Summary of the invention
In view of this, fundamental purpose of the present invention is to provide a kind of smart card operation method, can satisfy the demand of miscellaneous services such as real-time and non real-time.
Another object of the present invention is to provide a kind of smart card, can satisfy the demand of miscellaneous services such as real-time and non real-time.
For achieving the above object, technical scheme of the present invention is achieved in that
A kind of smart card operation method, this method comprises:
A, in carrying out the process of affairs, whenever execute a key node, then the execution result with described key node correspondence backs up, and by predefined updating mark position is provided with, writes down the executive process of described affairs; Described key node is a previously selected above important operation from all operations of finishing described office need;
If B interrupts in the process of carrying out described affairs, then after interrupting recovery,, determine the operation that next step will be carried out by inquiring about described updating mark position, and the described operation of determining of information and executing of the described backup of foundation.
Before the described steps A, further comprise:
Receive the notification instruction of self terminal, determine to carry out the operator scheme that described office need adopt,, then carry out described steps A if the operator scheme of determining is the integrality operation according to described notification instruction;
Perhaps, the operation mode information corresponding respectively according to the different affairs of preserving in advance determined to carry out the operator scheme that described office need adopt, if the operator scheme of determining is the integrality operation, then carries out described steps A.
Preferably, described notification instruction is Application Protocol Data Unit APDU instruction; The described operator scheme that need adopt according to the described office of the definite execution of notification instruction comprises:
Read the operator scheme indication information that carries in the operator scheme zone bit in the described APDU instruction, determine to carry out the operator scheme that described office need adopt according to described operator scheme indication information.
If the operator scheme of determining is atomicity operation, then in the process of carrying out described affairs, in taking place, have no progeny, the state of described affairs is rolled back to the state of described affairs before beginning to carry out.
Described affairs are the affairs of smartcard internal, perhaps for needing to carry out between smart card and the terminal affairs of information interaction.
Before the described operation of determining of the information and executing of the described backup of described foundation, further comprise:
Judge whether the interrupted number of times of described affairs has reached predefined maximum interruption times threshold value, if not, the then described operation of determining of information and executing of the described backup of foundation; If, then carry out authentication, and after authentication is passed through, according to the described operation of determining of information and executing of described backup.
A kind of smart card comprises:
Backup units is used for whenever executing a key node in the process of carrying out affairs, and then the execution result with described key node correspondence backs up, and by predefined updating mark position is provided with, writes down the executive process of described affairs; Described key node is a previously selected above important operation from all operations of finishing described office need;
Performance element is used for by inquiring about described updating mark position, determining the operation that next step will be carried out after the interruption recovery that the process of carrying out described affairs occurs, and the described operation of determining of information and executing of the described backup of foundation.
Preferably, further comprise in the described smart card:
Mode selecting unit is used to receive the notification instruction of self terminal, determines to carry out the operator scheme that described office need adopt according to described notification instruction, if the operator scheme of determining is the integrality operation, then notifies described backup units to carry out self function; Perhaps, be used for the operation mode information corresponding respectively, determine to carry out the operator scheme that described office need adopt,, then notify described backup units to carry out self function if the operator scheme of determining is the integrality operation according to the different affairs of preserving in advance.
Described mode selecting unit is further used for, if the operator scheme of determining is atomicity operation, then in the process of carrying out described affairs, has no progeny in taking place, and the state of described affairs is rolled back to the state of described affairs before beginning to carry out.
Described affairs are the affairs of described smartcard internal, perhaps for needing to carry out between described smart card and the terminal affairs of information interaction.
Wherein, described performance element comprises: determine subelement and carry out subelement;
Described definite subelement is used for by inquiring about described updating mark position, determining the operation that next step will be carried out after the interruption recovery that the process of carrying out described affairs occurs;
Described execution subelement is used for the described operation of determining of information and executing according to described backup.
