Verification method and apparatus, device, readable storage medium, and program product

By establishing an encryption and signature verification mechanism between the smart card and the terminal, verifying the legality of the smart card and the terminal, solving the problem of illegal use of smart cards and realizing a safe and reliable binding relationship.

WO2025103504A1PCT designated stage expired Publication Date: 2025-05-22GIESECKEDEVRIENT (JIANGXI) TECHNOLOGY CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/132683
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-17
Filing Date
2024-11-18
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In the prior art, the binding relationship between the smart card and the terminal is easily disassembled and transferred by illegal users, resulting in the illegal use of the smart card.

Method used

Verify the legitimacy between the smart card and the terminal by establishing an encryption and signature verification mechanism between the smart card and the terminal. The specific steps include after the smart card receives the verification instruction, encrypts the verification parameters using the public key, and uses the private key to sign the results. After receiving the verification, the terminal performs verification and decryption, and determines the legality of both parties after verification.

Benefits of technology

Effectively prevent smart cards from being illegally used, ensure the legal binding relationship between smart cards and terminals, and improve the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132683_22052025_PF_FP_ABST
    Figure CN2024132683_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the technical field of communications, and disclose a verification method and apparatus, a device, a readable storage medium, and a program product. The verification method is applied to a smart card, the smart card comprises a telecommunication card, and the smart card is communicatively connected to a terminal. The method comprises: when a first verification instruction is received, encrypting a first verification parameter by means of a first public key to obtain a first encryption result; signing the first encryption result by means of a second private key to obtain a first signature result, and sending the first encryption result and the first signature result to the terminal; when a second encryption result and a second signature result are received, performing signature verification on the second signature result by means of the first public key, and when the signature verification is passed, decrypting the second encryption result by means of the second private key to obtain a second verification parameter; and if verification of the second verification parameter is passed, determining that verification of the terminal is passed. The embodiments of the present application allow for verification of the legitimacy between a smart card and a terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Verification method, device, equipment, readable storage medium and program product Technical Field

[0001] The present application belongs to the field of communication technology, and in particular relates to a verification method, apparatus, device, readable storage medium, and program product. Background Art

[0002] After the terminal and the smart card are bound, the smart card can be used on the terminal.

[0003] In related technologies, the binding relationship between smart cards and terminals is typically maintained through a physical patch. Unauthorized users can remove the smart card from a terminal and then use it illegally by moving it to another terminal using the physical patch. This method of maintaining the binding relationship between smart cards and terminals presents the risk of unauthorized use of the smart card. Summary of the Invention

[0004] The embodiments of the present application provide a verification method, apparatus, device, readable storage medium, and program product, which can verify the legitimacy between a smart card and a terminal.

[0005] In a first aspect, an embodiment of the present application provides a verification method, which is applied to a smart card, wherein the smart card is in communication with a terminal, and the method includes:

[0006] Upon receiving the first verification instruction, encrypting the first verification parameter using the first public key to obtain a first encryption result, wherein the smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent a unique identifier of a terminal corresponding to the smart card, and the first verification instruction is sent to the smart card by the terminal after detecting that the smart card is powered on and obtaining a binding status of the smart card, and the binding status is bound;

[0007] The first encryption result is signed using the second private key to obtain a first signature result, and the first encryption result and the first signature result are sent to the terminal, so that when the terminal receives the first encryption result and the first signature result, it uses the second public key to verify the first signature result, and if the verification is successful, it uses the first private key to decrypt the first encryption result to obtain a first verification parameter, uses the second terminal fingerprint to verify the first terminal fingerprint, and if the verification is successful, it is determined that the smart card verification is successful, and uses the second public key to encrypt the second verification parameter to obtain a second encryption result, uses the first private key to sign the second encryption result, obtains a second signature result, and sends the second encryption result and the second signature result to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent the unique identification of the terminal;

[0008] Upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key. If the verification passes, decrypt the second encryption result using the second private key to obtain a second verification parameter.

[0009] If the second verification parameter is verified successfully, it is determined that the terminal verification is successful.

[0010] In some optional implementations of the first aspect, before encrypting the first verification parameter using the first public key to obtain the first encryption result, the method further includes:

[0011] Upon receiving a binding instruction sent by the terminal, encrypting the second public key using the third public key to obtain a third encryption result, and sending the third encryption result to the terminal, so that upon receiving the third encryption result, the terminal decrypts the third encryption result using the third private key to obtain the second public key, encrypts the third verification parameter using the second public key to obtain a fourth encryption result, signs the fourth encryption result using the third private key to obtain a third signature result, and sends the fourth encryption result and the third signature result to the smart card; the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key; the third verification parameter includes the first terminal fingerprint and the first public key, and the binding instruction is sent by the terminal to the smart card when the binding state is unbound;

[0012] When the fourth encryption result and the third signature result are received, the third signature result is verified using the third public key. If the verification passes, the fourth encryption result is decrypted using the second private key to obtain the third verification parameter.

[0013] In some optional implementations of the first aspect, the first public key, the first private key, and the first public key are all generated by the terminal, and the first public key is sent by the terminal to the smart card;

[0014] The second public key and the second private key are both generated by the smart card, and the second public key is sent to the terminal by the smart card.

[0015] In some optional implementations of the first aspect, the third public key and the third private key are both generated by the terminal.

[0016] In some optional implementations of the first aspect, when it is determined that the terminal has not passed, the method further includes:

[0017] When the smart card is powered on, a second verification instruction is sent to the terminal, so that the terminal verifies the first identification information using the second identification information when receiving the second verification instruction, and sends verification success information to the smart card when the verification is successful, the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to indicate that the verification of the first identification information is successful;

[0018] Upon receiving the verification success information, sending a third verification code to the terminal, so that upon receiving the third verification code, the terminal generates a first key using the first identification information and the third verification code, and sends the first key to the smart card; generating a first key using the third verification code and the first identification information, and sending the first key to the terminal; the smart card includes the third verification code;

[0019] When the first key is received, the second key is used to verify the first key. If the verification is successful, it is determined that the terminal has passed the verification. The second key is generated by the smart card according to the third verification code and the first identification information.

[0020] Based on the same inventive concept, in a second aspect, an embodiment of the present application provides a verification method, which is applied to a terminal, the terminal being in communication with a smart card, and the method includes:

[0021] When the smart card is detected to be powered on, the binding status of the smart card is obtained;

[0022] When the binding state is bound, a first verification instruction is sent to the smart card, so that when the smart card receives the first verification instruction, it encrypts the first verification parameter using the first public key to obtain a first encryption result, signs the first encryption result using the second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent a unique identifier of the terminal corresponding to the smart card;

[0023] Upon receiving the first encryption result and the first signature result, verifying the first signature result using the second public key, and if the signature verification passes, decrypting the first encryption result using the first private key to obtain the first verification parameter; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key;

[0024] Verifying the first terminal fingerprint using the second terminal fingerprint, determining that the smart card verification is successful if the verification is successful, and encrypting the second verification parameter using the second public key to obtain a second encryption result; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code, and the second verification code, and the second terminal fingerprint is used to uniquely identify the terminal;

[0025] Use the first private key to sign the second encryption result to obtain a second signature result, and send the second encryption result and the second signature result to the smart card, so that when the smart card receives the second encryption result and the second signature result, it uses the first public key to verify the second signature result. If the verification is successful, the second encryption result is decrypted using the second private key to obtain a second verification parameter. If the second verification parameter is verified successfully, it is determined that the terminal verification is successful.

[0026] In some optional implementations of the second aspect, after obtaining the binding status of the smart card, the method further includes:

[0027] When the binding state is unbound, sending a binding instruction to the smart card, so that when the smart card receives the binding instruction, it encrypts the second public key with the third public key to obtain a third encryption result;

[0028] Upon receiving the third encryption result, decrypting the third encryption result using the third private key to obtain the second public key; the third encryption result is obtained by encrypting the second public key using the third public key by the smart card, the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key;

[0029] Encrypting the third verification parameter using the second public key to obtain a fourth encryption result, and signing the fourth encryption result using the third private key to obtain a third signature result, where the third verification parameter includes the first terminal fingerprint and the first public key;

[0030] The fourth encryption result and the third signature result are sent to the smart card, so that when the smart card receives the fourth encryption result and the third signature result, it uses the third public key to verify the third signature result. If the verification passes, it uses the second private key to decrypt the fourth encryption result to obtain the third verification parameter.

