Ticket Card Anti-Tearing Protection Method Based on SM4 National Cryptography Algorithm
By using the SM4 national secret algorithm and dynamic block alternately to use the ticket card, the problem of insufficient security of ticket card data is solved, and the data is anti-tampering and tear protection is realized, ensuring the integrity of transaction records.
Patent Information
- Application Number
- CN202410626178.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-05-20
AI Technical Summary
In the prior art, the ticket card itself has no logical encryption and decryption function, and the data can be read and written arbitrarily, resulting in insufficient data security and ineffective prevention of data tampering and tearing.
The ticket card anti-tear protection method based on the SM4 national secret algorithm is adopted. By setting two dynamic blocks in the ticket card and using the SM4 algorithm to encrypt and verify the data, the alternating cycle of dynamic blocks is realized to ensure the data is tamper-proof and tear-proof.
It effectively prevents tampering and tearing of ticket card data, meets the data's anti-tampering and tear protection needs, and can fully record the transaction status of ticket card nearly two times.
Smart Images

Figure CN118468313B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to a method for protecting ticket cards from being torn based on the SM4 national cryptography algorithm. Background Art
[0002] With the development of mobile technology, intelligent rail transit ticket cards have become one of the core products in urban rail transit ticketing, which is closely related to people's travel. With the continuous expansion of local line networks and the establishment of a networked operation system, various demands for ticket types have emerged. A common practice is to carry multiple applications on a single ticket card, with each ticket type application corresponding to a different fare policy. This method is convenient for expanding ticket types and has a fast application expansion speed. However, it has relatively high requirements for ticket card data. Reasonable planning and design of the data in the ticket card are required to meet the business needs. Due to the limitation of the ticket card space, the structure of the ticket card is generally refined to the unit of a single bit for the structure design of the ticket card.
[0003] However, in the prior art, the ticket card itself has no logical encryption and decryption function, and the ticket card data can be read and written arbitrarily. Therefore, there is an urgent need for a method for protecting ticket cards from being torn based on the SM4 national cryptography algorithm to solve the above problems. Summary of the Invention
[0004] To solve the technical problems existing in the above prior art, the purpose of the present invention is to provide a method for protecting ticket cards from being torn based on the SM4 national cryptography algorithm, which can solve the drawbacks of repeated integration joint debugging development and testing work for multi-simulation service systems in the case of multi-scenario comprehensive integration requirements, and at the same time optimize the user experience of using and operating the comprehensive integration activities.
[0005] To achieve the above invention purpose, the present invention provides a method for protecting ticket cards from being torn based on the SM4 national cryptography algorithm. The ticket card includes a card number block, a static block, and two dynamic blocks. The method for protecting from being torn includes the following steps:
[0006] Step S1: Read the data in the ticket card and complete data parsing;
[0007] Step S2: Based on the data in the ticket card, complete the verification of the dynamic block;
[0008] Step S3: Determine the currently valid dynamic block according to the combination relationship of the valid states of the two dynamic blocks;
[0009] Step S4: Use the currently valid dynamic block for business processing, organize new dynamic block data and write it into the ticket card to realize the alternating cyclic use of the two dynamic blocks.
[0010] According to a technical solution of the present invention, in the step S2, it specifically includes:
[0011] Step S201: Obtain the physical card number and logical card number within the card number block;
[0012] Step S202: Calculate the dynamic MACs of the two dynamic blocks in sequence. When calculating and verifying the dynamic MACs, first automatically calculate and verify the static MAC.
[0013] According to a technical solution of the present invention, in the step S202, it specifically includes:
[0014] Step S2021: Combine the physical card number, logical card number, and key version in a preset order, and use the issuance key of urban rail transit to calculate the static MAC based on a preset encryption algorithm, and complete the verification of the static MAC; if the static MAC verification passes, execute step S1022, if not, stop;
[0015] Step S2022: Calculate the dynamic MAC of the corresponding dynamic block based on the static MAC, physical card number, logical card number, data of the corresponding dynamic block obtained in the step S1021, and a preset encryption algorithm, and complete the verification.
