Identity card reading method and terminal
By initializing the decrypted card module and decrypting the ID card data, the problem that existing devices cannot effectively process different types of ID card data is solved, the completeness and accuracy of the data are achieved, and the scope of application of the device is improved.
Patent Information
- Application Number
- CN202411990955.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-27
AI Technical Summary
Existing ID card reading devices cannot effectively process different types of ID card data, which makes it difficult to guarantee the completeness and accuracy of the data, and the scope of application of the device is limited.
By initializing the decrypted card module, obtaining the decrypted card security information, and sending reading instructions to the ID card reading module to obtain the ID card data. Then, parse and verify the ID card data, decrypt the data using the decrypted card security information, and obtain the identity document information.
It realizes effective processing of different types of ID card data, ensures the integrity and accuracy of the data, and improves the scope of application of the equipment.
Smart Images

Figure CN120046135A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of document reading devices, and particularly to an identity card reading method and a terminal. Background Art
[0002] With the rapid development of the financial industry, the demand for high-quality business hardware is increasing day by day. Traditional bank equipment is usually bulky and has a single function, making it difficult to meet the requirements of modern financial operations for efficiency, convenience, and security. Various types of mobile peripheral devices have entered more regions. Taking identity card reading as an example, when intelligent card reading devices enter specific markets in certain regions, international manufacturers' card readers and mobile peripheral all-in-ones usually read the data information of identity cards through NFC, and then parse and display the identity card information; because the types of documents and card types in each region vary greatly, only some documents can be read. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide an identity card reading method and a terminal, which can effectively process different types of identity card data, ensure the integrity and accuracy of the data, and improve the applicable range of the device.
[0004] To solve the above technical problem, the technical solution adopted by the present invention is as follows: An identity card reading method, comprising the steps of: S1. Initialize the decryption card module to obtain decryption card security information: S2. Send a reading instruction to the identity card reading module and obtain the identity card data returned by the identity card reading module, including reset response data ATR and unique identity identifier UID; S3. Parse and verify the identity card data, and decrypt the identity card data using the decryption card security information to obtain the identity card plaintext information.
[0005] To solve the above technical problem, another technical solution adopted by the present invention is as follows: An identity card reading terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: S1. Initialize the decryption card module to obtain decryption card security information: S2. Send a reading instruction to the identity card reading module and obtain the identity card data returned by the identity card reading module, including reset response data ATR and unique identity identifier UID; S3. Parse and verify the identity card data, and decrypt the identity card data using the decryption card security information to obtain the identity card plaintext information.
[0006] The beneficial effects of the present invention are as follows: It provides an identity card reading method and a terminal. By first initializing the decryption card module to obtain the decryption card security information, it realizes the decryption of the identity card data recognized by the identity card reading module to obtain the plaintext information, solving the problem that some identity card data cannot be parsed by traditional identity card reading devices. Among them, through the methods of initializing, reading, and decrypting data of the decryption card module, it can effectively process different types of identity card data, ensuring the integrity and accuracy of the data and improving the applicable range of the device. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figure 1 is a flowchart of an identity card reading method according to an embodiment of the present invention; Figure 2 is a timing flowchart for initializing the decryption card module according to an embodiment of the present invention; Figure 3 is a schematic flowchart of the interaction between the program UI interface display layer and the program function execution layer according to an embodiment of the present invention; Figure 4 is a schematic structural diagram of an identity card reading terminal according to an embodiment of the present invention.
[0008] Reference numeral description: 1. An identity card reading terminal; 2. A memory; 3. A processor. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0009] To describe in detail the technical content, the achieved objectives, and the effects of the present invention, the following is described in conjunction with the embodiments and with reference to the accompanying drawings.
[0010] Please refer to Figures 1 to 3 , an identity card reading method, including the steps of: S1. Initialize the decryption card module to obtain the decryption card security information: S2. Send a reading instruction to the identity card reading module and obtain the identity card data returned by the identity card reading module, including the reset response data ATR and the unique identity identifier UID; S3. Analyze and verify the identity card data, and decrypt the identity card data using the decryption card security information to obtain the identity card plaintext information.
