SIM (Subscriber Identity Module) card self-service card-writing pre-checking method combined with multiple checking mechanisms

By introducing multiple verification mechanisms in the self-service card writing technology, including verification of card type, card status, ICCID and verification code, the problem of low security of password or PIN code verification in the prior art is solved, and higher security and reliability are achieved, protecting the security of users and equipment.

CN120050655AActive Publication Date: 2025-05-27EASTCOMPEACE TECH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510165741.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-27
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

In the existing self-service card writing technology, password verification or PIN verification methods have low security problems and are easily stolen. A single verification method is difficult to resist various security threats, and users lack security awareness.

Method used

The SIM card self-service card writing pre-check method is adopted, including card type verification, card status verification, ICCID verification and verification code verification, and the system's security and reliability are improved through the multi-check verification mechanism.

Benefits of technology

Through the multiple verification mechanism, the security of the self-service card writing process is significantly improved, ensuring that only legal and valid cards can pass the verification and perform subsequent operations, effectively eliminating the risk operations of illegal users, and protecting the legitimate rights and interests of users and the credibility and security of self-service equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050655A_ABST
    Figure CN120050655A_ABST
Patent Text Reader

Abstract

The invention provides an SIM (Subscriber Identity Module) card self-service card writing pre-checking method combined with multiple checking mechanisms, which comprises the following steps of: pre-defining a card type and a card state of an SIM card and a generation rule of a verification code before a service is started; the method comprises the following steps of: before card writing operation, automatically triggering a multi-check mechanism 1, respectively and automatically checking the card type and the card state of the SIM card according to a sequence by the mechanism, and starting a multi-check mechanism 2 if the checking is passed; in the multi-verification mechanism 2, displaying the ICCID of the SIM card to the user for confirmation, if the ICCID passes the confirmation, reading the number of times of inputting the verification code, and judging whether the SIM card is locked or not; if the SIM card is not locked, the system pops up an interface for inputting a verification code, and the user inputs the obtained verification code; and the SIM card analyzes and verifies the verification code input by the user, and if the verification is passed, a self-service card writing process is started, and the card state of the SIM card is updated to be used. According to the invention, the safety and reliability of the system can be improved, and the safety requirement of a user on self-service equipment is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the technical field of mobile communications, and in particular to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism. Background Art

[0002] With the rapid development of science and technology, self-service equipment is becoming more and more popular in daily life, bringing great convenience to people's lives. As an important technology in self-service equipment, self-service card writing technology is widely used in various scenarios, such as self-service recharge, self-service business, etc. Existing self-service card writing technology mainly relies on password verification or PIN code verification to ensure the security of operation.

[0003] In the existing self-service card writing system, the user usually needs to enter the correct password or PIN code on the user equipment (UE). After the system receives the verification information entered by the user, it performs verification processing. If the verification passes, the system allows the user to perform subsequent card writing operations, such as recharging, information query or modification, etc. This verification method meets the requirements of self-service equipment for convenient operation to a certain extent due to its simplicity and feasibility.

[0004] However, as network security threats become increasingly severe, existing password verification or PIN code verification methods have gradually exposed the problem of low security. Specifically, there are the following security risks:

[0005] Passwords or PIN codes are easily stolen: Attackers can steal passwords or PIN codes entered by users through various means, such as keyloggers, network sniffing, etc. Once the password or PIN code is stolen, the attacker can impersonate the legitimate user to perform illegal operations, thus threatening the security of user data and privacy.

[0006] Single verification method: Existing self-service card writing technology usually only uses a password or PIN code as a verification method, lacking a multiple verification mechanism. This single verification method makes the system more vulnerable to attacks and difficult to effectively resist various security threats.

[0007] Lack of user security awareness: Some users lack awareness of password or PIN protection when using self-service devices, and are prone to setting weak passwords or leaking password information, further increasing the security risks of the system.