[0031] In some optional implementations of the second aspect, the method further includes:

[0032] Upon receiving the second verification instruction, verifying the first identification information using the second identification information, and if the verification is successful, sending verification success information to the smart card, so that the smart card sends a third verification code to the terminal upon receiving the verification success information, the smart card including the third verification code; the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to represent the successful verification of the first identification information;

[0033] When the third verification code is received, the first key is generated using the first identification information and the third verification code, and the first key is sent to the smart card, so that when the smart card receives the first key, it uses the second key to verify the first key. If the verification is successful, it is determined that the terminal has passed the verification, and the second key is generated by the smart card based on the third verification code and the first identification information.

[0034] Based on the same inventive concept, in a third aspect, an embodiment of the present application provides a verification device, which is applied to a smart card, the smart card being communicatively connected to a terminal, and the device comprising:

[0035] a first encryption module configured to, upon receiving a first verification instruction, encrypt a first verification parameter using a first public key to obtain a first encryption result, wherein the smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to uniquely identify the terminal corresponding to the smart card; the first verification instruction is sent to the smart card by the terminal upon detecting that the smart card is powered on and obtaining a binding status of the smart card, and the binding status is bound;

[0036] The first signature module is configured to sign the first encryption result using the second private key to obtain a first signature result, and send the first encryption result and the first signature result to the terminal, so that when the terminal receives the first encryption result and the first signature result, it verifies the first signature result using the second public key, and if the verification is successful, it decrypts the first encryption result using the first private key to obtain a first verification parameter, verifies the first terminal fingerprint using the second terminal fingerprint, and if the verification is successful, determines that the smart card verification is successful, and encrypts the second verification parameter using the second public key to obtain a second encryption result, signs the second encryption result using the first private key, obtains a second signature result, and sends the second encryption result and the second signature result to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent the unique identification of the terminal;

[0037] a first signature verification module configured to, upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key, and, if the verification passes, decrypt the second encryption result using the second private key to obtain a second verification parameter;

[0038] The first determining module is configured to determine that the terminal verification is successful if the second verification parameter verification is successful.

[0039] Based on the same inventive concept, in a fourth aspect, an embodiment of the present application provides a verification device, which is applied to a terminal, the terminal being in communication with a smart card, and the device includes:

[0040] The acquisition module is used to obtain the binding status of the smart card when it is detected that the smart card is powered on;

[0041] A first sending module is configured to send a first verification instruction to the smart card when the binding state is bound, so that upon receiving the first verification instruction, the smart card encrypts a first verification parameter using a first public key to obtain a first encryption result, signs the first encryption result using a second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, the first verification parameter including a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent a unique identifier of the terminal corresponding to the smart card;

[0042] A second signature verification module is configured to, upon receiving the first encryption result and the first signature result, verify the first signature result using the second public key, and, if the verification passes, decrypt the first encryption result using the first private key to obtain a first verification parameter; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key;

[0043] A first verification module is configured to verify the first terminal fingerprint using the second terminal fingerprint, determine that the smart card verification is successful if the verification is successful, and encrypt a second verification parameter using the second public key to obtain a second encryption result; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code, and the second verification code, and the second terminal fingerprint is used to uniquely identify the terminal;

[0044] The second signature module is used to sign the second encryption result using the first private key to obtain a second signature result, and send the second encryption result and the second signature result to the smart card, so that when the second encryption result and the second signature result are received, the smart card uses the first public key to verify the second signature result. If the verification is successful, the second encryption result is decrypted using the second private key to obtain a second verification parameter. If the second verification parameter is verified successfully, it is determined that the terminal verification is successful.

[0045] Based on the same inventive concept, in the fifth aspect, an embodiment of the present application provides an electronic device, which includes: a processor and a memory storing computer program instructions; when the processor executes the program instructions, it implements the verification method as described in any one of the first aspect or the second aspect.

[0046] Based on the same inventive concept, in the sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, a verification method as in any one of the first aspect or the second aspect is implemented.

[0047] Based on the same inventive concept, in the seventh aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the verification method as described in any one of the first aspect or the second aspect.

[0048] According to the verification method, apparatus, device, readable storage medium and program product provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. When the terminal verification passes and the smart card verification passes, it indicates that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0050] FIG1 is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0051] FIG2 is an interactive diagram of a verification method provided in an embodiment of the present application;

[0052] FIG3 is another interactive diagram of the verification method provided in an embodiment of the present application;

[0053] FIG4 is a flow chart of a verification method provided in an embodiment of the present application;

[0054] FIG5 is another flow chart of the verification method provided in an embodiment of the present application;

[0055] FIG6 is another flow chart of a verification method according to an embodiment of the present application;

[0056] FIG7 is a schematic diagram of another flow chart of the verification method provided in an embodiment of the present application;

[0057] FIG8 is a schematic structural diagram of a verification device provided in an embodiment of the present application;

[0058] FIG9 is another schematic diagram of the structure of the verification device provided in an embodiment of the present application;

[0059] FIG10 is a schematic structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0060] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0061] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0062] FIG1 is a schematic diagram of a scenario of a verification method provided in an embodiment of the present application.

[0063] As shown in Figure 1, in this application scenario, the verification system 10 may include a smart card 11 and a terminal 12. The smart card 11 and the terminal 12 may be communicatively connected.

[0064] The smart card 11 may include an embedded Universal Integrated Circuit Card (eUICC), a Subscriber Identity Module (SIM), an embedded Subscriber Identity Module (eSIM), a Universal Integrated Circuit Card (UICC), etc.

[0065] The terminal 12 may be a device that can be connected to a computer network or a communication system. For example, the terminal 12 may include a mobile phone, a tablet, a computer, etc.

[0066] In order to solve the problem of illegal use of smart cards in the above-mentioned method of maintaining the binding relationship between smart cards and terminals in the related art, the embodiments of the present application provide a verification method, device, equipment, readable storage medium and program product. The verification method provided by the embodiments of the present application is first described in conjunction with the accompanying drawings.

[0067] FIG2 is an interactive diagram of the verification method provided in an embodiment of the present application.

[0068] As shown in Figure 2, the verification method may be executed by the smart card and the terminal. The verification method may include S210 to S290.

[0069] S210: When detecting that the smart card is powered on, the terminal obtains the binding status of the smart card.

[0070] S220: When the binding state is bound, the terminal sends a first verification instruction to the smart card.

[0071] S230: Upon receiving the first verification instruction, the smart card encrypts the first verification parameter using the first public key to obtain a first encryption result. The smart card includes the first public key and the first verification parameter, which includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to uniquely identify the terminal corresponding to the smart card.

[0072] S240. The smart card signs the first encryption result using the second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal.

[0073] S250. When the terminal receives the first encryption result and the first signature result, it uses the second public key to verify the first signature result, and if the verification passes, it uses the first private key to decrypt the first encryption result to obtain the first verification parameter; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key.

[0074] S260. The terminal uses the second terminal fingerprint to verify the first terminal fingerprint. If the verification is successful, it is determined that the smart card verification is successful, and the second verification parameter is encrypted using the second public key to obtain a second encryption result; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent the unique identification of the terminal.

[0075] S270. The terminal signs the second encryption result using the first private key to obtain a second signature result, and sends the second encryption result and the second signature result to the smart card.

[0076] S280. Upon receiving the second encryption result and the second signature result, the smart card uses the first public key to verify the second signature result. If the verification passes, the smart card uses the second private key to decrypt the second encryption result to obtain a second verification parameter.

[0077] S290: If the second verification parameter verification is successful, the smart card determines that the terminal verification is successful.

