Non-inductive passing method, device and system based on SIM card, medium and program product
The SIM card-based contactless access system solves the problem of poor travel verification convenience, and realizes convenient, economical and secure identity verification and information verification for contactless access, thereby improving the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-07
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, business verification methods in scenarios with high resident travel density, such as railways and civil aviation, suffer from poor convenience. For example, if a passenger forgets to bring their ID card or their ID card is easily lost, using QR code verification is cumbersome.
The method adopts a SIM card-based contactless access approach. Through the collaborative work of mobile terminals, contactless access card application management platforms, contactless access service platforms, operator SIM management platforms, and contactless access verification terminals, the application, writing, and verification of contactless access user IDs are realized. The SIM card is used for identity verification and information verification, simplifying the operation process.
It enables convenient, economical, and secure identity verification and information checking for seamless passage in scenarios such as railways and civil aviation, reducing cumbersome steps such as manual operation and queuing, and improving user experience.
Smart Images

Figure CN121865252A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of information security technology, and in particular to a SIM card-based contactless access method, device, system, medium and program product. Background Technology
[0002] Currently, in scenarios with high resident travel volume, such as railways and civil aviation, traditional verification methods like ID cards or QR codes are generally used for business verification. However, using traditional ID cards presents challenges such as passengers forgetting to bring their ID cards or ID cards being easily lost. Using QR codes requires opening a mobile application, which is cumbersome. Clearly, existing business verification methods suffer from a lack of convenience. Summary of the Invention
[0003] This invention provides a SIM card-based contactless access method, device, system, medium, and program product to address the problem of poor convenience in current business verification methods.
[0004] To solve the above-mentioned technical problems, the present invention is implemented as follows:
[0005] In a first aspect, embodiments of the present invention provide a SIM card-based contactless access method applied to a mobile terminal, the mobile terminal including a contactless access user terminal and a SIM card, the method comprising:
[0006] The seamless access user terminal obtains the user's personal information, encrypts the user's personal information to obtain the first ciphertext, and sends the first ciphertext to the seamless access card application management platform to apply for a seamless access user ID;
[0007] The SIM card receives a sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The SIM card decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key.
[0008] The SIM card receives an instruction from the contactless access verification terminal to invoke the contactless access card application. Based on the instruction, the SIM card sends its hardware serial number and a random number to the contactless access verification terminal. The contactless access service encryption key and the random number are used to encrypt the contactless access user ID to obtain the contactless access user ID ciphertext. The contactless access user ID ciphertext is then sent to the contactless access verification terminal for contactless access verification.
[0009] Optionally, the user's personal information is encrypted to obtain a first ciphertext, including:
[0010] Based on the user's personal information, a real-person verification is performed. If the real-person verification is successful, the user's personal information and the verification result are encrypted to obtain the first ciphertext.
[0011] Optionally, the user's personal information includes facial image data; after sending the first encrypted message to the contactless access card application management platform, the process further includes:
[0012] The SIM card receives and stores the image compression data sent by the contactless access card application management platform, and the image compression data is obtained by compressing the image data.
[0013] Specifically, the seamless access service encryption key and the random number are used to encrypt the seamless access user ID to obtain the seamless access user ID ciphertext, including:
[0014] The SIM card uses the seamless access service encryption key and the random number to encrypt the seamless access user ID and the image compression data to obtain the seamless access user ID ciphertext.
[0015] Secondly, embodiments of the present invention provide a SIM card-based contactless access method, applied to a contactless access card application management platform, the method comprising:
[0016] Receive a first encrypted message sent by the seamless access user terminal in the mobile terminal, the first encrypted message including the user's personal information;
[0017] Decrypt the first ciphertext to obtain the user's personal information;
[0018] The user's personal information and the hardware serial number of the SIM card of the mobile terminal are encrypted to obtain the second ciphertext;
[0019] Send the second encrypted message to the seamless access service platform;
[0020] Receive a fourth ciphertext sent by the seamless access service platform, the fourth ciphertext containing a third ciphertext, the third ciphertext containing an encrypted seamless access user ID and an encrypted seamless access service encryption key;
[0021] Decrypting the fourth ciphertext yields the third ciphertext;
[0022] The third ciphertext is encrypted to obtain the fifth ciphertext;
[0023] The fifth encrypted message is sent to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
[0024] Optionally, the first ciphertext is decrypted to obtain the user's personal information, and then the process further includes:
[0025] The user's personal information is used for real-person verification. If the real-person verification is successful, the user's personal information and the hardware serial number of the SIM card of the mobile terminal are encrypted.
[0026] Thirdly, embodiments of the present invention provide a SIM card-based contactless access method, applied to a contactless access service platform, the method comprising:
[0027] The system receives a second encrypted message sent by the contactless access card application management platform. The second encrypted message includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card.
[0028] The second ciphertext is decrypted to obtain the user's personal information and the hardware serial number of the SIM card;
[0029] Based on the user's personal information and the SIM card's hardware serial number, a seamless access user ID is generated;
[0030] Generate a seamless access service encryption key based on the SIM card's hardware serial number;
[0031] The seamless access user ID and the seamless access service encryption key are encrypted to obtain the third ciphertext;
[0032] After encrypting the third ciphertext, a fourth ciphertext is obtained, and the fourth ciphertext is sent to the contactless access card application management platform.
[0033] Fourthly, embodiments of the present invention provide a SIM card-based seamless access method, applied to an operator's SIM management platform, the method comprising:
[0034] Receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key.
[0035] Decrypting the fifth ciphertext yields the seamless access user ID and the seamless access service encryption key;
[0036] The user ID and the encryption key for the contactless access service are encrypted to obtain the sixth ciphertext.
[0037] The sixth ciphertext is sent to the SIM card of the mobile terminal.
[0038] Fifthly, embodiments of the present invention provide a SIM card-based contactless access method, applied to a contactless access verification terminal, the method comprising:
[0039] After detecting the SIM card of the mobile terminal, a command to invoke the contactless access card application is sent to the SIM card;
[0040] Receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction;
[0041] Calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number;
[0042] The system receives a ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored on the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID.
[0043] The encrypted user ID of the seamless access service is decrypted using the calculated encryption key and the received random number to obtain the information to be verified.
[0044] The information to be verified is verified. If the verification is successful, the gate opening operation is performed.
[0045] Optionally, the method further includes:
[0046] Collect facial image data and compress the collected facial image data to obtain compressed facial image data;
[0047] The information to be verified also includes: the compressed facial image data stored on the SIM card;
[0048] The verification of the information to be verified includes:
[0049] The process involves comparing the user ID in the contactless communication information to be verified with the compressed facial image data collected by the contactless access verification terminal. If both the service comparison and the facial image comparison pass, the verification is confirmed to be successful.
[0050] Sixthly, embodiments of the present invention provide a mobile terminal, comprising:
[0051] The application module is used to obtain user personal information, encrypt the user personal information to obtain a first ciphertext, and send the first ciphertext to the contactless access card application management platform to apply for a contactless access user ID.
[0052] The writing module is used to receive the sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The module decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key.
[0053] The verification module is used to receive an instruction from the contactless access verification terminal to invoke the contactless access card application, and based on the instruction, send the hardware serial number of the SIM card and a random number to the contactless access verification terminal. It also encrypts the contactless access user ID using the contactless access service encryption key and the random number to obtain the contactless access user ID ciphertext, and sends the contactless access user ID ciphertext to the contactless access verification terminal for contactless access verification.
[0054] Seventhly, embodiments of the present invention provide a contactless access card application management platform, including:
[0055] The first receiving module is used to receive a first encrypted message sent by the seamless access user terminal in the mobile terminal, wherein the first encrypted message includes the user's personal information;
[0056] The first decryption module is used to decrypt the first ciphertext to obtain the user's personal information;
[0057] The first encryption module is used to encrypt the user's personal information and the hardware serial number of the SIM card of the mobile terminal to obtain the second ciphertext;
[0058] The first sending module is used to send the second ciphertext to the seamless access service platform;
[0059] The second receiving module is used to receive the fourth ciphertext sent by the seamless access service platform. The fourth ciphertext includes the third ciphertext, which includes the encrypted seamless access user ID and the encrypted seamless access service encryption key.
