A SAM card control system and method

Through near-field communication and NDEF file transmission between the device terminal and the SAM card module, the complex and cost-effective SAM card unlocking method is solved, online unlocking and security management is realized, and time and money costs are reduced.

CN119483960BActive Publication Date: 2025-07-04ZHUHAI RUICHENG TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510072927.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-07-04
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The existing SAM card unlocking method requires replacement of a new card or issuing the card offline to unlock it, resulting in high time and money costs, and problems such as security risks and complex tool version management.

Method used

Near-field communication is established with the SAM card module through the device terminal, unlock requests and ciphertext transmission is used using NFC units and NDEF files, the card issuing bank background server verifies and generates unlock commands, and the device terminal updates the SAM card authorization information.

Benefits of technology

It realizes online unlocking, saves SAM card exception handling time and money costs, avoids security risks and tool version management workload, and improves security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119483960B_ABST
    Figure CN119483960B_ABST
Patent Text Reader

Abstract

The present invention discloses a SAM card control system and method. The system includes: a SAM card module to be controlled, a device terminal, and an issuing bank's back-end server. The module includes a SAM card and an NFC unit. When the device terminal meets the relative distance condition, it establishes a near-field communication connection with the NFC unit and sends a read record command, causing the module to determine the NDEF file according to the command and feedback it to the device terminal. Based on the NDEF file, when the operation type is an unlocking type, the device terminal generates an unlocking request and sends it to the issuing bank's back-end server. When the back-end server verifies that the unlocking request meets the unlocking conditions, it generates an unlocking ciphertext according to a preset method and transmits it. When the device terminal receives the unlocking ciphertext, it generates an unlocking command based on a preset NFC unit tag reading and writing software and the unlocking ciphertext and sends it to the module, causing the module to update the authorization information of the SAM card according to the unlocking command. Through the online unlocking form, the processing time and money costs are saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a SAM card control system and method. Background Art

[0002] A Security Access Module (SAM) card is a hardware security module used for storing and processing encrypted data, performing identity authentication, and digital signature. It is widely used in fields such as finance, communication, payment, and production. The life cycle of a SAM card generally includes four stages: the first stage, SAM card production; the second stage, SAM card initialization; the third stage, SAM card usage; and the fourth stage, SAM card locking. To effectively control the usage security of the SAM card, the SAM card issuer usually sets the first and second stages to occur at the card factory or the issuer, while the third and fourth stages occur at the terminal, and sets the life cycle of the SAM card to be irreversible. Therefore, if the SAM card enters the locked state due to reaching the limit of usage times or detecting abnormal situations such as being attacked, the SAM card usage terminal will be restricted and unable to be used normally.

[0003] To solve the problem of recovery after locking, the terminal user can choose to apply for a new SAM card to replace the locked SAM card. The locked SAM card can also be sent to the issuer, and the issuer can use a dedicated command to unlock and reset the usage permission of the SAM card in a secure environment, and then send it back to the terminal for continued use. Or the issuer sends the corresponding unlocking tool to the terminal user through a secure channel, and the terminal user completes the unlocking or authorization times reset of the SAM card through the unlocking tool.

[0004] However, replacing the SAM card takes additional mailing time, and both the issuer and the device terminal need to configure new SAM card management parameters, increasing the complexity of the SAM card management systems at both ends. Although it does not cause SAM card waste and the workload of reconfiguring the terminal compared to the first technical solution; similarly, for the second method, the locked SAM card needs to be first sent from the terminal user to the issuer, and then after the issuer unlocks and resets the SAM card, it is sent back to the terminal user, so it will take more time and money. Then the third method is that the terminal user independently completes the unlocking and resetting, so the issuer cannot obtain the information of the SAM card and cannot uniformly manage the issued SAM cards. Then if the SAM card unlocking tool is cracked, the issuer will no longer be able to effectively control the secure and legal use of the SAM card, so it may bring serious security threats and economic losses. In addition, usually, the SAM card unlocking tool has high requirements for the software operating environment and operation process due to security considerations, and may require the issuer to manage different versions of the SAM card unlocking tools, thus additionally increasing the cost of offline tool version management. Summary of the Invention

[0005] The present invention provides a SAM card control system and method to achieve online unlocking control of the SAM card.

[0006] According to one aspect of the present invention, a SAM card control system is provided. The system includes: a SAM card module to be controlled, a device terminal, and an issuing bank background server. The SAM card module to be controlled includes a SAM card and an NFC unit;

[0007] The device terminal is configured to establish a near-field communication connection with the NFC unit in the SAM card module to be controlled in response to meeting the relative distance condition, and send a read record command carrying an NFC tag application identifier to the SAM card module to be controlled;

[0008] The SAM card module to be controlled is configured to determine an NFC data exchange format NDEF file according to the read record command and feedback it to the device terminal;

[0009] The device terminal is configured to determine the operation type of the SAM card based on the NDEF file. When the operation type is an unlocking type, an unlocking request is generated according to the NDEF file and sent to the issuing bank background server;

[0010] When the issuing bank background server verifies that the unlocking request meets the unlocking conditions, an unlocking ciphertext is generated in a preset manner and transmitted to a preset target. The preset target includes the device terminal or other associated devices;

[0011] The device terminal is configured to generate an unlocking command based on a preset NFC unit tag reading and writing software and the unlocking ciphertext when receiving the unlocking ciphertext, and send the unlocking command to the SAM card module to be controlled;

[0012] The SAM card module to be controlled is configured to update the authorization information of the SAM card according to the unlocking command.

