An IC card encryption and decryption method and intelligent door lock system
By using encryption and decryption methods in hotel door lock IC cards, and using encryption modules and decryption programs to protect user data, the problem of easy cracking of user data in the existing technology is solved, and effective data protection and security improvement is achieved.
Patent Information
- Application Number
- CN202411162714.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-23
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-08-23
AI Technical Summary
The user data protection of existing hotel door lock IC cards depends on password blocks and is easily cracked, resulting in user data being copied or modified, causing illegal infringement.
The encryption and decryption method of the IC card is adopted. The IC card includes a data storage module and an encryption module. The user data is encrypted into the user's ciphertext through the first encryption algorithm. The card swiping device stores the decryption program. The encryption module and the user's ciphertext are decrypted by the first and second decryption algorithms respectively to obtain reading permissions and user data.
Even if the data storage module of the IC card is cracked, the encrypted user password is still obtained, preventing crackers from obtaining real user data and effectively protecting the security of user data.
Smart Images

Figure CN119107720B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent door locks, and more specifically, to an encryption and decryption method of an IC card and an intelligent door lock system. Background Art
[0002] The current IC card password block cracking method is quite mature, and cracking tools can be easily purchased in online shopping malls. In addition, the user data of existing hotel door lock IC cards still relies on password blocks for data protection. Once the password block is cracked, the cracker can copy or modify the hotel's user data, thereby causing illegal infringement on the user.
[0003] In order to solve the above problems, most existing technologies adopt a one-card-one-password approach, that is, the password is bound to the UID number of the IC card, so that each card uses a different password. However, this approach only increases the difficulty of decryption and cannot prevent decryption and reading of user data. Summary of the invention
[0004] The purpose of the present invention is to provide an encryption and decryption method for an IC card which is not easily cracked to read user data, and an intelligent door lock system using the method.
[0005] The first aspect of the present invention provides an IC card encryption and decryption method for encrypting an IC card and decrypting the IC card on a card swiping device, wherein the IC card comprises a data storage module and an encryption module, wherein the encryption module is used to verify the authority to read the data storage module; the data storage module stores user ciphertext, which is obtained by encrypting user data via a first encryption algorithm; the card swiping device stores a decryption program; the decryption program comprises a first decryption algorithm and a second decryption algorithm; when the IC card enters the card swiping range of the card swiping device, the first decryption algorithm decrypts the encryption module to obtain the authority to read the data storage module, and the second decryption algorithm decrypts the user ciphertext to obtain the user data.
[0006] Optionally, the card swiping device also stores an encryption program. After the decryption program completes the decryption, the encryption program encrypts the user data again according to the first encryption algorithm. The encryption factor of the first encryption algorithm includes variable data so that different user ciphertexts are obtained each time the user data is encrypted.
[0007] Optionally, the data storage module stores a first timestamp of the current card making time; when the IC card enters the card swiping range of the card swiping device and the decryption program is successfully decrypted, the card swiping device erases the first timestamp and writes a second timestamp to the data storage module, and the card swiping device records the second timestamp at the same time; the card swiping device is configured to judge all user ciphertexts with timestamps earlier than the second timestamp after this card swiping event as invalid ciphertexts.
[0008] Optionally, the first timestamp is encrypted by a second encryption algorithm and stored in a data storage module; the card swiping device includes a third decryption algorithm and a second encryption algorithm, the second encryption algorithm is used to encrypt the second timestamp at the card swiping device end, and the encrypted second timestamp replaces the first timestamp in the data storage module; the third decryption algorithm is used to decrypt the first timestamp and / or second timestamp at the card swiping device end.
[0009] Optionally, the encryption factor includes the card swiping device MAC and a timestamp of the card making time as variable data.
[0010] The second aspect of the present invention discloses an intelligent door lock system, including an IC card and a lock end, wherein the lock end includes a card swiping device, and the intelligent door lock system adopts any encryption and decryption method of the IC card in the first aspect of the present invention.
