Method and System for Querying Smart Card Balance Based on Terminal Device

By using NFC communication between the smart card and the terminal device and encryption with temporary session keys, the device and network dependencies of smart card balance inquiries are resolved, enabling autonomous inquiries and data security even in environments without a network.

CN120471620BActive Publication Date: 2025-11-14金邦达有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510976288.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-11-14
Estimated Expiration
2045-07-16

AI Technical Summary

Technical Problem

Existing smart card balance inquiry methods require dedicated equipment or rely on public communication networks, resulting in inconvenience in carrying them and network instability, making it impossible to inquire about the balance in an environment without a network.

Method used

Through NFC communication between the smart card and the terminal device, the NDEF data storage area and security chip are used to enable the terminal device to automatically parse the NDEF format query command and convert it into an APDU command to obtain the smart card balance information. The data transmission is encrypted with a temporary session key to ensure security.

Benefits of technology

It enables users to check their smart card balance independently when there is no public communication network, avoiding reliance on dedicated equipment and networks, and ensuring data security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120471620B_ABST
    Figure CN120471620B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for querying smart card balances using a terminal device. The method includes bringing the smart card close to the terminal device; the smart card is equipped with a security chip and an NDEF data storage area, the NDEF data storage area storing first charge information and a query command in NDEF format; the smart card sends the first charge information and the query command to the terminal device; the terminal device parses the query command and sends an APDU command to the smart card, the APDU command including a command to query second charge information of the smart card; after receiving the APDU command, the smart card's security chip obtains the second charge information and sends it to the terminal device; the terminal device displays the received second charge information. This invention also provides a system for implementing the above method. This invention enables users to conveniently query their smart card balances without using public communication networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of smart card data processing, specifically, to a method for querying smart card balances based on a terminal device and a system for implementing this method. Background Technology

[0002] A smart card is a card equipped with a security chip that stores encrypted data. Because the security chip implements security measures to protect the stored data, the data stored within it is not easily tampered with. Therefore, smart cards are widely used in the financial sector, such as common public transport cards and bank cards.

[0003] When people use smart cards for transactions, they are often unaware of the card's balance. For example, when using a public transport card, the balance cannot be determined from the card's appearance. If the balance is insufficient, and the user is unaware of this but needs to use the card immediately, payment will be impossible, impacting user experience. Currently, there are three methods for checking smart card balances. The first is using a dedicated terminal device, such as a POS machine or recharge terminal, to read the data from the smart card. However, these dedicated devices are inconvenient to carry, have high production costs, and are not suitable for personal use. The second method is checking via an online app, requiring the user to connect to a backend server and run a specific app, such as a bank's app, to check the balance. However, this method relies on public communication networks, resulting in network latency issues, and instability in the public communication network can also affect the balance check operation. The third method is checking via SMS, requiring the user to compose a specific SMS message and send it to a specific number. However, this method is cumbersome and may incur communication fees.

[0004] Most existing contactless smart cards are equipped with NFC chips, which enable communication with terminal devices. NFC technology, as a short-range wireless communication technology, has seen widespread application in recent years. NDEF, as the NFC data exchange format, is a lightweight data format specification used for efficient data transfer between NFC devices. With the widespread adoption of smartphones, NFC functionality has become increasingly powerful, allowing smartphones to act as active or passive NFC devices to communicate with other NFC tags or devices.

[0005] Chinese invention patent application CN102737308A discloses a mobile terminal and a method and system for querying smart card information. The mobile terminal includes a SIM card identity registration module, a security management module, and a near-field communication (NFC) authentication module. The security management module decrypts the encrypted registration information to obtain the decrypted information and matches the relevant information of the smart card with the decrypted information. If the match is successful, the balance and / or transaction information of the smart card is output.

[0006] However, this method still relies on public communication networks to transmit smart card balance and / or transaction information, and cannot perform smart card balance inquiries without connecting to a public communication network. Summary of the Invention

[0007] The first objective of this invention is to provide a method for querying smart card balances based on terminal devices without the need for dedicated equipment or reliance on public communication networks.

[0008] A second objective of this invention is to provide a system for querying smart card balances based on a terminal device, which implements the above-described method for querying smart card balances based on a terminal device.

[0009] To achieve the aforementioned first objective, the method for querying smart card balance based on a terminal device provided by the present invention includes: bringing the smart card close to the terminal device; the smart card being equipped with a security chip and an NDEF data storage area, the NDEF data storage area storing the smart card's first charge information and a query command in NDEF format; the smart card sending the first charge information and the query command to the terminal device; the terminal device parsing the query command and sending an APDU command to the smart card, the APDU command including a command to query the smart card's second charge information; the smart card's security chip receiving the APDU command, obtaining the smart card's second charge information and sending it to the terminal device; and the terminal device displaying the received second charge information.

