A kind of safety equipment with virtual Chip Operating System, device and system
Technical field
The present invention relates to a kind of safety equipment with virtual Chip Operating System, device and system.
Background technology
It is an important engineering of banks of China card industrial upgrading that financial IC card is applied, it is the leap of revolution, because financial IC card has surmounted the concept of traditional bank's magnetic stripe card fully, the functions such as traditional magnetic stripe card only possesses consumption, transfers accounts, access cash, financial IC card has not only been inherited these functions, and its security is higher than magnetic stripe card, can also carry out the small amount rapid payment, the more important thing is, financial IC card can also be realized the conglomerate application, the application of other industry can be incorporated on the card real realize " one card for multiple uses ".
IC-card is that the English of integrated circuit card is called for short, and also is referred to as smart card, chip card etc.It becomes profile and the similar card form of magnetic stripe card by the ic chip package with a special use, namely makes an IC-card.IC-card is to use chip as carrier, and chip has computing function, the similar small-size computer of its principle of work, and magnetic stripe card is to use magnetic stripe as carrier, is similar to previous floppy disk, it only has memory function, does not have computing function.As its name suggests, financial IC card is exactly the bank card with chip by issued by banks, and it must meet the PBOC2.0 standard that " China's finance integrated circuit (IC) calliper model " that People's Bank of China promulgates namely is commonly called as in the industry.Financial IC card has safe, convenient, multiplex characteristics.
Safe.Current widely used magnetic stripe card, because technology simply, easily be replicated, use the magnetic strip information device of copying illegally to copy bank card magnetic track information, steal holder's sensitive information, use a hidden recorder holder's password and forge magnetic stripe card, falsely use the case such as magnetic strip information and happen occasionally in the ATM terminal by pinhole camera by electronic channels such as Web banks in the society, all cause certain loss for holder, card sending mechanism, affected the whole reputation of banks of China industry.Financial IC card has higher security than magnetic stripe card.Its capacity is large, and (general capacity is 64KB; and the magnetic stripe card capacity only has about 300B); can storage key, the information such as digital certificate, fingerprint; read-write protection and protecting data encryption are arranged on the card; and using protection to take personal identification number, card and read write line two-way authentication, has higher security.The IC-card difficulty of reproduction is high, possesses very strong anti-attack ability, can effectively take precautions against the generation of pseudo-card crime case.For example, Malaysia, China Taiwan are after promoting financial IC card, and its pseudo-card rate of fraud has all dropped to the historical low level.
Quick payment.Financial IC card can provide offline transaction, contactless transaction, so payment efficient will improve greatly, this is that magnetic stripe card is incomparable.Especially its unique electronic cash function just is equivalent to set up in addition a stored value card in bank card.When small amount payment, offline transaction can be provided, need not the processes such as plug-in card is swiped the card, input password, signature, as long as on the POS machine gently " one claps ", just can finish the payment below 1000 yuan, simple fast.Data show according to statistics, in the current consumption of civic, except staple commodities such as buying house, purchase car are consumed, consumption is the small amount consumption below 1000 yuan more than 80%, along with constantly popularizing of financial IC card, to greatly reduce citizen's time that queuing is swiped the card when shopping, consumption, thereby make the civic life safer, faster, more convenient, more comfortable.Simultaneously, substitute money transaction by electronic cash, carry and handling cost reducing cash, the economic loss of avoiding the direct receipt and payment counterfeit money of client and businessman and bringing thus promotes economic sound development to wait and is significant.
Conglomerate is used.Financial IC card can be divided into 6 to 8 intervals because storage space is large, and each interval is relatively independent, and financial function occupies a space, and other spaces can be used as the application of other industry.For example, head office of the People's Bank and human resources Department of Social Security have worked out the implementation guideline that loads financial function at social security card jointly, are exactly an important case of financial IC card sector application.Financial IC card can be developed several functions as required, realizes " one card for multiple uses " that such as making access card, accumulating card, member card etc., this will greatly reduce the quantity of card in citizen's wallet, makes the wallet weight reducing.After financial IC card was extensively promoted, the holder can enjoy issued transaction and the one-stop service of paying the fees directly in the use of the fields such as social security, medical treatment, traffic, culture, leisure, can realize life and " all-purpose card is capable " that consume, the more convenient services of final acquisition.