Preferably, further comprise in the described performance element:
Count sub-element is used to add up the interrupted number of times of described affairs;
Judgment sub-unit is used to judge whether the interrupted number of times of described affairs has reached predefined maximum interruption times threshold value, if not, then notify described execution subelement to carry out self function; If then carry out authentication, and after authentication is passed through, notify described execution subelement to carry out self function.
As seen, adopt technical scheme of the present invention, smart card in carrying out the process of a certain affairs, whenever execute a key node after, then the execution result with this key node correspondence backs up, and, the updating mark position writes down the executive process of these affairs by being set, like this, in case in the process of carrying out these affairs, interrupt, after waiting to interrupt recovering, can determine the operation that next step will be carried out according to the updating mark position, and can be according to this operation of determining of information and executing of backup.Compare with existing atomicity operator scheme, this operator scheme provided by the present invention can not cause loss of data because of interruption, so can satisfy the demand of miscellaneous services such as real-time and non real-time.
Embodiment
For solving problems of the prior art, a kind of brand-new smart card operation pattern is proposed among the present invention, be the integrality operator scheme: in the process of carrying out a certain affairs, whenever execute a key node, then the execution result with this key node correspondence backs up, and by predefined updating mark position is provided with, write down the executive process of these affairs, be current which key node of carrying out, described key node is a previously selected above important operation from all operations of finishing these office's need; Like this,, then after interrupting recovery,, can determine the operation that next step will be carried out by inquiry updating mark position if in the process of carrying out these affairs, interrupt, and can be according to the described operation of determining of information and executing of backup.
For making purpose of the present invention, technical scheme and advantage clearer, below with reference to the accompanying drawing embodiment that develops simultaneously, the present invention is described in further detail.
Fig. 1 is the process flow diagram of the inventive method embodiment.As shown in Figure 1, may further comprise the steps:
Step 101: set is carried out in the updating mark position that sets in advance.
In the present embodiment, when needs begin to carry out a certain affairs, at first set is carried out in the updating mark position that sets in advance, be about to the updating mark position and be set to 0.
Step 102: in the process of carrying out affairs, whenever execute a key node, then the execution result with this key node correspondence backs up, and by the updating mark position is provided with, writes down the executive process of these affairs.
Here the key node of being mentioned is meant a previously selected above important operation from all operations of finishing these office's need.
In this step, whenever execute a key node after, except the execution result of this key node correspondence will being backed up, also need the updating mark position is provided with, with the record affairs executive process.In the present embodiment, can distinguish corresponding different updating mark position set-up mode by pre-set different key node, like this, by this updating mark position of inquiry, can know carried out which key node that is in the subsequent process.Such as, after executing first key node, can be set to 1 in the updating mark position; After executing second key node, the updating mark position is set to 2, and the like.
Step 103: judge in the process of carrying out these affairs whether interrupt, if then execution in step 104; Otherwise, return execution in step 102.
Step 104: after interrupting recovery,, determine the operation that next step will be carried out by inquiry updating mark position, and according to this operation of determining of information and executing of backing up.
If in the process of carrying out affairs, owing to accidental interruption appears in various possible reasons, then after interrupting recovery, by inquiry updating mark position, what operation what can know that next step will carry out is, then, according to back up, the execution result of performed key node is carried out next step operation that will carry out that this is determined before promptly taking place to interrupt.
Illustrate: suppose that a certain affairs comprise three key nodes altogether, are respectively key node 1, key node 2 and key node 3; For ease of describing, supposing to finish these affairs only needs this three operations altogether.So,, but interrupt when also not executing key node 2, then after interrupting recovering, begin to carry out from key node 2 if executing key node 1; If executing key node 2, but interrupt when also not executing key node 3, then after interrupting recovering, begin to carry out from key node 3; Certainly, if when also executing key node 1, do not interrupt, then after interrupting recovery, begin execution from key node 1 and get final product.
In the subsequent process, process shown in the repeating step 102~104 is until all operations that executes these affairs.
