Smart card-based financial transaction method, apparatus, device, and medium

By performing function screening, offline authentication and identity acquisition on smart cards through smart terminals, combined with dynamic application ciphertext and behavior analysis, the problem of low transaction efficiency of smart cards in offline network environments is solved, and efficient and secure financial transactions are achieved.

CN119919137BActive Publication Date: 2025-10-10CLP FINANCIAL EQUIP SYST (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510376665.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-10-10
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

Existing smart card transaction methods are inefficient in offline network environments, and identity information can be easily forged, resulting in inefficient financial transactions.

Method used

Through intelligent terminals, smart cards are screened for functions, offline authentication and identity acquisition are performed, and dynamic application ciphertext and behavior analysis are used to ensure the security and legitimacy of transactions.

Benefits of technology

It improves the efficiency and security of financial transactions, prevents card counterfeiting, supports transactions in offline environments, and ensures the authenticity and integrity of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119919137B_ABST
    Figure CN119919137B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of finance, and relates to a financial transaction method and device based on an intelligent card, computer equipment and a storage medium, which comprises the following steps: an intelligent terminal performs function screening on an intelligent card to obtain response function data; the intelligent terminal performs offline authentication on the intelligent card according to the response function data to obtain dynamic application ciphertext; the intelligent terminal performs identity acquisition on the intelligent card according to the dynamic application ciphertext to obtain response identity information; the intelligent terminal performs behavior analysis on the intelligent card according to the response identity information to obtain transaction behavior risk; and the intelligent terminal performs authorized transaction on the intelligent card according to the transaction behavior risk to obtain a transaction result. The application can improve the efficiency of financial transaction.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of finance, in particular to a financial transaction method and device based on a smart card, equipment and medium. BACKGROUND

[0002] A smart card is a portable card embedded with a microprocessor or a storage chip, usually similar in appearance to a common credit card, but with more powerful functions and security. The smart card has a built-in security chip and encryption algorithm, which can protect transaction data and prevent theft or forgery, so it is widely used in the field of financial transactions.

[0003] The existing transaction method of the smart card is mostly based on simple data matching, that is, identity information is extracted from the smart card, and the smart terminal is connected to verify and transact. In actual application, the transaction method based on simple data matching has low efficiency in unstable network or offline environment, and the identity information is manually modified to cause software error matching. Moreover, after the iterative version, the package name matching program needs to be modified every time, which may cause low efficiency of single-chip microcomputer program upgrade verification, and further low efficiency of financial transaction. SUMMARY

[0004] The present application provides an artificial intelligence-based financial transaction method and device based on a smart card, a computer device and a medium to solve the technical problems that the existing smart card financial transaction method cannot be used in offline network environment, the transaction matching efficiency is low, and the program version matching efficiency is low, resulting in low financial transaction efficiency.

[0005] In a first aspect, a financial transaction method based on a smart card is provided, comprising:

[0006] The smart terminal performs function screening on the smart card to obtain response function data;

[0007] The smart terminal performs offline authentication on the smart card according to the response function data to obtain dynamic application ciphertext;

[0008] The smart terminal obtains identity information from the smart card according to the dynamic application ciphertext to obtain response identity information;

[0009] The smart terminal performs behavior analysis on the smart card according to the response identity information to obtain transaction behavior risk;

[0010] The smart terminal performs authorized transaction on the smart card according to the transaction behavior risk to obtain transaction result.

[0011] In a second aspect, a financial transaction device based on a smart card is provided, comprising a smart card and a smart terminal:

[0012] The smart card is configured to: send response function data to the smart terminal; send response identity information to the smart terminal; perform behavior analysis to obtain transaction behavior risks; perform authorized transactions to obtain transaction results;

[0013] The smart terminal is configured to: perform function screening on the smart card to obtain response data; perform offline authentication on the smart card based on the response function data to obtain dynamic application ciphertext; obtain the identity of the smart card based on the dynamic application ciphertext to obtain response identity information; perform behavior analysis on the smart card based on the response identity information to obtain transaction behavior risk; and authorize the transaction on the smart card based on the transaction behavior risk to obtain a transaction result.

