WO2011066704A1 - 一种公交一卡通业务系统及其实现方法 - Google Patents

一种公交一卡通业务系统及其实现方法 Download PDF

Info

Publication number
WO2011066704A1
WO2011066704A1 PCT/CN2010/000245 CN2010000245W WO2011066704A1 WO 2011066704 A1 WO2011066704 A1 WO 2011066704A1 CN 2010000245 W CN2010000245 W CN 2010000245W WO 2011066704 A1 WO2011066704 A1 WO 2011066704A1
Authority
WO
WIPO (PCT)
Prior art keywords
service platform
card
service
pos machine
bus card
Prior art date
Application number
PCT/CN2010/000245
Other languages
English (en)
French (fr)
Inventor
孙伟
何宗盛
Original Assignee
Sun Wei
Ho Chung Shing Tommy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sun Wei, Ho Chung Shing Tommy filed Critical Sun Wei
Publication of WO2011066704A1 publication Critical patent/WO2011066704A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/349Rechargeable cards
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models
    • G06Q20/28Pre-payment schemes, e.g. "pay before"
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/409Device specific authentication in transaction processing

Definitions

  • the invention relates to network communication technology, in particular to a bus card business system and an implementation method thereof.
  • the bus card business is gradually being widely used.
  • 1 is a system structural diagram of a bus card business in the prior art.
  • the bus card business system mainly includes: bus card, POS (Point of Sales, point of sale) machine and card server.
  • the bus card is a non-contact RF card;
  • the card server is located in the card company, maintaining and managing the identity and balance information of the bus card in the city or the region, and managing the POS.
  • bus card cards are mainly to buy tickets at public transport. For example, if a POS machine with a swipe card is installed on the bus, when you need to buy a ticket, you only need to bring the bus card to the POS machine. The POS machine will read the information on the bus card and deduct the corresponding card from the bus card. Tickets, and the corresponding information is saved by the POS machine, and finally the information is sent directly to the card server.
  • the bus card When it is necessary to recharge the bus card, the bus card needs to be close to the rechargeable POS machine.
  • the POS device reads the information in the card. After the operator collects the recharged cash, the POS machine manually changes the balance in the bus card. Information, the POS machine sends the interaction results directly to the card server.
  • the bus card can only be used to buy tickets at public transportation, so that although a large number of users carry a bus card in their daily life, Users can't use the bus card to make other credit card consumption at any time, which greatly limits the application of the bus card business.
  • the user when recharging the bus card, the user cannot complete the refill operation at any time, but must go to the specified number of recharge outlets. After the recharge cash is delivered, the POS machine at the refill outlet can be used to modify the card information. Complete the card recharge. It can be seen that with the system shown in FIG. 1, the user must go to the designated recharge outlets and must deliver cash recharge, which brings great inconvenience to the user's use, reduces the satisfaction of the business, and limits the development of the business.
  • the main purpose of the present invention is to provide a bus card business system and an implementation method thereof, and to expand the application of the bus card business, which brings convenience to the user.
  • a bus card business system includes: a bus card, a POS machine, a PC, a service platform, a third party system, and a card server.
  • the POS machine is used for authenticating the bus card, and after the authentication is passed, the identity card information of the bus card is sent to the PC, and corresponding reading and writing operations are performed on the bus card according to the business instruction sent by the PC;
  • the PC is configured to send a service request carrying the identity information of the bus card to the service platform, and send the service instruction sent by the service platform to the POS machine;
  • the service platform is used to interact with the third-party system. After the interaction is successful, the key request request for carrying the identity information of the bus card is sent to the card server according to the service request sent by the PC, and the service command sent by the card server is sent to the PC. machine;
  • the one-card server authenticates the bus card according to the identification information of the bus card in the key application request, and after the authentication is passed, returns a service instruction to the service platform according to the key request.
  • the card server further encrypts the service instruction by using the saved key before returning the service instruction to the service platform;
  • the POS machine includes: an antenna, a read/write module, a security chip module, and a processing module;
  • the reading and writing module is configured to read the identity information of the bus card, and forward it to the security chip module through the processing module;
  • the security chip module authenticates the bus card according to the identity information of the bus card, and after the authentication is passed, the bus card identity information is sent to the PC through the processing module, and the key is saved in the inaccessible key area, and the key is used.