[0060] The second decryption module is used to decrypt the fourth ciphertext to obtain the third ciphertext;
[0061] The second encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the fifth ciphertext;
[0062] The second sending module is used to send the fifth encrypted message to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
[0063] Eighthly, embodiments of the present invention provide a seamless access service platform, including:
[0064] The receiving module is used to receive a second ciphertext sent by the contactless access card application management platform. The second ciphertext includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card.
[0065] The decryption module is used to decrypt the second ciphertext to obtain the user's personal information and the hardware serial number of the SIM card;
[0066] The first generation module is used to generate a seamless access user ID based on the user's personal information and the hardware serial number of the SIM card;
[0067] The second generation module is used to generate a seamless access service encryption key based on the SIM card's hardware serial number.
[0068] The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain a third ciphertext;
[0069] The sending module is used to encrypt the third ciphertext to obtain the fourth ciphertext, and then send the fourth ciphertext to the contactless access card application management platform.
[0070] Ninthly, embodiments of the present invention provide an operator SIM management platform, comprising:
[0071] The receiving module is used to receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key.
[0072] The decryption module is used to decrypt the fifth ciphertext to obtain the seamless access user ID and the seamless access service encryption key;
[0073] The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the sixth ciphertext;
[0074] The sending module is used to send the sixth ciphertext to the SIM card of the mobile terminal.
[0075] In a tenth aspect, embodiments of the present invention provide a contactless access verification terminal, comprising:
[0076] The sending module is used to send an instruction to the SIM card to invoke the contactless access card application after detecting the SIM card of the mobile terminal;
[0077] The first receiving module is used to receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction;
[0078] The calculation module is used to calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number;
[0079] The second receiving module is used to receive the ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored in the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID.
[0080] The decryption module is used to decrypt the ciphertext of the seamless access user ID using the calculated encryption key for the seamless access service and the received random number, so as to obtain the information to be verified.
[0081] The verification module is used to verify the information to be verified. If the verification is successful, the gate opening operation is performed.
[0082] In the eleventh aspect, embodiments of the present invention provide a SIM card-based contactless access system, including a mobile terminal as described in the sixth aspect above, a contactless access card application management platform as described in the seventh aspect above, a contactless access service platform as described in the eighth aspect above, an operator SIM management platform as described in the ninth aspect above, and a contactless access verification terminal as described in the tenth aspect above.
[0083] In a twelfth aspect, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, it implements the steps of the SIM card-based contactless access method as described in the first, second, third, fourth, or fifth aspects above.
[0084] In a thirteenth aspect, embodiments of the present invention provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the SIM card-based contactless access method as described in the first, second, third, fourth, or fifth aspects above.
[0085] In a fourteenth aspect, embodiments of the present invention provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the SIM card-based contactless access method as described in the first, second, third, fourth, or fifth aspects above.
[0086] In this embodiment of the invention, the various subsystems in the seamless communication system cooperate to complete the application, writing, and verification processes of the seamless access user ID, providing a convenient, economical, and safe solution for intelligent travel and addressing the inconveniences and pain points of existing user travel. Attached Figure Description
[0087] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0088] Figure 1 This is a schematic diagram of the architecture of a SIM card-based contactless access system according to an embodiment of the present invention.
[0089] Figure 2 This is a schematic diagram of the interaction process of the SIM card-based contactless access method according to an embodiment of the present invention;
[0090] Figure 3 This is a schematic diagram of the key management method according to an embodiment of the present invention;
[0091] Figure 4 This is a flowchart illustrating the SIM card-based contactless access method executed by a mobile terminal according to an embodiment of the present invention.
[0092] Figure 5 This is a flowchart illustrating the SIM card-based contactless access method executed by the contactless access card application management platform according to an embodiment of the present invention.
[0093] Figure 6 This is a flowchart illustrating the SIM card-based contactless access method executed by the contactless access service platform according to an embodiment of the present invention.
[0094] Figure 7 This is a flowchart illustrating the SIM card-based seamless access method executed by the operator's SIM management platform according to an embodiment of the present invention.
[0095] Figure 8 This is a flowchart illustrating the SIM card-based contactless access method executed by the contactless access verification terminal in an embodiment of the present invention.
[0096] Figure 9 This is a structural block diagram of a mobile terminal according to an embodiment of the present invention;
[0097] Figure 10 This is a structural block diagram of the contactless access card application management platform according to an embodiment of the present invention;
[0098] Figure 11 This is a structural block diagram of the seamless access service platform according to an embodiment of the present invention;
[0099] Figure 12 This is a structural block diagram of the operator SIM management platform according to an embodiment of the present invention;
[0100] Figure 13 This is a structural block diagram of the contactless access verification terminal according to an embodiment of the present invention;
[0101] Figure 14 This is a structural block diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0102] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0103] Currently, mobile phones have become an indispensable part of our daily lives. With the rapid advancement and development of internet technology, SIM (Subscriber Identity Module) cards, initially used for network access authentication, have been given more uses and, through continuous technological iteration and upgrades, have gradually become an important carrier of personal data assets. The Super SIM card, a product launched by operators based on 5G networks, plays an increasingly important role in the digital transformation of society as an innovative and secure digital asset carrier. It possesses three core characteristics: secure storage, secure computing, and secure connectivity, providing users with a trusted multi-application execution environment. The Super SIM card has already achieved significant results in applications such as digital RMB and digital identity.
[0104] Seamless access technology is a technology that relies on identification and verification of information such as identification documents or mobile phones. It aims to achieve seamless verification and access for both personal and business information. By using seamless access technology, people can avoid the cumbersome steps of manual operation and queuing, quickly and conveniently completing identity verification and information verification to achieve seamless access. It is suitable for various scenarios, such as airports, train stations, hotels, banks, shopping malls, and other places requiring identity verification and information verification, providing users with a better experience and service.
[0105] Please refer to Figure 1 , Figure 1This is a schematic diagram of the architecture of a contactless access system based on a SIM (Subscriber Identity Module) card according to an embodiment of the present invention. The contactless access system includes: a mobile terminal, a contactless access card application management platform, a contactless access service platform, an operator SIM management platform, and a contactless access verification terminal.
[0106] (1) Mobile terminal
[0107] The mobile terminal in this embodiment of the invention can be a mobile phone terminal or other terminals, such as a smartwatch. The mobile terminal further includes: a contactless communication user terminal and a SIM card.
[0108] Seamless communication user client: Also known as seamless communication user portal, it can be set up in the mobile terminal in the form of H5 (HTML5), mini-program or client (APP). The seamless communication user client can apply to the operator's SIM management platform for AC (Access Control) rules for the seamless access card application on the SIM card (access control rules include access permissions for the seamless access card application), thereby obtaining the right to access the seamless access card application on the SIM card. The collected user personal information (such as ID card number, user name and facial image data) is securely transmitted in plaintext to the seamless access card application management platform to apply for a seamless access user ID (also referred to as user ID).
[0109] SIM card: Also known as a super SIM card, it serves as a secure carrier for contactless access card applications, providing proactive human-computer interaction command capabilities, as well as commercial cryptography-related services, including public key encryption and decryption, private key signature verification, symmetric key operations, and digest algorithms.
[0110] Seamless access card application: This is a card application specially designed for this invention. It is stored in the SIM card and, under the premise of meeting security policies, can complete the secure writing and reading of the seamless access user ID. It can also complete remote application management and other capabilities through the operator's SIM management platform.
[0111] The SIM card and the contactless access card can communicate with each other through the card-machine interface.
[0112] (2) Seamless access card application management platform
[0113] The contactless access card application management platform connects with the contactless access user terminal, the contactless access service platform, and the operator's SIM management platform to complete the application for the contactless access user ID. It then writes the contactless access user ID into the SIM card through the operator's SIM management platform, thereby managing the contactless access card application and the writing of the contactless access user ID within the SIM card.
[0114] (3) Seamless access service platform
[0115] The seamless access service platform mainly includes an application management module, a personal data management module, a data service module, a password management module, and an access / outbound management module, to complete functions such as seamless access user ID generation, management, and verification.