Financial IC card is applied and is listed vital task of information-based " the 12 " development plan of China's Financial industry in.People's Bank of China is in " about advancing the suggestion of financial IC card application work ", applying of financial IC card proposed concrete timetable, requirement was from 1 day January in 2013, national commercial bank should get off the ground financial IC card, from 1 day January in 2015, the bank card of all new issues should be financial IC card.In addition, aspect disposal environment, before the end of the year 2011, all POS terminals can both be accepted financial IC card, and before the end of the year 2012, all ATM can both be accepted financial IC card.
A kind of " based on the intelligent finance IC-card reading/writing method of electronic identity card system " disclosed in the disclosed No. 201110429724.4 Chinese invention patent application instructionss on Dec 20th, 2011; this scheme is based on unified electronic identity card system; the various identity informations that utilize the user to submit to are set up different credit grades; one group of unique network identifier and digital certificate have been generated; compare authentication for the information of when reading in and writing out the information of IC-card, calling electronic identity card system (EID system); also carry out simultaneously the validation of information after authentication is passed through; both guaranteed the authenticity of personal identification; can effectively avoid again subscriber identity information to be carried over into exposure and the disclosure risk at diverse network operator place; the while password; the triple protection of authentication and authentification of message; greatly improve the safety of user account fund and information, but do not solved in the different scenes the dynamic adjustment problem to access rights.Simultaneously, because each financial institution is all issuing independently financial IC card, the Chip Operating System that the financial IC card of every financial institution uses has difference, cause a people Duo Ka, duplicate construction, the wasting of resources and interconnected difficult situation, the present invention designs IC-card to reach the purpose of resource sharing, reduction cost by virtual Chip Operating System technology, simultaneously this technology is combined with information infrastructure and construct new application system, it is extended to the security protection that the wisdom maturation is used payment, cloud service and wisdom logistics more.
Summary of the invention
One of purpose of the present invention provides a kind of safety equipment with virtual Chip Operating System, this equipment can be integrated into all kinds of IC-cards on the card, described IC-card storage key, digital certificate, biological characteristic recognition information, and take virtual Chip Operating System as platform, send instruction by bus and control each IC-card and extraneous message exchange, the method will help on each IC-card unification to a card, integrated and the data sharing of realization information and interconnecting, people just do not need to have carried many IC-cards like this.These safety equipment can combine with storage card, SIM card, earphone, portable terminal plug-in unit, portable terminal suspension member, IC-card I.D., Citizen Card Item, USB memory device, show as all kinds of innovative products.
Two of purpose of the present invention provides a kind of safety feature with virtual Chip Operating System, which comprises at least a housing, the master chip with virtual Chip Operating System, interface and a financial IC card; It is characterized in that described master chip connects described interface by described virtual Chip Operating System and controls described financial IC card and extraneous message exchange; Described interface comprises a kind of in memory card interface, NFC interface, audio interface, blue tooth interface, infrared interface, data line interface, contactless ic card interface, USB interface, serial ports, the parallel port at least.Because the Chip Operating System of financial IC card, interface vary, this safety feature comes adaptive each type of financial financial IC card by virtual Chip Operating System and many interfaces, finishes access and the control of each type of financial financial IC card.Financial IC card comprises security module and mass storage; Described security module is used for storage key, digital certificate, biological characteristic recognition information, and this function can be used for the safety certification of all kinds of services; Described mass storage is used for storing software, data, document, described financial IC card driver, and this function can be used for the value-added services such as software recommendation, advertisement; Have slot can insert described financial IC card on the described housing, ports having can be connected to external unit; Described financial IC card is inserted slot, port links to each other with external unit, and external unit can be used as a removable memory to financial IC card, thereby can read and write financial IC by described interface, if external unit is computing machine or portable terminal, then can make it have POS machine function.
Three of purpose of the present invention provides a kind of use with many application payment system of the safety equipment of virtual Chip Operating System, and it comprises client, server, front end processor, virtual Chip Operating System and safety equipment; It is characterized in that described safety equipment comprise more than one the integrated circuit card with Chip Operating System, storage key, digital certificate or biological characteristic recognition information; Described virtual Chip Operating System realize towards the multitask of safety equipment share, concurrency management and processing; Described virtual Chip Operating System is installed on client or the safety equipment, described client is by virtual Chip Operating System control safety equipment and extraneous message exchange, and the storer in the Administrative Security equipment is also finished the processing of order in safety equipment inside; Described client, server, front end processor, virtual Chip Operating System and safety equipment are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least; The Chip Operating System of general financial IC card is fairly simple, task is single, do not possess that multitask is shared, concurrency management and processing power, and for many application payment system, a plurality of concurrent payment tasks from the user might appear processing, the grade of service of each task is different with security strategy, in order to raise the efficiency, improve user's experience, virtual Chip Operating System can reside in a plurality of payment tasks of process user and comprehensive payment demand in the client, brings unprecedented payment new experience to the user.Simultaneously, in the Ubiquitous Network environment, system can dynamically adjust security strategy with reply according to the grade of service after trusted environment changes or be under attack, strengthened reliability and the anti-attack ability of system.