[0011] According to the technical content disclosed in the present invention, the following beneficial effects are achieved:
[0012] The IC card encryption and decryption method provided by the present invention comprises a data storage module and an encryption module, wherein the IC card comprises a data storage module and an encryption module, wherein the encryption module is used to verify the authority to read the data storage module; the data storage module stores user ciphertext, and the user ciphertext is obtained by encrypting the user data through a first encryption algorithm; even if the data storage module of the IC card is cracked, the user data read out is still ciphertext, which effectively prevents the algorithm for issuing the card from being deduced based on the user data and prevents a large number of card copies. The card swiping device stores a decryption program; when the IC card enters the card swiping range of the card swiping device, the first decryption algorithm decrypts the encryption module to obtain the authority to read the data storage module, and the second decryption algorithm decrypts the user ciphertext to obtain the user data.
[0013] Further features and advantages of the present invention will become apparent from the following detailed description of exemplary embodiments of the present invention with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention.
[0015] Figure 1 It is the IC card system structure diagram of the present invention.
[0016] Figure 2 It is a diagram of the IC card encryption process of the present invention.
[0017] Figure 3 It is a diagram of the IC card decryption process of the present invention. DETAILED DESCRIPTION
[0018] Various exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be noted that the relative arrangement of components and steps, numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present invention unless otherwise specifically stated.
[0019] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0020] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0021] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0022] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0023] The first aspect of the present invention provides an encryption and decryption method for an IC card used in an intelligent door lock system. The method is mainly used to encrypt an IC card and decrypt the IC card on a lock-end card swiping device of the intelligent door lock system, where the card swiping device is a card swiper.
[0024] See also Figure 1 The IC card includes a data storage module and an encryption module, the encryption module is used to verify the authority to read the data storage module; the data storage module stores user ciphertext, and the user ciphertext is obtained by encrypting user data using a first encryption algorithm.
[0025] The user ciphertext is obtained by encrypting the user data through the first encryption algorithm, including: when the card is made for the first time, the card issuer calls the "dynamic key algorithm program" to calculate the dynamic key, and uses this key to call the "encryption program" to encrypt the original code of the user data into a string of ciphertext. The key has multiple parameters generated by a specific algorithm, and the multiple parameters include at least the timestamp and the MAC of the smart door lock. The specific algorithm is called to obtain the key through a series of operations on the timestamp, the MAC of the smart door lock and other parameters, and the above key is used to encrypt the original code of the user data to obtain the user ciphertext. It can be seen that the MAC of each lock is different, the MAC address is unique, and cannot be obtained, which improves security.
[0026] The card reader stores a decryption program and an encryption program; the decryption program includes a first decryption algorithm and a second decryption algorithm; when the IC card enters the card swiping range of the card swiping device, the first decryption algorithm decrypts the encryption module to obtain the permission to read the data storage module, and the second decryption algorithm decrypts the user ciphertext to obtain the original data code of the user data for the unlocking operation of the smart door lock. The encryption program runs after the decryption program completes the decryption, and the encryption program encrypts the user data again according to the first encryption algorithm. The encryption factor of the first encryption algorithm includes variable data, so that different user ciphertexts are obtained after each encryption of the user data.
[0027] Furthermore, the variable data includes a timestamp of the current card making time. In order to prevent the timestamp written into the user ciphertext from being stored in the data storage module in plain text and obtained by illegal personnel, the timestamp of the previous card making time is set as the first timestamp, and the first timestamp is encrypted by the second encryption algorithm and stored in the data storage module; the card swiping device includes a third decryption algorithm and a second encryption algorithm, and the second encryption algorithm is used to encrypt the second timestamp at the card swiping device end, and the encrypted second timestamp replaces the first timestamp in the data storage module; the third decryption algorithm is used to decrypt the first timestamp and / or the second timestamp at the card swiping device end.
[0028] Combination Figure 2 and Figure 3 , the encryption and decryption method of the IC card applied to the intelligent door lock system of the present invention is described in detail below in combination with a specific scenario:
[0029] Assume that guest A checks into Hotel X. When checking in at the front desk, the hotel front desk randomly takes an unmade IC card and checks in guest A. The hotel front desk places the IC card on the card maker, which generates a dynamic key based on the user data related to the door lock of the room to be checked in entered by the hotel front desk. The user data related to the door lock includes at least the first timestamp, the MAC of the smart door lock, and the authorization code obtained by the hotel from the supplier. With this dynamic key, the "encryption program" is called to encrypt the original code of the user data into a string of ciphertext, that is, the user data is stored in the data storage module of the IC card in the form of user ciphertext. At the same time, the card maker calls the second encryption algorithm to encrypt the first timestamp, and the ciphertext of the first timestamp is stored in the data storage module. The ciphertext of the first timestamp is stored in the data storage module, and the ciphertext of the first timestamp is stored in the data storage module for standby acquisition of the first timestamp when the card reader unlocks the door.
[0030] After the card is successfully made, when tenant A checks into the room, he places the IC card on the card reader of the room's smart door lock. When the IC card enters the card swiping range of the card reader, the first decryption algorithm stored in the card reader decrypts the encryption module to obtain the authority to read the data storage module. After obtaining the authority to read the data storage module, the card reader reads the ciphertext of the first timestamp, and then calls the third decryption algorithm to decrypt the ciphertext of the first timestamp to obtain the plaintext data of the first timestamp. Finally, the card reader calls the second decryption algorithm and decrypts the user ciphertext according to the plaintext data of the first timestamp, the MAC of the smart door lock, the authorization code obtained by the hotel from the supplier, and other parameters to obtain the original data code of the user data and perform the unlocking operation.
[0031] When the lock is unlocked successfully, the timestamp of the current time is set as the second timestamp. At this time, the card reader encrypts the user data again according to the encryption program stored in the card reader according to the first encryption algorithm, that is, the encryption program in the card reader generates a dynamic key according to the user data of tenant A, the second timestamp and the MAC of the smart door lock, and uses this dynamic key to call the "encryption program" to encrypt the original code of the user data into a string of ciphertext again, and store the user data in the data storage module of the IC card in the form of user ciphertext. Since the timestamp of this encryption call is the second timestamp, the user ciphertext encrypted this time is different from the user ciphertext encrypted by the card maker at the hotel front desk. While generating the user ciphertext, the card reader calls the second encryption algorithm to encrypt the second timestamp to obtain the second timestamp ciphertext. The card reader erases the first timestamp ciphertext and stores the second timestamp ciphertext in the data storage module to replace the previous first timestamp ciphertext. The second timestamp ciphertext is reserved for decryption and use when the IC is used to unlock the lock next time. The card reader is configured to determine all user ciphertexts whose timestamps after this card swipe event are earlier than the second timestamp as invalid ciphertexts.
[0032] The card reader is configured to determine all user ciphertexts with timestamps earlier than the second timestamp after the current card swiping event as invalid ciphertexts. The main purposes include:
[0033] (1) When the room card of tenant A is maliciously cracked and copied, if the swipe time of the copied IC card is later than the swipe time of tenant A's IC card, the copied IC card will be judged as an invalid card by the door lock end, thereby improving the security of the door lock. At this time, the door lock end can have a built-in alarm program, which will immediately issue an audible and visual alarm when an invalid IC card is identified and send an alarm message to the hotel front desk, further improving security.
[0034] (2) When the room card of tenant A is maliciously copied, if the swipe time of the copied IC card is earlier than the swipe time of tenant A's IC card, then when tenant A unlocks the door, his IC card will be judged as an invalid card by the door lock end and cannot be unlocked. Tenant A will therefore know that his room has been illegally invaded.
[0035] In summary, the encryption and decryption method of the IC card and the intelligent door lock system provided by the present invention bypass the security loophole that the IC card's own password will be cracked. Even if the password block of the IC card is cracked, the encrypted user secret text is still obtained, so the data of the user sector can be effectively protected, and the relevant cracking personnel are not allowed to obtain the real user data related to the hotel door lock, so as to copy or modify it, infringing the interests of the user. At the same time, even if the password block of the IC card is cracked, the user data read out is still ciphertext, which effectively prevents the algorithm for calculating the card according to the user data and prevents a large number of cards from being copied. In addition, when the user swipes the door lock, the encryption algorithm of the door lock will modify the data ciphertext on the user's IC card, and the change of the ciphertext increases the difficulty of the encryption algorithm to crack. The card swipe device is configured to judge all user ciphertexts with timestamps earlier than the second timestamp after this card swiping event as invalid ciphertexts, which can effectively prevent the IC card from being illegally copied and can serve as a warning.
[0036] Please note that the technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification. The above embodiments only express several implementation methods of the present application, and their descriptions are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, without departing from the concept of the present application, several variations and improvements can be made, which all belong to the scope of protection of the present application. Therefore, the scope of protection of the patent in this application shall be based on the attached claims.
[0037] The above are preferred embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. An IC card encryption and decryption method, used for encrypting an IC card and decrypting the IC card on a card swiping device, characterized in that: The IC card includes a data storage module and an encryption module, wherein the encryption module is used to verify the authority to read the data storage module; The data storage module stores user ciphertext, which is obtained by encrypting user data through a first encryption algorithm, including: calling an encryption program to encrypt the original data code of the user data including a first timestamp into a string of ciphertexts and storing it in the data storage module, and calling a second encryption algorithm to encrypt the first timestamp to obtain the ciphertext of the first timestamp and store it in the data storage module; A card swiping device stores a decryption program; the decryption program includes a first decryption algorithm, a second decryption algorithm and a third decryption algorithm; when the IC card enters the card swiping range of the card swiping device, the first decryption algorithm decrypts the encryption module to obtain the permission to read the data storage module, then calls the third decryption algorithm to decrypt the ciphertext of the first timestamp to obtain the plaintext data of the first timestamp, and finally calls the second decryption algorithm to use the plaintext data of the first timestamp to decrypt the user ciphertext to obtain the data original code of the user data; The card swiping device also stores an encryption program, which encrypts the user data again according to the first encryption algorithm after the decryption program completes the decryption. The encryption factor of the first encryption algorithm includes variable data so that different user ciphertexts are obtained each time the user data is encrypted.
2. The IC card encryption and decryption method according to claim 1, characterized in that: The data storage module stores a first timestamp of the current card making time; When the IC card enters the card swiping range of the card swiping device and the decryption program succeeds in decryption, the card swiping device erases the first timestamp and writes a second timestamp to the data storage module, and the card swiping device records the second timestamp; The card swiping device is configured to determine all user ciphertexts whose timestamps after the current card swiping event are earlier than the second timestamp as invalid ciphertexts.
3. The IC card encryption and decryption method according to claim 2, characterized in that: The first timestamp is encrypted by a second encryption algorithm and stored in the data storage module; the card swiping device includes a third decryption algorithm and the second encryption algorithm, the second encryption algorithm is used to encrypt the second timestamp on the card swiping device end, and the encrypted second timestamp replaces the first timestamp in the data storage module; The third decryption algorithm is used to decrypt the first timestamp and / or the second timestamp at the card swiping device.
4. The IC card encryption and decryption method according to claim 3, characterized in that: The encryption factor includes the card swiping device MAC and a timestamp of the card making time as the variable data.
5. An intelligent door lock system, comprising an IC card and a lock terminal, wherein the lock terminal comprises a card swiping device, characterized in that: The intelligent door lock system adopts the encryption and decryption method of the IC card according to any one of claims 1 to 4.
Citation Information
Patent Citations
Identity verification method and device and intelligent card
CN114745126A
Entrance guard data encryption method and system based on commercial cryptographic algorithm
CN118172853A