[0078] According to the verification method provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. If the terminal verification passes and the smart card verification passes, it means that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission.

[0079] The specific implementation of the above S210 to S290 is introduced below.

[0080] In S210 , the smart card is powered on by connecting the smart card to a power source.

[0081] The binding status of the smart card may include bound or unbound. The binding status of the smart card is used to indicate whether the smart card is bound to the terminal or other devices other than the terminal.

[0082] Optionally, after detecting that the smart card is powered on and the smart card is initialized, the terminal obtains the binding status of the smart card.

[0083] Exemplarily, the terminal obtains the binding status of the smart card, which may include:

[0084] The terminal sends a binding status acquisition instruction to the smart card, where the binding status acquisition instruction is used to instruct the smart card to send the binding status of the smart card to the terminal;

[0085] When receiving the binding status acquisition instruction, the smart card sends the binding status of the smart card to the terminal, where the smart card includes the binding status of the smart card.

[0086] In S220 , after detecting that the smart card is powered on, the terminal obtains the binding status of the smart card and, if the binding status is bound, sends a first verification instruction to the smart card.

[0087] The first verification instruction may be used to instruct the smart card to encrypt the first verification parameter using the first public key.

[0088] In S230, when the binding state is bound, the terminal sends a first verification instruction to the smart card. Upon receiving the first verification instruction, the smart card encrypts the first verification parameter using the first public key to obtain a first encryption result.

[0089] The correspondence between the smart card and the terminal may be that the smart card and the terminal are legal.

[0090] The first terminal fingerprint may include the terminal number corresponding to the smart card, etc.

[0091] The first terminal fingerprint can be obtained by encrypting the hardware parameters of the terminal corresponding to the smart card, or by encrypting the hardware and software parameters of the terminal corresponding to the smart card. Hardware parameters may include device brand, device model, operating system type, and operating system version. Software parameters may include a list of applications and installed plug-ins.

[0092] Optionally, both the first public key and the first private key can be generated by the terminal, and the first public key can be sent by the terminal to the smart card. The first public key and the first private key can form a first key pair. In other words, the first public key can be the terminal public key, and the first private key can be the terminal private key.

[0093] Exemplarily, encrypting the first verification parameter using the first public key to obtain a first encryption result may include:

[0094] The first verification parameter is encrypted using the first public key and a preset asymmetric algorithm to obtain a first encryption result.

[0095] The preset asymmetric algorithm may include an RSA (Rivest-Shamir-Adleman) algorithm, such as RSA2048.

[0096] It is understandable that encrypting the first verification parameter using the first public key and the RSA algorithm makes the transmission of the first verification parameter more secure, and the RSA algorithm can also be used to generate and verify digital signatures to verify the integrity and authenticity of data.

[0097] Optionally, the first verification code may be generated by the smart card upon receiving the first verification instruction. The first verification code may be a random number. The specific form of the first verification code may be set according to actual circumstances and is not limited here. For example, the first verification code may include at least one of numbers and letters.

[0098] In S240, when the smart card receives the first verification instruction, it uses the first public key to encrypt the first verification parameter to obtain the first encryption result. The smart card can also use the second private key to sign the first encryption result to obtain the first signature result, and send the first encryption result and the first signature result to the terminal.

[0099] Alternatively, the second public key and the second private key may both be generated by a smart card, and the second public key may be sent by the smart card to the terminal. The second public key and the second private key may form a second key pair. In other words, the second public key may be the smart card public key, and the second private key may be the smart card private key.

[0100] Exemplarily, using the second private key to sign the first encryption result to obtain the first signature result may include:

[0101] The first encryption result is signed using the second private key and a preset signature algorithm to obtain a first signature result.

[0102] The preset signature algorithm may include a digital signature algorithm (DSA).

[0103] It is understandable that the smart card does not perform any operation if it does not receive the first verification instruction.

[0104] In S250, after the smart card signs the first encryption result using the second private key to obtain the first signature result, and sends the first encryption result and the first signature result to the terminal, the terminal verifies the first signature result using the second public key upon receiving the first encryption result and the first signature result, and decrypts the first encryption result using the first private key if the verification passes, to obtain the first verification parameter.

[0105] If the signature verification passes, the first signature result can be considered complete. If the signature verification fails, the first signature result can be considered incomplete.

[0106] Optionally, when the signature verification fails, the terminal may output a first prompt message, and the first prompt message may be used to prompt the user that the first signature result fails the signature verification.

[0107] Exemplarily, decrypting the first encryption result using the first private key to obtain the first verification parameter may include:

[0108] The first encryption result is decrypted using the first private key and a preset asymmetric algorithm to obtain a first verification parameter.

[0109] In S260, when the terminal receives the first encryption result and the first signature result, it uses the second public key to verify the first signature result, and if the verification is successful, it uses the first private key to decrypt the first encryption result to obtain the first verification parameter. It can also use the second terminal fingerprint to verify the first terminal fingerprint. If the verification is successful, it is determined that the smart card verification is successful, and the second verification parameter is encrypting the second public key to obtain the second encryption result.

[0110] The second terminal fingerprint may include the terminal number, etc.

[0111] The second terminal fingerprint can be obtained by encrypting the terminal's own hardware parameters, or by encrypting the terminal's own hardware parameters and software parameters. Hardware parameters may include device brand, device model, operating system type, and operating system version. Software parameters may include a list of applications and installed plug-ins.

[0112] Optionally, if the second terminal fingerprint is the same as the first terminal fingerprint, it is determined that the verification is successful; if the second terminal fingerprint is different from the first terminal fingerprint, it is determined that the verification is unsuccessful.

[0113] Optionally, the second verification code may be generated by the terminal upon determining that the smart card has been authenticated. The second verification code may be a random number. The specific form of the second verification code may be set according to actual circumstances and is not limited here. For example, the second verification code may include at least one of a number and a letter.

[0114] The first verification code and the second verification code may be the same or different, which is not limited here.

[0115] Exemplarily, encrypting the second verification parameter using the second public key to obtain a second encryption result may include:

[0116] The second verification parameter is encrypted using the second public key and a preset asymmetric algorithm to obtain a second encryption result.

[0117] It is understandable that the terminal uses the second terminal fingerprint to verify the first terminal fingerprint. If the verification fails, the terminal determines that the smart card verification has failed, and the terminal outputs a second prompt message. The second prompt message can be used to prompt the user that the smart card verification has failed.

[0118] In S270, the terminal uses the second terminal fingerprint to verify the first terminal fingerprint. If the verification is successful, it determines that the smart card verification is successful, and uses the second public key to encrypt the second verification parameter to obtain the second encryption result. It can also use the first private key to sign the first encryption result to obtain the second signature result, and send the second encryption result and the second signature result to the smart card.

[0119] Exemplarily, the terminal signs the second encryption result using the first private key to obtain the second signature result, which may include:

[0120] The terminal signs the second encryption result using the first private key and a preset signature algorithm to obtain a second signature result.

[0121] In S280, after the terminal signs the second encryption result using the first private key to obtain the second signature result, and sends the second encryption result and the second signature result to the smart card, the smart card verifies the second signature result using the first public key upon receiving the second encryption result and the second signature result. If the verification passes, the smart card decrypts the second encryption result using the second private key to obtain the second verification parameter.

[0122] If the signature verification passes, the second signature result can be considered complete. If the signature verification fails, the second signature result can be considered incomplete.

[0123] Optionally, when the signature verification fails, the terminal may output a third prompt message, and the third prompt message may be used to prompt the user that the second signature result fails the signature verification.

[0124] Exemplarily, decrypting the second encryption result using the second private key to obtain the second verification parameter may include:

[0125] The second encryption result is decrypted using the second private key and a preset asymmetric algorithm to obtain a second verification parameter.

[0126] In S290, when the smart card receives the second encryption result and the second signature result, it uses the first public key to verify the second signature result. If the verification is successful, it uses the second private key to decrypt the second encryption result to obtain the second verification parameter. If the second verification parameter is verified successfully, it is determined that the terminal verification is successful.