  • the key decrypts the business instruction sent by the processing module, and returns the decrypted data to the processing module;
  • the processing module forwards the service instruction sent by the PC to the security chip module, and controls the read/write module to perform corresponding reading and writing operations on the bus card according to the decrypted service instruction returned by the security chip module.
  • the third-party system is an online banking or third-party payment system, which is configured to deduct the corresponding recharge amount from the corresponding account according to the received debit request, and return the deduction success message to the service platform;
  • the PC is configured to link to the recharge service page of the service platform, download the pre-bound OCX control of the page, generate a recharge request as the service request, and send the request according to the recharge amount and account information input by the user.
  • the service platform sends the recharge command sent by the card server through the service platform as a service instruction to the POS machine by using the OCX control;
  • the service platform After receiving the refill request, the service platform sends the debit request to the online banking or third-party payment system, and after receiving the deduction success message, performs a recharge key application for transmitting the identity card of the bus card to the card server. request;
  • the POS machine modifies the balance information in the bus card according to the recharge command sent by the PC. After the modification is successful, the current balance information of the bus card is encrypted by using the saved key, and is sent through the PC and the service platform. Give a card server;
  • the card server further decrypts the balance information of the received bus card by using the saved key, and updates the balance information of the bus card stored by itself according to the decrypted information.
  • the third-party system is a merchant system, configured to detect the goods selected by the user through the PC and the information paid by using the bus card, and generate corresponding product orders to be sent to the service platform;
  • the service platform is further configured to: after successfully receiving the commodity order, open the consumer service page, and after receiving the payment request sent by the PC, execute a payment key application request for transmitting the identity information of the bus card to the card server;
  • the PC is configured to link to a consumer service page of the service platform, download a pre-bound OCX control of the consumer service page, and send the payment request as the service request to the service platform, according to an instruction of the OCX control. Send the debit order issued by the service platform as a business instruction to the POS machine;
  • the POS machine modifies the balance information in the bus card according to the debit order sent by the PC. After the modification is successful, the current balance information of the bus card is encrypted by using the saved key, and the PC and the service platform are encrypted. Sent to the card server;
  • the card server further decrypts the balance information of the received bus card by using the saved key, and updates the balance information of the bus card stored by itself according to the decrypted information.
  • the POS machine further encrypts its identity information by using a pre-stored key and sends it to the PC when the PC is connected to the service platform, and decrypts the identity information of the received service platform by using the pre-stored key. And authenticating the service platform according to the decrypted information, and after the two-way authentication of the POS machine and the service platform is successful, performing the sending of the card identity information of the bus card to the PC;
  • the PC further sends the identity information of the received POS machine to the service platform, and sends the identity information of the received service platform to the POS machine;
  • the service platform further decrypts the identity information of the received POS machine by using a pre-stored key, authenticates the POS machine according to the decrypted information, and encrypts the identity information of the POS machine by using the pre-stored key and sends the identity information to the PC.
  • the process of transmitting the key application request to the card server is performed.
  • the POS machine sends the CA certificate saved by itself to the card server through the PC and the service platform;
  • the card server first performs authentication on the POS machine according to the CA certificate information obtained from the certification center and the CA certificate information of the POS machine sent by the service platform. After the authentication succeeds, the process of authenticating the bus card is performed. .
  • the service platform and the third-party system exchange information through the Internet or a private network DDN.
  • a service implementation method for the system of the present invention comprising:
  • the PIN card After the POS machine passes the certification of the bus card, the PIN card sends the identity information of the bus card to the PC, and the PC sends a service request carrying the identity information of the bus card to the service platform;
  • the service platform interacts with the third-party system. After the interaction is successful, the key application request for carrying the identity information of the bus card is sent to the card server according to the service request sent by the PC;
  • the card server authenticates the bus card according to the identification information of the bus card in the key application request, and after the authentication is passed, returns a service instruction to the service platform according to the key request;
  • the service platform sends the service instruction to the POS machine through the PC;
  • the POS machine performs corresponding reading and writing operations on the bus card according to the business instructions sent by the PC.
