms, including a first preset encryption and decryption algorithm and a second preset encryption and decryption algorithm to encrypt the data, which is then verified by the card seller's card writing component. Finally, the data is encrypted by the reader's corresponding third preset encryption and decryption algorithm to ensure data transmission security and compatibility.
It improves the security of card writing via WeChat Mini Program and its compatibility with card systems from multiple vendors, ensuring the security and compatibility of card writing data during transmission.
Smart Images

Figure CN115955335B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a card writing data processing method and system based on multiple encryption. Background Technology
[0002] With the continuous improvement of mobile internet technology and terminal device capabilities, the use of WeChat mini-programs is becoming increasingly widespread. Users can perform related business operations without downloading an app, bringing a brand-new, efficient, and convenient experience. For card writing platforms, compared to traditional PC-based card writing in physical stores, WeChat mini-program card writing, which directly uses Bluetooth technology, initiates the process through the WeChat mini-program, connecting to a Bluetooth card reader to complete the card writing and account opening process directly. This significantly improves the convenience of account opening operations and the utilization rate of equipment, while reducing the space usage of customer terminal devices. However, using WeChat mini-program card writing poses a risk of encrypted parameter leakage because the encrypted parameters need to be transmitted between the reader and the business server; furthermore, there are incompatibilities between card systems from different vendors.
[0003] Therefore, how to improve the security of card writing based on mini-programs and its compatibility with card systems from multiple vendors is a current research direction. Summary of the Invention
[0004] This invention provides a card writing data processing method and system based on multiple encryption, which solves the problem in the prior art that it is difficult to improve the security of card writing based on mini-programs and the compatibility with card systems from multiple vendors, thereby improving the security of card writing based on mini-programs and the compatibility with card systems from multiple vendors.
[0005] A method for processing card writing data based on multiple encryption, the method comprising: obtaining first personalized data from a resource system based on a card writing request sent by a front-end card writing applet; performing multiple encryptions on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data; calling a card vendor's card writing component to verify the personalized encrypted data to obtain card writing data; receiving the card writing data returned by the card vendor's card writing component, encrypting the card writing data based on a third preset encryption / decryption algorithm corresponding to the reader; and sending the encrypted card writing data to the front-end card writing applet.
[0006] In one embodiment, the step of performing multiple encryptions on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data includes: acquiring the first preset encryption / decryption algorithm and the second preset encryption / decryption algorithm; encrypting the first personalized data based on the first preset encryption / decryption algorithm to obtain second personalized data; and encrypting the second personalized data based on the second preset encryption / decryption algorithm to obtain personalized encrypted data.
[0007] In one embodiment, the first preset encryption algorithm is an asymmetric encryption algorithm or a key negotiation algorithm. Accordingly, encrypting the first personalized data based on the first preset encryption / decryption algorithm includes encrypting the first personalized data based on the public key in the asymmetric encryption algorithm or the session key generated by the key negotiation algorithm.
[0008] In one embodiment, the card writing component of the card vendor includes a process of decrypting and encrypting the personalized encrypted data based on the second preset encryption and decryption algorithm during the verification of the personalized encrypted data. Correspondingly, before encrypting the card writing data based on the third preset encryption and decryption algorithm corresponding to the reader, the method further includes: decrypting the card writing data based on the second preset encryption and decryption algorithm.
[0009] In one embodiment, the card writing applet on the front end and the HTTPS certificate corresponding to the server are issued by the same root certificate.
[0010] A card writing method is applied to a front-end card writing applet. The method includes: sending a card writing request to a server; receiving encrypted card writing data returned by the server; the encrypted card writing data is card writing data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm; decrypting the encrypted card writing data based on a third preset encryption / decryption algorithm corresponding to a reader to obtain first card writing data; and calling the reader to write the first card writing data.