[0016] According to a technical solution of the present invention, in the step S4, use the currently valid dynamic block for service processing, which specifically includes:
[0017] When the dynamic MACs of both dynamic blocks are calculated or verified to fail, confirm that the ticket card is an invalid card and directly end the service processing;
[0018] When only the dynamic MAC of one dynamic block is verified successfully, write the new dynamic block data into this dynamic block;
[0019] When the dynamic MACs of both dynamic blocks are verified successfully, based on the activation flag, determine whether the two dynamic blocks are in a valid state, and use the effectively dynamic block as the activation block to write the new dynamic block data into the other dynamic block.
[0020] According to a technical solution of the present invention, in the step S4, organize the new dynamic block data and write it into the ticket card, which specifically includes:
[0021] The data of the dynamic block at least includes the activation flag, entry time, exit time, and information of the entry station. Before writing, encrypt it based on the service key using a preset encryption algorithm to obtain the dynamic MAC, write the data into the corresponding dynamic block, and at the same time rewrite the activation flag in the dynamic block to identify the written block as the latest valid dynamic block.
[0022] According to a technical solution of the present invention, the preset encryption algorithm includes one or more of the exclusive OR algorithm, the CRC32 algorithm, the SHA algorithm, and the SM4 algorithm.
[0023] According to a technical solution of the present invention, the activation flag is a 1-bit cyclic counter with a range of 0 to 1;
[0024] When the data in the dynamic block is updated once, the number will increase by 1; when the value reaches 1, it will cycle back to 0;
[0025] The updated data is written into the specified dynamic block, and the data copied last time in another dynamic block will be retained;
[0026] When the transaction is interrupted while the card is being updated, the previous data remains unchanged.
[0027] According to a technical solution of the present invention, in step S1, it further includes:
[0028] Based on the static MAC of the static block, it is determined whether the ticket card is issued by urban rail transit.
[0029] According to an aspect of the present invention, there is provided a ticket card applicable to the ticket card anti-tearing protection method based on the SM4 national cryptography algorithm as described in any one of the above technical solutions.
[0030] According to an aspect of the present invention, there is provided a card reading device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the ticket card anti-tearing protection method based on the SM4 national cryptography algorithm as described in any one of the above technical solutions.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] The present invention proposes a ticket card anti-tearing protection method based on the SM4 national cryptography algorithm. Through the planning and encryption verification of data, based on the valid states of the two dynamic blocks, the two dynamic blocks are alternately and circularly used, which can meet the business requirements of anti-tampering and anti-tearing protection of the data on the ticket card, and can completely record the transaction situations of the ticket card in the recent two times. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0034] Figure 1 Schematic structural diagram of a card reader device showing the hardware operating environment involved in the solution of the embodiment of the present invention;
[0035] Figure 2 Schematic flow diagram of a ticket card anti-tear protection method based on the SM4 national cryptography algorithm in an embodiment of the present invention;
[0036] Figure 3 Schematically showing in an embodiment of the present invention Figure 2 Specific flow diagram of step S2 therein;
[0037] Figure 4 Schematically showing in an embodiment of the present invention Figure 3 Specific flow diagram of step S202 therein;
[0038] Figure 5 Schematic block diagram of a card reading system in an embodiment of the present invention;
[0039] Figure 6 Schematic structure planning diagram of a ticket card in an embodiment of the present invention;
[0040] Figure 7 Schematic flow chart of dynamic block identification for ticket card anti-tear protection in an embodiment of the present invention. Detailed implementation manners
[0041] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0042] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0043] According to an embodiment of the present application, a method embodiment of a ticket card anti-tearing protection method based on the SM4 national cryptographic algorithm is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0044] Figure 1 It is a schematic structural diagram of a card reader device for the hardware operating environment involved in the solution of the embodiment of the present invention.
[0045] As Figure 1 shown, the card reader device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless-fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM), or a stable non-volatile memory (non-Volatile Memory, nVM), such as a disk memory. Optionally, the memory 1005 may also be a storage system independent of the aforementioned processor 1001.
