CN104933565B - A kind of IC card transaction method and system - Google Patents

A kind of IC card transaction method and system Download PDF

Info

Publication number
CN104933565B
CN104933565B CN201510303111.4A CN201510303111A CN104933565B CN 104933565 B CN104933565 B CN 104933565B CN 201510303111 A CN201510303111 A CN 201510303111A CN 104933565 B CN104933565 B CN 104933565B
Authority
CN
China
Prior art keywords
transaction
card
data
management system
background management
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201510303111.4A
Other languages
Chinese (zh)
Other versions
CN104933565A (en
Inventor
林祥明
杨明
杨红超
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Bank of China Ltd
Original Assignee
Bank of China Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Bank of China Ltd filed Critical Bank of China Ltd
Priority to CN201510303111.4A priority Critical patent/CN104933565B/en
Publication of CN104933565A publication Critical patent/CN104933565A/en
Application granted granted Critical
Publication of CN104933565B publication Critical patent/CN104933565B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/352Contactless payments by cards
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

The present invention provides a kind of IC card transaction method and system, method, which includes: mobile intelligent terminal, establishes connection by NFC module and IC card;IC card transmits the transaction data containing transaction count information to mobile intelligent terminal;The transaction data containing transaction count information is sent to background management system by mobile intelligent terminal;Background management system verifies the transaction data containing transaction count information;After verification passes through, transaction request is handled, and the processing result of background management system is sent to mobile intelligent terminal;Mobile intelligent terminal is interacted with IC, responds the processing result of background management system.The present invention improves the convenience of IC card transaction and can guarantee the safety of IC card and background management system transaction.