[0014] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned smart card-based financial transaction method when executing the computer program.

[0015] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned smart card-based financial transaction method are implemented.

[0016] In the scheme implemented by the above-mentioned smart card-based financial transaction method, device, computer equipment and storage medium, the smart card can be functionally screened through the smart terminal to obtain response function data, and the application data required for the financial transaction can be extracted from the smart card, thereby improving the efficiency of the financial transaction. By performing offline authentication on the smart card based on the response function data, the random number and dynamic key can be combined to ensure that the ciphertext is unique and cannot be forged, thereby enhancing the transaction security. Through ciphertext verification, it can be ensured that the transaction is indeed initiated by a legitimate card, preventing card forgery, and supporting offline environments, thereby improving transaction efficiency. By obtaining the identity of the smart card based on the dynamic application ciphertext, the identity of the cardholder of the smart card can be determined, thereby verifying the identity of the cardholder and the legitimacy of the transaction, and improving the security of the transaction.

[0017] By analyzing the smart card's behavior based on the response identity information to determine transaction behavior risk, transaction risk detection can be performed based on the security of the smart card and smart terminal, improving the security and efficiency of financial transactions. By authorizing the smart card based on the transaction behavior risk and determining the transaction result, the authenticity and integrity of the transaction can be ensured, improving transaction security and efficiency. Therefore, the smart card-based financial transaction method, apparatus, computer device, and storage medium proposed in the present invention can address the issue of low product testing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0019] Figure 1 1 is a flow chart of a smart card-based financial transaction method according to an embodiment of the present invention;

[0020] Figure 2 yes Figure 1 A schematic flow chart of a specific implementation of step S2;

[0021] Figure 3 yes Figure 1 A schematic flow chart of a specific implementation of step S3;

[0022] Figure 4 is a schematic structural diagram of a smart card-based financial transaction device in one embodiment of the present invention;

[0023] Figure 5 is a structural diagram of a computer device in one embodiment of the present invention; DETAILED DESCRIPTION

[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0025] See also Figure 1 As shown, Figure 1 A flowchart of a smart card-based financial transaction method provided in an embodiment of the present invention includes the following steps:

[0026] S1. The smart terminal performs function screening on the smart card and obtains response function data.

[0027] Specifically, the smart terminal refers to a device terminal used to complete operations such as payment, identity authentication, and data processing, and is responsible for interacting with a smart card. The smart terminal can be a point of sale (POS) terminal, an automated teller machine (ATM) or a mobile payment terminal.

[0028] Specifically, the smart card is a portable card embedded with a microprocessor or memory chip. It usually looks similar to an ordinary credit card, but has more powerful functions and security. The smart card has a built-in security chip and encryption algorithm to protect transaction data and prevent it from being stolen or forged. It also supports multiple authentication mechanisms, such as dynamic key generation, offline authentication (DDA, CDA), etc., to ensure the legitimacy of transactions.

[0029] In an embodiment of the present invention, the smart terminal performs function screening on the smart card to obtain response function data, including:

[0030] The smart terminal sends an application display command to the smart card;

[0031] The smart card generates an application list according to the application display command;

[0032] The smart terminal performs application screening on the application list to obtain a target application name;

[0033] The smart terminal generates an application read command according to the target application name;

[0034] The smart terminal reads data from the smart card according to the application read command to obtain response function data.

[0035] In detail, the application display command refers to a command for controlling the smart card to display a list of all functional applications stored inside the smart card, wherein the application list stores the names of all functional applications in the smart card.

[0036] Specifically, the functional application refers to the corresponding application name of the function that the smart card can realize, such as an electronic wallet application that supports small payments and fast offline transactions, a debit card application that supports core bank card functions such as balance inquiry, transfer, withdrawal and online payment, and an identity authentication application that stores cardholder identity information and supports identity authentication through PIN code or biometrics.

