Method, apparatus, and device for processing transportation service

By deploying smart cards on vehicles and generating security protection keys on user mobile terminals for encryption operations, the problem of cumbersome and high cost of scanning codes and NFC ride solutions in the prior art is solved, and low-cost, high-efficiency and high-security transportation ride service processing is achieved.

CN119255211BActive Publication Date: 2025-07-25ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411388144.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2025-07-25
Estimated Expiration
2044-09-30

AI Technical Summary

Technical Problem

The existing QR code scanning and NFC rides have problems such as cumbersome operation, high cost and high dependence on mobile phone manufacturers.

Method used

By deploying smart cards on vehicles, and using near-field communication on the user's mobile terminal to obtain the identification information of the smart card and the verification factor to be checked, a security protection key is generated for encryption operations, and card reading instructions are generated to realize the two-way interaction between the smart card and the user's mobile terminal, and complete the checksum deduction.

Benefits of technology

It reduces costs, improves interaction speed and security, reduces the risk of smart cards being illegally copied, and reduces the dependence on mobile phone manufacturers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119255211B_ABST
    Figure CN119255211B_ABST
Patent Text Reader

Abstract

The embodiments of this specification disclose a method, device, and equipment for processing transportation vehicle boarding services. The solution applied to the user terminal program includes: after the user's mobile terminal approaches the smart card deployed for the transportation vehicle it is boarding, obtaining the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication; in a specified secure area on the user's mobile terminal, generating a security protection key corresponding to the transportation vehicle according to the identification information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified secure area; using the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction; sending the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor, and after the verification passes, return boarding-related information to the user's mobile terminal for charging.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of near-field communication technology, and in particular, to a method, apparatus, and device for processing transportation service. Background Art

[0002] With the development of Internet technology and the popularization of the use of smart phones, more and more services can be carried out through corresponding applications on smart phones, which brings great convenience to people's lives. Scanning a code to take a bus (mainly including buses and subways) is one of the convenient services. However, in actual applications, there are also some problems with cumbersome operations in scanning a code to take a bus.

[0003] In view of the above problems of scanning a code to take a bus, considering that more and more smart phones support the Near Field Communication (NFC) function, some service providers consider providing corresponding NFC solutions so that users can take a bus based on NFC interaction.

[0004] In these NFC solutions, it is necessary to deploy a hardware device that can identify NFC cards on the bus or subway turnstile and make corresponding modifications to the background system. Then, the smart phone of the user that supports the NFC function can simulate itself as an NFC bus card for the hardware device to identify, so as to achieve more convenient bus rides.

[0005] Based on this, there is also a need for a bus ride solution with lower cost, security guarantee, and help reduce dependence on mobile phone manufacturers. Summary of the Invention

[0006] One or more embodiments of this specification provide a method, apparatus, and device for processing transportation service to solve the following technical problems: a bus ride solution with lower cost, security guarantee, and help reduce dependence on mobile phone manufacturers.

[0007] To solve the above technical problems, one or more embodiments of this specification are implemented as follows:

[0008] A method for processing transportation service provided by one or more embodiments of this specification is applied to a user program on a user mobile terminal. The method includes:

[0009] After the user mobile terminal approaches a smart card deployed for the transportation it takes, obtain the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication;

[0010] In a specified security area on the user mobile terminal, a security protection key corresponding to the means of transportation is generated according to the identification information and pre-acquired card-reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0011] Using the security protection key, an encryption operation is performed on the factor to be verified to generate a card-reading instruction;

[0012] The card-reading instruction is sent to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card-reading instruction, verify the factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal;

[0013] According to the ride-related information, corresponding deductions are made on the user mobile terminal or the server corresponding to the user-side program.

[0014] A method for processing a means of transportation ride service provided by one or more embodiments of this specification, which is applied to a smart card deployed on a means of transportation. The method includes:

[0015] After the user mobile terminal approaches the smart card, the identification information corresponding to the smart card and the factor to be verified generated by the smart card are provided to the user mobile terminal through near-field communication;

[0016] Receive the card-reading instruction sent by the user-side program on the user mobile terminal, where the card-reading instruction is generated by the user-side program performing an encryption operation on the factor to be verified using the security protection key corresponding to the means of transportation. The security protection key is generated by the user-side program in its local specified security area according to the identification information and pre-acquired card-reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0017] Using the security protection key it holds, perform a decryption operation on the card-reading instruction, verify the factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal for corresponding deductions to be made on the user mobile terminal or the server corresponding to the user-side program.

[0018] A means of transportation ride service processing device provided by one or more embodiments of this specification, which is applied to a user-side program on a user mobile terminal. The device includes:

[0019] A verification information acquisition module, after the user mobile terminal approaches the smart card deployed for the means of transportation it rides, obtains the identification information corresponding to the smart card and the factor to be verified generated by the smart card through near-field communication;

[0020] A security protection key generation module, in a specified security area on the user mobile terminal, generates a security protection key corresponding to the vehicle according to the identification information and pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0021] A card reading instruction generation module, using the security protection key, performs an encryption operation on the factor to be verified to generate a card reading instruction;

[0022] A card reading instruction sending module, sends the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verifies the factor to be verified, and after the verification passes, returns ride-related information to the user mobile terminal;

[0023] A ride information deduction module, according to the ride-related information, performs corresponding deductions on the user mobile terminal or the server corresponding to the user-side program.

[0024] A vehicle ride service processing device provided by one or more embodiments of this specification, applied to a smart card deployed on a vehicle, the device includes:

[0025] A verification information providing module, after the user mobile terminal approaches the smart card, provides the identification information corresponding to the smart card and the factor to be verified generated by the smart card to the user mobile terminal through near-field communication;

[0026] A card reading instruction receiving module, receives the card reading instruction sent by the user-side program on the user mobile terminal, where the card reading instruction is generated by the user-side program performing an encryption operation on the factor to be verified by using the security protection key corresponding to the vehicle, and the security protection key is generated by the user-side program in a specified security area of its local according to the identification information and pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0027] A factor verification return module, uses the security protection key it holds to perform a decryption operation on the card reading instruction, verifies the factor to be verified, and after the verification passes, returns ride-related information to the user mobile terminal for corresponding deductions on the user mobile terminal or the server corresponding to the user-side program.

