Method and apparatus for realizing smart card extension

Through the combination of extension programs and host applications, the expansion of smart card devices on iOS devices or iPadOS devices is achieved, solving the problem of poor compatibility and improving the convenience of use.

WO2025145512A1PCT designated stage expired Publication Date: 2025-07-10FEITIAN TECHNOLOGIES CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/089718
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-04
Filing Date
2024-04-25
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

In the prior art, iOS devices or iPadOS devices cannot use smart card functions, such as SSL two-way authentication services and PDF file signatures, resulting in poor compatibility and inconvenient use.

Method used

Through the combination of extension programs and host applications, smart card devices are expanded on iOS devices or iPadOS devices, including certificate hash calculation, configuration information judgment, creation and management of certificate objects and key objects, as well as support for PIN code verification and signature operations.

Benefits of technology

The scope of use of smart card devices on iOS devices or iPadOS devices has been expanded, and compatibility and convenience of use has been improved without changing the smart card devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024089718_10072025_PF_FP_ABST
    Figure CN2024089718_10072025_PF_FP_ABST
Patent Text Reader

Abstract

A method for realizing smart card extension, which method is applicable to a terminal device based on iOS or iPadOS. The terminal device includes a host application and an extension reliant on the host application. After the terminal device establishes a connection with a smart card device, the host application registers a device certificate in the smart card device into a token configuration; when the extension is called by a third-party application, a smart card token is initialized by using the token configuration; when a PIN authentication interface in the extension is called by the third-party application, the extension enumerates certificate object identifiers and key object identifiers in the smart card token and prompts a user to perform selection; when user selection information has been received, a PIN is sent to the smart card device for verification; and when a signature interface in the extension is called by the third-party application, if the extension determines that the PIN has successfully passed verification, data to be signed that is in the signature interface is sent to the smart card device for signing. The present invention can expand the application range of a smart card device without the need to change the smart card device, and thus has good compatibility and is convenient to use.
Need to check novelty before this filing date? Find Prior Art

Description

A method and device for implementing smart card expansion Technical Field

[0001] The invention relates to a method and a device for realizing smart card expansion, belonging to the field of information security. Background Art

[0002] With Apple's rapid rise, the iPhone has won widespread popularity thanks to its superior performance and high-quality industrial design. Apple phones are powered by the iOS operating system developed by Apple. Conventional technology prevents the use of smart card features (such as SSL mutual authentication services and PDF file signing) on ​​iOS or iPadOS devices. Therefore, a solution to this problem is urgently needed.

[0003] Summary of the Invention

[0004] The purpose of the present invention is to provide a method and device for realizing smart card expansion, which expands the scope of use of smart card devices on iOS devices or iPadOS devices by combining an extension program and a host application without making any changes to the smart card device, thereby improving compatibility and making it more convenient to use.

[0005] To this end, according to a first aspect of the present invention, a method for implementing smart card expansion is provided, which is applicable to a terminal device running an iOS system or an iPadOS system, wherein the terminal device includes a host application and an extension program dependent on the host application. After the terminal device establishes a connection with a smart card device, the method includes:

[0006] Step S1: the host application selects a smart card application in the smart card device, reads a device object in the smart card device according to a preset screening condition, and calculates a hash value for the device certificate in the device object to obtain a certificate hash value;

[0007] Step S2: the host application obtains device configuration information, determines whether the certificate hash value is in the configured token configuration in the device configuration information, and reports an error if it is; otherwise, writes the certificate hash value into the token configuration and executes step S3;

[0008] Step S3: The host application creates a certificate template, stores the data in the device certificate into the certificate template to obtain a new device certificate, and determines whether the new device certificate is valid. If so, step S4 is executed; otherwise, an error is reported.

[0009] Step S4: the host application generates a certificate object and a key object according to the new device certificate, creates a corresponding certificate object identifier and key object identifier, and writes the certificate object identifier, the certificate object, the key object identifier, and the key object into the token configuration;

[0010] Step S5: When the extension program is called by a third-party application, the extension program obtains the incoming token configuration parameters, obtains the corresponding token configuration according to the token configuration parameters, and initializes the created smart card token according to the token configuration;

[0011] Step S6: When the PIN code authentication interface of the extension program is called by the third-party application, the extension program enumerates the certificate object identifiers and key object identifiers in the smart card token and prompts the user to select one. Upon receiving the certificate object identifier and key object identifier selected by the user, the extension program prompts the user to enter a PIN code and sends the received PIN code to the smart card device for verification.

[0012] Step S7: When the signature interface of the extension program is called by the third-party application, the extension program determines whether the PIN code has been successfully verified. If so, the extension program determines the signature algorithm, generates a signature instruction based on the certificate object identifier and the corresponding certificate object selected by the user, the key object identifier and the corresponding key object selected by the user, the signature algorithm, and the data to be signed in the signature interface parameters, and sends the signature instruction to the smart card device; otherwise, an error is reported; and

[0013] Step S8: When the extension program receives the signature data returned by the smart card device, it returns the signature data to the third-party application.

[0014] According to a second aspect of the present invention, there is provided an apparatus for implementing smart card expansion, which is provided in a terminal device of an iOS system or an iPadOS system, the apparatus comprising a host application module and an extension program module dependent on the host application module, the host application module comprising: a reading and calculating unit, an acquisition and judgment unit, a creation and judgment unit, and a generation and writing unit, the extension program module comprising: an enumeration and acquisition unit, a first receiving and sending unit, a judgment and determination unit, a first generating and sending unit, and a second receiving and sending unit;

[0015] The reading and calculating unit is configured to, after the terminal device establishes a connection with the smart card device, select a smart card application in the smart card device, read a device object in the smart card device according to a preset screening condition, and calculate a hash value for the device certificate in the device object to obtain a certificate hash value;

[0016] The acquisition judgment unit is used to obtain device configuration information, judge whether the certificate hash value is in the configured token configuration in the device configuration information, and report an error if it is; otherwise, write the certificate hash value into the token configuration to trigger the creation judgment unit;

[0017] The creation judgment unit is used to create a certificate template, store the data in the device certificate into the certificate template to obtain a new device certificate, and judge whether the new device certificate is valid. If so, the generation and writing unit is triggered, otherwise an error is reported;

[0018] The generating and writing unit is configured to generate a certificate object and a key object according to the new device certificate, create a corresponding certificate object identifier and a key object identifier, and write the certificate object identifier, the certificate object, the key object identifier, and the key object into the token configuration;

[0019] The enumeration acquisition unit is configured to acquire the token configuration parameters passed in when the extension module is called by a third-party application, acquire the corresponding token configuration according to the token configuration parameters, and initialize the created smart card token according to the token configuration;

[0020] The first receiving and sending unit is configured to, when the PIN code authentication interface in the extension program module is called by a third-party application, enumerate the certificate object identifier and the key object identifier in the smart card token and prompt the user to select one; upon receiving the certificate object identifier and the key object identifier selected by the user, prompt the user to enter a PIN code; and send the received PIN code to the smart card device for verification;

[0021] The determination unit is configured to determine whether the PIN code has been successfully verified when the signature interface in the extension module is called by a third-party application, and if so, determine the signature algorithm; otherwise, report an error;

[0022] The first generating and sending unit is used to generate a signature instruction based on the certificate object identifier and the corresponding certificate object selected by the user, the key object identifier and the corresponding key object selected by the user, the signature algorithm and the data to be signed in the signature interface parameters, and send the signature instruction to the smart card device;

[0023] The second receiving and sending unit is used to receive the signature data returned by the smart card device and return the signature data to the third-party application.