[0116] Application Management Module: Responsible for at least one of the following: installation, download, deletion, validity and invalidation of contactless access card applications, and management of contactless access business encryption key writing / update function.
[0117] Personal Data Management Module: Responsible for organizing the writing of seamless access user IDs into SIM cards, defining the data format, security requirements, data size, and encryption / decryption algorithms for seamless access user IDs, generating seamless access user IDs, and writing seamless access user IDs through the operator's SIM management platform.
[0118] The data service module maintains and verifies information related to the contactless access card application and user personal information (such as ID card, user name, and facial image data), and provides users with query services. This primarily includes queries for user SIM card information, contactless access card application information, auxiliary security domain configuration information, and personal user storage information. User SIM card information includes the user's mobile phone number, SIM card identifier, and carrier information; contactless access card application information includes the contactless access card application identifier (AID), application version, and installation status; and auxiliary security domain configuration information includes security domain configuration information, key configuration information, and system configuration parameters.
[0119] Password Management Module: Responsible for security domain key management, personal data service keys, and password-related encryption and decryption services.
[0120] Access / Outbound Management Module: Routes data from the user's mobile phone number to the operator's SIM management platform, initiating SIM card-related card content management tasks, including downloading, installing, activating, and deactivating the contactless access card application; writing and reading personal data; writing and updating the contactless access service encryption key; and reading the SIM card SEID (SIM card hardware serial number). It can also interface with business systems to complete the application for contactless access user IDs.
[0121] Carrier SIM Management Platform: Also known as TSM (Trusted Service Manager) platform. It is responsible for the space management of user SIM cards, enabling remote management of SIM cards for identity providers, and managing and updating SIM card access control (AC) rules; its main functions include:
[0122] Application Management Support Module: Responsible for data preparation, SIM card information query (mobile number operator affiliation query, number card relationship query), asynchronous notification of SIM card operation results, etc.
[0123] Card Content Management Module: Responsible for all data management operations within the SIM card, including downloading, activating, deactivating, writing personal data, reading personal data, and writing encryption keys for the contactless access service.
[0124] (4) Seamless access verification terminal
[0125] By integrating SIM card NFC (Near Field Communication) card swiping service, the system can read the contactless access user ID from the SIM card via NFC communication, connect the contactless access user ID with the business system to complete business verification, and enable gate opening operation after successful verification.
[0126] The SIM card-based contactless access system in this embodiment of the invention mainly includes the construction of a contactless access card application management platform, the construction of a contactless access card application, and the construction of a contactless access service platform. Through the business cooperation between the subsystems, after the contactless access card application is activated, the contactless access service can be completed by swiping the SIM card using NFC (Near Field Communication).
[0127] Please refer to Figure 2 This invention provides a SIM card-based contactless access method, which includes:
[0128] Step S1: Activate the contactless access card application.
[0129] In this step, the user installs the contactless access user client on their mobile terminal and applies to the contactless access card application management platform through the client to activate the contactless access card application and its AC (access control) rules. The contactless access card application management platform forwards the application to the operator's SIM management platform. The operator's SIM management platform remotely activates the contactless access card application based on the user's personal information (such as mobile phone number), writes the contactless access card application's AC (access control) rules to the SIM card, and notifies the user that activation is complete.
[0130] Optionally, step S1 includes:
[0131] Step S11: The seamless access user terminal operator and the operator's SIM management platform complete the security key exchange. This security key exchange can be completed offline (e.g., via email, counter service, etc.) or online. The seamless access user terminal operator also needs to submit an APP identifier (e.g., APP Hash value) to the operator's SIM management platform (used to uniquely identify the seamless access user terminal). The operator's SIM management platform will add the APP identifier to its whitelist, thus completing the seamless access user terminal operator's access application.
[0132] Step S12: The user terminal of the contactless access card applies to the contactless access card application management platform to activate the contactless access card application service and apply for the AC rules of the contactless access card application. Optionally, the user can apply to activate the contactless access card application service through H5, customer service hotline and dedicated SMS.
[0133] Step S13: After receiving the user application from the above steps, the contactless access card application management platform forwards the user application to the operator's SIM management platform.
[0134] Step S14: The operator's SIM management platform performs the following operations based on the received user application:
[0135] Assign a security domain and initial security key to the user's SIM card;
[0136] Data on the download and installation of the contactless access card application;
[0137] The organization writes AC rules into the data.
[0138] Step S15: The operator's SIM management platform writes the organization's seamless access card application and AC rules into the SIM card. At this point, the seamless access card application is successfully activated. The operator's SIM management platform enters the seamless communication user's identifier (such as hash value) into the configuration library and configures it to access the seamless access application. At this point, the seamless access user terminal has the ability to access the SIM card.
[0139] It should be noted that step S1 above can be completed online or offline.
[0140] Step S2: Apply for a seamless access user ID.
[0141] In this step, the seamless access user terminal obtains the user's personal information and sends it to the seamless access card application management platform. The seamless access card application management platform then securely packages the user's personal information and sends it to the seamless access business platform to apply for a seamless communication user ID.
[0142] Optionally, step S2 includes:
[0143] Step S21: The contactless access user terminal in the mobile terminal obtains the user's personal information, encrypts the user's personal information to obtain the first ciphertext, and sends the first ciphertext to the contactless access card application management platform to apply for a contactless access user ID.
[0144] In some embodiments, user personal information may include three elements, such as ID card, user name, and facial image data. In other embodiments, user personal information may include two elements, such as ID card and user name (excluding facial image data).
[0145] In some embodiments, optionally, the user's personal information can be encrypted using the public key of the contactless access card application management platform to obtain the first ciphertext. The public key of the contactless access card application management platform can be sent to the contactless access user terminal by the contactless access card application management platform when the user terminal applies to activate the contactless communication card application.
[0146] In some embodiments, if the contactless access user terminal has real-person verification capabilities, the user's personal information is encrypted to obtain a first ciphertext. This includes: performing real-person verification based on the user's personal information; if the real-person verification is successful, encrypting the user's personal information and the verification result to obtain the first ciphertext. For example, the user's personal information and the verification result are encrypted as M1 (e.g., M1 = SM2Encrypt(user's personal information, contactless access card application management platform public key)). If the real-person verification fails, an error message is displayed, and the process ends.
[0147] In some embodiments, if the contactless access user terminal does not have the ability to verify the identity of the user, the user's personal information is encrypted to obtain a first ciphertext. For example, the user's personal information is securely encrypted as M1' (e.g., M1' = SM2Encrypt(user's personal information, contactless access card application management platform public key)).
[0148] S22: The contactless access card application management platform receives a first encrypted message sent by the contactless access user terminal in the mobile terminal, the first encrypted message including user personal information; the contactless access card application management platform decrypts the first encrypted message to obtain the user personal information;
[0149] In some embodiments, optionally, the user's personal information can be decrypted using the private key corresponding to the public key used to encrypt the first ciphertext.
[0150] In some embodiments, if the first ciphertext sent by the seamless access user terminal is the aforementioned M1, the seamless access card application management platform uses the private key corresponding to the public key that encrypts M1 to decrypt M1, thereby obtaining the user's personal information and verification result. If the verification result is that the real person verification is successful, the application process for the seamless access user ID is initiated (i.e., the step of encrypting the user's personal information and the hardware serial number of the SIM card of the mobile terminal described below).
[0151] In some embodiments, if the first ciphertext sent by the seamless access user terminal is M1' as described above, the seamless access card application management platform decrypts M1' using the private key corresponding to the public key used to encrypt M1', obtaining the user's personal information. The seamless access card application management platform then uses the user's personal information for real-person verification. If the real-person verification is successful, the application process for the seamless access user ID begins (i.e., the step described below of encrypting the user's personal information and the hardware serial number of the mobile terminal's SIM card). If the real-person verification fails, an error message is displayed, and the process ends.
[0152] In some embodiments, the user's personal information includes facial image data. To ensure efficient use of SIM card space and verification efficiency, the contactless access card application management platform can compress the facial image data to obtain compressed facial image data, which is then written to the SIM card through the operator's SIM management platform. For example, the facial image data can be compressed to approximately 1KB, resulting in a relatively small data size.
[0153] As a SIM card, the first encrypted message is sent to the contactless access card application management platform. The process also includes: the SIM card receiving and storing the image compression data sent by the contactless access card application management platform, wherein the image compression data is obtained by compressing the image data.
[0154] S23: The contactless access card application management platform encrypts the user's personal information and the hardware serial number (SEID) of the SIM card of the mobile terminal to obtain a second ciphertext; the contactless access card application management platform sends the second ciphertext to the contactless access service platform;
[0155] In some embodiments, optionally, the contactless access card application management platform uses the public key of the contactless access service platform to encrypt the user's personal information and the hardware serial number of the mobile terminal's SIM card to obtain a second ciphertext. For example, the second ciphertext is M2, where M2 = SM2Encrypt(user's personal information + SEID + operator's SIM management platform public key, contactless access service platform public key)). The user's SIM card's hardware serial number (SEID) is unique across the entire network and is used to identify the SIM card. In this embodiment, the contactless access card application management platform uses the public key of the contactless access service platform to encrypt the user's personal information, the mobile terminal's SIM card hardware serial number, and the operator's SIM management platform public key to obtain the second ciphertext.
[0156] Step S3: Generate seamless access user ID.
[0157] In this step, after receiving the second ciphertext, the seamless access service platform uses the private key corresponding to the key used to encrypt the second ciphertext to decrypt it, obtaining the user's personal information. The user's personal information is then compared with the stored seamless access user ID whitelist to determine whether the user has already applied for a seamless access user ID. If the user has already applied, a duplicate application error is returned, and the process ends. Otherwise, the user's personal information is used to calculate the seamless access user ID, which is then entered into the whitelist and encrypted before being returned to the seamless access card application management platform.
[0158] Optionally, step S3 includes:
[0159] Step S31: The seamless access service platform receives the second ciphertext sent by the seamless access card application management platform. The second ciphertext includes encrypted user personal information and encrypted hardware serial number of the SIM card of the mobile terminal. The seamless access service platform decrypts the second ciphertext to obtain the user personal information and the hardware serial number of the SIM card.
[0160] Optionally, the seamless access service platform uses the private key corresponding to the key used to encrypt the second ciphertext (the public key of the seamless access service platform) to decrypt the second ciphertext. For example, if the second ciphertext is M2, and M2 = SM2Encrypt(user personal information + SEID + operator SIM management platform public key, seamless access service platform public key)), then user personal information = SM2Decrypt(M, seamless access service platform private key)).
[0161] In some embodiments, optionally, the seamless access service platform compares the decrypted user personal information with the seamless access user ID whitelist to determine whether the current user has already applied for a seamless access user ID. If not, it proceeds to S32 to calculate the seamless access user ID. Otherwise, it returns a duplicate application error and terminates the process.
[0162] Step S32: The seamless access service platform generates a seamless access user ID based on the user's personal information and the hardware serial number of the SIM card;
[0163] In some embodiments, optionally, the seamless access user ID is 16 bytes of HEX type data.
[0164] In some embodiments, optionally, the seamless access service platform generates a seamless access user ID using the user's ID number and the SIM card's hardware serial number (SEID) as plaintext information, ensuring that each seamless access user ID is unique.
[0165] In some embodiments, an optional example of generating a seamless access user ID is as follows:
[0166] Seamless access user ID = SM4Enk(KeyA, ID card number);
[0167] The encryption algorithm used is SM4, and the length of the seamless access user ID is 16 bytes.
[0168] In some embodiments, the KeyA key may be calculated as follows: Using encryption algorithms such as AES (Advanced Encryption Standard) or SM4, KeyA is obtained based on the user's SIM card hardware serial number (SEID) (e.g., KeyA = EncryptSM4(SEID + Seamless Access Card Application AID, KA)). Here, the Seamless Access Card Application AID refers to the identifier of the Seamless Access Card application, and KA is the master key issued by the Seamless Access Service Platform.
[0169] Step S33: The seamless access service platform generates a seamless access service encryption key based on the hardware serial number of the SIM card;
[0170] In this embodiment of the invention, the seamless access service platform generates a unique seamless access service encryption key KeyB for the SIM card, which is used to protect the seamless access user ID when the seamless access verification terminal reads the seamless access user ID via NFC.
[0171] In some embodiments, optionally, the length of the encryption key (KeyB) for the contactless access service is 16 bytes, and the generation algorithm can be SM4 or AES, such as KeyB = EncryptSM4(SEID + contactless access card application AID, KB), where KB is the master key issued by the contactless access service platform.
[0172] Step S34: The seamless access service platform encrypts the seamless access user ID and the seamless access service encryption key to obtain a third ciphertext; the seamless access service platform encrypts the third ciphertext to obtain a fourth ciphertext and sends the fourth ciphertext to the seamless access card application management platform.
[0173] In some embodiments, optionally, the seamless access service platform can use the public key of the operator's SIM management platform to encrypt the seamless access user ID and the seamless access service encryption key to obtain a third ciphertext, and then use the public key of the seamless access card application management platform to encrypt the third ciphertext to obtain a fourth ciphertext.
[0174] In some embodiments, optionally, the third ciphertext is M3 and the fourth ciphertext is M4, where M4 = Sign{(M3 = SM2Encrypt(KeyB + Seamless Access User ID, Public Key of Operator SIM Management Platform)) Seamless Access Card Application Management Platform Public Key}.
[0175] S35: The contactless access card application management platform receives a fourth ciphertext sent by the contactless access service platform. The fourth ciphertext contains a third ciphertext, which contains an encrypted contactless access user ID and an encrypted contactless access service encryption key. The contactless access card application management platform decrypts the fourth ciphertext to obtain the third ciphertext.
[0176] S36: The seamless access card application management platform encrypts the third ciphertext to obtain the fifth ciphertext; the seamless access card application management platform sends the fifth ciphertext to the operator's SIM management platform to write the seamless access user ID and the seamless access service encryption key into the SIM card of the mobile terminal.
[0177] This completes the application process for the seamless access user ID. The process of writing the seamless access user ID will then begin.
[0178] Step S4: Write the seamless access user ID.
[0179] In this step, the seamless access service platform writes the seamless access user ID to the SIM card through the operator's SIM management platform. The operator's SIM management platform first establishes a secure communication channel with the SIM card, then activates the seamless access card application and sends a seamless access user ID writing command. After parsing the command, the seamless access card application stores the seamless access user ID in its application space, completing the seamless access user ID writing. The operator's SIM management platform notifies the seamless access service platform that the seamless access user ID writing was successful. Any error encountered during the writing process will terminate the writing process and notify the seamless access service platform of the error.
[0180] Optionally, step S4 includes:
[0181] Step S41: The operator's SIM management platform first establishes communication with the SIM card based on the user's current mobile phone number or SEID (transmitted by the contactless access card application management platform). Optionally, it can choose BIP (Bearer Independence Protocol) or SMS to establish communication with the SIM card. Then, it opens a secure channel. Optionally, it can choose SCP02 or SCP03 secure channel. The operator's SIM management platform and the SIM card complete the generation of a session key, which is used to complete subsequent business interactions.
[0182] Step S42: The operator's SIM management platform receives the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes an encrypted contactless access user ID and an encrypted contactless access service encryption key. The operator's SIM management platform decrypts the fifth ciphertext to obtain the contactless access user ID and the contactless access service encryption key. The operator's SIM management platform encrypts the contactless access user ID and the contactless access service encryption key to obtain the sixth ciphertext. The operator's SIM management platform sends the sixth ciphertext to the SIM card of the mobile terminal.
[0183] In this embodiment of the invention, optionally, the sixth ciphertext is M6, where M6 = SM4Sign(KeyB, SM4Encrypt(SessionKey, KeyB + Seamless Access User ID)).
[0184] In this embodiment of the invention, optionally, the operator's SIM management platform assembles the M6 into an APDU (Application Protocol Data Unit) instruction that can be recognized by the contactless access card application and sends it to the SIM card.