[0037] In detail, the application screening can be performed using a keyword matching method or a cosine similarity algorithm matching method, that is, the application names in the application list that are close to the keywords of the functions that the smart terminal wants to implement are screened out as target application names.

[0038] Specifically, an application read command, such as a SELECT command or a READ RECORD command, may be generated using an Application Protocol Data Unit (APDU) command format.

[0039] In detail, the data reading refers to reading data related to the target application name stored in the smart card as response function data, such as usage records of the target application name and previously recorded application cache data.

[0040] In the embodiment of the present invention, the smart terminal performs function screening on the smart card to obtain response function data, and can extract application data required for financial transactions from the smart card, thereby improving the efficiency of financial transactions.

[0041] S2. The smart terminal performs offline authentication on the smart card according to the response function data to obtain a dynamic application ciphertext.

[0042] In detail, the offline authentication is a security mechanism in smart card financial transactions, which is used to verify whether the smart card is a real and non-forged card without being connected to the Internet. The offline authentication mainly ensures the authenticity of the smart card through the digital signature of the smart card and the verification logic of the terminal to prevent the use of forged smart cards.

[0043] In the embodiment of the present invention, referring to Figure 2 As shown, the smart terminal performs offline authentication on the smart card according to the response function data to obtain a dynamic application ciphertext, including:

[0044] S21. The smart terminal initializes a transaction application according to the response function data;

[0045] S22. The smart terminal extracts transaction parameter items from the transaction application;

[0046] S23. The smart terminal generates a dynamic random ciphertext according to the transaction parameter item;

[0047] S24. The smart card generates a dynamic application ciphertext according to the dynamic random ciphertext, and sends the dynamic application ciphertext to the smart terminal.

[0048] In detail, the transaction application refers to the application corresponding to the target application name for subsequent financial transactions, and initializing the transaction application based on the response data refers to extracting the application function from the response function data, and screening out the corresponding application template from the preset application template library based on the application function to form a transaction application.

[0049] Specifically, the application template library includes multiple component templates that can implement various application functions, such as limiting the transaction amount, whether to perform personal identification number (PIN) verification, and setting the maximum number of attempts after a transaction fails.

[0050] In detail, the transaction parameter items refer to the types of transaction data required for financial transactions, such as transaction amount, transaction mode, and currency type.

[0051] Specifically, the smart terminal generates a dynamic random ciphertext according to the transaction parameter item, including:

[0052] The smart terminal initializes a dynamic random check code;

[0053] The smart terminal generates a dynamic random ciphertext according to the transaction parameter item and the dynamic random check code.

[0054] In detail, a dynamic random check code can be initialized using a random number algorithm or a pseudo-random number algorithm. The dynamic random check code is a random number of a check code. Generating a dynamic random ciphertext based on the transaction parameter item and the dynamic random check code means splicing the dynamic random check code into the transaction parameter item to obtain the dynamic random ciphertext.

[0055] Specifically, the smart card generates a dynamic application ciphertext according to the dynamic random ciphertext, including:

[0056] The smart card extracts a dynamic random check code and a transaction parameter item from the dynamic random ciphertext;

[0057] The smart card performs parameter matching on the transaction parameter items to obtain smart card transaction parameters;

[0058] The smart card generates application dynamic data according to the smart card transaction parameters and the dynamic random check code;

[0059] The smart card encrypts the application dynamic data with a private key to obtain a dynamic application ciphertext.

[0060] In detail, the parameter matching refers to matching the application transaction data corresponding to the transaction parameter item from the storage data of the smart card as the smart card transaction data, and the application dynamic data is spliced ​​by the smart card transaction parameter and the dynamic random check code.

