Method, system and apparatus for dual authentication of canned chip data
By using a double-verification method for canned chip data, utilizing the encryption algorithm of card number, random number and RSA public key, combined with two-way HTTPS authentication and physical encryption machine, the problems of inaccurate chip data binding and insufficient production line control are solved, achieving one-to-one secure data writing and control, and reducing the risk of chip leakage.
Patent Information
- Application Number
- CN202411737270.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-11-29
AI Technical Summary
In the existing technology, when chip data is initialized, the binding relationship between data and chip cannot be accurately controlled, which poses the risk of data being canned into multiple chips, and the risk of chip leakage due to insufficient production line control capabilities.
A double verification method is adopted for canned chip data. The first round of data filling is performed by assigning card numbers and random numbers. Data is encrypted using the MAC3 algorithm and RSA public key. The secret key is generated by combining two-way HTTPS authentication and a physical encryption machine to ensure data integrity and one-to-one management and control.
Double verification of chip data is achieved to ensure that data is only written to one chip, reducing the risks brought by irregular operations and improving the security and control capabilities of data transmission.
Smart Images

Figure CN119671373B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of computers, and in particular to a method, system and device for double-verification canned chip data. BACKGROUND
[0002] In the prior art, after the chip production is completed in the factory, the chip data is initialized directly according to the pre-generated data canning. However, the data and chip binding relationship cannot be accurately controlled, which may bring the risk of one data canning to multiple chips due to irregular operation. Or through a specific tool that can connect the server to request to generate data and write into the chip after the chip production is completed in the factory. However, if the management and control ability of the production line is not strong, multiple chips may be produced on the production line, resulting in chip leakage. SUMMARY
[0003] Therefore, the purpose of the present application is to provide a method, system and device for double-verification canned chip data to solve at least one technical problem in the prior art.
[0004] According to a first aspect of an embodiment of the present application, a method for double-verification canned chip data is provided, the method comprising:
[0005] issuing a batch task of creating a door card and making a card;
[0006] receiving the issued batch task of creating a door card and making a card, assigning a card number to the issued batch task of creating a door card and making a card, and generating a random number; wherein the card number and the random number correspond one by one;
[0007] using the card number, the random number, and a preset card public key, performing first round data filling through a preset MAC3 algorithm to obtain a processing result of the first round data filling;
[0008] using the processing result of the first round data filling, obtaining a processing result of second round data filling through a preset second processing rule.
[0009] Further, before the receiving the issued batch task of creating a door card and making a card, assigning a card number to the issued batch task of creating a door card and making a card, and generating a random number, and using the card number, the random number, and a preset card public key, performing first round data filling through a preset MAC3 algorithm to obtain a processing result of the first round data filling, it further comprises:
[0010] receiving a first data file address issued by a preset card making system, receiving preset card making data, and returning a response result; wherein the preset card making data includes a data file carrying a card number, a random number, and encrypted through a specified algorithm;
[0011] The first round of personalization of the card is performed by using the preset card data, and a card public key is generated.
[0012] Further, the first round of data filling is performed by using the card number, the random number, and the preset card public key through a preset MAC3 algorithm to obtain a processing result of the first round of data filling, including:
[0013] The card number, the random number, and the preset card public key are initialized.
[0014] The initialization result of the card number, the random number, and the preset card public key is used to generate verification MAC data.
[0015] The verification MAC data is encrypted by using a preset algorithm to obtain a processing result of one round of data filling.
[0016] Further, the processing result of the first round of data filling is used to obtain a processing result of the second round of data filling through a preset second processing rule, including:
[0017] The first round of data filling processing result is parsed by using the random number corresponding to the card number, and a card certificate is issued according to the preset card public key.
[0018] The result of issuing the card certificate by using the preset card public key is assembled into a preset form of data and uploaded to a preset storage server.
[0019] Based on the result of uploading the assembled preset form of data to the preset storage server, the address of the data file is sent to a preset card vendor.
[0020] The preset card vendor receives the address of the data file, completes the second personalization, and returns a response result.
[0021] Further, the first round of data filling processing result is parsed by using the random number corresponding to the card number, and a card certificate is issued according to the preset card public key, including:
[0022] The first round of data filling processing result is parsed by using a preset MAC3 algorithm and a preset card public key to obtain a second processing result.
[0023] The request times of the card number in the second processing result are obtained, and if the request times of the card number do not exceed a preset value, the issuance is agreed.
