A PSAM card reader with anti-tamper protection

By using the central processor to output random pulse signals in the PSAM card reader and writer to form an anti-tamping protection closed loop, the problems of complex sensitivity adjustment and low security in the prior art are solved, and high reliability and low cost anti-tamping protection effect are achieved.

CN119962551BActive Publication Date: 2025-08-26BEIJING ZHAOXUN HENGDA TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411832498.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-08-26
Estimated Expiration
2044-12-12

AI Technical Summary

Technical Problem

The anti-tamping protection mechanism of existing PSAM card readers and writers has complex sensitivity adjustment, low security, and high cost.

Method used

The central processor is used to output random pulse signals to the dynamic anti-tamping link to form an anti-tamping protection closed loop. By initializing the parameters, waveforms and detection of the random pulse signals, the reliability of anti-tamping protection is improved.

Benefits of technology

It achieves improved reliability of anti-tamping protection, convenient sensitivity adjustment, reduces cost, and reduces interference to other signals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119962551B_ABST
    Figure CN119962551B_ABST
Patent Text Reader

Abstract

The present invention discloses a PSAM card reader / writer with anti-tampering protection, comprising a central controller, a power supply module, a card slot module, an anti-tampering circuit and a battery; wherein the serial communication port of the central controller is connected to the serial communication port of the card slot module; the input end of the anti-tampering circuit is connected to the anti-tampering output end of the central controller, and the output end of the anti-tampering circuit is connected to the anti-tampering input end of the central controller, forming an anti-tampering protection closed loop; the central processing unit performs initialization parameter configuration on a random pulse signal, outputs a corresponding random pulse signal, passes through a first dynamic anti-tampering link or a second dynamic anti-tampering link, and then returns to the corresponding anti-tampering input end of the central processing unit, forming one or more anti-tampering protection closed loops; when the central processing unit detects that the level signals of the corresponding anti-tampering input / output ends do not match, the anti-tampering protection mechanism is triggered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a PSAM card reader / writer with anti-disassembly protection, belonging to the technical field of information security. Background Art

[0002] A PSAM (Purchase Secure Access Module) card is a terminal security control module. A PSAM card reader is a device used to read and write PSAM cards. It is widely used in finance, telecommunications, transportation, security, and other fields to verify the legitimacy of user cards and protect terminal transaction security and data privacy. PSAM card readers typically feature tamper protection. If the reader casing is disassembled or damaged by unauthorized means, the tamper protection mechanism is triggered, causing the PSAM card reader to automatically clear stored critical data, sound an alarm, and lock the device, thus ensuring the security of the terminal's internal information.

[0003] In existing technologies, the tamper protection circuits in PSAM card readers typically trigger by detecting changes in a fixed voltage level. The sensitivity of the tamper protection is adjusted physically, resulting in a single trigger mechanism, low security, and complex sensitivity adjustment. Furthermore, some PSAM card readers require an external voltage-conversion chip to connect to the IC card, which increases the cost of the PSAM card reader.

[0004] Chinese patent application number 201210276442.X discloses an anti-tamper circuit based on the STM32 chip. This circuit controls the voltage level of the STM32 chip's TAMPER pin via a battery, a switch, and an RC charge-discharge circuit; detecting a low level on the TAMPER pin triggers the anti-tamper protection. This circuit's use of a fixed voltage level as a protection trigger mechanism makes it easy to identify. Applying a fixed high-level signal to resistor R2 via a microprobe and then disconnecting the anti-tamper switch S1 could allow illegal chip manipulation, thus limiting security. Furthermore, adjusting the protection sensitivity requires physically disassembling the device and modifying the RC parameters, making sensitivity adjustment complex.

[0005] Chinese patent application number 201520836823.8 discloses a three-in-one financial card reader / writer. The reader / writer includes a central controller, a power management unit, a reset circuit, a communication interface, a contactless IC card, a contact IC card, and a magnetic stripe card. The connection between the central controller and the contact IC card requires an external dedicated chip for level conversion, which increases costs. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a PSAM card reader with anti-tamper protection.