Step 105: behind all operations that executes these affairs, with the zero clearing of updating mark position, process ends.
Need to prove that the affairs of being mentioned among the present invention can be meant the affairs of smartcard internal, also can be meant the affairs that need to carry out between smart card and the terminal information interaction.Promptly at both of these case, by concrete example scheme of the present invention is described in further detail respectively below.
Example one:
Suppose that smart card is condition receiving card (CA), affairs are that the CA card watches the duration of program to charge according to the user.As shown in Figure 2, the implementation of these affairs may further comprise the steps:
Step 201: the APDU instruction that receiving terminal is sent, open the transaction protection function.
After the user finished watching program, the employed terminal of user can send to the CA card and comprise programme information, as watched the APDU instruction of information such as duration, pay per view mode and price.After this APDU instruction is received in the CA clamping, open the transaction protection function of self, be about to position, updating mark position.
Step 202: the duration of watching of adding up the user.
Step 203: check pay per view mode and price, calculate the required expense of paying of user.
Step 204: judge whether remaining sum is sufficient in the card, if then execution in step 205; Otherwise, carry out fault processing.
It is irrelevant how to carry out fault processing and the present invention, is not described.
Step 205: carry out the operation of deducting fees.
Step 206: record transaction details.
The specific implementation of above-mentioned steps 202~206 all with prior art in identical, repeat no more.
Step 207: close the transaction protection function, process ends.
Be about to the zero clearing of updating mark position.
If interrupt in the process accident of carrying out affairs shown in Figure 2, such as, after having calculated the required expense of paying of user, also do not have enough time to deduct fees and just cut off the power supply, so, if handle, then be equivalent to the user and watched TV programme but not pay, thereby benefits of operators is suffered damage according to existing mode; And after adopting scheme of the present invention, can address this problem preferably.
Suppose that above-mentioned steps 202,203,204,205 and 206 is key node, then in carrying out the process of affairs shown in Figure 2, whenever execute a key node after, all need to carry out the backup of data and the setting of updating mark position.Like this, if when execution in step 203, interrupt, so, by inquiry updating mark position, carried out the step 202 that is over before can knowing interruption, and, owing to backed up the execution result of step 202, so can be according to this execution result execution in step 203; The rest may be inferred for other situation.Especially, for interrupting this situation when the execution in step 202, can be by inquiry updating mark position because it is set to 0 at this moment, so know and also do not carry out any key node, subsequent interrupt recover the back directly execution in step 202 get final product.
Example two:
Suppose that smart card is the CA card, affairs are similarly the CA card and watch the duration of program to charge according to the user, but different be with shown in Figure 2, in this example, terminal can be not directly send to the CA card with user's the program duration of watching, but need the CA cartoon after constantly carrying out information interaction with terminal, obtain the initial and concluding time that the user watches program, so calculate the user watch the program duration; And, in the follow-up charging process, the CA card also need and terminal between carry out information interaction.As shown in Figure 3, the implementation of these affairs may further comprise the steps:
Step 301: user's application software that opens a terminal, CA sticks into capable initial reset simultaneously.
Step 302: terminal sends to the CA card selects the APDU1 that uses to instruct.
In this step, terminal sends the APDU1 instruction to the CA card, is applied as the pairing application of pay TV so that notice CA card self is selected.
Step 303: the program that the terminal selection will be watched receives the data stream and the authorization control message (ECM) of selected program, and comprises the APDU2 instruction of ECM information to the transmission of CA card.
After the CA clamping receives the APDU1 instruction of self terminal, can be to response message of terminal loopback; After terminal receives this response message, promptly carry out the described process of this step.
After APDU2 instruction is received in step 304:CA clamping,, obtain and zero-time that recording user begins to watch program, parse control word (CW) simultaneously and return to terminal according to the current time information that carries in the ECM information wherein.
Step 305: the data stream of scrambling resolved in the CW word that the terminal utilization receives.