  • step A after the POS machine authenticates the bus card, and before transmitting the bus card identity information to the PC, the method further includes: the POS device uses the pre-stored key to perform the identity information of the bus card. encryption;
  • the card server further includes: the card server decrypts the bus card identity information in the key application request by using the pre-stored key;
  • step C before returning the service instruction to the service platform according to the key request, the method further includes: the card server encrypting the service instruction by using the pre-saved key;
  • the step E further includes: after receiving the service instruction sent by the PC, the POS machine first decrypts the service instruction according to the pre-saved key.
  • the third party system is an online banking or third party payment system
  • the method further includes: the PC is linked to the recharge service page of the service platform, downloading the pre-bound OCX control of the page, activating the POS machine, and receiving the recharge amount and account information input by the user;
  • the service request is a recharge request for carrying the identity card information, the recharge amount and the account information of the bus card;
  • step B the step of the service platform interacting with the third-party system includes: the service platform sends the debit request to the online banking or the third-party payment system according to the account information in the recharge request, and the online banking or third-party payment system is based on the recharge amount. Deduct the corresponding money in the corresponding account and return the successful payment message to the business platform;
  • the service instruction is a refill command
  • the step E includes: the POS machine modifies the balance information in the bus card according to the refill command.
  • the third party system is a merchant system
  • the method further includes: the merchant system receives the commodity information that the user selects to purchase through the PC, and selects to use the bus card payment information, and the PC links to the consumer service page of the service platform, and downloads the pre-bound page of the page.
  • OCX control activate the POS machine;
  • the step of the service platform interacting with the third-party system includes: the merchant system generates a corresponding product order and sends the product order to the service platform, where the commodity order includes the amount of the payment amount information;
  • the key application request is a payment key application request carrying the bus card identity information and the payment amount information;
  • the business instruction is a deduction order
  • the step E includes: the POS machine modifies the balance information in the bus card according to the debit order.
  • step A the two-way authentication between the POS machine and the service platform is further included, and the authentication process includes any one of the following methods:
  • the POS machine sends an authentication command to the service platform through the PC; after receiving the authentication command, the service platform generates a random number RB, which is sent to the POS machine through the PC; the POS machine generates the random number RA, and uses the personalized key K1 of the service platform.
  • Step A is performed.
  • the service platform stores the root public key Ru, the private key Tv of the service platform, and the certificate CER_T issued by the root private key;
  • the POS machine stores the root public key Ru, the private key Rv of the POS machine, and the certificate CER_R issued by the root private key;
  • the PC sends an authentication request command to the service platform;
  • the service platform generates a random number RB, which is sent to the POS machine through the PC;
  • the POS machine generates the random number RA, and signs the RA
  • the service platform signs the RA
  • the present invention has at least the following advantages:
  • a PC, a service platform, and a third-party system are added to the bus card service system of the prior art, and the POS machine no longer directly communicates with the card server, but logs into the service platform through the PC, thereby The communication with the third-party system and the card server is completed.
  • the user can trigger the information exchange between the service platform and the third-party system through the PC, thereby obtaining more business applications from the third-party system, and expanding the bus card business.
  • Application bringing convenience to users.
  • the bus card can be recharged, and the recharge method of the present invention only needs the user to put the bus card into the POS machine, the POS machine is connected to the PC, and the corresponding recharge amount is input on the PC.
  • the account information can be paid, and the invention can automatically deduct the corresponding recharge amount from the account for the bus card to recharge. It can be seen that the recharging method of the invention does not require the user to go to the designated recharge outlet, and does not require the user to carry cash to recharge, thereby enabling the user to recharge the bus card in any non-cash manner anytime and anywhere, which brings great convenience to the user.
  • the user only needs to put the bus card into the POS machine, and the POS machine is connected to the PC.
  • the bus card can be used.
  • the payment of online shopping has greatly expanded the application of the bus card business, bringing great convenience to the user's use.
  • the card server and the POS machine can be completed, the security of the information transmission is ensured, and the POS machine can also perform the service platform for the service.
  • the one-card server can also authenticate the service platform, and the authentication method is flexible and diverse.