[0061] Specifically, the smart card performs private key encryption on the application dynamic data to obtain dynamic application ciphertext, including:

[0062] The smart card extracts the built-in private key;

[0063] The smart card generates round keys for the built-in private key to obtain a private key round key set;

[0064] The smart card groups the application dynamic data in plain text according to the private key round key set to obtain left-half dynamic data and right-half dynamic data;

[0065] The smart card selects private round keys from the private round key set one by one as target private round keys, and performs round encryption on the right half dynamic data using the target private round keys to obtain target encrypted dynamic data;

[0066] The smart card performs an XOR operation on the left half dynamic data using the target encrypted dynamic data to obtain target XOR dynamic data;

[0067] The smart card updates the left-half dynamic data using the right-half dynamic data, and updates the right-half dynamic data using the target XOR dynamic data, and returns to the step of the smart card selecting the private round keys in the private round key set one by one as the target private round key;

[0068] Until the target private round key is the last private round key in the private round key set, the smart card concatenates the left-half dynamic data and the right-half dynamic data corresponding to the target private round key into a dynamic application ciphertext.

[0069] In detail, the built-in private key is a private key built into the smart card, and the round key generation refers to iterative cyclic left shift, XOR operation and AND operation on the built-in private key, thereby obtaining a private key round key set consisting of multiple private key round keys, wherein the total number of the private key round key set can be 32, and the round encryption includes steps such as cyclic bitwise left shift, bitwise operation and bitwise XOR operation.

[0070] In an embodiment of the present invention, by performing offline authentication on the smart card based on the response function data, it is possible to combine random numbers and dynamic keys to ensure that the ciphertext is unique and cannot be forged, thereby enhancing transaction security. Moreover, through ciphertext verification, it is ensured that the transaction is indeed initiated by a legitimate card, preventing card forgery, and supporting offline environments, thereby improving transaction efficiency.

[0071] S3. The smart terminal obtains the identity of the smart card according to the dynamic application ciphertext to obtain response identity information.

[0072] In detail, the response identity information refers to the personal identification number (PIN) information in the smart card.

[0073] In the embodiment of the present invention, referring to Figure 3 As shown, the smart terminal obtains the identity of the smart card according to the dynamic application ciphertext and obtains response identity information, including:

[0074] S31. The intelligent terminal decrypts the dynamic application ciphertext to obtain a decrypted application ciphertext;

[0075] S32. The intelligent terminal performs a dynamic verification on the decrypted application ciphertext according to the dynamic random verification code to obtain a dynamic verification result;

[0076] S33, the smart terminal extracts smart card transaction parameters from the decrypted application ciphertext according to the dynamic verification result;

[0077] S34. The smart terminal sends an identity acquisition command to the smart card according to the dynamic verification result;

[0078] S35. The smart card matches the response identity information according to the identity acquisition command, and sends the response identity information to the smart terminal.

[0079] In detail, the ciphertext decryption refers to decrypting the dynamic application ciphertext using the decryption key of the smart terminal. The decryption algorithm of the ciphertext decryption is opposite to the algorithm of the private key encryption, that is, the smart terminal splits the dynamic application ciphertext into left-half dynamic data and right-half dynamic data, and the smart terminal selects the private key round key in the private key round key set one by one as the target private key round key, and the smart terminal uses the target private key round key to perform round decryption on the left-half dynamic data to obtain the target decrypted dynamic data; the smart terminal uses the target decrypted dynamic data to decrypt the left-half dynamic data. An exclusive-OR operation is performed on the right-half dynamic data to obtain secondary exclusive-OR dynamic data; the smart terminal updates the right-half dynamic data using the left-half dynamic data, and updates the left-half dynamic data using the secondary exclusive-OR dynamic data, and returns to the step of selecting the private round keys in the private round key set one by one as the target private round key by the smart terminal; until the target private round key is the last private round key in the private round key set, the smart terminal splices the left-half dynamic data and the right-half dynamic data corresponding to the target private round key into a dynamic application ciphertext.