[0028] A vehicle ride service processing device provided by one or more embodiments of this specification, applied to a user-side program on a user mobile terminal, the device includes:

[0029] At least one processor; and,

[0030] A memory communicatively connected to the at least one processor; wherein,

[0031] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to perform:

[0032] After the user mobile terminal approaches a smart card deployed for the vehicle it is boarding, obtain the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication;

[0033] In a specified security area on the user mobile terminal, generate a security protection key corresponding to the vehicle according to the identification information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0034] Use the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction;

[0035] Send the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor, and after the verification passes, return boarding-related information to the user mobile terminal;

[0036] Perform corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the boarding-related information.

[0037] A vehicle boarding service processing device provided by one or more embodiments of this specification, which is applied to a smart card deployed on a vehicle. The device includes:

[0038] At least one processor; and,

[0039] A memory communicatively connected to the at least one processor; wherein,

[0040] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to perform:

[0041] After the user mobile terminal approaches the smart card, provide the identification information corresponding to the smart card and the verification factor generated by the smart card to the user mobile terminal through near-field communication;

[0042] Receive the card-reading instruction sent by the client program on the user's mobile terminal. The card-reading instruction is generated by the client program through an encryption operation on the factor to be verified using the security protection key corresponding to the means of transportation. The security protection key is generated by the client program in a specified security area of its local device according to the identification information and the pre-acquired card-reading authorization data, so that the generated security protection key is not exposed outside the specified security area.

[0043] Use the security protection key in its own possession to perform a decryption operation on the card-reading instruction, verify the factor to be verified, and after the verification passes, return the relevant boarding information to the user's mobile terminal for corresponding deduction on the user's mobile terminal or the server corresponding to the client program.

[0044] One or more of the above technical solutions adopted in the embodiments of the present specification can achieve the following beneficial effects: There is no need to specially deploy additional hardware devices for the means of transportation. Instead, it is relatively simple to mainly deploy an intelligent card, so the cost is effectively reduced and it is easy to deploy flexibly. And by quickly obtaining the identification information corresponding to the verification intelligent card and the factor to be verified generated by the intelligent card, and through the two-way interaction based on the card-reading instruction and the security protection key corresponding to the means of transportation to complete the verification, the interaction speed is made as fast as possible, and the risk of illegal copying of the intelligent card is effectively reduced, taking into account both efficiency and security. Moreover, this solution enables the user's smartphone to be used as a card reader rather than as an analog card to achieve the deduction for taking the means of transportation, which is a riding solution that helps reduce the dependence on mobile phone manufacturers. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0046] Figure 1 It is a schematic flowchart of a method for processing transportation boarding services provided by one or more embodiments of the present specification;

[0047] Figure 2 It is a schematic flowchart of an intelligent card interaction solution based on ATS information and card-reading instructions provided by one or more embodiments of the present specification;

[0048] Figure 3 It is a schematic flowchart of a card-reading instruction generation scheme provided by one or more embodiments of the present specification;

[0049] Figure 4 A flowchart of a solution for the pain points of swiping cards when getting on and off a vehicle provided for one or more embodiments of this specification;

[0050] Figure 5 Under an application scenario provided for one or more embodiments of this specification, Figure 1 A flowchart of an implementation solution of the method;

[0051] Figure 6 A flowchart of another method for processing vehicle boarding and alighting services provided for one or more embodiments of this specification;

[0052] Figure 7 A structural diagram of a device for processing vehicle boarding and alighting services provided for one or more embodiments of this specification;

[0053] Figure 8 A structural diagram of another device for processing vehicle boarding and alighting services provided for one or more embodiments of this specification;

[0054] Figure 9 A structural diagram of a device for processing vehicle boarding and alighting services provided for one or more embodiments of this specification;

[0055] Figure 10 A structural diagram of another device for processing vehicle boarding and alighting services provided for one or more embodiments of this specification. Detailed implementation manners

[0056] The embodiments of this specification provide a method, a device, a device, and a storage medium for processing vehicle boarding and alighting services.

[0057] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0058] Some problems existing in the existing code-scanning ride and NFC ride solutions are mentioned in the background art, mainly including that the operations are still relatively cumbersome, the costs are relatively high, or there is a large dependence on mobile phone manufacturers, etc.

[0059] Regarding the problem of high cost, for current solutions such as bus cards, ride codes, or NFC mobile phones, a dedicated hardware device that can identify the corresponding cards or codes needs to be deployed for transportation means (mainly referring to buses, and other transportation means such as subways can also be included. For the convenience of description, buses will be mainly used as examples hereinafter). This device needs to have certain programming capabilities and implement functions such as card / code reading and charging inside the device, resulting in relatively high costs.

[0060] Regarding the problem of dependence, in traditional solutions, it is the user's NFC-enabled smartphone that simulates itself as an NFC ride card for the hardware device acting as a card reader to identify. This method is often subject to relatively strict control by mobile phone manufacturers in terms of permissions, etc. For service providers such as payment service providers, there are great restrictions and poor flexibility. For users, it is also not convenient to expand payment channels more freely.

[0061] To address the above-mentioned problems, this application intends to provide a low-cost and high-experience solution for taking rides. In this way, the bus company can achieve a riding experience as convenient as that of physical cards without complex renovations. At the same time, for the bus company, the subsequent maintenance cost of the system will also be significantly saved, which helps to promote it quickly at low cost. The following will continue to specifically describe the solution of this application.

[0062] The solution of this application involves multiple ends. One end is the user-side program on the user's mobile terminal. Mainly from this end's perspective, the user's mobile terminal can be a smart device carried around by the user, such as a smartphone, smartwatch, smart bracelet, tablet computer, handheld game console, or smart ring. The user-side program can be the client or applet of an application with payment capabilities. For example, typically, it can be some comprehensive leading applications (including applets embedded therein) installed on the user's mobile terminal, or applications independently launched by the bus department, etc.

[0063] Figure 1 It is a schematic flowchart of a method for processing transportation means boarding services provided for one or more embodiments of this specification. The execution subject of this process can include the above-mentioned user-side program, and the execution subject in terms of hardware can be the user's mobile terminal where the user-side program is located.