[0127] Exemplarily, when the first terminal fingerprint is identical to the second terminal fingerprint, it is determined that the terminal verification is successful.

[0128] It is understandable that, when the first terminal fingerprint is different from the second terminal fingerprint, it is determined that the terminal verification has failed. At this time, since the terminal verification has failed, that is, the terminal is illegal for the smart card, and therefore the terminal and the smart card cannot be bound.

[0129] In the embodiment of the present application, the first verification code may be used to obfuscate data such as the fingerprint of the second terminal.

[0130] In some optional implementations, as shown in FIG3 , after the terminal obtains the binding status of the smart card, that is, after S210 , the verification method may further include S310 to S350 .

[0131] S310: When the binding state is unbound, the terminal sends a binding instruction to the smart card;

[0132] S320: Upon receiving the binding instruction sent by the terminal, the smart card encrypts the second public key using the third public key to obtain a third encryption result, and sends the third encryption result to the terminal, where the smart card includes the second public key and the third public key.

[0133] S330: Upon receiving the third encryption result, the terminal decrypts the third encryption result using the third private key to obtain the second public key. The terminal includes the third private key, and the third public key corresponds to the third private key.

[0134] S340: The terminal encrypts the third verification parameter using the second public key to obtain a fourth encryption result, signs the fourth encryption result using the third private key to obtain a third signature result, and sends the fourth encryption result and the third signature result to the smart card. The third verification parameter includes the first terminal fingerprint and the first public key.

[0135] S350. When the smart card receives the fourth encryption result and the third signature result, it uses the third public key to verify the third signature result. If the verification passes, it uses the second private key to decrypt the fourth encryption result to obtain the third verification parameter.

[0136] In the embodiment of the present application, through the encrypted interaction between the terminal and the smart card, the third verification parameter can be securely and accurately transmitted from the terminal to the smart card, providing a basis for subsequent use of the third verification parameter.

[0137] In S1 , the binding instruction may be an instruction for instructing the smart card to encrypt the second public key using the third public key.

[0138] In S2, illustratively, encrypting the second public key with the third public key to obtain a third encryption result may include:

[0139] The second public key is encrypted using the third public key and a preset asymmetric algorithm to obtain a third encryption result.

[0140] Optionally, the smart card may further generate a second public key and a second private key when receiving the binding instruction sent by the terminal.

[0141] In S3, illustratively, both the third public key and the third private key are generated by the terminal. Upon generating the third private key and the third public key, the terminal transmits the third public key to the smart card vendor via a secure method, such as encryption, and the smart card vendor pre-installs the third public key in the smart card. Exemplarily, the third public key may be a protection public key, the third private key may be a protection private key, and the third key pair may be a protection key pair.

[0142] Decrypting the third encrypted result using the third private key to obtain the second public key may include:

[0143] The third encryption result is decrypted using the third private key and a preset asymmetric algorithm to obtain a second public key.

[0144] In S4, illustratively, encrypting the third verification parameter using the second public key to obtain a fourth encryption result may include:

[0145] The third verification parameter is encrypted using the second public key and a preset asymmetric algorithm to obtain a fourth encryption result.

[0146] Exemplarily, signing the fourth encryption result using the third private key to obtain a third signature result may include:

[0147] The fourth encryption result is signed using the third private key and a preset signature algorithm to obtain a third signature result.

[0148] In S5, if the signature verification passes, the third signature result can be considered complete. If the signature verification fails, the third signature result can be considered incomplete.

[0149] Optionally, when the signature verification fails, the terminal may output a fourth prompt message, and the fourth prompt message may be used to prompt the user that the third signature result fails the signature verification.

[0150] Exemplarily, decrypting the fourth encryption result using the second private key to obtain the third verification parameter may include:

[0151] The fourth encryption result is decrypted using the second private key and a preset asymmetric algorithm to obtain a third verification parameter.

[0152] It can be understood that in the embodiment of the present application, the legitimacy between the smart card and the terminal can be verified by encrypting with a preset asymmetric algorithm and signing with a preset signature algorithm. When the legitimacy verification between the smart card and the terminal is passed, that is, when both the smart card and the terminal are verified, the smart card and the terminal can be bound.

[0153] Exemplarily, when the binding status is unbound, the terminal sends a binding instruction to the smart card. The smart card eUICC generates an eUICC key pair (i.e., the second key pair), encrypts the eUICC PK (i.e., the second public key) using the Protection PK (i.e., the third public key), and then sends the encrypted result to the terminal. The terminal decrypts the eUICC PK using the Protection PK (i.e., the third private key) to obtain the eUICC PK. The terminal calculates the Device FingerPrint (i.e., the first terminal fingerprint) and generates a Device key pair (i.e., the first key pair). The terminal encrypts the Device FingerPrint and the Device PK (i.e., the first public key) using the eUICC PK. The terminal generates a signature for the encrypted result of the Device FingerPrint and the Device PK using the Protection SK (i.e., the third private key). The terminal sends the encrypted and signed result of the Device FingerPrint and the Device PK to the smart card eUICC. The smart card eUICC verifies the signature using the Protection PK (i.e., the third public key) to confirm the legitimacy of the data. If the data is legal, the smart card eUICC uses the eUICC SK (second private key) to decrypt the encrypted results of Device FingerPrint and Device PK to obtain Device FingerPrint and Device PK.

[0154] In an embodiment of the present application, each time the terminal is powered on, the binding status of the smart card is first obtained, that is, the machine-card binding status is queried. If the binding status of the smart card is unbound, the machine-card binding process from S310 to S350 shown in Figure 3 is executed, and then the machine-card verification process from S220 to S290 shown in Figure 2 is executed; if the binding status of the smart card is bound, the machine-card verification process from S210 to S290 shown in Figure 2 is executed.

[0155] In some optional implementations, when it is determined that the terminal has not passed the verification, the verification method may further include S11 to S15.

[0156] S11. When the smart card is powered on, the smart card sends a second verification instruction to the terminal. The second verification instruction includes first identification information, where the first identification information is used to represent a unique identification of the smart card.

[0157] S12. When the terminal receives the second verification instruction, it uses the second identification information to verify the first identification information. If the verification is successful, it sends a verification success message to the smart card. The second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success message is used to represent that the verification of the first identification information is successful.

[0158] S13. When receiving the verification success information, the smart card sends a third verification code to the terminal. The smart card includes the third verification code.

[0159] S14. Upon receiving the third verification code, the terminal generates a first key using the first identification information and the third verification code, and sends the first key to the smart card.

[0160] S15. When the smart card receives the first key, it uses the second key to verify the first key. If the verification is successful, it is determined that the terminal has passed the verification. The second key is generated by the smart card according to the third verification code and the first identification information.

[0161] In this embodiment, if the terminal fails to pass, the first key can be verified by the second key, and the terminal can be re-verified.

[0162] It is understandable that when a user has multiple terminals and needs to use a smart card with a terminal other than the terminal corresponding to the smart card, the terminal can be verified in the above manner to improve the flexibility of smart card use.

[0163] In S11, the second verification instruction may be used to instruct the terminal to verify the first identification information using the second identification information.

[0164] The first identification information may include the serial number of the smart card, etc.

[0165] In S12, the second identification information may include the serial number of the smart card corresponding to the terminal, etc.

[0166] Optionally, when the second identification information is the same as the first identification information, it is determined that the verification is passed, and it can be considered that the smart card has passed the verification, that is, the smart card is legal; when the second identification information is different from the first identification information, it is determined that the verification has failed, and it can be considered that the smart card has failed the verification, that is, the smart card is illegal.

[0167] Optionally, when the verification fails, the terminal may output fifth prompt information, where the fifth prompt information is used to prompt that the verification of the first identification information of the smart card fails.

[0168] For example, before the terminal leaves the factory, the smart card can transmit the second identification information to the terminal through a secure transmission method such as encryption. After receiving the second identification information, the terminal can store the second identification information in an identification information whitelist so that the second identification information can be obtained from the identification information whitelist later.