[0080] In detail, the dynamic verification refers to determining whether the decrypted application ciphertext contains the dynamic random verification code. If so, the dynamic verification result is a successful verification; if not, the dynamic verification result is a failed verification, and the financial transaction is terminated.

[0081] Specifically, the smart terminal extracts the smart card transaction parameters from the decrypted application ciphertext according to the dynamic verification result, which means that when the dynamic verification result is successful, the data in the decrypted application ciphertext except the dynamic random verification code is used as the smart card transaction parameters.

[0082] In detail, the smart terminal sends an identity acquisition command to the smart card based on the dynamic verification result, which means that the smart terminal sends an identity acquisition command to the smart card when the dynamic verification result is successful. The identity acquisition command is a command for obtaining a PIN code, which can be a GET DATA command or a VERIFY command.

[0083] In the embodiment of the present invention, by acquiring the identity of the smart card according to the dynamic application ciphertext, the identity of the smart card holder can be determined, thereby verifying the identity of the card holder and the legitimacy of the transaction, thereby improving the security of the transaction.

[0084] S4. The smart terminal performs a behavior analysis on the smart card according to the response identity information to obtain a transaction behavior risk.

[0085] Specifically, the terminal behavior risk refers to the risk level of the smart terminal when conducting this financial transaction.

[0086] In an embodiment of the present invention, the smart terminal performs a behavior analysis on the smart card based on the response identity information to obtain a transaction behavior risk, including:

[0087] The intelligent terminal performs identity verification on the response identity information to obtain an identity verification result;

[0088] The intelligent terminal performs hardware integrity verification to obtain a hardware verification result;

[0089] The smart terminal generates a terminal behavior risk according to the identity verification result and the hardware verification result;

[0090] The smart card reads the transaction counter to obtain the number of transactions;

[0091] The smart card generates a card behavior risk according to the number of transactions and a preset transaction limit;

[0092] The smart terminal generates a transaction behavior risk according to the card behavior risk and the terminal behavior risk.

[0093] In detail, the identity verification refers to determining whether the response identity information matches the identity information in the database of the smart terminal. If so, the identity verification result is a successful verification; if not, the identity verification result is a failed verification.

[0094] Specifically, the hardware integrity check refers to obtaining a hardware list and determining whether the hardware list of the smart terminal is complete. If the hardware list is complete, the hardware check result is a successful check; if the hardware check result is incomplete, the hardware check result is a failed check.

[0095] In detail, the smart terminal generates the terminal behavior risk according to the identity verification result and the hardware verification result, which means that when the identity verification result and the hardware verification result are both verified successfully, the terminal behavior risk is no risk, otherwise, it is risky.

[0096] Specifically, the GET DATA command can be used to read the transaction counter. The number of transactions refers to the transaction data recorded in the transaction counter (ATC). The card behavior risk generated based on the number of transactions and the preset transaction limit means that when the number of transactions is less than or equal to the transaction limit, the card behavior risk is risk-free; when the number of transactions is greater than the transaction limit, the card behavior risk is risky.

[0097] In detail, generating the transaction behavior risk according to the card behavior risk and the terminal behavior risk means that when both the card behavior risk and the terminal behavior risk are risk-free, the transaction behavior risk is risk-free; otherwise, the transaction behavior risk is risky.

[0098] In the embodiment of the present invention, by performing behavior analysis on the smart card according to the response identity information, the transaction behavior risk is obtained, and the transaction risk detection can be implemented according to the security of the smart card and the smart terminal, thereby improving the security and efficiency of financial transactions.

[0099] S5. The smart terminal authorizes the smart card to perform a transaction based on the transaction behavior risk and obtains a transaction result.

[0100] Specifically, the transaction result refers to the transaction status and final output content, such as transaction identification information, transaction timestamp and other information.