[0024] According to a third aspect of the present invention, the present invention provides an electronic device, comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, wherein the at least one processor executes the instructions to implement the above-mentioned method for implementing smart card expansion.

[0025] According to a fourth aspect of the present invention, the present invention provides a computer-readable storage medium, which includes a computer program. When the computer program runs on an electronic device, the electronic device executes the above-mentioned method for implementing smart card expansion.

[0026] According to a fifth aspect of the present invention, the present invention provides a chip system, comprising a chip, wherein the chip is coupled to a memory and is configured to execute a computer program stored in the memory to execute the above-mentioned method for implementing smart card expansion.

[0027] According to the present invention, by combining the extension program with the host application, the scope of use of smart card devices [such as smart cards (which can be combined with card readers) and keys] on iOS devices or iPadOS devices is expanded without making any changes to the smart card devices, thereby improving compatibility and making it more convenient to use. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] FIG1 is a flow chart of a method for implementing smart card expansion according to a first embodiment of the present invention;

[0029] FIG2 is a flow chart of a method for implementing smart card expansion according to a second embodiment of the present invention;

[0030] FIG3 is a flow chart of a method for implementing smart card expansion according to a third embodiment of the present invention. DETAILED DESCRIPTION

[0031] To make the objectives, technical solutions and advantages of the present invention more clear, embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0032] Embodiment one:

[0033] Embodiment 1 of the present invention provides a method for implementing smart card expansion, as shown in FIG1 , including:

[0034] Step S1: The host application selects a smart card application in the smart card device, reads a device object in the smart card device according to a preset screening condition, and calculates a hash value for the device certificate in the device object to obtain a certificate hash value;

[0035] Specifically, in the first embodiment, the device object in the smart card device is read according to preset screening conditions, including: the host application saves the context object of the smart card application, obtains the card slot array through the context object, traverses the card slot array, reads the device name from the card slot array, and reads the device object in the smart card device according to the device name.

[0036] Acquiring a card slot array through the context object, including: acquiring the card slot array through the context object and the first interface;

[0037] Reading a device object in a smart card device through a device name includes: obtaining the device object through a second interface and the device name.

[0038] Calculating a hash value for the device certificate in the device object to obtain a certificate hash value includes: reading the device certificate in the device object through a fifth interface, and calculating a hash value for the device certificate according to a preset algorithm to obtain a certificate hash value;

[0039] Step S2: The host application obtains the device configuration information and determines whether the certificate hash value is in the configured token configuration in the device configuration information. If so, an error is reported; otherwise, the certificate hash value is written to the token configuration and step S3 is executed.

[0040] Specifically, in the first embodiment, step S2 includes:

[0041] Step B1: The host application obtains device configuration information, obtains a driver configuration type object from the device configuration information according to a preset extended interface file identifier, and obtains token driver configuration data, token key keychain data, and system token driver configuration context from the driver configuration type object;

[0042] Step B2: The host application obtains the token configuration whose key value is a preset name from the dictionary object in the device configuration information according to the system token driver configuration context;

[0043] Step B3: The host application determines whether the certificate hash value is in the token configuration. If so, an error is reported. Otherwise, the certificate hash value, token driver configuration data, and token keychain data are saved to the token configuration, and step S3 is executed.

[0044] Step S3: The host application creates a certificate template, stores the data in the device certificate into the certificate template to obtain a new device certificate, and determines whether the new device certificate is valid. If so, execute step S4, otherwise report an error.

[0045] Step S4: The host application generates a certificate object and a key object based on the new device certificate, creates corresponding certificate object identifiers and key object identifiers, and writes the certificate object identifier, certificate object, key object identifier, and key object into the token configuration;

[0046] Specifically, in the first embodiment, step S4 includes:

[0047] Step C1: The host application generates a certificate object based on the new device certificate, generates a key object based on the key in the device certificate, creates corresponding certificate object identifiers and key object identifiers, and sets the key to enable signing, decryption, and login.

[0048] Step C2: The host application uses the certificate object identifier, the certificate object, the key object identifier, and the key object as keychain items, and creates a token configuration with the certificate hash value as the key value and the keychain item as the name;

[0049] Step C3: The host application adds the token configuration to the dictionary object;

[0050] Step S5: When the extension program is called by the third-party application, the extension program obtains the incoming token configuration parameters, obtains the corresponding token configuration according to the token configuration parameters, and initializes the created smart card token according to the token configuration;

[0051] In the first embodiment, the extension program is encapsulated as an interface, and the third-party application calls the extension program according to the token configuration parameters;

[0052] Step S6: When the PIN code authentication interface of the extension program is called by a third-party application, the extension program enumerates the certificate object identifiers and key object identifiers in the smart card token and prompts the user to select one. Upon receiving the certificate object identifier and key object identifier selected by the user, the extension program prompts the user to enter a PIN code and sends the received PIN code to the smart card device for verification.

[0053] Step S7: When the signature interface of the extension program is called by a third-party application, the extension program determines whether the PIN code has been successfully verified. If so, it determines the signature algorithm, generates a signature instruction based on the certificate object identifier and the corresponding certificate object selected by the user, the key object identifier and the corresponding key object selected by the user, the signature algorithm, and the data to be signed in the signature interface parameters, and sends the signature instruction to the smart card device; otherwise, an error is reported;

[0054] Step S8: When the extension program receives the signature data returned by the smart card device, it returns the signature data to the third-party application.

[0055] Preferably, in the first embodiment, steps S5 to S8 can be implemented in different ways. For example, if the third-party application is a browser, implementation way 1 is:

[0056] Step S5 includes:

[0057] Step S5-1: When the extension program is called by the browser, the corresponding extension application interface is enumerated according to the preset interface identifier, the token configuration parameters of the extension application interface are obtained, the corresponding token configuration is obtained according to the token configuration parameters, and the created smart card token is initialized according to the token configuration;

[0058] Step S5-2: The extension program creates a token session based on the smart card token and initializes the token session, binding the token session to the smart card token.

[0059] Accordingly, step S6 includes:

[0060] Step S6-1: When the PIN code authentication interface of the extension program is called by the browser, the extension program enumerates the certificate object identifiers and key object identifiers in the smart card token and prompts the user to select one. After receiving the certificate object identifier and key object identifier selected by the user, the browser pops up a PIN code input box to prompt the user to enter the PIN code;

[0061] Step S6-2: After receiving the PIN code entered by the user, the extension program sends the PIN code to the corresponding smart card device via Lightning communication;

[0062] Step S6-3: The extension program receives the PIN verification result returned by the smart card device and returns it to the browser;

[0063] The PIN verification result includes a PIN verification result success or a PIN verification result failure.

[0064] Accordingly, step S7 includes:

[0065] Step S7-1: When the extension program's signature interface is called by the browser, the extension program determines whether the PIN code has been successfully verified. If so, step S7-2 is executed; otherwise, an error message is reported.

[0066] Step S7-2: The extension negotiates a signature algorithm with the token session;

[0067] Step S7-3: The extension program obtains the corresponding certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, generates a signature instruction based on the certificate object identifier, certificate object, key object identifier, key object, signature algorithm and signature interface parameters to be signed, and sends it to the smart card device through Lighting communication.