[0013] According to a second aspect of the present invention, a SAM card control method is provided. The method is applied to the SAM card control system according to any one of the embodiments of the present invention. The system includes: a SAM card module to be controlled, a device terminal, and an issuing bank background server. The SAM card module to be controlled includes a SAM card and an NFC unit. The method includes:

[0014] The device terminal responds to meeting the relative distance condition, establishes a near-field communication connection with the NFC unit in the SAM card module to be controlled, and sends a read record command carrying an NFC tag application identifier to the SAM card module to be controlled;

[0015] The to-be-controlled SAM card module determines an NFC data exchange format NDEF file according to the read record command and feeds it back to the device terminal;

[0016] The device terminal determines the operation type of the SAM card based on the NDEF file. When the operation type is the unlocking type, an unlocking request is generated according to the NDEF file and sent to the issuing bank's back-end server;

[0017] When the issuing bank's back-end server verifies that the unlocking request meets the unlocking conditions, an unlocking ciphertext is generated in a preset manner and transmitted to a preset target, and the preset target includes the device terminal or other associated devices;

[0018] When the device terminal receives the unlocking ciphertext, an unlocking command is generated based on the preset NFC unit tag reading and writing software and the unlocking ciphertext and sent to the to-be-controlled SAM card module;

[0019] The to-be-controlled SAM card module updates the authorization information of the SAM card according to the unlocking command.

[0020] The technical solution of the embodiment of the present invention provides a system including: a to-be-controlled SAM card module, a device terminal, and an issuing bank's back-end server. The to-be-controlled SAM card module includes a SAM card and an NFC unit; the device terminal is used to establish a near-field communication connection with the NFC unit in the to-be-controlled SAM card module in response to meeting the relative distance condition and send a read record command carrying an NFC tag application identifier to the to-be-controlled SAM card module; the to-be-controlled SAM card module is used to determine an NFC data exchange format NDEF file according to the read record command and feed it back to the device terminal; the device terminal is used to determine the operation type of the SAM card based on the NDEF file. When the operation type is the unlocking type, an unlocking request is generated according to the NDEF file and sent to the issuing bank's back-end server; the issuing bank's back-end server is used to generate an unlocking ciphertext in a preset manner and transmit it to a preset target when verifying that the unlocking request meets the unlocking conditions, and the preset target includes the device terminal or other associated devices; the device terminal is used to generate an unlocking command based on the preset NFC unit tag reading and writing software and the unlocking ciphertext and send it to the to-be-controlled SAM card module when receiving the unlocking ciphertext; the to-be-controlled SAM card module is used to update the authorization information of the SAM card according to the unlocking command. Information transmission between the device terminal is established through the NFC unit, and unlocking is performed in the form of the device terminal being online. There is no need to replace a new SAM card, nor does the issuing bank need to unlock the SAM card offline, saving the SAM card exception handling time and financial costs. The issuing bank does not need to send the corresponding unlocking tool software to the end user to unlock the SAM card, so risks are avoided and the workload of unlocking tool software version management is reduced.

[0021] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0023] Figure 1 is a schematic structural diagram of a SAM card control system provided in Embodiment 1 of the present invention;

[0024] Figure 2 is a flowchart of the steps of a SAM card control system provided in Embodiment 1 of the present invention;

[0025] Figure 3 is a flowchart of a SAM card control method provided in Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] Embodiment 1

[0029] Figure 1Schematic diagram of a SAM card control system provided in the first embodiment of the present invention. This embodiment is applicable to the control of SAM cards, such as Figure 1 As shown, the system includes: a SAM card module to be controlled, a device terminal, and an issuing bank's back-end server. The SAM card module to be controlled includes a SAM card and an NFC unit.

[0030] The device terminal is configured to establish a near-field communication connection with the NFC unit in the SAM card module to be controlled in response to meeting the relative distance condition, and send a read record command carrying an NFC tag application identifier to the SAM card module to be controlled; the SAM card module to be controlled is configured to determine an NFC data exchange format NDEF file according to the read record command and feed it back to the device terminal; the device terminal is configured to determine the operation type of the SAM card based on the NDEF file. When the operation type is an unlocking type, an unlocking request is generated according to the NDEF file and sent to the issuing bank's back-end server; the issuing bank's back-end server is configured to generate an unlocking ciphertext in a preset manner and transmit it to a preset target when the unlocking request is verified to meet the unlocking condition. The preset target includes the device terminal or other associated devices; the device terminal is configured to generate an unlocking command based on the preset NFC unit tag reading and writing software and the unlocking ciphertext and send it to the SAM card module to be controlled when receiving the unlocking ciphertext; the SAM card module to be controlled is configured to update the authorization information of the SAM card according to the unlocking command.