[0101] In an embodiment of the present invention, the smart terminal authorizes the smart card for a transaction based on the transaction behavior risk to obtain a transaction result, including:

[0102] Determine whether the transaction risk is risk-free;

[0103] If not, the financial transaction is terminated, and the transaction result is a transaction failure;

[0104] If yes, the smart terminal matches the authorization response ciphertext and sends the authorization response ciphertext to the smart card;

[0105] The smart card decrypts the authorization corresponding ciphertext to obtain authorization response data;

[0106] The smart card determines whether the authorization response data matches the preset authorization data;

[0107] If not, the financial transaction is terminated, and the transaction result is a transaction failure;

[0108] If yes, the smart terminal generates an online transaction application based on the transaction application and the smart card transaction parameters;

[0109] The smart terminal performs an online transaction on the smart card according to the online transaction application to obtain a transaction result.

[0110] In detail, the Authorization Response Cryptogram (ARPC) is a dynamic cryptogram generated by the issuing bank and is sent to the smart terminal to respond to and verify the transaction request sent by the transaction terminal. The authorization data refers to the authorization response cryptogram stored in the smart card.

[0111] Specifically, the online transaction refers to transmitting transaction data with the online transaction application in the smart terminal according to the transaction script in the transaction card, thereby generating a transaction result.

[0112] In the embodiment of the present invention, by authorizing the smart card for a transaction based on the transaction behavior risk and obtaining a transaction result, the authenticity and integrity of the transaction can be ensured, thereby improving transaction security and efficiency.

[0113] It can be seen that in the above scheme, the smart card is functionally screened by the smart terminal to obtain response function data, and the application data required for financial transactions can be extracted from the smart card, thereby improving the efficiency of financial transactions. By performing offline authentication on the smart card based on the response function data, the random number and dynamic key can be combined to ensure that the ciphertext is unique and cannot be forged, thereby enhancing transaction security. Through ciphertext verification, it can be ensured that the transaction is indeed initiated by a legitimate card, preventing card forgery, and supporting offline environments, thereby improving transaction efficiency. By obtaining the identity of the smart card based on the dynamic application ciphertext, the identity of the cardholder of the smart card can be determined, thereby verifying the identity of the cardholder and the legitimacy of the transaction, and improving the security of the transaction.

[0114] By analyzing the smart card's behavior based on the response identity information to determine transaction behavior risk, transaction risk detection can be performed based on the security of the smart card and smart terminal, improving the security and efficiency of financial transactions. By authorizing the smart card based on the transaction behavior risk and determining the transaction result, the authenticity and integrity of the transaction can be ensured, improving transaction security and efficiency. Therefore, the smart card-based financial transaction method proposed in this invention can address the issue of low product testing efficiency.

[0115] It should be understood that the size of the serial number of each step in the above embodiments does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0116] In an embodiment, a smart card-based financial transaction device is provided, which corresponds to the smart card-based financial transaction method in the above embodiment one by one. As shown in the figure, the smart card-based financial transaction device includes a smart card 101 and a smart terminal 102: Figure 4

[0117] The smart card 101 is configured to: send response function data to the smart terminal; send response identity information to the smart terminal; perform behavior analysis to obtain transaction behavior risk; and perform authorized transaction to obtain transaction result;

[0118] The smart terminal 102 is configured to: perform function screening on the smart card to obtain response data; perform offline authentication on the smart card according to the response function data to obtain dynamic application ciphertext; perform identity acquisition on the smart card according to the dynamic application ciphertext to obtain response identity information; perform behavior analysis on the smart card according to the response identity information to obtain transaction behavior risk; and perform authorized transaction on the smart card according to the transaction behavior risk to obtain transaction result.

[0119] In an embodiment, when the smart terminal 102 performs function screening on the smart card to obtain response function data, it is used for:

[0120] sending an application display command to the smart card and obtaining an application list generated by the smart card in response to the application display command;

[0121] performing application screening on the application list to obtain a target application name;

[0122] generating an application reading command according to the target application name;

[0123] performing data reading on the smart card according to the application reading command to obtain response function data.