Description

A kind of IC card transaction method and system
Technical field
The invention belongs to financial transaction field, in particular to a kind of method and system of IC card transaction.
Background technique
Load, circle, which mention, recognize load etc., at present is related to IC card and writes the financial transaction of card being required in POS terminal, bank's net It is carried out on the traditional channels such as point sales counter, since site and POS deployment are limited, this is just brought inconvenience to the user's use, limitation The popularization of financial IC card.
Summary of the invention
A kind of IC card transaction method and system provided by the invention, enable to client to carry out the friendship of IC card whenever and wherever possible Easily, user-friendly, and can guarantee the safety of IC card and background management system transaction.
The present invention provides a kind of IC card transaction method, comprising:
Mobile intelligent terminal establishes connection by NFC module and IC card;
The transaction data of the IC card transmission containing transaction count information gives the mobile intelligent terminal;
The transaction data containing transaction count information is sent to the back-stage management system by the mobile intelligent terminal System;
The background management system verifies the transaction data containing transaction count information;
After verification passes through, transaction request is handled, and the processing result of the background management system is sent to the movement Intelligent terminal;
The mobile intelligent terminal is interacted with the IC card, responds the processing result of the background management system.
In one embodiment of the invention, the transaction data containing transaction count information is included at least: more than IC card number, IC card Volume, current transaction count, authorization requests ciphertext (Authorization Request Cryptogram, ARQC), credit card issuer are answered With data (9F10 is a TAG in PBOC standard IC card), authorization requests data (ARQC source data);Wherein, the ARQC It is related to transaction count for the ciphertext of ARQC source data;The 9F10 includes IC card remaining sum, and ARQC source data packet contains transaction amount And transaction count;The every transaction count of transaction of IC card is incremented by 1.
In one embodiment of the invention, the mobile intelligent terminal receives the transaction data containing transaction count information Afterwards, the mobile intelligent terminal generates a transaction journal number, and by the transaction journal number and described contains transaction count information Transaction data be sent to the background management system.
In one embodiment of the invention, mistake that background management system verifies the transaction data containing transaction count information Journey are as follows: decryption ARQC, the ARQC source data after being decrypted will decrypt obtained ARQC source data and contain transaction count information Transaction data in ARQC source data make comparisons, if comparison result is identical, the authorization requests ciphertext is verified successfully, if than Compared with result difference, then background management system reports an error to the mobile intelligent terminal;9F10 is decrypted, more than the IC card after being decrypted Volume makes comparisons the IC card remaining sum that decryption obtains with the IC card remaining sum in the transaction data containing transaction count information, if comparing It as a result is identical, then credit card issuer application data check success, if comparison result is different, background management system reports an error to movement Intelligent terminal.
In one embodiment of the invention, after verification passes through, the process for handling transaction request includes: the background management system root According to the IC card remaining sum after the transaction amount calculation processing transaction request in the IC card remaining sum and the ARQC source data and generate Authorization response ciphertext (Authorization Response Cryptogram, ARPC) and credit card issuer script;Wherein, ARPC with ARQC, current transaction count are related;The credit card issuer script and the current transaction count of the IC card, ARQC, transaction amount and after The key of platform management system storage is related.
In one embodiment of the invention, the processing result process of the background management system is responded are as follows: the verification authorization is rung Answer ciphertext, the IC card takes the authorization requests ciphertext, current transaction count to generate an authorization response ciphertext, and by its with it is rear Platform management system is transmitted through the authorization response ciphertext come and makes comparisons, if comparison result is identical, authorization response ciphertext verification at Function, if comparison result is different, the IC card reports an error to the intelligent movable device;
The credit card issuer script is verified, the IC card decrypts the credit card issuer script, obtains transaction count, if decryption hair fastener The transaction count originally obtained of traveling far and wide is identical as current transaction count, then the credit card issuer script verifies successfully, if comparison result is not Together, then the IC card reports an error to the mobile intelligent terminal;
After the authorization response ciphertext and the credit card issuer script all verify successfully, the credit card issuer script is executed.
In one embodiment of the invention, when background management system processing transaction request time-out or IC card respond the back-stage management When the processing result failure of system, IC card transaction method further includes rushing positive process of exchange:
The mobile intelligent terminal establishes connection by NFC module and IC card;The IC card transmission rushes positive transaction data extremely The mobile intelligent terminal;The mobile intelligent terminal, which is at least sent, rushes positive transaction data and last transaction serial number to after described Platform management system;The background management system searches last transaction according to last transaction serial number, and according to the positive transaction of the punching Data and last transaction data carry out rushing positive transaction verification;After being verified, the positive transaction of background management system processing punching.
It is described to rush positive transaction data and include at least in one embodiment of the invention: IC card number, IC card remaining sum, ARQC, 9F10, ARQC source data and current transaction count.
In one embodiment of the invention, after the mobile intelligent terminal establishes connection by NFC module and the IC card, also wrap Include the process of the IC card Yu the mobile intelligent terminal validation-cross.
The present invention separately provides a kind of IC card transaction system, comprising: IC card, mobile intelligent terminal and background management system;
The mobile intelligent terminal includes: NFC module, information acquisition unit, wireless transmission unit and information exchange unit;
The NFC module connects the IC card and the mobile intelligent terminal, is that the IC card and the intelligent movable are whole End provides data transmission channel;The information acquisition unit receives the transaction data containing transaction count information of IC card transmission; The transaction data containing transaction count information is sent to the background management system by the wireless transmission unit;The letter Breath interactive unit is interacted with the IC card, responds the processing result of background management system;
The background management system includes: information receiving unit, verification unit, transaction handling unit, communication unit;
The information receiving unit receives the transaction data containing transaction count information;The verification unit verifies institute State the transaction data containing transaction count information;The transaction handling unit handles transaction request;The communication unit will be described The processing result of background management system is sent to the mobile intelligent terminal.
In one embodiment of the invention, the transaction data containing transaction count information is included at least: more than IC card number, IC card Volume, current transaction count, ARQC, 9F10, ARQC source data;Wherein, ARQC is the ciphertext of ARQC source data, with transaction count phase It closes, 9F10 includes IC card remaining sum, and the ARQC source data packet contains transaction amount and transaction count, the primary transaction time of the every transaction of IC card Number is incremented by 1.
In one embodiment of the invention, the mobile intelligent terminal further includes a transaction journal generation unit, is connected to institute Information acquisition unit is stated, after the information acquisition unit receives the transaction data containing transaction count information, starting Transaction journal generation unit generates a transaction journal number, and by the transaction journal number and described is contained by wireless transmission unit There is the transaction data of transaction count information to be sent to the background management system.