  • the symmetric authentication algorithm can be used to encrypt the authentication or the asymmetric algorithm can be used to encrypt the authentication, thereby further ensuring the security of the bus card service of the present invention. , improved system performance.
  • FIG. 1 is a system structural diagram of a bus card business in the prior art
  • FIG. 2 is a basic structural diagram of a system of a bus card service in the present invention.
  • FIG. 3 is a first specific implementation structure diagram of a bus card business system in the present invention.
  • FIG. 4 is a flow chart of Embodiment 1 of the present invention.
  • FIG. 5 is a second specific implementation structure diagram of a bus card business system in the present invention.
  • Figure 6 is a flow chart of Embodiment 2 of the present invention.
  • the invention provides a bus card business system.
  • 2 is a basic structural diagram of a bus card business system in the present invention.
  • the basic structure of the system of the present invention includes: a bus card, a POS machine, a PC, a service platform, a third party system, and a card server.
  • the POS machine is used for authenticating the bus card, and after the authentication is passed, the identity card information of the bus card is sent to the PC, and corresponding reading and writing operations are performed on the bus card according to the business instruction sent by the PC;
  • the PC is configured to send a service request carrying the identity information of the bus card to the service platform, and send the service instruction sent by the service platform to the POS machine;
  • the service platform is used to interact with the third-party system. After the interaction is successful, the key request request for carrying the identity information of the bus card is sent to the card server according to the service request sent by the PC, and the service command sent by the card server is sent to the PC. machine;
  • the one-card server authenticates the bus card according to the identity information of the bus card in the key application request, and after the authentication is passed, returns a service instruction to the service platform according to the key application request.
  • the present invention also proposes a service implementation method using the bus card business system.
  • the core idea of the method is: after the POS machine passes the certification of the bus card, the POS card sends the identity information of the bus card to the PC, PC.
  • the machine sends a service request carrying the identity information of the bus card to the service platform; the service platform interacts with the third-party system, and after the interaction is successful, the key application request for carrying the identity information of the bus card is sent to the card server according to the service request sent by the PC.
  • the card server authenticates the bus card according to the identity information of the bus card in the key application request, and after the authentication is passed, returns a service instruction to the service platform according to the key application request; the service platform sends the service instruction to the POS through the PC.
  • the POS machine performs corresponding reading and writing operations on the bus card according to the business instructions sent by the PC.
  • a PC, a service platform, and a third-party system are added to the bus card service system of the prior art, and the POS machine no longer directly communicates with the card server, but logs into the service platform through the PC, thereby The communication with the third-party system and the card server is completed.
  • the user can trigger the information exchange between the service platform and the third-party system through the PC, thereby obtaining more business applications from the third-party system, and expanding the bus card business.
  • Application bringing convenience to users.
  • the bus card business system shown in FIG. 2 can be used to implement various business applications, for example, non-cash recharging of the bus card at any time; using the bus card to conduct online shopping; using the bus card Supermarket credit card spending and so on.
  • This embodiment details the specific implementation process of the non-cash recharge of the bus card at any time.
  • FIG. 3 is a first specific structural diagram of a bus card service system in the present invention
  • FIG. 4 is a flowchart of Embodiment 1 of the present invention.
  • the third-party system in the system of the present invention is an online banking or a third-party payment system (such as Alipay, etc.), and the implementation process specifically includes The following steps:
  • Step 401 Bind the client installation software (OCX) control to each service page of the service platform in advance.
  • OCX client installation software
  • the OCX control is software for performing information interaction with the POS to instruct the POS machine to complete the business operation.
  • the POS machine is directly connected to the PC. Therefore, in order to enable the service platform to control the operation of the POS machine, the OCX control is bound to the service page of the service platform.
  • the PC can obtain the page-bound OCX control to interact with the POS machine to instruct the POS machine to complete the business operation.
  • Step 402 The bus card user puts the bus card into the POS machine and connects the POS machine to the PC, and logs into the recharge service page of the service platform through the PC to select the recharge function.
  • the POS machine can be connected to the PC through the USB interface.
  • Step 403 The PC downloads the OCX control bound to the recharge service page from the service platform, and the OCX control in the PC activates the POS machine and detects the POS machine.