[0068] Preferably, the second implementation method of steps S5 to S8 is:

[0069] Before step S1, the process also includes: the extension program registers for notifications, the host application establishes a notification listener and creates an application group;

[0070] Step S5 includes:

[0071] Step S51: When the extension program is called by the browser, the corresponding extension application interface is enumerated according to the preset interface identifier, the token configuration parameters of the extension application interface are obtained, the corresponding token configuration is obtained according to the token configuration parameters, and the created smart card token is initialized according to the token configuration;

[0072] Step S52: The extension program creates a token session according to the smart card token and initializes the token session, binding the token session to the smart card token.

[0073] Accordingly, step S6 includes:

[0074] Step S61: When the PIN code authentication interface of the extension program is called by the browser, the extension program enumerates the certificate object identifiers and key object identifiers in the smart card token and prompts the user to select one. After receiving the certificate object identifier and key object identifier selected by the user, the browser prompts the user to enter the PIN code through a PIN code input box that pops up;

[0075] Step S62: The extension program sends the received PIN code to the host application as a notification, and blocks and waits for the host application to return data;

[0076] Step S63: The host application generates a PIN verification instruction based on the PIN code and sends the PIN verification instruction to the smart card device;

[0077] Step S64: The host application receives the PIN verification result returned by the smart card device and caches it in the application group, and sends a broadcast;

[0078] Step S65: When the extension program receives the broadcast and monitors changes in the stored data in the application group, it returns the PIN verification result in the application group to the browser;

[0079] In the first embodiment, the PIN verification result includes a successful PIN verification result or a failed PIN verification result.

[0080] Accordingly, step S7 includes:

[0081] Step S71: When the signature interface of the extension program is called by the browser, the extension program determines whether the PIN code has been successfully verified. If so, step S72 is executed; otherwise, an error message is reported;

[0082] Step S72: The extension program negotiates a signature algorithm with the token session;

[0083] Step S73: The extension program obtains the corresponding certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, respectively, encapsulates the data to be signed according to the certificate object identifier and the corresponding certificate object, the key object identifier and the corresponding key object, the certificate identifier, the signature algorithm, and the signature interface parameters to obtain an encapsulation result, sends the encapsulation result to the host application in a notification manner, and blocks waiting for the host application to return data;

[0084] Step S74: When the host application monitors the encapsulation result, it parses the encapsulation result, generates a signature instruction based on the certificate object identifier, certificate object, key object identifier, key object, signature algorithm and data to be signed, and sends the signature instruction to the smart card device;

[0085] Specifically, the signature instruction is sent to the smart card device via USB / BLE / NFC / Lighting and other communication methods;

[0086] Accordingly, step S8 includes:

[0087] Step S81: The host application caches the signature result returned by the smart card device into the application group and sends a broadcast;

[0088] In the first embodiment, the signature result includes signature failure information or signature data;

[0089] Step S82: When the extension program receives the broadcast and monitors changes in the data stored in the application group, it determines whether there is signature data in the application group. If yes, it executes step S83; otherwise, it reports an error.

[0090] Step S83: The extension program obtains the signature data in the application group and returns it to the browser.

[0091] In summary, the present invention expands the scope of use of smart card devices [such as smart cards (which can be combined with card readers) and KEYs] on iOS devices or iPadOS devices by combining extension programs with host applications. No changes are required to the smart card devices, which improves compatibility and is more convenient to use.

[0092] Embodiment 2:

[0093] A second embodiment of the present invention provides a method for implementing smart card extension, which is applicable to terminal devices of iOS and iPadOS systems. The terminal device includes a host application and an extension program, and the extension program relies on the host application to work. This second embodiment specifically describes the implementation process of an SSL login operation through a smart card device as an example. As shown in FIG2 , the method of this embodiment includes:

[0094] Step 201: When the host application detects that a smart card device is connected to the terminal device, the host application selects the smart card application and saves the context object;

[0095] The host application in the second embodiment is used to save the device certificate to the certificate object and key object in the corresponding smart card token, so that the extension program can call the certificate object and key object;

[0096] Step 202: The host application obtains the card slot array through the context object;

[0097] Specifically, in the second embodiment, the card slot array is obtained through the context object and the first interface;

[0098] For example, the first interface is: TKSmartCardSlotManager*manager=[TKSmartCardSlotManagerdefaultManager];

[0099] Step 203: The host application traverses the card slot array, reads the device name from the card slot array, and reads the device object in the smart card device through the device name;

[0100] Specifically, in the second embodiment, the device object in the smart card device is read through the second interface and the acquired name;

[0101] For example, the second interface is: TKSmartCard*m_TKsc=[[manager slotnamed:"device name"]makeSmartCard];

[0102] Or, through the fourth interface, read the device object in the smart card device according to the first device name in the card slot array;

[0103] For example, the fourth interface is: TKSmartCard*m_TKsc=[[manager slotnamed:manager.slotNames.firstObject]makeSmartCard]; wherein manager.slotNames is the card slot array;

[0104] Step 204: The host application calculates a hash value for the device certificate in the device object to obtain the certificate hash value:

[0105] Specifically, in the second embodiment, the device certificate in the device object is read through the fifth interface, and the device certificate is hashed according to the sha256 algorithm to obtain a certificate hash value (certSHA256Value);

[0106] For example, the fifth interface is: [m_TKsc transmitRequest: read certificate apdu reply: ^(NData*certData, NSError*error){}], where certData is the device certificate;

[0107] Step 205: The host application obtains the device configuration information, enumerates the configured token configurations in the device configuration information, and determines whether the certificate hash value is in the token configuration. If yes, an error is reported; otherwise, step 206 is executed.

[0108] In the second embodiment, the configured token configurations in the device configuration information are enumerated, including:

[0109] Step B1: obtaining a driver configuration type object from the device configuration information (TKTokenDriverConfiguration class) according to a preset extended interface file identifier (com.apple.ctk.class-id), and obtaining the token driver configuration data, token key keychain data, and system token driver configuration context in the driver configuration type object;

[0110] In the second embodiment, the driver configuration (TKTokenDriverConfiguration) type object stores an object with a certificate hash value;

[0111] Specifically, the host application obtains the system token driver configuration context through NSDictionary*driverConfigDict=[TKTokenDriverConfigurationdriverConfigurations];

[0112] Step B2: The host application obtains the token configuration whose key value is a preset name from the dictionary object according to the system token-driven configuration context;

[0113] In the second embodiment, the preset name is com.ftsafe.SCManager.ProviderToken;

[0114] The dictionary object is a two-dimensional array, with the first column being the key and the second column being the item. The item column can hold variables of various types.

[0115] Step 206: The host application saves the certificate hash value, token driver configuration data, and token key keychain data to the token configuration;

[0116] Step 207: The host application creates a certificate template, writes the data in the device certificate into the certificate template to obtain a new device certificate, and determines whether the new device certificate is valid. If so, a certificate object is generated based on the new device certificate, a key object is generated based on the key in the new device certificate, and a corresponding certificate object identifier and key object identifier are created. The certificate object identifier and the corresponding certificate object, key object identifier and the corresponding key object are written to the token configuration, and step 208 is executed. Otherwise, an error is reported.