[0024] Otherwise, if the request times of the card number exceed the preset value, the issuance is refused.
[0025] Further, before the result of issuing the card certificate by using the preset card public key is assembled into a preset form of data and uploaded to a preset storage server, the method further comprises:
[0026] checking whether the card number pre-stored in the chip exists in the result of issuing the card certificate by using the preset card public key;
[0027] if the card number pre-stored in the chip exists, writing is successful;
[0028] otherwise, writing is failed.
[0029] Further, the method further comprises:
[0030] the server uses two-way HTTPS authentication for data transmission.
[0031] Further, the method further comprises:
[0032] the secret key is generated by a physical encryption machine.
[0033] According to a second aspect of the embodiments of the present application, a system for double-verification canned chip data is provided, and the system comprises:
[0034] an acquisition module configured to issue a batch task of creating a door card;
[0035] a first processing module configured to receive the batch task of creating the door card, assign a card number to the batch task of creating the door card, and generate a random number; wherein the card number and the random number are in one-to-one correspondence;
[0036] a second processing module configured to use the card number, the random number, and a preset card public key to perform first round data filling by using a preset MAC3 algorithm, and obtain a processing result of the first round data filling;
[0037] a third processing module configured to use the processing result of the first round data filling to obtain a processing result of second round data filling by using a preset second processing rule.
[0038] According to a third aspect of the embodiments of the present application, an equipment for double-verification canned chip data is provided, and the equipment comprises:
[0039] a memory having an executable program stored thereon;
[0040] a processor configured to execute the executable program in the memory to implement the steps of any one of the above-mentioned methods.
[0041] The technical scheme provided by the embodiment of the present application can include the following beneficial effects:
[0042] It can be understood that the technical scheme provided by the present application comprises the following steps: issuing a batch task of creating a door card; then, receiving the batch task of creating the door card, assigning a card number to the batch task of creating the door card, and generating a random number; the card number and the random number correspond to each other; using the card number, the random number, and a preset card public key, a first round of data filling is performed through a preset MAC3 algorithm to obtain a processing result of the first round of data filling; finally, using the processing result of the first round of data filling, a second round of data filling is performed through a preset second processing rule to obtain a processing result of the second round of data filling. It can be understood that the technical scheme provided by the present application adopts twice filling, the first filling is pre-allocated card number and random number, the factory needs to write the card number and the random number into the chip, the chip generates a RSA public-private key pair, and the RSA public key, the card number, and the random number are used to calculate the MAC3, this process is completed in the chip, and the result is directly returned, which is difficult to change manually; when the second round of data is applied, the random number signed with the allocated card number is obtained, the MAC3 is calculated by using the RSA public key, and the request number of the card number is recorded, if the card number has been signed, the signing is refused, so that the data integrity check and the factory control are realized; when the second filling is checked, the filling data returned is checked, if the card number is not pre-stored in the chip, the filling fails, the data one-to-one control is strengthened, and the risk of filling one data to multiple chips caused by irregular operation is solved.
[0043] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS
[0044] The accompanying drawings, which are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present application and, together with the specification, serve to explain the principles of the present application.
[0045] Figure 1 is a step schematic diagram of a method for filling chip data based on double verification according to an exemplary embodiment;
[0046] Figure 2 is an implementation flow schematic diagram of a method for filling chip data based on double verification according to an exemplary embodiment;
[0047] Figure 3 is a system composition schematic diagram of filling chip data based on double verification according to an exemplary embodiment;
[0048] Figure 4is a schematic diagram of a device for double-verification canned chip data according to an exemplary embodiment. DETAILED DESCRIPTION
[0049] The exemplary embodiments will be described in detail herein with reference to the attached drawings. In the following description, like reference numerals refer to like elements, unless the context clearly dictates otherwise. The following description is not meant to limit the application to all of the embodiments described herein. Rather, the following description is meant to provide examples of apparatus and methods consistent with the application as detailed in the appended claims.
[0050] Embodiment One
[0051] Referring to Figure 1 , Figure 1 is a schematic diagram of steps of a method for double-verification canned chip data according to an exemplary embodiment, the method comprising:
[0052] S1. issuing a batch task of creating door cards for card making;
[0053] S2. receiving the issued batch task of creating door cards for card making, assigning a card number to the issued batch task of creating door cards for card making, and generating a random number; wherein the card number and the random number correspond to each other one by one;
[0054] S3. using the card number, the random number, and a preset card public key, performing a first round of data filling through a preset MAC3 algorithm to obtain a processing result of the first round of data filling;
[0055] S4. using the processing result of the first round of data filling, obtaining a processing result of a second round of data filling through a preset second processing rule.
