A method and device for verifying the authority of an IC card, a card reading device, and a storage medium

By performing secondary encryption on the main control sector and data sector of the IC card and calculating multi-level card reading passwords, the problem of low reliability and security of traditional IC card encryption methods is solved, achieving higher IC card usage security and access control management reliability.

CN116226942BActive Publication Date: 2026-05-19SHENZHEN QINLIN TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN QINLIN TECH
Filing Date
2023-02-28
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Traditional IC card encryption methods have low reliability and security, making them easy to crack and resulting in security vulnerabilities in access control management.

Method used

It employs a two-stage encryption method involving the master control sector and the data sector. By calculating the first and second card reading passwords, the IC card's permissions are verified, and different encryption factors and algorithms are used to increase the difficulty of cracking.

Benefits of technology

This improves the reliability and security of IC cards, increases the difficulty of cracking them, and enhances the security of access control management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116226942B_ABST
    Figure CN116226942B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a kind of IC card's permission verification method, device, card reading equipment and storage medium.The method comprises: reading the main control sector data of IC card, and according to the card information in the main control sector data, the first card reading password is calculated;The main control sector data further includes the sector password of data sector;Verify whether the first card reading password is correct, if correct, then according to the sector password, the second card reading password is calculated;Verify whether the second card reading password is correct, if correct, then the target permission data corresponding to card reading equipment is read from the data sector;According to the target permission data, the permission of the IC card is verified.The technical scheme provided in the embodiment of the application, by separately setting main control sector and data sector, the storage of permission data is encrypted twice, and the encryption mode is different, so as to improve the difficulty of IC card being violently cracked, improve the reliability and security of IC card use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of IC card encryption technology, and in particular to an IC card authorization verification method, device, card reader, and storage medium. Background Technology

[0002] IC cards are commonly used for access control devices. If the access control device successfully verifies the IC card's authorization, the door can be unlocked by swiping the card. However, IC cards are easily copied, potentially leading to unauthorized use by unregistered personnel. Therefore, encryption of IC cards has become increasingly common. However, traditional encryption methods are too simplistic, typically using a unique key for each card, employing the card number plus a fixed key. This makes them vulnerable to brute-force attacks. Furthermore, if the algorithm and fixed key are leaked, all IC cards in the entire project could be easily compromised, resulting in significant security vulnerabilities in access control systems and low reliability and security. Summary of the Invention

[0003] This invention provides an IC card authorization verification method, device, card reader, and storage medium to solve the problem of low reliability and security when using traditional encryption methods.

[0004] In a first aspect, embodiments of the present invention provide an IC card authorization verification method, the method comprising:

[0005] The system reads the main control sector data of the IC card and calculates the first card reading password based on the card information in the main control sector data; the main control sector data also includes the sector password of the data sector.

[0006] Verify whether the first card reader password is correct. If it is correct, calculate the second card reader password based on the sector password.

[0007] Verify whether the second card reader password is correct. If it is correct, read the target permission data corresponding to the card reader from the data sector.

[0008] Verify the IC card's permissions based on the target permission data.

[0009] Optionally, before calculating the second card reader password based on the sector password, the method further includes:

[0010] The sector number of the target data sector storing the target permission data in the IC card is determined according to the permission identifier of the card reader;

[0011] The target sector password is obtained from the master control sector data according to the sector number;

[0012] Accordingly, calculating the second card reader password based on the sector password includes:

[0013] Calculate the second card reader password based on the target sector password;

[0014] Accordingly, reading the target permission data corresponding to the card reader from the data sector includes:

[0015] Read the target permission data from the target data sector.

[0016] Optionally, there may be multiple data sectors;

[0017] Accordingly, determining the sector number of the target data sector storing the target permission data in the IC card based on the permission identifier of the card reader includes:

[0018] The sector number is obtained by taking the modulo remainder of the number of data sectors with the permission identifier.