[0169] In S13, the smart card may generate a third verification code upon receiving the verification success information. The third verification code may be a random number. The specific form of the third verification code may be set according to actual circumstances and is not limited here. For example, the third verification code may include at least one of numbers and letters.

[0170] It is understandable that the smart card does not perform any operation if it does not receive the verification success information.

[0171] In S14, illustratively, generating the first key using the first identification information and the third verification code may include:

[0172] A first key is generated using the first identification information, the third verification code, and a preset symmetric algorithm.

[0173] The preset symmetric algorithm may include at least one of a DES (Data Encryption Standard) algorithm, 3DES, or an AES (Advanced Encryption Standard) algorithm.

[0174] In S15, verifying the first key using the second key may include:

[0175] If the second key is the same as the first key, determining that the verification is successful;

[0176] In a case where the second key and the first key are different, it is determined that the authentication has failed.

[0177] Exemplarily, the second key may be generated by the smart card according to the third verification code, the first identification information and a preset symmetric algorithm.

[0178] In the case where the verification fails, it is determined that the terminal has not passed the verification, and the smart card and the terminal cannot be bound.

[0179] Exemplarily, upon obtaining the first identification information EID1, the terminal verifies whether the first identification information EID1 passes verification based on the identification information whitelist. If the second identification information EID2 does not exist in the identification information whitelist, the terminal determines that the first identification information EID1 has failed verification. If the second identification information EID2 exists in the identification information whitelist, the terminal determines that the first identification information EID1 has passed verification. If the first identification information EID1 passes verification, the smart card is determined to be legitimate. The smart card generates a random number eUICC_RNG and generates a temporary key Key_Temp_eUICC using a symmetric algorithm based on EID1 and eUICC_RNG. The smart card sends the random number eUICC_RNG to the terminal. After receiving the random number eUICC_RNG, the terminal generates a temporary key Key_Temp_Device based on the stored EID2 and eUICC_RNG, and returns Key_Temp_Device to the smart card. The smart card compares Key_Temp_Device with Key_Temp_eUICC. If they match, the terminal is legitimate; otherwise, the terminal is illegitimate.

[0180] Based on the same inventive concept, the embodiment of the present application also provides a verification method. The verification method provided by the embodiment of the present application is described below in conjunction with the accompanying drawings.

[0181] FIG4 shows a flow chart of a verification method provided in an embodiment of the present application.

[0182] The verification method provided in the embodiment of the present application can be applied to a smart card, that is, the method can be executed by the smart card. The smart card is in communication connection with the terminal, as shown in FIG4 , and the method may include S410 to S440 .

[0183] S410. When a first verification instruction is received, the first verification parameter is encrypted using the first public key to obtain a first encryption result. The smart card includes the first public key and the first verification parameter. The first verification parameter includes a first terminal fingerprint and a first verification code. The first terminal fingerprint is used to represent the unique identifier of the terminal corresponding to the smart card. The first verification instruction is sent to the smart card by the terminal when it detects that the smart card is powered on and obtains the binding status of the smart card. When the binding status is bound, the terminal obtains the binding status of the smart card.

[0184] S420. Sign the first encryption result with the second private key to obtain a first signature result, and send the first encryption result and the first signature result to the terminal, so that when the terminal receives the first encryption result and the first signature result, it verifies the first signature result with the second public key, and if the verification is passed, decrypts the first encryption result with the first private key to obtain a first verification parameter, verifies the first terminal fingerprint with the second terminal fingerprint, and if the verification is passed, determines that the smart card verification is passed, and encrypts the second verification parameter with the second public key to obtain a second encryption result, signs the second encryption result with the first private key, obtains a second signature result, and sends the second encryption result and the second signature result to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to characterize the unique identification of the terminal.

[0185] S430. Upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key. If the verification passes, decrypt the second encryption result using the second private key to obtain a second verification parameter.

[0186] S440: If the second verification parameter verification is successful, determine that the terminal verification is successful.

[0187] According to the verification method provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. If the terminal verification passes and the smart card verification passes, it means that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission.

[0188] In some optional implementations, as shown in FIG5 , before encrypting the first verification parameter using the first public key to obtain the first encryption result, the method further includes:

[0189] S510. Upon receiving the binding instruction sent by the terminal, encrypt the second public key using the third public key to obtain a third encryption result, and send the third encryption result to the terminal, so that upon receiving the third encryption result, the terminal decrypts the third encryption result using the third private key to obtain the second public key, encrypts the third verification parameter using the second public key to obtain a fourth encryption result, signs the fourth encryption result using the third private key to obtain a third signature result, and sends the fourth encryption result and the third signature result to the smart card; the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key; the third verification parameter includes the first terminal fingerprint and the first public key, and the binding instruction is sent by the terminal to the smart card when the binding state is unbound;

[0190] S520. When the fourth encryption result and the third signature result are received, the third signature result is verified using the third public key. If the verification passes, the fourth encryption result is decrypted using the second private key to obtain a third verification parameter.

[0191] In some optional implementations, the first public key, the first private key, and the first public key are all generated by the terminal, and the first public key is sent by the terminal to the smart card;

[0192] The second public key and the second private key are both generated by the smart card, and the second public key is sent to the terminal by the smart card.

[0193] In some optional implementations, the third public key and the third private key are both generated by the terminal.

[0194] In some optional implementations, when it is determined that the terminal has not passed, the method further includes:

[0195] When the smart card is powered on, a second verification instruction is sent to the terminal, so that the terminal verifies the first identification information using the second identification information when receiving the second verification instruction, and sends verification success information to the smart card when the verification is successful, the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to indicate that the verification of the first identification information is successful;

[0196] Upon receiving the verification success information, sending a third verification code to the terminal, so that upon receiving the third verification code, the terminal generates a first key using the first identification information and the third verification code, and sends the first key to the smart card; generating a first key using the third verification code and the first identification information, and sending the first key to the terminal; the smart card includes the third verification code;

[0197] When the first key is received, the second key is used to verify the first key. If the verification is successful, it is determined that the terminal has passed the verification. The second key is generated by the smart card according to the third verification code and the first identification information.

[0198] The verification method in this embodiment has the same or similar beneficial effects as the verification method in the above embodiment, and will not be described in detail here.

[0199] Based on the same inventive concept, the embodiment of the present application also provides a verification method. The verification method provided by the embodiment of the present application is described below in conjunction with the accompanying drawings.

[0200] FIG6 shows another flow chart of the verification method provided in an embodiment of the present application.

[0201] The verification method provided in the embodiment of the present application can be applied to a terminal, that is, the method can be executed by the terminal. The terminal is in communication with the smart card, as shown in FIG6 , and the method may include S610 to S650.

[0202] S610: When detecting that the smart card is powered on, obtain the binding status of the smart card;

[0203] S620. If the binding state is bound, send a first verification instruction to the smart card, so that upon receiving the first verification instruction, the smart card encrypts the first verification parameter using the first public key to obtain a first encryption result, signs the first encryption result using the second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent a unique identifier of the terminal corresponding to the smart card;

[0204] S630. Upon receiving the first encryption result and the first signature result, verify the first signature result using the second public key. If the signature verification passes, decrypt the first encryption result using the first private key to obtain a first verification parameter. The terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key.

[0205] S640: Verify the first terminal fingerprint using the second terminal fingerprint. If the verification is successful, determine that the smart card verification is successful, and encrypt the second verification parameter using the second public key to obtain a second encryption result. The terminal includes a second verification code and a second terminal fingerprint. The second verification parameter includes the second terminal fingerprint, the first verification code, and the second verification code. The second terminal fingerprint is used to uniquely identify the terminal.

[0206] S650. Use the first private key to sign the second encryption result to obtain a second signature result, and send the second encryption result and the second signature result to the smart card, so that when the smart card receives the second encryption result and the second signature result, it uses the first public key to verify the second signature result. If the verification passes, it uses the second private key to decrypt the second encryption result to obtain a second verification parameter. If the second verification parameter passes, it is determined that the terminal verification is passed.