[0010] As can be seen from the above scheme, when the smart card is brought close to the terminal device, the smart card can automatically send the first fee information and the query command in NDEF format to the terminal device. In this way, the terminal device can parse the query command in NDEF format and convert it into an APDU command that the security chip can recognize. Then, the APDU command is sent to the smart card. The security chip of the smart card obtains the second fee information according to the received APDU command and sends the second fee information to the terminal device.

[0011] In this way, the terminal device can display information such as the smart card's balance and transaction history. The entire process does not transmit data through public communication networks, but relies solely on communication between the smart card and the terminal device's NFC chip. Therefore, balance inquiries can be made even without a public communication network. Furthermore, since this invention only uses a terminal device with NFC functionality to inquire about the balance, it does not require a dedicated terminal device. And since most smartphones now have NFC functionality, users can easily check their smart card balances themselves through their terminal devices.

[0012] A preferred approach is that after each smart card transaction is completed, the security chip updates the current balance information and the most recent transaction record information to the NDEF data storage area in an atomic operation.

[0013] Therefore, the data stored in the NDEF data storage area of ​​the smart card already includes the smart card's balance and several transaction records. When the smart card sends the first fee information to the terminal device, the terminal device can obtain the smart card's balance and the most recent transaction records.

[0014] A further approach is that when the security chip updates the current balance information and the most recent transaction record information to the NDEF data storage area in an atomic operation, it uses a temporary session key to encrypt the first fee information, so that the first fee information stored in the NDEF data storage area is encrypted information.

[0015] Therefore, the first charge information is encrypted. Upon receiving this information, the terminal device needs to decrypt it. This ensures that even if the first charge information stored in the NDEF data storage area of ​​the smart card is intercepted, the card's balance and other information cannot be obtained without knowing the decryption key, thus guaranteeing the security of data transmission.

[0016] A further approach is to generate the temporary session key using a dynamic random number, the UID information within the card's lifecycle, and a counter value.

[0017] Therefore, the temporary session key generated using the above factors is not fixed. Even if a temporary session key is illegally intercepted, the next temporary session key will not be obtained, thus ensuring the security of encryption.

[0018] A further approach is to send a dynamic random number and a counter value along with the encrypted first fee information when the smart card sends it to the terminal device.

[0019] Therefore, after receiving the first fee information, the terminal device can use the received dynamic random number and count value as factors to generate the corresponding temporary session key, thereby correctly decrypting the first fee information.

[0020] A further proposed solution is that after obtaining the first fee information, the terminal device decrypts the first fee information; if the terminal device fails to decrypt the first fee information, it does not parse the query command in NDEF format.

[0021] Therefore, if the terminal device cannot correctly decrypt the first fee information, it means that the terminal device and the smart card are not compatible, or the terminal device is an illegal terminal device. As a result, the terminal device will not parse the query command in NDEF format, that is, it will not send the APDU command to the smart card, and the smart card will not send the second fee information.

[0022] A further approach is to send the second fee information from the smart card's security chip to the terminal device using a temporary session key.

[0023] Therefore, the second fee information is also encrypted using the same temporary session key as the first fee information. In this way, after the terminal device receives the encrypted second fee information, it can decrypt it using the same temporary session key, which can improve the security of the second fee information transmission.

[0024] A further proposed solution is that the first fee information includes the current balance and a preset number of transaction records; the second fee information includes the remaining transaction records.

[0025] To achieve the second objective mentioned above, the system for querying smart card balance based on a terminal device provided by the present invention includes a smart card and a terminal device. The smart card is equipped with a security chip and an NDEF data storage area. The NDEF data storage area stores the smart card's first charge information and a query command in NDEF format. The smart card is used to send the first charge information and the query command to the terminal device. The terminal device is used to parse the query command and send an APDU command to the smart card. The APDU command includes a command to query the smart card's second charge information. After receiving the APDU command, the smart card's security chip obtains the smart card's second charge information and sends it to the terminal device. The terminal device displays the received second charge information.