In one embodiment of the invention, the verification unit decrypts ARQC, and the ARQC source data after being decrypted will decrypt To ARQC source data make comparisons with the ARQC source data in the transaction data containing transaction count information, if comparison result phase Together, then the authorization requests ciphertext verifies successfully, if comparison result is different, background management system reported an error to intelligent movable end End;
The verification unit decrypts 9F10, and the IC card remaining sum after being decrypted will be decrypted obtained IC card remaining sum and be contained The IC card remaining sum of the transaction data of transaction count information is made comparisons, if comparison result is identical, the credit card issuer application data school Success is tested, if comparison result is different, background management system reports an error to mobile intelligent terminal.
In one embodiment of the invention, background management system further includes computing unit, and computing unit is according to the IC card remaining sum And IC card remaining sum after the transaction amount calculation processing transaction request in the ARQC source data and generate ARPC and hair fastener is traveled far and wide This;Wherein, authorization response ciphertext is related to authorization requests ciphertext, transaction count;The credit card issuer script and the IC card are current Transaction count, ARQC, transaction amount and the key of background management system storage are related.
In one embodiment of the invention, when background management system handles transaction request time-out or IC card responds the backstage pipe When the processing result failure of reason system, IC card transaction further includes rushing positive process of exchange: the mobile intelligent terminal passes through NFC module Connection is established with IC card;The IC card transmission rushes positive transaction data to the mobile intelligent terminal;The mobile intelligent terminal is extremely Few send rushes positive transaction data and last transaction serial number to the background management system;The background management system was according to last time Transaction journal number searches last transaction, and rushes positive transaction data and last transaction data carry out rushing positive transaction verification according to described; After being verified, the positive transaction of background management system processing punching.
It is described to rush positive transaction data and include at least in one embodiment of the invention: IC card number, IC card remaining sum, ARQC, 9F10, ARPC source data and current transaction count.
In one embodiment of the invention, after the mobile intelligent terminal establishes connection by NFC module and the IC card, also Process including the IC card Yu the mobile intelligent terminal validation-cross.
Mobile intelligent terminal provided by the invention can be the terminals such as the commonly used mobile phone with NFC function, PAD, phase For conventional terminal, the convenience of IC card transaction is greatly improved.The present invention can be established by NFC module and IC card Connection, so that the reading to IC card information is realized, in addition, including transaction count information, enhancing in the transaction data of IC card transmission Safety in process of exchange, meanwhile, IC card transaction method provided by the invention further includes rushing positive trading processing process, together Sample, background management system will verify transaction count, transaction amount and IC card remaining sum, when positive transaction is rushed in processing into one Step improves mobile intelligent terminal and is realizing safety when interacting with IC card and background management system.IC card provided by the invention Method of commerce and system can facilitate, securely achieve IC card transaction.
Detailed description of the invention
In order to illustrate the technical solution of the embodiments of the present invention more clearly, required use in being described below to embodiment Attached drawing be briefly described, it should be apparent that, drawings in the following description are only some embodiments of the invention, for this For the those of ordinary skill of field, without any creative labor, it can also be obtained according to these attached drawings other Attached drawing.
Fig. 1 is a kind of IC card transaction method flow chart of one embodiment of the invention;
Fig. 2 is a kind of positive transaction flow chart of IC card transaction method punching of one embodiment of the invention;
Fig. 3 is a kind of IC card transaction system structure chart of one embodiment of the invention;
Fig. 4 is a kind of IC card load transaction flow figure of one embodiment of the invention;
Fig. 5 is the IC card and mobile intelligent terminal and background management system interaction diagrams of one embodiment of the invention.
Specific embodiment
In order to keep technical characterstic and effect of the invention more obvious, technical solution of the present invention is done with reference to the accompanying drawing It further illustrates, the specific example that the present invention can also have other different is illustrated or implements, anyone skilled in the art The equivalents done within the scope of the claims belong to protection category of the invention.
As shown in FIG. 1, FIG. 1 is a kind of IC card transaction method flow charts of one embodiment of the invention, comprising:
Step S1: mobile intelligent terminal establishes connection by NFC module and IC card.
In another embodiment of the present invention, mobile intelligent terminal provides human-computer interaction interface, which can show IC card Essential information (IC card number and IC card serial number) and type of transaction option etc. when transaction, select type of transaction, input transaction amount, After confirmation, IC card and mobile intelligent terminal interact verifying.In the present embodiment, IC card and mobile intelligent terminal validation-cross mistake Journey include: using initialization, read using data, offline data certification, processing limitation, holder certification, terminal behavior analysis and Online process, wherein offline data certification is option.Above-mentioned verification process meets PBOC debt-credit note application flow, about PBOC debt-credit note application flow will be described in detail in the embodiment below, and details are not described herein again.
Step S2:IC card transmits the transaction data of the information containing transaction count to mobile intelligent terminal.One embodiment of the invention In, the transaction data of the information containing transaction count of IC card transmission includes: IC card number, IC card serial number, current transaction count, more than IC card Volume, ARQC, 9F10, ARQC source data.Wherein, the ciphertext of ARQC and transaction counter (Application Transaction Counter, ATC) enumeration correlation, the every transaction of IC card is primary, and the counting of ATC can all be incremented by 1.Transaction count is had by transmission The transaction data of information can increase substantially safety of the mobile intelligent terminal as IC card transaction terminal.On how to utilize biography The defeated transaction data containing transaction count information guarantees that the principle of safety of IC card transaction will carry out in subsequent embodiment It is described in detail, details are not described herein again.
Detailed, ARQC source data, which refers to, generates data used in ARQC, including the authorization amount of money+other amount of money+terminal country Code+terminal authentication result+transaction currency code+trade date+type of transaction+random number+using transaction count+card verifying As a result.9F10 is a TAG in PBOC standard IC card, indicates " credit card issuer application data ", contains current card remaining sum, card Verification result, MAC value, wherein MAC value is generated by current card remaining sum using certain algorithm and key.ARQC is the source ARQC number According to ciphertext, generated jointly by transaction count and other ARQC source datas.The mark of IC card number and IC card serial number IC card, IC card Number for distinguishing other IC card, IC card serial number is used to indicate the number that one IC card is replaced.
Step S3: the transaction data containing transaction count information is sent to background management system by mobile intelligent terminal.Tool Body, it retransmits after transaction data group message to background management system, background management system stores the interaction data of every transaction. In another embodiment, after mobile intelligent terminal receives the transaction data containing transaction count information, a transaction journal number is generated, Mobile intelligent terminal will be sent to back-stage management system after the transaction data containing transaction count information and transaction journal group message System, mark of the transaction journal number as every transaction can be convenient for inquiring transaction record from background management system.