[0007] In order to achieve the above object, the present invention adopts the following technical solutions:

[0008] According to an embodiment of the present invention, a PSAM card reader with anti-tamper protection is provided, comprising a central controller, a power supply module, a card slot module, an anti-tamper circuit and a battery; wherein,

[0009] The output end of the power supply module is connected to the power supply end of the central controller to provide power supply thereto; the serial communication port of the central controller is connected to the serial communication port of the card slot module for mutual information communication; the input end of the anti-tampering circuit is connected to the anti-tampering output end of the central controller, and the output end of the anti-tampering circuit is connected to the anti-tampering input end of the central controller to form an anti-tampering protection closed loop; the output end of the battery is connected to the branch processing unit of the central controller to provide it with backup power;

[0010] The central controller is used to control the overall operation of the PSAM card reader and output a random pulse signal to the anti-tampering circuit;

[0011] The anti-tampering circuit includes at least a first dynamic anti-tampering link and / or a second dynamic anti-tampering link; wherein the output end of the first dynamic anti-tampering link is connected to a fixed high potential end via a resistor, and when the first dynamic anti-tampering link is disconnected, the output end presents a fixed high level; the output end of the second dynamic anti-tampering link is connected to a fixed ground potential end via a resistor, and when the second dynamic anti-tampering link is disconnected, the output end presents a fixed low level;

[0012] The card slot module is used to insert the PSAM card to perform corresponding operations;

[0013] The central processing unit initializes the parameters of the random pulse signal, outputs the corresponding random pulse signal, passes through the first dynamic anti-tampering link or the second dynamic anti-tampering link, and then returns to the corresponding anti-tampering input terminal of the central processing unit, forming one or more anti-tampering protection closed loops; when the central processing unit detects that the level signals of the corresponding anti-tampering input / output terminals do not match, the anti-tampering protection mechanism is triggered.

[0014] Preferably, the first dynamic anti-disassembly link includes a first contact switch and a first resistor; wherein,

[0015] The input end of the first contact switch is connected to the first anti-tamper output end of the central processing unit, the output end of the first contact switch is connected to the first anti-tamper input end of the central processing unit and the first resistor, and the other end of the first resistor is connected to the backup power supply end of the central processing unit.

[0016] Preferably, the second dynamic anti-disassembly link includes a second contact switch and a second resistor; wherein,

[0017] The input end of the second contact switch is connected to the second anti-tamper output end of the central processing unit, the output end of the second contact switch is connected to the second anti-tamper input end of the central processing unit and the second resistor, and the other end of the second resistor is connected to the ground potential end.

[0018] Preferably, the central processing unit configures the interval time of the random pulse signal, and the current high level width or low level width T of the random pulse signal satisfies the following formula:

[0019] T=n*t

[0020] Where t is the interval time for configuration selection, n is the current value of the random number, and n is a positive integer.

[0021] Preferably, the central processing unit configures the number of sampling times of the received signal of the anti-tampering input terminal within an interval; within an interval, if all sampling results are different from the level at the corresponding anti-tampering output terminal, it is determined to be an attack and the anti-tampering protection mechanism is triggered.

[0022] Preferably, the central processing unit configures the voltage conversion rate of the anti-tamper input terminal;

[0023] When the voltage overshoot caused by the random pulse signal level flipping has a greater impact, a lower voltage conversion rate is selected;

[0024] When the random pulse signal has poor quality and is distorted, a higher voltage conversion rate is selected.

[0025] Preferably, the card slot module includes a card seat, three filter circuits and a third filter capacitor; wherein,

[0026] The three transmission lines of the serial communication port of the card holder are respectively connected to the serial communication port of the central processing unit through one of the filter circuits;

[0027] The power supply end of the card holder is connected to one end of the third filter capacitor and then connected to the power output end of the central processing unit.

[0028] Preferably, the filtering circuit includes a sixth resistor, a fifth filtering capacitor and a second TVS protection tube; wherein,

[0029] One end of the sixth resistor is connected to the fifth filter capacitor, the second TVS protection tube and the corresponding port of the card holder, and the other end of the sixth resistor is connected to the corresponding port of the central processing unit; the other end of the fifth filter capacitor and the second TVS protection tube is connected to the ground potential end.

[0030] Preferably, the central processing unit configures and selects the magnitude of the output power supply voltage to provide a suitable operating voltage for the card slot module.