[0026] As can be seen from the above scheme, when the smart card is near the terminal device, it automatically sends first charge information and a query command in NDEF format to the terminal device. The terminal device decrypts the first charge information and displays it, allowing the user to easily view the smart card's balance. Furthermore, after decrypting the first charge information, the terminal device parses the NDEF query command and converts it into an APDU command that the security chip can recognize. This APDU command is then sent to the smart card. The smart card's security chip retrieves the second charge information based on the received APDU command and sends it to the terminal device.

[0027] Since the terminal device can display information such as the smart card's balance and transaction history, the entire process does not transmit data through public communication networks. It relies solely on the NFC chip between the smart card and the terminal device for communication. Therefore, balance inquiries can be made even without a public communication network. Furthermore, because this invention only requires an NFC-enabled terminal device to check the balance, no dedicated terminal device is needed. And since most smartphones now have NFC functionality, users can easily check their smart card balances themselves using a terminal device.

[0028] A preferred approach is that the first charge information of the smart card stored in the NDEF data storage area is encrypted using a temporary session key. Attached Figure Description

[0029] Figure 1 This is a structural block diagram of a system embodiment of the present invention based on querying smart card balances using a terminal device.

[0030] Figure 2 This is a flowchart of an embodiment of the method for querying smart card balance based on terminal device according to the present invention.

[0031] The present invention will be further described below with reference to the accompanying drawings and embodiments. Detailed Implementation

[0032] The method for querying smart card balance based on terminal device of the present invention allows users to query the balance of smart card using terminal devices such as smartphones. The balance query process does not require the use of dedicated terminal devices or public communication networks. The balance query can be completed simply through NFC communication between the smart card and the terminal device.

[0033] A system implementation example for querying smart card balances via terminal devices:

[0034] See Figure 1The system for querying smart card balance based on terminal device in this embodiment has a smart card 10 and a terminal device 15. Both the smart card 10 and the terminal device 15 have NFC chips and communicate based on their respective NFC chips. That is, the smart card 10 and the terminal device 15 communicate with each other via NFC.

[0035] The smart card 10 contains a security chip 11 and an NDEF data storage area 12. The security chip 11 records the balance and transaction history of the smart card 10. Because the security chip 11 adopts security standards, the data within it is not easily tampered with. Preferably, the security chip 11 includes an offline data area for storing offline data. Offline data is data that can be read without security authentication, but it can only be read and not modified. In this embodiment, the balance and transaction history of the smart card 10 are stored in the offline data area, and the data in the offline data area can be read by the terminal device 15.

[0036] The NDEF data storage area 12 is used to store data in NDEF format, which is the NFC data exchange format. In this embodiment, the NDEF data storage area 12 stores encrypted first fee information, which can be directly transmitted from the NDEF data storage area 12 to the terminal device 15. Since the amount of data transmitted between the smart card 10 and the terminal device 15 is limited, the first fee information only includes the balance information of the smart card 10 and a small amount of transaction record information, such as only the most recent transaction records. More transaction record information is stored in the security chip 11; therefore, the remaining transaction record information recorded by the security chip 11 is referred to as second fee information.

[0037] Since the first fee information can be directly transmitted to the terminal device 15, the security chip 11 needs to encrypt the first fee information to ensure the security of data transmission. Specifically, the first fee information is encrypted using a preset algorithm and a temporary session key. In this embodiment, the temporary session key is generated using three factors: a dynamic random number, the UID information within the card's lifespan, and a count value. The dynamic random number is a random number dynamically generated by the security chip 11. The UID information within the card's lifespan is the identity code recorded by the security chip 11 and will not change. The count value is a counter generated by the internal counter of the security chip 11. Each time the smart card 10 successfully sends the first fee information to the terminal device 15, the count value will automatically increase by 1, and it can only increase monotonically, not decrease.

[0038] In addition to recording encrypted initial charge information, the NDEF data storage area 12 will also record dynamic random numbers and counter values, but will not record UID information for the card's lifecycle. Furthermore, the NDEF data storage area 12 will also store query commands in NDEF format.

[0039] Terminal device 15 can receive first fee information from NDEF data storage area 12 and decrypt it to obtain the balance of smart card 10 and recent transaction records. Additionally, it can receive and parse NDEF format query commands to obtain APDU commands, which can be recognized by security chip 11. Furthermore, terminal device 15 can also obtain second fee information from security chip 11, i.e., the remaining transaction records. After obtaining the balance and transaction records, terminal device 15 can display them, for example, through a screen or by broadcasting them via a speaker.