  • Step 404 The POS machine performs card search processing, reads the identity information of the bus card, and authenticates the bus card according to the read identity information. After the authentication is passed, the bus card identity information is sent to the PC.
  • Step 405 The PC receives the recharge amount and account information input by the user, and sends a recharge request carrying the bus card identity information, the recharge amount, and the account information to the service platform.
  • Step 406 The service platform sends the debit request to the corresponding online banking or third-party payment system according to the account information in the refill request.
  • Step 407 The corresponding online banking or third-party payment system deducts the corresponding recharge amount from the corresponding account according to the received debit request, and returns the deduction success message to the service platform.
  • Step 408 After receiving the deduction success message, the service platform first initiates the CA authentication of the POS machine at the card server, and after the authentication is passed, sends a refill key application request carrying the bus card card identity information and the refill amount information to the card server.
  • Step 409 The card server authenticates the card according to the identity card information of the bus card. After the authentication is passed, a recharge command is generated, and the recharge command is encrypted by using the pre-stored key, and then sent to the service platform.
  • Step 410 The service platform sends the refill command to the PC, and the OCX control in the PC sends the recharge command to the POS machine.
  • Step 411 The POS machine recharges the bus card according to the recharge command, that is, modifies the balance information in the bus card.
  • the POS machine is used to conveniently recharge the bus card at any time, and the online banking or third-party payment system is used for recharging, without the user having to use the cash to recharge the designated recharge outlet.
  • the present invention may further include the following steps 412-413.
  • Step 412 The POS machine encrypts the current balance information of the bus card by using the pre-stored key, and sends the card to the card server through the PC and the service platform.
  • Step 413 The card server further decrypts the balance information of the received bus card by using the saved key, and updates the balance information of the bus card stored by itself according to the decrypted information.
  • This embodiment details the specific implementation process of using the bus card to conduct online shopping.
  • FIG. 5 is a second specific implementation structure diagram of a bus card service system in the present invention
  • FIG. 6 is a flowchart of Embodiment 2 of the present invention.
  • the third-party system in the system of the present invention is a merchant system that is contracted with the service platform.
  • the implementation process specifically includes the following steps:
  • Step 601 Bind the client installation software (OCX) control to each service page of the service platform in advance.
  • OCX client installation software
  • the OCX control is software for performing information interaction with the POS to instruct the POS machine to complete the business operation.
  • the POS machine is directly connected to the PC. Therefore, in order to enable the service platform to control the operation of the POS machine, the OCX control is bound to the service page of the service platform.
  • the PC can obtain the page-bound OCX control to interact with the POS machine to instruct the POS machine to complete the business operation.
  • Step 602 The bus card user logs in to the merchant system through the PC, selects the item to be purchased, and selects to use the bus card to pay.
  • Step 603 The merchant system generates a corresponding product order and sends it to the service platform according to the user's selection.
  • the item order includes the amount of the item to be purchased, that is, the payment amount information.
  • Step 604 After receiving the commodity order, the service platform opens the consumer service page.
  • Step 605 The user puts the bus card into the POS machine and connects the POS machine to the PC, and logs in to the consumer service page of the service platform through the PC.
  • the POS machine can be connected to the PC through the USB interface.
  • Step 606 The PC downloads an OCX control bound to the consumer service page from the service platform, and the OCX control in the PC activates the POS machine and detects the POS machine.
  • Step 607 The POS machine performs card search processing, reads the identity information of the bus card, and authenticates the bus card according to the read identity information. After the authentication is passed, the bus card identity information is sent to the PC.
  • Step 608 The PC sends a payment request for carrying the identity information of the bus card to the service platform.
  • Step 609 After receiving the payment request, the service platform first initiates the CA authentication of the POS machine at the card server, and after the authentication is passed, sends a payment key application request carrying the bus card card identity information and the payment amount information to the card server.
  • Step 610 The card server authenticates the bus card according to the identity card information of the bus card. After the authentication is passed, the debit order is encrypted by using the pre-stored key, and then sent to the service platform.
  • Step 611 The service platform sends the deduction command to the PC, and the OCX control in the PC sends the deduction command to the POS machine.
  • Step 612 The POS machine deducts the corresponding amount from the bus card card according to the deduction order, that is, modifies the balance information in the bus card.