[0008] In summary, the password verification or PIN code verification method in the existing self-service card writing technology has obvious security issues, and it is urgent to propose a more secure and reliable verification method to ensure the security of user data and privacy. Summary of the invention

[0009] In view of the deficiencies in the prior art, the present invention provides a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism, which can improve the security and reliability of the system and meet the user's security requirements for self-service equipment.

[0010] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0011] A SIM card self-service card writing pre-verification method combined with a multiple verification mechanism comprises the following steps:

[0012] Before starting the service, predefine the SIM card type, card status and verification code generation rules;

[0013] When purchasing a SIM card of a specified card type, a verification code corresponding to the SIM card is obtained simultaneously;

[0014] Before the card writing operation, the multiple verification mechanism 1 is automatically triggered, which automatically verifies the card type and card status of the SIM card in sequence. If the verification passes, the multiple verification mechanism 2 is started;

[0015] In the multi-verification mechanism 2, the ICCID of the SIM card is first displayed to the user for confirmation. If the user confirms, the number of times the verification code is entered is read to determine whether the SIM card is locked;

[0016] If the SIM card is not locked, the system will pop up a verification code input interface, and the user will enter the obtained verification code;

[0017] The SIM card parses and verifies the verification code entered by the user. If the verification passes, the self-service card writing process is started and the card status of the SIM card is updated to used.

[0018] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the card type definition includes: the card type file name is a preset specific code, and the card type is a SIM card type combined with a multiple verification mechanism; wherein, before the card writing operation is performed, the multiple verification mechanism is automatically triggered;

[0019] The card status definition includes: the card status file name is a preset identification code, and the card status includes an unused state, a used state and a locked state, which are respectively represented by specific numerical values, including an unused state corresponding to a numerical value "0", a locked state corresponding to a numerical value "1", and a used state corresponding to a numerical value "2".

[0020] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the verification code generation rule specifically includes:

[0021] The verification code consists of 15 pure digits, which is composed of the last 11 digits of the IMSI plus a 4-digit verification code;

[0022] The maximum number of times the verification code can be entered is a 2-digit positive integer, and is specifically defined as 2 times.

[0023] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the verification code generation algorithm includes:

[0024] The encrypted data item is the last 16 digits of the ICCID and a combination string consisting of the specific string "94600" and the last 11 digits of the IMSI;

[0025] The encryption key is K1, which is divided into two parts: the first 16 bits and the last 16 bits, which are used for single DES operation respectively;

[0026] Among them, the encryption and decryption algorithm adopts the DES-ECB mode.

[0027] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the verification code calculation step includes:

[0028] Step 1: Use the first 16 bits of K1 as the key and the last 16 bits of ICCID as the encrypted data to perform DES-ECB encryption operation, and take the last 2 bits of the ciphertext;

[0029] Step 2: Use the last 16 digits of K1 as the key, combine the specific string "94600" with the last 11 digits of IMSI as the encrypted data, perform DES-ECB encryption operation, and take the last 2 digits of the ciphertext;

[0030] Step 3: Combine the last two digits obtained in step 1 and step 2 into a 4-digit verification code; if a letter is generated during the combination process, divide the letter by 10 in alphabetical order and convert it to the corresponding number to form a 4-digit verification code;

[0031] Step 4: Combine the last 11 digits of the IMSI with the 4-digit verification code obtained in step 3 to obtain a 15-digit verification code.

[0032] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the specific process of the multiple verification mechanism includes the following steps:

[0033] Insert the SIM card into the UE and turn it on. The UE triggers the SIM card to read the 2F00 file, which is defined as a card type file in advance.

[0034] If the 2F00 file content read from the SIM card indicates that the card type is 01, that is, it is designated as a self-service card writing type, the process continues; otherwise, the process ends;

[0035] The SIM card reads the 2F0A file, which is defined as the card status file in advance;

[0036] If the 2F0A file content read from the SIM card indicates that the card status is 0, that is, unused, the process continues; otherwise, the process ends;

[0037] The SIM card reads the ICCID and displays it to the user, prompting the user to check whether the ICCID is consistent with the one printed on the card body;

[0038] If the user confirms that the ICCID is consistent, the process continues; otherwise, the process ends and the user needs to replace the correct card and start again;

[0039] Verification code reading steps: The SIM card reads and determines the number of times the verification code is entered. If the number of times the verification code is entered is less than 2, the process continues; if the number of times the verification code is entered reaches or exceeds 2, the card is locked and the user is prompted to go to the business hall to unlock it.