Four of purpose of the present invention be a kind of use with the cloud service system of virtual Chip Operating System safety equipment, it comprises cloud terminal, cloud computing center, virtual Chip Operating System and safety equipment; It is characterized in that described safety equipment comprise more than one the integrated circuit card with Chip Operating System, storage key, digital certificate or biological characteristic recognition information; Described virtual Chip Operating System realize towards the multitask of safety equipment share, concurrency management and processing; Described virtual Chip Operating System is installed on cloud terminal or the safety equipment, described cloud terminal is by virtual Chip Operating System control safety equipment and extraneous message exchange, and the storer in the Administrative Security equipment is also finished the processing of order in safety equipment inside; Described cloud terminal, cloud computing center, virtual Chip Operating System and safety equipment are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least.
Five of purpose of the present invention provides a kind of use with the wisdom logistics system of virtual Chip Operating System safety equipment, and it comprises portable terminal, wisdom logistics center, virtual Chip Operating System, safety equipment and safety feature; It is characterized in that described safety equipment comprise more than one the integrated circuit card with Chip Operating System, storage key, digital certificate or biological characteristic recognition information; Described virtual Chip Operating System realize towards the multitask of safety equipment share, concurrency management and processing; Described safety feature is a kind of electromechanical lock, and described safety equipment are by the described safety feature communication of interface; Described virtual Chip Operating System is installed on portable terminal, safety feature or the safety equipment, described portable terminal, safety feature be by the message exchange of virtual Chip Operating System control safety equipment and wisdom logistics center, and the storer in the Administrative Security equipment is also finished the processing of order in safety equipment inside; The mutual important information of described portable terminal and described wisdom logistics center is protected by described safety equipment; Described portable terminal, wisdom logistics center, virtual Chip Operating System and safety equipment are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least.
Description of drawings
Fig. 1 is the safety equipment structure principle chart of embodiments of the invention one;
Fig. 2 is the safety apparatus structure schematic diagram of embodiments of the invention two;
Fig. 3 is that the use of embodiments of the invention three is with many application payment system schematic diagram of the safety equipment of virtual Chip Operating System;
Fig. 4 is that the use of embodiments of the invention four is with the cloud service system schematic diagram of virtual Chip Operating System safety equipment;
Fig. 5 is that the use of embodiments of the invention five is with the wisdom logistics system schematic diagram of virtual Chip Operating System safety equipment;
Embodiment
Embodiment one: a kind of safety equipment with virtual Chip Operating System, as shown in Figure 1, it comprises a SIM card body 4, master chip 2 and two IC-cards 1 with virtual Chip Operating System 3, IC-card 1 storage key, digital certificate or biological characteristic recognition information are such as fingerprint, iris, face characteristic information etc.; Master chip 2 is connected by spi bus 6 with IC-card 1; It is characterized in that described master chip 2 is by the described virtual described IC-card 1 of Chip Operating System 3 controls and extraneous message exchange, send the processing that instruction is managed the storer in the described IC-card and finished instruction in described IC-card inside, described safety equipment combine with SIM card; Described instruction meets the IS07816 standard; Described IC-card 1 is for meeting the financial IC card module of EMV standard, PBOC2.0 standard.
Embodiment two: a kind of safety feature with virtual Chip Operating System as shown in Figure 2, which comprises at least a housing 4, the master chip 2 with virtual Chip Operating System 3, contact and noncontact double-interface IC card interface 5 and a financial IC card 6; It is characterized in that master chip 2 connects the message exchange of double-interface IC card interface 5 control financial IC cards 6 and external unit 1 by virtual Chip Operating System 3; Financial IC card 6 comprises security module and mass storage; Security module is used for storage key, digital certificate, biological characteristic recognition information, and mass storage is used for the driver of storing software, data, document, financial IC card 6; Have double-interface IC card slot 5 can insert financial IC card 6 on the housing 4, ports having can be connected to external unit 1; Financial IC card 6 is inserted slot 5, and port links to each other with external unit 1, and external unit 1 can be used as a removable memory to financial IC card 6, thereby can read and write financial IC6 by the contactless ic card interface.