  • the present invention may further include the following steps 613-614.
  • Step 613 The POS machine encrypts the current balance information of the bus card by using the pre-stored key, and sends the card to the card server through the PC and the service platform.
  • Step 614 The card server further decrypts the balance information of the received bus card by using the saved key, and updates the balance information of the bus card stored by itself according to the decrypted information.
  • the card server can perform CA authentication on the POS machine, thereby ensuring the POS machine. legality.
  • the present invention needs to perform the following processing: submit a POS registration request to the authentication center (CA), the CA establishes registration information of the POS, and returns the registration result including the reference number and the authorization code to the POS machine. Finally, the CA certificate is distributed to the POS machine.
  • the CA certificate is distributed in various ways.
  • one is out-of-band distribution, that is, offline, and the CA certificate assigned to the POS machine is stored in the storage medium, and the POS machine is from the storage.
  • the corresponding CA certificate is obtained in the medium; the other is in-band distribution, the POS machine is connected to the CA, and the reference number and authorization code are provided to the CA.
  • the CA verifies that the reference number and the authorization code are correct, the CA certificate is sent to the POS machine.
  • the POS machine obtains the CA certificate; in addition, the CA certificate needs to be saved in the card server.
  • the process of step 408 and step 609 can be used to perform CA authentication on the POS machine by the card server to ensure the POS machine. Legitimacy.
  • the benefits of the service platform and the POS machine can not be imitated.
  • the service platform and the POS machine can also be added. The two-way authentication process, before the POS machine is connected to the service platform to prepare for the recharge and online shopping of the bus card, the authentication between the platform and the POS must be performed first.
  • the key of the service platform is placed in the encryption machine, and the POS machine is The key is placed in the master MCU; the POS machine encrypts the authentication information with the key and sends it to the service platform to authenticate the identity, and the service platform decrypts the identity with the key; and vice versa, the service platform sends the key authentication information to the POS machine for authentication.
  • Identity the POS machine uses the key to decrypt the authentication identity. After the two parties have authenticated, they will perform recharge or online shopping operations. If one party fails to pass the certification, other operations are prohibited.
  • the specific two-way authentication method can include the following two methods:
  • RB the random number length may be the packet length of the cipher algorithm
  • RA the random number length can be half of the packet length of the
  • Method 2 When the service platform is initialized or issued, the root public key Ru, the private key Tv of the service platform itself, and the certificate CER_T issued by the root private key are stored.
  • the POS machine stores the root public key Ru, the POS machine's own private key Rv, and the certificate CER_R issued with the root private key.
  • the POS machine sends an authentication request command to the service platform through the PC; the service platform generates a random number RB, which is sent to the POS machine through the PC; the POS machine generates the random number RA, and uses its own private key Rv to perform RA
  • the public key of the POS machine verifies the digital signature SgnData1. If the verification succeeds, the identity authentication of the POS machine is completed, and the next operation is performed, otherwise the identity authentication of the POS machine fails, and the authentication process is suspended;
  • the service platform signs the RA
  • the two-way authentication process between the service platform and the POS device may be performed in step 402 for the process shown in FIG. 4, that is, when the POS machine logs in to the recharge service page of the service platform through the PC, the above two-way execution is performed. After the authentication process is successful, the subsequent steps are performed.
  • the process may be performed in step 605. That is, when the POS machine logs in to the consumer service page of the service platform through the PC, the above-mentioned two-way authentication process is executed. After the authentication succeeds, the subsequent steps are performed.
  • bus card service system of the present invention includes at least any one or more of the following specific system implementation modes:
  • the transmitted information may be encrypted.
  • the specific system implementation manner includes:
  • the card server further encrypts the service instruction by using the saved key before returning the service instruction to the service platform; at this time, the POS machine internally includes: an antenna, a read/write module, a security chip module, and a processing module; among them,
  • the reading and writing module is configured to read the identity information of the bus card, and forward it to the security chip module through the processing module;
  • the security chip module authenticates the bus card according to the identity information of the bus card, and after the authentication is passed, the bus card identity information is sent to the PC through the processing module, and the key is saved in the inaccessible key area, and the key is used.