[0031] In this embodiment, the device terminal can be understood as a device configured with NFC function, supporting the NFC card reader mode and capable of screen display. For example, it can include a mobile phone configured with NFC function, etc. The relative distance condition can be understood as the condition for judging whether the distance between the device terminal and the SAM card module to be controlled reaches the distance for establishing a near-field communication connection. The Near Field Communication (NFC) unit can be understood as a unit equipped with NFC function to enable the SAM card module to be controlled to have NFC function. The NFC tag Application Identifier (AID) can be understood as the NFC tag application identifier AID defined by NFC Forum T4T, which is used to uniquely identify the coding system of the NFC application. Through this AID, it can be determined that the NFC unit is configured with the NFC Forum T4T application. The read record command can be understood as the command for reading NDEF records. The NFC Data Exchange Format (NDEF) file can be understood as a file formed by encapsulating the transmitted information into one or more "records". NDEF refers to the standardized format for exchanging data between NFC devices. It defines a structured way to store and transmit data, enabling NFC devices to identify, read, and write NFC tags containing various types of information. The unlock request can be understood as the request for unlocking the locked SAM card. The operation type can be understood as the control method for the SAM card. For example, when the SAM card is locked, it corresponds to the unlock type. When the SAM card is not locked, it can also include the information display type, etc., which can be defined according to requirements.

[0032] In this embodiment, the issuing bank's back-end server can be understood as the back-end server of the issuing bank that issues the SAM card. The unlock condition can be understood as the condition for verifying whether the SAM card can be unlocked. For example, it can be the access permission of the terminal user of the SAM card, etc. The preset method can be understood as the method for generating the unlock ciphertext set according to different transmission channels. The unlock ciphertext can be understood as the content used to unlock the SAM card in ciphertext form. The preset target can be understood as the terminal that receives the unlock ciphertext. For example, it can be the device terminal that sends the unlock request or other associated devices. Other associated devices can be understood as the devices used for unlocking the SAM card. For example, it can include card readers. The preset NFC unit tag reading and writing software can be understood as an APP that supports the reading and writing of NFC unit tags. The unlock command can be understood as the command for unlocking the SAM card to enable the SAM card to perform the unlocking. The authorization information can be understood as the information related to the use of the SAM card. For example, it can include the use status, the number of authorization times, and the authorization validity period, etc.

[0033] Specifically, when the user has a control requirement for the SAM card, the SAM card module to be controlled can be brought close to the device terminal. When the device terminal responds to the relative distance condition being met with the SAM card module to be controlled, it can establish a near-field communication connection with the NFC unit in the SAM card module to be controlled, and then perform data interaction in the format of an Application Protocol Data Unit (APDU). After establishing the near-field communication connection, the NFC reader in the device terminal uses the NFC Forum T4T fixed application-defined NFC tag application identifier (AID) to send a read record command carrying the NFC tag application identifier to the SAM card module to be controlled.

[0034] Specifically, when the SAM card module to be controlled receives the read record command, since this AID is used to identify whether the SAM card module to be controlled contains the NFC tag application corresponding to the AID (i.e., the aforementioned NFC Forum T4T fixed application), if the SAM card module to be controlled has the NFC tag application corresponding to the AID, it can first respond with the corresponding status word to the device terminal to indicate that it has the corresponding NFC tag application, and obtain the NDEF file representing the current state of the SAM card from the SAM application through the NFC tag application, and then feedback it to the device terminal.

[0035] Specifically, based on the NDEF file feedback by the SAM card module to be controlled, the device terminal can parse the NDEF file, first determine the operation type for the SAM card module to be controlled. When the operation type is the unlocking type, the device terminal can generate an unlocking request according to the unlocking-related information in the NDEF file, and send the unlocking request to the card-issuing bank's back-end server through the interaction method provided in the NDEF file.

[0036] Specifically, when the card-issuing bank's back-end server receives the unlocking request, it can first verify the SAM card verification ciphertext in the unlocking request. If the ciphertext is correct, it determines the SAM card access permission in the unlocking request. When it has the access permission and meets the unlocking conditions, the card-issuing bank's back-end server can generate the corresponding unlocking ciphertext in a preset manner and transmit it to the preset target. When the preset target is the device terminal, it can be directly sent through the transmission channel. When the preset target is other associated devices, it can be transmitted to other associated devices through transmission forms such as emails. If the unlocking conditions are not met, the unlocking request is rejected, and it can be feedback to the device terminal by responding with corresponding prompts and other means.

[0037] Specifically, when the device terminal receives the unlocking ciphertext, it can generate an unlocking command by copying the NDEF record in the unlocking ciphertext based on the preset NFC unit tag reading and writing software and send it to the SAM card module to be controlled. When the SAM card module to be controlled receives the unlocking command, it can write the NDEF record in the unlocking command into the SAM card to update the authorization information of the SAM card.