Step S4: background management system verifies the transaction data containing transaction count information.Specifically, backstage is managed Reason system decrypts ARQC after the message for receiving mobile intelligent terminal transmission, and the ARQC source data after being decrypted compares solution Authorization requests data in the ARQC source data obtained after close and the transaction data containing transaction count information, if comparison result phase Together, then continue to verify, if comparison result is different, background management system, which reports an error, returns to mobile intelligent terminal, shuts the book.It is logical It crosses and ARQC is verified, be able to verify that the true and false of IC card, while distorting for transaction amount can be prevented, include trade gold in ARQC Volume can not just pass through when verifying ARQC from the background if transaction amount is tampered during data are transmitted to backstage, report an error and return Back to mobile intelligent terminal, transaction is unable to complete.
Decrypt 9F10, the IC card remaining sum after decrypt, and will be in the IC card remaining sum that obtained after decryption and transaction data IC card remaining sum is made comparisons, if comparison result is identical, verifies success, if comparison result is different, background management system stops handing over Easily.Distorting for card balance can be prevented by the verification to 9F10.
After ARQC and 9F10 is verified successfully, then enter step S5, it should be noted that the present invention be not intended to limit ARQC and The verification sequence of 9F10.
Step S5: after verification passes through, transaction request is handled, and the processing result of background management system is sent to mobile intelligence It can terminal.Specifically, processing transaction request process are as follows: background management system takes the trade gold in IC card remaining sum and ARQC source data IC card remaining sum (deducting transaction amount from the IC card amount of money in transaction request data) after volume calculation processing transaction request generates ARPC and credit card issuer script.Wherein, credit card issuer script and the current transaction count of IC card, ARQC, transaction amount and back-stage management system The key stored of uniting is related;ARPC is generated jointly by the counting and other data of ARQC, ATC.
Step S6: mobile intelligent terminal is interacted by NFC module and IC card, completes IC card to background management system The response of processing result.Respond the processing result process of background management system are as follows: verification ARPC, IC card are counted by ARQC, current ATC Number generates an ARPC, and it is transmitted through the ARPC come with background management system and is made comparisons, if comparison result is identical, the school ARPC Success is tested, if comparison result is different, IC card, which reports an error, gives intelligent movable device.It can be effectively prevent by the verification to ARPC The recycling of ARPC.
Verify credit card issuer script, IC card decrypts credit card issuer script, obtains transaction count, when the obtained transaction count of decryption with Current transaction count is identical, then credit card issuer script verifies successfully, if comparison result is different, IC card reported an error to intelligent movable end End.By the verification to credit card issuer script, it can be effectively prevent credit card issuer script and the recycling of ARQC, be exemplified below The process for preventing ARQC from reusing.For example, the ATC of current IC card is counted as 2, when attacker sends out by the ATC ARQC for being counted as 1 Send to what background management system gained backstage by cheating and write card base sheet, at this point, the IC card that backstage generates write card base originally and be counted by ATC and its Its data is generated by key, IC card is taken write card base sheet after be decrypted, discovery ATC be counted as 1, with current ATC count It is not inconsistent, IC card can be refused to write card base sheet, thus Fail Transaction.Prevent from writing the process of the recycling of card base sheet are as follows: work as credit card issuer When script is repeatedly sent to IC card by attacker, IC card is taken write card base sheet after it is decrypted, discovery transaction count with it is upper Secondary transaction count is identical, and refusal is write card base sheet by IC card.
After authorization response ciphertext and credit card issuer script all verify successfully, credit card issuer script is executed.
Optionally, when background management system processing transaction request time-out or the processing result of IC card response background management system When failure, IC card transaction method further includes rushing positive process of exchange, illustrates to rush the detailed process just traded below with reference to Fig. 2:
Step S21: mobile intelligent terminal establishes connection by NFC module and IC card.In one embodiment of the invention, IC card with It further include the process that IC card and mobile intelligent terminal interact verifying after mobile intelligent terminal establishes connection.IC card and movement Intelligent terminal interactive verification process includes: using initialization, reads to recognize using data, offline data certification, processing limitation, holder Card, terminal behavior analysis and online process, wherein offline data certification be option, other use IC provided by the invention When card method of commerce, it can also be authenticated without offline data.IC card and mobile intelligent terminal interactive verification process will be real below Example explanation is applied, details are not described herein again.
The transmission of step S22:IC card rushes positive transaction data to mobile intelligent terminal.Wherein, positive transaction data is rushed to include at least: IC card number, IC card remaining sum, ARQC, 9F10, ARQC source data and current transaction count.It further include IC in another embodiment of the present invention Card serial number
Step S23: mobile intelligent terminal, which is at least sent, to be rushed positive transaction data and last transaction serial number to the backstage and manages Reason system.Mobile intelligent terminal will rush positive transaction data, last transaction serial number, last transaction amount of money group message in the present embodiment After be sent to background management system.
Step S24: background management system searches last transaction according to last transaction serial number, and according to the positive transaction of the punching Data and last transaction data carry out rushing positive transaction verification, specific verification process are as follows: verify last transaction transaction count whether Than when the orthogonal easy transaction count of preshoot it is small by 1;Whether the IC card remaining sum of verifying last transaction is equal to when the orthogonal easy IC card of preshoot Remaining sum;Whether the transaction amount of verifying last transaction is equal to when the orthogonal easy transaction amount of preshoot;Positive transaction data is rushed in verifying.It tests Card rushes positive transaction data and mainly examines ARQC, 9F10.
Step S25: if above-mentioned verifying is all correct, the positive transaction of background management system processing punching, if there is authentication error at one, after Platform management system reports an error to mobile intelligent terminal.
One embodiment of the invention provides a kind of IC card transaction system, as shown in figure 3, IC transaction system includes IC card 30, moves Dynamic intelligent terminal 31 and background management system 32;
Mobile intelligent terminal 31 includes: NFC module 311, information acquisition unit 313, wireless transmission unit 312, information friendship Mutual unit 314;
NFC module 311 is the number of IC card 30 and mobile intelligent terminal 31 for connecting IC card 30 and mobile intelligent terminal 31 Transmission channel is provided according to transmission and interaction;Information acquisition unit 313 receives the transaction containing transaction count information of IC card transmission Data;Transaction data containing transaction count information is sent to background management system 32 by wireless transmission unit 312;Information exchange Unit 314 is interacted with IC card 30, responds the processing result of background management system.
Background management system 32 includes: information receiving unit 321, verification unit 322, transaction handling unit 323, communication unit Member 324;
Information receiving unit 321 receives the transaction data containing transaction count information;The verification of verification unit 322 is containing transaction time The transaction data of number information;Transaction handling unit 323 handles transaction request;Communication unit 324 is by the processing of background management system As a result it is sent to mobile intelligent terminal 31.
In the present embodiment, the transaction data being related to includes at least IC card number, IC card serial number, IC card remaining sum, current transaction Number, ARQC, 9F10, ARQC source data, wherein ARQC is the ciphertext of ARQC source data, and ARQC includes transaction amount and transaction Number, 9F10 include IC card remaining sum.