  • the key decrypts the business instruction sent by the processing module, and returns the decrypted data to the processing module;
  • the processing module forwards the service instruction sent by the PC to the security chip module, and controls the read/write module to perform corresponding reading and writing operations on the bus card according to the service instruction returned by the security chip module.
  • the system of the present invention can be used to conveniently recharge the bus card card at any time without the user having to use the cash to recharge the designated refill outlet.
  • the third party in the system of the present invention The system is an online banking or third-party payment system.
  • the specific system implementation methods include:
  • the online banking or third-party payment system in particular, according to the received debit request, deducting the corresponding recharge amount from the corresponding account, and returning the deduction success message to the service platform;
  • the PC is specifically configured to link to the recharge service page of the service platform, download an OCX control from the page, generate a recharge request as the service request according to the recharge amount and account information input by the user, and send the request to the service platform.
  • the OCX control uses the OCX control to send the recharge command sent by the card server through the service platform as a service instruction to the POS machine;
  • the service platform After receiving the refill request, the service platform sends the debit request to the online banking or third-party payment system, and after receiving the deduction success message, performs a recharge key application for transmitting the identity card of the bus card to the card server. request;
  • the POS machine modifies the balance information in the bus card according to the recharge command sent by the PC. After the modification is successful, the current balance information of the bus card is encrypted by using the saved key, and is sent through the PC and the service platform. Give a card server;
  • the card server further decrypts the balance information of the received bus card by using the saved key, and modifies the balance information of the bus card stored by itself according to the decrypted information.
  • the bus card card can be used for online shopping.
  • the third-party system in the system of the present invention is a merchant system, and the specific system implementation manners include:
  • the merchant system After detecting the goods selected by the user through the PC and the information paid by the bus card, the merchant system generates a corresponding product order and sends it to the service platform;
  • the service platform is further configured to: after receiving the commodity order, open the consumer service page, and after receiving the payment request sent by the PC, perform a payment key application request for transmitting the identity information of the bus card to the card server;
  • the PC is used to link to the consumer service page of the service platform, download the OCX control from the consumer service page of the service platform, and send the payment request as the service request to the service platform, and according to the instruction of the OCX control, the service
  • the debit order sent by the platform as a business instruction is sent to the POS machine;
  • the POS machine modifies the balance information in the bus card according to the debit order sent by the PC. After the modification is successful, the current balance information of the bus card is encrypted by using the saved key, and the PC and the service platform are encrypted. Sent to the card server;
  • the card server further decrypts the balance information of the received bus card by using the saved key, and modifies the balance information of the bus card stored by itself according to the decrypted information.
  • the encryption design is added to the POS machine and the service platform of the system of the present invention, and the service platform and the POS machine can perform mutual authentication.
  • the specific system implementation includes :
  • the POS machine further encrypts its identity information by using a pre-stored key and sends it to the PC when the PC is connected to the service platform, and decrypts the identity information of the received service platform by using the pre-stored key. And authenticating the service platform according to the decrypted information, and after the two-way authentication of the POS machine and the service platform is successful, performing the sending of the card identity information of the bus card to the PC;
  • the PC further sends the identity information of the received POS machine to the service platform, and sends the identity information of the received service platform to the POS machine;
  • the service platform further decrypts the identity information of the received POS machine by using a pre-stored key, authenticates the POS machine according to the decrypted information, and encrypts the identity information of the POS machine by using the pre-stored key and sends the identity information to the PC.
  • the process of transmitting the key application request to the card server is performed.
  • the POS can be authenticated by the card server in the system of the present invention.
  • the specific system implementation manners include:
  • the POS machine sends the CA certificate saved by itself to the card server through the PC and the service platform;
  • the card server first performs authentication on the POS machine according to the CA certificate information obtained from the certification center and the CA certificate information of the POS machine sent by the service platform. After the authentication succeeds, the process of authenticating the bus card is performed. .
  • the information interaction between the service platform and the PC can be performed through a TCP/IP connection;
  • the service platform and a third-party system (such as an online banking, a third-party payment system, or a merchant system) can be connected via the Internet or a private network. (DDN) connections for information interaction.
  • DDN private network.