[0038] The technical solution of the embodiment of the present invention provides a system including: a SAM card module to be controlled, a device terminal, and an issuing bank background server. The SAM card module to be controlled includes a SAM card and an NFC unit; the device terminal is used to establish a near-field communication connection with the NFC unit in the SAM card module to be controlled in response to meeting the relative distance condition, and send a read record command carrying an NFC tag application identifier to the SAM card module to be controlled; the SAM card module to be controlled is used to determine the NFC data exchange format NDEF file according to the read record command and feedback it to the device terminal; the device terminal is used to determine the operation type of the SAM card based on the NDEF file. When the operation type is the unlocking type, generate an unlocking request according to the NDEF file and send it to the issuing bank background server; the issuing bank background server is used to generate an unlocking ciphertext in a preset manner and transmit it to a preset target when verifying that the unlocking request meets the unlocking conditions. The preset target includes the device terminal or other associated devices; the device terminal is used to generate an unlocking command based on the preset NFC unit tag reading and writing software and the unlocking ciphertext when receiving the unlocking ciphertext and send it to the SAM card module to be controlled; the SAM card module to be controlled is used to update the authorization information of the SAM card according to the unlocking command. Information transmission between the device terminal is established through the NFC unit, and unlocking is performed in the form of the device terminal being online. There is no need to replace the new SAM card, nor does the issuing bank need to unlock the SAM card offline, saving the SAM card exception handling time and monetary cost. The issuing bank does not need to send the corresponding unlocking tool software to the end user to unlock the SAM card, so the risk is avoided and the workload of unlocking tool software version management is reduced.

[0039] Further, on the basis of the above embodiment, the SAM card module to be controlled may further include a super input / output chip SIO interface. Correspondingly, the step of determining the NFC data exchange format NDEF file according to the read record command and feedbacking it to the device terminal is refined as:

[0040] The NFC unit receives a read record command through the NFC tag application and forwards it to the SAM card based on the SIO interface; the SAM card determines the current status through the SAM application. If the current status is unlocked, the type field in the NDEF record is set to the first type, and the SAM card usage information is placed in the payload field of the NDEF record to obtain the organized NDEF file; if the current status is locked, the type field in the NDEF record is set to the second type, the decrypted ciphertext based on the unique number of the SAM card is calculated, and the decrypted ciphertext, the uniform resource identifier of the issuing bank's back-end server, and the SAM card information are placed in the payload field to obtain the NDEF file; the NDEF file is sent to the NFC tag application through the SIO interface, and the NDEF file is fed back to the device terminal through the NFC unit.

[0041] In this embodiment, the Super Input / Output Chip (SIO) interface can be understood as an interface for data transmission between the SAM and the NFC. In the software system architecture of the SAM card module to be controlled, the SAM application and the NFC tag application can be separated by multiple firewalls to ensure that each application is independent and not affected. Therefore, an SIO interface can be added in the application management platform (i.e., the SAM card operating system) to achieve data transmission between the SAM application and the NFC tag application. The SAM application can be understood as being dedicated to encryption, decryption, and authentication of the hardware security module. The current status can be understood as status information used to characterize the locking situation of the SAM card. The NDEF record can be understood as a record for transmitting the data required for the current SAM card operation. The type field can be understood as a field used to distinguish the operation type of the SAM card. The first type can be understood as a field used to indicate the information display type, for example, it can be represented by 'T'. The payload field, that is, the payload field, is used to record the payload. The SAM card usage information can be understood as information related to the current usage of the SAM card, such as the SAM card identification information and the remaining duration of the validity period, etc., which can be predefined according to the information the user wants to display. The second type can be understood as a field used to indicate the unlocking type, for example, it can be represented by 'U'. The Universally Unique Identifier (UID) of the SAM card can be understood as the unique identifier used to characterize the identity of the SAM card. The decrypted ciphertext can be understood as the decryption request after encryption. The Uniform Resource Identifier (URI) can be understood as a string used to uniquely identify Internet resources, which can locate and access the resources of the issuing bank's back-end server on the network. For example, it can be the web access URL. The SAM card information can be understood as specific information for organizing the unlocking process.

[0042] Specifically, the device terminal indirectly transmits information to the SAM card through the NFC unit. Then, the NFC unit of the SAM card module to be controlled receives the read record command through the NFC tag application and forwards it to the SAM card based on the SIO interface. The SAM card determines its current state through the SAM application. If the current state is unlocked, the TYPE field in the NDEF record is set to the first type (e.g., 'T'), and the SAM card usage information is placed in the PAYLOAD field of the NDEF record to obtain the organized NDEF file. If the current state is locked, the TYPE field in the NDEF record is set to the second type (e.g., 'U'), and the decrypted ciphertext based on the unique number of the SAM card is calculated through the SAM application. The decrypted ciphertext, the uniform resource identifier of the issuing bank's background server, and the SAM card information are placed in the PAYLOAD field to obtain the NDEF file. The NDEF file is sent to the NFC tag application through the SIO interface, and the NDEF file is fed back to the device terminal through the NFC unit.

