Communication security detection method and device for loading all-purpose card application on social security card
By verifying the IP data and message data of the social security card and encrypting the communication data, the communication security problem in the application of the social security card loading card is solved, and comprehensive security detection of the network layer, application layer and data layer is realized, and communication security is improved.
Patent Information
- Application Number
- CN202510269760.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-20
AI Technical Summary
During the application of the social security card loading one-card, communication security issues lead to the risk of information leakage and tampering, and the security of the existing technology is low.
By obtaining the card feature information of the social security card, including IP data, message data and encryption and decryption methods, the social security card is initially safely verified, and the communication data is encrypted according to the encryption and decryption methods to ensure the security of the communication data.
It realizes comprehensive communication security detection of the network layer, application layer and data layer during the application of social security card loading, avoids the risk of data leakage and tampering, and improves communication security.
Smart Images

Figure CN120185805A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of communication security, and particularly relates to a communication security detection method and device for loading a one-card application on a social security card. Background Art
[0002] With the continuous development of information technology, the social security card, an important tool for people's livelihood services, is constantly expanding and deepening its function boundaries and application scenarios. Loading a one-card application on the social security card enables the social security card to cross industry boundaries and achieve universal use across fields and regions, providing great convenience for the public in multiple fields such as transportation, public services, and commercial consumption.
[0003] However, with the popularization and in-depth development of loading a one-card application on the social security card, the potential safety hazards brought by its communication security issues are gradually expanding. Since a large amount of personal information and transaction data are stored during the process of loading a one-card application on the social security card, once there are loopholes or malicious attacks in the communication process, serious consequences such as information leakage will occur. Currently, during the process of loading a one-card application on the social security card, usually only the normalcy of the user's identity information is verified, which results in low security during the process of loading a one-card application on the social security card. Therefore, there is an urgent need for a communication security detection method and device for loading a one-card application on the social security card to solve the defects of the existing technology. Summary of the Invention
[0004] The present invention aims to provide a communication security detection method and device for loading a one-card application on a social security card to solve the above technical problems. By performing security verification on IP data and message data and encrypting communication data, the communication security of loading a one-card application on the social security card is improved.
[0005] To solve the above technical problems, an embodiment of the present invention provides a communication security detection method for loading a one-card application on a social security card, including:
[0006] Obtaining the communication data and card feature information of the social security card, where the card feature information includes: IP data, message data, and encryption and decryption methods;
[0007] Performing a preliminary security verification on the social security card according to the IP data and message data to determine that the social security card meets a preset first security requirement;
[0008] Encrypting the communication data according to the encryption and decryption method to obtain encrypted communication data;
[0009] Forwarding the encrypted communication data to the one-card application to complete the communication security detection of loading the one-card application on the social security card.
[0010] It is understandable that, compared with the prior art, the present invention obtains the card feature information of the social security card, and then performs a security verification on the social security card based on the IP data and the message data to ensure that the social security card meets the preset first security requirement. Then, the communication data of the social security card is encrypted according to the encryption and decryption method, thereby realizing the communication security detection of loading the all-in-one card application on the social security card; the present invention verifies the IP data and the message data of the social security card, and encrypts the communication data, so as to perform security detection on the network layer, application layer and data layer in the process of loading the all-in-one card application on the social security card, ensuring the comprehensive communication security detection in the process of loading the all-in-one card application on the social security card, avoiding the risks of data leakage and tampering caused by the single communication security detection measure in the prior art, and improving the communication security of loading the all-in-one card application on the social security card.
[0011] As a preferred solution, the preliminary security verification of the social security card according to the IP data and the message data to determine that the social security card meets the preset first security requirement specifically includes:
[0012] Match the IP data with a preset IP database to determine whether the IP data is in the preset IP database;
[0013] When the IP data is in the preset IP database, verify and encrypt the message data to determine that the social security card meets the preset first security requirement.
[0014] This preferred solution can quickly and accurately exclude abnormal IP addresses by verifying the IP data of the social security card, thereby ensuring the network layer security in the process of loading the all-in-one card application on the social security card, and verifying and encrypting the message data to ensure the application layer security in the process of loading the all-in-one card application on the social security card, improving the communication security of loading the all-in-one card application on the social security card.