[0046] Those skilled in the art can understand that Figure 1 the structure shown in
[0047] does not constitute a limitation on the card reader device, and may include more or fewer components than shown in the figure, or combine some components, or arrange different components. Figure 1 shown, the memory 1005, as a storage medium, may include an operating system, a network communication module, a user interface module, and a ticket card anti-tearing protection program.
[0048] In Figure 1In the card-reading device shown, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the card-reading device of the present invention can be arranged in the card-reading device. The card-reading device calls the ticket anti-tearing protection program stored in the memory 1005 through the processor 1001 and executes the ticket anti-tearing protection method based on the SM4 national cryptographic algorithm provided by the embodiments of the present invention.
[0049] Figure 2 It is a schematic flowchart of the ticket anti-tearing protection method based on the SM4 national cryptographic algorithm of the present invention.
[0050] As Figure 2 and Figure 7 shown, a ticket anti-tearing protection method based on the SM4 national cryptographic algorithm of the present invention includes the following steps:
[0051] Step S1: Read the data in the ticket, and complete data parsing;
[0052] Step S2: Based on the data in the ticket, complete the verification of the dynamic block;
[0053] Step S3: Determine the currently valid dynamic block according to the combination relationship of the valid states of the two dynamic blocks;
[0054] Step S4: Use the currently valid dynamic block to perform service processing, organize new dynamic block data and write it into the ticket, so as to realize the alternating cyclic use of the two dynamic blocks.
[0055] Through the planning and encryption verification of data, based on the valid states of the two dynamic blocks, the alternating cyclic use of the two dynamic blocks is realized, which can meet the business requirements of anti-tampering and data anti-tearing protection of the data on the ticket, and can completely record the transaction situations of the ticket in the last two times.
[0056] Among them, the ticket is usually divided into blocks based on ticket data, including a card number block, a static block and two dynamic blocks. The card number block is divided into a physical card number area and a logical card number area;
[0057] The static block is divided into an issuance area and a product area. The issuance area is used to represent the key version, issuance batch, issuance date, static MAC, etc. The static MAC is organized by the physical card number, logical card number and key version in a certain order, and the static MAC is calculated with the issuance key and written into the card. The product area is used to represent the ticket type, wallet type, passenger type, card life cycle, ticket validity type, ticket validity period, selling site, selling amount, etc.;
[0058] The dynamic blocks include two data blocks with exactly the same structure, including a journey area, which is mainly used to identify the current valid block of the card. The journey area of the dynamic block contains an activation flag, ticket status, entry time, exit time, consumption amount, card transaction serial number, etc.
[0059] In some embodiments of the present invention, step S2 specifically includes:
[0060] Step S201: Obtain the physical card number and logical card number within the card number block;
[0061] Step S202: Calculate the dynamic MACs of the two dynamic blocks in sequence. When calculating and verifying the dynamic MAC, first automatically calculate and verify the static MAC.
[0062] In some embodiments of the present invention, step S202 specifically includes:
[0063] Step S2021: Combine the physical card number, logical card number, and key version in a preset order, and use the issuance key of urban rail transit to calculate the static MAC based on a preset encryption algorithm, and complete the verification of the static MAC; if the static MAC verification passes, execute step S1022, if not, stop;
[0064] Step S2022: Calculate the dynamic MAC of the corresponding dynamic block based on the static MAC, physical card number, logical card number, data of the corresponding dynamic block obtained in step S1021, and a preset encryption algorithm, and complete the verification.
[0065] The static MAC of the static block is usually calculated by combining the physical card number, logical card number, and key version in a certain order, using the issuance key of urban rail transit, and based on a preset encryption algorithm. For example, retain the first 3 - 6 bytes of the 7 - 12 - byte physical card number, perform exclusive OR operations on the last 2 - 5 bytes of the physical card number and the first 2 bytes in sequence to form X bytes, then splice the Y bytes of the logical card number to form (X + Y) bytes. For the key version of the static block, use the ticket issuance key and the SM4 national encryption algorithm to calculate a 4 - byte static MAC.