In the present embodiment, after verification unit verification passes through, computing unit is according to the friendship in IC card remaining sum and ARQC source data IC card remaining sum and ARPC and credit card issuer script are generated after easy amount of money calculation processing transaction request.Wherein, credit card issuer script and IC card Current transaction count, ARQC, transaction amount and the key of background management system storage are related, ARPC and ARQC, transaction count phase It closes.
In one embodiment, mobile intelligent terminal further includes a transaction journal generation unit, is connected to information acquisition unit, After information acquisition unit receives the transaction data containing transaction count information, starting transaction journal generation unit generates one Transaction journal number, and after being sent to transaction journal number and transaction data containing transaction count information by wireless transmission unit Platform management system.
In addition to this, when background management system processing transaction request time-out, IC card transaction further includes rushing positive process of exchange: being moved Dynamic intelligent terminal establishes connection by NFC module and IC card;IC card transmission rushes positive transaction data to mobile intelligent terminal;Mobile intelligence Energy terminal, which is at least sent, rushes positive transaction data and last transaction serial number to background management system;Background management system was according to last time Transaction journal number searches last transaction, and the verification unit of background management system further comprises transaction count comparator, more than IC card Volume comparator and transaction amount comparator.Whether transaction count comparator verifies the transaction count of last transaction than when preshoot is orthogonal Easy transaction count is small by 1;Whether IC card remaining sum comparator verifying last transaction IC card remaining sum is equal to when the orthogonal easy IC card of preshoot Remaining sum;Equal to when the orthogonal easy transaction amount of preshoot when transaction amount comparator verifies the transaction amount of last transaction.On if It is all correct to state verifying, the positive transaction of the transaction handling unit processing punching, and by the communication unit by the back-stage management The processing result of system is sent to the mobile intelligent terminal;If there is authentication error at one, the background management system report an error to The mobile intelligent terminal.
The transaction of IC card involved in the present invention refers to that load, circle mention, lock card, transfer accounts, consume, commonly borrowing credit transaction Deng, it is all to follow PBOC debt-credit note using the transaction of normal process by what IC card was initiated, it can substantially include all bank cards By means of credit transaction.IC card in the present invention is to follow the common IC card of PBOC specification, and transaction can be realized in general finance IC.On State mobile intelligent terminal in embodiment can for NFC function mobile phone or tablet computer or built-in above-mentioned mobile intelligence The mobile phone or tablet computer of energy terminal.Below by by the mobile phone with NFC function, realize the transaction of load for be described in detail this The technical solution of invention, other kinds of transaction is referring to load trading scheme.
It please refers to shown in Fig. 4, Fig. 4 is a kind of IC card load transaction flow figure of one embodiment of the invention.Load transaction flow Journey is as follows:
1, load is inquired: mobile phone calls NFC function and IC card to establish connection, and reads card number, card serial number, disconnection and IC card Connection, organize message, send load inquiry transaction to background management system.
2, load inquiry return: background management system return the IC card can load maximum dollar amount.
3, load is traded: client inputs the amount of money for thinking load, and after determining, mobile phone calls NFC function and IC card to establish connection, And the interaction of the following steps is carried out with IC: application initialization reads using data, offline data certification, processing limitation, holds People's certification, terminal risk management, terminal behavior analysis, card behavioural analysis, online process.After interactive authentication, IC card transmission is handed over Easy data IC card number, IC card serial number, IC card remaining sum, ARQC, 9F10 (remaining sum containing IC card), ARQC source data (containing transaction amount) etc. To mobile phone, wherein the ciphertext of ARQC is related to transaction count.Then, mobile phone produces transaction journal number, and by transaction data and friendship Easy serial number composition message is sent to background management system.
4, load returns: background management system carries out ARQC verification, 9F10 verification, if verification failure, back-stage management system System reports an error to mobile phone.If verification passes through, the transaction amount in IC card remaining sum and ARQC source data is taken to carry out business processing, and count It calculates new IC card remaining sum, generate APRC and credit card issuer script command, be sent to mobile phone.If background management system handles Times Mistake, then load transaction terminate, if the processing result of background management system returns success to mobile phone, mobile phone utilizes NFC and IC card Carry out the interaction of following steps: credit card issuer certification, transaction terminate, credit card issuer script is handled, and entire transaction, disconnection are completed after interaction NFC connection.
5, the positive transaction of punching: if background management system processing time-out or the failure of " processing of credit card issuer script " step, mobile phone Re-call the connection of NFC function foundation and IC card, mobile phone and IC card carry out the interaction of the following steps: application selection is answered With initialization, read using data, offline data certification, processing limitation, holder's certification, terminal risk management, terminal behavior point Analysis, card behavioural analysis, online process, the data that IC card is transmitted to mobile phone in interaction include IC card number, IC card serial number, more than IC card Volume, ARQC, 9F10, ARQC source data, current transaction count ATC etc., then mobile phone group message (comprising IC card number, IC card serial number, IC card remaining sum, ARQC, 9F10, ARQC source data, ATC, the APP serial number of former load, transaction amount of former load etc.) at load The positive transaction of punching is sent to background management system.
6, the positive transaction of punching returns: background management system is traded with " the APP serial number of former load " information searching original load, and Verify former load transaction ATC whether than when preshoot is easy ATC orthogonal small by one, verify former load transaction IC card remaining sum whether etc. In working as the orthogonal easy IC card remaining sum of preshoot, whether the transaction amount for verifying former load transaction is equal to when the orthogonal easy trade gold of preshoot Volume examines the MAC of ARQC, 9F10 to report an error if there is the authentication failed of a step and be back to mobile phone;Otherwise, it carries out rushing decent job from the background The processing of business, and return successfully to mobile phone.
According to the technique and scheme of the present invention, the mobile intelligent terminal provided through the invention can be realized transmission containing transaction The transaction data of number information is to background management system, and there are certain relationship (such as transaction amount between the data in transaction data With ARQC source data, IC card remaining sum and 9F10 etc.), and there is one-time validity (e.g., ARQC, ARPC and issuing card script etc.), So that mobile intelligent terminal all escapes the inspection of only recipient to the malice change of any sensitive data, malice is also avoided It reuses.It is related to dynamic family or changes the transaction of the IC card amount of money --- such as load and the positive transaction of load punching are required to read IC card simultaneously ARQC is generated by IC card, background management system verifying ARQC simultaneously controls business according to condition, to ensure that dynamic family is handed over Easy safety.
Under the premise of the safety of safety and background management system based on IC card itself can not be broken, below to upper The safety measure stated in embodiment load transaction scene further illustrates:
1, " load inquiry " stage is attacked: IC card number or IC card serial number nonsensitive data are acquired harmless;It is tampered, Will affect backstage return it is maximum can the load amount of money correctness, this amount of money is only used to for reference.