Step 306: when the user watched program to finish, terminal sent to the CA card and carries the APDU3 instruction of watching program end time.
Step 307:CA card statistics user watches duration, and calculates the expense that the user need pay and return to terminal.
Step 308: terminal sends to the CA card determines that the APDU4 that pays the fees instructs.
Step 309:CA sticks into the capable operation of deducting fees.
Step 310: after the success of deducting fees, CA card record transaction details, process ends.
Identical in the specific implementation of flow process shown in Figure 3 and the prior art, repeat no more.
Suppose that affairs shown in Figure 3 have four key nodes, are respectively step 303~306, step 307, step 309 and step 310.Whenever after executing a key node, all need to carry out the backup of data and the setting of updating mark position.Like this, in the process of carrying out these affairs, if in execution in step 303~306, perhaps interrupt in the process of execution in step 307, then after interrupting recovery, direct execution in step 307 (if the CA card does not also receive the program end time of watching of self terminal when taking place to interrupt, then the time when taking place to interrupt is as watching program end time); If interrupted in 309 o'clock carrying out, then after interrupting recovering, direct execution in step 309; If when execution in step 310, interrupt, then after interrupt recovering, direct execution in step 310.As seen, adopt above-mentioned processing mode after, avoided because the loss of data that accidental interruption caused, thereby made the operation of paying the fees after interrupting recovering, to proceed, safeguarded benefits of operators.
In addition, also provide the operator scheme choice mechanism in the scheme of the present invention, promptly supported the selection of smart card, that is to say, supported the continuation after data rollback and the operation disruption is carried out the selection of two kinds of patterns integrality operation and two kinds of patterns of atomicity operation.Certainly, if also have other operator scheme, can include range of choice in equally.Usually, for the less demanding affairs of real-time, can select the atomicity operation, and, then can select the integrality operation for the affairs that real-time is had relatively high expectations.Concrete selection mode can be: smart card receives the notification instruction of self terminal, determine to carry out the operator scheme that current office need adopt according to this notification instruction, perhaps, smart card also can be preserved the corresponding respectively operation mode information of different affairs of (manually being provided with) in advance according to self, determines to carry out the operator scheme that current office need adopt.Wherein, for preceding a kind of mode, described notification instruction typically refers to the APDU instruction, when a certain affairs of beginning, terminal can be utilized the first APUD instruction that sends to smart card, such as the APDU1 instruction in instruction of the APDU in the step 201 shown in Figure 2 and the step 302 shown in Figure 3, by an operator scheme zone bit that is provided with therein, the operator scheme that this office need be adopted is notified to smart card.
Have again, a kind of operation recovery protection mechanism also is provided in the scheme of the present invention, promptly in order to prevent malicious attack, guarantee the security of data manipulation, set in advance a maximum interruption times threshold value, like this, when the interrupted number of times of a certain affairs surpasses this maximum interruption times threshold value, then lock the application of this affairs correspondence; Continue these affairs if desired, then must should use release, the treatment scheme after could continuing then by authentication.
Fig. 4 is the realization flow figure of the operation recovery protection mechanism in the embodiment of the invention.As shown in Figure 4, may further comprise the steps:
Step 401: interrupt recovering, check that the affairs that count are interrupted number of times.
Carry out in the process of a certain affairs at smart card, after interrupting recovery, continue to carry out before the subsequent operation, at first check the interrupted number of times of the affairs that counted.In actual applications, can realize adding up affairs by the counter in the smart card and be interrupted this function of number of times.
Step 402: judge whether to be interrupted number of times greater than predefined maximum interruption times threshold value, if then execution in step 403; Otherwise, execution in step 405.
Step 403: carry out the asymmetric encryption authentication.
Promptly the terminal of pair carrying out information interaction with it by smart card is carried out the asymmetric encryption authentication.Certainly, also can adopt other authentication mode, herein only for illustrating.How to authenticate and be prior art, repeat no more.