[0040] Example of a method for querying smart card balance using a terminal device:

[0041] The following is combined with Figure 2 This paper introduces a method for displaying the balance of a smart card based on a terminal device. Since the smart card and the terminal device need to decrypt the initial fee information, to ensure the terminal device can accurately generate the decryption key, authentication between the smart card and the terminal device is required before retrieving the smart card's balance. For example, the smart card authenticates its identity to the terminal device, and after successful authentication, the smart card sends its UID information (within its lifecycle) and the rules for generating a temporary session key to the terminal device. It should be noted that the authentication between the smart card and the terminal device only needs to be performed once. Once authentication is complete, subsequent balance queries do not require re-authentication.

[0042] Of course, the identity authentication operation can also be implemented in advance by the smart card issuer through a background program. For example, the background program can bind the terminal device to the smart card in advance and write the UID information of the smart card during its life cycle and the temporary session key generation rules into the terminal device in advance.

[0043] Each time the smart card is used, i.e., when the balance changes, the security chip records the current balance information and the latest transaction record. Furthermore, the security chip atomically updates the NDEF data storage area with these information. Preferably, when updating the NDEF data storage area, the security chip encrypts the first charge information using a temporary session key and stores the encrypted first charge information in the NDEF data storage area. Therefore, the NDEF data storage area does not store plaintext balance information or transaction record information.

[0044] When a user needs to check their balance, step S1 is executed first, where the smart card is brought close to the terminal device. At this time, the NFC chip of the terminal device is activated, establishing NFC communication with the smart card. Then, the smart card executes step S2, sending the encrypted first charge information, dynamic random number, counter value, and NDEF format query command stored in the NDEF data storage area to the terminal device.

[0045] Next, the terminal device executes step S3 to decrypt the received encrypted first fee information. Since the smart card has already sent a dynamic random number and a count value in step S2, and the terminal device has already recorded the UID information of the smart card during its lifecycle, the terminal device uses a pre-set temporary session key generation rule and generates a temporary session key based on three factors: the dynamic random number, the UID information during the card's lifecycle, and the count value. This temporary session key is then used to decrypt the encrypted first fee information, thereby obtaining the plaintext first fee information.

[0046] In addition, the terminal device itself also records a count value. Since the terminal device records the UID information of the smart card throughout its lifecycle, the count value automatically increments each time the terminal device successfully reads the first charge information from the smart card. Furthermore, the count value can only monotonically increase, ensuring that the count value recorded by the terminal device is synchronized with the count value recorded by the security chip. If, in step S2, the count value received by the terminal device from the smart card is inconsistent with the count value recorded by the terminal device itself, it indicates that the data sent by the smart card may have been illegally migrated. For example, criminals may intercept the data to be transmitted from the NDEF data storage area of ​​a legitimate smart card and copy it to an illegitimate smart card. Since the count value in the intercepted data has not changed, the count value in the intercepted data will not be equal to the count value recorded by the terminal device. In this case, the terminal device will not decrypt the first charge information to prevent criminals from illegally obtaining the smart card's balance information.

[0047] The terminal device also needs to execute step S4 to determine whether the encrypted first fee information has been successfully decrypted. If decryption fails, it indicates that the generated temporary session key is incorrect. This may be due to a discrepancy between the UID information of the smart card during its lifecycle and the UID information recorded by the terminal device. In this case, it means that the terminal device is not bound to the smart card, meaning that the terminal device has not been authenticated with the smart card, and there is a problem of unauthorized terminal device reading smart card data. Therefore, if the terminal device cannot correctly decrypt the first fee information, it will not obtain the first fee information, and the terminal device will not perform the operation of parsing the NDEF format query command.

[0048] If the judgment result of step S4 is yes, indicating that the terminal device can correctly decrypt the first fee information, then step S5 is executed, whereby the terminal device displays the first fee information and parses the query command in NDEF format. Since the terminal device equipped with an NFC chip can parse NDEF format data, it does not require additional application installation to parse the NDEF format query command and obtain the APDU command. In this embodiment, the APDU command is a command to query the second fee information of the smart card, and the APDU command is recognized by the security chip. Preferably, this APDU command only needs to read the second fee information from the offline data area of ​​the security chip.

[0049] Then, the terminal device executes step S6, sending the parsed APDU command to the smart card. The smart card's security chip receives the APDU command. Since this APDU command is merely a command to read the second charge information in the offline data area of ​​the security chip, it cannot perform other operations; that is, it cannot read other data, much less modify the data in the security chip. Thus, the terminal device cannot rewrite the data within the security chip; it can only read the second charge information.

[0050] After the security chip obtains the APDU command, it executes step S7, retrieves the second fee information from the offline data area according to the APDU command, and sends the second fee information to the terminal device. Preferably, before sending the second fee information, the security chip encrypts the second fee information, for example, using the same temporary session key used to encrypt the first fee information in step S2; that is, the encryption key for the first fee information is the same as the encryption key for the second fee information. In this way, the security chip does not need to generate a new temporary session key, and the terminal device also does not need to generate an additional temporary session key.

[0051] Finally, the terminal device executes step S8, receives the encrypted second fee information sent by the security chip, and decrypts the second fee information using the same temporary session key as in step S3, thereby obtaining the plaintext second fee information, and displays the second fee information on the display screen.

[0052] Using the method of this invention, users only need an NFC-enabled terminal device to check the balance of a smart card, without the need for dedicated equipment. Furthermore, neither the smart card nor the terminal device needs to connect to a public communication network during the entire check process, meaning that balance inquiries can be made even in scenarios without a public communication network, greatly enhancing convenience. Because the terminal device does not need to connect to a public communication network during the balance check, it also ensures that the smart card's balance and transaction record information will not be leaked through public communication networks.

[0053] Furthermore, since both the first and second fee information sent by the smart card to the terminal device are encrypted, even if the data sent by the smart card is illegally intercepted, or if an unauthorized terminal device tries to read the smart card's balance, the unauthorized smart card cannot decrypt the first fee information and therefore cannot obtain the smart card's balance information and transaction record information. This ensures that the smart card's balance information will not be illegally read.

[0054] Finally, it should be emphasized that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for querying smart card balance based on a terminal device, including: Bring the smart card close to the terminal device; Its features are: The smart card is equipped with a security chip and an NDEF data storage area, which stores the smart card's first fee information and NDEF format query instructions. The smart card sends the first fee information and the query instruction to the terminal device. The terminal device displays the received first fee information and parses the query instruction to send an APDU command to the smart card. The APDU command includes a command to query the second fee information of the smart card. After receiving the APDU command, the security chip of the smart card obtains the second fee information of the smart card and sends it to the terminal device. The terminal device then displays the received second fee information. The first fee information includes the current balance and a preset amount of transaction record information; The second fee information includes information on remaining transaction records.

2. The method for querying smart card balance based on terminal device according to claim 1, characterized in that: After each transaction is completed, the security chip updates the current balance information and the most recent transaction record information to the NDEF data storage area in an atomic operation.

3. The method for querying smart card balance based on terminal device according to claim 2, characterized in that: When the security chip updates the current balance information and the most recent transaction record information to the NDEF data storage area in an atomic operation, it uses a temporary session key to encrypt the first fee information, so that the first fee information stored in the NDEF data storage area is encrypted information.

4. The method for querying smart card balance based on terminal device according to claim 3, characterized in that: The temporary session key is generated using a dynamic random number, the UID information within the card's lifecycle, and a counter value.

5. The method for querying smart card balance based on terminal device according to claim 4, characterized in that: When the smart card sends the encrypted first fee information to the terminal device, it also sends the dynamic random number and the count value together.

6. The method for querying smart card balance based on terminal device according to claim 3, characterized in that: After obtaining the first fee information, the terminal device decrypts the first fee information; If the terminal device fails to decrypt the first fee information, it will not parse the NDEF format query command.

7. The method for querying smart card balance based on a terminal device according to any one of claims 3 to 6, characterized in that: The second fee information sent by the security chip of the smart card to the terminal device is also encrypted using the temporary session key.

8. A system for querying smart card balance based on a terminal device, comprising a smart card and a terminal device, characterized in that: The smart card is equipped with a security chip and an NDEF data storage area, which stores the smart card's first fee information and NDEF format query instructions. The smart card is used to send the first fee information and the query instruction to the terminal device. The terminal device is used to display the received first fee information, parse the query instruction, and send an APDU command to the smart card. The APDU command includes a command to query the second fee information of the smart card. After receiving the APDU command, the security chip of the smart card obtains the second fee information of the smart card and sends it to the terminal device. The terminal device then displays the received second fee information. The first fee information includes the current balance and a preset amount of transaction record information; The second fee information includes information on remaining transaction records.

9. The system for querying smart card balance based on terminal device according to claim 8, characterized in that: The first fee information of the smart card stored in the NDEF data storage area is information encrypted using a temporary session key.

Citation Information

Patent Citations

  • Mobile terminal and method and system for inquiring information of intelligent card

    CN102737308A

  • Method and apparatus for realizing peer-to-peer communication of near field communication

    CN106845974A

  • SAM card control system and method

    CN119483960A