2, " load inquiry return " stage is attacked: be modified maximum can the load amount of money, it is harmless, will not be to user's IC card gold Volume impacts.
3, " load " stage is attacked: IC card number, IC card serial number are tampered, and backstage verifies ARQC and will fail (due to ARQC Decryption generates ARQC source data, and IC card number, IC card serial number are to generate one of ARQC source data), so that Fail Transaction, not will lead to Accidentally trade.IC card remaining sum is tampered, and backstage verifies 9F10 and will fail, this is because 9F10 decryption generates IC card remaining sum, Xie Misheng At IC card remaining sum compared with the IC card remaining sum in transaction data, thus guarantee not will lead to accidentally trade.ARQC, 9F10 or ARQC Source data is tampered, and will lead to ARQC or 9F10 verification failure, so that Fail Transaction, not will lead to and accidentally trade.If ARQC or 9F10 is stolen, can not also reuse, because ARQC and 9F10 is related to the transaction count of transaction counter ATC of IC card, The ATC to trade every time can change, and cause ARQC and 9F10 that can also change, and the MAC of ARQC and 9F10 can not be by mould It is bionical at.In addition because the interactive step of the security control of IC card, mobile phone and IC card can be in strict accordance with the standard of debt-credit note application Process, any distorting can all be refused by IC card, therefore also prevent the attack in process.
4, " load return " stage is attacked: the ARPC or credit card issuer script on backstage are tampered, and can all IC card be caused to be refused, Prevent malice distort or malice change credit card issuer script in IC card remaining sum.ARPC and credit card issuer script are stolen, Can not reuse, ARPC is related to the ARQC of credit card issuer script with ATC and at that time, can only when time using, can not wrong time or Recycling, and generation can not be imitated.
5, " punching the is just " stage is attacked: the defendance measure that this stage is attacked is similar with " load " stage.In addition, client exists Load is write in the successful situation of card, if still malice initiates the positive transaction of punching, will lead to the verification failure of backstage IC card remaining sum.If client exists Load is write in the successful situation of card, and the consumption of the equal amount of money has been done, then the positive transaction of initiation punching of malice, though IC card remaining sum is handed at this time Easily success, but ATC verification will fail, because the consumer sale of IC card, which will lead to ATC, adds 1.
6, " punching the is positive to be returned " stage is attacked: being returned if correct return is tampered for mistake, or mistake is returned and repaired It is changed to correctly return, does not influence account processing.
Illustrate technical solution of the present invention to become apparent from, IC card and mobile intelligent terminal and background management system are handed over below Mutual process carries out lower detailed description, and detailed process is as shown in figure 5, interaction flow involved in flow chart is traded in debit/credit Obtained in processing using.Solid box is indispensable process, and overstriking dotted line frame is also indispensable process, but some in such indispensable process Step may is that selectable, but still should be executed in All Activity labeled as the step of indispensable process.Fine dotted line Frame is selectable and according to card or the parameter of terminal, or the step of being codetermined according to the parameter of the two.The card being set forth below Piece is IC card, and terminal refers to the mobile intelligent terminal for having function and structure of the present invention, refers to having function of the present invention from the background The background management system of energy and structure.
Using selection (indispensability)
When in the range of being placed in terminal and can be read, terminal obtains the list of application that card is supported.
Using initialization (indispensability)
After terminal selection application, terminal carries out obtaining the function that card is supported using initialization.
It reads to apply data (indispensability)
Terminal reads the application data record in card using read record order.
Offline data authenticates support of (optional) terminal according to card and terminal to these methods, decides whether using off line Either statically or dynamically data authentication carrys out off line certification card.If terminal supports offline data authentication function, and detects card Support static data certification (SDA) or Dynamic Data Authentication (DDA), then terminal need to carry out offline data certification, and it is raw to obtain card At dynamic application ciphertext.
Processing limitation (indispensability)
Terminal is checked by processing limitation using whether transaction allows to continue.The scope of examination includes using the phase of coming into force, answers Application purpose control can be used in the limitation control condition defined with failure period, application version number and other credit card issuers, credit card issuer Can system be used for domestic or international to limit card, or be used for cash, shopping or service.
Holder verifies (indispensability)
Terminal must have holder's identification verification function.Holder's authentication is used to confirm the legitimacy of holder, To prevent the use of loss or stolen card.Terminal is true by the holder's authentication method list (CVM lists) for checking card Surely which kind of verification method used.There is following several method:
--- off line plaintext PIN verifying;
--- online PIN verifying;
--- signature;
--- CVM failure;
--- it is not necessarily to CVM;
--- signature is combined with off line plaintext PIN verifying;
--- identity document verifying.
Terminal risk management (indispensability)
Terminal must have risk management function, but check item therein can choose.Terminal passes through terminal and card The data that piece provides can carry out nil-norm (Floor Limit) inspection, transaction frequency inspection, neocaine inspection, terminal abnormal File checking, trade company force the modes such as online, the random selection on-line transaction of transaction to complete risk management.
Terminal behavior analyzes (indispensability)
Terminal requests application cryptogram to card, and IC card executes card behavioural analysis, and generates application cryptogram to terminal.
Card behavioural analysis (indispensability)
IC card can execute risk management algorithm that credit card issuer defines to prevent credit card issuer to be spoofed.When card receives terminal Application cryptogram request when, card is carried out card risk management inspection, come decide whether to change terminal profile trading processing, Inspection may include: previously unfinished on-line transaction, upper transaction credit card issuer authentification failure or offline data authentification failure, Transaction stroke count or the limitation of the amount of money etc. are reached.IC card can determine following manner continuous business:
--- agree to that off line is completed;
--- online authorization;
--- refusal transaction.
It completes after checking, card generates application using the application cryptogram process key that application data and one are stored on card Ciphertext.This ciphertext is returned to terminal again by it.
Online process (optional) and credit card issuer script processing (optional) are described in detail in the above-described embodiments, Details are not described herein again.
Transaction terminates (indispensability)
Examined including ARPC, write card base this verification, write card script execution, except it is nontransaction in preceding several steps because of processing extremely It is terminated, otherwise terminal has to carry out this function and is used to close the trade.Card and terminal execute last processing to complete to trade.
Mobile intelligent terminal provided by the invention can be the terminals such as the commonly used mobile phone with NFC function, PAD, phase For conventional terminal, the convenience of IC card transaction is greatly improved.The present invention can be established by NFC model and IC card Connection, so that the reading to IC card information is realized, in addition, including transaction count information, enhancing in the transaction data of IC card transmission Safety in process of exchange, meanwhile, IC card transaction method provided by the invention further includes rushing positive trading processing process, together Sample, background management system will verify transaction count, transaction amount and IC card remaining sum, when positive transaction is rushed in processing into one Step improves mobile intelligent terminal and is realizing safety when interacting with IC card and background management system.The present invention can conveniently, Securely achieve IC card transaction.
The above is only used to illustrate the technical scheme of the present invention, any those of ordinary skill in the art can without prejudice to Under spirit and scope of the invention, modifications and changes are made to the above embodiments.Therefore, protection scope of the present invention should regard right Subject to claimed range.