[0031] Compared with the prior art, the PSAM card reader with tamper protection provided by the present invention improves the reliability of the tamper protection by adopting a technical solution in which a central processing unit outputs a random pulse signal to a dynamic tamper protection link and then returns it to the central processing unit input terminal to form a tamper protection closed loop, and the parameters, waveform, and detection of the random pulse signal are initialized accordingly. Furthermore, the protection sensitivity can be easily adjusted. Therefore, the PSAM card reader with tamper protection provided by the present invention has the advantages of a clever and reasonable structural design, low design cost, high reliability, and excellent circuit performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A structural block diagram of a PSAM card reader with anti-tamper protection provided by an embodiment of the present invention;

[0033] Figure 2 This is a pin wiring diagram of the central controller in an embodiment of the present invention;

[0034] Figure 3 This is a circuit schematic diagram of an anti-tampering circuit in an embodiment of the present invention;

[0035] Figure 4 A schematic diagram of a random pulse signal and its parameters in an embodiment of the present invention;

[0036] Figure 5 This is a schematic diagram of a voltage overshoot generated by a random pulse signal flip in an embodiment of the present invention;

[0037] Figure 6 FIG. 4 is a circuit wiring diagram of the card slot module in an embodiment of the present invention. DETAILED DESCRIPTION

[0038] The technical content of the present invention is described in detail below with reference to the accompanying drawings and specific embodiments.

[0039] like Figure 1As shown, an embodiment of the present invention provides a PSAM card reader with anti-tamper protection, comprising a central controller SCPU, a power supply module, a card slot module, an anti-tamper circuit, and a battery; a debugging interface may also be included as needed. The output end of the power supply module is connected to the power supply end of the central controller SCPU to provide it with power; the serial communication port (SCI7816) of the central controller SCPU is connected to the serial communication port of the card slot module for mutual information communication; the input end of the anti-tamper circuit is connected to the anti-tamper output terminal TAMPER_OUT of the central controller SCPU, and the output end of the anti-tamper circuit is connected to the anti-tamper input terminal TAMPER_IN of the central controller SCPU, forming an anti-tamper protection closed loop; the output end of the battery is connected to the branch processing unit BPU of the central controller SCPU to provide it with backup power; the serial port input / output end of the central controller SCPU is connected to the input / output end of the debugging interface for mutual information communication.

[0040] The central controller SCPU is used to control the overall operation of the PSAM card reader and output random pulse signals to the anti-tamper circuit. The branch processing unit (BPU) in the central controller SCPU is used to store key data or key information.

[0041] The anti-dismantling circuit includes at least a first dynamic anti-dismantling link and / or a second dynamic anti-dismantling link; wherein, the output end of the first dynamic anti-dismantling link is connected to a fixed high potential end through a resistor, and when the first dynamic anti-dismantling link is disconnected, the output end presents a fixed high level; the output end of the second dynamic anti-dismantling link is connected to a fixed ground potential end through a resistor, and when the second dynamic anti-dismantling link is disconnected, the output end presents a fixed low level.

[0042] The card slot module is used to insert the PSAM card for corresponding operations.

[0043] The debugging interface is a communication interface for downloading programs or debugging the PSAM card.

[0044] The CPU initializes the random pulse signal parameters and outputs the corresponding random pulse signal, which then passes through the first dynamic anti-tampering link or the second dynamic anti-tampering link and returns to the corresponding anti-tampering input terminal of the CPU, forming one or more anti-tampering protection closed loops. When the CPU detects a mismatch between the level signals of the corresponding anti-tampering input / output terminals, the anti-tampering protection mechanism is triggered.

[0045] In one embodiment of the present invention, the central controller SCPU can use chip U1, and the battery can use button battery BT1. Chip U1 is an integrated circuit chip that integrates high performance and high security. It uses SC300 security core processor and built-in hardware security encryption module to support encryption algorithms such as DES, TDES, and AES, and has attack detection function, which meets financial security standards. The pin wiring of chip U1 is as follows: Figure 2 As shown, the connection between chip U1 and each unit is as follows:

[0046] The VBAT33 pin (i.e. PIN84) of chip U1 is connected to the button battery BT1 as a backup power supply terminal to provide backup power for the branch processing unit BPU inside the chip; the VDD33 pin of chip U1 is used as the working power supply terminal (i.e. PIN2, PIN52, PIN71 and PIN75). When the working power supply terminal is powered off, the button battery BT1 can power the branch processing unit BPU through the VBAT33 pin to ensure the normal operation of the branch processing unit BPU.