[0117] In the second embodiment, step 207 generates a certificate object based on the new device certificate, generates a key object based on the key in the new device certificate, creates a corresponding certificate object identifier and key object identifier, and writes the certificate object identifier, certificate object, key object identifier, key object, and certificate hash value into the token configuration, including:

[0118] Step 207-1: Generate a certificate object based on the new device certificate, generate a key object based on the key in the new device certificate, and create a certificate object identifier and a key object identifier;

[0119] Step 207-2: Set the key to sign, decrypt, and log in;

[0120] Step 207-3: The certificate object identifier, the certificate object, the key object identifier, and the key object are used as keychain items;

[0121] Step 207-4: Create a token configuration with the certificate hash value as the key value and the keychain item as the name;

[0122] Step 207-5: Add the token configuration to the dictionary object;

[0123] Step 208: When the extension program is called by the browser, the extension program obtains the incoming token configuration parameters, obtains the corresponding token configuration according to the token configuration parameters, initializes the created smart card token according to the token configuration, creates a token session according to the smart card token and initializes the token session, and binds the token session to the smart card token;

[0124] In the second embodiment, the extension program is encapsulated into an interface, and the browser can call the extension program through token configuration parameters;

[0125] The host application in the second embodiment is used to register the certificate object and key object of the smart card device to the token configuration. In the second embodiment, the browser calls the extended application interface, obtains the certificate object by accessing the token configuration, and communicates with the smart card device through a communication method such as Lightning. The smart card device calls the interface in the extension program to complete operations such as PIN verification, signing, or encryption and decryption.

[0126] In the second embodiment, the extension program is loaded by the system after installation. When the host application calls the smart card related service, the corresponding extension program is called. For example, if the browser supports SSL login, when the user triggers SSL login, the browser calls the corresponding extension program to perform the SSL login operation.

[0127] Step 209: When the PIN code authentication interface in the extension program is called by the browser, the extension program enumerates the certificate object identifier and key object identifier in the smart card token pair and prompts the user to select one. After receiving the certificate object identifier and key object identifier selected by the user, the browser pops up a PIN code input box and prompts the user to enter the PIN code.

[0128] Step 210: The extension program sends the received PIN code to the corresponding smart card device via Lightning communication, and then executes step 211;

[0129] Step 211: The smart card device verifies the received PIN code. If the verification is successful, the PIN verification result is set to success and returned to the extension program. If the verification fails, the PIN verification result is set to failure and returned to the extension program.

[0130] Step 212: The extension returns the received PIN verification result to the browser;

[0131] Step 213: When the signature interface in the extension program is called by the browser, the extension program determines whether the PIN code has been successfully verified based on the PIN verification result. If so, step 214 is executed; otherwise, an error message is reported.

[0132] Preferably, when the judgment in step 213 is no, the method further includes: the extension program pops up a PIN code input box through the browser and prompts the user to enter the PIN code, and the extension program sends the received user-entered PIN code to the corresponding smart card device through Lightning communication. If a successful PIN verification result is returned by the smart card device, step 214 is executed;

[0133] Specifically, the extension program determines whether the PIN code has been successfully verified according to the PIN verification result, including: determining whether the PIN verification result of the extension program is successful, if so, the PIN code has been successfully verified, otherwise the PIN code has not been successfully verified;

[0134] Step 214: The extension program negotiates a signature algorithm with the token session, obtains the certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, generates a signature instruction according to the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and the data to be signed in the signature interface parameters, and sends the signature instruction to the smart card device via Lightning communication;

[0135] In the second embodiment, before obtaining the certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user in step 214, the further step includes: the extension program determines whether the key object identifier selected by the user is valid, and if so, obtains the certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user; otherwise, an error is reported;

[0136] Specifically, judging whether the key object identifier is legal includes: judging whether the key object identifier selected by the user matches the set key object identifier, if so, it is legal, otherwise it is illegal;

[0137] Preferably, in the second embodiment, the data to be signed can be the original data to be signed (binary data), or the hash value of the original data to be signed;

[0138] Step 215: The smart card device receives the signature instruction and parses it to obtain the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and data to be signed. It then determines whether the key object identifier is valid. If so, it executes step 216. Otherwise, it returns a signature failure message to the extension program and executes step 217.

[0139] Specifically, determining whether the key object identifier is legal includes: determining whether the received key object identifier matches the key object identifier in the key object in the smart card device, if so, it is legal, otherwise it is illegal;

[0140] Step 216: The smart card device determines the signature private key based on the certificate object, key object, key object identifier, and certificate object identifier, uses the signature private key to sign the signature data according to the signature algorithm to obtain signature data, returns the signature data to the extension program, and executes step 217;

[0141] Specifically, in the second embodiment, step 216 includes: the smart card device signs the received data to be signed, composes APDU information data according to the signature data, returns the APDU information data to the extension program, and executes step 217;

[0142] For example, the smart card device signs the received data to be signed to obtain dataToSign, composes dataToSign into APDU information data, and returns the APDU information data to the extension program through the following sending method;

[0143] Sending method: [m_TKsc2 transmitRequest:apdu data reply:^(NSData*response,NSError*error){}];

[0144] Step 217: The extension program determines whether the data returned by the smart card device is signed data. If so, the extension program returns the signed data to the browser; otherwise, an error message is reported.

[0145] Preferably, the error message in this step may be a prompt indicating that the login has failed.

[0146] Example 3:

[0147] A third embodiment of the present invention provides a method for implementing smart card extension on iOS, which is applicable to terminal devices of iOS and iPadOS systems. The terminal device includes a host application and an extension program, and the extension program relies on the host application to work. This third embodiment specifically describes the implementation process of an SSL login operation through a smart card device as an example. As shown in FIG3 , the method includes:

[0148] Step 300: The extension registers for notifications, the host application establishes a notification listener and creates an application group;

[0149] Before step 300, the user adds the host application and its extensions to the same Apple Group, and initializes the application group by the name of the Apple Group;

[0150] In the third embodiment, the application group (NSuserDefault) is used to store data, and both the host application and the extension can access the data in the application group;

[0151] The host application in the third embodiment is used to save the device certificate to the certificate object and key object in the corresponding smart card token, so that the extension program can call the certificate object and key object. It is also responsible for communicating with the smart card device and completing encryption, decryption, signature verification and other operations with the smart card device.

[0152] Step 301: When the host application detects that a smart card device is connected to the terminal device, it selects the smart card application, saves the context object, and obtains the card slot array through the context object;

[0153] Specifically, in the third embodiment, selecting the corresponding application includes: the host application sends an application selection instruction to the smart card, the smart card processes the application selection instruction, selects the application corresponding to the application selection instruction, and then returns a selection success message to the host application;

[0154] For example, the instruction of the selected application is in APDU format, specifically 00A40400 0B A0 00 00 03 08 00 00 10 00 01 00, where 00A40400 is the instruction header, 0B is the data field length (i.e., application identifier length), and A0 00 00 03 08 00 00 10 00 01 00 is the data in the data field (i.e., application identifier);

[0155] Step 302: The host application traverses the card slot array, reads the device name from the card slot array, and reads the device object in the smart card device through the device name;

[0156] Step 303: The host application calculates a hash value for the device certificate in the device object, obtains the device configuration information, and enumerates the configured token configurations in the device configuration information;

[0157] Specifically, in the third embodiment, the implementation process of enumerating the configured token configurations in the device configuration information is the same as that of the second embodiment, and will not be repeated here;

[0158] Step 304: The host application determines whether the certificate hash value is in the token configuration. If yes, an error message is reported; otherwise, step 305 is executed.

[0159] Step 305: The host application saves the certificate hash value, token driver configuration data, and token key keychain data to the token configuration;

[0160] Preferably, in step 305, the host application assembles the token driver configuration data and the token key keychain data into a keychain list and saves it to the token configuration;

[0161] For example, in the third embodiment, the keychain list is keychainItems, and the token configuration is TKTokenConfiguration;

[0162] Step 306: The host application creates a certificate template, writes the data in the device certificate into the certificate template to obtain a new device certificate, and determines whether the new device certificate is valid. If so, execute step 307; otherwise, report an error.