[0185] Step S43: The SIM card of the mobile terminal receives the sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The SIM card decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key.
[0186] Optionally, the SIM card sends the aforementioned APDU instruction to the contactless access card application; for example, in the format 00B80000Length+M6. The contactless access card application parses the APDU instruction, uses the generated SessionKey to perform data MAC (Message Authentication Code) verification and data decryption, recovers KeyB + contactless access user ID, and writes KeyB + contactless access user ID into a specific storage area within the application.
[0187] Step S44: The SIM card returns a successful write result to the operator's SIM management platform. The operator's SIM management platform then returns the result to the contactless access card application management platform, and finally provides feedback to the user. At this point, the write operation of the contactless access user ID is complete.
[0188] Step S5: Seamless access user ID verification.
[0189] When users travel in scenarios such as high-speed rail and civil aviation that utilize contactless access cards, they bring the NFC of their mobile terminal (such as a mobile phone) close to the contactless access verification terminal (such as a railway verification gate) to complete the reading of the contactless access user ID. The contactless access user ID is then verified with the business system. If the verification is successful, the gate opening action is completed; otherwise, the process ends.
[0190] The verification process of the seamless access user ID in this embodiment of the invention includes two scenarios: comparison with and without facial image.
[0191] 1. Scenarios where the verification process does not include facial recognition:
[0192] S51-1: After the contactless access verification terminal detects the SIM card of the mobile terminal, it sends an instruction to the SIM card to invoke the contactless access card application.
[0193] S51-2: The SIM card receives an instruction from the contactless access verification terminal to invoke the contactless access card application, and based on the instruction, sends the hardware serial number and random number of the SIM card to the contactless access verification terminal.
[0194] In some embodiments, optionally, after the SIM card receives the instruction to call the contactless access card application, it calls the contactless access card application processing interface through the application registry. The contactless access card application then returns the hardware serial number and random number of the SIM card, thus activating the contactless access card application.
[0195] Optionally, the random number can be a 16-byte random number.
[0196] S51-3: The contactless access verification terminal receives the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction; the contactless access verification terminal calculates the contactless access service encryption key of the SIM card based on the hardware serial number of the SIM card;
[0197] For example, the encryption key KeyB for the seamless access service of the SIM card can be calculated using the following method: KeyB = SM4Encrypt(SEID, KB), where KB can be written to the seamless access verification terminal offline.
[0198] S51-4: The SIM card uses the seamless access service encryption key and the random number to encrypt the seamless access user ID to obtain the seamless access user ID ciphertext, and sends the seamless access user ID ciphertext to the seamless access verification terminal for seamless access verification.
[0199] Optionally, after receiving the call instruction from the SIM card, the contactless access card application performs security verification and parsing on the instruction. If the verification is successful, it performs security processing on the contactless access user ID, encrypts the contactless access user ID using the application's contactless access service encryption key KeyB and the random number to obtain the contactless access user ID ciphertext, and sends the contactless access user ID ciphertext to the contactless access verification terminal for contactless access verification.
[0200] In some embodiments, the specific formula for the encrypted user ID M7 for seamless access is optionally as follows:
[0201] M7 = SM4Encryt (Seamless Access User ID, SessionKey{R16,KeyB}).
[0202] S51-5: The seamless access verification terminal receives the seamless access user ID ciphertext sent by the SIM card. The seamless access user ID ciphertext is obtained by encrypting the information to be verified stored on the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID. The seamless access verification terminal decrypts the seamless access user ID ciphertext using the calculated seamless access service encryption key and the received random number to obtain the information to be verified. The seamless access verification terminal performs seamless access user ID and service verification.
[0203] Optionally, the seamless access verification terminal performs the same SessionKey calculation on the calculated KeyB, decrypts the ciphertext of the seamless access user ID to obtain the plaintext of the seamless access user ID, and then sends the seamless access user ID to the business system for security verification and business verification. If the business verification is successful, the verification result is returned to the seamless access verification terminal.
[0204] Optionally, the specific formula for the plaintext user ID for seamless access is:
[0205] Seamless access user ID plaintext = SM4Dcrypt(seamless access user ID ciphertext, SessionKey{R16, KeyB})
[0206] S51-6: If the verification is successful, then the gate opening operation will be performed.
[0207] 2. Scenarios where facial recognition is integrated into the verification process:
[0208] S52-1: After the contactless access verification terminal detects the SIM card of the mobile terminal, it sends an instruction to the SIM card to call the contactless access card application, and at the same time collects facial image data and compresses the collected facial image data to obtain compressed facial image data.
[0209] S52-2: The SIM card receives an instruction from the contactless access verification terminal to invoke the contactless access card application, and based on the instruction, sends the hardware serial number and random number of the SIM card to the contactless access verification terminal.
[0210] In some embodiments, optionally, after the SIM card receives the instruction to call the contactless access card application, it calls the contactless access card application processing interface through the application registry. The contactless access card application then returns the hardware serial number and random number of the SIM card, thus activating the contactless access card application.
[0211] Optionally, the random number can be a 16-byte random number.
[0212] S52-3: The contactless access verification terminal receives the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction; the contactless access verification terminal calculates the contactless access service encryption key of the SIM card based on the hardware serial number of the SIM card;
[0213] For example, the encryption key KeyB for the seamless access service of the SIM card can be calculated using the following method: KeyB = SM4Encrypt(SEID, KB), where KB can be written to the seamless access verification terminal offline.
[0214] S52-4: The SIM card uses the seamless access service encryption key and the random number to encrypt the seamless access user ID and the image compression data to obtain the seamless access user ID ciphertext, and sends the seamless access user ID ciphertext to the seamless access verification terminal for seamless access verification.
[0215] Optionally, after receiving the call instruction from the SIM card, the contactless access card application performs security verification and parsing on the instruction. If the verification is successful, it performs secure processing of the contactless access user ID, encrypting the contactless access user ID and the image compression data using the application's contactless access service encryption key KeyB and the random number to obtain the contactless access user ID ciphertext, and sending the contactless access user ID ciphertext to the contactless access verification terminal for contactless access verification.
[0216] In some embodiments, the optional formula for the encrypted user ID for seamless access is as follows:
[0217] The encrypted user ID for seamless access is SM4Encryt(user ID for seamless access + compressed image, SessionKey{R16,KeyB}).
[0218] S52-5: The seamless access verification terminal receives the seamless access user ID ciphertext sent by the SIM card. The seamless access user ID ciphertext is obtained by encrypting the seamless access user ID and the image compression data using the seamless access service encryption key and the random number. The seamless access verification terminal decrypts the seamless access user ID ciphertext using the calculated seamless access service encryption key and the received random number to obtain the information to be verified. The information to be verified includes the seamless access user ID and the image compression data. The seamless access verification terminal performs a service comparison based on the seamless communication user ID in the information to be verified, and performs an image comparison between the image compression data in the information to be verified and the image compression data collected by the seamless access verification terminal. If both the service comparison and the image comparison pass, the verification is confirmed to be successful.
[0219] Optionally, the seamless access verification terminal performs the same SessionKey calculation on the calculated KeyB, decrypts the ciphertext of the seamless access user ID to obtain the seamless access user ID and the plaintext of the compressed facial image data. Then, the seamless access verification terminal sends the seamless access user ID to the business system for business verification. At the same time, it compares the plaintext of the compressed facial image data with the collected and calculated compressed facial image data. If the business verification and facial image verification are successful, the verification result is returned to the seamless access verification terminal.
[0220] S52-6: If the verification is successful, the gate opening operation will be performed.
[0221] The key management process used in the following embodiments of the present invention will be described.
[0222] In this embodiment of the invention, a two-level decentralized security strategy can be adopted to complete the KMS (Key Management Service) management process, including key distribution, entry, update, and management, ensuring that the keys used by each system are independent, secure, and controllable, while also ensuring that key management is simple and efficient, effectively integrating the keys and algorithms used by each system.
[0223] Please refer to Figure 3 Examples will be given to illustrate the key management methods on each system side.
[0224] 1) Seamless access control platform: Generates and stores root key KEY.