[0047] The SCI_IO pin (i.e., PIN88), SCI_RST pin (i.e., PIN87), and SCI_CLK pin (i.e., PIN86) of chip U1 are connected to the corresponding input / output ports of the card slot module for mutual information communication; the CVCC pin (i.e., PIN1) of chip U1 is connected to the power supply terminal of the card slot module to provide it with a 1.8V or 3V operating voltage.

[0048] The EXT0 to EXT5 pins (i.e., PIN83 to PIN78) of chip U1 serve as three pairs of anti-tampering pins TAMPER0_IN and TAMPER0_OUT, TAMPER1_IN and TAMPER1_OUT, and TAMPER2_IN and TAMPER2_OUT, which are respectively connected to the input / output ends of the corresponding dynamic anti-tampering links in the anti-tampering circuit to form an anti-tampering protection closed loop.

[0049] The DP pin (ie, PIN69) and DM pin (ie, PIN68) of the chip U1 are connected to the debug interface as serial port input / output terminals.

[0050] In one embodiment of the present invention, Figure 3 As shown, the anti-tamper circuit includes two first dynamic anti-tamper links and one second dynamic anti-tamper link.

[0051] The first first dynamic anti-disassembly link includes a first contact switch K1 and a first resistor R1; wherein, the input end 1 of the first contact switch K1 is connected to the anti-disassembly output pin TAMPER0_OUT of the chip U1, the output end 2 of the first contact switch K1 is connected to the anti-disassembly input pin TAMPER0_IN of the chip U1 and the first resistor R1, and the other end of the first resistor R1 is connected to the VBAT33 pin of the chip U1 (that is, the output end of the button battery BT1).

[0052] The second first dynamic anti-tampering link includes a third contact switch K3 and a third resistor R3; wherein, the input end 1 of the third contact switch K3 is connected to the anti-tampering output pin TAMPER2_OUT of the chip U1, the output end 2 of the third contact switch K3 is connected to the anti-tampering input pin TAMPER2_IN of the chip U1 and the third resistor R3, and the other end of the third resistor R3 is connected to the VBAT33 pin of the chip U1 (that is, the output end of the button battery BT1).

[0053] The second dynamic anti-tampering link includes a second contact switch K2 and a second resistor R2; wherein, the input end 1 of the second contact switch K2 is connected to the anti-tampering output pin TAMPER1_OUT of the chip U1, the output end 2 of the second contact switch K2 is connected to the anti-tampering input pin TAMPER1_IN of the chip U1 and the second resistor R2, and the other end of the second resistor R2 is connected to the ground potential end.

[0054] Each dynamic anti-tamper link is routed in a serpentine pattern across the entire PCB or FPC cable, and is connected to the cover plate via zebra strips. If external force causes the dynamic anti-tamper link to be disconnected, tamper protection is triggered.

[0055] The first resistor R1 or the third resistor R3 set at the output end of the first dynamic anti-disassembly link, and the second resistor R2 set at the output end of the second dynamic anti-disassembly link, have the function of when the contact switch (K1 or K2 or K3) is disconnected, the corresponding anti-disassembly input pin (TAMPER0_IN or TAMPER1_IN or TAMPER2_IN) of the chip U1 will be in a floating input state. Due to the introduction of external voltage interference, a large current will be generated, thereby consuming the backup power supply of the chip U1 (that is, the button battery BT1 connected to the VBAT33 end). The setting of the first resistor R1, the second resistor R2 and the third resistor R3 can provide a fixed level for the corresponding anti-disassembly input pin of the chip U1 while reducing the power consumption of the backup power supply, thereby extending the service life of the button battery.

[0056] In this embodiment, the resistance of the first resistor R1, the second resistor R2, and the third resistor R3 is 10 MΩ. The resistance value of this resistor should not be too small to avoid generating additional current when the voltage level of the pin TAMPER0_IN, the pin TAMPER1_IN, or the pin TAMPER2_IN of the chip U1 is dynamically flipped. The working principle of the anti-tamper protection in this embodiment is described in detail below.