[0066] Among them, the static MAC does not need to be calculated separately. The static MAC is calculated during the process of calculating the dynamic MAC.
[0067] For the calculation of the dynamic MAC, for example, use the (X + Y) - byte data for calculating the static MAC, 4 - byte static MAC, the CRC32 value of the Z - byte dynamic block, and the exclusive OR value of the W - byte CRC32 to calculate the dynamic MAC of this dynamic block with these (X + Y + 4 + Z + W) bytes.
[0068] It is understandable that in a single ticket card business process, three dynamic MAC calculations will be performed. The first calculation is for the dynamic MAC of the first dynamic block, the second calculation is for the dynamic MAC of the second dynamic block. After the verification passes, the dynamic block is rewritten. After the business process is completed, the dynamic MAC of the dynamic block to be written is calculated.
[0069] In some embodiments of the present invention, in step S4, the current valid dynamic block is used for business processing, which specifically includes:
[0070] When the dynamic MACs of both of the two dynamic blocks are calculated or verified to fail, it is confirmed that the ticket card is an invalid card, and the business process is directly ended;
[0071] When only the dynamic MAC of one of the two dynamic blocks is verified to be successful, there is no need to judge the effective state based on the activation flag, and the new dynamic block data is directly written into this dynamic block;
[0072] When the dynamic MACs of both of the two dynamic blocks are verified to be successful, it is judged whether the two dynamic blocks are in an effective state based on the activation flag. Then, the effective dynamic block is used as the activation block, and the new dynamic block data is written into the other dynamic block.
[0073] In this embodiment, after reading the ticket card information, first verify whether the dynamic MACs of the two dynamic blocks are correct. Inside the verification of the dynamic MAC, the static MAC is automatically verified first. If the static MAC is incorrect, the dynamic MAC cannot be calculated. After the dynamic MAC verification is completed, then according to the combination of the effective states of the two dynamic blocks, it is determined which data block is currently used. After the business operation, the other dynamic block is rewritten. When rewriting the other dynamic block, the combination relationship of the effective states is also rewritten, always keeping the rewritten block as the current valid block.
[0074] Generally speaking, when the card reading device performs a ticket card business, if the ticket card data is not rewritten completely due to reasons such as too fast card swiping, one of the dynamic cards will be invalid, but the other dynamic block can still be used.
[0075] Specifically, if the first dynamic block is the last one written and its dynamic area MAC is valid, then the first dynamic block will be the current activation block, and the second dynamic block will be rewritten;
[0076] If the first dynamic block is the last one written and its dynamic area MAC is invalid, then the dynamic area MAC of the second dynamic block will be checked. If it is valid, then the second dynamic block will be the current activation block, and the first dynamic block will be rewritten;
[0077] If the second dynamic block is the last one written and its dynamic area MAC is valid, then the second dynamic block will be the current activation block, and the first dynamic block will be rewritten;
[0078] If the second dynamic block was written last and its dynamic area MAC is invalid, then the dynamic area MAC of the first dynamic block will be checked. If it is valid, then the first dynamic block will be the current active block and the second dynamic block will be rewritten;
[0079] If both dynamic area MACs are invalid, it means the card is damaged and cannot be used in toll transactions.
[0080] In some embodiments of the present invention, in step S4, organizing new dynamic block data and writing it into the ticket card specifically includes:
[0081] The data of the dynamic block at least includes an activation flag, an in-station time, an out-station time, and information of the in-station station. Before writing, it is encrypted using a preset encryption algorithm based on a service key to obtain a dynamic MAC, and the data is written into the corresponding dynamic block. At the same time, the activation flag in the dynamic block is rewritten to identify the written block as the latest and valid dynamic block.
[0082] In some embodiments of the present invention, the preset encryption algorithm includes one or more of an exclusive OR algorithm, a CRC32 algorithm, an SHA algorithm, and an SM4 algorithm.