[0040] According to a SIM card self-service pre-verification method combined with a multiple verification mechanism provided by the present invention, a verification code input interface is displayed to the user, and the user enters a 15-digit verification code, which is verification code 1;

[0041] The SIM card records the number of times the verification code is entered plus 1, and analyzes whether the verification code 1 entered by the user conforms to the pre-defined verification code composition and rules;

[0042] If the verification code 1 is parsed correctly, proceed to the next step; otherwise, the verification code is wrong and return to the verification code reading step;

[0043] The SIM card generates verification code 2 according to the pre-defined verification code generation rules, and performs consistency check between verification code 2 and verification code 1 input by the user;

[0044] If verification code 1 and verification code 2 are consistent, the verification is successful and the process continues; otherwise, the verification code is wrong and returns to the verification code reading step.

[0045] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, after the verification in the multiple verification mechanism stage is passed, the SIM card updates the card status to 2, that is, the used status; the self-service card writing pre-verification process is completed, triggering the start of the subsequent self-service card writing process.

[0046] According to a SIM card self-service pre-verification method combined with a multiple verification mechanism provided by the present invention, the encryption and decryption algorithm adopts the DES-ECB mode, including:

[0047] Generate a legal DES key. The key length must be 64 bits. If the input key string is less than 8 bytes long, fill it with 0x01 for every 1 bit missing, 0x02 0x02 for every 2 bits missing, and so on.

[0048] Perform a permutation process on the generated key, replacing the 64-bit key according to the specified order or "table". The permuted key only contains the 56 valid bits of the original key;

[0049] The data to be encrypted is grouped into 64-bit blocks. If the last block is less than 64 bits long, it is also padded according to the standard ECB padding rule.

[0050] Each data block is encrypted, the encryption process includes generating a 32-bit block using a function f, the function f operates on two blocks, one is a 32-bit data block and the other is a 48-bit key Kn; wherein the calculation method of the function f includes expanding the 32-bit data block to 48 bits, and then obtaining a final 32-bit output through S-box transformation and permutation P;

[0051] In the encryption process, iterate 16 times continuously, using a different subkey in each iteration, and combine the right 32 bits of the previous result with the left 32 bits in the current step through XOR addition, and use function f to process the right 32 bits in the current step and the left 32 bits in the previous step;

[0052] Combine each encrypted data block in sequence into the final ciphertext.

[0053] According to a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism provided by the present invention, the decryption process is the reverse process of the encryption process:

[0054] Use the same key and subkey sequence, but reverse the order in which the subkeys are applied;

[0055] The ciphertext is divided into groups, and each group is decrypted. The decryption process also includes iterative calculation using the function f;

[0056] Combine each decrypted data block into the final plaintext in sequence and remove the padding bytes.

[0057] It can be seen that compared with the prior art, the present invention has the following beneficial effects:

[0058] 1. Multiple verification mechanisms are safer: The present invention greatly improves the security of the self-service card writing process by introducing multiple verification mechanisms, including card type verification, card status verification, ICCID verification and verification code verification. This mechanism can comprehensively and meticulously verify the card information submitted by the user, ensuring that only legal and valid cards can pass the verification and perform subsequent operations. For illegal cards or waste cards, the system can quickly identify and trigger the locking mechanism, effectively eliminating the possibility of illegal users using self-service equipment to perform risky operations such as card opening, which not only protects the legitimate rights and interests of users, but also maintains the reputation and security of self-service equipment.