[0019] Optionally, before obtaining the sector number by taking the modulo remainder of the permission identifier with respect to the number of data sectors, the method further includes:

[0020] The permission identifier is processed using a preset obfuscated number.

[0021] Optionally, the sector cipher is calculated from a first encryption factor, which includes a random cipher.

[0022] Optionally, the master control sector data may further include a first check bit field;

[0023] Accordingly, before calculating the second card reader password based on the sector password, the method further includes:

[0024] The first preset encryption algorithm is used to encrypt the data in the master control sector data other than the first check bit field, and the first check bit field is used for comparison.

[0025] And / or,

[0026] The sector cipher includes a second check bit field;

[0027] Accordingly, before calculating the second card reader password based on the sector password, the method further includes:

[0028] The second preset encryption algorithm is used to encrypt the data in the sector password other than the second check bit field, and the second check bit field is used for comparison.

[0029] Optionally, the card information includes card status and / or card validity period;

[0030] Accordingly, before calculating the second card reader password based on the sector password, the method further includes:

[0031] Verify the validity of the IC card based on the card status and / or the card validity period.

[0032] Secondly, embodiments of the present invention also provide an IC card authorization verification device, the device comprising:

[0033] The first card reader password calculation module is used to read the main control sector data of the IC card and calculate the first card reader password based on the card information in the main control sector data; the main control sector data also includes the sector password of the data sector;

[0034] The second card reader password calculation module is used to verify whether the first card reader password is correct. If it is correct, the second card reader password is calculated based on the sector password.

[0035] The target permission data reading module is used to verify whether the second card reading password is correct. If it is correct, it reads the target permission data corresponding to the card reading device from the data sector.

[0036] The permission verification module is used to verify the permissions of the IC card based on the target permission data.

[0037] Thirdly, embodiments of the present invention also provide a card reader, the card reader comprising:

[0038] One or more processors;

[0039] Memory, used to store one or more programs;

[0040] When the one or more programs are executed by the one or more processors, the one or more processors implement the IC card authorization verification method provided in any embodiment of the present invention.

[0041] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the IC card authorization verification method provided in any embodiment of the present invention.

[0042] This invention provides a method for verifying the permissions of an IC card. First, the main control sector data of the IC card is read, and a first card reader password is calculated based on the card information contained therein. If the first card reader password is verified, a second card reader password is calculated based on the sector password of the data sector in the main control sector data. If the second card reader password is verified, the target permission data corresponding to the card reader is read from the data sector. Then, the IC card's permissions can be verified based on this target permission data. The IC card permission verification method provided by this invention performs secondary encryption on the storage of permission data by separately setting the main control sector and the data sector, and the two encryption methods are different, thereby increasing the difficulty of brute-force cracking of the IC card and improving the reliability and security of IC card use. Attached Figure Description

[0043] Figure 1 This is a flowchart of the IC card authorization verification method provided in Embodiment 1 of the present invention;

[0044] Figure 2 This is a schematic diagram of the IC card authorization verification device provided in Embodiment 2 of the present invention;

[0045] Figure 3 This is a schematic diagram of the card reader device provided in Embodiment 3 of the present invention. Detailed Implementation

[0046] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0047] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the steps as sequential processes, many of these steps can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the steps can be rearranged. The process can be terminated when its operation is complete, but may also have additional steps not included in the figures. The process can correspond to a method, function, procedure, subroutine, subroutine, etc.

[0048] Example 1

[0049] Figure 1This is a flowchart of an IC card access control method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where IC card access control is verified when using an IC card to open an access control device. This method can be executed by the IC card access control device provided in this embodiment, which can be implemented in hardware and / or software, and is generally integrated into a card reader (such as an access control device). Figure 1 As shown, the specific steps include the following:

[0050] S11. Read the main control sector data of the IC card and calculate the first card reading password based on the card information in the main control sector data; the main control sector data also includes the sector password of the data sector.

[0051] Specifically, IC cards typically have 16 sectors for data storage, while some IC cards include 17 sectors. One of these sectors can be designated as the master control sector, and one or more other sectors can be used as data sectors. In particular, for IC cards with 17 sectors, the 17th sector can be designated as the master control sector. Since ordinary card readers cannot recognize this, the security of access control data can be further enhanced. The master control sector can be used to store card information, encryption configuration information, and sector passwords for the data sectors, etc. The data sectors can be used to store access control data corresponding to the card reader. Furthermore, card information can include card number, card status, and card expiration date, etc. Encryption configuration information can include encryption methods, version information, data obfuscation methods, and data sector activation, etc., thus providing more encryption options and allowing for seamless adaptation after card reader upgrades. The sector password can be calculated using an encryption algorithm based on a first encryption factor and written to the IC card via a card writing device. Optionally, the first encryption factor includes a random password, which can be randomly generated when generating each sector password, thus achieving dynamic encryption of the data sectors and ensuring that the password for each sector of each card is different, thereby further increasing the difficulty of cracking. Furthermore, the first encryption factor can also include one or more of the following: IC card number, fixed key / salt, device private key, sector number, and project private key. Due to the presence of the random password, even if these additional encryption factors or even the encryption algorithm used are leaked, the sector password for each data sector remains uncalculated and underivative. For each IC card in the entire project, brute-force cracking and data writing to all data sectors are required separately, significantly increasing the difficulty and workload of cracking. For data sectors, due to sector capacity limitations, each data sector can store a maximum of 256 bits of data. Therefore, 0 and 1 can be used to represent permission data. For example, 0 can represent no access permission and 1 can represent access permission. Thus, each data sector can store different permissions for 256 card readers. A 16-sector IC card can store different permissions for up to 3840 card readers, and a 17-sector IC card can store different permissions for up to 4096 card readers, thereby enabling fine-grained permission management in ultra-large projects.

[0052] The card reader can be pre-set to read which sector first; this sector is the master control sector of the IC card. When a user swipes the card (i.e., the IC card is brought close to the reader), the reader can first read the master control sector data to obtain card information and the sector passwords of the data sectors. Then, based on a one-card-one-password encryption logic, a first card reader password can be calculated based on the card information. Specifically, this can be calculated using an encryption algorithm based on a second encryption factor. The second encryption factor can include the IC card number from the card information, as well as the project private key and a fixed key / salt, etc., thus ensuring that the first card reader passwords generated for different projects and different IC card numbers are different. The encryption algorithm can be determined based on the encryption configuration information in the master control sector data, so different IC cards can use different encryption algorithms. There are no restrictions on the specific encryption algorithm used; asymmetric encryption can be selected.

[0053] S12. Verify whether the first card reader password is correct. If it is correct, calculate the second card reader password based on the sector password.

[0054] Specifically, after obtaining the first card reader password, it can be compared with the corresponding correct password to verify its correctness. If the first card reader password is correct, the second card reader password can be calculated based on the sector password stored in the master control sector. The second card reader password is a secondary encryption of the sector password, specifically calculated using an encryption algorithm based on a third encryption factor. This third encryption factor can include the sector password, as well as the IC card number, sector number, project private key, and fixed key / salt, etc. The fixed key / salt can be different from the fixed key / salt in the second encryption factor, and the encryption algorithm used can also be different. If the first card reader password is incorrect, the authorization verification can be directly determined as failed.

[0055] S13. Verify whether the second card reader password is correct. If correct, read the target permission data corresponding to the card reader from the data sector.

[0056] Specifically, after obtaining the second card reader password, it can be compared with the corresponding correct password to verify its validity. If the second card reader password is correct, the target permission data, such as 0 or 1, can be read from the data sector of the card reader. If the second card reader password is incorrect, the permission verification can be directly determined as failed.

[0057] Optionally, before calculating the second card reader password based on the sector password, the method further includes: determining the sector number of the target data sector storing the target permission data in the IC card based on the permission identifier of the card reader; obtaining the target sector password from the master control sector data based on the sector number; correspondingly, calculating the second card reader password based on the sector password includes: calculating the second card reader password based on the target sector password; correspondingly, reading the target permission data corresponding to the card reader from the data sector includes: reading the target permission data from the target data sector.

[0058] Specifically, one or more data sectors can be enabled. When multiple data sectors are enabled, one or more sector passwords can also be stored. When one data sector is enabled, a unique sector password can be directly obtained for verification of the second card reader password. Then, the corresponding target permission data is read from that data sector according to the card reader's permission identifier. Alternatively, the target data sector storing the target permission data can be first determined based on the correspondence between the card reader's permission identifier and the sector number of the data sector. Then, the corresponding target sector password can be found based on the sector number of the target data sector. Or, a unique sector password can be directly obtained for verification, and then the corresponding target permission data is read from the target data sector according to the card reader's permission identifier. When multiple data sectors are enabled, the target data sector storing the target permission data can be first determined based on the correspondence between the card reader's permission identifier and the sector number of the data sector. Then, the corresponding target sector password can be found in the master control sector data according to the sector number of the target data sector for verification of the second card reader password. Then, the corresponding target permission data is read from the target data sector according to the card reader's permission identifier.

[0059] Optionally, there may be multiple data sectors. Correspondingly, determining the sector number of the target data sector storing the target permission data in the IC card based on the permission identifier of the card reader includes: taking the modulo remainder of the permission identifier divided by the number of data sectors to obtain the sector number. Specifically, the permission data can be distributed across various data sectors. The data sector in which the target permission data corresponding to the card reader is located can be calculated. Specifically, the required sector number can be obtained by taking the modulo remainder of the permission identifier of the card reader (e.g., 1-4096) divided by the number of enabled data sectors (minimum 1, maximum total number of sectors minus 1), thus ensuring that data is stored in each data sector.

[0060] Optionally, before obtaining the sector number by taking the modulo remainder of the permission identifier with respect to the number of data sectors, the method further includes: processing the permission identifier using a preset obfuscation number. Specifically, a preset obfuscation number can be added to the permission identifier before taking the modulo remainder of the number of data sectors to obtain the required sector number, thereby making the calculation result difficult to crack. For example, if the permission identifier is 257, the preset obfuscation number is 16, and the number of data sectors (1-16) is 16, then taking the modulo remainder of 257+16 with respect to 16 yields 1, indicating that the target permission data of the card reader is stored in sector 1.

[0061] S14. Verify the permissions of the IC card based on the target permission data.

[0062] Specifically, after obtaining the target permission data from the card reader, the IC card's permissions can be verified based on this data. For example, if the target permission data read is 1, it means the card has permission; if the target permission data read is 0, it means the card does not have permission.

[0063] Based on the above technical solution, optionally, the master control sector data further includes a first check bit field; correspondingly, before calculating the second card reader password based on the sector password, the method further includes: encrypting the data in the master control sector data other than the first check bit field using a first preset encryption algorithm, and comparing it using the first check bit field; and / or, the sector password includes a second check bit field; correspondingly, before calculating the second card reader password based on the sector password, the method further includes: encrypting the data in the sector password other than the second check bit field using a second preset encryption algorithm, and comparing it using the second check bit field.

[0064] Specifically, the master control sector can reserve space for a first check bit to store the first check bit field. This field can be used to perform error detection, correction, and anti-counterfeiting verification on the entire master control sector data, thereby preventing data forgery or tampering. Therefore, before calculating the second card reader password, specifically after verifying the correctness of the first card reader password, the first preset encryption algorithm can be used to encrypt the data in the master control sector data other than the first check bit field, and compared with the first check bit field stored in the reserved space. If they do not match, it indicates that the master control sector data has been forged or tampered with. Similarly, the storage area for the sector password in the master control sector can also reserve space for a second check bit to store the second check bit field. This field can be used to perform error detection, correction, and anti-counterfeiting verification on the sector password, thereby preventing data forgery or tampering. Therefore, before calculating the second card reader password, specifically after determining the target data sector, the second preset encryption algorithm can be used to encrypt the data in the sector password other than the second check bit field, and compared with the second check bit field stored in the reserved space. If they do not match, it indicates that the sector password has been forged or tampered with. If the first checksum field or the second checksum field is inconsistent, the permission verification can be directly determined to have failed.

[0065] Based on the above technical solution, optionally, the card information includes card status and / or card validity period; correspondingly, before calculating the second card reader password based on the sector password, the method further includes: verifying whether the IC card is valid based on the card status and / or the card validity period. Specifically, the main control sector can store the IC card status and / or card validity period, so before calculating the second card reader password, specifically after the first verification bit field is verified and before determining the target data sector, the method can determine whether the IC card is a valid card based on the card status and / or card validity period. If valid, subsequent steps can proceed normally; if invalid, the authorization verification can be directly determined to have failed.

[0066] The technical solution provided in this invention first reads the main control sector data of the IC card and calculates a first card reading password based on the card information therein. If the first card reading password is verified, a second card reading password is calculated based on the sector password of the data sector in the main control sector data. If the second card reading password is verified, the target permission data corresponding to the card reader is read from the data sector, and then the IC card's permissions can be verified based on this target permission data. By separately setting the main control sector and the data sector, the storage of permission data is encrypted twice, and the two encryption methods are different, thereby increasing the difficulty of brute-force cracking of the IC card and improving the reliability and security of IC card use.

[0067] Example 2

[0068] Figure 2This is a schematic diagram of the IC card authorization verification device provided in Embodiment 2 of the present invention. This device can be implemented in hardware and / or software, and is generally integrated into a card reader to execute the IC card authorization verification method provided in any embodiment of the present invention. Figure 2 As shown, the device includes:

[0069] The first card reader password calculation module 21 is used to read the main control sector data of the IC card and calculate the first card reader password based on the card information in the main control sector data; the main control sector data also includes the sector password of the data sector;

[0070] The second card reader password calculation module 22 is used to verify whether the first card reader password is correct. If it is correct, the second card reader password is calculated based on the sector password.

[0071] The target permission data reading module 23 is used to verify whether the second card reading password is correct. If it is correct, it reads the target permission data corresponding to the card reading device from the data sector.

[0072] The permission verification module 24 is used to verify the permissions of the IC card based on the target permission data.

[0073] The technical solution provided in this invention first reads the main control sector data of the IC card and calculates a first card reading password based on the card information therein. If the first card reading password is verified, a second card reading password is calculated based on the sector password of the data sector in the main control sector data. If the second card reading password is verified, the target permission data corresponding to the card reader is read from the data sector, and then the IC card's permissions can be verified based on this target permission data. By separately setting the main control sector and the data sector, the storage of permission data is encrypted twice, and the two encryption methods are different, thereby increasing the difficulty of brute-force cracking of the IC card and improving the reliability and security of IC card use.

[0074] Based on the above technical solution, optionally, the IC card's authorization verification device also includes:

[0075] The sector number determination module is used to determine the sector number of the target data sector storing the target permission data in the IC card according to the permission identifier of the card reader before calculating the second card reading password based on the sector password.

[0076] The target sector password acquisition module is used to acquire the target sector password from the master control sector data according to the sector number;

[0077] Accordingly, the second card reader password calculation module 22 is specifically used for:

[0078] Calculate the second card reader password based on the target sector password;

[0079] Accordingly, the target permission data reading module 23 is specifically used for:

[0080] Read the target permission data from the target data sector.

[0081] Based on the above technical solution, optionally, the data sector can be multiple;

[0082] Correspondingly, the sector number determination module is specifically used for:

[0083] The sector number is obtained by taking the modulo remainder of the number of data sectors with the permission identifier.

[0084] Based on the above technical solution, optionally, the sector number determination module is also used for:

[0085] Before obtaining the sector number by taking the modulo of the permission identifier with respect to the number of data sectors, the permission identifier is processed using a preset obfuscated number.

[0086] Based on the above technical solution, optionally, the sector password is calculated from a first encryption factor, which includes a random password.

[0087] Based on the above technical solution, optionally, the master control sector data also includes a first check bit field;

[0088] Correspondingly, the IC card's authorization verification device also includes:

[0089] The first verification module is used to encrypt the data other than the first verification bit field in the master control sector data using a first preset encryption algorithm before calculating the second card reader password based on the sector password, and to compare the data using the first verification bit field.

[0090] And / or,

[0091] The sector cipher includes a second check bit field;

[0092] Correspondingly, the IC card's authorization verification device also includes:

[0093] The second verification module is used to encrypt the data other than the second verification bit field in the sector password using a second preset encryption algorithm before calculating the second card reader password based on the sector password, and to compare the data using the second verification bit field.

[0094] Based on the above technical solution, optionally, the card information includes card status and / or card validity period;

[0095] Correspondingly, the IC card's authorization verification device also includes:

[0096] The card validity verification module is used to verify whether the IC card is valid based on the card status and / or the card validity period before calculating the second card reading password based on the sector password.

[0097] The IC card authorization verification device provided in this embodiment of the invention can execute the IC card authorization verification method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0098] It is worth noting that in the above embodiments of the IC card authorization verification device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0099] Example 3

[0100] Figure 3 This is a schematic diagram of the structure of a card reader device provided in Embodiment 3 of the present invention, showing a block diagram of an exemplary card reader device suitable for implementing the embodiments of the present invention. Figure 3 The displayed card reader is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention. Figure 3 As shown, the card reader includes a processor 31, a memory 32, an input device 33, and an output device 34; the number of processors 31 in the card reader can be one or more. Figure 3 Taking a processor 31 as an example, the processor 31, memory 32, input device 33, and output device 34 in the card reader can be connected via a bus or other means. Figure 3 Taking the example of a connection between China and Israel via a bus.

[0101] The memory 32, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the IC card authorization verification method in this embodiment of the invention (e.g., the first card reader password calculation module 21, the second card reader password calculation module 22, the target authorization data reading module 23, and the authorization verification module 24 in the IC card authorization verification device). The processor 31 executes various functional applications and data processing of the card reader device by running the software programs, instructions, and modules stored in the memory 32, thereby implementing the aforementioned IC card authorization verification method.

[0102] The memory 32 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data created based on the use of the card reader. Furthermore, the memory 32 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 32 may further include memory remotely located relative to the processor 31, which can be connected to the card reader via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0103] Input device 33 can be used to read data stored in the IC card and generate key signal inputs related to user settings and function control of the card reader. Output device 34 can be used to control the opening and closing of switches according to the IC card's permissions.

[0104] Example 4

[0105] Embodiment 4 of the present invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform an IC card authorization verification method, the method comprising:

[0106] The system reads the main control sector data of the IC card and calculates the first card reading password based on the card information in the main control sector data; the main control sector data also includes the sector password of the data sector.

[0107] Verify whether the first card reader password is correct. If it is correct, calculate the second card reader password based on the sector password.

[0108] Verify whether the second card reader password is correct. If it is correct, read the target permission data corresponding to the card reader from the data sector.

[0109] Verify the IC card's permissions based on the target permission data.

[0110] Storage media can be any type of memory device or storage device. The term "storage media" is intended to include: mounting media, such as CD-ROMs, floppy disks, or magnetic tape devices; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (e.g., hard disks or optical storage); registers or other similar types of memory elements. Storage media may also include other types of memory or combinations thereof. Furthermore, storage media may reside in a computer system in which the program is executed, or may reside in a different second computer system connected to the computer system via a network (such as the Internet). The second computer system can provide program instructions to the computer for execution. The term "storage media" can include two or more storage media that may reside in different locations (e.g., in different computer systems connected via a network). Storage media may store program instructions (e.g., specifically implemented as a computer program) that can be executed by one or more processors.

[0111] Of course, the computer-executable instructions provided in the embodiments of the present invention are not limited to the method operations described above, but can also perform related operations in the IC card authorization verification method provided in any embodiment of the present invention.

[0112] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0113] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0114] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0115] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A method for verifying the authorization of an IC card, characterized in that, include: Read the main control sector data of the IC card and calculate the first card reading password based on the card information in the main control sector data; The master control sector data also includes the sector password of the data sector; Verify whether the first card reader password is correct. If it is correct, calculate the second card reader password based on the sector password. The second card reader password is a secondary encryption of the sector password. Verify whether the second card reader password is correct. If it is correct, read the target permission data corresponding to the card reader from the data sector. Verify the IC card's permissions based on the target permission data; Before calculating the second card reader password based on the sector password, the method further includes: The sector number of the target data sector storing the target permission data in the IC card is determined according to the permission identifier of the card reader; The target sector password is obtained from the master control sector data according to the sector number; Accordingly, the step of calculating the second card reader password based on the sector password includes: Calculate the second card reader password based on the target sector password; Accordingly, reading the target permission data corresponding to the card reader from the data sector includes: Read the target permission data from the target data sector; The data sectors are multiple; correspondingly, determining the sector number of the target data sector storing the target permission data in the IC card based on the permission identifier of the card reader includes: The sector number is obtained by taking the modulo remainder of the number of data sectors with the permission identifier.

2. The IC card authorization verification method according to claim 1, characterized in that, Before obtaining the sector number by taking the modulo remainder of the number of data sectors with respect to the permission identifier, the method further includes: The permission identifier is processed using a preset obfuscated number.

3. The IC card authorization verification method according to claim 1, characterized in that, The sector cipher is calculated from a first encryption factor, which includes a random cipher.

4. The IC card authorization verification method according to claim 1, characterized in that, The master control sector data also includes a first check bit field; Accordingly, before calculating the second card reader password based on the sector password, the method further includes: The first preset encryption algorithm is used to encrypt the data in the master control sector data other than the first check bit field, and the first check bit field is used for comparison. And / or, The sector cipher includes a second check bit field; Accordingly, before calculating the second card reader password based on the sector password, the method further includes: The second preset encryption algorithm is used to encrypt the data in the sector password other than the second check bit field, and the second check bit field is used for comparison.

5. The IC card authorization verification method according to claim 1, characterized in that, The card information includes card status and / or card validity period; Accordingly, before calculating the second card reader password based on the sector password, the method further includes: Verify the validity of the IC card based on the card status and / or the card validity period.

6. An IC card authorization verification device, characterized in that, include: The first card reader password calculation module is used to read the main control sector data of the IC card and calculate the first card reader password based on the card information in the main control sector data. The master control sector data also includes the sector password of the data sector; The second card reader password calculation module is used to verify whether the first card reader password is correct. If it is correct, the second card reader password is calculated based on the sector password. The second card reader password is a secondary encryption of the sector password. The target permission data reading module is used to verify whether the second card reading password is correct. If it is correct, it reads the target permission data corresponding to the card reading device from the data sector. The permission verification module is used to verify the permissions of the IC card based on the target permission data; The device further includes: The sector number determination module is used to determine the sector number of the target data sector storing the target permission data in the IC card according to the permission identifier of the card reader before calculating the second card reading password based on the sector password. The target sector password acquisition module is used to acquire the target sector password from the master control sector data according to the sector number; Accordingly, the second card reader password calculation module is specifically used for: Calculate the second card reader password based on the target sector password; Accordingly, the target permission data reading module is specifically used for: Read the target permission data from the target data sector; The data sectors are multiple; correspondingly, the sector number determination module is specifically used for: The sector number is obtained by taking the modulo remainder of the number of data sectors with the permission identifier.

7. A card reader, characterized in that, include: One or more processors; Memory, used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the IC card authorization verification method as described in any one of claims 1-5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the IC card authorization verification method as described in any one of claims 1-5.