Step 404: judge whether authentication is passed through, if then execution in step 405; Otherwise, return execution in step 403.
Step 405: the number of times that is interrupted that will count adds one.
Step 406: continue operation afterwards according to Backup Data and updating mark position.
Step 407: judge whether to interrupt once more, if then return execution in step 401; Otherwise, execution in step 408.
Step 408: continue to carry out subsequent operation, and behind EO, the number of times of adding up that is interrupted is made zero process ends.
Based on said method, Fig. 5 is the composition structural representation of apparatus of the present invention (being smart card) embodiment.As shown in Figure 5, comprising:
Backup units 51 is used for whenever executing a key node in the process of carrying out affairs, and then the execution result with this key node correspondence backs up, and by predefined updating mark position is provided with, writes down the executive process of these affairs; Described key node is a previously selected above important operation from all operations of finishing these office's need;
Performance element 52 is used for by inquiry updating mark position, determining the operation that next step will be carried out after the interruption recovery that the process of carrying out affairs occurs, and according to this operation of determining of information and executing of backing up.
In addition, also can further comprise in the smart card shown in Figure 5:
Mode selecting unit 53 is used to receive the notification instruction of self terminal, determines to carry out the operator scheme that current office need adopt according to this notification instruction, if the operator scheme of determining is the integrality operation, then notifies backup units 51 to carry out self function; Perhaps, be used for the operation mode information corresponding respectively, determine to carry out the operator scheme that current office need adopt,, then notify backup units 51 to carry out self function if the operator scheme of determining is the integrality operation according to the different affairs of preserving in advance.
This mode selecting unit 53 also can be further used for, if the operator scheme of determining is atomicity operation, then in the process of carrying out current affairs, has no progeny in taking place, and the state of these affairs will be rolled back to the state of these affairs before beginning to carry out.
Above-mentioned affairs can be meant the affairs of smartcard internal, also can be meant the affairs that need to carry out between smart card and the terminal information interaction.
Wherein, can specifically comprise in the performance element 52: determine subelement 521 and carry out subelement 522;
Determine subelement 521, be used for after the interruption recovery that the process of carrying out affairs occurs,, determining the operation that next step will be carried out by inquiry updating mark position;
Carry out subelement 522, be used for the operation of determining according to the information and executing of backup.
In addition, also can further comprise in this performance element 52:
Count sub-element 523 is used to add up the interrupted number of times of affairs of current execution;
Judgment sub-unit 524 is used to judge whether the described number of times that is interrupted has reached predefined maximum interruption times threshold value, if not, then notice is carried out subelement 522 and is carried out self function; If then carry out authentication, and after authentication was passed through, notice was carried out subelement 522 and is carried out self function.
The concrete workflow of smart card embodiment shown in Figure 5 please refer to the respective description among the method embodiment shown in Figure 1, repeats no more herein.
In a word, adopt technical scheme of the present invention, smart card in carrying out the process of a certain affairs, whenever execute a key node after, the execution result that is about to this key node correspondence backs up, and, the updating mark position writes down the executive process of affairs by being set, like this, in case in the process of carrying out these affairs, interrupt, after waiting to interrupt recovering, then can determine the operation that next step will be carried out according to the updating mark position, and can be according to this operation of determining of information and executing of backup.Compare with existing atomicity operator scheme, this operator scheme provided by the present invention can not cause loss of data because of interruption, so can satisfy the demand of miscellaneous services such as real-time and non real-time.In addition, scheme of the present invention also provides a kind of operator scheme choice mechanism and a kind of operation recovery protection mechanism, has guaranteed the dirigibility and the security of smart card operation.
In sum, more than be preferred embodiment of the present invention only, be not to be used to limit protection scope of the present invention.Within the spirit and principles in the present invention all, any modification of being done, be equal to replacement, improvement etc., all should be included within protection scope of the present invention.