[0225] 2) The seamless access service platform distributes the access service key KA for the seamless access service of SIM cards and assigns a unique KeyA service key to each SIM card, for example, KeyA=SM4Encrypt(KA,SEID||seamless access user ID).
[0226] 3) The contactless access service platform assigns an application management key KB to the contactless access card application management platform. The contactless access card application management platform assigns a unique KeyB transmission key to each SIM card and stores KeyB on the SIM card. This ensures that each user uses a different transmission key for each contactless access, guaranteeing one-time password and improving security.
[0227] 4) The contactless access verification terminal stores KA and KB keys. When a user uses the contactless access card application, the contactless access verification terminal obtains KeyA and KeyB through the same distribution rules and performs relevant verification processing.
[0228] In the diagram, the KA and KB keys can be transmitted offline or via dedicated line through the inter-platform key service interface.
[0229] The following describes the SIM card-based contactless access methods executed by each subsystem in the contactless access system.
[0230] Please refer to Figure 4 This invention also provides a SIM card-based contactless access method applied to a mobile terminal, the mobile terminal including a contactless access user terminal and a SIM card, the method including:
[0231] Step S401: The contactless access user terminal obtains the user's personal information, encrypts the user's personal information to obtain the first ciphertext, and sends the first ciphertext to the contactless access card application management platform to apply for a contactless access user ID;
[0232] Step S402: The SIM card receives the sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The SIM card decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key.
[0233] Step S403: The SIM card receives an instruction from the contactless access verification terminal to invoke the contactless access card application. Based on the instruction, the SIM card sends its hardware serial number and a random number to the contactless access verification terminal. The contactless access service encryption key and the random number are used to encrypt the contactless access user ID to obtain the contactless access user ID ciphertext. The contactless access user ID ciphertext is then sent to the contactless access verification terminal for contactless access verification.
[0234] In some embodiments, optionally, encrypting the user's personal information to obtain a first ciphertext includes: performing real-person verification based on the user's personal information; if the real-person verification is successful, encrypting the user's personal information and the verification result to obtain the first ciphertext.
[0235] In some embodiments, optionally, the user's personal information includes facial image data; after sending the first encrypted text to the contactless access card application management platform, the method further includes:
[0236] The SIM card receives and stores the image compression data sent by the contactless access card application management platform, and the image compression data is obtained by compressing the image data.
[0237] Specifically, the seamless access service encryption key and the random number are used to encrypt the seamless access user ID to obtain the seamless access user ID ciphertext, including:
[0238] The SIM card uses the seamless access service encryption key and the random number to encrypt the seamless access user ID and the image compression data to obtain the seamless access user ID ciphertext.
[0239] Specific details of the SIM card-based contactless access method executed by the mobile terminal in this embodiment of the invention can be found in [reference needed]. Figure 2 The embodiment shown illustrates a SIM card-based seamless access method executed on the mobile terminal side.
[0240] Please refer to Figure 5 This invention also provides a SIM card-based contactless access method, applied to a contactless access card application management platform, the method comprising:
[0241] Step S501: Receive the first encrypted message sent by the seamless access user terminal in the mobile terminal, wherein the first encrypted message includes the user's personal information;
[0242] Step S502: Decrypt the first ciphertext to obtain the user's personal information;
[0243] Step S503: Encrypt the user's personal information and the hardware serial number of the SIM card of the mobile terminal to obtain the second ciphertext;
[0244] Step S504: Send the second encrypted message to the seamless access service platform;
[0245] Step S505: Receive the fourth ciphertext sent by the seamless access service platform, the fourth ciphertext containing the third ciphertext, the third ciphertext containing the encrypted seamless access user ID and the encrypted seamless access service encryption key;
[0246] Step S506: Decrypt the fourth ciphertext to obtain the third ciphertext;
[0247] Step S507: Encrypt the third ciphertext to obtain the fifth ciphertext;
[0248] Step S508: Send the fifth ciphertext to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
[0249] In some embodiments, optionally, the first ciphertext is decrypted to obtain the user's personal information, and then the method further includes: using the user's personal information to perform real-person verification; if the real-person verification is successful, proceeding to the step of encrypting the user's personal information and the hardware serial number of the SIM card of the mobile terminal.
[0250] Specific details of the SIM card-based contactless access method executed by the contactless access card application management platform in this embodiment of the invention can be found in the reference. Figure 2 The embodiment shown illustrates a SIM card-based contactless access method executed on the application management platform side.
[0251] Please refer to Figure 6 This invention also provides a SIM card-based seamless access method, applied to a seamless access service platform, the method comprising:
[0252] Step S601: Receive the second ciphertext sent by the contactless access card application management platform. The second ciphertext includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card.
[0253] Step S602: Decrypt the second ciphertext to obtain the user's personal information and the hardware serial number of the SIM card;
[0254] Step S603: Generate a seamless access user ID based on the user's personal information and the hardware serial number of the SIM card;
[0255] Step S604: Generate a seamless access service encryption key based on the SIM card's hardware serial number;
[0256] Step S605: Encrypt the seamless access user ID and the seamless access service encryption key to obtain the third ciphertext;
[0257] Step S606: After encrypting the third ciphertext, a fourth ciphertext is obtained, and the fourth ciphertext is sent to the contactless access card application management platform.
[0258] Specific details of the SIM card-based contactless access method executed by the contactless access service platform in this embodiment of the invention can be found in the reference. Figure 2 The embodiment shown illustrates a SIM card-based seamless access method executed on the seamless access service platform side.
[0259] Please refer to Figure 7 This invention also provides a SIM card-based seamless access method, applied to an operator's SIM management platform, the method comprising:
[0260] Step S701: Receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key.
[0261] Step S702: Decrypt the fifth ciphertext to obtain the seamless access user ID and the seamless access service encryption key;
[0262] Step S703: Encrypt the seamless access user ID and the seamless access service encryption key to obtain the sixth ciphertext;
[0263] Step S704: Send the sixth ciphertext to the SIM card of the mobile terminal.
[0264] Specific details of the SIM card-based contactless access method executed by the operator's SIM management platform in this embodiment of the invention can be found in [reference needed]. Figure 2 The embodiment shown illustrates a SIM card-based seamless access method executed on the operator's SIM management platform side.
[0265] Please refer to Figure 8This invention also provides a SIM card-based contactless access method, applied to contactless access verification terminals, the method comprising:
[0266] Step S801: After detecting the SIM card of the mobile terminal, send an instruction to the SIM card to invoke the contactless access card application;
[0267] Step S802: Receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction;
[0268] Step S803: Calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number;
[0269] Step S804: Receive the ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored in the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID.
[0270] Step S805: Using the calculated encryption key for the seamless access service and the received random number, decrypt the ciphertext of the seamless access user ID to obtain the information to be verified;
[0271] Step S806: Verify the information to be verified. If the verification is successful, perform the gate opening operation.
[0272] Optionally, the SIM card-based contactless access method further includes:
[0273] Collect facial image data and compress the collected facial image data to obtain compressed facial image data;
[0274] The information to be verified also includes: the compressed facial image data stored on the SIM card;
[0275] The contactless access verification terminal verifies the information to be verified, including:
[0276] The process involves comparing the user ID in the contactless communication information to be verified with the compressed facial image data collected by the contactless access verification terminal. If both the service comparison and the facial image comparison pass, the verification is confirmed to be successful.
[0277] Specific details of the SIM card-based contactless access method executed by the contactless access verification terminal in this embodiment of the invention can be found in the reference. Figure 2 The embodiment shown illustrates a SIM card-based contactless access method executed on the contactless access verification terminal side.
[0278] The above-mentioned SIM card-based contactless access method has the following beneficial effects:
[0279] First, it simplifies user operations and enhances the travel experience. Users can quickly pass through the business verification process without actively presenting tickets or performing any operations, which not only greatly improves passage efficiency but also reduces user waiting time.
[0280] Second, it proposes a new generation of seamless access technology to protect privacy. The SIM card serves as a secure carrier, ensuring that all personal and travel information is processed and stored in a secure environment, effectively protecting user privacy.