[0011] As can be seen from the above description, the beneficial effects of the present invention are as follows: It provides an identity card reading method. By first initializing the decryption card module to obtain the decryption card security information, it realizes the decryption of the identity card data recognized by the identity card reading module to obtain the plaintext information, solving the problem that some identity card data cannot be parsed by traditional identity card reading devices. Among them, through the methods of initializing, reading, and decrypting data of the decryption card module, it can effectively process different types of identity card data, ensuring the integrity and accuracy of the data and improving the applicable range of the device.
[0012] Further, the specific steps of step S1 are as follows: S11. Send a card search instruction to the decryption card module; S12. After successful card search, send a power-on instruction to the decryption card module; S13. After the decryption card module is successfully powered on, send multiple APDU instructions to interact with the decryption card module and generate decryption card security information; S14. Send the generated decryption card security information to the background interface for legality verification; S15. After the verification passes, complete the initialization of the decryption card module.
[0013] As can be seen from the above description, through steps such as card search, power-on instruction, and APDU interaction for the decryption card module, the initialization of the decryption card module is realized, ensuring that all steps strictly comply with the security protocol when obtaining the decryption card security information, avoiding potential security hazards, enhancing the operability and stability of the decryption card module, and improving the reliability of the device reading function.
[0014] Further, in step S13, sending multiple APDU instructions to interact with the decryption card module and generating decryption card security information is specifically as follows: Use the sdk execution program to send multiple APDU instructions to the decryption card module and obtain the response, read the card control data, obtain the card ID and ciphertext key of the decryption card, and use the ciphertext key to encrypt a random number and then return it to the decryption card module for verification. If the verification passes, the authentication is successful, and at the same time, the decryption card security information is generated. Otherwise, the communication is aborted and a notification of initialization failure is returned.
[0015] As can be seen from the above description, by using the sdk execution program to send APDU instructions to interact with the decryption card module, it can accurately read the card control data, card ID, and ciphertext key, and perform encrypted random number verification, effectively enhancing the authentication mechanism of the decryption card module, ensuring the security of each reading operation, and at the same time avoiding authentication failures caused by data transmission errors, guaranteeing the credibility of the identity card data.
[0016] Further, in step S3, parsing and verifying the identity card data specifically includes: Adjusting, splitting, and reorganizing the data formats of the historical bytes of the reset response data ATR and the unique identifier UID of the identity, verifying and reorganizing the header information, historical bytes, and check part of the ATR, adding new check bytes, and calculating the integrity according to the check rules.
[0017] As can be seen from the above description, by adjusting, splitting, and reorganizing the data formats of the historical bytes of the ATR and the UID data, the data parsing process is optimized, which not only improves the processing ability for complex data formats but also ensures less information loss during the parsing process and enhances data integrity. At the same time, by adding new check bytes and calculating the integrity, it is ensured that the decrypted data is available for further processing or display.
[0018] Further, after step S3, it further includes: S4. Parsing the identity card plaintext information according to the data format rules, obtaining data such as name, ID number, date of birth, address, age, and avatar, and then performing visual display.
[0019] As can be seen from the above description, parsing the plaintext identity card data and extracting information including name, ID number, date of birth, address, age, and avatar can convert the identity card information into a visual data object and display it through the terminal, enhancing the user interaction experience of the device and providing real-time data support for subsequent business processing.
[0020] Please refer to Figure 4 , an identity card reading terminal, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: S1. Initializing the decryption card module to obtain decryption card security information: S2. Sending a reading instruction to the identity card reading module and obtaining the identity card data returned by the identity card reading module, including the reset response data ATR and the unique identifier UID of the identity; S3. Parsing and verifying the identity card data, and decrypting the identity card data using the decryption card security information to obtain the identity card plaintext information.