[0207] According to the verification method provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. If the terminal verification passes and the smart card verification passes, it means that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission.

[0208] In some optional implementations, as shown in FIG7 , before obtaining the binding status of the smart card, that is, before S410 , the method further includes:

[0209] When the binding state is unbound, sending a binding instruction to the smart card, so that when the smart card receives the binding instruction, it encrypts the second public key with the third public key to obtain a third encryption result;

[0210] Upon receiving the third encryption result, decrypting the third encryption result using the third private key to obtain the second public key; the third encryption result is obtained by encrypting the second public key using the third public key by the smart card, the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key;

[0211] Encrypting the third verification parameter using the second public key to obtain a fourth encryption result, and signing the fourth encryption result using the third private key to obtain a third signature result, where the third verification parameter includes the first terminal fingerprint and the first public key;

[0212] The fourth encryption result and the third signature result are sent to the smart card, so that when the smart card receives the fourth encryption result and the third signature result, it uses the third public key to verify the third signature result. If the verification passes, it uses the second private key to decrypt the fourth encryption result to obtain the third verification parameter.

[0213] In some optional embodiments, the method further comprises:

[0214] Upon receiving the second verification instruction, verifying the first identification information using the second identification information, and if the verification is successful, sending verification success information to the smart card, so that the smart card sends a third verification code to the terminal upon receiving the verification success information, the smart card including the third verification code; the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to represent the successful verification of the first identification information;

[0215] When the third verification code is received, the first key is generated using the first identification information and the third verification code, and the first key is sent to the smart card, so that when the smart card receives the first key, it uses the second key to verify the first key. If the verification is successful, it is determined that the terminal has passed the verification, and the second key is generated by the smart card based on the third verification code and the first identification information.

[0216] The verification method in this embodiment has the same or similar beneficial effects as the verification method in the above embodiment, and will not be described in detail here.

[0217] Based on the same inventive concept, an embodiment of the present application further provides a verification device. The verification device provided by the embodiment of the present application is described below with reference to the accompanying drawings.

[0218] FIG8 shows a schematic structural diagram of a verification device provided in an embodiment of the present application.

[0219] The verification device provided in the embodiment of the present application can be applied to a smart card, which is in communication with a terminal. As shown in Figure 8, the verification device provided in the embodiment of the present application may include a first encryption module 810, a first signature module 820, a first signature verification module 830, and a first determination module 840.

[0220] A first encryption module 810 is configured to, upon receiving a first verification instruction, encrypt a first verification parameter using a first public key to obtain a first encryption result. The smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code. The first terminal fingerprint is used to uniquely identify the terminal corresponding to the smart card. The first verification instruction is sent to the smart card by the terminal after detecting that the smart card is powered on and obtaining the binding status of the smart card, and the binding status is bound.

[0221] The first signature module 820 is configured to sign the first encryption result using the second private key to obtain a first signature result, and send the first encryption result and the first signature result to the terminal, so that upon receiving the first encryption result and the first signature result, the terminal verifies the first signature result using the second public key, and if the verification is successful, decrypts the first encryption result using the first private key to obtain a first verification parameter, verifies the first terminal fingerprint using the second terminal fingerprint, determines that the smart card verification is successful if the verification is successful, encrypts the second verification parameter using the second public key to obtain a second encryption result, signs the second encryption result using the first private key, obtains a second signature result, and sends the second encryption result and the second signature result to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent the unique identification of the terminal;

[0222] The first signature verification module 830 is configured to, upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key. If the verification succeeds, decrypt the second encryption result using the second private key to obtain a second verification parameter.

[0223] The first determining module 840 is configured to determine that the terminal verification is successful if the second verification parameter verification is successful.

[0224] According to the verification device provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. If the terminal verification is passed and the smart card verification is passed, it means that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission.

[0225] In some optional embodiments, the verification device may further include:

[0226] a second encryption module configured to, upon receiving a binding instruction sent by the terminal, encrypt the second public key using the third public key to obtain a third encryption result, and send the third encryption result to the terminal, so that upon receiving the third encryption result, the terminal decrypts the third encryption result using the third private key to obtain the second public key, encrypts the third verification parameter using the second public key to obtain a fourth encryption result, signs the fourth encryption result using the third private key to obtain a third signature result, and sends the fourth encryption result and the third signature result to the smart card; the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key; the third verification parameter includes the first terminal fingerprint and the first public key, and the binding instruction is sent by the terminal to the smart card when the binding state is unbound;

[0227] The third signature verification module is used to verify the third signature result using the third public key when receiving the fourth encryption result and the third signature result. If the verification passes, the fourth encryption result is decrypted using the second private key to obtain a third verification parameter.

[0228] In some optional implementations, the first public key, the first private key, and the first public key are all generated by the terminal, and the first public key is sent by the terminal to the smart card;

[0229] The second public key and the second private key are both generated by the smart card, and the second public key is sent to the terminal by the smart card.

[0230] In some optional implementations, the third public key and the third private key are both generated by the terminal.

[0231] In some optional implementations, when it is determined that the terminal has not passed, the apparatus further includes:

[0232] a second sending module, configured to send a second verification instruction to the terminal when the smart card is powered on, so that the terminal verifies the first identification information using the second identification information when receiving the second verification instruction, and sends a verification success message to the smart card when the verification is successful, wherein the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success message is used to indicate that the verification of the first identification information is successful;

[0233] a third sending module, configured to, upon receiving the verification success information, send a third verification code to the terminal, so that upon receiving the third verification code, the terminal generates a first key using the first identification information and the third verification code, and sends the first key to the smart card; generates a first key using the third verification code and the first identification information, and sends the first key to the terminal; the smart card includes the third verification code;

[0234] The second determination module is configured to verify the first key using the second key upon receiving the first key, and determine that the terminal has passed the verification if the verification is successful. The second key is generated by the smart card according to the third verification code and the first identification information.

[0235] The verification device in this embodiment has the same or similar beneficial effects as the verification method in the above embodiment, and will not be described in detail here.

[0236] Based on the same inventive concept, an embodiment of the present application also provides a verification method. The verification device provided in the embodiment of the present application is described below in conjunction with the accompanying drawings.

[0237] FIG9 shows another schematic structural diagram of the verification device provided in an embodiment of the present application.

[0238] The verification device provided in the embodiment of the present application can be applied to a terminal, which is in communication with a smart card. As shown in Figure 9, the verification device provided in the embodiment of the present application may include an acquisition module 910, a first sending module 920, a second signature verification module 930, a first verification module 940, and a second signature module 950.

[0239] An acquisition module 910 is configured to acquire the binding status of the smart card when detecting that the smart card is powered on;

[0240] A first sending module 920 is configured to, when the binding state is bound, send a first verification instruction to the smart card, so that upon receiving the first verification instruction, the smart card encrypts a first verification parameter using a first public key to obtain a first encryption result, signs the first encryption result using a second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, and the first verification parameter includes a first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent a unique identifier of the terminal corresponding to the smart card;

[0241] The second signature verification module 930 is configured to, upon receiving the first encryption result and the first signature result, verify the first signature result using the second public key, and, if the verification succeeds, decrypt the first encryption result using the first private key to obtain the first verification parameter. The terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key.

[0242] A first verification module 940 is configured to verify the first terminal fingerprint using the second terminal fingerprint. If the verification is successful, the smart card verification is determined to be successful, and the second verification parameter is encrypted using the second public key to obtain a second encryption result. The terminal includes a second verification code and a second terminal fingerprint. The second verification parameter includes the second terminal fingerprint, the first verification code, and the second verification code. The second terminal fingerprint is used to uniquely identify the terminal.

[0243] The second signature module 950 is used to sign the second encryption result using the first private key to obtain a second signature result, and send the second encryption result and the second signature result to the smart card, so that when the smart card receives the second encryption result and the second signature result, it uses the first public key to verify the second signature result. If the verification is successful, it uses the second private key to decrypt the second encryption result to obtain a second verification parameter. If the second verification parameter is verified successfully, it is determined that the terminal verification is successful.

[0244] According to the verification device provided in the embodiment of the present application, the smart card verifies the fingerprint of the first terminal through the fingerprint of the second terminal to determine whether the terminal has passed the verification, and the terminal verifies whether the smart card has passed the verification through the second verification parameter. If the terminal verification is passed and the smart card verification is passed, it means that the terminal and the smart card are legal, and then the terminal and the smart card can be bound. In summary, the embodiment of the present application can verify the legitimacy between the smart card and the terminal. In addition, the embodiment of the present application encrypts and signs the first verification parameter and the second verification parameter, thereby improving the security of data transmission.

[0245] In some optional embodiments, the verification device further includes:

[0246] a fourth sending module, configured to send a binding instruction to the smart card when the binding state is unbound, so that the smart card, upon receiving the binding instruction, encrypts the second public key using the third public key to obtain a third encryption result;

[0247] a first decryption module configured to, upon receiving the third encryption result, decrypt the third encryption result using the third private key to obtain the second public key; the third encryption result is obtained by encrypting the second public key using the third public key on the smart card, the smart card including the second public key and the third public key, the terminal including the third private key, and the third public key corresponding to the third private key;

[0248] a fourth encryption module, configured to encrypt the third verification parameter using the second public key to obtain a fourth encryption result, and sign the fourth encryption result using the third private key to obtain a third signature result, where the third verification parameter includes the first terminal fingerprint and the first public key;

[0249] The fifth sending module is used to send the fourth encryption result and the third signature result to the smart card, so that when the smart card receives the fourth encryption result and the third signature result, it uses the third public key to verify the third signature result. If the verification passes, it uses the second private key to decrypt the fourth encryption result to obtain the third verification parameter.

[0250] In some optional embodiments, the verification device further includes:

[0251] a second verification module configured to, upon receiving the second verification instruction, verify the first identification information using the second identification information, and, if the verification is successful, send a verification success message to the smart card, so that upon receiving the verification success message, the smart card sends a third verification code to the terminal, the smart card including the third verification code; the second verification instruction including the first identification information, the first identification information being used to represent a unique identifier of the smart card, the second identification information being used to represent a unique identifier of the smart card corresponding to the terminal, and the verification success message being used to indicate that the verification of the first identification information is successful;

[0252] The generation module is used to generate a first key using the first identification information and the third verification code when a third verification code is received, and send the first key to the smart card, so that the smart card verifies the first key using the second key when the first key is received. If the verification is successful, it is determined that the terminal has passed the verification, and the second key is generated by the smart card based on the third verification code and the first identification information.

[0253] The verification device in this embodiment has the same or similar beneficial effects as the verification method in the above embodiment, and will not be described in detail here.

[0254] An embodiment of the present application further provides an electronic device, which includes: a processor and a memory storing program instructions; when the processor executes the program instructions, the method provided in any one of the embodiments of Figures 2 to 4 is implemented.

[0255] An embodiment of the present application further provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the method provided in any one of the embodiments of FIG. 2 to FIG. 7 is implemented.

[0256] An embodiment of the present application further provides a computer program product. When instructions in the computer program product are executed by a processor of an electronic device, the electronic device can execute the method provided in any one of the embodiments of FIG. 2 to FIG. 7 .

[0257] FIG10 shows a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application.

[0258] The electronic device may include a processor 1001 and a memory 1002 storing program instructions.

[0259] Specifically, the processor 1001 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0260] The memory 1002 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 1002 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 1002 may include removable or non-removable (or fixed) media. Where appropriate, the memory 1002 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 1002 is a non-volatile solid-state memory.

[0261] In certain embodiments, memory 1002 includes read-only memory (ROM). The ROM may be mask-programmed ROM, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), electrically alterable ROM (EAROM), or flash memory, or a combination of two or more thereof, where appropriate.

[0262] The memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present application.

[0263] The processor 1001 implements any one of the methods in the above embodiments by reading and executing program instructions stored in the memory 1002 .

[0264] In one example, the electronic device may further include a communication interface 1003 and a bus 1010. As shown in FIG10 , the processor 1001, the memory 1002, and the communication interface 1003 are connected via the bus 1010 and communicate with each other.

[0265] The communication interface 1003 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0266] Bus 1010 comprises hardware, software or both, couples the parts of electronic equipment to each other.For example, and not limitation, bus can comprise accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations.In suitable cases, bus 1010 can comprise one or more buses.Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.

[0267] The embodiments of the present application can be implemented by providing a readable storage medium having program instructions stored thereon; when the program instructions are executed by a processor, any one of the methods in the above embodiments is implemented.

[0268] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0269] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0270] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0271] Aspects of the present application have been described above with reference to the flow chart and / or block diagram of the method, device (system) and program product according to the embodiments of the present application.It should be understood that each box in the flow chart and / or block diagram and the combination of each box in the flow chart and / or block diagram can be realized by program instructions.These program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device, to produce a kind of machine, so that these instructions executed via the processor of a computer or other programmable data processing device enable the realization of the function / action specified in one or more boxes of the flow chart and / or block diagram.Such processor can be but is not limited to a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit.It is also understood that each box in the block diagram and / or flow chart and the combination of the boxes in the block diagram and / or flow chart can also be realized by the dedicated hardware performing the specified function or action, or can be realized by the combination of dedicated hardware and computer instructions.

[0272] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A verification method, characterized in that: Applied to a smart card, the smart card is communicatively connected with a terminal, and the method comprises: Upon receiving the first verification instruction, encrypting the first verification parameter using the first public key to obtain a first encryption result, wherein the smart card includes the first public key and the first verification parameter, and the first verification parameter includes the first terminal fingerprint and a first verification code; the first terminal fingerprint is used to characterize the unique identifier of the terminal corresponding to the smart card, and the first verification instruction is sent to the smart card by the terminal when detecting that the smart card is powered on and obtaining the binding state of the smart card, and the binding state is bound; The first encryption result is signed by using the second private key to obtain a first signature result, and the first encryption result and the first signature result are sent to the terminal, so that when the terminal receives the first encryption result and the first signature result, the first signature result is verified by using the second public key, and if the verification is passed, the first encryption result is decrypted by using the first private key to obtain the first verification parameter, the first terminal fingerprint is verified by using the second terminal fingerprint, and if the verification is passed, it is determined that the smart card verification is passed, and the second verification parameter is encrypting by using the second public key to obtain a second encryption result, the second encryption result is signed by using the first private key to obtain a second signature result, and the second encryption result and the second signature result are sent to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to characterize the unique identification of the terminal; Upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key, and if the verification passes, decrypt the second encryption result using the second private key to obtain the second verification parameter; When the second verification parameter verification is successful, it is determined that the terminal verification is successful.

2. The method according to claim 1, characterized in that Before encrypting the first verification parameter using the first public key to obtain the first encryption result, the method further includes: Upon receiving the binding instruction sent by the terminal, encrypt the second public key with the third public key to obtain a third encryption result, and send the third encryption result to the terminal, so that upon receiving the third encryption result, the terminal decrypts the third encryption result with the third private key to obtain the second public key, encrypts the third verification parameter with the second public key to obtain a fourth encryption result, signs the fourth encryption result with the third private key to obtain a third signature result, and sends the fourth encryption result and the third signature result to the smart card; the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key; the third verification parameter includes the first terminal fingerprint and the first public key, and the binding instruction is sent to the smart card by the terminal when the binding state is unbound; Upon receiving the fourth encryption result and the third signature result, the third signature result is verified using the third public key. If the verification passes, the fourth encryption result is decrypted using the second private key to obtain the third verification parameter.

3. The method according to claim 1 or 2, characterized in that: The first public key, the first private key and the first public key are all generated by the terminal, and the first public key is sent by the terminal to the smart card; The second public key and the second private key are both generated by the smart card, and the second public key is sent by the smart card to the terminal.