[0057] Once the PSAM card reader is powered on (that is, the VDD33 and VBAT33 pins of the CPU chip U1 are powered on), the tamper-proof input / output pins EXT0 through EXT5 become active. In this embodiment, the output voltage of the button battery BT1 is 3V, and the voltage of the VDD33 pin is 3.3V. The CPU chip U1 initializes the output signal parameters of the tamper-proof output pins through software. This is explained below using the first dynamic tamper-proof link as an example.

[0058] The output signal of chip U1's tamper-resistant output pin, TAMPER0_OUT, is a random pulse signal. The high level of this pulse signal is the same as the VBAT33 voltage, both 3V, and the low level is 0V. CPU chip U1 is enabled through a software program operating register, and the tamper-resistant output pin, TAMPER0_OUT, outputs a random pulse signal according to the set parameters. Under normal operating conditions, chip U1's tamper-resistant input pin, TAMPER0_IN, synchronously receives this random pulse signal through the first contact switch, K1, in the first dynamic tamper-resistant link. That is, under normal operating conditions, the voltage levels of chip U1's pair of tamper-resistant input / output pins (TAMPER0_IN and TAMPER0_OUT) remain dynamically in phase. When external violence causes the first contact switch K1 in the first dynamic anti-tampering link to be disconnected, the anti-tampering input pin TAMPER0_IN of the chip U1 obtains the VBAT33 voltage 3V through the first resistor R1, presenting a fixed high level. At this time, when the chip U1 detects that the level signal of the anti-tampering input / output pin does not match, it triggers the anti-tampering protection mechanism, automatically clears the key data information stored in the branch processing unit BPU, and issues an alarm and locks the machine, thereby ensuring the security of the internal information of the terminal.

[0059] From the above analysis, it can be seen that the trigger mechanism of the anti-dismantling protection in this embodiment does not detect the change of a single fixed level, but uses a random pulse signal to form an anti-dismantling protection closed loop through a pair of anti-dismantling input / output pins and a dynamic anti-dismantling link of the chip U1. When it is detected that the level signals of a pair of anti-dismantling input / output pins do not match, the anti-dismantling protection mechanism is triggered. Therefore, the outside cannot illegally operate the chip by applying a fixed level, and the security performance is greatly improved. The working principle of the second dynamic anti-dismantling link is basically the same as that of the first dynamic anti-dismantling link. The difference is that when external violence causes the second contact switch K2 in the second dynamic anti-dismantling link to be disconnected, the anti-dismantling input pin TAMPER1_IN of the chip U1 obtains the ground potential level through the second resistor R2, that is, it presents a fixed low level. The three dynamic anti-dismantling links together provide more reliable anti-dismantling security protection for the PSAM card reader.

[0060] It should be noted that the anti-tamper circuit specifically includes one or more dynamic anti-tamper links, and the number can be selected based on actual application requirements. Using multiple dynamic anti-tamper links can further improve the reliability of anti-tamper protection. The following details the CPU's initialization parameter configuration related to the random pulse signal and its principles.

[0061] First, the chip U1 configures the interval time t of the random pulse signal output by the anti-tamper output pin through a software program. This is achieved by adjusting the register value (2 bits) through the software program. The specific configuration method is detailed in Table 1.

[0062] Table 1 Configuration table of interval time t

[0063]

[0064] In this embodiment, the random pulse signal is a randomly flipped square wave pulse signal, which has two important parameters: the interval time t and the random number n (n is a positive integer). Figure 4 As shown, taking the interval configuration as

[01] as an example, assuming that the interval time t1 = 500ms, the square wave pulse signal first outputs a high level, and the random number n = 2. At this time, the high level of the square wave pulse is flipped to a low level after 2 intervals t1, so the width of the first high-level square wave is n*t1 = 1000ms. Assuming that when flipping to a low level, the random number n = 1, then the low level is flipped to a high level after 1 interval t1. At this time, the width of the first low-level square wave is n*t1 = 500ms. Similarly, the random pulse signal performs a level flip of random width according to the interval time t and the random number n. The current high-level width or low-level width T of the random pulse signal satisfies the following formula:

[0065] T=n*t

[0066] Where t is the interval between configuration selections, and n is the current value of the random number.