[0021] As can be seen from the above description, the beneficial effects of the present invention are as follows: Based on the same technical concept, in cooperation with the above-mentioned method for reading identity cards, an identity card reading terminal is provided. By first initializing the decryption card module to obtain the decryption card security information, the identity card data recognized by the identity card reading module is decrypted to obtain the plaintext information, solving the problem that some identity card data cannot be parsed by traditional identity card reading devices. Among them, by initializing, reading, and decrypting the data of the decryption card module, different types of identity card data can be effectively processed, ensuring the integrity and accuracy of the data, and improving the applicable range of the device.
[0022] Further, the specific steps of step S1 are as follows: S11. Send a card search instruction to the decryption card module; S12. After successful card search, send a power-on instruction to the decryption card module; S13. After the decryption card module is powered on successfully, send multiple APDU instructions to interact with the decryption card module and generate decryption card security information; S14. Send the generated decryption card security information to the background interface for legality verification; S15. After the verification passes, complete the initialization of the decryption card module.
[0023] As can be seen from the above description, the initialization of the decryption card module is realized by steps such as card search, power-on instruction, and APDU interaction for the decryption card module, ensuring that all steps strictly comply with the security protocol when obtaining the decryption card security information, avoiding potential security risks, enhancing the operability and stability of the decryption card module, and improving the reliability of the device reading function.
[0024] Further, in step S13, sending multiple APDU instructions to interact with the decryption card module and generating decryption card security information is specifically as follows: Use the sdk execution program to send multiple APDU instructions to the decryption card module and obtain the response, read the card control data, obtain the card ID and ciphertext key of the decryption card, and encrypt the random number with the ciphertext key and then return it to the decryption card module to verify whether it is correct. If the verification passes, the authentication is successful, and at the same time, the decryption card security information is generated. Otherwise, the communication is aborted and a notification of initialization failure is returned.
[0025] As described above, by using the sdk execution program to send APDU instructions to interact with the decryption card module, the card control data, card ID, and ciphertext key can be accurately read, and the encrypted random number verification can be performed, effectively enhancing the authentication mechanism of the decryption card module, ensuring the security of each read operation, avoiding authentication failures caused by data transmission errors, and guaranteeing the credibility of the ID card data.
[0026] Further, in step S3, parsing and verifying the ID card data specifically includes: Adjusting the data format, splitting, and reorganizing the historical bytes of the reset response data ATR and the unique identifier UID of the identity, verifying and reorganizing the header information, historical bytes, and check part of the ATR, adding new check bytes, and calculating the integrity according to the check rules.
[0027] As described above, by adjusting the data format, splitting, and reorganizing the historical bytes of the ATR and UID data, the data parsing process is optimized, which not only improves the processing ability of complex data formats but also ensures the reduction of information loss during the parsing process, enhancing data integrity; at the same time, by adding new check bytes and calculating the integrity, it is ensured that the decrypted data is available for further processing or display.
[0028] Further, after step S3, it further includes: S4. Parsing the cleartext information of the identity certificate according to the data format rules, and visualizing and displaying the obtained name, ID number, date of birth, address, age, and portrait data.
[0029] As described above, parsing the cleartext ID card data and extracting information including name, ID number, date of birth, address, age, and portrait can convert the ID card information into a visual data object and display it through the terminal, enhancing the user interaction experience of the device and providing real-time data support for subsequent business processing.
[0030] A method and terminal for reading an ID card provided by the present invention are mainly applied to various ID card reading scenarios, especially the reading scenario of Indonesian ID cards (EKTP). The following is a specific description in combination with specific embodiments: Please refer to Figure 1 , the first embodiment of the present invention is: A method for reading an ID card, as Figure 1 shown, includes the steps: S1. Initialize the decryption card module to obtain the decryption card security information.
[0031] S2. Send a read instruction to the ID card reading module and obtain the ID card data returned by the ID card reading module, including the reset response data ATR and the unique identifier UID.
[0032] S3. Analyze and verify the ID card data, and decrypt the ID card data using the decryption card security information to obtain the clear text information of the identity certificate.