4. The method according to claim 2, characterized in that: The third public key and the third private key are both generated by the terminal.

5. The method according to claim 1, characterized in that In the case where it is determined that the terminal has not passed, the method further includes: When the smart card is powered on, a second verification instruction is sent to the terminal, so that when the terminal receives the second verification instruction, the terminal verifies the first identification information by using the second identification information, and when the verification is successful, verification success information is sent to the smart card, wherein the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to represent that the verification of the first identification information is successful; upon receiving the verification success information, sending a third verification code to the terminal, so that upon receiving the third verification code, the terminal generates a first key using the first identification information and the third verification code, and sends the first key to the smart card; generating a first key using the third verification code and the first identification information, and sending the first key to the terminal; the smart card includes the third verification code; When the first key is received, the first key is verified using the second key. When the verification succeeds, it is determined that the terminal has passed the verification. The second key is generated by the smart card according to the third verification code and the first identification information.

6. A verification method, characterized in that: Applied to a terminal, the terminal is connected to a smart card for communication, and the method comprises: When detecting that the smart card is powered on, obtaining a binding state of the smart card; When the binding state is binding, sending a first verification instruction to the smart card, so that when the smart card receives the first verification instruction, it encrypts the first verification parameter by using the first public key to obtain a first encryption result, signs the first encryption result by using the second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, and the first verification parameter includes the first terminal fingerprint and a first verification code; the first terminal fingerprint is used to characterize the unique identification of the terminal corresponding to the smart card; Upon receiving the first encryption result and the first signature result, verifying the first signature result using the second public key, and decrypting the first encryption result using the first private key if the verification passes, to obtain the first verification parameter; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; The first terminal fingerprint is verified by using the second terminal fingerprint, and if the verification is successful, it is determined that the smart card verification is successful, and the second verification parameter is encrypted by using the second public key to obtain a second encryption result; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent the unique identification of the terminal; The second encryption result is signed by using the first private key to obtain a second signature result, and the second encryption result and the second signature result are sent to the smart card, so that when the second encryption result and the second signature result are received, the smart card verifies the second signature result by using the first public key, and if the verification passes, decrypts the second encryption result by using the second private key to obtain a second verification parameter, and determines that the terminal verification passes if the second terminal fingerprint and the first verification code are verified.

7. The method according to claim 6, characterized in that After obtaining the binding status of the smart card, the method further includes: When the binding state is unbound, sending a binding instruction to the smart card, so that when the smart card receives the binding instruction, it encrypts the second public key with the third public key to obtain a third encryption result; Upon receiving the third encryption result, decrypting the third encryption result using the third private key to obtain the second public key; the third encryption result is obtained by encrypting the second public key by the smart card using the third public key, the smart card includes the second public key and the third public key, the terminal includes the third private key, and the third public key corresponds to the third private key; Encrypting the third verification parameter using the second public key to obtain a fourth encryption result, and signing the fourth encryption result using the third private key to obtain a third signature result, wherein the third verification parameter includes the first terminal fingerprint and the first public key; The fourth encryption result and the third signature result are sent to the smart card, so that when the smart card receives the fourth encryption result and the third signature result, it uses the third public key to verify the third signature result; if the verification passes, it uses the second private key to decrypt the fourth encryption result to obtain the third verification parameter.

8. The method according to claim 6, characterized in that The method further comprises: When receiving the second verification instruction, verify the first identification information using the second identification information, and when the verification is successful, send verification success information to the smart card, so that when the smart card receives the verification success information, it sends a third verification code to the terminal, and the smart card includes the third verification code; the second verification instruction includes the first identification information, the first identification information is used to represent the unique identification of the smart card, the second identification information is used to represent the unique identification of the smart card corresponding to the terminal, and the verification success information is used to represent that the verification of the first identification information is successful; When the third verification code is received, a first key is generated using the first identification information and the third verification code, and the first key is sent to the smart card, so that when the smart card receives the first key, it uses the second key to verify the first key. When the verification is successful, it is determined that the terminal has passed the verification. The second key is generated by the smart card based on the third verification code and the first identification information.

9. A verification device, characterized in that: Applied to a smart card, the smart card is connected to a terminal for communication, and the device comprises: a first encryption module, configured to, upon receiving a first verification instruction, encrypt a first verification parameter using a first public key to obtain a first encryption result, wherein the smart card includes the first public key and the first verification parameter, and the first verification parameter includes the first terminal fingerprint and a first verification code; the first terminal fingerprint is used to characterize a unique identifier of a terminal corresponding to the smart card, and the first verification instruction is sent to the smart card by the terminal when detecting that the smart card is powered on and obtaining a binding state of the smart card, and the binding state is binding; a first signature module, configured to sign the first encryption result using a second private key to obtain a first signature result, and send the first encryption result and the first signature result to the terminal, so that when the terminal receives the first encryption result and the first signature result, it verifies the first signature result using a second public key, and when the verification is passed, it decrypts the first encryption result using the first private key to obtain the first verification parameter, verifies the first terminal fingerprint using a second terminal fingerprint, and when the verification is passed, determines that the smart card verification is passed, and encrypts the second verification parameter using the second public key to obtain a second encryption result, signs the second encryption result using the first private key to obtain a second signature result, and sends the second encryption result and the second signature result to the smart card; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to characterize the unique identification of the terminal; a first signature verification module, configured to, upon receiving the second encryption result and the second signature result, verify the second signature result using the first public key, and, if the verification passes, decrypt the second encryption result using the second private key to obtain the second verification parameter; The first determination module is used to determine that the terminal verification is successful when the second terminal fingerprint and the first verification code are successfully verified.

10. A verification device, characterized in that: Applied to a terminal, the terminal is connected to a smart card for communication, and the device comprises: An acquisition module, configured to acquire the binding status of the smart card when detecting that the smart card is powered on; A first sending module is used to send a first verification instruction to the smart card when the binding state is binding, so that when the smart card receives the first verification instruction, it encrypts the first verification parameter using the first public key to obtain a first encryption result, signs the first encryption result using the second private key to obtain a first signature result, and sends the first encryption result and the first signature result to the terminal; the smart card includes the first public key and the first verification parameter, and the first verification parameter includes the first terminal fingerprint and a first verification code; the first terminal fingerprint is used to represent the unique identification of the terminal corresponding to the smart card; a second signature verification module, configured to verify the first signature result using a second public key upon receiving the first encryption result and the first signature result, and decrypt the first encryption result using a first private key to obtain the first verification parameter if the verification passes; the terminal includes the second public key and the first private key, the first public key corresponds to the first private key, and the second public key corresponds to the second private key; A first verification module, configured to verify the first terminal fingerprint using a second terminal fingerprint, determine that the smart card verification is passed if the verification is successful, and encrypt the second verification parameter using the second public key to obtain a second encryption result; the terminal includes a second verification code and a second terminal fingerprint, the second verification parameter includes the second terminal fingerprint, the first verification code and the second verification code, and the second terminal fingerprint is used to represent a unique identifier of the terminal; The second signature module is used to sign the second encryption result by using the first private key to obtain a second signature result, and send the second encryption result and the second signature result to the smart card, so that when the second encryption result and the second signature result are received, the smart card verifies the second signature result by using the first public key, and if the verification passes, decrypts the second encryption result by using the second private key to obtain a second verification parameter, and if the second verification parameter is verified, it is determined that the terminal verification has passed.

11. An electronic device, characterized in that: The electronic device comprises: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the verification method according to any one of claims 1 to 8 is implemented.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the verification method according to any one of claims 1 to 8 is implemented.

13. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the verification method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Identify authorization method between storage card and terminal equipment at off-line state

    CN101090316A

  • Three-party authentication method and device as well as intelligent card supporting two-way authentication

    CN102833066A

  • Verification method, device and equipment, readable storage medium and program product

    CN118338293A

  • Card management method, user terminal, server, system and storage medium

    US20230351384A1

  • Method for locking card, subscriber identity module card and mobile terminal

    WO2010139170A1