[0083] Exclusive OR is the ordinary single-byte exclusive OR; CRC32 (Cyclic Redundancy Check) is cyclic redundancy check; SHA (Security Hash Algorithm) is a standard Hash algorithm; SM4 is a packet data algorithm for wireless local area network standards and is a symmetric encryption algorithm.
[0084] In some embodiments of the present invention, the activation flag is a 1-bit cyclic counter with a range of 0 to 1;
[0085] When the data in the dynamic block is updated once, the number will increase by 1; when the value reaches 1, it will cycle back to 0;
[0086] The updated data is written into the specified dynamic block, and the data copied last time in the other dynamic block will be retained;
[0087] If the transaction is interrupted when the card is being updated, the previous data remains unchanged.
[0088] For example, when the card is issued, the activation status values of the first dynamic block (represented by value A) and the second dynamic block (represented by value B) both start from 0.
[0089] Read (A = 0, B = 0, A.activestatus = 0) and write to A, set A value = 1;
[0090] Reading (A = 1, B = 0) indicates that A was written last, so write to B and set the value of B = 1;
[0091] Reading (A = 1, B = 1) indicates that B was written last, so write to A and set the value of A = 0;
[0092] Reading (A = 0, B = 1) indicates that A was written last, so write to B and set the value of B = 0;
[0093] Reading (A = 0, B = 0, A.activestatus!= 0) indicates that B was written last, write to A and set the value of A = 1;
[0094] Reading (A = 1, B = 0), etc.
[0095] This field and the dynamic area MAC are used to verify which data block is currently active. Once it is determined which block is active, the device will verify the dynamic area MAC of one or two data blocks.
[0096] In some embodiments of the present invention, the step S1 further includes:
[0097] Based on the static MAC of the static block, determine whether the ticket is issued by urban rail transit.
[0098] The static block includes the ticket issuance area and the ticket sale area. The ticket issuance area contains information such as the key version, issuance date, issuance batch, etc., and calculates the static MAC from the physical card number, logical card number, and key version using the issuance key. When the ticket is used, it is used to verify that the ticket is issued by urban rail transit. The ticket issuance area is generally issued and rewritten by the urban rail transit center, and the station equipment only verifies this information and does not rewrite it; the ticket sale area records other information about ticket issuance, such as ticket type, valid entry station, validity period type, value of the validity period, sale amount, passenger type, etc. The ticket sale area is issued and rewritten by the urban rail transit center, and the station equipment rewrites this sale area repeatedly according to the business.
[0099] As Figure 6 As shown, according to one aspect of the present invention, there is provided a ticket applicable to the ticket anti - tear protection method based on the SM4 national cryptography algorithm described in any one of the above technical solutions. The ticket structure is designed according to the technical standard of the Beijing Rail Transit ACC interface specification.
[0100] The card structure of the ticket card is divided by single bytes and planned by single-byte bit positions. Each block of data in the card structure, during the life cycle of the ticket card, the issued logical card number in the card number block is written once when the ticket card is issued and cannot be changed; for each block of data in the card structure during the life cycle of the ticket card, information such as the key version in the issuing area of the static block is written when the urban rail transit ticket card is issued, and the card reading device does not rewrite it.
[0101] The ticket card includes a card number block, a static block, and two dynamic blocks. The structures of the two dynamic blocks are exactly the same and are adjacent in position. The card number block contains the physical card number and the issued logical card number;
[0102] The static block contains fields such as card version, card life cycle, key version, issue date and time, issue batch, test card flag, card attributes, passenger type, wallet attributes, issue amount, issued SAM card number, payment method, validity period type, value of the validity period, ticket type, reserved fields, static MAC, etc.;
[0103] The dynamic block contains fields such as activation status, card status, card transaction serial number, invoice printing flag, effective start time, effective end time, effective station, transfer times, ticket card journey status, reserved fields, dynamic MAC, etc.