[0043] Exemplarily, the NDEF record format under the first type can be specifically shown in Table 1:

[0044] Table 1 NDEF record format showing SAM card information

[0045]

[0046] Among them, the first column represents the header information, including flag bits such as MB, ME, CF, SR, IL, and TNF. These flag bits are used to describe various attributes of the record. The second column represents the type length, which is used to indicate the length of the record type field. The third column represents the payload length, which is used to record the length of the valid content. The fourth column represents the record type. The fifth column represents the ID length. The sixth column represents the record ID. The seventh column represents the SAM card information content, which records the payload.

[0047] Table 2 NDEF record format for requesting SAM card unlocking

[0048]

[0049] Similar to the above description, it can be seen that the representation symbols of the record types are different. The record type of the displayed information is represented by 'T', while the record type of the unlocking is represented by 'U'.

[0050] Furthermore, based on the above embodiments, the step of determining the operation type of the SAM card based on the NDEF file can be refined as:

[0051] Extract the type field in the NDEF file; when the type field is the first type, determine the operation type of the SAM card as the information display type; when the type field is the second type, determine the operation type of the SAM card as the unlocking type.

[0052] Specifically, when the device terminal receives the NDEF file, it can parse to obtain the type field in the NDEF file; when the type field is the first type, determine the operation type of the SAM card as the information display type; when the type field is the second type, determine the operation type of the SAM card as the unlocking type.

[0053] Optionally, the device terminal further includes:

[0054] When the operation type is the information display type, parse the NDEF file to obtain the SAM card usage information and display the SAM card usage information.

[0055] Specifically, when the operation type is the information display type, the device terminal can parse the NDEF file to obtain the SAM card usage information included therein and display the SAM card usage information on the screen of the device terminal.

[0056] Further, on the basis of the above embodiment, the step of generating an unlocking request according to the NDEF file and sending it to the card-issuing bank's back-end server can be refined as:

[0057] Parse the NDEF file to obtain the decryption ciphertext, SAM card information, and the uniform resource identifier of the card-issuing bank's back-end server; generate a decryption request according to the decryption ciphertext and SAM card information; access the uniform resource identifier and send the decryption request to the card-issuing bank's back-end server.

[0058] Specifically, the device terminal can parse the NDER file to obtain the unlocking ciphertext for verifying the SAM card, SAM card information, and the uniform resource identifier of the card-issuing bank's back-end server. The device terminal can generate a decryption request in a preset format, access the uniform resource identifier through means such as a web browser, and send the decryption request to the card-issuing bank's back-end server.

[0059] Exemplarily, the data format of the decryption request can be shown by Example in Table 3

[0060] Table 3 Unlocking request data format for applying for SAM card unlocking fields

[0061]

[0062] Further, on the basis of the above embodiment, the step of generating an unlocking ciphertext in a preset manner and transmitting it to a preset target can be refined as:

[0063] When the preset method is to transmit to other associated devices, the unlocking ciphertext is generated in the form of an unlocking command set and transmitted to other associated devices; when the preset method is to transmit to the device terminal, the unlocking ciphertext is generated according to the response NDEF record and transmitted to the device terminal.

[0064] In this embodiment, the unlocking command set can be understood as a command set in ciphertext form and is a form of executable data frame.

[0065] Specifically, according to different preset targets, the form of the unlocking ciphertext can be divided into two types, namely the unlocking command set and the NDEF record. When the preset method is to transmit to other associated devices, since other associated devices decrypt and transmit by directly writing to the SAM card and do not require NFC forwarding, the issuing bank's back-end server can generate the unlocking ciphertext in the form of an unlocking command set and transmit it to other associated devices. When the preset method is to transmit to the device terminal, since the device terminal can directly transmit data with the SAM card module to be controlled through NFC, the issuing bank's back-end server can generate the unlocking ciphertext according to the response NDEF record and transmit it to the device terminal.

[0066] Optionally, the system further includes:

[0067] When the preset target is other associated devices, based on the unlocking command set in the unlocking ciphertext, other associated devices generate unlocking commands in the form of application protocol data unit (APDU) and send them to the SAM card module to be controlled one by one.

[0068] In this embodiment, the form of the application protocol data unit (APDU) is the basic information unit for transmitting commands and responses between the NFC card and the device terminal.

[0069] Specifically, when the preset target is other associated devices, other associated devices (such as a card reader) generate unlocking commands in the form of application protocol data unit (APDU) based on the unlocking command set in the unlocking ciphertext and send them to the SAM card module to be controlled one by one.

[0070] It can be known that there are many devices with NFC functions, such as bank cards or access control cards, etc. When these devices are close to the device terminal, a near-field communication connection will be established, but they cannot execute the functions mentioned in the present invention. Therefore, a distinguishing method is needed to distinguish which devices have control requirements.

[0071] Furthermore, in order to distinguish devices, the SAM card module to be controlled is further used for:

[0072] When receiving a read record command, generate a target response status word through the NFC tag application of the NFC unit and feedback it to the device terminal.