[0059] 2. More flexible to meet different needs: The multiple verification mechanism designs of the present invention are highly flexible and can be customized according to different application scenarios and user needs. Specifically, the system can define different card types and card states according to actual needs to meet the specific requirements of different business scenarios. At the same time, the verification code generation rules can also be flexibly adjusted according to actual needs to ensure the accuracy and effectiveness of the verification process. This flexibility makes the present invention widely applicable to various self-service scenarios. Whether it is finance, telecommunications or other industries, they can find verification solutions that suit their business needs.

[0060] In summary, the present invention effectively improves the security and applicability of self-service card writing technology by introducing multiple verification mechanisms and highly flexible design ideas, which not only provides users with a safer and more convenient self-service experience, but also provides operators of self-service equipment with more reliable and efficient technical support.

[0061] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 It is a flow chart of an embodiment of a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism of the present invention.

[0063] Figure 2 It is a flow diagram of a method embodiment of a SIM card self-service pre-verification method combined with a multiple verification mechanism of the present invention. DETAILED DESCRIPTION

[0064] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0065] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0066] See also Figure 1 and Figure 2 This embodiment provides a SIM card self-service card writing pre-verification method combined with a multiple verification mechanism, the method comprising the following steps:

[0067] Step S1, before the service is started, pre-define the card type, card status and verification code generation rules of the SIM card;

[0068] Step S2, when purchasing a SIM card of a specified card type, synchronously obtaining a verification code corresponding to the SIM card;

[0069] Step S3, before the card writing operation, the multiple verification mechanism 1 is automatically triggered, and the mechanism automatically verifies the card type and card status of the SIM card in sequence. If the verification passes, the multiple verification mechanism 2 is started;

[0070] Step S4, in the multiple verification mechanism 2, the ICCID of the SIM card is first displayed to the user for confirmation. If the user confirms that it is passed, the number of times the verification code is entered is read, and it is determined whether the SIM card is locked;

[0071] Step S5: If the SIM card is not locked, the system pops up an interface for inputting a verification code, and the user inputs the obtained verification code;

[0072] Step S6, the SIM card parses and verifies the verification code input by the user. If the verification passes, the self-service card writing process is started and the card status of the SIM card is updated to used.

[0073] Therefore, this embodiment defines the card type, card status and verification code generation rules in advance, writes the defined card type and card status, and pre-set card data ICCID, K1 and other data into the card during the card making stage, and prints the ICCID on the SIM card body. In the second step, the user purchases a SIM card of this card type, obtains the verification code, inserts the SIM card into the UE and turns it on, and the SIM card starts the multiple verification mechanism 1, automatically verifies the card type and card status in sequence, and the multiple verification mechanism 1 can effectively prevent illegal cards. After the multiple verification mechanism 1 passes, the multiple verification mechanism 2 is started to verify the user operation, first display the ICCID to the user for confirmation, read the verification code input times after confirmation, and determine whether the card is locked. If it is not locked, the verification code input interface pops up for the user to enter the verification code, and the SIM card parses and verifies the verification code. If the verification passes, the self-service card writing process is started, and the card status is updated to be used. The multiple verification mechanism 2 can effectively prevent illegal users. Therefore, through the multiple verification mechanism 1 and the multiple verification mechanism 2, an efficient and safe SIM card self-service card writing method is realized.

[0074] In this embodiment, the card type definition includes: the card type file name is a preset specific code, such as "XX" is specifically "2F00" or other specified codes, and the card type, such as "01" specifically corresponding to "XX", is a SIM card type combined with a multiple verification mechanism; wherein, before the card writing operation is performed, the multiple verification mechanism is automatically triggered to ensure the accuracy and security of the card writing process; the multiple verification mechanism includes but is not limited to at least one of password verification, identity verification and data integrity verification. Example: the card type file name is 2F00, and the card type is 01.

[0075] In this embodiment, the card status definition includes: the card status file name is a preset identification code, such as "XX" is specifically "2F0A", and the card status includes an unused state (default value), a used state and a locked state, which are respectively represented by specific values, including an unused state corresponding to a value "0", a locked state corresponding to a value "1", and a used state corresponding to a value "2. The definition and representation of the card status facilitates the system to track and manage the use of the SIM card, and the system can perform corresponding operations or restrictions according to different card states to ensure the safe use and management efficiency of the SIM card.