[0056] In specific implementation, as steps S1-S2 and Figure 2 The card making system assigns a card number and generates a random number according to the issued batch task of creating door cards for card making.
[0057] Then, the card number and the corresponding random number are written into a data file, the data file is generated after the file is encrypted through a preset AES encryption algorithm, and the address of the first data file is sent to a preset card vendor.
[0058] After receiving the card making data, the card vendor responds to the preset card making system, and uses the received card making data to complete the first round of personalization of the card, and generates a card public key.
[0059] It should be noted that the first round of personalization refers to writing the card number and the random number into the card to generate the card public key & MAC3.
[0060] It should be noted that, in the process of data transmission, 1. The server uses two-way HTTPS authentication, and non-authentication cannot access the business. 2. The canned file is encrypted by AES, and the key is generated by a physical encryption machine to ensure true randomness. The file encryption key is encrypted using the RSA algorithm, and the RSA public and private keys are encrypted offline using GPB. Multiple security measures make canned data more secure.
[0061] Further, in specific implementation, as described in step S3, the card number, random number, and preset card public key are used to perform first-round data filling by a preset MAC3 algorithm to obtain a first-round data filling processing result, including:
[0062] Initialize the card number, random number, and preset card public key;
[0063] Use the result of initializing the card number, random number, and preset card public key to generate a mac data;
[0064] Encrypt the mac data using a preset algorithm to obtain a one-round data filling processing result.
[0065] In specific implementation, the mac3 algorithm is used to check the card merchant data to prevent data tampering.
[0066] It should be noted that the card public key refers to the RSA public key, which can be directly generated using the card applet. The mac3 algorithm is implemented as follows
[0067] / **
[0068] *Algorithm implementation idea as follows
[0069] *1. Initialize data:
[0070] *Initialization vector (8 bytes) iv: byte[] VECT_INIT = {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00};
[0071] *8-byte key key8: The first 8 bytes of challenge;
[0072] *24-byte key key24: challenge is 16 bytes, divided into partA and partB every 8 bytes, and the result is challenge+partA;
[0073] *2. Generate mac data (integer multiple of 8 in length) data: Take the first 149 bytes (including: modulus length 0x90 + public key modulus 144 bytes + exponent length 0x03 + public key exponent 3 bytes) in the cardData in each card number data in the application certificate signature + padding (0x800000), a total of 152 bytes, 19 data blocks per 8 bytes.
[0074] *3. Calculate mac in two steps (the data passed in is the data generated in the second step):
[0075] *a. Generate initialization vector: use DES / CBC / NoPadd i ng algorithm with key8 as the key to encrypt data data, and the encryption result of each 8-byte data block is used as the initialization vector for the next encryption, until the 144th byte of data (i.e. the 18th data block, the last 8-byte block does not participate in the calculation of iv), and the final generated result is used as the new iv.
[0076] *b. Use key24 as the key, and the iv in a as the vector, and use DESede / CBC / NoPadd i ng algorithm to encrypt the last 8 bytes of data.
[0077] In a specific implementation, the processing result of the first round of data filling is used to obtain a processing result of a second round of data filling through a preset second processing rule, including:
[0078] The processing result of the first round of data filling is parsed using the random number corresponding to the card number, and a card certificate is issued according to the preset card public key;
[0079] The result of issuing the card certificate using the preset card public key is assembled into a preset form of data and uploaded to a preset storage server;
[0080] Based on the result of uploading the preset form of data assembled to the preset storage server, the address of the data file is sent to a preset card vendor;
[0081] The preset card vendor receives the address of the data file, completes the second personalization, and returns a response result.
[0082] It should be noted that the second personalization refers to the process of applying for a card certificate according to the generated RSA public key and writing the certificate into the card.
[0083] Further, the processing result of the first round of data filling is parsed using the random number corresponding to the card number, and a card certificate is issued according to the preset card public key, including:
[0084] The processing result of the first round of data filling is parsed by using the preset MAC3 algorithm and the preset card public key to obtain a second processing result;
[0085] The request times of the card number in the second processing result are obtained, and if the request times of the card number do not exceed a preset value, the card certificate is agreed to be issued;
[0086] Otherwise, if the request times of the card number exceed the preset value, the card certificate is refused to be issued.