[0073] In this embodiment, the target response status word can be understood as an identifier used to represent the existence of an NFC tag application.

[0074] Specifically, when the SAM card module to be controlled receives a read record command, the target response status word can be generated by the NFC tag application of the NFC unit and fed back to the device terminal, so as to represent that the SAM card module to be controlled is a device with control requirements through the target response status word.

[0075] Furthermore, the device terminal is further configured to:

[0076] Receive the response status word. When the response status word is not the target response status word, disconnect the near-field communication connection.

[0077] Specifically, since there are still some devices with NFC functions, such as transportation cards, etc., which do not need to be controlled by this method, this type of device needs to be screened out. When the device terminal receives the response status word, it can first judge the response status word. When the response status word is not the target response status word, that is, the device establishing the near-field communication connection only has NFC functions but does not have control requirements, the device terminal can disconnect the near-field communication connection.

[0078] The technical solution of the embodiment of the present invention establishes a communication connection and data interaction between the SAM card module to be controlled and the device terminal based on the existing mature and common communication protocol NFC and the data exchange format NDEF file. The device terminal only needs to have the NFC function, which has the advantages of simple implementation, ensuring communication data security and being compatible with different devices. By interacting the NDEF file between the SAM card module to be controlled and the device terminal, the device terminal can independently judge the operation type to be performed on the SAM card, changing the traditional requirement of reading SAM card information that users need to be familiar with the complex private commands and data format parsing in the corresponding product manual to the device terminal automatically sending and parsing the data responded by the SAM card through the SAM card supporting the NDEF data format, and displaying various information of the SAM card in the form preset by the issuing bank, realizing the automatic control of the SAM card. When the operation type is the information display type, the SAM card usage information obtained by parsing the NDEF file can be displayed, solving the problem that the SAM card usage information cannot be displayed. When the operation type is the unlocking type, the device terminal automatically generates an unlocking request and sends it to the issuing bank's back-end server through an online connection method, so that when the issuing bank's back-end server verifies that the unlocking request meets the unlocking conditions, it automatically generates an unlocking ciphertext, realizing the transmission of the unlocking ciphertext on the basis of ensuring the device security. Through various transmission forms of the device terminal or other associated devices, the unlocking ciphertext is sent to the SAM card module to be controlled, so that the SAM card verifies the unlocking command and updates the authorization information after the verification passes, realizing the unlocking of the SAM card through an online method. The issuing bank does not need to send the corresponding unlocking tool software to the end user to unlock the SAM card, thus avoiding risks, and improving the security through the double ciphertext verification of the issuing bank's back-end server and the SAM card, and also reducing the workload of version management of the unlocking tool software. The online unlocking method allows the issuing bank to build a real-time processing system for SAM cards on the back-end server, solving problems such as different locations and time differences. There is no need to replace the new SAM card, nor does the issuing bank need to unlock the SAM card offline, so it saves the time and money costs for abnormal handling of the terminal SAM card.

[0079] Exemplarily, for the convenience of understanding the overall process of the present invention, a specific example is used as a demonstration. Figure 2 FIG. is a flowchart of the steps of a SAM card control system provided in Embodiment 1 of the present invention. As Figure 2 shown, the steps may include:

[0080] S201. In response to meeting the relative distance condition, establish a near-field communication connection with the NFC unit in the SAM card module to be controlled, and send a read record command carrying the NFC tag application identifier to the SAM card module to be controlled;

[0081] S202. If there is an NFC tag application corresponding to the NFC tag application identifier in the read record command, the target response status word is SW-9000;

[0082] S203. Determine whether the SAM card is locked through the SAM application. If so, jump to step S208; if not, jump to step S204;

[0083] S204. The SAM application organizes the NDEF record, including setting the TYPE field to 'T' and placing the SAM card usage information in the PAYLOAD field;

[0084] S205. Parse the NDEF record and display the SAM card usage information on the screen;

[0085] S206. If there is no NFC tag application corresponding to the NFC tag application identifier in the read record command, the response status word is SW-6A82;

[0086] S207. When the response status word is SW-6A82, disconnect the near-field communication connection;

[0087] S208. The SAM application organizes the NDEF record, including setting the TYPE field to 'U', calculating the decrypted ciphertext based on the SAM card UID, and organizing SAM card information such as the URI for accessing the issuer's background server into the PAYLOAD field;

[0088] S209. Parse the NDEF file to generate a decryption request, access the uniform resource identifier, and send the decryption request to the issuer's background server;

[0089] S210. Verify whether the unlock request meets the unlock conditions. If so, jump to step S212 or S213; if not, jump to step S211;

[0090] S211. Reject the unlock request from the device terminal;

[0091] S212. When the preset target is the device terminal, generate an unlock ciphertext in the form of an NDEF record and feedback it to the device terminal;

[0092] S213. When the preset target is other associated devices, generate an unlock ciphertext in the form of an unlock command set and transmit it to other associated devices;

[0093] S214. Based on the preset NFC unit tag reading and writing software, copy the NDEF record in the unlock ciphertext and generate an unlock command and send it to the SAM card module to be controlled;

[0094] S215. Receive the unlocking command through the NFC tag application and forward it to the SAM application through the SIO interface. The SAM application executes the verification of the SAM card unlocking ciphertext. When the verification passes, update the authorization information.