[0163] Step 307: The host application generates a certificate object based on the new device certificate, generates a key object based on the key in the new device certificate, creates a corresponding certificate object identifier and key object identifier, writes the certificate object identifier and the corresponding certificate object, key object identifier and the corresponding key object into the token configuration, and executes step 308;

[0164] Specifically, in the third embodiment, writing the certificate object identifier, certificate object, key object identifier, key object and certificate hash value into the token configuration includes: the host application assembling the certificate object identifier, certificate object, key object identifier and key object into a token keychain list (TKTokenKeychainItem), encapsulating the token keychain list into a token configuration, and using the certificate hash value to set the key value of the corresponding token keychain list, so that the corresponding device private key and device certificate can be found through the key value when signing;

[0165] Step 308: When the extension program is called by the browser, the extension program obtains the incoming token configuration parameters, obtains the corresponding token configuration according to the token configuration parameters, initializes the created smart card token according to the token configuration, creates a token session according to the smart card token, initializes the token session, and binds the token session to the smart card token;

[0166] In the third embodiment, the extension program is encapsulated as an interface and called by the browser;

[0167] In the third embodiment, the extension program is loaded by the system after installation. When the host application calls the smart card related service, the corresponding extension program is called. For example, if the browser supports SSL login, when the user triggers SSL login, the browser calls the corresponding extension program to perform the SSL login operation.

[0168] The extension program of the third embodiment is used as a communication bridge between the host application and the browser;

[0169] Step 309: When the PIN code authentication interface in the extension program is called by the browser, the extension program enumerates the certificate object identifier and key object identifier in the smart card token and prompts the user to make a selection;

[0170] Step 310: After receiving the certificate object identifier and key object identifier selected by the user, the extension program pops up a PIN code input box through the browser and prompts the user to enter the PIN code, and sends the received PIN code to the host application as a notification;

[0171] In the third embodiment, after step 310, the following steps are further performed: the extension program cyclically monitors whether the application program group returns data;

[0172] Step 311: The host application generates a PIN verification instruction based on the PIN code and sends the PIN verification instruction to the smart card device;

[0173] In this third embodiment, the host application supports sending the PIN verification instruction to the smart card device via the following communication methods: NFC, BLE, USB, Lightning;

[0174] Step 312: The smart card device verifies the PIN code in the received PIN verification instruction. If the verification is successful, the PIN verification result is set to success and returned to the host application. The host application caches the successful PIN verification result in the application group and sends a broadcast, and then executes step 313. If the verification fails, the PIN verification result is set to failure and returned to the host application. The host application caches the failed PIN verification result in the application group and sends a broadcast, and then executes step 313.

[0175] In the third embodiment, after the application group (NSUserDefaults) caches data, it periodically writes the cached data to disk to prevent data loss after the data is successfully written to NSUserDefaults and the program exits. You can use synchronize to force the data to be written to disk immediately after the data is successfully written to NSUserDefaults.

[0176] Step 313: When the extension program receives the broadcast and monitors changes in the stored data in the application group, it returns the PIN verification result in the application group to the browser;

[0177] Step 314: When the signature interface in the extension program is called by the browser, the extension program determines whether the PIN code has been successfully verified based on the PIN verification result. If so, step 315 is executed; otherwise, an error message is reported.

[0178] Preferably, in the third embodiment, when the judgment in step 314 is no, the following steps are further included:

[0179] Step T: The extension program pops up the PIN code input box again and sends the received PIN code to the host application as a notification. The host application generates a PIN verification instruction based on the PIN code and sends the PIN verification instruction to the smart card device. The smart card device verifies the PIN code in the received PIN verification instruction. If the verification is successful, the PIN verification result is set to success and returned to the host application. The host application caches the successful PIN verification result in the application group and sends a broadcast. If the verification fails, the PIN verification result is set to failure and returned to the host application. The host application caches the failed PIN verification result in the application group and sends a broadcast. When the extension program receives the broadcast and monitors changes in the data stored in the application group, if the data stored in the application group indicates a successful PIN verification result, step 315 is executed.

[0180] Preferably, if the verification information is determined to be a verification failure, the method further includes: the extended program determining whether the number of verification failures reaches a preset value, and if so, reporting an error and ending the process; otherwise, executing step T;

[0181] Preferably, step 313 further includes: when the extension program detects a broadcast, saving the data in the application group and clearing the application group;

[0182] Step 315: The extension negotiates a signature algorithm with the token session, obtains the corresponding certificate object and key object in the smart card token based on the certificate object identifier and key object identifier selected by the user, encapsulates the data to be signed based on the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and signature interface parameters to obtain an encapsulation result, sends the encapsulation result to the host application in a notification manner, and blocks waiting for the host application to return data;

[0183] In the third embodiment, before encapsulating the data to be signed in the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and signature interface parameters to obtain the encapsulation result in step 315, the extension program further includes: determining whether the format of the data to be signed in the signature interface parameters meets the browser's requirements; if so, the extension program continues; otherwise, an error is reported;

[0184] In the third embodiment, after step 315, the following steps are further performed: the extension program cyclically monitors whether the application program group returns data;

[0185] Step 316: When the host application monitors the encapsulation result, it parses the encapsulation result, generates a signature instruction based on the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and data to be signed, and sends the signature instruction to the smart card device;

[0186] In the third embodiment, sending the signature instruction to the smart card device includes: sending the signature instruction to the smart card device via a communication method such as USB / BLE / NFC / Lighting;

[0187] Step 317: The smart card device parses the signature instruction to obtain the certificate object, key object, certificate object identifier, key object identifier, signature algorithm, and data to be signed. The smart card device determines whether the key object identifier is valid. If so, the smart card device determines the signature private key based on the certificate object, key object, key object identifier, and certificate object identifier. The smart card device uses the signature private key to sign the data to be signed according to the signature algorithm to obtain signature data. The smart card device returns the signature data to the host application and executes step 318. Otherwise, the smart card device returns a signature failure message to the host application and executes step 318.

[0188] Step 318: The host application caches the signature result received from the smart card into the application group and sends a broadcast;

[0189] The signature result in the third embodiment is signature failure information or signature data;

[0190] In the third embodiment, after the application group caches data, it periodically writes the cached data to disk to prevent data loss after the data is successfully written to NSUserDefaults and the program exits. You can use synchronize to force the data to be written to disk immediately after the data is successfully written to NSUserDefaults.

[0191] Step 319: When the extension program receives the broadcast and monitors changes in the data stored in the application group, it determines whether there is signature data in the application group. If yes, it executes step 320; otherwise, it reports an error.

[0192] In the third embodiment, the error message of this step may be a prompt indicating that the login failed;

[0193] Step 319 also includes: when the extension program receives a broadcast, saving the data in the application group and clearing the application group;

[0194] Step 320: The extension returns the signed data to the browser.

[0195] Specifically, the implementation process of the present invention is described in detail by taking signing a PDF file as an example;

[0196] Step T1: When the host application detects that a smart card device is connected to the terminal device, it generates a certificate object and a key object based on the device certificate in the smart card device and registers them in the token configuration;

[0197] Specifically, the specific process of step T1 refers to steps 201 to 207 or steps 301 to 307;

[0198] Step T2: Adobe passes in the token configuration parameters to call the extension program to open the file to be signed, and a signature button pops up to prompt the user to confirm the signing operation;

[0199] Step T3: When Adobe receives the information that the user clicked the digital signature button, the extension obtains the corresponding token configuration based on the passed token configuration parameters, initializes the created smart card token through the token configuration, and calls the extension's PIN authentication interface to perform the PIN verification operation. Adobe then calls the extension's signature interface. If the PIN verification is successful, the extension performs the signing operation.