Embodiment three: a kind of use is with many application payment system of the safety equipment of virtual Chip Operating System, and as shown in Figure 3, it comprises client 1, server 2, front end processor 3, virtual Chip Operating System 4 and safety equipment 5; It is characterized in that described safety equipment 5 comprise more than one that with the integrated circuit card of Chip Operating System, storage key, digital certificate or biological characteristic recognition information are such as fingerprint, iris, face characteristic information etc.; Described virtual Chip Operating System realize towards the multitask of safety equipment 5 share, concurrency management and processing, occur as many payment tasks are arranged simultaneously, to the scheduling of payment task etc.; Described virtual Chip Operating System 4 is installed in client 1, the driver of safety equipment 5 can be installed on the virtual Chip Operating System 4; Described virtual Chip Operating System 4 is installed in safety equipment 5, need to encapsulate by the Chip Operating System of an above IC-card in 4 pairs of safety equipment 5 of virtual Chip Operating System; By 4 control safety equipment 5 and the extraneous message exchanges of virtual Chip Operating System, the storer in the Administrative Security equipment 5 is also finished the processing of order in safety equipment 5 inside; Described client 1, server 2, front end processor 3, virtual Chip Operating System 4 and safety equipment 5 are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least.
Embodiment four: a kind of use is with the cloud service system of virtual Chip Operating System safety equipment, and as shown in Figure 4, it comprises cloud terminal 1, cloud computing center 2, virtual Chip Operating System 3 and safety equipment 4; It is characterized in that described safety equipment 5 comprise more than one that with the integrated circuit card of Chip Operating System, storage key, digital certificate or biological characteristic recognition information are such as fingerprint, iris, face characteristic information etc.; Described virtual Chip Operating System 4 realize towards the multitask of safety equipment 5 share, concurrency management and processing, occur as multinomial cloud service task is arranged simultaneously, to the scheduling of task and concurrent processing etc.; Described virtual Chip Operating System 4 is installed on cloud terminal 1 or the safety equipment 5, described cloud terminal 1 is by 4 control safety equipment 5 and the extraneous message exchanges of virtual Chip Operating System, and the storer in the Administrative Security equipment 5 is also finished the processing of order in safety equipment 5 inside; Described cloud terminal 1, cloud computing center 2, virtual Chip Operating System 3 and safety equipment 4 are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least.
Embodiment five: a kind of use is with the wisdom logistics system of virtual Chip Operating System safety equipment, and as shown in Figure 5, it comprises portable terminal 1, wisdom logistics center 2, virtual Chip Operating System 3, safety equipment 4 and safety feature 5; It is characterized in that described safety equipment 4 comprise more than one that with the integrated circuit card of Chip Operating System, storage key, digital certificate or biological characteristic recognition information are such as fingerprint, iris, face characteristic information etc.; Described virtual Chip Operating System 3 realize towards the multitask of safety equipment 4 share, concurrency management and processing; Described safety feature 5 is a kind of electromechanical locks, and described safety equipment 5 are by described safety feature 5 communications of interface; Described virtual Chip Operating System 3 is installed on portable terminal 1, safety feature 5 or the safety equipment 4, described portable terminal 1, safety feature 5 be by the message exchange of virtual Chip Operating System 3 control safety equipment 4 and wisdom logistics center 2, and the storer in the Administrative Security equipment 5 is also finished the processing of order in safety equipment 5 inside; Described portable terminal 1 and described wisdom logistics center 2 mutual important informations are protected by described safety equipment 4; Described portable terminal 1, wisdom logistics center 2, virtual Chip Operating System 3 and safety equipment 4 are dynamically adjusted security strategy according to the grade of service, the described grade of service comprises service level and priority at least, and described security strategy comprises the security strategy based on identity, rule, role at least.
Those skilled in the art can also carry out various modifications to above content under the condition that does not break away from the definite the spirit and scope of the present invention of claims.Therefore scope of the present invention is not limited in above explanation, but determined by the scope of claims.The modification of various kinds.Therefore scope of the present invention is not limited in above explanation, but determined by the scope of claims.