[0095] Embodiment 2

[0096] Figure 3 The present invention provides a flowchart of a SAM card control method for Embodiment 2. This embodiment is applicable to the control of SAM cards. This method can be executed by a SAM card control system, which includes: a SAM card module to be controlled, a device terminal, and an issuing bank background server. The SAM card module to be controlled includes a SAM card and an NFC unit.

[0097] As Figure 3 shown, the method includes:

[0098] S310. In response to meeting the relative distance condition through the device terminal, establish a near-field communication connection with the NFC unit in the SAM card module to be controlled, and send a read record command carrying the NFC tag application identifier to the SAM card module to be controlled.

[0099] S320. Through the SAM card module to be controlled, determine the NFC data exchange format NDEF file according to the read record command and feedback it to the device terminal.

[0100] S330. Through the device terminal, determine the operation type of the SAM card based on the NDEF file. When the operation type is the unlocking type, generate an unlocking request according to the NDEF file and send it to the issuing bank background server.

[0101] S340. When the issuing bank background server verifies that the unlocking request meets the unlocking conditions, generate an unlocking ciphertext in a preset manner and transmit it to a preset target. The preset target includes the device terminal or other associated devices.

[0102] S350. When the device terminal receives the unlocking ciphertext, generate an unlocking command based on the preset NFC unit tag reading and writing software and the unlocking ciphertext, and send it to the SAM card module to be controlled.

[0103] S360. Through the SAM card module to be controlled, update the authorization information of the SAM card according to the unlocking command.

[0104] The technical solution of the embodiment of the present invention provides a system including a SAM card module to be controlled, a device terminal, and an issuing bank's back-end server. The SAM card module to be controlled includes a SAM card and an NFC unit. The device terminal, in response to meeting the relative distance condition, establishes a near-field communication connection with the NFC unit in the SAM card module to be controlled, and sends a read record command carrying an NFC tag application identifier to the SAM card module to be controlled; the SAM card module to be controlled determines an NFC data exchange format NDEF file according to the read record command and feeds it back to the device terminal; the device terminal determines the operation type of the SAM card based on the NDEF file. When the operation type is an unlocking type, an unlocking request is generated according to the NDEF file and sent to the issuing bank's back-end server; when the issuing bank's back-end server verifies that the unlocking request meets the unlocking condition, an unlocking ciphertext is generated in a preset manner and transmitted to a preset target, and the preset target includes the device terminal or other associated devices; when the device terminal receives the unlocking ciphertext, an unlocking command is generated based on a preset NFC unit tag reading and writing software and the unlocking ciphertext and sent to the SAM card module to be controlled; the SAM card module to be controlled updates the authorization information of the SAM card according to the unlocking command. The NFC unit establishes information transmission with the device terminal, and the unlocking is performed in the form of the device terminal being online. There is no need to replace the SAM card with a new one, nor does the issuing bank need to unlock the SAM card offline, saving the time and cost of SAM card exception handling. The issuing bank does not need to send the corresponding unlocking tool software to the end user to unlock the SAM card, so risks are avoided and the workload of unlocking tool software version management is reduced.

[0105] The SAM card control system provided by the embodiment of the present invention can execute the SAM card control method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0106] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. No limitations are imposed herein.

[0107] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A SAM card control system, characterized in that, The system includes: a SAM card module to be controlled, a device terminal, and an issuing bank's back-end server. The SAM card module to be controlled includes a SAM card and an NFC unit; The device terminal is configured to establish a near-field communication connection with the NFC unit in the SAM card module to be controlled in response to meeting a relative distance condition, and send a read record command carrying an NFC tag application identifier to the SAM card module to be controlled; The SAM card module to be controlled is configured to determine an NFC data exchange format NDEF file according to the read record command and feedback it to the device terminal; The device terminal is configured to determine the operation type of the SAM card based on the NDEF file. When the operation type is an unlocking type, generate an unlocking request according to the NDEF file and send it to the issuing bank's back-end server; The issuing bank's back-end server is configured to generate an unlocking ciphertext in a preset manner and transmit it to a preset target when verifying that the unlocking request meets the unlocking conditions. The preset target includes the device terminal or other associated devices; The device terminal is configured to generate an unlocking command based on a preset NFC unit tag reading and writing software and the unlocking ciphertext and send it to the SAM card module to be controlled when receiving the unlocking ciphertext; The SAM card module to be controlled is configured to update the authorization information of the SAM card according to the unlocking command; Wherein, the device terminal is a device configured with NFC function and supporting the NFC reader mode; Wherein, the SAM card module to be controlled further includes a super input / output chip SIO interface. Correspondingly, determining the NFC data exchange format NDEF file according to the read record command and feedbacking it to the device terminal includes: The NFC unit receives the read record command through the NFC tag application and forwards it to the SAM card based on the SIO interface; The SAM card determines the current state through the SAM application. If the current state is unlocked, set the type field in the NDEF record to the first type, and place the SAM card usage information in the payload field of the NDEF record to obtain an organized NDEF file; If the current state is locked, set the type field in the NDEF record to the second type, calculate a decryption ciphertext based on the unique number of the SAM card, and place the decryption ciphertext, the uniform resource identifier of the issuing bank's back-end server, and the SAM card information in the payload field to obtain the NDEF file; Send the NDEF file to the NFC tag application through the SIO interface, and feedback the NDEF file to the device terminal through the NFC unit.