[0104] As Figure 5 shown, according to one aspect of the present invention, a card reading system is provided, including:
[0105] A reading module 101 for reading the data in the ticket card and completing data parsing;
[0106] A verification module 102 for completing the verification of the dynamic block based on the data in the ticket card;
[0107] A judgment module 103 for determining the currently valid dynamic block according to the combined relationship of the valid states of the two dynamic blocks;
[0108] A writing module 104 for using the currently valid dynamic block to perform service processing, organizing new dynamic block data and writing it into the ticket card to realize the alternating cyclic use of the two dynamic blocks.
[0109] The functions of the above-mentioned each module are the same as the corresponding steps involved in the above-mentioned ticket card anti-tearing protection method based on the SM4 national cryptographic algorithm. The above-mentioned modules can execute the corresponding steps of the ticket card anti-tearing protection method based on the SM4 national cryptographic algorithm to realize the corresponding functions.
[0110] According to one aspect of the present invention, a computer-readable storage medium is provided for storing computer instructions. When the computer instructions are executed by a processor, a ticket card anti-tearing protection method based on any one of the above technical solutions is realized.
[0111] A computer-readable storage medium may include any medium capable of storing or transmitting information. Examples of computer-readable storage media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. Code segments may be downloaded via a computer network such as the Internet, an intranet, and the like.
[0112] As Figure 7 shown, the process of an embodiment of the ticket card anti-tearing protection method based on the SM4 national cryptographic algorithm includes:
[0113] First, judge dynamic block A and dynamic block B to determine which is the active block and which is the backup block;
[0114] When the card is issued, the activation status values of both dynamic block A and dynamic block B start from 0.
[0115] When both A.activeSatus (valid status) and B.activeStatus are 0, and the journey status of dynamic block A is 0, indicating that the product has not been used, determine that dynamic block A is the active block and dynamic block B is the backup block;
[0116] When A.activeSatus is 0 and B.activeSatus is 1, determine that A is the active block and B is the backup block;
[0117] When A.activeSatus is 1 and B.activeSatus is 0, determine that A is the active block and B is the backup block;
[0118] When A.activeSatus is 1 and B.activeSatus is 1, determine that B is the active block and A is the backup block;
[0119] After determining the active block and the backup block, check whether the MAC is correct:
[0120] If the MAC verification of the active block is successful, read the active block and write to the backup area;
[0121] If the MAC verification of the active block fails and the MAC verification of the backup block is successful, read the backup block and write to the active block;
[0122] If the MAC verification of the active block fails and the MAC verification of the backup block fails, it is considered that the card is damaged and the device is notified.
[0123] That is, the validity of the two dynamic blocks can be checked first, and then the MAC verification is performed.
[0124] A method for protecting a ticket card against tearing based on the SM4 national cryptographic algorithm of the present invention. First, read the data in the ticket card and complete data parsing; second, based on the data in the ticket card, complete the verification of the dynamic block; third, determine the currently valid dynamic block according to the combined relationship of the valid states of the two dynamic blocks; finally, use the currently valid dynamic block to perform business processing, organize new dynamic block data and write it into the ticket card to realize the alternating and cyclic use of the two dynamic blocks. Through the planning and encryption verification of the data, based on the valid states of the two dynamic blocks, the alternating and cyclic use of the two dynamic blocks is realized, which can meet the business requirements of anti-tampering and data anti-tearing protection of the data on the ticket card, and can completely record the transaction situations of the ticket card in the last two times.
[0125] In addition, it should be noted that the present invention can be provided as a method, a device or a computer program product. Therefore, the embodiments of the present invention can take the form of completely hardware embodiments, completely software embodiments or embodiments combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program codes.
[0126] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, an embedded processor or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocks Figure 1 a device for performing the functions specified in one block or multiple blocks.
[0127] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements in the process Figure 1 one process or multiple processes and / or blocks Figure 1 a device for performing the functions specified in one block or multiple blocks. These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are performed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide for implementing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 Steps of functions specified in one or more boxes.
[0128] It should also be noted that in this text, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising said element.