[0087] Further, before the result of issuing the card certificate by using the preset card public key is assembled into data in a preset form and uploaded to a preset storage server, the method further comprises:
[0088] Verifying whether the card number pre-stored in the chip exists in the result of issuing the card certificate by using the preset card public key;
[0089] If the card number pre-stored in the chip exists, the writing is successful;
[0090] Otherwise, the writing fails.
[0091] In one embodiment, by the scheme in the application, the card number is pre-allocated in the first step, and a true random value is generated, the one-to-one correspondence between the card number and the random value is ensured, the card number and the random value are sent to the card vendor, the card vendor completes the first round of filling, the number of orders in each batch can be controlled, only the rated number of data can be applied, if a repeated card number is applied to issue data, the abnormal process is directly entered; the card number and the random value sent in the first round are embedded in the final data, and the verification is performed when the second round of data is filled in the production line after the data is obtained, so that it is ensured that one data can be used in only one chip.
[0092] The technical scheme provided by the application adopts twice filling, the card number and the random number pre-allocated in the first filling are written into the chip by the factory, the chip generates a RSA public-private key pair, the RSA public key, the card number and the random number are used to calculate MAC3, the process is completed in the chip, and the result is directly returned, which is difficult to change manually; when the second round of data is applied, the random number issued with the allocated card number is obtained, MAC3 is calculated by using the RSA public key, and the request times of the card number are recorded, if the card number has been issued, the card certificate is refused to be issued, so that the data integrity verification and the factory control are realized; when the second filling is verified, the filling data returned is verified, if the card number pre-stored in the chip does not exist, the writing fails, the one-to-one control of the data is strengthened, and the risk that one data is filled into multiple chips due to irregular operation is solved.
[0093] Referring to Figure 3 , Figure 3 is a system composition schematic diagram for double-verification canned chip data according to an exemplary embodiment, and the system comprises:
[0094] The acquisition module 30 is configured to issue a batch task of creating a door card.
[0095] The first processing module 31 is configured to receive the batch task of creating a door card, assign a card number to the batch task of creating a door card, and generate a random number, wherein the card number and the random number are in one-to-one correspondence.
[0096] The second processing module 32 is configured to perform first round data filling by using the card number, the random number, and a preset card public key through a preset MAC3 algorithm to obtain a processing result of the first round data filling.
[0097] The third processing module 33 is configured to obtain a processing result of second round data filling by using the processing result of the first round data filling through a preset second processing rule.
[0098] Referring to Figure 4 , Figure 4 is a device composition schematic diagram for double-verification canned chip data according to an exemplary embodiment, and the device comprises:
[0099] The memory 41 has a stored executable program.
[0100] The processor 42 is configured to execute the executable program in the memory 41 to implement the steps of the method in any one of the above embodiments.
[0101] It can be understood that the same or similar parts in the above embodiments can be mutually referred to, and the content not described in detail in some embodiments can refer to the same or similar content in other embodiments.
[0102] It should be noted that, in the description of the present application, the terms "first", "second", etc. are only for the purpose of description, and cannot be understood as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise specified, the meaning of "a plurality of" is at least two.
[0103] Any procedural or methodological descriptions in flow charts or otherwise described herein can be understood to represent modules, segments, or portions of code that include executable instructions for implementing the specific logical functions or steps, and the scope of preferred embodiments of the present application includes additional implementations in which the functions are performed in a different order, including substantially simultaneously, or in reverse order, as will be understood by those skilled in the art to which embodiments of the present application pertain.
[0104] It should be understood that portions of the present application can be implemented in hardware, software, firmware, or combinations thereof. In the above-described embodiments, multiple steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, and as in another embodiment, implementation can be in any one or a combination of the following technologies, which are all well known in the art: discrete logic circuitry having logic gates for implementing logic functions upon an application of data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and the like.
[0105] Those skilled in the art can understand that all or part of the steps carried out by the above-described embodiments can be instructed by a program to relevant hardware, and the program can be stored in a computer readable storage medium, and when executed, includes one or a combination of steps of the method embodiments.
[0106] In addition, each functional unit in each embodiment of the present application can be integrated in one processing module, or each unit can be physically present separately, or two or more units can be integrated in one module. The above-mentioned integrated module can be realized in the form of hardware or in the form of a software functional module. The integrated module, if realized in the form of a software functional module and sold or used as an independent product, can also be stored in a computer readable storage medium.
[0107] The above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disk, etc.
