Card issuing system based on root key parallel mechanism

By introducing a root key parallel mechanism in the card issuing system, it supports the parallel use of multiple sets of root keys, solving the problems of existing systems in terms of security, flexibility and resource utilization efficiency, and achieving higher security, flexibility and economicality.

CN120146087APending Publication Date: 2025-06-13EASTCOMPEACE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510155191.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing card issuing systems have many problems in terms of security, flexibility and resource utilization efficiency, including the security risks of a single card root key, resource waste and mutual interference between services.

Method used

The root key parallel mechanism is introduced to support the parallel use of multiple sets of root keys. Through the coordinated work of the card identity identification module, card issuing process control module, card making module, card issuing module and hardware encryption machine, flexible key management and automatic matching of business processes are achieved.

Benefits of technology

It improves the security and flexibility of the system, disperses the risk of single key leakage, reduces resource waste and user inconvenience, and optimizes the overall operating efficiency and economics of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120146087A_ABST
    Figure CN120146087A_ABST
Patent Text Reader

Abstract

The invention provides a card issuing system based on a root key parallel mechanism, and the system comprises a card identity recognition module which is used for recognizing the identity of a card according to a business type, and marking a unique card identity ID for each card; the card issuing process control module is used for managing the matching relation between the card ID and the corresponding card issuing process and the card writing root key ID; the card making module is used for carrying out card identity identification on the incremental card according to the card identity of the incremental card; the card issuing module is used for responding to a card issuing request initiated by a service party and completing a corresponding card issuing function; and the hardware encryption machine is used for storing and calling the secret key, managing the mapping relation between the secret key ID and the secret key value, and completing the acquisition of the corresponding secret key value and the data encryption and decryption operation according to the requests of the card making module and the card issuing module. By introducing a root key parallel mechanism, simultaneous existence and parallel use of a plurality of sets of root keys are realized, so that the security, flexibility and resource utilization efficiency of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a card-issuing system based on a root key parallel mechanism. Background Art

[0002] In existing card-issuing systems, a mechanism based on a write card root key is usually adopted to ensure the security and uniqueness of card data. When the system is enabled, a write card root key is generated, which serves as the core security element of the entire card-issuing system and undertakes the important responsibilities of discrete processing and one-card-one-password identity authentication. However, with the continuous development of technology and the increasing severity of security threats, a series of problems have gradually emerged in the security and flexibility of existing card-issuing systems.

[0003] Firstly, the existing mechanism based on a single write card root key has obvious security risks. Once this key is leaked or cracked by attackers through various means, the security of the entire card-issuing system will be seriously threatened. Attackers may use this key to forge cards, tamper with data, or even launch malicious attacks on the system, resulting in system paralysis or data loss. In addition, since different services usually share the same key and process in the card-issuing system, this mutual interference between services further exacerbates the security risks and stability problems of the system.

[0004] Secondly, existing card-issuing systems face the problem of resource waste when upgrading security measures. To cope with emerging security threats, the system may need to regularly replace the write card root key or adopt more advanced encryption technologies. However, such upgrades often require replacing all cards, which not only requires a large amount of human, material, and time costs, but also brings great inconvenience to users. Users may need to reapply for cards, update relevant information, and even face service interruptions caused by card replacement.

[0005] Finally, existing card-issuing systems also have deficiencies in business isolation. Since different services usually use the same key and process for processing in the card-issuing system, it is difficult to ensure the security isolation between different services. Once a security problem occurs in a certain service, it is very likely to affect other services, threatening the security of the entire system. This mutual interference between services not only affects the security of the system, but also limits the system's flexible support for diverse business requirements.

[0006] In summary, existing card-issuing systems have many problems in terms of security and flexibility, and there is an urgent need for a more secure, flexible, and efficient card-issuing mechanism to replace the existing mechanism based on a single write card root key. Summary of the Invention

[0007] In view of the above problems existing in the prior art, the present invention provides a card-issuing system based on a root key parallel mechanism. By introducing the root key parallel mechanism, multiple sets of root keys can coexist and be used in parallel, thereby improving the security, flexibility, and resource utilization efficiency of the system.