[0200] Specifically, the implementation process of performing the PIN verification operation and the signature operation refers to steps 209 to 217 or steps 309 to 320;

[0201] If the signature is successful, Adobe will add the digital signature information to the current file in the form of an information stamp, and Adobe will organize verification of the validity of the signature information. If the signature fails, Adobe will prompt the corresponding error message.

[0202] In this third embodiment, a third-party application (such as a browser) can also call the encryption interface in the extension program to implement encryption operations. The implementation process can refer to the signature operation process (i.e., replacing the signature algorithm and the data to be signed with the encryption algorithm and the data to be encrypted), which will not be repeated here.

[0203] Example 4:

[0204] A fourth embodiment of the present invention provides a device for implementing smart card expansion, which is provided in a terminal device of an iOS system or an iPadOS system. The device includes a host application module and an extension program module dependent on the host application module. The host application module includes: a reading and calculation unit, an acquisition and judgment unit, a creation and judgment unit, and a generation and writing unit. The extension program module includes: an enumeration and acquisition unit, a first receiving and sending unit, a judgment and determination unit, a first generating and sending unit, and a second receiving and sending unit.

[0205] A reading and calculating unit is used to select a smart card application in the smart card device after the terminal device establishes a connection with the smart card device, read the device object in the smart card device according to a preset screening condition, and calculate a hash value of the device certificate in the device object to obtain a certificate hash value;

[0206] An acquisition judgment unit is used to obtain device configuration information and judge whether the certificate hash value is in the token configuration in the device configuration information. If so, an error is reported; otherwise, the certificate hash value is written into the token configuration to trigger the creation of the judgment unit;

[0207] Create a judgment unit, which is used to create a certificate template, store the data in the device certificate into the certificate template to obtain a new device certificate, and judge whether the new device certificate is valid. If it is, it triggers the generation of the writing unit, otherwise it reports an error;

[0208] A generation and writing unit is used to generate a certificate object and a key object according to a new device certificate, create a corresponding certificate object identifier and a key object identifier, and write the certificate object identifier, the certificate object, the key object identifier, and the key object into the token configuration;

[0209] An enumeration acquisition unit is used to obtain the token configuration parameters passed in when the extension module is called by a third-party application, obtain the corresponding token configuration according to the token configuration parameters, and initialize the created smart card token according to the token configuration;

[0210] a first receiving and sending unit, configured to, when a PIN code authentication interface in the extended program module is called by a third-party application, enumerate the certificate object identifiers and key object identifiers in the smart card token and prompt the user to select one; upon receiving the certificate object identifier and key object identifier selected by the user, prompt the user to enter a PIN code; and send the received PIN code to the smart card device for verification;

[0211] A determination unit, configured to determine whether the PIN code has been successfully verified when the signature interface in the extension module is called by a third-party application, and if so, determine the signature algorithm; otherwise, report an error;

[0212] The first generating and sending unit is used to generate a signature instruction based on the certificate object identifier and the corresponding certificate object selected by the user, the key object identifier and the corresponding key object selected by the user, the signature algorithm and the data to be signed in the signature interface parameters, and send the signature instruction to the smart card device;

[0213] The second receiving and sending unit is configured to return the signature data to the third-party application when the signature data returned by the smart card device is received.

[0214] In the fourth embodiment, the reading calculation unit is used to read the device object in the smart card device according to preset filtering conditions, including: the host application is specifically used to save the context object of the smart card application, obtain the card slot array through the context object, traverse the card slot array, read the device name from the card slot array, and read the device object in the smart card device according to the device name.

[0215] Furthermore, the reading calculation unit is specifically used to save the context object of the smart card application, obtain the card slot array through the context object and the first interface, traverse the card slot array, read the device name from the card slot array, and obtain the device object through the second interface and the device name.

[0216] In the fourth embodiment, the reading calculation unit is used to calculate the hash of the device certificate in the device object to obtain the certificate hash value, including: the reading calculation unit is specifically used to read the device certificate in the device object through the fifth interface, and calculate the hash of the device certificate according to the preset algorithm to obtain the certificate hash value.

[0217] In the fourth embodiment, the obtaining and judging unit includes:

[0218] A first acquisition subunit is configured to acquire device configuration information, acquire a driver configuration type object from the device configuration information according to a preset extended interface file identifier, and acquire token driver configuration data, token key keychain data, and system token driver configuration context from the driver configuration type object;

[0219] The second acquisition subunit is used to acquire a token configuration whose key value is a preset name from a dictionary object in the device configuration information according to the system token-driven configuration context;

[0220] The judgment saving subunit is used to judge whether the certificate hash value is in the token configuration. If so, an error is reported; otherwise, the certificate hash value, token driver configuration data and token key chain data are saved to the token configuration.

[0221] In the fourth embodiment, generating a write unit includes:

[0222] The generation and setting subunit is used to generate a certificate object based on the new device certificate, generate a key object based on the key in the new device certificate, create corresponding certificate object identifiers and key object identifiers, and set the key to sign, decrypt, and log;

[0223] The second creation subunit is used to use the certificate object identifier and the corresponding certificate object and the key object identifier and the corresponding key object as keychain items, and create a token configuration with the certificate hash value as the key value and the keychain item as the name;

[0224] Add subunit for adding token configuration to dictionary object.

[0225] Preferably, in the fourth embodiment, the enumeration acquisition unit includes:

[0226] The first enumeration acquisition subunit is used to obtain the token configuration parameters passed in when the extension module is called by a third-party application, obtain the corresponding token configuration according to the token configuration parameters, and initialize the created smart card token according to the token configuration;

[0227] The first creation binding subunit is used to create a token session according to the smart card token and initialize the token session, and bind the token session to the smart card token.

[0228] Preferably, the first receiving and sending unit is specifically used to enumerate the certificate object identifier and key object identifier in the smart card token and prompt the user to make a selection when the PIN code authentication interface in the extension program module is called by the browser; after receiving the certificate object identifier and key object identifier selected by the user, a PIN code input box is popped up through the browser to prompt the user to enter the PIN code; after receiving the PIN code entered by the user, the PIN code is sent to the corresponding smart card device through the Lighting communication method.

[0229] Accordingly, the judgment and determination unit is specifically configured to determine whether the PIN code has been successfully verified when the signature interface in the extension module is called by a third-party application, and if so, negotiate a signature algorithm with the token session, otherwise report an error;

[0230] Correspondingly, the first generation and sending unit is specifically used to obtain the corresponding certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, generate a signature instruction for the data to be signed in the certificate object identifier, certificate object, key object identifier, key object, signature algorithm and signature interface parameters, and send it to the smart card device through Lighting communication.

[0231] Preferably, in the fourth embodiment, the extension program module further includes a registration unit for registering notifications; the host application module further includes a creation unit for establishing a notification monitor and creating an application program group.