[0015] As a preferred solution, the verification and encryption of the message data specifically includes:
[0016] Obtain the message header and message body of the message data, and determine the communication protocol corresponding to the message data according to the message header and message body;
[0017] Match the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database;
[0018] Encrypt the message data according to a preset asymmetric signature verification algorithm.
[0019] This preferred solution determines the communication protocol during the process of loading the one-card application on the social security card by analyzing the message header and message body, and then encrypts the message data, ensuring the application layer security during the process of loading the one-card application on the social security card and improving the communication security of loading the one-card application on the social security card.
[0020] As a preferred solution, encrypting the communication data according to the encryption and decryption method to obtain encrypted communication data specifically includes:
[0021] Obtaining an initial key and a key encryption key from a preset key server;
[0022] Encrypting the communication data according to a preset 3DES encryption algorithm and the initial key, and encrypting the initial key according to the key encryption key to obtain encrypted communication data.
[0023] This preferred solution encrypts the communication data with the initial key and then encrypts the initial key with the key encryption key, improving the anti-attack ability during the process of loading the one-card application on the social security card, reducing the risk of data leakage and tampering, ensuring the data layer security during the process of loading the one-card application on the social security card, and improving the communication security of loading the one-card application on the social security card.
[0024] As a preferred solution, after encrypting the initial key according to the key encryption key, it further includes:
[0025] Dispersing the initial key based on the function word of the initial key to obtain a number of function master keys;
[0026] Obtaining the chip serial number of the social security card and generating a dispersion factor according to the chip serial number;
[0027] Dispersing the function master keys according to the dispersion factor.
[0028] This preferred solution ensures the security and uniqueness of the initial key through the decentralized management of the initial key, thereby improving the security of the data layer during the process of loading the one-card application on the social security card, and thus improving the communication security of loading the one-card application on the social security card.
[0029] Correspondingly, the embodiment of the present invention provides a communication security detection device for loading the one-card application on the social security card, including: a data acquisition module, a preliminary security verification module, a data encryption module, and a data communication module;
[0030] Among them, the data acquisition module is used to acquire the communication data and card feature information of the social security card, where the card feature information includes: IP data, message data, and encryption and decryption methods;
[0031] The preliminary security verification module is used to perform a preliminary security verification on the social security card according to the IP data and the message data, and determine that the social security card meets the preset first security requirements;
[0032] The data encryption module is used to encrypt the communication data according to the encryption and decryption method to obtain encrypted communication data;
[0033] The data communication module is used to forward the encrypted communication data to the one-card application to complete the communication security detection of loading the one-card application on the social security card.
[0034] As a preferred solution, the preliminary security verification module includes: a preliminary security verification unit;
[0035] The preliminary security verification unit is used to match the IP data with a preset IP database to determine whether the IP data is in the preset IP database;
[0036] When the IP data is in the preset IP database, verify and encrypt the message data to determine that the social security card meets the preset first security requirements.
[0037] As a preferred solution, the preliminary security verification unit includes: a message data encryption subunit;
[0038] The message data encryption subunit is used to obtain the message header and the message body of the message data, and determine the communication protocol corresponding to the message data according to the message header and the message body;
[0039] Match the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database;
[0040] Encrypt the message data according to a preset asymmetric signature verification algorithm.
[0041] As a preferred solution, the data encryption module includes: a data encryption unit;
[0042] The data encryption unit is used to obtain an initial key and a key encryption key from a preset key server;
[0043] Encrypt the communication data according to a preset 3DES encryption algorithm and the initial key, and encrypt the initial key according to the key encryption key to obtain encrypted communication data.
[0044] As a preferred solution, the data encryption unit includes: a key dispersion unit;
[0045] The key dispersion unit is used to disperse the initial key based on the functional word of the initial key to obtain a number of functional master keys;
[0046] Obtain the chip serial number of the social security card, and generate a dispersion factor according to the chip serial number; disperse the functional master key according to the dispersion factor.