[0076] In this embodiment, the verification code generation rules specifically include:

[0077] The verification code consists of 15 pure digits, which is composed of the last 11 digits of the IMSI plus a 4-digit verification code;

[0078] The maximum number of times the verification code can be entered is a 2-digit positive integer, and the example defines the maximum number of times the verification code can be entered as 2.

[0079] In this embodiment, the verification code generation algorithm includes:

[0080] The encrypted data item is the last 16 digits of the ICCID and a combination string consisting of the specific string "94600" and the last 11 digits of the IMSI;

[0081] The encryption key is K1, which is divided into two parts: the first 16 bits and the last 16 bits, which are used for single DES operation respectively;

[0082] Among them, the encryption and decryption algorithm adopts the DES-ECB mode.

[0083] In this embodiment, the verification code calculation steps include:

[0084] Step 1: Use the first 16 bits of K1 as the key and the last 16 bits of ICCID as the encrypted data to perform DES-ECB encryption operation, and take the last 2 bits of the ciphertext;

[0085] Step 2: Use the last 16 digits of K1 as the key, combine the specific string "94600" with the last 11 digits of IMSI as the encrypted data, perform DES-ECB encryption operation, and take the last 2 digits of the ciphertext;

[0086] Step 3: Combine the last two digits obtained in step 1 and step 2 into a 4-digit verification code; if a letter is generated during the combination process, divide the letter by 10 in alphabetical order and convert it to the corresponding number to form a 4-digit verification code;

[0087] Step 4: Combine the last 11 digits of the IMSI with the 4-digit verification code obtained in step 3 to obtain a 15-digit verification code.

[0088] Specifically, the business system obtains the corresponding encrypted data item and encryption key according to the verification code generation rule, thereby generating a verification code and providing it to the user.

[0089] Verification code calculation example:

[0090] Encrypted data items: ICCID: 8986000012A9F0010768, IMSI: 460025484200768.

[0091] Encryption key: K1: D425F4BCCBAB8D2FCDFD0B0DA5EF21A4.

[0092] Step 1: Use the first 16 bits of K1 (D425F4BCCBAB8D2F) as the key, and the last 16 bits of ICCID (000012A9F0010768) as the encrypted data. Use the encryption algorithm DES-ECB to get the ciphertext (B368FB2D1CD766BF), and take the last 2 bits of the ciphertext (BF).

[0093] Step 2: The last 16 digits of K1 (CDFD0B0DA5EF21A4) are used as the key, "94600" + the last 11 digits of IMSI (9460025484200768) are used as the encrypted data, and the encryption algorithm DES-ECB is used to obtain the ciphertext (67030AC8DBAC37C0), and the last 2 digits of the ciphertext (C0) are taken;

[0094] Step 3: Combine the last 2 digits of step 1 (BF) and the last 2 digits of step 2 (C0) to form a 4-digit verification code (BFC0). The letters in the verification code are divided by 10 and the remainder is taken. B is 1, F is 5, and C is 2, and a 4-digit verification code (1520) is obtained.

[0095] Step 4: The last 11 digits of IMSI (25484200768) + 4-digit verification code (1520) will give you a 15-digit verification code (254842007681520).

[0096] In this embodiment, the specific process of the multiple verification mechanism includes the following steps:

[0097] Insert the SIM card into the UE and turn it on. The UE triggers the SIM card to read the 2F00 file (2F00 is defined as a card type file in advance). The file is defined as a card type file in advance.