[0232] Preferably, in the fourth embodiment, the first receiving and sending unit is specifically configured to, when the PIN code authentication interface in the extension program module is called by the browser, enumerate the certificate object identifier and the key object identifier in the smart card token and prompt the user to select one; after receiving the certificate object identifier and the key object identifier selected by the user, pop up a PIN code input box through the browser to prompt the user to enter the PIN code; send the received PIN code to the host application module in a notification manner, and block waiting for the host application module to return data;

[0233] Accordingly, the host application module also includes:

[0234] A second generating and sending unit is used to generate a PIN verification instruction according to the PIN code and send the PIN verification instruction to the smart card device;

[0235] A receiving, caching and sending unit is used to receive the PIN verification result returned by the smart card device, cache it in the application group, and send a broadcast;

[0236] In the fourth embodiment, the PIN verification result includes a successful PIN verification result or a failed PIN verification result;

[0237] The extension program module further includes: a first forwarding module, which is used to return the PIN verification result in the application group to the browser when receiving the broadcast and monitoring the change of the stored data in the application group.

[0238] In the fourth embodiment, the receiving and determining unit is specifically configured to determine whether the PIN code has been successfully verified when the signature interface in the extension module is called by the browser, and if so, negotiate a signature algorithm with the token session, otherwise report an error;

[0239] The first generating and sending unit is specifically configured to obtain the certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, respectively, encapsulate the data to be signed according to the certificate object identifier, the certificate object, the key object identifier, the key object, the signature algorithm, and the signature interface parameters to obtain an encapsulation result, send the encapsulation result to the host application module in a notification manner, and block and wait for the host application module to return data;

[0240] The host application module also includes:

[0241] a parsing and sending unit, configured to parse the encapsulation result when it is monitored, generate a signature instruction based on the certificate object identifier, certificate object, key object identifier, key object, signature algorithm, and data to be signed obtained from the parsing, and send the signature instruction to the smart card device;

[0242] A second receiving, caching and sending unit is configured to cache the signature result returned by the smart card device into the application group and send a broadcast;

[0243] In the fourth embodiment, the signature result includes signature failure information or signature data;

[0244] The second receiving and sending unit is specifically used to determine whether there is signature data in the application group when receiving a broadcast and monitoring changes in the stored data in the application group. If yes, obtain the signature data in the application group and return it to the third-party application, otherwise report an error.

[0245] Preferably, the present invention further provides an electronic device comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, wherein the at least one processor executes the instructions to implement a method for implementing smart card expansion according to the present invention. When the electronic device is a system-on-chip, it may be composed solely of a chip or may include a chip and other discrete components, which is not specifically limited by the present invention. The chip is coupled to the memory and is configured to execute a computer program stored in the memory to implement the method for implementing smart card expansion according to the present invention.

[0246] The present invention can be implemented in whole or in part through software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on an electronic device, the process or function described in the present invention is generated in whole or in part. The computer program can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one base station, electronic device, server, or data center to another base station, electronic device, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium accessible by the electronic device or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, hard disk, or magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)). The electronic device of the present invention can include the aforementioned apparatus.

[0247] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art can understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0248] Although the present invention has been described with reference to specific features and embodiments thereof, it will be apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the invention. Accordingly, this specification and the drawings are merely illustrative of the invention as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the invention. It will be apparent that various modifications and variations may be made to the present invention by those skilled in the art without departing from the spirit and scope of the invention. Thus, the present invention is intended to encompass such modifications and variations as fall within the scope of the claims and their equivalents.

Claims

1. A method for realizing smart card expansion, characterized in that, A terminal device applicable to the iOS system or the iPadOS system, the terminal device includes a host application and an extension program dependent on the host application. After the terminal device establishes a connection with a smart card device, the method includes the following steps: S1) The host application selects a smart card application in the smart card device, reads device objects in the smart card device through preset screening conditions, and calculates a hash value of the device certificate in the device objects to obtain a certificate hash value; S2) The host application obtains device configuration information, determines whether the certificate hash value is in the configured token configurations in the device configuration information. If so, an error is reported. Otherwise, the certificate hash value is written into the token configuration, and step S3 is executed; S3) The host application creates a certificate template, stores the data in the device certificate into the certificate template to obtain a new device certificate, and determines whether the new device certificate is valid. If so, step S4 is executed. Otherwise, an error is reported; S4) The host application generates a certificate object and a key object according to the new device certificate, creates corresponding certificate object identifiers and key object identifiers, and writes the certificate object identifier, the certificate object, the key object identifier, and the key object into the token configuration; S5) When the extension program is called by a third-party application, the extension program obtains the incoming token configuration parameters, obtains the corresponding token configuration according to the token configuration parameters, and initializes and creates a smart card token according to the token configuration; S6) When the PIN code authentication interface of the extension program is called by the third-party application, the extension program enumerates the certificate object identifiers and key object identifiers in the smart card token and prompts the user to make a selection. When the certificate object identifier and key object identifier selected by the user are received, the user is prompted to enter a PIN code, and the received PIN code is sent to the smart card device for verification; S7) When the signature interface of the extension program is called by the third-party application, the extension program determines whether the PIN code has been successfully verified. If so, the signature algorithm is determined, and a signature instruction is generated and sent to the smart card device according to the certificate object identifier selected by the user and the corresponding certificate object, the key object identifier selected by the user and the corresponding key object, the signature algorithm, and the data to be signed in the signature interface parameters. Otherwise, an error is reported; And S8) When the extension program receives the signature data returned by the smart card device, the signature data is returned to the third-party application.

2. The method according to claim 1, wherein The reading of the device objects in the smart card device through preset screening conditions includes: The host application saves the context object of the smart card application, obtains a card slot array through the context object, traverses the card slot array, reads the device name from the card slot array, and reads the device objects in the smart card device through the device name.

3. The method according to claim 2, wherein The obtaining of the card slot array through the context object includes: obtaining the card slot array through the context object and a first interface; Reading the device object in the smart card device through the device name includes: obtaining the device object through the second interface and the device name.

4. The method according to claim 1, characterized in that, Calculating the hash of the device certificate in the device object to obtain the certificate hash value includes: reading the device certificate in the device object through the fifth interface, and calculating the hash of the device certificate according to a preset algorithm to obtain the certificate hash value.

5. The method according to claim 1, characterized in that Step S2 includes the following steps: B1) The host application obtains device configuration information, obtains a driver configuration type object from the device configuration information according to a preset extended interface file identifier, and obtains token driver configuration data, token key keychain data, and a system token driver configuration context from the driver configuration type object; B2) The host application obtains a token configuration with a key value of a preset name from a dictionary object in the device configuration information according to the system token driver configuration context; and B3) The host application determines whether the certificate hash value is in the token configuration. If so, an error is reported. Otherwise, the certificate hash value, the token driver configuration data, and the token key keychain data are saved to the token configuration, and step S3 is executed.

6. The method according to claim 1, characterized in that Step S4 includes the following steps: C1) The host application generates a certificate object according to the new device certificate, generates a key object according to the key in the new device certificate, creates corresponding certificate object identifiers and key object identifiers, and sets the key to be signable, decryptable, and loggable; C2) The host application uses the certificate object identifier, the certificate object, the key object identifier, and the key object as keychain items, and creates a token configuration with the certificate hash value as the key value and the keychain items as the name; and C3) The host application adds the token configuration to the dictionary object.