[0281] Third, it will drive the upgrading and iteration of traditional business verification methods (such as ticket verification). This invention will lead a revolution in business verification methods, transitioning from traditional verification methods to a fully automated business verification process using SIM cards.
[0282] Please refer to Figure 9 This invention also provides a mobile terminal, comprising:
[0283] The application module is used to obtain user personal information, encrypt the user personal information to obtain a first ciphertext, and send the first ciphertext to the contactless access card application management platform to apply for a contactless access user ID.
[0284] The writing module is used to receive the sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The module decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key.
[0285] The verification module is used to receive an instruction from the contactless access verification terminal to invoke the contactless access card application, and based on the instruction, send the hardware serial number of the SIM card and a random number to the contactless access verification terminal. It also encrypts the contactless access user ID using the contactless access service encryption key and the random number to obtain the contactless access user ID ciphertext, and sends the contactless access user ID ciphertext to the contactless access verification terminal for contactless access verification.
[0286] In some embodiments, optionally, the first application module is used to perform real-person verification based on the user's personal information. If the real-person verification is successful, the user's personal information and the verification result are encrypted to obtain a first ciphertext.
[0287] In some embodiments, optionally, the mobile terminal further includes:
[0288] The receiving module is used to receive and store the image compression data sent by the contactless access card application management platform, wherein the image compression data is obtained by compressing the image data.
[0289] Specifically, encrypting the seamless access user ID using the seamless access service encryption key and the random number to obtain the seamless access user ID ciphertext includes: encrypting the seamless access user ID and the image compression data using the seamless access service encryption key and the random number to obtain the seamless access user ID ciphertext.
[0290] Please refer to Figure 10 This invention also provides a contactless access card application management platform, comprising:
[0291] The first receiving module is used to receive a first encrypted message sent by the seamless access user terminal in the mobile terminal, wherein the first encrypted message includes the user's personal information;
[0292] The first decryption module is used to decrypt the first ciphertext to obtain the user's personal information;
[0293] The first encryption module is used to encrypt the user's personal information and the hardware serial number of the SIM card of the mobile terminal to obtain the second ciphertext;
[0294] The first sending module is used to send the second ciphertext to the seamless access service platform;
[0295] The second receiving module is used to receive the fourth ciphertext sent by the seamless access service platform. The fourth ciphertext includes the third ciphertext, which includes the encrypted seamless access user ID and the encrypted seamless access service encryption key.
[0296] The second decryption module is used to decrypt the fourth ciphertext to obtain the third ciphertext;
[0297] The second encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the fifth ciphertext;
[0298] The second sending module is used to send the fifth encrypted message to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
[0299] In some embodiments, optionally, the contactless access card application management platform further includes:
[0300] The real-person verification module is used to perform real-person verification using the user's personal information. If the real-person verification is successful, the module proceeds to the step of encrypting the user's personal information and the hardware serial number of the SIM card of the mobile terminal.
[0301] Please refer to Figure 11 This invention also provides a seamless access service platform, comprising:
[0302] The receiving module is used to receive a second ciphertext sent by the contactless access card application management platform. The second ciphertext includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card.
[0303] The decryption module is used to decrypt the second ciphertext to obtain the user's personal information and the hardware serial number of the SIM card;
[0304] The first generation module is used to generate a seamless access user ID based on the user's personal information and the hardware serial number of the SIM card;
[0305] The second generation module is used to generate a seamless access service encryption key based on the SIM card's hardware serial number.
[0306] The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain a third ciphertext;
[0307] The sending module is used to encrypt the third ciphertext to obtain the fourth ciphertext, and then send the fourth ciphertext to the contactless access card application management platform.
[0308] Please refer to Figure 12 This invention also provides an operator SIM management platform, comprising:
[0309] The receiving module is used to receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key.
[0310] The decryption module is used to decrypt the fifth ciphertext to obtain the seamless access user ID and the seamless access service encryption key;
[0311] The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the sixth ciphertext;
[0312] The sending module is used to send the sixth ciphertext to the SIM card of the mobile terminal.
[0313] Please refer to Figure 13 This invention also provides a contactless access verification terminal, comprising:
[0314] The sending module is used to send an instruction to the SIM card to invoke the contactless access card application after detecting the SIM card of the mobile terminal;
[0315] The first receiving module is used to receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction;
[0316] The calculation module is used to calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number;
[0317] The second receiving module is used to receive the ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored in the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID.
[0318] The decryption module is used to decrypt the ciphertext of the seamless access user ID using the calculated encryption key for the seamless access service and the received random number, so as to obtain the information to be verified.
[0319] The verification module is used to verify the information to be verified. If the verification is successful, the gate opening operation is performed.
[0320] Optionally, the contactless access verification terminal further includes:
[0321] The acquisition module is used to acquire facial image data and compress the acquired facial image data to obtain compressed facial image data;
[0322] The information to be verified also includes: the compressed facial image data stored on the SIM card;
[0323] The verification module is used to perform a service comparison based on the seamless communication user ID in the information to be verified, and to perform a facial comparison between the compressed facial data in the information to be verified and the compressed facial data collected by the seamless access verification terminal. If both the service comparison and the facial comparison pass, the verification is confirmed to be successful.
[0324] This invention also provides a SIM card-based contactless access system, including the mobile terminal, contactless access card application management platform, contactless access service platform, operator SIM management platform, and contactless access verification terminal mentioned in the above embodiments.
[0325] Please refer to Figure 14The present invention also provides an electronic device 1400, including a processor 1401, a memory 1402, and a computer program stored in the memory 1402 and executable on the processor 1401. When the computer program is executed by the processor 1401, it implements the various processes of the above-described SIM card-based contactless access method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0326] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the various processes of the above-described SIM card-based contactless access method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0327] This application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above-described... Figure 4 The various processes of the method embodiments shown in 5, 6, 7, or 8 can achieve the same technical effect, and will not be described again here to avoid repetition.
[0328] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0329] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0330] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of the present invention.
Claims
1. A SIM card-based contactless access method, characterized in that, Applied to a mobile terminal, the mobile terminal including a contactless access user terminal and a SIM card, the method includes: The seamless access user terminal obtains the user's personal information, encrypts the user's personal information to obtain the first ciphertext, and sends the first ciphertext to the seamless access card application management platform to apply for a seamless access user ID; The SIM card receives a sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The SIM card decrypts the sixth ciphertext to obtain and store the seamless access user ID and the seamless access service encryption key. The SIM card receives an instruction from the contactless access verification terminal to invoke the contactless access card application. Based on the instruction, the SIM card sends its hardware serial number and a random number to the contactless access verification terminal. The contactless access service encryption key and the random number are used to encrypt the contactless access user ID to obtain the contactless access user ID ciphertext. The contactless access user ID ciphertext is then sent to the contactless access verification terminal for contactless access verification.
2. The method according to claim 1, characterized in that, The user's personal information is encrypted to obtain the first ciphertext, which includes: Real-person verification is performed based on the user's personal information; If the identity verification is successful, the user's personal information and verification result are encrypted to obtain the first ciphertext.
3. The method according to claim 1, characterized in that, The user's personal information includes facial image data; after sending the first encrypted message to the contactless access card application management platform, the system further includes: The SIM card receives and stores the image compression data sent by the contactless access card application management platform, and the image compression data is obtained by compressing the image data. Specifically, the seamless access service encryption key and the random number are used to encrypt the seamless access user ID to obtain the seamless access user ID ciphertext, including: The SIM card uses the seamless access service encryption key and the random number to encrypt the seamless access user ID and the image compression data to obtain the seamless access user ID ciphertext.
4. A SIM card-based contactless access method, characterized in that, The method, applied to a contactless access card application management platform, includes: Receive a first encrypted message sent by the seamless access user terminal in the mobile terminal, the first encrypted message including the user's personal information; Decrypt the first ciphertext to obtain the user's personal information; The user's personal information and the hardware serial number of the SIM card of the mobile terminal are encrypted to obtain the second ciphertext; Send the second encrypted message to the seamless access service platform; Receive a fourth ciphertext sent by the seamless access service platform, the fourth ciphertext containing a third ciphertext, the third ciphertext containing an encrypted seamless access user ID and an encrypted seamless access service encryption key; Decrypting the fourth ciphertext yields the third ciphertext; The third ciphertext is encrypted to obtain the fifth ciphertext; The fifth encrypted message is sent to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
5. The method according to claim 4, characterized in that, The first ciphertext is decrypted to obtain the user's personal information, and then the process further includes: Use the user's personal information for real-person verification; If the identity verification is successful, the process proceeds to encrypt the user's personal information and the hardware serial number of the mobile terminal's SIM card.