[0047] It can be understood that, compared with the prior art, the present device obtains the card feature information of the social security card, and then performs security verification on the social security card based on the IP data and message data to ensure that the social security card meets the preset first security requirement. Then, the communication data of the social security card is encrypted according to the encryption and decryption method, thereby realizing the communication security detection of loading the one-card application on the social security card; the present device verifies the IP data and message data of the social security card, and encrypts the communication data, so as to perform security detection on the network layer, application layer and data layer in the process of loading the one-card application on the social security card, ensuring comprehensive communication security detection in the process of loading the one-card application on the social security card, avoiding the risks of data leakage and tampering caused by the single communication security detection measures in the prior art, and improving the communication security of loading the one-card application on the social security card. Description of the Drawings
[0048] Figure 1 : It is a step flowchart of a communication security detection method for loading a one-card application on a social security card provided by an embodiment of the present invention;
[0049] Figure 2 : It is a structural schematic diagram of a communication security detection device for loading a one-card application on a social security card provided by an embodiment of the present invention;
[0050] Among them, 201: Data acquisition module; 202: Preliminary security verification module; 203: Data encryption module; 204: Data communication module. Specific Embodiments
[0051] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0052] It should be noted that in the communication security detection method for loading a one-card application on a social security card described in the embodiments of the present invention, the communication is the data of the social security card, and the data of the social security card is forwarded to the one-card application through the terminal device;
[0053] Specifically, the terminal device here can be a smart phone, a self-service machine, a public transportation device, etc.; during the communication process of data, it involves the network layer, application layer, and data layer in the computer network and information system architecture; the network layer is usually responsible for determining information such as the IP address of the data, so as to determine the transmission path of the data; the application layer usually contains numerous transmission protocols and defines the communication rules and formats of the data; the data layer usually processes the data.
[0054] Embodiment 1
[0055] Please refer to Figure 1 , which is the step flowchart of a communication security detection method for loading a one-card application on a social security card provided by an embodiment of the present invention, including steps S101 to S104.
[0056] Step S101: Obtain the communication data and card feature information of the social security card, where the card feature information includes: IP data, message data, and encryption and decryption methods.
[0057] Step S102: Perform a preliminary security verification on the social security card according to the IP data and message data, and determine that the social security card meets the preset first security requirement.
[0058] In this embodiment, the performing a preliminary security verification on the social security card according to the IP data and message data, and determining that the social security card meets the preset first security requirement specifically includes:
[0059] Match the IP data with a preset IP database, and determine whether the IP data is in the preset IP database;
[0060] When the IP data is in the preset IP database, verify and encrypt the message data, and determine that the social security card meets the preset first security requirement.
[0061] In an alternative embodiment, the IP data is specifically the IP address of the social security card, and the preset IP database contains the common IP addresses of each social security card. By matching the IP address of the social security card with its corresponding common IP address, abnormal operations such as logging in from other places can be quickly screened out, thereby ensuring the communication security of loading the one-card application on the social security card.
[0062] In an alternative embodiment, when matching the IP address with the preset IP database, a matching algorithm based on interval conversion can be used. First, convert the IP address into a long integer data, and then match it with the IP database to determine that the IP data of the social security card is in the preset IP database.
[0063] In an alternative embodiment, the administrator can log in to the management operation background of the terminal device and then modify the common IP addresses in the preset IP database, so as to ensure that only the social security cards matching the common IP addresses can conduct subsequent communications. Specifically, the IP database here can also be replaced by an IP whitelist, and only the social security cards in the IP whitelist can continue subsequent communications.
[0064] By verifying the IP data of the social security card, this embodiment can quickly and accurately exclude abnormal IP addresses, thus ensuring the network layer security during the process of the social security card loading the one-card application, and verifying and encrypting the message data to ensure the application layer security during the process of the social security card loading the one-card application, improving the communication security of the social security card loading the one-card application.
[0065] In this embodiment, the verification and encryption of the message data specifically include:
[0066] Obtain the message header and message body of the message data, and determine the communication protocol corresponding to the message data according to the message header and message body;
[0067] Match the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database;
[0068] Encrypt the message data according to a preset asymmetric signature verification algorithm.
[0069] In an alternative embodiment, the message header and message header in this embodiment are the common structures of the message and are organized in JSON format; match the communication protocol corresponding to the message data with a preset communication protocol database to ensure that the communication protocol corresponding to the message data is any one of TCP / IP and HTTP, so as to determine that the communication protocol corresponding to the message data is in the preset communication protocol database.
[0070] This alternative embodiment can improve the communication efficiency and reliability during the process of the social security card loading the one-card application by limiting the communication protocol to any one of TCP / IP and HTTP and by organizing the message structure in JSON format.
[0071] It should be noted that TCP / IP (Transmission Control Protocol / Internet Protocol) is a set of communication protocols for realizing network interconnection; HTTP (HyperText Transfer Protocol) is an application layer protocol and one of the key protocols constituting the Internet foundation. JSON (JavaScript Object Notation) format is a lightweight data exchange format, which is easy to read and write, and is also easy for machines to parse and generate.
[0072] In an optional embodiment, after verifying the communication protocol, the digital certificate of the communication protocol is also securely verified to ensure the security and integrity of data transmission during the process of loading the one-card application on the social security card.
[0073] In an optional embodiment, the preset asymmetric signature verification algorithm can be the RSA (Rivest-Shamir-Adleman) algorithm, the ECDSA algorithm (Elliptic Curve Digital Signature Algorithm), or the DSA algorithm (Digital Signature Algorithm). Among them, the asymmetric signature verification algorithm is a signature algorithm based on public and private keys, and in this algorithm, the public key and the private key appear in pairs.
[0074] In this embodiment, the communication protocol during the process of loading the one-card application on the social security card is determined for the message header and the message body, and then the message data is encrypted, ensuring the application layer security during the process of loading the one-card application on the social security card and improving the communication security of loading the one-card application on the social security card.
[0075] Step S103: Encrypt the communication data according to the encryption and decryption method to obtain encrypted communication data.
[0076] In this embodiment, the encrypting the communication data according to the encryption and decryption method to obtain encrypted communication data specifically includes:
[0077] Obtain an initial key and a key encryption key from a preset key server;
[0078] Encrypt the communication data according to the preset 3DES encryption algorithm and the initial key, and encrypt the initial key according to the key encryption key to obtain encrypted communication data.
[0079] In this embodiment, the initial key is used to encrypt communication data, and then the key encryption key is used to encrypt the initial key, which improves the anti-attack ability during the process of loading the one-card application on the social security card, reduces the risk of data leakage and tampering, ensures the security of the data layer during the process of loading the one-card application on the social security card, and improves the communication security of loading the one-card application on the social security card.
[0080] In an alternative embodiment, the initial key and the key encryption key are obtained from the Lingnan Tong TSM (Trusted Service Management), and then the 3DES ECB mode is used to encrypt the communication data, and the key encryption key is imported into a preset third-party encryption machine.
[0081] In an alternative embodiment, the key encryption key (KEK) is a special key whose main function is to encrypt and decrypt other keys, especially those used for data encryption (usually referred to as data encryption keys or DEKs, that is, the initial key in this embodiment).
[0082] It should be noted that the Lingnan Tong TSM is an application platform for Lingnan Tong to implement the trusted service management (Trusted Service Management) function; the 3DES encryption algorithm is an enhanced encryption algorithm based on the DES (Data Encryption Standard) algorithm, which improves security by increasing the key length and performing multiple iterative encryptions. 3DES uses three keys to perform three DES encryption operations on the data; the 3DES ECB mode is an application of the 3DES (Triple Data Encryption Algorithm) algorithm in the electronic codebook (ECB) mode.
[0083] In this embodiment, after encrypting the initial key according to the key encryption key, the following steps are further included:
[0084] The initial key is dispersed based on the function word of the initial key to obtain a number of functional master keys;
[0085] The chip serial number of the social security card is obtained, and a dispersion factor is generated according to the chip serial number;
[0086] The functional master keys are dispersed according to the dispersion factor.
[0087] In an optional embodiment, the initial key is diversified based on a function word of the initial key to obtain functional master keys such as ENC (encryption key), MAC (message authentication code key), and DEK (data encryption key). Then, 8-byte SEID is intercepted from the CPLC in the security chip of the social security card, and this 8-byte SEID is used as a diversification factor to further diversify each functional master key.
[0088] It should be noted that CPLC (Card Production Life Cycle, the unique serial number of the chip) is a set of unique identifiers generated during the production process of the security chip, which contains various production, authentication, and security-related information of the chip; SEID (Security Element Identifier), which can be used as a unique identifier and has uniqueness and security; 8-byte SEID means that the length of the SEID is 8 bytes.
[0089] In this embodiment, through the diversified management of the initial key, the security and uniqueness of the initial key are ensured, thereby improving the security of the data layer during the process of loading the one-card application on the social security card, and thus improving the communication security of loading the one-card application on the social security card.
[0090] Step S104: Forward the encrypted communication data to the one-card application to complete the communication security detection of loading the one-card application on the social security card.
[0091] In this embodiment, by obtaining the card feature information of the social security card and then performing security verification on the social security card based on the IP data and message data, it is ensured that the social security card meets the preset first security requirements. Then, the communication data of the social security card is encrypted according to the encryption and decryption method, thereby realizing the communication security detection of loading the one-card application on the social security card; in this embodiment, by verifying the IP data and message data of the social security card and encrypting the communication data, the security detection of the network layer, application layer, and data layer during the process of loading the one-card application on the social security card is carried out, ensuring the comprehensive communication security detection during the process of loading the one-card application on the social security card, avoiding the risks of data leakage and tampering caused by the single communication security detection measures in the prior art, and improving the communication security of loading the one-card application on the social security card.
[0092] Embodiment Two
[0093] Please refer to Figure 2 , which is a schematic structural diagram of a communication security detection device for loading a one-card application on a social security card provided by an embodiment of the present invention, including: a data acquisition module 201, a preliminary security verification module 202, a data encryption module 203, and a data communication module 204;
[0094] Among them, the data acquisition module 201 is used to acquire the communication data and card feature information of the social security card. Among them, the card feature information includes: IP data, message data, and encryption and decryption methods.
[0095] The preliminary security verification module 202 is used to perform a preliminary security verification on the social security card according to the IP data and message data, and determine that the social security card meets the preset first security requirements.
[0096] In this embodiment, the preliminary security verification module 202 includes: a preliminary security verification unit;
[0097] The preliminary security verification unit is used to match the IP data with a preset IP database to determine whether the IP data is in the preset IP database;
[0098] When the IP data is in the preset IP database, verify and encrypt the message data to determine that the social security card meets the preset first security requirements.
[0099] In this embodiment, the preliminary security verification unit includes: a message data encryption subunit;
[0100] The message data encryption subunit is used to obtain the message header and message body of the message data, and determine the communication protocol corresponding to the message data according to the message header and message body;
[0101] Match the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database;
[0102] Encrypt the message data according to a preset asymmetric signature verification algorithm.
[0103] The data encryption module 203 is used to encrypt the communication data according to the encryption and decryption method to obtain encrypted communication data.
[0104] In this embodiment, the data encryption module 203 includes: a data encryption unit;
[0105] The data encryption unit is used to obtain an initial key and a key encryption key from a preset key server;
[0106] Encrypt the communication data according to a preset 3DES encryption algorithm and the initial key, and encrypt the initial key according to the key encryption key to obtain encrypted communication data.
[0107] In this embodiment, the data encryption unit includes: a key dispersion unit;
[0108] The key dispersion unit is used to disperse the initial key based on the function word of the initial key to obtain a plurality of functional master keys;
[0109] Obtain the chip serial number of the social security card, and generate a dispersion factor according to the chip serial number;
[0110] Disperse the functional master key according to the dispersion factor.
[0111] The data communication module 204 is used to forward the encrypted communication data to the one-card application to complete the communication security detection of loading the one-card application on the social security card.
[0112] In this embodiment, by obtaining the card feature information of the social security card, and then performing security verification on the social security card based on the IP data and message data to ensure that the social security card meets the preset first security requirements, and then encrypting the communication data of the social security card according to the encryption and decryption methods, the communication security detection of loading the one-card application on the social security card is realized; in this embodiment, by verifying the IP data and message data of the social security card and encrypting the communication data, the security detection of the network layer, application layer and data layer in the process of loading the one-card application on the social security card is carried out, ensuring the comprehensive communication security detection in the process of loading the one-card application on the social security card, avoiding the risks of data leakage and tampering caused by the single communication security detection measures in the prior art, and improving the communication security of loading the one-card application on the social security card.
[0113] In summary, in the embodiment of the present invention, by obtaining the card feature information of the social security card, and then performing security verification on the social security card based on the IP data and message data to ensure that the social security card meets the preset first security requirements, and then encrypting the communication data of the social security card according to the encryption and decryption methods, the communication security detection of loading the one-card application on the social security card is realized; in the embodiment of the present invention, by verifying the IP data and message data of the social security card and encrypting the communication data, the security detection of the network layer, application layer and data layer in the process of loading the one-card application on the social security card is carried out, ensuring the comprehensive communication security detection in the process of loading the one-card application on the social security card, avoiding the risks of data leakage and tampering caused by the single communication security detection measures in the prior art, and improving the communication security of loading the one-card application on the social security card.
[0114] The specific embodiments described above have further detailed the purpose, technical solution and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. In particular, it is pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A communication security detection method for loading a social security card with a one-card application, characterized in that: include: Acquire the communication data and card feature information of the social security card, wherein the card feature information includes: IP data, message data and encryption and decryption methods; Performing a preliminary security verification on the social security card according to the IP data and the message data to determine that the social security card meets the preset first security requirement; Encrypt the communication data according to the encryption and decryption method to obtain encrypted communication data; The encrypted communication data is forwarded to the one-card application to complete the communication security detection of the one-card application loaded on the social security card.
2. A communication security detection method for loading a social security card with a one-card application as claimed in claim 1, characterized in that: The performing of a preliminary security verification on the social security card according to the IP data and the message data to determine that the social security card meets the preset first security requirement specifically includes: Matching the IP data with a preset IP database to determine whether the IP data is in the preset IP database; When the IP data is in the preset IP database, the message data is verified and encrypted to determine that the social security card meets the preset first security requirement.
3. A communication security detection method for loading a social security card with a one-card application as claimed in claim 2, characterized in that: The verifying and encrypting the message data specifically includes: Obtaining a message header and a message body of the message data, and determining a communication protocol corresponding to the message data according to the message header and the message body; Matching the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database; The message data is encrypted according to a preset asymmetric signature verification algorithm.
4. A communication security detection method for loading a social security card with a one-card application as claimed in claim 1, characterized in that: The encrypting the communication data according to the encryption and decryption method to obtain the encrypted communication data specifically includes: Obtaining an initial key and a key encryption key from a preset key server; The communication data is encrypted according to a preset 3DES encryption algorithm and the initial key, and the initial key is encrypted according to the key encryption key to obtain encrypted communication data.
5. A communication security detection method for loading a social security card with a one-card application as claimed in claim 4, characterized in that: After encrypting the initial key according to the key encryption key, the method further includes: Dispersing the initial key based on the function word of the initial key to obtain a plurality of function master keys; Obtaining the chip serial number of the social security card, and generating a dispersion factor according to the chip serial number; The function master key is dispersed according to the dispersion factor.
6. A communication security detection device for loading a social security card with a one-card application, characterized in that: include: Data acquisition module, preliminary security verification module, data encryption module and data communication module; The data acquisition module is used to acquire the communication data and card feature information of the social security card, wherein the card feature information includes: IP data, message data and encryption and decryption methods; The preliminary security verification module is used to perform preliminary security verification on the social security card according to the IP data and the message data, and determine that the social security card meets the preset first security requirement; The data encryption module is used to encrypt the communication data according to the encryption and decryption method to obtain encrypted communication data; The data communication module is used to forward the encrypted communication data to the one-card application to complete the communication security detection of loading the one-card application on the social security card.
7. A communication security detection device for loading a social security card with a one-card application as claimed in claim 6, characterized in that: The preliminary safety verification module includes: a preliminary safety verification unit; The preliminary security verification unit is used to match the IP data with a preset IP database to determine whether the IP data is in the preset IP database; When the IP data is in the preset IP database, the message data is verified and encrypted to determine that the social security card meets the preset first security requirement.
8. A communication security detection device for loading a social security card with a one-card application as claimed in claim 7, characterized in that: The preliminary security verification unit includes: a message data encryption subunit; The message data encryption subunit is used to obtain a message header and a message body of the message data, and determine a communication protocol corresponding to the message data according to the message header and the message body; Matching the communication protocol corresponding to the message data with a preset communication protocol database to determine that the communication protocol corresponding to the message data is in the preset communication protocol database; The message data is encrypted according to a preset asymmetric signature verification algorithm.
9. A communication security detection device for loading a social security card with a one-card application as claimed in claim 6, characterized in that: The data encryption module comprises: a data encryption unit; The data encryption unit is used to obtain an initial key and a key encryption key based on a preset key server; The communication data is encrypted according to a preset 3DES encryption algorithm and the initial key, and the initial key is encrypted according to the key encryption key to obtain encrypted communication data.
10. A communication security detection device for loading a social security card with a one-card application as claimed in claim 9, characterized in that: The data encryption unit includes: a key dispersing unit; The key dispersing unit is used to disperse the initial key based on the function word of the initial key to obtain a plurality of function master keys; Obtaining the chip serial number of the social security card, and generating a dispersion factor according to the chip serial number; The function master key is dispersed according to the dispersion factor.