[0067] Secondly, when chip U1 performs real-time detection on the random pulse signal received by the anti-tamper input pin through the dynamic anti-tamper link, it configures the number of sampling times S of the detection signal within an interval to filter out signal glitches. The specific method is to divide the interval time t of the random pulse signal into 1-4 equal sampling points. Assuming that it is divided into 4 equal parts with a total of 4 sampling points, it is necessary to perform 4 consecutive level sampling at the anti-tamper input pin. If the 4 sampling results within an interval time t are all different from the level at the corresponding anti-tamper output pin, it is determined to be an attack and the anti-tamper protection mechanism is triggered; otherwise, it is treated as a signal glitch and the anti-tamper protection mechanism is not triggered. Chip U1 configures the number of sampling times S of the detection signal through a software program, and adjusts the register value (2 bits) through the software program to achieve this. The specific configuration method is detailed in Table 2.

[0068] Table 2 Configuration table of sampling times S

[0069]

[0070] Assume that the configuration of the sampling times S is selected as

[01] , then the random pulse signal is sampled twice continuously within the interval t. If the two sampling results are different from the level at the corresponding anti-tampering output pin, it is determined to be attacked and the anti-tampering protection mechanism is triggered; otherwise, it is treated as a signal glitch and the anti-tampering protection mechanism is not triggered.

[0071] The above-mentioned interval and sampling frequency configuration only needs to be configured once, when chip U1's operating power supply (VDD33) is first powered on and initialized. The configuration register values ​​will not change subsequently as long as the backup power supply (VBAT33) remains powered. During this configuration process, a shorter interval and fewer sampling times result in a faster and more easily triggered tamper protection. A longer interval and more sampling times result in a slower and less easily triggered tamper protection. This makes adjusting the tamper protection sensitivity very convenient.

[0072] Next, chip U1 configures the voltage slew rate (SR) at the tamper input pin. The voltage slew rate, also known as the slew rate, indicates the speed at which the voltage changes, or the maximum value of the voltage change per unit time.

[0073] On the one hand, since the dynamic anti-tampering link is densely covered on the entire PCB board or FPC cable in a serpentine routing manner, when the random pulse signal has a rising or falling level flip, a voltage overshoot phenomenon will occur, such as Figure 5As shown in the figure, this overshoot voltage can easily cause crosstalk to other signals, such as sensitive signals such as ADC, DAC, 7816, MSR, and clock. Therefore, it is necessary to reduce the slew rate to increase the rise or fall time of the voltage, thereby reducing the overshoot voltage.

[0074] On the other hand, since the dynamic anti-tamper link is connected to the cover via zebra strips, if the zebra strips and cover are not securely pressed together, a large impedance (up to kilo-ohms) will exist, which is equivalent to a large resistor connected in series with the anti-tamper link. Therefore, when the random pulse signal level flips, it will cause signal distortion, resulting in incorrect level transmission of the random pulse signal, increased backup power supply current and power consumption, and shortened button battery life. Therefore, it is necessary to increase the slew rate to reduce the voltage rise or fall time, thereby improving signal distortion.

[0075] Chip U1 configures the voltage slew rate SR (Slew Rate) at the tamper-proof input pin by adjusting the register value (2 bits) through software program. The specific configuration method is detailed in Table 3.

[0076] Table 3 Configuration table of voltage conversion rate SR

[0077]

[0078] In practical applications, the voltage conversion rate SR can be selected and configured according to the actual needs of the application scenario. When the voltage overshoot caused by the random pulse signal level flip has a greater impact, the voltage conversion rate SR can be configured as

[00] . In this case, the voltage conversion rate SR is low (low speed). When the random pulse signal quality is poor and distortion occurs, the voltage conversion rate SR can be configured as

[11] . In this case, the voltage conversion rate SR is high (very high speed).

[0079] The central processing unit chip U1 uses the above method to initialize the parameters, waveform and detection aspects of the random pulse signal output by each anti-dismantling output terminal, and the parameters of the random pulse signal output by different anti-dismantling output terminals can be set to be the same or different; then, each random pulse signal returns to the corresponding anti-dismantling input terminal of the chip U1 through the first dynamic anti-dismantling link or the second dynamic anti-dismantling link, forming one or more anti-dismantling protection closed-loop circuits, which greatly improves the reliability of the anti-dismantling protection, and the protection sensitivity adjustment is very convenient. At the same time, it can also reduce the interference of the random pulse signal on other signals on the chip.