Claims (16)

1. a kind of IC card transaction method characterized by comprising
Mobile intelligent terminal establishes connection by NFC module and IC card;
The transaction data of the IC card transmission containing transaction count information gives the mobile intelligent terminal;Wherein, described to contain friendship The transaction data of easy number information includes at least: IC card number, IC card remaining sum, current transaction count, authorization requests ciphertext, credit card issuer Using data, authorization requests data;
The transaction data containing transaction count information is sent to background management system by the mobile intelligent terminal;
The background management system verifies the transaction data containing transaction count information;
After verification passes through, processing transaction request generates authorization response ciphertext and credit card issuer script, wherein authorization response ciphertext with award Power request ciphertext, current transaction count are related;Credit card issuer script and the current transaction count of IC card, authorization requests ciphertext, trade gold Volume and the key of background management system storage are related, and the processing result of the background management system is sent to the mobile intelligence It can terminal;
The mobile intelligent terminal is interacted with the IC card, responds the processing result of the background management system;
Wherein, the processing result process of the response background management system are as follows: verify the authorization response ciphertext, the IC Authorization requests ciphertext described in Qana, current transaction count generate an authorization response ciphertext, and it is passed with background management system The authorization response ciphertext to come over is made comparisons, if comparison result is identical, the authorization response ciphertext is verified successfully, if comparison result Difference, then the IC card reports an error to the mobile intelligent terminal;
The credit card issuer script is verified, the IC card decrypts the credit card issuer script, obtains transaction count, if decryption hair fastener is traveled far and wide Originally the transaction count obtained is identical as current transaction count, then the credit card issuer script verifies successfully, if comparison result is different, The IC card reports an error to the mobile intelligent terminal;
After the authorization response ciphertext and the credit card issuer script all verify successfully, the credit card issuer script is executed.
2. IC card transaction method as described in claim 1, which is characterized in that the authorization requests ciphertext is the authorization requests The ciphertext of data is related to current transaction count;The credit card issuer application data include IC card remaining sum;The authorization requests data Include transaction amount and current transaction count;The every transaction count of transaction of IC card is incremented by 1.
3. IC card transaction method as claimed in claim 2, which is characterized in that the mobile intelligent terminal receives described contain After the transaction data of transaction count information, generate a transaction journal number, and by the transaction journal number and it is described contain transaction time The transaction data of number information is sent to the background management system.
4. IC card transaction method as claimed in claim 2, which is characterized in that the background management system contains transaction to described The process that the transaction data of number information is verified are as follows: decryption and authorization request ciphertext, the authorization requests data after being decrypted, It is made comparisons with the authorization requests data in the transaction data containing transaction count information, it is described if comparison result is identical Authorization requests ciphertext verifies successfully, if comparison result is different, the background management system reports an error to the mobile intelligent terminal;
Decrypt the credit card issuer application data, the IC card remaining sum after being decrypted, by itself and the transaction containing transaction count information IC card remaining sum in data is made comparisons, if comparison result is identical, the credit card issuer application data check success, if comparing knot Fruit is different, then the background management system reports an error to the mobile intelligent terminal.
5. IC card transaction method as claimed in claim 2, which is characterized in that after verification passes through, handle the process of transaction request Include:
The background management system is handed over according to the transaction amount calculation processing in the IC card remaining sum and the authorization requests data Easily request after IC card remaining sum and generate authorization response ciphertext and credit card issuer script.
6. IC card transaction method as claimed in claim 3, which is characterized in that when background management system processing transaction request time-out Or IC card respond the background management system processing result failure when, IC card transaction method further includes rushing positive process of exchange:
The mobile intelligent terminal establishes connection by NFC module and IC card;
The IC card transmission rushes positive transaction data to the mobile intelligent terminal;
The mobile intelligent terminal, which is at least sent, rushes positive transaction data and last transaction serial number to the background management system;
The background management system according to last transaction serial number search last transaction, and according to it is described rush positive transaction data and on Secondary transaction data carries out rushing positive transaction verification;
After being verified, the positive transaction of background management system processing punching.
7. IC card transaction method as claimed in claim 6, which is characterized in that described to rush positive transaction data and include at least: IC card Number, IC card remaining sum, authorization requests ciphertext, credit card issuer application data, authorization requests data and current transaction count.
8. IC card transaction method as described in claim 1 or 6, which is characterized in that the mobile intelligent terminal passes through NFC module It further include the process of the IC card Yu the mobile intelligent terminal validation-cross after establishing connection with the IC card.
9. a kind of IC card transaction system characterized by comprising IC card, mobile intelligent terminal and background management system;
The mobile intelligent terminal includes: NFC module, information acquisition unit, wireless transmission unit and information exchange unit;
The NFC module connects the IC card and the mobile intelligent terminal, mentions for the IC card with the mobile intelligent terminal For data transmission channel;The information acquisition unit receives the transaction data containing transaction count information of IC card transmission, wherein The transaction data containing transaction count information includes at least: IC card number, IC card remaining sum, current transaction count, authorization requests Ciphertext, credit card issuer application data, authorization requests data;The wireless transmission unit is by the transaction containing transaction count information Data are sent to the background management system;The information exchange unit is interacted with the IC card, responds back-stage management system The processing result of system;
The background management system includes: information receiving unit, verification unit, transaction handling unit, communication unit;
The information receiving unit receives the transaction data containing transaction count information;Contain described in the verification unit verification There is the transaction data of transaction count information;The transaction handling unit processing transaction request generates authorization response ciphertext and credit card issuer Script, wherein authorization response ciphertext is related to authorization requests ciphertext, current transaction count;Credit card issuer script is currently handed over IC card Easy number, authorization requests ciphertext, transaction amount and the key of background management system storage are related;After the communication unit will be described The processing result of platform management system is sent to the mobile intelligent terminal;
Wherein, the processing result process of the response background management system are as follows: verify the authorization response ciphertext, the IC Authorization requests ciphertext described in Qana, current transaction count generate an authorization response ciphertext, and it is passed with background management system The authorization response ciphertext to come over is made comparisons, if comparison result is identical, the authorization response ciphertext is verified successfully, if comparison result Difference, then the IC card reports an error to the intelligent movable equipment;The credit card issuer script is verified, the IC card decrypts the hair fastener This is traveled far and wide, transaction count is obtained, if the transaction count that decryption credit card issuer script obtains is identical as current transaction count, the hair Card is traveled far and wide, and this verification is successful, if comparison result is different, the IC card reports an error to the mobile intelligent terminal;The authorization response After ciphertext and the credit card issuer script all verify successfully, the credit card issuer script is executed.
10. IC card transaction system as claimed in claim 9, which is characterized in that the authorization requests ciphertext is that the authorization is asked The ciphertext for seeking data is related to current transaction count;The credit card issuer application data include IC card remaining sum, the authorization requests number According to including transaction amount and current transaction count;The every transaction count of transaction of IC card is incremented by 1.
11. IC card transaction system as claimed in claim 10, which is characterized in that the mobile intelligent terminal further includes a transaction Serial number generation unit is connected to the information acquisition unit, when the information acquisition unit receive it is described containing transaction time After the transaction data of number information, starting transaction journal generation unit generates a transaction journal number, and passes through wireless transmission unit The transaction journal number and the transaction data containing transaction count information are sent to the background management system.
12. IC card transaction system as claimed in claim 10, which is characterized in that the verification unit decryption and authorization request is close Text, the authorization requests data after being decrypted, by itself and the authorization requests data in the transaction data containing transaction count information It makes comparisons, if comparison result is identical, the authorization requests ciphertext is verified successfully, if comparison result is different, the backstage pipe Reason system reports an error to mobile intelligent terminal;
The verification unit decrypts credit card issuer application data, and the IC card remaining sum after being decrypted believes it with containing transaction count IC card remaining sum in the transaction data of breath is made comparisons, if comparison result is identical, the credit card issuer application data check success, If comparison result is difference, the background management system reports an error to mobile intelligent terminal.
13. IC card transaction system as claimed in claim 10, which is characterized in that the background management system further includes calculating list Member, the computing unit is according to the transaction amount calculation processing transaction request in the IC card remaining sum and the authorization requests data Rear IC card remaining sum simultaneously generates authorization response ciphertext and credit card issuer script.
14. IC card transaction system as claimed in claim 11, which is characterized in that when background management system processing transaction request time-out When or IC card respond the background management system processing result failure when, IC card transaction further include rushing positive process of exchange:
The mobile intelligent terminal establishes connection by NFC module and IC card;
The IC card transmission rushes positive transaction data to the mobile intelligent terminal;
The mobile intelligent terminal, which is at least sent, rushes positive transaction data and last transaction serial number to the background management system;
The background management system according to last transaction serial number search last transaction, and according to it is described rush positive transaction data with it is upper Secondary transaction data carries out rushing positive transaction verification;
After being verified, the positive transaction of background management system processing punching.
15. IC card transaction system as claimed in claim 14, which is characterized in that described to rush positive transaction data and include at least: IC Card number, IC card remaining sum, authorization requests ciphertext, credit card issuer application data, authorization requests data and current transaction count.
16. the IC card transaction system as described in claim 9 or 14, which is characterized in that pass through NFC in the mobile intelligent terminal It further include the process of the IC card Yu the mobile intelligent terminal validation-cross after module and the IC card establish connection.
CN201510303111.4A 2015-06-05 2015-06-05 A kind of IC card transaction method and system Active CN104933565B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510303111.4A CN104933565B (en) 2015-06-05 2015-06-05 A kind of IC card transaction method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510303111.4A CN104933565B (en) 2015-06-05 2015-06-05 A kind of IC card transaction method and system