6. A SIM card-based contactless access method, characterized in that, The method, applied to a seamless access control platform, includes: The system receives a second encrypted message sent by the contactless access card application management platform. The second encrypted message includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card. The second ciphertext is decrypted to obtain the user's personal information and the hardware serial number of the SIM card; Based on the user's personal information and the SIM card's hardware serial number, a seamless access user ID is generated; Generate a seamless access service encryption key based on the SIM card's hardware serial number; The seamless access user ID and the seamless access service encryption key are encrypted to obtain the third ciphertext; After encrypting the third ciphertext, a fourth ciphertext is obtained, and the fourth ciphertext is sent to the contactless access card application management platform.
7. A SIM card-based contactless access method, characterized in that, The method, applied to an operator's SIM management platform, includes: Receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key. Decrypting the fifth ciphertext yields the seamless access user ID and the seamless access service encryption key; The user ID and the encryption key for the contactless access service are encrypted to obtain the sixth ciphertext. The sixth ciphertext is sent to the SIM card of the mobile terminal.
8. A SIM card-based contactless access method, characterized in that, The method, applied to a contactless access verification terminal, includes: After detecting the SIM card of the mobile terminal, a command to invoke the contactless access card application is sent to the SIM card; Receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction; Calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number; The system receives a ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored on the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID. The encrypted user ID of the seamless access service is decrypted using the calculated encryption key and the received random number to obtain the information to be verified. The information to be verified is verified. If the verification is successful, the gate opening operation is performed.
9. The method according to claim 8, characterized in that, Also includes: Collect facial image data and compress the collected facial image data to obtain compressed facial image data; The information to be verified also includes: the compressed facial image data stored on the SIM card; The verification of the information to be verified includes: The process involves comparing the user ID in the contactless communication information to be verified with the compressed facial image data collected by the contactless access verification terminal. If both the service comparison and the facial image comparison pass, the verification is confirmed to be successful.
10. A mobile terminal, characterized in that, include: The application module is used to obtain user personal information, encrypt the user personal information to obtain a first ciphertext, and send the first ciphertext to the contactless access card application management platform to apply for a contactless access user ID. The writing module is used to receive the sixth ciphertext sent by the operator's SIM management platform. The sixth ciphertext includes an encrypted seamless access user ID and an encrypted seamless access service encryption key. The seamless access user ID is generated based on the user's personal information. The sixth ciphertext is decrypted to obtain and store the seamless access user ID and the seamless access service encryption key; The verification module is used to receive an instruction from the contactless access verification terminal to invoke the contactless access card application, and based on the instruction, send the hardware serial number of the SIM card and a random number to the contactless access verification terminal. It also encrypts the contactless access user ID using the contactless access service encryption key and the random number to obtain the contactless access user ID ciphertext, and sends the contactless access user ID ciphertext to the contactless access verification terminal for contactless access verification.
11. A contactless access card application management platform, characterized in that, include: The first receiving module is used to receive a first encrypted message sent by the seamless access user terminal in the mobile terminal, wherein the first encrypted message includes the user's personal information; The first decryption module is used to decrypt the first ciphertext to obtain the user's personal information; The first encryption module is used to encrypt the user's personal information and the hardware serial number of the SIM card of the mobile terminal to obtain the second ciphertext; The first sending module is used to send the second ciphertext to the seamless access service platform; The second receiving module is used to receive the fourth ciphertext sent by the seamless access service platform. The fourth ciphertext includes the third ciphertext, which includes the encrypted seamless access user ID and the encrypted seamless access service encryption key. The second decryption module is used to decrypt the fourth ciphertext to obtain the third ciphertext; The second encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the fifth ciphertext; The second sending module is used to send the fifth encrypted message to the operator's SIM management platform to write the seamless access user ID and seamless access service encryption key into the SIM card of the mobile terminal.
12. A seamless access control platform, characterized in that, include: The receiving module is used to receive a second ciphertext sent by the contactless access card application management platform. The second ciphertext includes encrypted user personal information and encrypted hardware serial number of the mobile terminal's SIM card. The decryption module is used to decrypt the second ciphertext to obtain the user's personal information and the hardware serial number of the SIM card; The first generation module is used to generate a seamless access user ID based on the user's personal information and the hardware serial number of the SIM card; The second generation module is used to generate a seamless access service encryption key based on the SIM card's hardware serial number. The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain a third ciphertext; The sending module is used to encrypt the third ciphertext to obtain the fourth ciphertext, and then send the fourth ciphertext to the contactless access card application management platform.
13. A carrier SIM management platform, characterized in that, include: The receiving module is used to receive the fifth ciphertext sent by the contactless access card application management platform. The fifth ciphertext includes the third ciphertext, which includes the encrypted contactless access user ID and the encrypted contactless access service encryption key. The decryption module is used to decrypt the fifth ciphertext to obtain the seamless access user ID and the seamless access service encryption key; The encryption module is used to encrypt the seamless access user ID and the seamless access service encryption key to obtain the sixth ciphertext; The sending module is used to send the sixth ciphertext to the SIM card of the mobile terminal.
14. A contactless access verification terminal, characterized in that, include: The sending module is used to send an instruction to the SIM card to invoke the contactless access card application after detecting the SIM card of the mobile terminal; The first receiving module is used to receive the hardware serial number and random number of the SIM card returned by the SIM card based on the instruction; The calculation module is used to calculate the encryption key for the SIM card's seamless access service based on the SIM card's hardware serial number; The second receiving module is used to receive the ciphertext of the seamless access user ID sent by the SIM card. The ciphertext of the seamless access user ID is obtained by the SIM card encrypting the information to be verified stored in the SIM card using the seamless access service encryption key and the random number. The information to be verified includes the seamless communication user ID. The decryption module is used to decrypt the ciphertext of the seamless access user ID using the calculated encryption key for the seamless access service and the received random number, so as to obtain the information to be verified. The verification module is used to verify the information to be verified. If the verification is successful, the gate opening operation is performed.
15. A SIM card-based contactless access system, characterized in that, It includes the mobile terminal as described in claim 10, the contactless access card application management platform as described in claim 11, the contactless access service platform as described in claim 12, the operator SIM management platform as described in claim 13, and the contactless access verification terminal as described in claim 14.
16. An electronic device, characterized in that, include: The processor, the memory, and the program stored in the memory and executable on the processor, wherein when executed by the processor, the program implements the steps of the SIM card-based contactless access method as described in any one of claims 1 to 3; or, when executed by the processor, the program implements the steps of the SIM card-based contactless access method as described in any one of claims 4 to 5; or, when executed by the processor, the program implements the steps of the SIM card-based contactless access method as described in any one of claims 6 to 7; or, when executed by the processor, the program implements the steps of the SIM card-based contactless access method as described in any one of claims 8 to 9.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, implements the steps of the SIM card-based contactless access method as described in any one of claims 1 to 3; or, when executed, implements the steps of the SIM card-based contactless access method as described in any one of claims 4 to 5; or, when executed, implements the steps of the SIM card-based contactless access method as described in any one of claims 6 to 7; or, when executed, implements the steps of the SIM card-based contactless access method as described in any one of claims 8 to 9.
18. A computer program product, characterized in that, The method includes computer instructions that, when executed, implement the steps of the SIM card-based contactless access method as described in any one of claims 1 to 3; or, when executed, the computer instructions implement the steps of the SIM card-based contactless access method as described in any one of claims 4 to 5; or, when executed, the computer instructions implement the steps of the SIM card-based contactless access method as described in any one of claims 6 to 7; or, when executed, the computer instructions implement the steps of the SIM card-based contactless access method as described in any one of claims 8 to 9.