[0011] In one embodiment, the process of the reader writing the first card writing data includes: transmitting the first card writing data to the card, and having the card decrypt the first card writing data based on a first preset encryption / decryption algorithm to obtain second card writing data and write it to the card.
[0012] A card writing system includes: a front-end card writing applet and a server; the front-end card writing applet sends a card writing request to the server; the server obtains first personalized data from a resource system based on the card writing request; performs multiple encryptions on the first personalized data using a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data; calls a card vendor's card writing component to verify the personalized encrypted data to obtain card writing data; receives the card writing data returned by the card writing component, encrypts the card writing data using a third preset encryption / decryption algorithm corresponding to a reader, and sends the encrypted card writing data to the front-end card writing applet; the front-end card writing applet receives the encrypted card writing data returned by the server; decrypts the encrypted card writing data using a third preset encryption / decryption algorithm corresponding to a reader to obtain first card writing data; and calls a reader to write the first card writing data.
[0013] A computer device includes a memory and a processor, wherein the memory stores computer-readable instructions, which, when executed by the processor, cause the processor to perform the steps of the aforementioned card writing data processing method or card writing method based on multiple encryption.
[0014] A storage medium storing computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of the above-described multi-encryption-based card writing data processing method or card writing method.
[0015] The aforementioned card writing data processing method and system based on multiple encryption, by using a first preset encryption and decryption algorithm and a second preset encryption and decryption algorithm to perform multiple encryption on the first personalized data, not only ensures the security of personalized data transmission between the back-end card writing system and the card merchant's card writing component and achieves compatibility with different cards, but also ensures the security of data transmission during card writing between the reader and the card. Attached Figure Description
[0016] Figure 1 This is a diagram illustrating the implementation environment of the card writing method and the card writing data processing method based on multiple encryption provided in one embodiment.
[0017] Figure 2 This is a schematic diagram of the structure of a remote card writing system provided in one embodiment;
[0018] Figure 3 This is a flowchart illustrating a card writing data processing method based on multiple encryption in one embodiment;
[0019] Figure 4 This is a flowchart illustrating a card writing method in one embodiment. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0021] It should be noted that, unless otherwise defined, the technical or scientific terms used in this invention should have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "first," "second," and similar terms used in this invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0022] To facilitate understanding, the technical terms involved in this invention will first be explained.
[0023] (1) Writing the card
[0024] Writing to a SIM card refers to storing user-related data. Specifically, writing to a SIM card involves storing information about the digital mobile phone customer, encryption keys, and the user's phonebook on the SIM card chip. This data can be used by the GSM network to authenticate the customer's identity and encrypt voice information during calls.
[0025] (2) Root Certificate
[0026] A root certificate is a special type of digital certificate; it's the lowest-level trusted certificate, issued by a Certificate Authority (CA). Its primary function is to establish a foundation of trust between users. Every digital certificate must be supported by a root certificate; only with a root certificate is a digital certificate considered valid and trusted.
[0027] In this invention, the HTTPS certificates used between the front-end card writing mini-program and the back-end card writing system are issued using the same root certificate, and both parties require authentication and authorization for communication.
[0028] To facilitate understanding, we will use two existing card writing technologies to illustrate the technical problems existing in the current technology.
[0029] There are two existing card writing methods: one is remote card writing via a wired reader from a PC using a browser / server (B / S) architecture; the other is card writing via a Bluetooth reader from a terminal app. The B / S architecture is a network architecture model that centralizes the core functionality of the system on a server, simplifying system development, maintenance, and use, as it can run through a browser without requiring additional client installations. This invention primarily aims to improve the method of card writing via a Bluetooth reader from a terminal app.
[0030] Typically, when a terminal app writes cards via a Bluetooth reader, it only uses the reader for single-layer encryption, and the data between the reader and the card is unprotected, posing a security risk. Furthermore, the encrypted data needs to be transmitted between the front-end card writing app and the back-end server, increasing the risk of data leakage. In addition, it usually cannot support different card systems simultaneously. Therefore, the card writing method and the multi-encryption-based card writing data processing method provided by this invention address these problems, improving the security of app-based card writing and its compatibility with multiple vendor card systems.
[0031] The following is combined with Figures 1-4 This invention describes a card writing data processing method and card writing method and system based on multiple encryption.
[0032] Figure 1 This diagram illustrates the implementation environment of a card writing method and a multi-encryption-based card writing data processing method provided in one embodiment. The method includes a web management platform 110, a background card writing system 120, a cache server cluster 130, a database server cluster 140, a client remote writing app 150, a Bluetooth reader 160, and a UIM / SIM card 170. The web management platform 110 is connected to the mobile intranet, while the background card writing system 120, cache server cluster 130, and database server cluster 140 are all connected to the mobile core network. Both the web management platform 110 and the background card writing system 120 can securely transmit data with the client remote writing app 150 via HTTPS. The background card writing system 120 may include at least one remote card writing system node.
[0033] The client-side remote card writing mini-program 150 can be, for example, a card writing mini-program implemented using WeChat mini-program technology. The UIM / SIM card 170 is a UIM / SIM card requiring personalization, used for new account openings or card replacements. Furthermore, business personnel / maintenance personnel can perform operations such as permission and remote card writing management through the web management platform 110. The backend card writing system 120 is equivalent to a remote backend server, mainly used to manage system function modules and interface modules. Specific management functions include account management, permission management, card product management, card vendor management, key management (using a hardware encryption machine), card writing component management, log management, and statistical analysis. The interface modules mainly include a card writing data application interface and a card writing result reporting interface. The database server cluster 140 can be used to store data corresponding to the web management platform 110 and the backend card writing system 120, while the cache server cluster 130 can be used to store intermediate data generated during the operation of the web management platform 110 and the backend card writing system 120.
[0034] Figure 2 This is a schematic diagram of the remote card writing system provided by the present invention. Figure 2 As shown, the remote card writing system is structured in a layered manner, specifically including: gateway layer, business layer, basic platform layer, middleware layer and data layer.
[0035] The gateway layer includes load balancing, circuit breaking / rate limiting, intelligent routing, a registry center, and security authentication services. The business layer is mainly divided into two parts: a remote write management system and a remote write service system. The remote write management system includes user management, permission management, card product management, card vendor management, key management, card writing component management, and log management. The remote write service system includes reporting card writing data and results (calling the key management system for encryption / decryption and management). The business layer can be understood as corresponding to the aforementioned backend card writing system 120. The basic platform layer includes object storage, task notification, log analysis, statistical reports, system monitoring, and a configuration center. The middleware layer includes message queues, MyCat table and database sharding, and Tomcat automatic deployment. The data layer can use MySQL for database storage, Redis for cache storage, MFS for file storage, and Elasticsearch for distributed search and analysis.
[0036] Understandably, layering ensures the system's robustness and maintainability, and greatly facilitates installation, deployment, and implementation. Furthermore, the system maintains business scalability. Business scalability gives business personnel greater autonomy, enabling them to dynamically add business modules based on market demands, thus providing a guarantee for the gradual advancement of data business development.
[0037] like Figure 3As shown, in one embodiment, a multi-encryption-based card writing data processing method is proposed, which can be executed by a server. The server may include a background card writing system 120 and a key management system. Specifically, as... Figure 3 As shown, the card writing data processing method based on multiple encryption provided by the present invention may include the following steps:
[0038] Step 310: Based on the card writing request sent by the front-end card writing applet, obtain the first personalized data from the resource system.
[0039] Among them, the resource system is the resource system corresponding to the card merchant.
[0040] It is understood that the server can receive card writing requests from the front-end card writing mini-program, the card writing request including card information; and send a request to the card merchant resource system corresponding to the card information to apply for personalized data. The card information is used to indicate the card merchant type. For example, it can be data pre-written by the card merchant during card production, such as the Integrated Circuit Card Identifier (ICCID) or empty card serial number.
[0041] Step 320: The first personalized data is encrypted multiple times based on the first preset encryption and decryption algorithm and the second preset encryption and decryption algorithm to obtain personalized encrypted data.
[0042] The first preset encryption / decryption algorithm is the one corresponding to the card. The second preset encryption / decryption algorithm is the one corresponding to the card seller's card writing component. These two algorithms are used to perform multiple encryptions on the first personalized data, resulting in personalized encrypted data.
[0043] The first piece of personalized data is the personal information of the user whose card is to be written. The card vendor writing component is the card writing component corresponding to the card vendor whose card is to be written.
[0044] As mentioned earlier, the server can receive card writing requests from the front-end card writing mini-program, which include card information; and send a request to the card merchant resource system corresponding to the card information to apply for personalized data. In other words, in practical applications, the received card writing requests can be from different card merchants, therefore, the card to be written each time can be from a different card merchant. Therefore, in step 320, the encryption algorithm corresponding to the card merchant's card writing component is used to encrypt the first personalized data. This not only ensures the security of the personalized data during subsequent calls to the card merchant's card writing component to verify the first personalized data, but also achieves compatibility with different cards.
[0045] In addition, the first preset encryption and decryption algorithm is used to further encrypt the personalized data, which can ensure the security of personal data during subsequent transmission between the reader and the card.
[0046] Step 330: Call the card seller's card writing component to verify the personalized encrypted data and obtain the card writing data.
[0047] It's understandable that verifying the personalized encrypted data by calling the corresponding card seller's card writing component demonstrates compatibility with different cards. It's also understandable that, prior to this step, step 320 has already encrypted the first personalized data using a second preset encryption / decryption algorithm corresponding to the card seller's card writing component. Therefore, not only is the security of the first personalized data ensured during transmission from the backend card writing system to the card seller's card writing component, but only the corresponding card seller's card writing component knows the corresponding decryption method. In other words, only the corresponding card seller's card writing component can decrypt the first personalized data and verify it, thereby further ensuring the security of the personalized data.
[0048] Step 340: Receive the card writing data returned by the card vendor's card writing component, and encrypt the card writing data based on the third preset encryption / decryption algorithm corresponding to the reader.
[0049] Under normal circumstances, after receiving the card writing data, the backend card writing system encrypts the data using a third preset encryption / decryption algorithm corresponding to the reader. However, it does not encrypt the first personalized data using a second preset encryption / decryption algorithm corresponding to the card vendor's card writing component, nor does it encrypt the personalized data using a first preset encryption / decryption algorithm corresponding to the card. Therefore, the card writing data obtained based on the personalized data typically lacks the card data encryption compared to the card writing data of this invention. Consequently, there is a security risk during the transmission of the card writing data between the reader and the card. In contrast, the card writing data of this invention is encrypted using a first preset encryption / decryption algorithm corresponding to the card, thus further improving the security of the personalized data throughout the entire process from the backend card writing system to the card.
[0050] Step 350: Send the encrypted card writing data to the front-end card writing mini-program.
[0051] The card writing data processing method based on multiple encryption provided by this invention performs multiple encryption on the first personalized data based on a first preset encryption and decryption algorithm and a second preset encryption and decryption algorithm. This not only ensures the security of personalized data transmission between the back-end card writing system and the card seller's card writing component and achieves compatibility with different cards, but also ensures the security of data transmission during card writing between the reader and the card.
[0052] In one embodiment, the step of performing multiple encryptions on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data includes: acquiring the first preset encryption / decryption algorithm and the second preset encryption / decryption algorithm; encrypting the first personalized data based on the first preset encryption / decryption algorithm to obtain second personalized data; and encrypting the second personalized data based on the second preset encryption / decryption algorithm to obtain personalized encrypted data.
[0053] Specifically, the first preset encryption / decryption algorithm and the second preset encryption / decryption algorithm are pre-stored in the key management system. Therefore, the first preset encryption / decryption algorithm and the second preset encryption / decryption algorithm can be obtained from the key management system.
[0054] In one embodiment, the first preset encryption algorithm is an asymmetric encryption algorithm or a key negotiation algorithm. Accordingly, encrypting the first personalized data based on the first preset encryption / decryption algorithm includes:
[0055] The first personalized data is encrypted using the public key in an asymmetric encryption algorithm or the session key generated by a key negotiation algorithm.
[0056] In one embodiment, the card writing component, during the verification of the personalized encrypted data, includes a decryption and encryption process based on the second preset encryption / decryption algorithm. Correspondingly, before encrypting the card writing data based on the third preset encryption / decryption algorithm corresponding to the reader, the method further includes:
[0057] The card writing data is decrypted based on the second preset encryption / decryption algorithm.
[0058] In one embodiment, the card writing applet on the front end and the HTTPS certificate corresponding to the server are issued by the same root certificate.
[0059] It is understandable that the front-end card writing mini-program and the corresponding HTTPS certificate on the server are issued by the same root certificate, and both parties need authentication and authorization to communicate, which can improve the security of personalized data communication between the front-end card writing mini-program and the server.
[0060] This invention also provides a card writing method, a front-end card writing applet, the method comprising: sending a card writing request to a server; receiving encrypted card writing data returned by the server; the encrypted card writing data being card writing data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm; decrypting the encrypted card writing data based on a third preset encryption / decryption algorithm corresponding to the reader to obtain first card writing data; and calling the reader to write the first card writing data.
[0061] It is understood that the card writing request and the encrypted card writing data in this card writing method can be found in the relevant descriptions of the card writing data processing method based on multiple encryption mentioned above. For the sake of brevity, they will not be repeated here.
[0062] The card writing method provided by this invention ensures secure communication between the card and the reader during the card writing process by writing card data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm. This improves the security of the transmission of personalized data from the server to the card and also achieves compatibility with different cards.
[0063] In one embodiment, the process of the reader writing the first card writing data includes: transmitting the first card writing data to the card, and having the card decrypt the first card writing data based on a first preset encryption / decryption algorithm to obtain second card writing data and write it to the card.
[0064] Figure 4 This is a schematic flowchart illustrating the card writing method provided by the present invention. It can be understood that... Figure 4 The card writing method provided by this invention is explained through the interaction process between the front-end card writing mini-program, reader, card, card seller card writing component, back-end card writing system, key management system, and resource management system. It can be understood that the back-end card writing system and key management system together constitute the server. For example... Figure 4 As shown, the card writing method provided by the present invention includes the following steps:
[0065] Step 401: The remote writing mini-program receives the card writing request sent by the web management platform and sends an instruction to the reader to request card reading.
[0066] Step 402: The reader executes the card reading instruction to obtain card information from the card.
[0067] Step 403: The reader returns the read card information to the remote writing mini-program.
[0068] Step 404: The remote writing mini-program sends the obtained card information and other card writing request parameters to the card writing system to request card writing.
[0069] Step 405: The background card writing system verifies the validity of the card based on the ICCID or empty card serial number in the card information. If the card is a physical card, it is determined to be invalid, and step 4051 is executed; if the card is an empty card, it is determined to be valid, and step 4052 is executed.
[0070] Step 4051: Return the invalid message to the remote writing mini-program and display "Please insert the white card to try again, process terminated" in the remote writing mini-program;
[0071] Step 4052: Further parse the ICCID or empty card serial number, obtain the card type according to the rules corresponding to the ICCID or empty card serial number, and send an execution instruction to the resource system to request personalized data.
[0072] It is understandable that before sending an execution instruction requesting personalized data to the resource system, the execution instruction can be encrypted using an encryption algorithm in the key management system.
[0073] Step 406: The resource system matches personalized data based on the personalized data information in the execution instruction, and returns a response data message through the personalized data.
[0074] Step 407: The background card writing system receives personalized data via the HTTPS protocol, and then, based on the card information, calls the first preset encryption and decryption algorithm corresponding to the card and the second preset encryption and decryption algorithm corresponding to the card seller's card writing component from the key management system to perform multiple encryptions on the personalized data, thereby obtaining personalized encrypted data.
[0075] Step 408: The backend card writing system sends the encapsulated personalized encrypted data to the card seller's card writing component.
[0076] Step 409: The card seller's card writing component decrypts and verifies the correctness of the personalized data, and encapsulates and encrypts the personalized data to obtain the card writing data.
[0077] Step 410: The card seller's card writing component returns the card writing data to the card writing system.
[0078] Step 411: The background card writing system receives the card writing data and calls the second preset encryption and decryption algorithm corresponding to the card merchant's card writing component in the key management system to decrypt the card writing data. At the same time, it uses the third preset encryption and decryption algorithm corresponding to the reader to encrypt and encapsulate the data to obtain the encrypted card writing data, which can be simply referred to as ciphertext card writing data.
[0079] It is understandable that if step 409 requires further decryption of the personalized data after the card seller's card writing component has been decrypted using the first preset encryption and decryption algorithm corresponding to the card, then in step 411, before using the third preset encryption and decryption algorithm corresponding to the reader to encrypt the data, the first preset encryption and decryption algorithm corresponding to the card can be used to encrypt the card writing data first.
[0080] Step 412: The background card writing system returns the encrypted card writing data to the mini-program.
[0081] Step 413: The remote writing mini-program receives the encrypted card writing data and decrypts it according to the third preset encryption and decryption algorithm corresponding to the reader. Then, it calls the reader to execute the card writing command through the Bluetooth channel.
[0082] In step 414, the reader transmits the encrypted card writing data to the card, and the card uses its private key to decrypt the data and write personalized data.
[0083] Step 415: The reader returns the instruction execution result to the remote writing mini-program.
[0084] Step 416: The remote writing mini-program sends the card writing result request to the backend card writing system.
[0085] Step 417: The background card writing system interacts with the key management system to process the card writing result message and encapsulate the message.
[0086] Step 418: The background card writing system calls the resource system interface to send back the card writing result.
[0087] Step 419: The resource system parses the card writing result and encapsulates the response data.
[0088] Step 420: The resource system returns the card writing result response data to the background card writing system.
[0089] Step 421: The background card writing system parses the response message and updates the corresponding data status and record in the database.
[0090] Step 422: The background card writing system returns the card writing result response to the remote writing mini-program.
[0091] Step 423: The final card writing result is displayed on the remote writing mini-program page, and the process ends.
[0092] This invention also provides a card writing system, comprising: a front-end card writing applet and a server; the front-end card writing applet is used to send a card writing request to the server; the server is used to obtain first personalized data from a resource system based on the card writing request; and to perform multiple encryptions on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data; it is also used to call the card vendor's card writing component to verify the personalized encrypted data to obtain card writing data; and to receive the card writing data returned by the card writing component, encrypt the card writing data based on a third preset encryption / decryption algorithm corresponding to the reader, and send the encrypted card writing data to the front-end card writing applet; the front-end card writing applet is used to receive the encrypted card writing data returned by the server; the encrypted card writing data is card writing data encrypted by the second preset encryption / decryption algorithm; and to decrypt the encrypted card writing data based on the third preset encryption / decryption algorithm corresponding to the reader to obtain first card writing data; and to call the reader to write the first card writing data.
[0093] The card writing data processing system based on multiple encryption provided by this invention performs multiple encryptions on the first personalized data based on a first preset encryption and decryption algorithm and a second preset encryption and decryption algorithm. This not only ensures the security of personalized data transmission between the back-end card writing system and the card seller's card writing component and achieves compatibility with different cards, but also ensures the security of data transmission during card writing between the reader and the card.
[0094] In one embodiment, a computer device is provided, the computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the following steps corresponding to the card writing data processing method based on multiple encryption: obtaining first personalized data from a resource system based on a card writing request sent by a front-end card writing applet; performing multiple encryption on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data; calling a card vendor's card writing component to verify the personalized encrypted data to obtain card writing data; receiving the card writing data returned by the card vendor's card writing component, encrypting the card writing data based on a third preset encryption / decryption algorithm corresponding to the reader; and sending the encrypted card writing data to the front-end card writing applet. Alternatively, when the processor executes the computer program, it implements the following steps corresponding to the card writing method: sending a card writing request to the server; receiving encrypted card writing data returned by the server; the encrypted card writing data is card writing data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm; decrypting the encrypted card writing data based on a third preset encryption / decryption algorithm corresponding to the reader to obtain first card writing data; and calling the reader to write the first card writing data.
[0095] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, and when the program instructions are executed by a computer, the computer is able to execute the card writing data processing method and card writing method based on multiple encryption provided by the present invention, wherein the card writing data processing method based on multiple encryption comprises: obtaining first personalized data from a resource system based on a card writing request sent by a front-end card writing applet; performing multiple encryption on the first personalized data based on a first preset encryption and decryption algorithm and a second preset encryption and decryption algorithm to obtain personalized encrypted data; calling a card vendor card writing component to verify the personalized encrypted data to obtain card writing data; receiving the card writing data returned by the card vendor card writing component, encrypting the card writing data based on a third preset encryption and decryption algorithm corresponding to the reader; and sending the encrypted card writing data to the front-end card writing applet. The card writing method includes: sending a card writing request to the server; receiving encrypted card writing data returned by the server; the encrypted card writing data is card writing data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm; decrypting the encrypted card writing data based on a third preset encryption / decryption algorithm corresponding to the reader to obtain first card writing data; and calling the reader to write the first card writing data.
[0096] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the card writing data processing method and card writing method based on multiple encryption provided by the present invention. The card writing data processing method based on multiple encryption includes: obtaining first personalized data from a resource system based on a card writing request sent by a front-end card writing applet; performing multiple encryptions on the first personalized data based on a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm to obtain personalized encrypted data; calling a card vendor's card writing component to verify the personalized encrypted data to obtain card writing data; receiving the card writing data returned by the card vendor's card writing component and encrypting the card writing data based on a third preset encryption / decryption algorithm corresponding to the reader; and sending the encrypted card writing data to the front-end card writing applet. The card writing method includes: sending a card writing request to the server; receiving encrypted card writing data returned by the server; the encrypted card writing data is card writing data encrypted by a first preset encryption / decryption algorithm and a second preset encryption / decryption algorithm; decrypting the encrypted card writing data based on a third preset encryption / decryption algorithm corresponding to the reader to obtain first card writing data; and calling the reader to write the first card writing data.
[0097] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0098] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A card writing data processing method based on multiple encryption, characterized in that, Applied to a server side, the method comprises: Based on the card writing request sent by the front-end card writing applet, obtaining first personalized data from a resource system; Based on a first preset encryption and decryption algorithm corresponding to the card and a second preset encryption and decryption algorithm corresponding to a card vendor card writing component, multiple encryption is performed on the first personalized data to obtain personalized encrypted data; The card vendor card writing component is called to verify the personalized encrypted data to obtain card writing data; The card writing data returned by the card vendor card writing component is received, and the card writing data is encrypted based on a third preset encryption and decryption algorithm corresponding to a reader; The encrypted card writing data is sent to the front-end card writing applet, so that the card writing applet decrypts the encrypted card writing data based on the third preset encryption and decryption algorithm corresponding to the reader to obtain first card writing data, and the reader is called to write the first card writing data to the card; wherein, in the process of writing the first card writing data to the card by the reader, the first card writing data is transmitted to the card, and the first card writing data is decrypted by the card based on the first preset encryption and decryption algorithm to obtain second card writing data and written into the card.
2. The multiple encryption-based card writing data processing method of claim 1, wherein, The first preset encryption and decryption algorithm and the second preset encryption and decryption algorithm are obtained; The first personalized data is encrypted based on the first preset encryption and decryption algorithm to obtain second personalized data; The second personalized data is encrypted based on the second preset encryption and decryption algorithm to obtain personalized encrypted data. The first preset encryption algorithm is an asymmetric encryption algorithm or a key agreement algorithm, and correspondingly, the encryption of the first personalized data based on the first preset encryption and decryption algorithm comprises:
3. The multiple encryption-based card writing data processing method of claim 2, wherein, The first personalized data is encrypted based on a public key in the asymmetric encryption algorithm or a session key generated based on the key agreement algorithm. The card vendor card writing component comprises a decryption and encryption process of the personalized encrypted data based on the second preset encryption and decryption algorithm in the process of verifying the personalized encrypted data, and correspondingly, before the card writing data is encrypted based on the third preset encryption and decryption algorithm corresponding to the reader, the method further comprises:
4. The multiple encryption-based card writing data processing method of claim 1, wherein, The card writing data is decrypted based on the second preset encryption and decryption algorithm. The https certificate corresponding to the front-end card writing applet and the server side is the same certificate.
5. The multiple encryption-based card writing data processing method of claim 1, wherein, Applied to a front-end card writing applet, the method comprises:
6. A card writing method characterized by comprising: Sending a card writing request to a server side; Receiving encrypted card writing data returned by the server side; the encrypted card writing data is card writing data encrypted based on a first preset encryption and decryption algorithm corresponding to a card and a second preset encryption and decryption algorithm corresponding to a card vendor card writing component; Decrypting the encrypted card writing data based on a third preset encryption and decryption algorithm corresponding to a reader to obtain first card writing data; Calling the reader to write the first card writing data; The first write card data is transmitted to the card by the reader during the process of writing the first write card data to the card, and the card decrypts the first write card data based on a first preset encryption and decryption algorithm to obtain second write card data and writes the second write card data to the card.
7. A card writing system characterized by comprising: The system comprises a front-end write card applet and a server; The front-end write card applet is configured to send a write card request to the server; The server is configured to obtain first personalized data from a resource system based on the write card request, to perform multiple encryption on the first personalized data based on a first preset encryption and decryption algorithm corresponding to the card and a second preset encryption and decryption algorithm corresponding to a card vendor write card component, to obtain personalized encrypted data, to call the card vendor write card component to verify the personalized encrypted data to obtain write card data, and to receive the write card data returned by the write card component, to encrypt the write card data based on a third preset encryption and decryption algorithm corresponding to the reader, and to send the encrypted write card data to the front-end write card applet; The front-end write card applet is configured to receive the encrypted write card data returned by the server, to decrypt the encrypted write card data based on the third preset encryption and decryption algorithm corresponding to the reader to obtain first write card data, and to call the reader to write the first write card data.
8. A computer device comprising a memory and a processor, the memory having stored therein computer readable instructions, characterized in that, The computer readable instructions, when executed by the processor, cause the processor to perform the steps of the write card data processing method based on multiple encryption according to any one of claims 1 to 5 or the write card method according to any one of claim 6.
9. A storage medium storing computer readable instructions, wherein, The computer readable instructions, when executed by the one or more processors, cause the one or more processors to perform the steps of the write card data processing method based on multiple encryption according to any one of claims 1 to 5 or the write card method according to any one of claim 6.
Citation Information
Patent Citations
Data transmission method and device based on block chain, electronic equipment and storage medium
CN112104627A
Remote card writing method, card writing terminal, server and storage medium
CN114579985A