[0080] In one embodiment of the present invention, the card slot module is connected to the central processing unit chip U1. In actual application, inserting the PSAM card into the card slot module can communicate with the central controller U1 and complete the corresponding read and write operations. Figure 6 As shown, the card slot module includes a card holder J1, three filter circuits, and a third filter capacitor C3; wherein, the three transmission lines of the serial communication port of the card holder J1 are respectively connected to the serial communication port of the central processing unit through a filter circuit; the power supply end of the card holder J1 is connected to one end of the third filter capacitor and then connected to the power output end of the central processing unit.

[0081] exist Figure 6 In the figure, pin 2 of the card holder J1 is connected to the SCI_RST pin of the chip U1 through the first filtering circuit, pin 3 of the card holder J1 is connected to the SCI_CLK pin of the chip U1 through the second filtering circuit, and pin 7 of the card holder J1 is connected to the SCI_IO pin of the chip U1 through the third filtering circuit, so as to realize mutual information communication; the power pin 1 of the card holder J1 is connected in parallel with the third filtering capacitor C3 and then connected to the CVCC pin of the chip U1 to obtain a 1.8V or 3V operating voltage.

[0082] The structures of the three filter circuits are the same. Take the first filter circuit as an example. The first filter circuit includes a sixth resistor R6, a fifth filter capacitor C5, and a second TVS (Transient Voltage Suppressors) protection tube TV2; wherein, one end of the sixth resistor R6 is connected to the fifth filter capacitor C5, the second TVS protection tube TV2, and pin 2 of the card holder J1, and the other end of the sixth resistor R6 is connected to the SCI_RST pin of the chip U1; the other ends of the fifth filter capacitor C5 and the second TVS protection tube TV2 are connected to the ground potential end. The series resistor and parallel capacitor in the filter circuit are used to filter out high-frequency clutter interference, and the TVS protection tube is used to eliminate electrostatic shock interference to ensure the quality of communication signal transmission. In the filter circuit of this embodiment, the resistance of the series resistor is 22Ω, the capacitance of the parallel capacitor is 30pf; the capacitance of the third filter capacitor C3 is 4.7uf, which ensures good transient response of the CVCC power supply.

[0083] In this embodiment, CPU chip U1 has a built-in SmartCard interface (supporting EMV Level-1 protocol specifications and ISO 7816-3 standards). SCI0 integrates 7816 level conversion functionality, allowing for configurable output voltages of 3V or 1.8V. Chip U1's CVCC pin provides the appropriate operating voltage for card connector J1. The output voltage can be selected by adjusting a register value (1 bit) via software. Specific configuration methods are detailed in Table 4.

[0084] Table 4 Card slot module power supply voltage configuration

[0085]

[0086] Through the above configuration, the power supply voltage of the card slot module can be selected without providing a voltage conversion chip between the central controller U1 and the card slot module, thereby achieving the purpose of cost saving.

[0087] In summary, compared with the prior art, the PSAM card reader with tamper protection provided by the present invention improves the reliability of the tamper protection by adopting a technical solution in which a central processing unit outputs a random pulse signal to a dynamic tamper protection link and then returns it to the central processing unit input terminal to form a tamper protection closed loop, and the parameters, waveform, and detection of the random pulse signal are initialized accordingly. Furthermore, the protection sensitivity can be easily adjusted. Therefore, the PSAM card reader with tamper protection provided by the present invention has the advantages of a clever and reasonable structural design, low design cost, high reliability, and excellent circuit performance.

[0088] It should be noted that the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, features defined as "first" or "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0089] The PSAM card reader with tamper protection provided by the present invention has been described in detail above. For those skilled in the art, any obvious changes made thereto without departing from the essence of the present invention will constitute infringement of the patent right of the present invention and the corresponding legal liability will be borne.