[0098] If the 2F00 file content read from the SIM card indicates that the card type is 01, that is, it is designated as a self-service card writing type, the process continues; otherwise, the process ends;

[0099] The SIM card reads the 2F0A file (2F00 is defined as the card status file in advance), which is defined as the card status file in advance;

[0100] If the 2F0A file content read from the SIM card indicates that the card status is 0, that is, unused, the process continues; otherwise, the process ends;

[0101] The SIM card reads the ICCID and displays it to the user, prompting the user to check whether the ICCID is consistent with the one printed on the card body;

[0102] If the user confirms that the ICCID is consistent, the process continues; otherwise, the process ends and the user needs to replace the correct card and start again;

[0103] Verification code reading steps: The SIM card reads and determines the number of times the verification code has been entered. If the number of times the verification code has been entered is less than 2, the process continues; if the number of times the verification code has been entered reaches or exceeds 2, the card is locked and the user is prompted to go to the business hall to unlock it.

[0104] Display the verification code input interface to the user, and the user enters the 15-digit verification code, which is verification code 1;

[0105] The SIM card records the number of times the verification code is entered plus 1, and analyzes whether the verification code 1 entered by the user conforms to the pre-defined verification code composition and rules;

[0106] If the verification code 1 is parsed correctly, proceed to the next step; otherwise, the verification code is wrong and return to the verification code reading step;

[0107] The SIM card generates verification code 2 according to the pre-defined verification code generation rules, and performs consistency check between verification code 2 and verification code 1 input by the user;

[0108] If verification code 1 and verification code 2 are consistent, the verification is successful and the process continues; otherwise, the verification code is wrong and returns to the verification code reading step.

[0109] After the verification in the multiple verification mechanism stage is passed, the SIM card updates the card status to 2, that is, the used status; the self-service card writing pre-verification process is completed, triggering the subsequent self-service card writing process.

[0110] In this embodiment, the encryption and decryption algorithm adopts the DES-ECB mode, including:

[0111] Generate a legal DES key. The key length must be 64 bits. If the input key string is less than 8 bytes long, fill it with 0x01 for every 1 bit missing, 0x02 0x02 for every 2 bits missing, and so on.

[0112] Perform a permutation process on the generated key, replacing the 64-bit key according to the specified order or "table". The permuted key only contains the 56 valid bits of the original key;

[0113] The data to be encrypted is grouped into 64-bit blocks. If the last block is less than 64 bits long, it is also padded according to the standard ECB padding rule.

[0114] Each data block is encrypted, the encryption process includes generating a 32-bit block using a function f, the function f operates on two blocks, one is a 32-bit data block and the other is a 48-bit key Kn; wherein the calculation method of the function f includes expanding the 32-bit data block to 48 bits, and then obtaining a final 32-bit output through S-box transformation and permutation P;

[0115] In the encryption process, iterate 16 times continuously, using a different subkey in each iteration, and combine the right 32 bits of the previous result with the left 32 bits in the current step through XOR addition, and use function f to process the right 32 bits in the current step and the left 32 bits in the previous step;

[0116] Combine each encrypted data block in sequence into the final ciphertext.

[0117] In the decryption process, it is the reverse process of the encryption process:

[0118] Use the same key and subkey sequence, but reverse the order in which the subkeys are applied;

[0119] The ciphertext is divided into groups, and each group is decrypted. The decryption process also includes iterative calculation using the function f.

[0120] Combine each decrypted data block into the final plaintext in sequence and remove the padding bytes.

[0121] The DES-ECB mode encryption and decryption algorithm of this embodiment pays special attention to the security of the key and the integrity of the data during the implementation process. The validity of the key is ensured through strict key generation and preprocessing steps, and the integrity and encryptability of the data block are ensured through standard ECB padding rules. In the encryption process, the strength and security of the encryption are improved through multiple iterations and complex calculations of the function f, making the ciphertext difficult to crack. In the decryption process, the correctness and consistency of the decryption result are ensured by reversing the steps of the encryption process and the subkey order.

[0122] In summary, this embodiment effectively improves the security and applicability of self-service card writing technology by introducing multiple verification mechanisms and highly flexible design ideas. This not only provides users with a safer and more convenient self-service experience, but also provides operators of self-service equipment with more reliable and efficient technical support.

[0123] Specifically, this embodiment greatly improves the security of the self-service card writing process by introducing multiple verification mechanisms, including card type verification, card status verification, ICCID verification, and verification code verification. This mechanism can comprehensively and meticulously verify the card information submitted by the user, ensuring that only legal and valid cards can pass the verification and perform subsequent operations. For illegal cards or invalid cards, the system can quickly identify and trigger the locking mechanism, effectively eliminating the possibility of illegal users using self-service devices to perform risky operations such as card opening, which not only protects the legitimate rights and interests of users, but also maintains the reputation and security of self-service devices.

[0124] Specifically, the multiple verification mechanism designs of this embodiment are highly flexible and can be customized according to different application scenarios and user needs. Specifically, the system can define different card types and card states according to actual needs to meet specific requirements in different business scenarios. At the same time, the verification code generation rules can also be flexibly adjusted according to actual needs to ensure the accuracy and effectiveness of the verification process. This flexibility enables the present invention to be widely applicable to various self-service scenarios. Whether it is finance, telecommunications or other industries, they can find verification solutions that suit their business needs.

[0125] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0126] The above-mentioned embodiments are only preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and substitutions made by technicians in this field on the basis of the present invention shall fall within the scope of protection required by the present invention.

Claims

1. A SIM card self-service pre-verification method combining multiple verification mechanisms, characterized in that: The following steps are involved: Before starting the service, predefine the SIM card type, card status and verification code generation rules; When purchasing a SIM card of a specified card type, a verification code corresponding to the SIM card is obtained simultaneously; Before the card writing operation, the multiple verification mechanism 1 is automatically triggered, which automatically verifies the card type and card status of the SIM card in sequence. If the verification passes, the multiple verification mechanism 2 is started; In the multi-verification mechanism 2, the ICCID of the SIM card is first displayed to the user for confirmation. If the user confirms, the number of times the verification code is entered is read to determine whether the SIM card is locked; If the SIM card is not locked, the system will pop up a verification code input interface, and the user will enter the obtained verification code; The SIM card parses and verifies the verification code entered by the user. If the verification passes, the self-service card writing process is started and the card status of the SIM card is updated to used.

2. The method according to claim 1, characterized in that: The card type definition includes: the card type file name is a preset specific code, and the card type is a SIM card type combined with a multiple verification mechanism; wherein the multiple verification mechanism is automatically triggered before the card writing operation is performed; The card status definition includes: the card status file name is a preset identification code, and the card status includes an unused state, a used state and a locked state, which are respectively represented by specific values, including an unused state corresponding to a value "0", a locked state corresponding to a value "1", and a used state corresponding to a value "2".

3. The method according to claim 2, characterized in that: The verification code generation rules specifically include: The verification code consists of 15 pure digits, which is composed of the last 11 digits of the IMSI plus a 4-digit verification code; The maximum number of times the verification code can be entered is a 2-digit positive integer, and is specifically defined as 2 times.

4. The method according to claim 3, characterized in that: The verification code generation algorithm includes: The encrypted data item is the last 16 digits of the ICCID and a combination string consisting of the specific string "94600" and the last 11 digits of the IMSI; The encryption key is K1, which is divided into two parts: the first 16 bits and the last 16 bits, which are used for single DES operation respectively; Among them, the encryption and decryption algorithm adopts the DES-ECB mode.

5. The method according to claim 4, characterized in that The verification code calculation steps include: Step 1: Use the first 16 bits of K1 as the key and the last 16 bits of ICCID as the encrypted data to perform DES-ECB encryption operation, and take the last 2 bits of the ciphertext; Step 2: Use the last 16 digits of K1 as the key, combine the specific string "94600" and the last 11 digits of IMSI as the encrypted data, perform DES-ECB encryption operation, and take the last 2 digits of the ciphertext; Step 3: Combine the last two digits obtained in step 1 and step 2 into a 4-digit verification code; if a letter is generated during the combination process, divide the letter by 10 in alphabetical order and convert it to the corresponding number to form a 4-digit verification code; Step 4: Combine the last 11 digits of the IMSI with the 4-digit verification code obtained in step 3 to obtain a 15-digit verification code.

6. The method according to claim 1, characterized in that: The specific process of the multiple verification mechanism includes the following steps: Insert the SIM card into the UE and turn it on. The UE triggers the SIM card to read the 2F00 file, which is defined as a card type file in advance. If the 2F00 file content read from the SIM card indicates that the card type is 01, that is, it is designated as a self-service card writing type, the process continues; otherwise, the process ends; The SIM card reads the 2F0A file, which is defined as the card status file in advance; If the 2F0A file content read from the SIM card indicates that the card status is 0, that is, unused, the process continues; otherwise, the process ends; The SIM card reads the ICCID and displays it to the user, prompting the user to check whether the ICCID is consistent with the one printed on the card body; If the user confirms that the ICCID is consistent, the process continues; otherwise, the process ends and the user needs to replace the correct card and start again; Verification code reading steps: The SIM card reads and determines the number of times the verification code has been entered. If the number of times the verification code has been entered is less than 2, the process continues; if the number of times the verification code has been entered reaches or exceeds 2, the card is locked and the user is prompted to go to the business hall to unlock it.

7. The method according to claim 6, characterized in that: Display the verification code input interface to the user, and the user enters the 15-digit verification code, which is verification code 1; The SIM card records the number of times the verification code is entered plus 1, and analyzes whether the verification code 1 entered by the user conforms to the pre-defined verification code composition and rules; If the verification code 1 is parsed correctly, proceed to the next step; Otherwise, the verification code is wrong, and the process returns to the verification code reading step; The SIM card generates verification code 2 according to the pre-defined verification code generation rules, and performs consistency check between verification code 2 and verification code 1 input by the user; If verification code 1 and verification code 2 are consistent, the verification passes and the process continues; Otherwise, the verification code is wrong and returns to the verification code reading step.

8. The method according to claim 7, characterized in that: After the verification in the multiple verification mechanism stage is passed, the SIM card updates the card status to 2, that is, the used status; the self-service card writing pre-verification process is completed, triggering the start of the subsequent self-service card writing process.

9. The method according to claim 4, characterized in that The encryption and decryption algorithm adopts the DES-ECB mode, including: Generate a legal DES key. The key length must be 64 bits. If the input key string is less than 8 bytes long, fill it with 0x01 for every 1 bit missing, 0x02 0x02 for every 2 bits missing, and so on. Perform a permutation process on the generated key, replacing the 64-bit key according to the specified order or "table". The permuted key only contains the 56 valid bits of the original key; The data to be encrypted is grouped into 64-bit blocks. If the last block is less than 64 bits long, it is also padded according to the standard ECB padding rule. Each data block is encrypted, the encryption process includes generating a 32-bit block using a function f, the function f operates on two blocks, one is a 32-bit data block and the other is a 48-bit key Kn; wherein the calculation method of the function f includes expanding the 32-bit data block to 48 bits, and then obtaining a final 32-bit output through S-box transformation and permutation P; In the encryption process, iterate 16 times continuously, using a different subkey in each iteration, and combine the right 32 bits of the previous result with the left 32 bits in the current step through XOR addition, and use function f to process the right 32 bits in the current step and the left 32 bits in the previous step; Combine each encrypted data block in sequence into the final ciphertext.

10. The method according to claim 9, characterized in that: In the decryption process, it is the reverse process of the encryption process: Use the same key and subkey sequence, but reverse the order in which the subkeys are applied; The ciphertext is divided into groups, and each group is decrypted. The decryption process also includes iterative calculation using the function f. Combine each decrypted data block into the final plaintext in sequence and remove the padding bytes.

Citation Information

Patent Citations

  • A telecom intelligent card, an air card writing system and an air card writing method

    CN101547437A

  • POS terminal eSIM card remote burning method, device and system and storage medium

    CN118574106A

  • Information acquisition method and device, equipment and computer storage medium

    CN118798235A

  • Method for restoring identification card operation function of temporary functionloss customer and mobile communication apparatus

    CN1710971A

  • Simulacrum of physical security device and methods

    US20120117635A1