7. The method according to claim 1, wherein Step S5 includes the following steps: S5-1) When the extension program is called by the browser, enumerate the corresponding extension application interfaces according to a preset interface identifier, obtain the token configuration parameters of the extension application interface, obtain the corresponding token configuration according to the token configuration parameters, and initialize and create a smart card token according to the token configuration; and S5-2) The extension program creates a token session according to the smart card token and initializes the token session, and binds the token session to the smart card token. Step S6 includes the following steps:

8. The method according to claim 7, wherein S6-1) When the PIN code authentication interface of the extension program is called by the browser, the extension program enumerates the certificate object identifier and the key object identifier in the smart card token and prompts the user to make a selection. When the selected certificate object identifier and key object identifier are received, the user is prompted to enter the PIN code through the PIN code input box popped up by the browser; S6-2) When the extension program receives the PIN code entered by the user, it sends the PIN code to the corresponding smart card device through the Lighting communication method; and S6-3) The extension program receives the PIN verification result returned by the smart card device and returns it to the browser. ​ The PIN verification result includes a successful PIN verification result or a failed PIN verification result.

9. The method according to claim 8, wherein The step S7 includes the following steps: S7-1) When the signature interface of the extension program is called by the browser, the extension program determines whether the PIN code has been successfully verified. If so, step S7-2 is executed; otherwise, an error is reported. S7-2) The extension program negotiates a signature algorithm with the token session. And S7-3) The extension program respectively obtains the corresponding certificate object and key object in the smart card token according to the selected certificate object identifier and key object identifier of the user, generates a signature instruction based on the certificate object identifier, the certificate object, the key object identifier, the key object, the signature algorithm, and the data to be signed in the signature interface parameters, and sends it to the smart card device through the Lighting communication method.

10. The method according to claim 1, wherein Before the step S1, the following is also included: The extension program registers a notification, and the host application establishes a listener for the notification and creates an application group.

11. The method according to claim 10, wherein The step S5 includes the following steps: S51) When the extension program is called by the browser, enumerate the corresponding extension application interfaces according to the preset interface identifier, obtain the token configuration parameters of the extension application interfaces, obtain the corresponding token configuration according to the token configuration parameters, and initialize and create the smart card token according to the token configuration. And S52) The extension program creates a token session according to the smart card token and initializes the token session, and binds the token session to the smart card token.

12. The method according to claim 11, characterized in that, The step S6 includes the following steps: S61) When the PIN code authentication interface of the extension program is called by the browser, the extension program enumerates the certificate object identifier and key object identifier in the smart card token and prompts the user to make a selection. When the selected certificate object identifier and key object identifier are received from the user, the user is prompted to enter the PIN code through the PIN code input box popped up by the browser. S62) The extension program sends the received PIN code to the host application in the form of a notification and blocks waiting for the host application to return data. S63) The host application generates a PIN verification instruction according to the PIN code and sends the PIN verification instruction to the smart card device. S64) The host application receives the PIN verification result returned by the smart card device and caches it in the application group, and sends a broadcast. And S65) When the extension program receives the broadcast and monitors that the stored data in the application group has changed, it returns the PIN verification result in the application group to the browser. The PIN verification result includes a successful PIN verification result or a failed PIN verification result.

13. The method according to claim 12, wherein The step S7 includes the following steps: S71) When the signature interface of the extension program is called by the browser, the extension program determines whether the PIN code has been successfully verified. If so, step S72 is executed; otherwise, an error is reported. S72) The extension program negotiates a signature algorithm with the token session. S73) The extension program obtains the corresponding certificate object and key object in the smart card token according to the certificate object identifier and key object identifier selected by the user, encapsulates the certificate object identifier, the certificate object, the key object identifier, the key object, the signature algorithm, and the data to be signed in the signature interface parameters to obtain an encapsulation result, sends the encapsulation result to the host application in the form of a notification, and blocks waiting for the host application to return data; and S74) When the host application monitors the encapsulation result, it parses the encapsulation result, generates a signature instruction based on the parsed certificate object, the certificate object identifier, the key object, the key object identifier, the signature algorithm, and the data to be signed, and sends the signature instruction to the smart card device.

14. The method according to claim 13, wherein The step S8 includes the following steps: S81) The host application caches the signature result returned by the smart card device received into the application group and sends a broadcast. The signature result includes signature failure information or signature data; S82) When the extension program receives the broadcast and monitors that the data stored in the application group has changed, it determines whether there is signature data in the application group. If so, it executes step S83; otherwise, it reports an error; and S83) The extension program obtains the signature data in the application group and returns it to the browser.

15. A device for realizing smart card expansion, characterized in that, It is set in a terminal device of the iOS system or iPadOS system. The device includes a host application module and an extension program module dependent on the host application module. The host application module includes: a reading and calculating unit, an obtaining and judging unit, a creating and judging unit, and a generating and writing unit. The extension program module includes: an enumerating and obtaining unit, a first receiving and sending unit, a judging and determining unit, a first generating and sending unit, and a second receiving and sending unit; The reading and calculating unit is configured to, after the terminal device establishes a connection with the smart card device, select a smart card application in the smart card device, read a device object in the smart card device through a preset filtering condition, and calculate a hash value of the device certificate in the device object to obtain a certificate hash value; The obtaining and judging unit is configured to obtain device configuration information, determine whether the certificate hash value is in the configured token configuration in the device configuration information. If so, it reports an error; otherwise, it writes the certificate hash value into the token configuration and triggers the creating and judging unit; The creating and judging unit is configured to create a certificate template, store the data in the device certificate into the certificate template to obtain a new device certificate, and determine whether the new device certificate is valid. If so, it triggers the generating and writing unit; otherwise, it reports an error; The generating and writing unit is configured to generate a certificate object and a key object according to the new device certificate, create corresponding certificate object identifiers and key object identifiers, and write the certificate object identifiers, the certificate object, the key object identifiers, and the key objects into the token configuration; The enumeration acquisition unit is configured to, when the extension program module is called by a third-party application, acquire the incoming token configuration parameters, obtain the corresponding token configuration according to the token configuration parameters, and initialize and create a smart card token according to the token configuration; The first receiving and sending unit is configured to, when the PIN code authentication interface in the extension program module is called by a third-party application, enumerate the certificate object identifier and the key object identifier in the smart card token and prompt the user to make a selection, and when receiving the selected certificate object identifier and key object identifier, prompt the user to enter the PIN code, and send the received PIN code to the smart card device for verification; The determination unit is configured to, when the signature interface in the extension program module is called by a third-party application, determine whether the PIN code has been successfully verified, and if so, determine the signature algorithm, otherwise report an error; The first generation and sending unit is configured to generate a signature instruction according to the selected certificate object identifier and the corresponding certificate object, the selected key object identifier and the corresponding key object, the signature algorithm, and the data to be signed in the signature interface parameters, and send the signature instruction to the smart card device; and The second receiving and sending unit is configured to receive the signature data returned by the smart card device and return the signature data to the third-party application.

16. An electronic device, a computer-readable storage medium, or a chip system, characterized in that The electronic device includes at least one processor, a memory, and instructions stored on the memory and executable by the at least one processor, and the at least one processor executes the instructions to implement the method according to claim 1; The computer-readable storage medium includes a computer program, and when the computer program runs on an electronic device, the electronic device is caused to execute the method according to claim 1; Or The chip system includes a chip, and the chip is coupled to a memory and is configured to execute a computer program stored in the memory to execute the method according to claim 1.

Citation Information

Patent Citations

  • A method and a device for realizing smart card application expansion

    CN109088733A

  • Digital signature authentication method, system and device, and storage medium

    CN109618341A

  • Method and device for realizing expansion of intelligent card

    CN117528519A

  • Smartcard, Smartcard System and Method for Configuring a Smartcard

    US20140289844A1