[0008] The present invention achieves the above object through the following technical solutions:

[0009] A card-issuing system based on a root key parallel mechanism, comprising:

[0010] A card identity recognition module, configured to recognize the identity of a card according to the service type and assign a unique card identity ID to each card;

[0011] A card-issuing process control module, configured to manage the matching relationship between the card identity ID, its corresponding card-issuing process, and the write card root key ID;

[0012] A card production module, configured to provide an interface for filling in basic information and identify the card identity of an incremental card according to the card identity of the incremental card;

[0013] A card-issuing module, configured to respond to a card-issuing request initiated by a service party and complete the corresponding card-issuing function according to the process and write card root key ID returned by the card-issuing process control module;

[0014] A hardware encryption machine, configured to store and call keys, manage the mapping relationship between the key ID and the key value, and complete the acquisition of the corresponding key value and data encryption and decryption operations according to the requests of the card production module and the card-issuing module;

[0015] Among them, the card-issuing system supports multiple sets of root keys in parallel. When the key needs to be upgraded, the system first completes the preparation work for the new service, then configures a new service type in the card-issuing system, matches the new key ID and the new service rules; at the same time, mark the original service type on the existing cards, and automatically mark the new service type on the incremental cards during the card production process of subsequent incremental cards and store them in the database; when the service system initiates a write card request, read the card serial number of the card, correspond it with the card mark in the database, and call the corresponding root key and service process according to the card mark.

[0016] According to the card-issuing system based on a root key parallel mechanism provided by the present invention, when performing key configuration, the specific steps are as follows:

[0017] The service initiator operates the hardware encryption machine to send a request to the hardware encryption machine to generate a new write card root key;

[0018] The hardware encryption machine generates a new write card root key according to the parameters provided by the service initiator;

[0019] The hardware encryption machine returns a new card writing root key ID to the service initiator, and the card writing root key ID is used for the subsequent configuration of new service types;

[0020] The service initiator defines corresponding discrete rules according to the received new card root key ID.

[0021] According to a card issuance system based on a root key parallel mechanism provided by the present invention, when performing business preparation, the specific steps are as follows:

[0022] The service initiator initiates a request to configure a new service type in the card issuing system and provides the parameters required for the new service type;

[0023] The card issuing system configures the new service type according to the parameters provided by the service initiator, and matches the new service type with the card type, the new card root key ID and the discrete rule;

[0024] The card issuing system returns the configuration result of the new business type to the business initiator;

[0025] The business initiator initiates a request to enable a new business type in the card issuing system;

[0026] The card issuing system reads the card identity ID field of the stock card in the database, and updates the stock card whose card identity ID is empty to the original card identity ID; and keeps the identity ID unchanged for the stock card whose card identity ID is not empty;

[0027] The card issuing system returns the activation result of the new service type to the service initiator.

[0028] According to a card issuance system based on a root key parallel mechanism provided by the present invention, in the card making stage, a card writing root key stored in an encryption machine is used to generate a unique one-card-one-key for each card according to a discrete rule customized by the business;

[0029] Associating the generated one-card-one-password with the corresponding card and storing it;

[0030] In the card writing phase, the same card writing root key and discrete rule are used again to calculate the card-specific secret for each card;

[0031] Compare the one-card-one-secret code calculated at the card writing stage with the one-card-one-secret code stored at the card making stage;

[0032] If the two are consistent, the verification is successful and the card is confirmed to be a legal card; if the two are inconsistent, the verification fails and the card is determined to be an illegal card.

[0033] According to a card issuing system based on a root key parallel mechanism provided by the present invention, after the card issuing system receives a card making request from a business initiator, the card issuing system searches and determines the card writing root key ID and discrete rules corresponding to the card type from a preset key management system according to the card type in the request; based on the card writing root key ID and discrete rules, the card issuing system sends a one-card-one-secret generation request containing the number of cards made to the hardware encryption machine, so as to trigger the hardware encryption machine to generate one-card-one-secret data matching the number of cards made.

[0034] According to a card issuing system based on a root key parallel mechanism provided by the present invention, the hardware encryption machine obtains the corresponding card writing root key from a secure storage area according to the card writing root key ID in the one-card-one-secret generation request sent by the card issuing system; then, the hardware encryption machine generates the one-card-one-secret data required for card making by using the card writing root key and discrete rules, and returns the generated one-card-one-secret data to the card issuing system; after receiving the one-card-one-secret data, the card issuing system combines other card making data generated by itself to form a complete card making data set corresponding to the number of cards made; finally, the card issuing system stores the complete card making data set, matches and stores the corresponding card identification information in the database according to the card serial number in the card making data set, and returns the complete card making data set to the business initiator.

[0035] According to a card issuing system based on a root key parallel mechanism provided by the present invention, after the card issuing system starts the corresponding card issuing process, the card writing data corresponding to the card serial number is obtained from a preset card writing database according to the read card serial number; the card issuing system initiates a one-card-one-secret calculation request to the hardware encryption machine, and the request includes a card writing root key ID and a discrete rule for generating a one-card-one-secret, so that the hardware encryption machine can generate a corresponding one-card-one-secret based on this information.

[0036] According to a card issuing system based on a root key parallel mechanism provided by the present invention, after receiving a one-card-one-secret calculation request from the card issuing system, the hardware encryption machine calls the corresponding card writing root key stored in the security area; then, the hardware encryption machine generates a one-card-one-secret corresponding to the card serial number according to the provided discrete rules and the called card writing root key; finally, the hardware encryption machine returns the generated one-card-one-secret to the card issuing system for the subsequent card writing operation of the card issuing system.

[0037] According to a card issuing system based on a root key parallel mechanism provided by the present invention, after receiving a card-one-key message returned by a hardware encryption machine, the card issuing system assembles a card writing instruction according to the card-one-key message; the card issuing system issues the assembled card writing instruction to the inserted card issuing card, and the card executes the card writing operation after receiving the card writing instruction; the card issuing system analyzes the card writing result, and after confirming that the card writing is successful, executes subsequent business processes; the card issuing system outputs the card issuing result to the business initiator, including information on the success or failure of the card issuing, and related card information.

[0038] A card-issuing system based on the root key parallel mechanism provided by the present invention, when defining discrete rules, specifically includes:

[0039] Taking the card merchant code as the first discrete factor for the first discrete processing to generate a first discrete value;

[0040] Taking the last 4 digits of the card serial number of the card as the second discrete factor for the second discrete processing to generate a second discrete value;

[0041] Combining the first discrete value and the second discrete value to generate a key with one key per card.

[0042] It can be seen that, compared with the prior art, the present invention has the following beneficial effects:

[0043] By introducing the root key parallel mechanism, the present invention supports the parallel operation of multiple sets of root keys, effectively dispersing the risk of a single root key being leaked or attacked and cracked. Once a security problem occurs with a certain root key, the system can immediately deactivate the key without affecting the secure operation of other services, thereby greatly enhancing the security of the entire system. At the same time, different keys and processes are used for different services, achieving secure isolation between services, effectively preventing data and operations between different services from interfering with each other, and further enhancing the overall security of the system.

[0044] When adding new keys, the present invention can automatically assign new identifiers to subsequent incremental cards without the need to discard old cards. This coexistence of new and old cards not only avoids the resource waste caused by large-scale card replacement but also reduces the replacement cost and inconvenience for users. In addition, through reasonable key management and business process design, the present invention also optimizes the overall operation efficiency of the card-issuing system, reduces unnecessary resource consumption, and further improves the economy of the system.

[0045] The present invention designs different keys and business processes for different business types, enabling the system to flexibly respond to diverse business needs, not only improving the adaptability and scalability of the system but also providing strong support for future business innovation and development. At the same time, by introducing an automatic identification mechanism and a card identity recognition module, the present invention realizes the matching of keys and business processes without user perception, enabling the system to automatically select appropriate keys and processes for processing according to the identity and type of the card, further enhancing the efficiency and accuracy of business processing.

[0046] In summary, the card-issuing system and device based on the root key parallel mechanism proposed by the present invention have shown significant beneficial effects in terms of security, resource utilization, and business processing flexibility, providing a new idea and solution for the upgrade and improvement of the card-issuing system.

[0047] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. Description of the Drawings

[0048] Figure 1 It is a schematic diagram of an embodiment of a card-issuing system based on the root key parallel mechanism of the present invention.

[0049] Figure 2 It is a schematic flowchart of key configuration and service preparation implemented in an embodiment of a card-issuing system based on the root key parallel mechanism of the present invention.

[0050] Figure 3 It is a schematic diagram of the write card root key and discrete rules in an embodiment of a card-issuing system based on the root key parallel mechanism of the present invention.

[0051] Figure 4 It is a schematic flowchart of the card manufacturing process implemented in an embodiment of a card-issuing system based on the root key parallel mechanism of the present invention.

[0052] Figure 5 It is a schematic flowchart of the card-issuing process implemented in an embodiment of a card-issuing system based on the root key parallel mechanism of the present invention. Specific Embodiments

[0053] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention fall within the scope of protection of the present invention.

[0054] Reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0055] See Figure 1 , this embodiment provides a card-issuing system based on a root key parallel mechanism, including:

[0056] The card identity recognition module is used to recognize the identity of the card according to the business type and assign a unique card identity ID to each card. Among them, the card identity recognition module recognizes the identity of the card according to the business type and assigns the card identity ID. When the stock cards at the beginning of the business do not have card identity IDs, the card identity recognition module uniformly assigns card identity IDs to the stock cards. For the incremental cards generated during subsequent card production, they are uniformly assigned new card identity IDs. When a new business type is added again after the business is running, the card identity recognition module only processes the incremental cards and does not affect the stock cards.

[0057] The card issuing process control module is used to manage the matching relationship between the card identity ID and its corresponding card issuing process and the write card root key ID. Among them, the card issuing process control module manages the matching relationship between the card identity ID, its corresponding card issuing process, and the write card root key ID. After the card identity ID is obtained by the card identity recognition module through the CardSN of the initiated request, the card issuing process control module matches the card issuing process and the write card root key ID for the card identity ID.

[0058] The card production module is used to provide an interface for filling in basic information and identify the incremental cards according to the card identities of the incremental cards. Among them, the basic information includes basic information such as card production type, quantity, and card merchant.

[0059] The card issuing module is used to respond to the card issuing request initiated by the business party and complete the corresponding card issuing functions according to the process and the write card root key ID returned by the card issuing process control module, such as functions like obtaining write card data, calculating one card one password, and assembling write card instructions.

[0060] The hardware encryption machine is used for the storage and invocation of keys, the management of the mapping relationship between key IDs and key values, and according to the requests of the card production module and the card issuing module, completes the acquisition of the corresponding key values and data encryption and decryption operations.

[0061] Among them, the card issuing system supports multiple sets of root keys in parallel. When the key needs to be upgraded, the system first completes the preparation work for the new business, then configures the new business type in the card issuing system, matches the new key ID and the new business rules. At the same time, mark the stock cards with the card identifiers of the original business type, and automatically mark the incremental cards with the card identifiers of the new business type during the card production process of subsequent incremental cards and store them in the database. When the business system initiates a write card request, read the card serial number of the card and correspond it with the card identifier in the database, and call the corresponding root key and business process according to the card identifier.

[0062] When performing key configuration, the specific steps are as follows:

[0063] The business initiator operates the hardware encryption machine and initiates a request to generate a new write card root key to the hardware encryption machine;

[0064] The hardware encryption machine generates a new card writing root key based on the parameters provided by the service initiator;

[0065] The hardware encryption machine returns a new card writing root key ID to the service initiator, and the card writing root key ID is used for the subsequent configuration of new service types;

[0066] The service initiator defines corresponding discrete rules according to the received new card root key ID.

[0067] When preparing for business, the specific steps are:

[0068] The service initiator initiates a request to configure a new service type in the card issuing system and provides the parameters required for the new service type;

[0069] The card issuing system configures the new service type according to the parameters provided by the service initiator, and matches the new service type with the card type, the new card root key ID and the discrete rule;

[0070] The card issuing system returns the configuration result of the new business type to the business initiator;

[0071] The business initiator initiates a request to enable a new business type in the card issuing system;

[0072] The card issuing system reads the card identity ID field of the stock card in the database, and updates the stock card whose card identity ID is empty to the original card identity ID; for the stock card whose card identity ID is not empty, the identity ID remains unchanged;

[0073] The card issuing system returns the activation result of the new service type to the service initiator.

[0074] Specifically, Figure 2 As shown, the key configuration and service preparation process of this embodiment includes:

[0075] 1. The service initiator operates the hardware encryption machine and initiates a request to generate a new card write root key to the hardware encryption machine;

[0076] 2. The hardware encryption machine generates a new card writing root key based on the parameters of the service initiator;

[0077] 3. The hardware encryption machine returns the new card root key ID to the service initiator. The new card root key ID is used for the configuration of the new service type.

[0078] 4. The service initiator defines discrete rules based on the newly written card root key ID;

[0079] 5. The business initiator initiates a request to configure a new business type in the card issuing system;

[0080] 6. The card issuing system configures the new service type, matches the card type, the new card root key ID and the discrete rules according to the parameters provided by the service initiator;

[0081] 7. The card issuing system returns the configuration results to the business initiator;

[0082] 8. The business initiator initiates a request to enable the new business type in the card issuing system;

[0083] 9. The card issuing system reads the card ID field of the stock card in the database. If the card ID field is empty, the stock card is updated to the original card ID. If the card ID field is not empty, it is not updated.

[0084] The card issuing system returns the activation result to the business initiator.

[0085] In this embodiment, at the card production stage, the card writing root key stored in the encryption machine is used to generate a unique one-card-one-key for each card according to the discrete rules customized by the business;

[0086] Associating the generated one-card-one-password with the corresponding card and storing it;

[0087] In the card writing phase, the same card writing root key and discrete rule are used again to calculate the card-specific secret for each card;

[0088] Compare the one-card-one-secret calculated in the card writing stage with the one-card-one-secret stored in the card making stage to verify the consistency of the one-card-one-secret in the card writing stage and the card making stage;

[0089] If the two are consistent, the verification is successful and the card is confirmed to be a legal card; if the two are inconsistent, the verification fails and the card is determined to be an illegal card.

[0090] like Figure 3 As shown, in this embodiment, when defining discrete rules, it specifically includes:

[0091] The card merchant code is used as the first discrete factor for the first discrete processing to generate the first discrete value; the last 4 digits of the card serial number of the card are used as the second discrete factor for the second discrete processing to generate the second discrete value; the first discrete value and the second discrete value are combined to generate a one-card-one-secret key. Among them, the discrete rule is to use the 2-digit card merchant code as the discrete factor for the first discrete processing, and the last 4 digits of the card serial number (CardSN) as the second discrete factor, so as to obtain one-card-one-secret.

[0092] In this embodiment, after the card-issuing system receives a card-making request from the service initiator, according to the card type in the request, it searches for and determines the write card root key ID and discrete rule corresponding to the card type from the preset key management system; based on the write card root key ID and discrete rule, the card-issuing system sends a one-card-one-key generation request containing the card-making quantity information to the hardware encryption machine to trigger the hardware encryption machine to generate one-card-one-key data matching the card-making quantity.

[0093] The hardware encryption machine obtains the corresponding write card root key from the secure storage area according to the write card root key ID in the one-card-one-key generation request sent by the card-issuing system; then, the hardware encryption machine uses the write card root key and discrete rule to generate the one-card-one-key data required for card making, and returns the generated one-card-one-key data to the card-issuing system; after receiving the one-card-one-key data, the card-issuing system combines other card-making data generated by itself to synthesize a complete card-making data set corresponding to the card-making quantity; finally, the card-issuing system stores the complete card-making data set, matches and stores the corresponding card identification information in the database according to the card serial number in the card-making data set, and at the same time returns the complete card-making data set to the service initiator.

[0094] Specifically, as Figure 4 shown, the card-making process of this embodiment includes:

[0095] 1. The service initiator inputs basic information such as the card-making quantity, card merchant, and card type in the card-issuing system and then initiates a card-making request;

[0096] 2. The card-issuing system searches for the corresponding write card root key ID and discrete rule according to the card type of the card-making request;

[0097] 3. The card-issuing system sends a one-card-one-key generation request to the hardware encryption machine;

[0098] 4. Obtain the write card root key according to the write card root key ID, and generate the one-card-one-key required for card making according to the discrete rule;

[0099] 5. The hardware encryption machine returns the generated one-card-one-key to the card-issuing system;

[0100] 6. The card-issuing system generates other card-making data, and synthesizes it with the one-card-one-key data to form a complete card-making data corresponding to the card-making quantity;

[0101] 7. Match the corresponding card identification according to the CardSN (i.e., incremental card) in the card-making data, and store it in the database for subsequent card-issuing links;

[0102] 8. The card-issuing system returns the complete card-making data to the service initiator;

[0103] 9. The service initiator hands over the card-making data to the card merchant for card making and subsequent mailing and other work.

[0104] In this embodiment, after the card-issuing system starts the corresponding card-issuing process, according to the read card serial number, the card-writing data corresponding to the card serial number is obtained from the preset card-writing database; the card-issuing system sends a one-card-one-key calculation request to the hardware encryption machine, and this request contains the card-writing root key ID and the discrete rule for generating the one-card-one-key, so that the hardware encryption machine can generate the corresponding one-card-one-key according to this information.

[0105] After receiving the one-card-one-key calculation request from the card-issuing system, the hardware encryption machine calls the corresponding card-writing root key stored in the secure area; then, the hardware encryption machine generates a one-card-one-key corresponding to the card serial number according to the provided discrete rule and the called card-writing root key; finally, the hardware encryption machine returns the generated one-card-one-key to the card-issuing system for the card-issuing system to perform subsequent card-writing operations.

[0106] After receiving the one-card-one-key returned by the hardware encryption machine, the card-issuing system assembles it into a card-writing instruction; the card-issuing system sends the assembled card-writing instruction to the inserted card-issuing card, and the card performs the card-writing operation after receiving the card-writing instruction; the card-issuing system analyzes the card-writing result, and after confirming that the card-writing is successful, it executes the subsequent service process; the card-issuing system outputs the card-issuing result to the service initiator, including information on whether the card-issuing is successful or failed, and relevant card information.

[0107] Specifically, as Figure 5 shown, the card-issuing process of this embodiment includes:

[0108] 1. After the service initiator completes operations such as user authentication and payment, it sends a card-issuing request to the card-issuing system;

[0109] 2. The card-issuing system responds to the card-issuing request and reads the CardSN of the inserted card;

[0110] 3. The card-issuing system calls the card identity recognition module according to the CardSN to complete the identity recognition of the card and obtains the card identity ID;

[0111] 4. The card-issuing system calls the card-issuing process control module according to the card identity ID and matches the corresponding service process and card-writing root key ID;

[0112] 5. The card-issuing system starts the corresponding card-issuing process and obtains the corresponding card-writing data according to the CardSN;

[0113] 6. The card-issuing system sends a one-card-one-key calculation rule to the hardware encryption machine, providing the card-writing root key ID and the discrete rule;

[0114] 7. The hardware encryption machine calls the corresponding card-writing root key and generates a one-card-one-key corresponding to the CardSN according to the discrete rule;

[0115] 8. The hardware encryption machine returns a unique key corresponding to CardSN to the card-issuing system;

[0116] 9. The card-issuing system assembles a card-writing instruction according to the unique key;

[0117] 10. The card-issuing system sends the card-writing instruction to the card to complete subsequent service processes such as card writing, analysis of card-writing results, and activation;

[0118] 11. The card-issuing system outputs the card-issuing result to the service initiator.

[0119] In practical applications, through the root key parallel mechanism of the system in this embodiment, multiple sets of root keys are supported to run in parallel. When the key needs to be upgraded, new service preparation work needs to be completed first. Use the hardware encryption machine to generate a new card-writing root key and define new discrete rules. The card-issuing system configures new service types, matches new key IDs and new service rules. The second step is to mark the existing cards with the card identifiers of the original service type. Subsequently, the incremental cards are automatically marked with the card identifiers of the new service type during card production and then stored in the database. After completing the identification of all cards, when the business system initiates card writing, the CardSN is read and corresponds to the card identifier in the database. When the card identifier is of the original service type, the original root key and service process are called. When the card identifier is of the new service type, the new root key and service process are called, thus completing the card-issuing system with parallel root keys.

[0120] In summary, the system provided in this embodiment supports the parallel operation of multiple sets of root keys by introducing the root key parallel mechanism, effectively dispersing the risk of a single root key being leaked or attacked and cracked. Once a security problem occurs with a certain root key, the system can immediately deactivate the key without affecting the secure operation of other services, thus greatly enhancing the security of the entire system. At the same time, different keys and processes are used for different services, achieving secure isolation between services, effectively preventing data and operations between different services from interfering with each other, and further enhancing the overall security of the system.

[0121] When adding a new key, this embodiment can automatically mark the subsequent incremental cards with new identifiers without the need to discard the old cards. This coexistence of old and new cards not only avoids the waste of resources caused by large-scale card replacement but also reduces the replacement cost and inconvenience for users. In addition, through reasonable key management and service process design, this embodiment also optimizes the overall operation efficiency of the card-issuing system, reduces unnecessary resource consumption, and further improves the economy of the system.

[0122] In this embodiment, different keys and service processes are designed for different service types, enabling the system to flexibly respond to diverse service requirements. This not only improves the adaptability and scalability of the system but also provides strong support for future service innovation and development. At the same time, by introducing an automatic identification mechanism and a card identity recognition module, this embodiment achieves a service-unaware matching of keys and service processes, enabling the system to automatically select appropriate keys and processes for processing based on the identity and type of the card, further enhancing the efficiency and accuracy of service processing.

[0123] Therefore, the card-issuing system and device based on the root key parallel mechanism proposed in this embodiment have shown remarkable beneficial effects in terms of security, resource utilization, and service processing flexibility, providing new ideas and solutions for the upgrade and improvement of the card-issuing system.

[0124] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0125] The above embodiments are only the preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantive changes and substitutions made by those skilled in the art based on the present invention belong to the scope required to be protected by the present invention.

Claims

1. A card issuance system based on a root key parallel mechanism, characterized in that: include: The card identification module is used to identify the identity of the card according to the business type and to identify a unique card ID for each card; The card issuance process control module is used to manage the matching relationship between the card identity ID and its corresponding card issuance process and the card writing root key ID; The card making module is used to provide an interface for filling in basic information and to identify the incremental card according to its card identity; The card issuance module is used to respond to the card issuance request initiated by the business party and complete the corresponding card issuance function according to the process and card writing root key ID returned by the card issuance process control module; The hardware encryption machine is used for key storage and call, as well as the management of the mapping relationship between key ID and key value, and completes the acquisition of corresponding key value and data encryption and decryption operations according to the request of card making module and card issuing module; Among them, the card issuing system supports multiple sets of root keys in parallel. When the key needs to be upgraded, the system first completes the new business preparation, and then configures the new business type in the card issuing system to match the new key ID and new business rules; at the same time, the card identification of the original business type is marked on the existing cards, and the card identification of the new business type is automatically marked on the incremental cards during the subsequent incremental card making process and stored in the database; when the business system initiates a card write request, the card serial number of the card is read and matched with the card identification in the database, and the corresponding root key and business process are called according to the card identification.

2. The system according to claim 1, characterized in that: When configuring the key, the specific steps are as follows: The service initiator operates the hardware encryption machine and initiates a request to generate a new card write root key to the hardware encryption machine; The hardware encryption machine generates a new card writing root key based on the parameters provided by the service initiator; The hardware encryption machine returns a new card writing root key ID to the service initiator, and the card writing root key ID is used for the subsequent configuration of new service types; The service initiator defines corresponding discrete rules according to the received new card root key ID.

3. The system according to claim 2, characterized in that: When preparing for business, the specific steps are: The service initiator initiates a request to configure a new service type in the card issuing system and provides the parameters required for the new service type; The card issuing system configures the new service type according to the parameters provided by the service initiator, and matches the new service type with the card type, the new card root key ID and the discrete rule; The card issuing system returns the configuration result of the new service type to the service initiator; The business initiator initiates a request to enable a new business type in the card issuing system; The card issuing system reads the card identity ID field of the stock card in the database, and updates the stock card whose card identity ID is empty to the original card identity ID; for the stock card whose card identity ID is not empty, the identity ID remains unchanged; The card issuing system returns the activation result of the new service type to the service initiator.

4. The system according to claim 1, characterized in that: During the card production phase, the card writing root key stored in the encryption machine is used to generate a unique card-specific key for each card based on the discrete rules customized by the business. Associating the generated one-card-one-password with the corresponding card and storing it; In the card writing phase, the same card writing root key and discrete rule are used again to calculate the card-specific secret for each card; Compare the one-card-one-secret code calculated at the card writing stage with the one-card-one-secret code stored at the card making stage; If the two are consistent, the verification is successful and the card is confirmed to be a legal card; if the two are inconsistent, the verification fails and the card is determined to be an illegal card.

5. The system according to claim 1, characterized in that: After the card issuing system receives the card production request from the business initiator, it searches and determines the card writing root key ID and discrete rules corresponding to the card type from the preset key management system according to the card type in the request; based on the card writing root key ID and discrete rules, the card issuing system sends a one-card-one-secret generation request containing the number of cards produced to the hardware encryption machine, so as to trigger the hardware encryption machine to generate one-card-one-secret data matching the number of cards produced.

6. The system according to claim 5, characterized in that: The hardware encryption machine obtains the corresponding write-card root key from the secure storage area according to the write-card root key ID in the one-card-one-secret generation request sent by the card issuing system; then, the hardware encryption machine uses the write-card root key and discrete rules to generate the one-card-one-secret data required for card production, and returns the generated one-card-one-secret data to the card issuing system; after receiving the one-card-one-secret data, the card issuing system combines it with other card production data generated by itself to form a complete card production data set corresponding to the number of cards produced; finally, the card issuing system stores the complete card production data set, matches the card serial number in the card production data set and stores the corresponding card identification information in the database, and returns the complete card production data set to the business initiator.

7. The system according to claim 1, characterized in that: After the card issuance system starts the corresponding card issuance process, the card writing data corresponding to the card serial number is obtained from the preset card writing database according to the read card serial number; The card issuing system initiates a one-card-one-secret calculation request to the hardware encryption machine. The request contains the card write root key ID and discrete rules used to generate one-card-one-secret, so that the hardware encryption machine can generate the corresponding one-card-one-secret based on this information.

8. The system according to claim 7, characterized in that: After receiving the one-card-one-secret calculation request from the card issuing system, the hardware encryption machine calls the corresponding card writing root key stored in the secure area; then, the hardware encryption machine generates a one-card-one-secret corresponding to the card serial number based on the provided discrete rules and the called card writing root key; finally, the hardware encryption machine returns the generated one-card-one-secret to the card issuing system for subsequent card writing operations by the card issuing system.

9. The system according to claim 8, characterized in that: After receiving the card-code returned by the hardware encryption machine, the card issuing system assembles a card-writing instruction based on the card-code; the card issuing system sends the assembled card-writing instruction to the inserted card issuing card, and the card executes the card-writing operation after receiving the card-writing instruction; the card issuing system analyzes the card-writing result, and after confirming that the card writing is successful, it executes the subsequent business process; the card issuing system outputs the card issuing result to the business initiator, including information on the success or failure of the card issuance, as well as related card information.

10. The system according to claim 4, characterized in that: When defining discrete rules, specifically include: Performing a first discrete process using the card merchant code as a first discrete factor to generate a first discrete value; The last 4 digits of the card serial number of the card are used as the second discrete factor to perform a second discrete process to generate a second discrete value; The first discrete value and the second discrete value are combined to generate a one-card-one-secret key.