Publications (2)

Publication Number Publication Date
CN104933565A CN104933565A (en) 2015-09-23
CN104933565B true CN104933565B (en) 2019-04-05

Family

ID=54120722

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510303111.4A Active CN104933565B (en) 2015-06-05 2015-06-05 A kind of IC card transaction method and system

Country Status (1)

Country Link
CN (1) CN104933565B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11989724B2 (en) 2018-10-02 2024-05-21 Capital One Services Llc Systems and methods for cryptographic authentication of contactless cards using risk factors

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105528699A (en) * 2015-12-24 2016-04-27 中国银行股份有限公司 Chip information verification method and device for financial chip card
CN105931038A (en) * 2016-03-23 2016-09-07 中国银联股份有限公司 Method and system for transferring between IC card electronic cash accounts
WO2017166067A1 (en) * 2016-03-29 2017-10-05 李昕光 Recharging system
CN106096955A (en) * 2016-06-17 2016-11-09 广东工业大学 A kind of many application IC-card transaction data dynamic transfer systems
CN106355404B (en) * 2016-08-26 2020-09-01 武汉天喻信息产业股份有限公司 Debit credit transaction system and method with security vulnerability protection mechanism
CN106355399A (en) * 2016-09-19 2017-01-25 安徽爱她有果电子商务有限公司 Agricultural product safes system based on transaction data security
CN110177001A (en) * 2019-05-21 2019-08-27 广东联合电子服务股份有限公司 A kind of NFC circle deposit method, system and storage medium based on soft certificate
US11392933B2 (en) * 2019-07-03 2022-07-19 Capital One Services, Llc Systems and methods for providing online and hybridcard interactions

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2182479A1 (en) * 2008-11-03 2010-05-05 Gemalto SA A method for communicating an authorization response cryptogram to an external entity, and a corresponding system
CN102640176A (en) * 2009-04-24 2012-08-15 洛格摩提公司 Method and system of electronic payment transaction, in particular by using contactless payment means
CN103310557A (en) * 2012-03-15 2013-09-18 中国移动通信集团公司 Over-the-air electronic cash loading method, system and device for NFC (near field communication) mobile phone
CN103440706A (en) * 2013-08-23 2013-12-11 捷德(中国)信息科技有限公司 Method and device for eliminating QPBOC abnormal transaction of financial IC card
CN104301288A (en) * 2013-07-16 2015-01-21 中钞信用卡产业发展有限公司 Method and system for online identity authentication, online transaction certification, and online certification protection

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2010131226A1 (en) * 2009-05-14 2010-11-18 Logomotion, S.R.O. Contactless payment device, method of contactless top-up of electronic money on a payment device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2182479A1 (en) * 2008-11-03 2010-05-05 Gemalto SA A method for communicating an authorization response cryptogram to an external entity, and a corresponding system
CN102640176A (en) * 2009-04-24 2012-08-15 洛格摩提公司 Method and system of electronic payment transaction, in particular by using contactless payment means
CN103310557A (en) * 2012-03-15 2013-09-18 中国移动通信集团公司 Over-the-air electronic cash loading method, system and device for NFC (near field communication) mobile phone
CN104301288A (en) * 2013-07-16 2015-01-21 中钞信用卡产业发展有限公司 Method and system for online identity authentication, online transaction certification, and online certification protection
CN103440706A (en) * 2013-08-23 2013-12-11 捷德(中国)信息科技有限公司 Method and device for eliminating QPBOC abnormal transaction of financial IC card

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
PBOC金融应用植入NFC手机的若干关键问题研究;卢海华;《中国优秀硕士学位论文全文数据库 信息科技辑》;20130315;第2013年卷(第03期);第I136-938页
智能IC卡系统中如何保证交易的一致性;华宁宁 等;《金卡工程》;20021231;第32-34页

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11989724B2 (en) 2018-10-02 2024-05-21 Capital One Services Llc Systems and methods for cryptographic authentication of contactless cards using risk factors

Also Published As

Publication number Publication date
CN104933565A (en) 2015-09-23

Similar Documents

Publication Publication Date Title
CN104933565B (en) A kind of IC card transaction method and system
US20200286088A1 (en) Method, device, and system for securing payment data for transmission over open communication networks
RU2648944C2 (en) Methods, devices, and systems for secure provisioning, transmission and authentication of payment data
US11361319B2 (en) Service processing method, apparatus, and system
CN104599408B (en) Third party's account ATM withdrawal method and system based on dynamic two-dimension code
US20110103586A1 (en) System, Method and Device To Authenticate Relationships By Electronic Means
CN108476227A (en) System and method for equipment push supply
CN106411950B (en) Authentication method, apparatus and system based on block chain transaction id
CN106997527A (en) Credit payment method and device based on mobile terminal P2P
CN101841417A (en) Electronic signature device supporting short-distance wireless communication technology and method for ensuring safety of electronic transaction by applying same
WO2008137535A1 (en) Method and system for controlling risk using static payment data and an intelligent payment device
JP2014513825A5 (en)
CN110447213A (en) Method and system for relay attack detection
CN107730243A (en) A kind of card user and POS interactive system and method
CN105897721A (en) Method and device for verifying reliability of identity of financial card user
US11682001B2 (en) Devices and methods for selective contactless communication
CN105741099A (en) Payment clearance method
CN103268436A (en) Method and system for touch-screen based graphical password authentication in mobile payment
KR20160146734A (en) Remote transaction system, method and point of sale terminal
CN103714624B (en) Electronic purse recharging method, system and supplement operation terminal with money
US20180165679A1 (en) Method and system for transaction authentication
US10846681B2 (en) System and method for providing payment service
CN114207578A (en) Mobile application integration
CN109313782A (en) Pre-approval financial transaction provides system and method
CN105608568A (en) Device integrating functions of finance card payment and settlement and finance card payment and settlement method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant