Method and system for issuing a telecommunication smart card based on an authorization card

CN117459930BActive Publication Date: 2026-09-25金邦达有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311200742.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-15
Publication Date
2026-09-25
Estimated Expiration
2043-09-15

AI Technical Summary

Benefits of technology

[0011]本发明的第一目的是提供一种减少授权次数浪费并提高智能卡生产效率的基于授权卡的电信智能卡的发卡方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117459930B_ABST
    Figure CN117459930B_ABST
Patent Text Reader

Abstract

The application provides a method and a system for issuing a telecom intelligent card based on an authorized card, which comprises the following steps: in a data processing stage, obtaining initial card manufacturing data of an original batch, and converting the initial card manufacturing data to obtain converted card manufacturing data; in an issuing stage, obtaining a target card manufacturing data, analyzing the target card manufacturing data to obtain a first key in the target card manufacturing data, querying a key conversion history table to determine whether a second key exists in the key conversion history table, sending the second key to a card issuing module if the second key exists, generating the second key corresponding to the first key based on the authorized card in real time if the second key does not exist, storing the generated second key in the key conversion history table, and sending the generated second key to the card issuing module; and writing the first key and the second key into the telecom intelligent card. The application also provides a card issuing system for implementing the above method. The application can avoid waste of authorized times and reduce the production cost of the intelligent card.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of smart card production, specifically to a method for issuing telecommunications smart cards based on authorized cards and a card issuance system for implementing this method. Background Technology

[0002] With technological advancements, smart cards have become widely used in mobile communications, mobile payments, and identity verification. Common smart cards include SIM cards, ID cards, and financial IC cards. Among these, SIM cards are common telecom smart cards based on the GSM standard. Manufacturing telecom smart cards requires purchasing chips from chip suppliers and writing an operating system (COS) into those chips. Currently, some telecom smart card chip suppliers provide both chips and operating systems. In this case, smart card manufacturers can directly manufacture cards and write the operating system directly into the chip after obtaining the operating system. However, other chip suppliers do not provide operating systems, requiring smart card manufacturers to obtain the operating system from operating system suppliers and write it into the chip.

[0003] Due to copyright protection for operating systems, operating system vendors typically license their systems using a licensing card model. This means the vendor provides a licensing card to the smart card manufacturer, which generates the key to be written to the smart card. If the operating system is obtained from the vendor, it needs to be connected to the licensing card during the smart card manufacturing process. Because the licensing card has a counter that limits the number of times the operating system can be licensed, each time the smart card manufacturer obtains a license from the card, the number of licenses decreases by one. If the number of licenses reaches zero, the licensing card becomes invalid, and the smart card manufacturer needs to purchase a new licensing card to write the operating system to the smart card's chip.

[0004] Currently, the smart card manufacturing process mainly includes two stages: the data processing stage and the card issuance stage. In the data processing stage, smart card manufacturers need to acquire initial card manufacturing data and convert it in batches into the data format required by the card manufacturing equipment for this project. In the card issuance stage, the converted card manufacturing data is written into the corresponding telecommunications smart card according to project requirements, and the smart card is then personalized.

[0005] Currently, when using authorized cards for card production, the authorization operation is mainly performed during the data processing stage. The issuance process of telecom smart cards based on authorized cards is as follows: First, the data processing module obtains the initial card production data. Second, it retrieves one initial card production data from multiple data sets, parses this data set, and sends the first key generated from the initial card production data to the authorized card. Third, the authorized card calculates and generates a second key based on the input first key and returns the second key to the data processing module. Fourth, after receiving the second key, the data processing module generates and converts the card production data required for card production according to project requirements. Fifth, steps two through four are repeated to complete the batch processing of the entire batch of card production data. Finally, the converted batch card production data is output for batch card production during the issuance stage.

[0006] When using card-making equipment to make and issue cards, the card-issuing module needs to write the first key and the second key from each card-making data into the telecom smart card and perform personalization operations. At this time, the operating system will automatically verify whether the second key is correct. If the second key is incorrect, the card making will fail. Only after the verification is successful will the subsequent personalization card issuance operations be completed.

[0007] However, existing card issuance methods based on authorization cards have the following problems:

[0008] First, since the second key is generated in advance during the data processing stage, if the original batch card production data is incorrect or other situations require the cancellation of the entire batch of card production data, the authorized card usage will have already been used, resulting in wasted authorized card usage and increased card production costs.

[0009] Secondly, there are two different production models for telecom smart cards: one based on authorized cards and the other without, where the chip supplier also provides the operating system. Since both models may be used simultaneously in a single project, the data processing phase focuses on data processing and conversion, and it's impossible to know which type of chip will be used in subsequent stages. This leads to the following problems: First, if authorized card-based card production isn't required, but authorization is applied to the card production data during the data processing phase (i.e., authorization is applied at the data processing stage), but a third-party operating system isn't needed later, this results in wasted authorization attempts. Second, for chips requiring authorization, if the card production data isn't authorized, the operating system will fail verification during card issuance, leading to card production failure and requiring re-production, thus impacting the efficiency of telecom smart card production.

[0010] The aforementioned problems could be solved if the usage of each chip in the project could be known during the data processing phase. However, due to the time interval between the data processing and card issuance phases, and considering various factors such as real-time chip inventory changes and planned allocations in the subsequent card issuance phase, the data processing phase needs to continuously split the data according to order adjustments. For example, it needs to split the data into unauthorized mode data and authorized mode data, and then process it into corresponding order data to match and meet various uncertain changes in the subsequent card issuance phase. This results in high maintenance costs for the data processing phase, which in turn affects the card production efficiency of smart cards. Summary of the Invention

[0011] The primary objective of this invention is to provide a method for issuing telecommunications smart cards based on authorization cards that reduces wasted authorization attempts and improves smart card production efficiency.

[0012] A second objective of this invention is to provide a telecom smart card issuance system based on an authorized card that implements the above-described telecom smart card issuance method.

[0013] To achieve the first objective of this invention, the method for issuing telecommunications smart cards based on authorized cards provided by this invention includes the following steps: In the data processing stage, initial card production data in a raw batch is acquired, and the initial card production data is batch-converted to obtain converted card production data; In the card issuance stage, a target card production data is obtained from the converted card production data, the target card production data is parsed, and a first key is obtained from the target card production data; a key conversion history table is queried to determine whether a second key corresponding to the first key exists in the key conversion history table; if the second key exists in the key conversion history table, the second key is sent to the card issuance module; if the second key does not exist in the key conversion history table, a second key corresponding to the first key is generated in real time based on the authorized card, the generated second key is stored in the key conversion history table, and the generated second key is sent to the card issuance module; the first key and the second key are written into the telecommunications smart card.

[0014] As can be seen from the above scheme, when authorization is required for card production, the authorization operation is not performed during the data processing stage, but rather during the card issuance stage. Since the card issuance stage already determines which card production data can be written into the smart card, there is essentially no need to change the card production data. Therefore, performing authorization during the card issuance stage can reduce the waste of authorization attempts.

[0015] Furthermore, since it's clear which chips require authorization before card production can be completed during the card issuance stage, chips that don't require authorization can be produced using traditional methods without performing authorization. This avoids wasting authorization attempts by performing authorization on unauthorized card production data, thus reducing card production costs.

[0016] A preferred approach is to generate a second key corresponding to the first key in real time based on the authorization card, which includes: the card issuing module connecting to the authorization card, sending the first key to the authorization card, and the authorization card generating the second key.

[0017] As can be seen, the second key is generated in real time by the authorization card during the card issuance stage, avoiding the need to wait a long time after the second key is generated before writing it into the chip. This makes the generation of the second key more real-time and effectively reduces the phenomenon of wasted authorization attempts.

[0018] A further approach is to store the generated second key in a key conversion history table, which includes encrypting the first key and the second key together and then storing the encrypted key in the key conversion history table.

[0019] Therefore, it can be seen that the first key and the second key stored in the key conversion history table are both encrypted, and the storage security of the first key and the second key is better.

[0020] A further approach is to acquire only the initial card production data of the original batch during the data processing stage and then perform batch conversion on the initial card production data.

[0021] Therefore, the data processing stage only needs to convert the initial card production data in batches and does not perform authorization operations. This avoids the waste of authorization attempts caused by batch errors in the initial card production data or other situations that require canceling the entire batch of card production data. At the same time, it improves the processing efficiency of the data processing stage and reduces the maintenance cost of the data processing stage.

[0022] A further approach involves writing the first and second keys into the telecom smart card, and then performing the following: verifying the telecom smart card's operating system based on the second key.

[0023] As can be seen, during subsequent operating system verification, the operating system can verify the written second key to determine the correctness of the authorization.

[0024] A further approach is to determine whether the telecom smart card corresponding to the target card data is a chip that does not use the authorized card mode for personalization before obtaining a target card data from the converted card data. If so, the corresponding card issuance program that does not require an authorized card is used directly to issue the card.

[0025] By using different card manufacturing modes for chips with two different authorization scenarios, we can avoid authorizing the card manufacturing data corresponding to chips that do not require authorization, thereby avoiding the waste of authorization attempts.

[0026] To achieve the second objective mentioned above, the present invention provides a smart card issuance system based on an authorized card, comprising a data processing module for acquiring initial card production data in a batch and performing batch conversion on the initial card production data to obtain converted card production data; the system further comprises an issuance module for acquiring a target card production data from the converted card production data, parsing the target card production data, and obtaining a first key from the target card production data; the issuance module is also used to query a key conversion history table to determine whether a second key corresponding to the first key exists in the key conversion history table; if the second key exists in the key conversion history table, the second key is sent to the issuance module; if the second key does not exist in the key conversion history table, a second key corresponding to the first key is generated in real time based on the authorized card, the generated second key is stored in the key conversion history table, and the generated second key is sent to the issuance module; the first key and the second key are written into the smart card. Attached Figure Description

[0027] Figure 1 This is a structural block diagram of an embodiment of the telecommunications smart card issuance system based on an authorized card according to the present invention.

[0028] Figure 2 This is a flowchart of an embodiment of the telecommunications smart card issuance method based on an authorized card according to the present invention.

[0029] The present invention will be further described below with reference to the accompanying drawings and embodiments. Detailed Implementation

[0030] The telecom smart card issuance method based on an authorized card of the present invention improves the existing telecom smart card manufacturing process by setting the authorization procedure of the authorized card in the card issuance stage rather than in the data processing stage, thereby avoiding the waste of authorization attempts due to card manufacturing data updates or changes. Furthermore, since the card issuance operation is performed immediately after authorization, it is possible to know which chips require authorization and which do not, thus enabling authorization to be performed only on the chips that require it, further reducing the waste of authorization attempts.

[0031] Example of a telecom smart card issuance system based on authorized cards:

[0032] See Figure 1 The telecom smart card issuance system based on the authorized card includes a data processing module 10 and an issuance module 20. The data processing module 10 is used to process the card production data in the data processing stage, including obtaining the initial card production data and batch converting the initial card production data into converted card production data that can be used in the issuance stage.

[0033] The card issuing module 20 is used to perform card production operations during the card issuance stage. During the card production process, it is necessary to determine whether the chip used for card production needs to be authorized, that is, whether the chip used for card production has an operating system provided by the chip supplier. If the chip supplier provides an operating system, no authorization operation is required. If the operating system is provided by a third-party operating system supplier, authorization needs to be obtained through the authorization card 30, and a key is generated based on the authorization card 30 for subsequent verification.

[0034] Example of a method for issuing telecommunications smart cards based on authorized cards:

[0035] The following is combined Figure 2 The working method of the above-mentioned telecommunications smart card issuance system is described. First, in step S1, during the data processing stage, the data processing module 10 obtains the original card production data, such as initial card production data obtained from the smart card demander. This initial card production data is often not suitable for the card production requirements of the issuance module, for example, the format of the card production data cannot be recognized by the card production equipment.

[0036] After acquiring a batch of initial card-making data, the data processing module 10 executes step S2 to convert the initial card-making data into card-making data that meets the format requirements, thereby obtaining the converted card-making data. In this embodiment, the data processing module 10 converts the initial card-making data in batches, thereby improving the efficiency of card-making data conversion.

[0037] In this embodiment, the data processing module 10 only acquires the initial card production data and performs batch conversion operations on the initial card production data. It does not perform authorization operations, that is, it does not obtain the second key for verification through the authorization card 30 based on the card production data. In other words, the authorization card 30 does not generate the second key during the data processing stage.

[0038] After the data processing module 10 converts and generates the converted card-making data, it enters the card issuance stage when card production is required. The card issuance module 20 first executes step S3 to determine whether the chip used for the current card production requires authorization, that is, whether the chip used currently has an operating system provided by the chip supplier. If the chip supplier has provided an operating system, it means that the chip used currently does not need to be authorized by the authorization card 30. Then, step S4 is executed to directly issue cards using the card issuance program that does not require an authorization card. For example, the converted card-making data can be directly written into the smart card.

[0039] If the chip supplier of the currently used chip does not provide an operating system, an operating system needs to be obtained from a third party, requiring authorization through authorization card 30. In this case, step S5 needs to be executed to obtain one piece of card manufacturing data from multiple converted card manufacturing data. This piece of card manufacturing data is the target card manufacturing data, and card manufacturing is performed based on this target card manufacturing data. Since the card issuing module 20 needs to obtain a second key for verification from authorization card 30 during the card manufacturing process, the card issuing system also needs to be connected to authorization card 30, for example, establishing a connection between the card issuing module 20 and authorization card 30.

[0040] Next, step S6 is executed to obtain the first key Key from the target card data. The card issuing module 20 extracts the first key Key from the target card data by parsing it.

[0041] Then, the card issuing system connects to the key conversion history table. In this embodiment, the key conversion history table records the correspondence between the first key and the second key that have been converted. The second key, S-key, is a key generated by the authorization card 30 based on the first key, and it is also used to verify the operating system written to the telecom smart card. Each time the authorization card 30 generates a second key, the number of authorizations decreases by one. The key conversion history table can be stored on a designated server. Preferably, the data in the key conversion history table, i.e., the first key and the second key, is encrypted data, and all data in the key conversion history table is written by the card issuing module 20.

[0042] Furthermore, for a first key, the authorization card 30 will only generate one second key. Therefore, the first key and the second key have a one-to-one correspondence. If a first key is stored in the key conversion history table, it is not necessary to use the first key to generate the second key. Instead, the corresponding second key can be directly found from the key conversion history table.

[0043] After obtaining the first key, step S7 is executed to determine whether a second key corresponding to the first key exists in the key conversion history table. If a corresponding second key exists in the key conversion history table, step S10 is executed to directly obtain the second key. Specifically, the card issuing system directly reads the second key from the key conversion history table.

[0044] If the result of step S7 is negative, it means that the second key does not exist in the key conversion history table, that is, the authorization card 30 has not generated a second key for the first key. Then, step S8 is executed to generate a second key through the authorization card 30. Specifically, after the card issuing module 20 is connected to the authorization card 30, it sends the first key obtained from the analysis of the converted card production data to the authorization card 30, and the authorization card 30 generates a corresponding second key based on the first key.

[0045] After the authorization card 30 generates the second key, it returns the generated second key to the card issuing module 20. Then, the card issuing module 20 further executes step S9, writing the second key into the key conversion history table. Preferably, when writing the second key into the key conversion history table, the card issuing module 20 also needs to write the first key and record the correspondence between the first and second keys, ensuring a one-to-one correspondence between the first and second keys in the key conversion history table. Additionally, the card issuing module 20 uses an encryption algorithm to encrypt the first and second keys before storing them in the key conversion history table.

[0046] Finally, after executing step S10 or step S9, the card issuing module 20 has obtained the second key, and then executes step S11. The card issuing system writes the first key and the second key corresponding to the current target card data into the smart card. After the card issuing device writes the operating system into the smart card, the second key is used to realize the automatic verification of the operating system. For example, when the operating system runs for the first time, a verification operation is performed, and the second key needs to be input into the operating system to verify the authenticity of the second key. If the verification fails, the operating system will not be able to run normally.

[0047] After the first key and the second key are written into the telecom smart card, the production of the telecom smart card is completed, and the card manufacturing process is finished.

[0048] If an anomaly occurs during the smart card manufacturing process, such as the target card data not being correctly written to the smart card, or a problem with the smart card's printing plate, a replacement card operation is required, which means remaking the smart card. However, the target card data will not change, meaning the first key corresponding to the smart card will remain unchanged. At this time, since a second key has been generated using the first key from the target card data, but the smart card corresponding to the second key has not been activated due to process reasons, the second key has not actually been used. Therefore, during the replacement card process, the already generated second key can still be written to the replacement smart card. In other words, in step S7, if it is determined that a corresponding second key already exists for the first key corresponding to the target card data, it means the second key has already been generated. Since this is during the replacement card stage, the second key can still be written to the replacement smart card, thus avoiding wasted authorization attempts and reducing smart card production costs.

[0049] As can be seen, because this invention generates the second key in real time during the card issuance stage, rather than pre-generating it during the data processing stage, even if the card production data needs to be cancelled after the data processing stage, the already generated second key will not be wasted. Furthermore, since the second key is generated during the card issuance stage, it is not necessary to closely link the data processing stage and the card issuance stage to distinguish whether each piece of card production data requires authorization. This avoids anomalies caused by data authorization factors leading to card issuance failures. It also eliminates the need to monitor subsequent stages' real-time chip inventory changes and order allocation, reducing the maintenance workload during the data processing stage and improving data processing efficiency.

[0050] Finally, it should be emphasized that the present invention is not limited to the above-described embodiments. In practical applications, there can be many variations, such as changes to the encryption algorithm used to write the first key and the second key into the key conversion history table. These variations should also be included within the scope of protection of the claims of the present invention.

Claims

1. A method for issuing telecommunications smart cards based on authorized cards, including: During the data processing stage, the initial card production data of the original batch is obtained, and the initial card production data is batch converted to obtain the converted card production data; Its features are: During the card issuance stage, a target card data is obtained from the converted card data, the target card data is parsed, and the first key in the target card data is obtained. The key conversion history table is queried to determine whether a second key corresponding to the first key exists in the key conversion history table. If the second key exists in the key conversion history table, the second key is sent to the card issuing module. If the second key does not exist in the key conversion history table, a second key corresponding to the first key is generated in real time based on the authorization card. The generated second key is stored in the key conversion history table and sent to the card issuing module. Write the first key and the second key into the telecom smart card; The real-time generation of a second key corresponding to the first key based on the authorization card includes: a card issuing module connected to the authorization card, sending the first key to the authorization card, and the authorization card generating the second key; Furthermore, during the data processing stage, only the initial card production data of the original batch is acquired and the initial card production data is batch converted. No authorization operation is performed during the data processing stage, and the second key for verification is not obtained through the authorized card based on the card production data.

2. The method for issuing telecommunications smart cards based on authorization cards according to claim 1, characterized in that: Storing the generated second key in the key conversion history table includes: encrypting the first key and the second key together and then storing them in the key conversion history table.

3. The method for issuing telecommunications smart cards based on authorized cards according to claim 1 or 2, characterized in that: After writing the first key and the second key into the telecom smart card, the following steps are also performed: verifying the operating system of the telecom smart card based on the second key.

4. The method for issuing telecommunications smart cards based on authorized cards according to claim 1 or 2, characterized in that: Before obtaining a target card data from the converted card data, it is determined whether the telecom smart card corresponding to the target card data is a chip that does not use the authorized card mode for personalization. If so, the corresponding card issuance program that does not require an authorized card is used directly to issue the card.

5. A telecommunications smart card issuance system based on an authorized card, including: The data processing module is used to acquire the initial card production data of the original batch and perform batch conversion on the initial card production data to obtain the converted card production data; Its features are: The card issuing module is used to obtain a target card data from the converted card data, parse the target card data, and obtain the first key from the target card data; The card issuing module is also used to query the key conversion history table to determine whether a second key corresponding to the first key exists in the key conversion history table. If the second key exists in the key conversion history table, the second key is sent to the card issuing module. If the second key does not exist in the key conversion history table, a second key corresponding to the first key is generated in real time based on the authorization card, the generated second key is stored in the key conversion history table, and the generated second key is sent to the card issuing module. The first key and the second key are then written into the telecom smart card. When the second key corresponding to the first key is generated in real time based on the authorization card, the card issuing module of the card issuing system establishes a connection with the authorization card, sends the first key to the authorization card, and the authorization card generates the second key; Furthermore, the data processing module only acquires the initial card production data of the original batch and performs batch conversion on the initial card production data. The data processing module does not perform authorization operations and does not obtain the second key for verification based on the card production data through the authorized card.

6. The telecommunications smart card issuance system based on an authorization card according to claim 5, characterized in that: The first key and the second key are stored in the key conversion history table in an encrypted manner.

7. The telecommunications smart card issuance system based on an authorization card according to claim 5 or 6, characterized in that: The card issuing module is also used to write the first key and the second key into the telecom smart card, and then verify the operating system of the telecom smart card based on the second key.

Citation Information

Patent Citations

  • Novel multi-application authentication card issuing system for smart card

    CN104202369A

  • Encryption and decryption method of certificate authorization card identifying information, device and digital program system

    CN105516763A