[0033] That is, in this embodiment, by initializing the decryption card module first to obtain the decryption card security information, the ID card data recognized by the ID card reading module is decrypted to obtain the clear text information, which solves the problem that some ID card data cannot be parsed by traditional ID card reading devices. Among them, through the methods of initializing, reading, and decrypting data of the decryption card module, different types of ID card data can be effectively processed, ensuring the integrity and accuracy of the data, and improving the applicable range of the device.
[0034] At the same time, after step S3 in this embodiment, it also includes: S4. Analyze the clear text information of the identity certificate according to the data format rules, and perform visual display after obtaining the name, ID number, date of birth, address, age, and portrait data.
[0035] That is, by analyzing the clear text ID card data and extracting information including name, ID number, date of birth, address, age, and portrait, the ID card information can be converted into a visual data object and displayed through the terminal, enhancing the user interaction experience of the device and providing real-time data support for subsequent business processing.
[0036] Please refer to Figure 2 and Figure 3 , Embodiment 2 of the present invention is: An ID card reading method, based on the above-mentioned Embodiment 1, as Figure 2 shown is the initialization timing flowchart of the decryption card module during the ID card reading process of Indonesia provided in this embodiment, where Figure 2 the explanations of each English term in IEKTPSAM: refers to the execution module interface layer of the decryption card (PSAM card) module of EKTP (Indonesian ID card); EKTPProcessor: refers to the sdk execution program of all functions of EKTP; setEKTPSAMCallback: refers to setting the callback of the PSAM card function interface. For example, when the following program finds the PSAM card, it will inform the upper-layer application; FindSAM(slot): It means that the sdk execution program EKTPProcessor calls the IEKTPSAM execution module interface to perform the operation of finding the PSAM card. Here, slot is a parameter indicating whether to perform the power-on search operation of the PSAM card in contact or non-contact mode; onFindEKTPSAM(slot, code): It refers to the callback after the behavior of finding the PSAM card of EKTP ends, informing the sdk execution program EKTPProcessor of the search result. The parameter slot indicates whether the EKTP search method is contact or non-contact.
[0037] Then in this embodiment, step S1 is specifically as follows: S11. Send a card search instruction to the decryption card module.
[0038] S12. After the card search is successful, send a power-on instruction to the decryption card module.
[0039] S13. After the decryption card module is powered on successfully, send multiple APDU instructions to interact with the decryption card module and generate decryption card security information. Specifically: Use the sdk execution program to send multiple APDU instructions to the decryption card module and obtain the response, read the card control data, obtain the card ID and ciphertext key of the decryption card, and encrypt the random number with the ciphertext key and then return it to the decryption card module to verify whether it is correct. If the verification passes, the authentication is successful, and at the same time, the decryption card security information is generated. Otherwise, the communication is aborted and an initialization failure notice is returned.
[0040] S14. Send the generated decryption card security information to the background interface for legality verification, which can be network verification. In this embodiment, the decryption card security information can be sent to the background verification interface of the Indonesian government to verify the legality of the decryption card security information. Since the specific verification implementation method of the other party is unknown, the current general guess of the verification method is: decrypt the security information, perform a decryption operation on the ciphertext key in the information and the key in the background, and verify the legality of the security information.
[0041] S15. After the verification passes, complete the initialization of the decryption card module.
[0042] That is, in this embodiment, the decryption card module is initialized by steps such as card searching, power-on instruction, and APDU interaction, ensuring that all steps strictly comply with the security protocol when obtaining the security information of the decryption card, avoiding potential security hazards, enhancing the operability and stability of the decryption card module, and improving the reliability of the device reading function. At the same time, by using the sdk execution program to send APDU instructions to interact with the decryption card module, the card control data, card ID, and ciphertext key can be accurately read, and the encrypted random number verification can be performed, effectively enhancing the authentication mechanism of the decryption card module, ensuring the security of each reading operation, avoiding authentication failures caused by data transmission errors, and guaranteeing the credibility of the ID card data.