Claims

1. A PSAM card reader with anti-tamper protection, characterized in that It includes a central controller, a power supply module, a card slot module, an anti-tampering circuit and a battery; among which, The output end of the power supply module is connected to the power supply end of the central controller to provide power supply thereto; the serial communication port of the central controller is connected to the serial communication port of the card slot module for mutual information communication; the input end of the anti-tampering circuit is connected to the anti-tampering output end of the central controller, and the output end of the anti-tampering circuit is connected to the anti-tampering input end of the central controller to form an anti-tampering protection closed loop; the output end of the battery is connected to the branch processing unit of the central controller to provide it with backup power; The central controller is used to control the overall operation of the PSAM card reader and output a random pulse signal to the anti-tampering circuit; The anti-tampering circuit includes at least a first dynamic anti-tampering link and / or a second dynamic anti-tampering link; wherein the output end of the first dynamic anti-tampering link is connected to a fixed high potential end via a resistor, and when the first dynamic anti-tampering link is disconnected, the output end presents a fixed high level; the output end of the second dynamic anti-tampering link is connected to a fixed ground potential end via a resistor, and when the second dynamic anti-tampering link is disconnected, the output end presents a fixed low level; The card slot module is used to insert the PSAM card to perform corresponding operations; The central processing unit initializes the parameters of the random pulse signal, outputs the corresponding random pulse signal, passes through the first dynamic anti-tampering link or the second dynamic anti-tampering link, and then returns to the corresponding anti-tampering input terminal of the central processing unit, forming one or more anti-tampering protection closed loops; when the central processing unit detects that the level signals of the corresponding anti-tampering input / output terminals do not match, the anti-tampering protection mechanism is triggered.

2. The PSAM card reader with tamper protection as claimed in claim 1, wherein: The first dynamic anti-disassembly link includes a first contact switch and a first resistor; wherein, The input end of the first contact switch is connected to the first anti-tamper output end of the central processing unit, the output end of the first contact switch is connected to the first anti-tamper input end of the central processing unit and the first resistor, and the other end of the first resistor is connected to the backup power supply end of the central processing unit.

3. The PSAM card reader with tamper protection as claimed in claim 1, wherein: The second dynamic anti-disassembly link includes a second contact switch and a second resistor; wherein, The input end of the second contact switch is connected to the second anti-tamper output end of the central processing unit, the output end of the second contact switch is connected to the second anti-tamper input end of the central processing unit and the second resistor, and the other end of the second resistor is connected to the ground potential end.

4. The PSAM card reader with tamper protection as claimed in claim 1, wherein: The central processing unit configures the interval time of the random pulse signal, and the current high level width or low level width T of the random pulse signal satisfies the following formula: T=n*t Where t is the interval time for configuration selection, n is the current value of the random number, and n is a positive integer.

5. The PSAM card reader / writer with tamper protection as claimed in claim 1, wherein: The central processing unit configures the number of sampling times of the received signal of the anti-tampering input terminal within an interval; within an interval, if all sampling results are different from the level at the corresponding anti-tampering output terminal, it is determined to be an attack and the anti-tampering protection mechanism is triggered.

6. The PSAM card reader with tamper protection as claimed in claim 1, characterized in that: The central processing unit configures the voltage conversion rate of the anti-tamper input terminal; When the voltage overshoot caused by the random pulse signal level flipping has a greater impact, a lower voltage conversion rate is selected; When the random pulse signal has poor quality and is distorted, a higher voltage conversion rate is selected.

7. The PSAM card reader with tamper protection as claimed in claim 1, characterized in that: The card slot module includes a card seat, three filter circuits and a third filter capacitor; wherein, The three transmission lines of the serial communication port of the card holder are respectively connected to the serial communication port of the central processing unit through one of the filter circuits; The power supply end of the card holder is connected to one end of the third filter capacitor and then connected to the power output end of the central processing unit.

8. The PSAM card reader with tamper protection as claimed in claim 7, characterized in that: The filtering circuit includes a sixth resistor, a fifth filtering capacitor and a second TVS protection tube; wherein, One end of the sixth resistor is connected to the corresponding port of the fifth filter capacitor, the second TVS protection tube and the card holder, and the other end of the sixth resistor is connected to the corresponding port of the central processing unit; the other end of the fifth filter capacitor and the second TVS protection tube is connected to the ground potential end.

9. The PSAM card reader with tamper protection as claimed in claim 1, characterized in that: The central processing unit configures and selects the magnitude of the output power supply voltage to provide a suitable operating voltage for the card slot module.

Citation Information

Patent Citations

  • Tamper circuit based on STM32 chip

    CN102854907A

  • Three blocks of a finance read write line

    CN205068456U

  • Disassembly-preventing monitoring circuit, electronic tag, anti-theft system and anti-theft method thereof

    CN108665046A

  • Electronic tag

    CN202662042U