[0124] In an embodiment, when the smart terminal 102 performs offline authentication on the smart card according to the response function data to obtain dynamic application ciphertext, it is used for:

[0125] initializing a transaction application according to the response function data;

[0126] extracting a transaction parameter item from the transaction application;

[0127] generating a dynamic random ciphertext according to the transaction parameter item; ​

[0128] The dynamic random ciphertext is sent to the smart card, and the dynamic application ciphertext returned by the smart card according to the dynamic random ciphertext is obtained.

[0129] The specific definition of the smart card-based financial transaction device can be found in the definition of the smart card-based financial transaction method above and will not be repeated here. Each module in the smart card-based financial transaction device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each of these modules may be embedded in or independent of a processor within a computer device in hardware form, or may be stored in a computer device memory in software form, allowing the processor to call and execute the corresponding operations of each module.

[0130] In one embodiment, a computer device is provided, wherein the internal structure of the computer device can be as follows: Figure 5 As shown. The computer device includes a processor, memory, a network interface, a display screen, and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements the functions or steps of a smart card-based financial transaction method.

[0131] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0132] The smart terminal performs function screening on the smart card and obtains response function data;

[0133] The smart terminal performs offline authentication on the smart card according to the response function data to obtain a dynamic application ciphertext;

[0134] The smart terminal acquires the identity of the smart card according to the dynamic application ciphertext to obtain response identity information;

[0135] The smart terminal performs a behavior analysis on the smart card according to the response identity information to obtain a transaction behavior risk;

[0136] The smart terminal authorizes the transaction on the smart card according to the transaction behavior risk to obtain a transaction result.

[0137] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0138] The smart terminal performs function screening on the smart card and obtains response function data;

[0139] The smart terminal performs offline authentication on the smart card according to the response function data to obtain a dynamic application ciphertext;

[0140] The smart terminal acquires the identity of the smart card according to the dynamic application ciphertext to obtain response identity information;

[0141] The smart terminal performs a behavior analysis on the smart card according to the response identity information to obtain a transaction behavior risk;

[0142] The smart terminal authorizes the transaction on the smart card according to the transaction behavior risk to obtain a transaction result.

[0143] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can refer to the relevant description in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0144] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0145] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0146] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some of the technical features therein with equivalents. However, these modifications or replacements do not deviate from the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the scope of protection of the present invention. It should be noted that if software tools or components other than those of the company appear in the embodiments of this application, they are only used for example and do not represent actual use.

Claims

1. A financial transaction method based on a smart card, characterized in that: The method comprises: The smart terminal performs function screening on the smart card and obtains response function data; The smart terminal performs offline authentication on the smart card according to the response function data to obtain a dynamic application ciphertext, including: extracting an application function from the response function data, screening a corresponding application template from a preset application template library according to the application function to form a transaction application, extracting transaction parameter items from the transaction application, initializing a preset dynamic random check code, generating a dynamic random ciphertext according to the transaction parameter items and the initialized dynamic random check code, receiving a dynamic application ciphertext generated and fed back by the smart card according to the dynamic random ciphertext, and sending the dynamic application ciphertext to the smart terminal; The smart terminal decrypts and dynamically verifies the dynamic application ciphertext to obtain a dynamic verification result, sends an identity acquisition command to the smart card based on the dynamic verification result, and receives response identity information sent by the smart card that is matched with the identity acquisition command; The smart terminal verifies the response identity information and the hardware of the smart terminal to generate a terminal behavior risk, receives a card behavior risk generated by the smart card based on the number of transactions of the smart card and a preset transaction limit, and generates a transaction behavior risk based on the card behavior risk and the terminal behavior risk; The smart terminal authorizes the transaction on the smart card according to the transaction behavior risk to obtain a transaction result.

2. The smart card-based financial transaction method according to claim 1, wherein: The smart terminal performs function screening on the smart card to obtain response function data, including: The smart terminal sends an application display command to the smart card; The smart card generates an application list according to the application display command; The smart terminal performs application screening on the application list to obtain a target application name; The smart terminal generates an application read command according to the target application name; The smart terminal reads data from the smart card according to the application read command to obtain response function data.

3. The smart card-based financial transaction method according to claim 1, wherein: The method further comprises: The smart terminal sends the generated dynamic random ciphertext to the smart card; The smart card extracts a dynamic random check code and a transaction parameter item from the dynamic random ciphertext; The smart card performs parameter matching on the transaction parameter items to obtain smart card transaction parameters; The smart card generates application dynamic data according to the smart card transaction parameters and the dynamic random check code; The smart card encrypts the application dynamic data with a private key to obtain a dynamic application ciphertext.

4. The smart card-based financial transaction method according to claim 1, wherein: The intelligent terminal decrypts and dynamically verifies the dynamic application ciphertext to obtain a dynamic verification result, including: The intelligent terminal decrypts the dynamic application ciphertext to obtain a decrypted application ciphertext; The intelligent terminal performs dynamic verification on the decrypted application ciphertext according to the dynamic random verification code to obtain a dynamic verification result.

5. The smart card-based financial transaction method according to claim 1, wherein: The smart terminal verifies the response identity information and the hardware of the smart terminal to generate a terminal behavior risk, including: The intelligent terminal performs identity verification on the response identity information to obtain an identity verification result; The intelligent terminal performs hardware integrity verification to obtain a hardware verification result; The smart terminal generates a terminal behavior risk according to the identity verification result and the hardware verification result.

6. The smart card-based financial transaction method according to claim 1, wherein: The smart terminal authorizes the smart card for a transaction based on the transaction behavior risk, and obtains a transaction result, including: Determine whether the transaction risk is risk-free; If not, the financial transaction is terminated, and the transaction result is a transaction failure; If yes, the smart terminal matches the authorization response ciphertext and sends the authorization response ciphertext to the smart card; The smart card decrypts the authorization response ciphertext to obtain authorization response data; The smart card determines whether the authorization response data matches the preset authorization data; If not, the financial transaction is terminated, and the transaction result is a transaction failure; If yes, the smart terminal generates an online transaction application based on the transaction application and the smart card transaction parameters; The smart terminal performs an online transaction on the smart card according to the online transaction application to obtain a transaction result.

7. A financial transaction device based on a smart card, characterized in that: Including smart cards and smart terminals: The smart card is configured to: send response function data to the smart terminal; send response identity information to the smart terminal; perform behavior analysis to obtain transaction behavior risks; perform authorized transactions to obtain transaction results; The smart terminal is configured to: perform function screening on the smart card to obtain response data; The smart terminal performs offline authentication on the smart card based on the response function data to obtain a dynamic application ciphertext, including: extracting an application function from the response function data, selecting a corresponding application template from a preset application template library based on the application function to form a transaction application, extracting transaction parameter items from the transaction application, initializing a preset dynamic random check code, generating a dynamic random ciphertext based on the transaction parameter items and the initialized dynamic random check code, receiving the dynamic application ciphertext generated and fed back by the smart card based on the dynamic random ciphertext, and sending the dynamic application ciphertext to the smart terminal; the smart terminal decrypts and dynamically verifies the dynamic application ciphertext to obtain a dynamic verification result, sends an identity acquisition command to the smart card based on the dynamic verification result, and receives response identity information sent by the smart card that is matched with the identity acquisition command; the smart terminal verifies the response identity information and the hardware of the smart terminal to generate a terminal behavior risk, receives a card behavior risk generated by the smart card based on the number of transactions of the smart card and a preset transaction limit, and generates a transaction behavior risk based on the card behavior risk and the terminal behavior risk; Authorizing the transaction on the smart card according to the transaction behavior risk to obtain a transaction result.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the smart card-based financial transaction method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the smart card-based financial transaction method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • IC card transaction method and IC card transaction system

    CN104933565A