[0043] Such as Figure 3 The figure shows the schematic flow diagram of the interaction between the program UI interface display layer and the program function execution layer. Figure 3 The English noun explanations are as follows: Fragment UICallback: UI interface layer; EKTPProcess: Refers to the sdk execution program for all functions of the EKTP ID card; Contactless not detected: Non-contact card search, not found; Contactless detected: Non-contact card search, found; If not ektp card or ektp corrupt / broken: Read timeout or the card is damaged and unavailable.
[0044] EKTP Read success: Successfully read the Ektp card.
[0045] The flow steps of the interaction between the program UI interface display layer and the program function execution layer in this embodiment are described as follows: Step 1: setUICallback (set interface callback), actionClearScreen (reset and clear the UI data of the interface), actionDetecCard (card detection, whether PSAM cards are in place), these are the operations for initialization preparation.
[0046] Step 2: The UI layer interface triggers card reading, and then enters the card search process of waiting for the card (WaitingCard).
[0047] Step 3: The non-contact EKTP ID card is not found (CardNotFound) or the EKTP ID card is found (CardFound).
[0048] Step 4: Start reading the EKTP ID card, with successful reading (ReadSuccessful) or failed reading (ReadFail).
[0049] In this embodiment, step S2 is specifically as follows: S21. Send a reading instruction to the ID card reading module.
[0050] S22. The corresponding ID card reading module activates the card search instruction.
[0051] S23. After the ID card reading module finds the card, that is, after reading the ID card data of the ID card, it returns response data to determine whether the card search is successful.
[0052] S24. The ID card reading module ends the card search and sends an APDU instruction to the ID card.
[0053] In this embodiment, APDU refers to the Application Protocol Data Unit, which is the data unit format for communication between the smart card and the card reader and can be divided into two types: 1. Command APDU: Sent from the terminal module to the smart card to request the card to perform certain operations.
[0054] 2. Response APDU: Returned from the smart card to the terminal to transfer the operation result.
[0055] S25. The EKTP execution program EKTPProcessor controls the sending of a power-on instruction to the decryption card module. If the card is powered on successfully, it will return the reset response data ATR and the unique identifier UID to the terminal device, and the terminal will then send it to the execution program EKTPProcessor. Otherwise, if it fails, it will return the response response data of power-on failure to the execution program EKTPProcessor.
[0056] That is, when using the PSAM card for APDU instruction interaction, we can extract two types of key information from the returned data: ATR (Answer To Reset): This is a piece of data actively sent by the card to the card reader during reset, aiming to inform the card's functional characteristics, supported communication protocols, and other configuration information. ATR is an important basis for the card reader to initialize communication with the card.
[0057] UID (Unique Identifier): This is the unique identifier of the card, used to identify and distinguish different cards, which is particularly important during the card reading process and often serves as the core data in the application.
[0058] However, in practical applications, it is found that the ATR and UID data returned by some cards always fail the verification through the interface of the Indonesian government's back-end. To solve this problem, we have conducted in-depth analysis and re-design of the data content returned by the cards.
[0059] That is, in step S3, the ID card data is parsed and verified, specifically as follows: Adjust the data format, split and reorganize the historical bytes of the reset response data ATR and the unique identifier UID of the identity. Verify and reorganize the header information, historical bytes and verification part of the ATR, and add new verification bytes, and calculate the integrity according to the verification rules.
[0060] By adjusting the data format, splitting and reorganizing the historical bytes of the ATR and the UID data, the data parsing process is optimized, which not only improves the processing ability of complex data formats, but also ensures the reduction of information loss during the parsing process and enhances data integrity; at the same time, by adding new verification bytes and calculating the integrity, it is ensured that the decrypted data is available for further processing or display.
[0061] Specifically, in this embodiment, the ATR and UID data formats returned by some cards do not match the expectations, resulting in the failure of the verification of the Indonesian government's back-end interface. This may be due to the differences in the implementation of the internal protocols of the cards, or the inclusion of some unnecessary redundant information in the returned data.
[0062] There are various data formats involved in the card protocol, including the header information, historical bytes and verification part of the ATR. It is necessary to verify the functions and logics of these parts one by one; the interface has strict requirements for the UID data, and it is necessary to find reasonable field combinations to meet its verification rules; the verification process depends on the verification bytes (such as CRC) returned by the card, and it is necessary to ensure that the reorganized data can still pass the integrity verification.