[0064] Figure 1 The process in it includes the following steps:

[0065] S102: After the user's mobile terminal approaches the smart card deployed for the transportation means it takes, obtain the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card through near-field communication.

[0066] The transportation means mainly can include buses. Of course, this solution may also be applied to some other transportation means boarding scenarios, such as subways, trams on the ground, and even taxis, etc. The smart card can be a card with certain computing capabilities that supports the NFC function, such as a contactless CPU card. In this way, the cost is relatively low and it is easy to deploy, without the need to deploy the above-mentioned hardware devices with higher costs and inconvenient maintenance.

[0067] How to specifically deploy it can depend on which transportation means it is. For buses, the smart card can be directly deployed inside the bus, such as at the usual place where passengers swipe their cards when getting on the bus; for subways, the smart card can be deployed on the subway turnstiles; and so on.

[0068] The corresponding identification information can be pre-written in the smart card. This identification information can be the identification of the smart card itself or the identification of its corresponding transportation means. The identification information is, for example, physical identification, custom number, device type, etc., information with sufficient distinctiveness, so as to facilitate subsequent differentiation of the boarding services for different types of transportation means and different transportation means under the same type, and to facilitate correct settlement of fees.

[0069] The factor to be verified is a factor used for subsequent interaction and consistency verification between the smart card and the user's mobile terminal to ensure the legality of both parties (not being impersonated, for example, the smart card has not been illegally copied, and the user of the user's mobile terminal has correctly opened the corresponding boarding service, etc.). To improve security, the smart card can generate different factors to be verified for each boarding interaction. For example, random factors (random numbers or other random strings, etc.) can be used as the factors to be verified. Of course, it is also possible to use other data with certain secrecy (difficult to guess) as the factor to be verified.

[0070] S104: In the specified security area on the user's mobile terminal, generate the security protection key corresponding to the transportation means according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area.

[0071] In order to be able to smoothly implement the interaction verification process based on the factor to be verified, the user needs to pre-open the corresponding boarding service, so as to pre-obtain the card reading authorization data to support this interaction verification process.

[0072] Specifically, for example, before the user's mobile terminal approaches the smart card deployed for the transportation vehicle it takes, a request for opening the boarding service based on the smart card is sent to the server program corresponding to the user-side program on the server in advance. After receiving the card-reading authorization data returned by the server program after agreeing to the boarding service opening request, the card-reading authorization data can be saved locally for backup. The server can be, for example, the server of the service provider of the transportation vehicle, or the server of the service provider providing the corresponding payment service (i.e., the payment service provider), depending on the specific cooperation method. The latter method is more convenient for subsequent deduction and settlement of the boarding service and is convenient for promoting this solution to more transportation vehicles.

[0073] The card-reading authorization data can be in the form of a token or other forms. The same card-reading authorization data can be granted to different opening users, which helps to simplify the processing logic on the smart card.

[0074] Each transportation vehicle (or the smart card deployed thereon) can have its own corresponding security protection key respectively, and has the ability to obtain the security protection key without relying on the above-mentioned user mobile terminal. For example, the security protection key can be generated by the server and then written into the smart card deployed on the transportation vehicle, or the smart card can generate the security protection key by itself. In order to improve the processing efficiency during boarding, the smart card can obtain the security protection key in advance.

[0075] This security protection key can be used for encrypted communication between the smart card and the user mobile terminal (mainly using symmetric encryption) to implement the interactive verification process. In this case, the user mobile terminal also needs to obtain the security protection key. For this, the method adopted in this application is that the user mobile terminal generates the security protection key corresponding to the identification information according to the identification information obtained in the previous step and the card-reading authorization data obtained in advance. In this way, there is no need to negotiate with the smart card additionally for the key, and it can support the smart cards corresponding to multiple transportation vehicles more efficiently and flexibly.

[0076] It should be noted that the security protection key obtained by the user mobile terminal is generated in the specified security area on the user mobile terminal, so as to avoid the leakage of the security protection key from the user mobile terminal, thereby also being able to prevent attackers from using the leaked security protection key to illegally copy the smart card, and it also helps to ensure the security of the boarding transaction and protect the interests of multiple parties such as the transportation vehicle operator, the boarding user, and the payment service provider.

[0077] The specified security area can be, for example, a security area such as TEE or IIFFA. The calculations performed in these areas belong to trusted computing, which can more fully ensure information privacy and security. At the same time, it does not prevent indirectly using the information to be protected to calculate the final target result.

[0078] S106: Use the security protection key to perform an encryption operation on the factor to be verified, and generate a card reading instruction.

[0079] In one or more embodiments of this specification, ride-related information is obtained through card reading interaction for the purpose of deduction. Here, the card reading interaction is cleverly utilized to simultaneously verify the factor to be verified. Based on this idea, a card reading instruction needs to be constructed accordingly. Here, the factor to be verified can be encrypted and used as the attached data of the standard card reading instruction. Thus, the format of the standard card reading instruction can be utilized as much as possible, reducing the transformation cost and having little impact on the efficiency of the card reading interaction. The factor to be verified can be directly encrypted using the security protection key, or can be transformed or attached with other data (such as user-related information such as user identification or user preference data, etc.) and then encrypted using the security protection key. The encryption and decryption algorithms used in this application are not limited here and are not the focus, and can be selected according to actual security requirements, efficiency requirements, or smart card processing capabilities.

[0080] S108: Send the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the factor to be verified, and after the verification passes, return the ride-related information to the user mobile terminal.

[0081] The security protection key held by the smart card itself is obtained from the server or the card writer or generated by itself, and does not need to be obtained from the user mobile terminal. The smart card can use the security protection key to decrypt the factor to be verified from the card reading instruction, and then can verify whether the factor to be verified is consistent with the factor to be verified provided to the user mobile terminal in step S102. If they are consistent, the verification passes; otherwise, the verification fails.

[0082] The ride-related information is information used to determine how to deduct fees, and it includes, for example, one or more of the following information: identification of the transportation means, route information, fare rules, preferential information, etc. The deduction amount, when to deduct the fee, or the type of deduction can be calculated based on the ride-related information.

[0083] S110: Perform corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

[0084] In one or more embodiments of this specification, one or more of the above-mentioned ride-related information is obtained, and based on the obtained information, especially for example, the fare rules, the deduction amount corresponding to this ride is calculated accordingly. According to the deduction amount, corresponding deductions are made on the user mobile terminal or the server corresponding to the user-side program.