[0129] Finally, it should be noted that the above is the preferred embodiment of the present invention. It should be pointed out that although the preferred embodiments of the present invention have been described, for those skilled in the art of this technology, once the basic creative concept of the present invention is known, several improvements and refinements can be made without departing from the principles described in the present invention, and these improvements and refinements should also be regarded as within the protection scope of the present invention. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
Claims
1. A ticket and card anti-tear protection method based on the SM4 national secret algorithm, characterized in that: The ticket card includes a card number block, a static block and two dynamic blocks, and the anti-tear protection method includes the following steps: Step S1, read the data in the ticket card and complete data analysis; Step S2: Based on a preset encryption algorithm, the data in the ticket is used to complete the verification of the dynamic block; Step S3, determining the currently valid dynamic block according to the combination relationship of the valid states of the two dynamic blocks; Step S4: Use the currently valid dynamic block to process business, organize new dynamic block data and write it into the ticket card, so as to realize the alternating and cyclic use of the two dynamic blocks; The preset encryption algorithm includes at least the SM4 national encryption algorithm.
2. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 1 is characterized in that: In the step S2, it specifically includes: Step S201, obtaining the physical card number and the logical card number in the card number block; Step S202: Calculate the dynamic MACs of the two dynamic blocks in sequence. When calculating and verifying the dynamic MACs, automatically calculate and verify the static MACs first.
3. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 2 is characterized in that: In the step S202, it specifically includes: Step S2021, combining the physical card number, the logical card number and the key version in a preset order, using the issuance key of the urban rail transit, calculating the static MAC based on the preset encryption algorithm, and completing the static MAC verification; if the static MAC verification passes, executing step S2022, if not, stopping; Step S2022: Calculate the dynamic MAC of the corresponding dynamic block based on the static MAC, physical card number, logical card number, corresponding data of the dynamic block and the preset encryption algorithm obtained in step S2021, and complete the verification.
4. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 3 is characterized in that: In step S4, the business processing is performed using the currently valid dynamic block, which specifically includes: When the dynamic MACs of the two dynamic blocks fail to be calculated or verified, the ticket card is confirmed to be an invalid card and the business processing is terminated directly; When the dynamic MAC check of only one of the dynamic blocks succeeds, the new dynamic block data is written into the dynamic block; When the dynamic MACs of the two dynamic blocks are both verified successfully, whether the two dynamic blocks are in a valid state is determined based on the activation flag, and the valid dynamic block is used as the activation block to write the new dynamic block data into the other dynamic block.
5. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 4 is characterized in that: In step S4, organizing new dynamic block data and writing it into the ticket card specifically includes: The data of the dynamic block includes at least activation flag, entry time, exit time, and information of the entry station. Before writing, it is encrypted using a preset encryption algorithm based on the business key to obtain a dynamic MAC, and the data is written into the corresponding dynamic block. At the same time, the activation flag in the dynamic block is rewritten to indicate that the written block is the latest valid dynamic block.
6. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 5 is characterized in that: The preset encryption algorithm also includes one or more of an XOR algorithm, a CRC32 algorithm, a SHA algorithm, an SM1 algorithm, an SM2 algorithm, and an SM3 algorithm.
7. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 5 is characterized in that: The activation flag is a 1-bit cycle counter ranging from 0 to 1; When the data in the dynamic block is updated once, the number will increase by 1; when the value reaches 1, it will loop back to 0; The updated data is written to the specified dynamic block, and the last copied data in another dynamic block will be retained; If the transaction is interrupted while the card is being updated, the last data remains unchanged.
8. The ticket and card anti-tearing protection method based on the SM4 national secret algorithm according to claim 1 is characterized in that: The step S1 further includes: Based on the static MAC of the static block, it is determined whether the ticket is a ticket issued by urban rail transit.
9. A ticket card, characterized in that: Applicable to the ticket and card anti-tearing protection method based on the SM4 national secret algorithm as described in any one of claims 1 to 8.
10. A card reading device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the ticket and card anti-tearing protection method based on the SM4 national secret algorithm as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Cross-bank card-free cash withdrawal processing method and device based on virtual account
CN110322244A
Dynamic Card Validation Value
US20090173782A1