[0108] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0109] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary and are not to be construed as limiting the present application, and that variations, modifications, substitutions and changes can be made by those skilled in the art without departing from the scope of the present application.
Claims
1. A method based on double verification of canned chip data, characterized in that: The method comprises: Issue batch tasks for creating door card production; Receive the batch task of creating door card production, assign card numbers to the batch task of creating door card production, and generate random numbers; wherein the card numbers correspond to the random numbers one by one; Using the card number, random number, and preset card public key, the preset MAC3 algorithm is used to Perform the first round of data filling and obtain the processing results of the first round of data filling; Using the processing results of the first round of data filling, the processing results of the second round of data filling are obtained through the preset second processing rules; The processing result of the first round of data filling is used to obtain the processing result of the second round of data filling through a preset second processing rule, including: Utilizing the random number corresponding to the card number, parsing the processing result of the first round of data filling, and issuing a card certificate according to the preset card public key; The result of issuing the card certificate using the preset card public key is assembled into data in a preset format and uploaded to a preset storage server; Based on the result of uploading the assembled data in the preset format to the preset storage server, sending the address of the data file to the preset card merchant; The preset card merchant receives the address of the data file, completes the second personalization and returns a response result; The second personalization refers to the process of applying for a card certificate based on the generated RSA public key and writing the certificate into the card.
2. The method according to claim 1, characterized in that The step of receiving the batch task of creating door card production, assigning a card number to the batch task of creating door card production, and generating a random number, performing a first round of data filling using a preset MAC3 algorithm using the card number, the random number, and a preset card public key, and obtaining a processing result of the first round of data filling, further comprising: Receive the first data file address issued by the preset card making system, receive the preset card making data, and return a response result; wherein the preset card making data includes: a data file carrying the card number and random number and encrypted by a specified algorithm; Using the preset card making data, perform the first round of card personalization to generate a card public key; Among them, the first round of personalization refers to writing the random card number into the card to generate the card public key & MAC3.
3. The method according to claim 1, characterized in that The card number, random number, and preset card public key are used to perform a first round of data filling through a preset MAC3 algorithm to obtain a processing result of the first round of data filling, including: Initialize the card number, random number, and preset card public key; Generate MAC verification data using the result of initializing the card number, random number, and preset card public key; The MAC verification data is encrypted using a preset algorithm to obtain a processing result of a round of data filling.
4. The method according to claim 1, wherein The method of analyzing the processing result of the first round of data filling by using the random number corresponding to the card number and issuing a card certificate according to the preset card public key includes: Analyze the processing result of the first round of data filling using a preset MAC3 algorithm and a preset card public key to obtain a second processing result; Obtaining the number of requests for the card number in the second processing result, and approving issuance if the number of requests for the card number does not exceed a preset value; Otherwise, if the number of requests for the card number exceeds a preset value, the card will be refused to be issued.
5. The method according to claim 1, wherein After parsing the processing result of the first round of data filling using the random number corresponding to the card number, and issuing a card certificate according to the preset card public key, before assembling the result of the card certificate issued by the preset card public key into data in a preset format and uploading it to a preset storage server, the method further includes: Verify whether the card number pre-stored in the chip is present in the result of issuing the card certificate using the preset card public key; If there is a card number pre-stored in the chip, the write is successful; Otherwise, the write fails.
6. The method according to claim 1, characterized in that The method further comprises: The server uses two-way HTTPS authentication for data transmission.
7. The method according to claim 1, characterized in that The method further comprises: The secret key is generated by a physical encryption machine.
8. A system based on double verification of canned chip data, characterized in that: The method for double-verifying canned chip data according to any one of claims 1 to 7, wherein the system comprises: The acquisition module is used to issue batch tasks for creating door card production; A first processing module is configured to receive the batch task of issuing door card production, assign card numbers to the batch task of issuing door card production, and generate random numbers; wherein the card numbers correspond to the random numbers one by one; A second processing module is configured to perform a first round of data filling using a preset MAC3 algorithm using the card number, random number, and preset card public key, and obtain a processing result of the first round of data filling; The third processing module is used to obtain the processing result of the second round of data filling by using the processing result of the first round of data filling through a preset second processing rule.
9. A device based on double verification of canned chip data, characterized in that, The device comprises: a memory having an executable program stored therein; A processor, configured to execute the executable program in the memory to implement the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Business certificate acquisition method and device and electronic equipment
CN114978751A
Key generation method and key filling method
CN116760537A