[0085] If corresponding deductions are made on the user's mobile terminal, an offline method can be adopted. In this way, more convenience can be brought to users, and scenarios with poor wireless communication signals such as the subway can be better compatible. If it is done on the server, the server's policy is used to deduct the fare on behalf of the boarding user corresponding to the user's mobile terminal. The deducted fees will be settled to the service provider of the transportation vehicle, such as the bus company, etc.

[0086] In one or more embodiments of the present specification, after the smart card passes the verification, the smart card can also record the current boarding record corresponding to the user-end program for fare deduction or checking the fare deduction result. In this way, the service provider of the transportation vehicle and the payment service provider can cooperate more trustingly and accurately, and it also helps to settle accounts more timely.

[0087] In order to enable the smart card to more accurately record the boarding record for a specific user, the smart card can actively sense the user identification corresponding to the other party's user-end program, so as to accurately associate the boarding record with the user identification.

[0088] By Figure 1 's method, there is no need to specially deploy additional hardware devices for the transportation vehicle. Instead, it is relatively simple to mainly deploy a smart card. In this way, the cost is effectively reduced and it is easy to deploy flexibly; and by quickly obtaining the identification information corresponding to the smart card and the verification factor generated by the smart card, and through the two-way interaction based on the card reading instruction and the security protection key corresponding to the transportation vehicle to complete the verification, the interaction speed is made as fast as possible, and the risk of the smart card being illegally copied is also effectively reduced, taking into account both efficiency and security; moreover, this solution enables the user's smartphone to be used as a card reader instead of as an analog card to realize the deduction of transportation vehicle fares, which helps to reduce the dependence on mobile phone manufacturers for the riding solution.

[0089] Based on Figure 1 's method, the present specification also provides some specific implementation schemes and extended schemes of this method, which will be continued to be described below.

[0090] In one or more embodiments of the present specification, a smart card interaction scheme based on ATS (Answer To Select) information and card reading instructions is adopted. In this way, both efficiency and security can be taken into account. Intuitively, see Figure 2 , Figure 2 which is the flow schematic diagram of this smart card interaction scheme.

[0091] Figure 2 The process in

[0092] S202: Obtain the ATS information of the smart card through near-field communication.

[0093] The ATS information can be used for a nearby terminal to select the correct smart card or for the smart card to respond to the nearby terminal correctly. However, in this application, it is mainly used for the user mobile terminal to quickly obtain the material for generating the security protection key and the factor to be verified this time. This material at least includes the identification information corresponding to the smart card. Specifically, for example, the interaction of RATS information and ATS information is carried out.

[0094] S204: Parse the identification information corresponding to the smart card and the factor to be verified generated by the smart card from the ATS information.

[0095] S206: Generate a protected card reading instruction according to the identification information, and perform a card reading interaction with the smart card based on the card reading instruction to verify the factor to be verified.

[0096] In this step, the pre-obtained card reading authorization data and the generation and use encryption actions of the security protection key are also used. The specific implementation manner can refer to the previous description.

[0097] In this way, before the user mobile terminal actually starts card reading, it can be quickly prepared based on the ATS information, and then the card reading action is performed. In addition to obtaining the relevant boarding information, the key point of card reading is that: by the way, the verification process for providing security protection is also completed.

[0098] To make the above-mentioned by-the-way effect more intuitive, one or more embodiments of this specification provide a flow schematic diagram of a card reading instruction generation scheme. See Figure 3 .

[0099] Figure 3 The process in

[0100] S302: Generate a Near Field Communication standard card reading instruction.

[0101] The Near Field Communication standard card reading instruction can refer to the reading instruction constructed in a relatively standard format when usually performing Near Field Communication to read a card or tag supporting the NFC function without implementing the solution of this application. Such an instruction is an instruction that a card or tag supporting the NFC function can normally respond to even without special modification, so that the instruction sender can read the corresponding written data in the card or tag.

[0102] S304: Encrypt the factor to be verified by using the security protection key to obtain an encrypted factor.

[0103] S306: Assemble the near field communication standard card reading instruction and the encryption factor to obtain a near field communication extended card reading instruction, so that the smart card can parse the factor to be verified from the near field communication extended card reading instruction and perform the verification.

[0104] For the near field communication standard card reading instruction, information is extended through data assembly, so that the finally obtained near field communication extended card reading instruction can additionally carry the factor to be verified (which can be in encrypted form). This method has a relatively low implementation cost and also brings a relatively small processing overhead, which is more friendly to smart cards with relatively limited capabilities, thus helping to improve the interaction efficiency.

[0105] In practical applications, for the scenario of taking a bus, there is another pain point, that is, for some routes with a long distance and segmented pricing, users need to swipe their cards when getting on and off the bus, otherwise incorrect billing will occur (usually calculated according to the farthest section), resulting in losses to users. And some users will forget to swipe their cards at least once, or they are unaware that the card swiping fails. To address this pain point, the present application also provides a solution using a smart card. See Figure 4 , Figure 4 for the flow diagram of this solution.

[0106] Figure 4 The process in

[0107] S402: Use the security protection key to perform an encryption operation on the factor to be verified to generate a card reading instruction containing the first location information of the user mobile terminal, so that the smart card can obtain the first location information; or, after the user mobile terminal approaches the smart card deployed for the vehicle it takes, send the first location information of the user mobile terminal to the server.

[0108] The first location information is the location information when the user first interacts with the smart card after getting on the bus. Therefore, it reflects the boarding location, and based on this, the boarding station can be determined. For the entity that obtains the first location information, subsequent actions can be performed. Of course, the first location information can also be transferred to other entities for execution, and the execution result can be written into the smart card in a timely manner.

[0109] S404: After sending the card reading instruction to the smart card, detect whether the user mobile terminal and the vehicle are in a position separation state.

[0110] If conditions permit, the position separation state can be detected more frequently.

[0111] However, a relatively reasonable solution is provided here as an example, including: receiving a location acquisition request sent by the server after the vehicle arrives at the next stop (there may be a delay here, because after arriving at the stop, some users need to wait for a short period of time, such as tens of seconds, before they can be separated far enough from the vehicle); returning the second location information of the user's mobile terminal to the server so that the server can directly use the second location information, or providing the second location information to the smart card, wherein the second location information is used to detect the location separation state in combination with the location information of the vehicle. It can be seen that the second location information may reflect the location of getting off the vehicle, based on which the station to get off the vehicle can be determined. Combined with the previous first location information, the correct section of the corresponding user's ride can be reasonably inferred, and then the correct billing can be achieved, and the mistakes of user or system factors can be accommodated, so that users do not even need to get off the vehicle to swipe the card in this scenario, which is more convenient and reliable.

[0112] S406: If yes, the fee is deducted according to the first location information and the location information of the user mobile terminal after separation.

[0113] The separated position information is, for example, the second position information, or is more accurately determined based on the second position information.

[0114] The basic solution and the extended solution of the present application are described above. To facilitate understanding and implementation, one or more embodiments of this specification provide an application scenario. Figure 1 A flow chart of an implementation scheme of the method can be used as a more recommended implementation scheme, see Figure 5 . In this application scenario, the means of transportation is specifically a bus (it can be implemented similarly for subways or some other means of transportation), and the above-mentioned smart card is exemplarily named: Touch Mother Card. This solution involves four ends: the Touch Mother Card deployed on the bus; the Bus Touch applet on the user's mobile phone, such as provided by the payment service provider, as the above-mentioned user-end program; the bus owner service end; the Bus Touch service end, such as provided by the payment service provider, that is, the service end corresponding to the Bus Touch applet.

[0115] exist Figure 5 In the embodiment, some steps are briefly marked and explained, which can be understood in combination with the following content and the knowledge possessed by those skilled in the art:

[0116] 1. This solution does not require the installation of special hardware equipment on the bus. Instead, a contactless CPU card, i.e. a touch mother card, can be placed in the bus.

[0117] 2. The touch master card is uniformly issued by the bus operator (from the perspective of the payment service provider, i.e., the service provider of the above-mentioned buses) or the payment service provider. The issuance may involve writing information such as the vehicle number of the bus, the line number it travels on, and the fare rules of the vehicle into the touch master card.

[0118] 3. When a user opens the touch-and-go bus service, they first need to apply for activation in the payment service provider's mini-program, i.e., the above-mentioned bus touch mini-program. When applying, the mini-program will request the bus operator's server and provide information such as the mobile phone number and nickname to be activated for the bus. At the same time, the bus or the payment service provider will issue the permission to read the touch master card.

[0119] 4. After the user is activated, they will obtain a card-reading token on the mobile phone, which belongs to the above-mentioned card-reading authorization data. When taking the bus, the user only needs to bring the mobile phone close to the touch master card. The mobile phone will, under the protection of the card-reading token, read the information of the touch master card. Then, the mobile phone or the server will calculate the fare and initiate the automatic deduction.

[0120] 5. The automatic deduction adopts a security protection mechanism and does not require the passenger to confirm again. The security mechanism is as follows:

[0121] 5.1. First, each card has a unique password. The read-write key of the touch master card for each vehicle is unique. The main principle is as follows: The payment service provider (or the bus) has the highest card-reading root key. When the touch master card is issued, based on the physical identifier of the touch master card, assumed to be H, it is dispersed (so that different vehicles correspond to different keys) to obtain the key KeyC, which is used as the above-mentioned security protection key and written into the touch master card as the security protection key for information protection. This calculation process can involve the card-reading token so that the key KeyC can also be generated on the passenger's mobile phone later.

[0122] 5.2. When a passenger activates the touch application, the payment service provider's user-end program (or bus) generates a key and writes it into the IIFFA storage area of the payment service provider's user-end program or the TEE area of the mobile phone. The payment service provider's user-end program obtains the ATS information of the touch mother card through NFC. The ATS information includes the hardware identifier H of the touch mother card and a randomly generated factor, denoted as RandA, as the above-mentioned factor to be verified. The payment service provider's user-end program APP parses RandA and H, calls the security area of the payment service provider's user-end program, and performs subsequent operations through the IIFFA or TEE link. First, assemble the card reading instruction and construct it as readcard. Secondly, according to the card reading token, the security area can use H to disperse and obtain the key KeyC, and use KeyC to encrypt RandA to obtain EnCD, and then assemble it to the end of the card reading instruction to form the final card reading instruction: denoted as readcard|EncD.

[0123] 5.3. The mobile phone sends the command back to the touch mother card. After receiving the command, the touch target card uses its own KeyC to decrypt EncD, obtains the plain text, and compares it with the random number generated by itself to verify whether it is consistent. If the verification passes, the card related information is returned, otherwise, it is not returned. In this way, a security protection mechanism for this scenario is constructed.

[0124] 6. Under the security protection mechanism, the user-side program of the payment service provider obtains the data information on the touch mother card, in which the information is ciphertext and needs to be decrypted by calling IIFFA or TEE environment again. The decryption key is also KeyC. The amount of this deduction can be calculated by the vehicle number, the route number, and the vehicle's fare rules. The deduction can be initiated by the server, or the mobile phone can be temporarily deducted, so that the mobile phone can be used for offline riding.

[0125] 7. In addition, additional functional enhancements can be made, such as: touching the mother card can sense the user identification information of the scanned payment service provider's user-end program through signal amplification and MCU, which can temporarily save the ride data on the one hand, and on the other hand, can also prompt the user that the user has boarded the bus through external voice broadcast capabilities. In addition, a wireless communication module (for example, a 4G or 5G module) can be superimposed to push the ride record to the server for reconciliation of the ride.

[0126] Based on the same idea, one or more embodiments of this specification also provide a flow chart of another method for processing a transportation vehicle boarding service, which is described from the perspective of a smart card deployed on a transportation vehicle, and the execution subject of the process is the smart card or a program running on it, see Figure 6 .

[0127] Figure 6 The process in

[0128] S602: After the user's mobile terminal approaches the smart card, provide the identification information corresponding to the smart card and the verification factor generated by the smart card to the user's mobile terminal through near-field communication.

[0129] S604: Receive the card-reading instruction sent by the user program on the user's mobile terminal. The card-reading instruction is generated by the user program using the security protection key corresponding to the means of transportation to perform an encryption operation on the verification factor. The security protection key is generated by the user program in a specified security area of its local according to the identification information and the pre-acquired card-reading authorization data, so that the generated security protection key is not exposed outside the specified security area.

[0130] S606: Use the security protection key held by itself to perform a decryption operation on the card-reading instruction, verify the verification factor, and after the verification passes, return the ride-related information to the user's mobile terminal for corresponding deduction on the user's mobile terminal or the server corresponding to the user program.

[0131] The security protection key can be obtained by two dispersions of a preset system root key through, for example, industry application identification and the physical identification corresponding to ATS information; and the card-reading authorization data can be obtained by one dispersion of the system root key through, for example, industry application identification. In this case, the security protection key is logically the superior key of the smart card. Therefore, secure operations for interacting with the smart card can be implemented in the security area of the user's mobile terminal, and the ability to implement one-time one-key can be achieved.

[0132] For the user's mobile terminal, the user program can perform secure transportation in the security area according to the card-reading authorization data. Its security factor is, for example, the above-mentioned physical identification, and the calculation data is the random number of this interaction (which can be used as the verification factor) and the instruction information. On the premise of ensuring that the sub-key is not output, a secure message for this instruction interaction is generated to achieve one-time one-key.

[0133] Based on the same idea, one or more embodiments of this specification also provide the corresponding device and equipment for the above method, such as Figures 7 - 10 shown. The device and equipment can correspondingly execute the above method and related optional solutions.

[0134] Figure 7 is a schematic structural diagram of a device for processing the ride service of a means of transportation provided by one or more embodiments of this specification. The device is applied to the user program on the user's mobile terminal, and the device includes:

[0135] A verification information acquisition module 702, after the user mobile terminal approaches a smart card deployed for the vehicle it rides on, obtains the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card through near-field communication;

[0136] A protection key generation module 704 generates a security protection key corresponding to the vehicle in a specified security area on the user mobile terminal according to the identification information and pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0137] A card reading instruction generation module 706 performs an encryption operation on the verification factor to be verified by using the security protection key to generate a card reading instruction;

[0138] A card reading instruction sending module 708 sends the card reading instruction to the smart card, so that the smart card decrypts the card reading instruction by using the security protection key it holds, verifies the verification factor to be verified, and returns ride-related information to the user mobile terminal after the verification passes;

[0139] A ride information deduction module 710 performs corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

[0140] Optionally, the vehicle includes a bus.

[0141] Optionally, it further includes:

[0142] A ride service activation module 712 sends a ride service activation request based on the smart card to the server-side program corresponding to the user-side program on the server before the user mobile terminal approaches a smart card deployed for the vehicle it rides on;

[0143] Receives the card reading authorization data returned by the server-side program after agreeing to the ride service activation request.

[0144] Optionally, the verification information acquisition module 702 obtains the ATS information of the smart card through near-field communication;

[0145] Parses the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card from the ATS information.

[0146] Optionally, the verification factor to be verified is a randomly generated random factor.

[0147] Optionally, the card reading instruction generation module 706 generates a near-field communication standard card reading instruction;

[0148] Encrypt the factor to be verified using the security protection key to obtain an encrypted factor;

[0149] Assemble the near field communication standard card reading instruction and the encrypted factor to obtain a near field communication extended card reading instruction, so that the smart card can parse the factor to be verified from the near field communication extended card reading instruction and perform the verification.

[0150] Optionally, the card reading instruction generation module 706 encrypts the factor to be verified using the security protection key to generate a card reading instruction including the first location information of the user mobile terminal, so that the smart card can obtain the first location information for performing the deduction according to the first location information;

[0151] Or, the device further includes:

[0152] A location information reporting module 714, after the user mobile terminal approaches the smart card deployed on the vehicle it rides on, sends the first location information of the user mobile terminal to the server for performing the deduction according to the first location information.

[0153] Optionally, the performing the deduction according to the first location information specifically includes:

[0154] After sending the card reading instruction to the smart card, detect whether the user mobile terminal and the vehicle are in a position separation state;

[0155] If so, perform the deduction according to the first location information and the separated location information of the user mobile terminal.

[0156] Optionally, the detecting whether the user mobile terminal and the vehicle are in a position separation state specifically includes:

[0157] Receive a location acquisition request sent by the server after the vehicle arrives at the next stop;

[0158] Return the second location information of the user mobile terminal to the server so that the server can directly use the second location information or provide the second location information to the smart card, where the second location information is used to combine with the location information of the vehicle to detect the position separation state.

[0159] Figure 8 It is a schematic structural diagram of another vehicle ride service processing device provided by one or more embodiments of this specification. The device is applied to a smart card deployed on a vehicle, and the device includes:

[0160] The verification information providing module 802, after the user mobile terminal approaches the smart card, provides the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card to the user mobile terminal through near-field communication;

[0161] The card reading instruction receiving module 804 receives the card reading instruction sent by the user program on the user mobile terminal. The card reading instruction is generated by the user program using the security protection key corresponding to the means of transportation to perform an encryption operation on the verification factor to be verified. The security protection key is generated by the user program in a specified security area of its local according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0162] The factor verification return module 806 uses the security protection key it holds to perform a decryption operation on the card reading instruction, verifies the verification factor to be verified, and after the verification passes, returns the ride-related information to the user mobile terminal for corresponding deduction on the user mobile terminal or the server corresponding to the user program.

[0163] Figure 9 The structure schematic diagram of a means of transportation ride service processing device provided for one or more embodiments of this specification. The device is applied to the user program on the user mobile terminal. The device includes:

[0164] At least one processor; and,

[0165] A memory communicatively connected to the at least one processor; wherein,

[0166] The memory stores instructions executable by the at least one processor. The instructions are executed by the at least one processor so that the at least one processor can execute:

[0167] After the user mobile terminal approaches the smart card deployed for the means of transportation it rides, obtain the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card through near-field communication;

[0168] In a specified security area of the user mobile terminal, generate the security protection key corresponding to the means of transportation according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0169] Use the security protection key to perform an encryption operation on the verification factor to be verified to generate a card reading instruction;

[0170] Send the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform decryption operations on the card reading instruction, verify the factor to be verified, and after passing the verification, return ride-related information to the user mobile terminal;

[0171] Perform corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

[0172] Figure 10 It is a schematic structural diagram of a transportation ride service processing device provided by one or more embodiments of this specification. The device is applied to a smart card deployed on a transportation vehicle. The device includes:

[0173] At least one processor; and,

[0174] A memory communicatively connected to the at least one processor; wherein,

[0175] The memory stores instructions executable by the at least one processor. The instructions are executed by the at least one processor, so that the at least one processor can execute:

[0176] After the user mobile terminal approaches the smart card, provide the identification information corresponding to the smart card and the factor to be verified generated by the smart card to the user mobile terminal through near-field communication;

[0177] Receive the card reading instruction sent by the user-side program on the user mobile terminal. The card reading instruction is generated by the user-side program using the security protection key corresponding to the transportation vehicle to perform an encryption operation on the factor to be verified. The security protection key is generated by the user-side program in a specified security area of its local according to the identification information and pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area;

[0178] Use the security protection key it holds to perform decryption operations on the card reading instruction, verify the factor to be verified, and after passing the verification, return ride-related information to the user mobile terminal for corresponding deductions on the user mobile terminal or the server corresponding to the user-side program.

[0179] Based on the same idea, one or more embodiments of this specification also provide a non-volatile computer storage medium, which is applied to the user-side program on the user mobile terminal. The medium stores computer-executable instructions, and the computer-executable instructions are set as:

[0180] After the user mobile terminal approaches the smart card deployed for the vehicle it rides on, obtain the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card through near-field communication;

[0181] In a specified secure area on the user mobile terminal, generate a security protection key corresponding to the vehicle according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified secure area;

[0182] Use the security protection key to perform an encryption operation on the verification factor to be verified to generate a card reading instruction;

[0183] Send the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal;

[0184] Perform corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

[0185] Based on the same idea, one or more embodiments of this specification also provide another non-volatile computer storage medium, which is applied to the smart card deployed on the vehicle. The medium stores computer-executable instructions, and the computer-executable instructions are set as:

[0186] After the user mobile terminal approaches the smart card, provide the identification information corresponding to the smart card and the verification factor to be verified generated by the smart card to the user mobile terminal through near-field communication;

[0187] Receive the card reading instruction sent by the user-side program on the user mobile terminal. The card reading instruction is generated by the user-side program using the security protection key corresponding to the vehicle to perform an encryption operation on the verification factor to be verified. The security protection key is generated by the user-side program in a specified secure area of its local according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified secure area;

[0188] Use the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal for corresponding deductions to be made on the user mobile terminal or the server corresponding to the user-side program.

[0189] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compilers used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not just one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.

[0190] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.

[0191] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0192] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0193] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, the embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0194] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks for implementing the specified functions.

[0195] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks for implementing the specified functions.

[0196] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks for implementing the specified functions.

[0197] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0198] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0199] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0200] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0201] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0202] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device, equipment, and non-volatile computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0203] The above description has been made of specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0204] The above is only one or more embodiments of this specification and is not intended to limit this specification. For those skilled in the art, various changes and modifications can be made to one or more embodiments of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of the claims of this specification.

Claims

1. A method for processing a transportation vehicle boarding service, which is applied to a user-side program on a user mobile terminal. The method includes: After the user mobile terminal approaches a smart card deployed for the transportation vehicle it is to board, obtaining the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication; In a specified security area on the user mobile terminal, generating a security protection key corresponding to the transportation vehicle according to the identification information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; Using the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction; Sending the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor, and after the verification passes, return boarding-related information to the user mobile terminal; Performing corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the boarding-related information.

2. The method according to claim 1, wherein the transportation vehicle includes a bus.

3. The method according to claim 1, before the user mobile terminal approaches a smart card deployed for the transportation vehicle it is to board, the method further includes: Sending a boarding service activation request based on the smart card to the server-side program corresponding to the user-side program on the server; Receiving the card reading authorization data returned by the server-side program after agreeing to the boarding service activation request.

4. The method according to claim 1, wherein the obtaining the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication specifically includes: Obtaining the ATS information of the smart card through near-field communication; Parsing the identification information corresponding to the smart card and the verification factor generated by the smart card from the ATS information.

5. The method according to claim 1, wherein the verification factor is a randomly generated random factor.

6. The method according to claim 1, wherein the using the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction specifically includes: Generating a near-field communication standard card reading instruction; Using the security protection key to encrypt the verification factor to obtain an encrypted factor; Assembling the near-field communication standard card reading instruction and the encrypted factor to obtain a near-field communication extended card reading instruction, so that the smart card can parse the verification factor from the near-field communication extended card reading instruction and perform the verification.

7. The method according to claim 1, wherein the using the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction specifically includes: Using the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction including the first location information of the user mobile terminal, so that the smart card can obtain the first location information for performing the deduction according to the first location information; Or, the method further includes: After the user mobile terminal approaches the smart card deployed for the vehicle it rides on, the first location information of the user mobile terminal is sent to the server for performing the deduction based on the first location information.

8. The method according to claim 7, wherein the performing the deduction based on the first location information specifically includes: After sending the card reading instruction to the smart card, detecting whether the user mobile terminal and the vehicle are in a position separation state; If so, performing the deduction based on the first location information and the post-separation location information of the user mobile terminal.

9. The method according to claim 8, wherein the detecting whether the user mobile terminal and the vehicle are in a position separation state specifically includes: Receiving a location acquisition request sent by the server after the vehicle arrives at the next stop; Returning the second location information of the user mobile terminal to the server so that the server directly uses the second location information, or providing the second location information to the smart card, where the second location information is used to combine with the location information of the vehicle to detect the position separation state.

10. The method according to claim 1, wherein performing corresponding deduction on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information; Obtaining at least one of the following information included in the ride-related information: the identifier of the vehicle, the route information, the fare rule; Calculating the deduction amount corresponding to the current ride according to the obtained information; Performing corresponding deduction on the user mobile terminal or the server corresponding to the user-side program according to the deduction amount.

11. The method according to claim 1, further comprising: Triggering the smart card to record the current ride record corresponding to the user-side program in the smart card after the verification passes, for performing the deduction or checking the deduction.

12. In the method according to claim 1, the security protection keys corresponding to different vehicles are different.

13. A method for processing vehicle ride services, applied to a smart card deployed on a vehicle, the method comprising: After the user mobile terminal approaches the smart card, providing the identifier information corresponding to the smart card and the to-be-verified factor generated by the smart card to the user mobile terminal through near field communication; Receiving a card reading instruction sent by a user-side program on the user mobile terminal, wherein the card reading instruction is generated by the user-side program through performing an encryption operation on the to-be-verified factor by using the security protection key corresponding to the vehicle, and the security protection key is generated by the user-side program in a specified security area of its local according to the identifier information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; Using the security protection key it holds, perform decryption operations on the card reading instruction, verify the factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal for corresponding deduction on the user mobile terminal or the server corresponding to the user-side program.

14. A transportation vehicle ride service processing device, applied to a user-side program on a user mobile terminal, the device comprising: A verification information acquisition module, after the user mobile terminal approaches a smart card deployed for the transportation vehicle it rides on, obtains the identification information corresponding to the smart card and the factor to be verified generated by the smart card through near-field communication; A protection key generation module, in a specified security area on the user mobile terminal, generates a security protection key corresponding to the transportation vehicle according to the identification information and pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; A card reading instruction generation module, uses the security protection key to perform encryption operations on the factor to be verified to generate a card reading instruction; A card reading instruction sending module, sends the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform decryption operations on the card reading instruction, verify the factor to be verified, and after the verification passes, return ride-related information to the user mobile terminal; A ride information deduction module, performs corresponding deduction on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

15. The device according to claim 14, wherein the transportation vehicle includes a bus.

16. The device according to claim 14, further comprising: A ride service activation module, before the user mobile terminal approaches a smart card deployed for the transportation vehicle it rides on, sends a ride service activation request based on the smart card to the server-side program corresponding to the user-side program on the server; Receives the card reading authorization data returned by the server-side program after agreeing to the ride service activation request.

17. The device according to claim 14, wherein the verification information acquisition module obtains the ATS information of the smart card through near-field communication; Parses the identification information corresponding to the smart card and the factor to be verified generated by the smart card from the ATS information.

18. The device according to claim 14, wherein the factor to be verified is a randomly generated random factor.

19. The device according to claim 14, wherein the card reading instruction generation module generates a near-field communication standard card reading instruction; Uses the security protection key to encrypt the factor to be verified to obtain an encrypted factor; Assembles the near-field communication standard card reading instruction and the encrypted factor to obtain a near-field communication extended card reading instruction, so that the smart card can parse the factor to be verified from the near-field communication extended card reading instruction and perform the verification.

20. The device according to claim 14, wherein the card reading instruction generation module uses the security protection key to perform an encryption operation on the factor to be verified, and generates a card reading instruction including the first location information of the user mobile terminal, so that the smart card can obtain the first location information for performing the deduction according to the first location information; Alternatively, the device further includes: A location information reporting module, after the user mobile terminal approaches the smart card deployed for the vehicle it takes, sends the first location information of the user mobile terminal to the server for performing the deduction according to the first location information.

21. The device according to claim 20, wherein the performing the deduction according to the first location information specifically includes: After sending the card reading instruction to the smart card, detecting whether the user mobile terminal and the vehicle are in a position separation state; If so, performing the deduction according to the first location information and the location information after separation of the user mobile terminal.

22. The device according to claim 21, wherein the detecting whether the user mobile terminal and the vehicle are in a position separation state specifically includes: Receiving a location acquisition request sent by the server after the vehicle arrives at the next stop; Returning the second location information of the user mobile terminal to the server, so that the server can directly use the second location information, or provide the second location information to the smart card, wherein the second location information is used to combine with the location information of the vehicle to perform the detection of the position separation state.

23. A vehicle ride service processing device is applied to a smart card deployed on a vehicle. The device includes: A verification information providing module, after the user mobile terminal approaches the smart card, provides the identification information corresponding to the smart card and the factor to be verified generated by the smart card to the user mobile terminal through near field communication; A card reading instruction receiving module, receives the card reading instruction sent by the user program on the user mobile terminal, wherein the card reading instruction is generated by the user program using the security protection key corresponding to the vehicle to perform an encryption operation on the factor to be verified, and the security protection key is generated by the user program in a specified security area of its local according to the identification information and the pre-acquired card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; A factor verification and return module, uses the security protection key it holds to perform a decryption operation on the card reading instruction, verifies the factor to be verified, and after the verification passes, returns ride-related information to the user mobile terminal for performing corresponding deductions on the user mobile terminal or the server corresponding to the user program.

24. A vehicle ride service processing device is applied to a user program on a user mobile terminal. The device includes: At least one processor; And, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform: After the user mobile terminal approaches the smart card deployed for the vehicle it takes, obtain the identification information corresponding to the smart card and the verification factor generated by the smart card through near-field communication; In a specified security area on the user mobile terminal, generate a security protection key corresponding to the vehicle according to the identification information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; Use the security protection key to perform an encryption operation on the verification factor to generate a card reading instruction; Send the card reading instruction to the smart card, so that the smart card uses the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor, and after the verification passes, return ride-related information to the user mobile terminal; Perform corresponding deductions on the user mobile terminal or the server corresponding to the user-side program according to the ride-related information.

25. A vehicle ride service processing device, applied to a smart card deployed on a vehicle, the device includes: At least one processor; And, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform: After the user mobile terminal approaches the smart card, provide the identification information corresponding to the smart card and the verification factor generated by the smart card to the user mobile terminal through near-field communication; Receive the card reading instruction sent by the user-side program on the user mobile terminal, wherein the card reading instruction is generated by the user-side program performing an encryption operation on the verification factor using the security protection key corresponding to the vehicle, and the security protection key is generated by the user-side program in a specified security area of its local according to the identification information and the pre-obtained card reading authorization data, so that the generated security protection key is not exposed outside the specified security area; Use the security protection key it holds to perform a decryption operation on the card reading instruction, verify the verification factor, and after the verification passes, return ride-related information to the user mobile terminal for performing corresponding deductions on the user mobile terminal or the server corresponding to the user-side program.

Citation Information

Patent Citations

  • Method, device and system for mutual authentication between terminal and intelligent card

    CN101883357A

  • Bus fee deduction method and system

    CN112712634A