[0063] Therefore, by deeply interpreting the format of the data returned by the card, following the specifications of the card communication protocol, reorganizing and combining the data content, repeatedly transmitting the data to the verification interface of the Indonesian government's back-end for verification and testing, and continuously optimizing the data structure according to the actual verification results.
[0064] A tuning and optimization solution is provided in this embodiment as follows: Field content description Example data 00000B3B8C80015070366FC830AAAA017781D7AC30 00000B3B8C80015070366FC830AAAA017781D7AC30 00000B: Data header 3B: Class B card 70366FC8: Four bytes starting from a number after 50 are the PUPI (Pseudo-Unique Identifier of the card), i.e., UID.
[0065] Step 1: Data filtering and extraction First, screen the data returned by the card, removing parts irrelevant to interface verification, certain specific type identification fields, and redundant check bytes. The remaining content mainly includes the following parts: ATR core fields: Retain the header information and core data part of ATR to describe the communication function and supported protocols of the card, and try to generate using new field combinations.
[0066] UID candidate fields: Extract potential UID information.
[0067] Step 2: Adjustment of historical bytes The historical bytes of ATR are an important part of the card protocol, used to transmit additional function information. In the protocol, the length of this field is fixed. For the case where the length of the historical bytes returned by some cards is abnormal, readjust this field to ensure that its length conforms to the protocol specification.
[0068] The content of the historical bytes includes the following information: Pseudo-Unique Identifier (PUPI): A random identifier generated during the communication process of Type B cards, used to prevent the card from being repeatedly tracked.
[0069] Application data and protocol information: Describe the application layer protocols and parameter configurations supported by the card.
[0070] Step 3: Data recombination and combination Recombine the header information, historical bytes, application data, and protocol information of ATR in a certain order to form a new data structure. At the same time, to meet the format requirements of the government interface, some fields are redefined, and some fixed values are tried as new UID candidate data.
[0071] In addition, during the data combination process, optimize the data content by supplementing bytes and modifying some field values (identifier fields in the historical bytes).
[0072] The detailed rules are as follows: Step 1: Replace 8c with 88, remove 50, change 30 at the end to 20, and remove the middle UID data Step 2: Perform an exclusive OR operation on the ASCII code value of each character of the modified data as the new check byte.
[0073] Step 3: Then, according to the format of the assembled data, "3B" + the modified data + the check byte, recombine the data to obtain the new data results of ATR and UID.
[0074] Step 4: Recalculation of the check value According to the check rules of the card protocol (such as CRC check), perform integrity verification on the recombined data, calculate the new check value, and ensure that the data complies with the specifications.
[0075] Result verification The optimized data is transmitted to the data interface for testing. Verify the feasibility of the solution through the following steps: 1. Data integrity verification: Confirm that the new data format has passed the integrity check of the interface.
[0076] 2. UID availability verification: The redefined UID is successfully recognized and can uniquely identify different cards.
[0077] 3. Function verification: The ATR data of the card can accurately describe the card functions and support subsequent business logic processing.
[0078] The final verification shows that the redesigned data structure has successfully solved the problem that some card data cannot pass the check, and the entire solution is proven to be effective and universal.
[0079] Please refer to Figure 4 , and the third embodiment of the present invention is: An identity card reading terminal 1, including a memory 2, a processor 3, and a computer program stored on the memory 2 and executable on the processor 3. When the processor 3 executes the computer program, it completes the steps in one of the identity card reading methods in the above-mentioned Embodiment 1 or Embodiment 2.
[0080] In summary, an identity card reading method and terminal provided by the present invention solve the problem that traditional identity card reading devices cannot parse some identity card data. By initializing, reading, and decrypting the data of the decryption card module, different types of identity card data can be effectively processed, ensuring the integrity and accuracy of the data, and improving the applicable range of the device.
[0081] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent transformation made using the content of the specification and drawings of the present invention, or directly or indirectly applied in the relevant technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A method for reading an ID card, characterized in that: The method comprises the following steps: S1. Initialize the decryption card module and obtain the decryption card security information: S2, sending a read instruction to the ID card reading module, and obtaining the ID card data returned by the ID card reading module, including the reset response data ATR and the unique identity identifier UID; S3, parsing and verifying the ID card data, and using the decryption card security information to decrypt the ID card data to obtain identity certification information.
2. A method for reading an ID card according to claim 1, characterized in that: The step S1 is specifically as follows: S11, sending a card search instruction to the card decryption module; S12, sending a power-on instruction to the card decryption module after the card is successfully found; S13, after the decryption card module is powered on successfully, multiple APDU instructions are sent to interact with the decryption card module, and decryption card security information is generated; S14, sending the generated decrypted card security information to the background interface for legitimacy verification; S15. After the verification is passed, the initialization of the decryption card module is completed.
3. A method for reading an ID card according to claim 2, characterized in that: In step S13, multiple APDU instructions are sent to interact with the decryption card module and generate decryption card security information, specifically: The SDK execution program is used to send multiple APDU instructions to the decryption card module and obtain a response, read the card control data, obtain the card ID and ciphertext key of the decryption card, and use the ciphertext key to encrypt the random number and return it to the decryption card module for verification. If the verification passes, the authentication is successful and the decryption card security information is generated at the same time. Otherwise, the communication is terminated and the initialization failure notification is returned.
4. A method for reading an ID card according to claim 1, characterized in that: The step S3 is to parse and verify the ID card data, specifically: The data format of the historical bytes of the reset response data ATR and the unique identity identifier UID is adjusted, split and reorganized, the header information, historical bytes and check part of the ATR are verified and reorganized, and new check bytes are added, and the integrity is calculated according to the check rules.
5. The ID card reading method according to claim 1, characterized in that: After step S3, the following steps are also included: S4. Parse the identity document information according to the data format rules, obtain the name, ID number, date of birth, address, age and head portrait data, and then display them visually.
6. An ID card reading terminal, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are implemented: S1. Initialize the decryption card module and obtain the decryption card security information: S2, sending a read instruction to the ID card reading module, and obtaining the ID card data returned by the ID card reading module, including the reset response data ATR and the unique identity identifier UID; S3, parsing and verifying the ID card data, and using the decryption card security information to decrypt the ID card data to obtain identity certification information.
7. An ID card reading terminal according to claim 6, characterized in that: The step S1 is specifically as follows: S11, sending a card search instruction to the card decryption module; S12, sending a power-on instruction to the card decryption module after the card is successfully found; S13, after the decryption card module is powered on successfully, multiple APDU instructions are sent to interact with the decryption card module, and decryption card security information is generated; S14, sending the generated decrypted card security information to the background interface for legitimacy verification; S15. After verification, the initialization of the decryption card module is completed.
8. An ID card reading terminal according to claim 7, characterized in that: In step S13, multiple APDU instructions are sent to interact with the decryption card module and generate decryption card security information, specifically: The SDK execution program is used to send multiple APDU instructions to the decryption card module and obtain a response, read the card control data, obtain the card ID and ciphertext key of the decryption card, and use the ciphertext key to encrypt the random number and return it to the decryption card module for verification. If the verification passes, the authentication is successful and the decryption card security information is generated at the same time. Otherwise, the communication is terminated and an initialization failure notification is returned.
9. An ID card reading terminal according to claim 6, characterized in that: The step S3 is to parse and verify the ID card data, specifically: The data format of the historical bytes of the reset response data ATR and the unique identity identifier UID is adjusted, split and reorganized, the header information, historical bytes and check part of the ATR are verified and reorganized, and new check bytes are added, and the integrity is calculated according to the check rules.
10. An ID card reading terminal according to claim 6, characterized in that: After step S3, the following steps are also included: S4. Parse the identity document information according to the data format rules, obtain the name, ID number, date of birth, address, age and head portrait data, and then display them visually.