2. The system according to claim 1, wherein Determining the operation type of the SAM card based on the NDEF file includes: Extracting the type field in the NDEF file; When the type field is the first type, determine that the operation type of the SAM card is an information display type; When the type field is the second type, determine that the operation type of the SAM card is an unlocking type.

3. The system according to claim 2, wherein The device terminal further includes: When the operation type is the information display type, parse the NDEF file to obtain SAM card usage information and display the SAM card usage information.

4. The system according to claim 1, wherein The generating an unlocking request according to the NDEF file and sending the unlocking request to the issuing bank background server includes: Parse the NDEF file to obtain a decrypted ciphertext, SAM card information, and a uniform resource identifier of the issuing bank background server; Generate a decryption request according to the decrypted ciphertext and the SAM card information; Access the uniform resource identifier and send the decryption request to the issuing bank background server.

5. The system according to claim 1, wherein The generating an unlocking ciphertext in a preset manner and transmitting the unlocking ciphertext to a preset target includes: When the preset manner is to transmit to other associated devices, generate an unlocking ciphertext in the form of an unlocking command set and transmit the unlocking ciphertext to other associated devices; When the preset manner is to transmit to the device terminal, generate the unlocking ciphertext according to the response NDEF record and transmit the unlocking ciphertext to the device terminal.

6. The system according to claim 1, characterized in that, The system further includes: When the preset target is the other associated device, the other associated device generates an unlocking command in the form of an application protocol data unit (APDU) based on the unlocking command set in the unlocking ciphertext and sends the unlocking command to the SAM card module to be controlled item by item.

7. The system according to claim 1, characterized in that, The SAM card module to be controlled is further configured to: When receiving the read record command, generate a target response status word through the NFC tag application of the NFC unit and feedback the target response status word to the device terminal.

8. The system according to claim 7, wherein The device terminal is further configured to: Receive the response status word, and when the response status word is not the target response status word, disconnect the near-field communication connection.

9. A SAM card control method, characterized in that, The method is applied to the SAM card control system according to any one of claims 1-8. The system includes: a SAM card module to be controlled, a device terminal, and an issuing bank background server. The SAM card module to be controlled includes a SAM card and an NFC unit. The method includes: The device terminal responds to meet the relative distance condition, establishes a near-field communication connection with the NFC unit in the SAM card module to be controlled, and sends a read record command carrying an NFC tag application identifier to the SAM card module to be controlled; The SAM card module to be controlled determines an NFC data exchange format (NDEF) file according to the read record command and feeds back the NDEF file to the device terminal; The device terminal determines the operation type of the SAM card based on the NDEF file. When the operation type is the unlocking type, generate an unlocking request according to the NDEF file and send the unlocking request to the issuing bank background server; When the issuing bank background server verifies that the unlocking request meets the unlocking condition, generate an unlocking ciphertext in a preset manner and transmit the unlocking ciphertext to a preset target. The preset target includes the device terminal or other associated devices; When the device terminal receives the unlocking ciphertext, generate an unlocking command based on a preset NFC unit tag reading and writing software and the unlocking ciphertext and send the unlocking command to the SAM card module to be controlled; The to-be-controlled SAM card module updates the authorization information of the SAM card according to the unlocking command; wherein, the device terminal is a device configured with NFC function and supporting NFC reader mode; wherein, the to-be-controlled SAM card module further includes a Super Input / Output (SIO) chip interface. Correspondingly, determining the NFC Data Exchange Format (NDEF) file according to the read record command and feeding it back to the device terminal includes: receiving the read record command through the NFC unit via the NFC tag application and forwarding it to the SAM card based on the SIO interface; determining the current state by the SAM card through the SAM application. If the current state is unlocked, setting the type field in the NDEF record to the first type, and placing the SAM card usage information in the payload field of the NDEF record to obtain the organized NDEF file; if the current state is locked, setting the type field in the NDEF record to the second type, calculating the decrypted ciphertext based on the unique number of the SAM card, and placing the decrypted ciphertext, the Uniform Resource Identifier (URI) of the issuing bank's back-end server, and the SAM card information in the payload field to obtain the NDEF file; sending the NDEF file to the NFC tag application through the SIO interface, and feeding back the NDEF file to the device terminal through the NFC unit.

Citation Information

Patent Citations

  • Smart card unlocking

    CN115485709A