Abstract

本发明公开了一种公交一卡通业务系统及其实现方法。该系统包括:POS机,用于将公交一卡通卡片身份信息发送给PC机,根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作;PC机,用于向业务平台发送携带公交一卡通卡片身份信息的业务请求;业务平台,用于与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求,将一卡通服务器发来的业务指令发送给PC机;一卡通服务器,根据密钥申请请求中的公交一卡通卡片的识别信息对公交一卡通卡片进行认证,认证通过后,根据密钥请求向业务平台返回业务指令。本发明扩展了公交一卡通业务的应用,为用户的使用带来了方便。

Description

一种公交一卡通业务系统及其实现方法
技术领域
本发明涉及网络通信技术,特别是涉及一种公交一卡通业务系统及其实现方法。
背景技术
目前,公交一卡通业务逐渐被广泛应用。图1是现有技术中公交一卡通业务的系统结构图。参见图1,为了实现公交一卡通业务,公交一卡通业务系统中主要包括:公交一卡通卡片、POS (Point of sales,销售点)机和一卡通服务器。其中,公交一卡通卡片是一种非接触式射频卡;一卡通服务器位于通卡公司,维护和管理该城市或该地区的公交一卡通卡片的身份和余额信息,以及管理POS机。
目前,公交一卡通卡片的用处主要是在公共交通工具处进行刷卡买票。比如,在公交车上安装有刷卡的POS机,当需要买票时,只需将公交一卡通卡片靠近POS机,POS机就会读取公交一卡通卡片上的信息,从公交一卡通卡片上扣除相应的票款,并由POS机保存相应的信息,最后将信息直接发送给一卡通服务器。
当需要为公交一卡通卡片充值时,需要将公交一卡通卡片靠近可充值的POS机,该POS机会读取卡片中的信息,由操作人员收取充值现金后,通过POS机人为修改公交一卡通卡片中的余额信息,POS机将交互结果直接发送给一卡通服务器。
由以上描述可以看出,利用图1所示系统,公交一卡通卡片只能被用来在公共交通工具处进行刷卡买票,这样,虽然大量用户在日常生活中都会随身携带公交一卡通卡片,但是,用户也无法随时利用公交一卡通卡片进行其他刷卡消费,从而大大限制了公交一卡通业务的应用。
另外,目前对公交一卡通卡片进行充值时,用户不能随时完成充值操作,而必须到指定的数量较少的充值网点,在交付完充值现金后,才能利用位于充值网点的POS机修改卡片的信息,完成对卡片的充值。可见,利用图1所示系统,用户必须到指定充值网点,以及必须交付现金充值,从而为用户的使用带来很大的不便,降低了业务的满意度,限制了业务的发展。
发明内容
有鉴于此,本发明的主要目的在于提供一种公交一卡通业务系统及其实现方法,扩展公交一卡通业务的应用,为用户的使用带来方便。
为了达到上述目的,本发明的技术方案是这样实现的:
一种公交一卡通业务系统,该系统包括:公交一卡通卡片,POS机,PC机,业务平台、第三方系统以及一卡通服务器。
POS机,用于对公交一卡通卡片进行认证,认证通过后,将公交一卡通卡片身份信息发送给PC机,根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作;
PC机,用于向业务平台发送携带公交一卡通卡片身份信息的业务请求,将业务平台发来的业务指令发送给POS机;
业务平台,用于与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求,将一卡通服务器发来的业务指令发送给PC机;
一卡通服务器,根据密钥申请请求中的公交一卡通卡片的识别信息对公交一卡通卡片进行认证,认证通过后,根据密钥请求向业务平台返回业务指令。
所述一卡通服务器,进一步在向业务平台返回业务指令之前,利用保存的密钥对该业务指令进行加密;
所述POS机包括:天线、读写模块、安全芯片模块和处理模块;其中,
读写模块,用于读取公交一卡通卡片的身份信息,通过处理模块转发给安全芯片模块;
安全芯片模块,根据公交一卡通卡片身份信息,对公交一卡通卡片进行认证,认证通过后,通过处理模块将公交一卡通卡片身份信息发送给PC机,以及在不可访问的密钥区保存密钥,利用密钥对处理模块发来的业务指令进行解密,将解密后的数据返回给处理模块;
处理模块,将PC机发来的业务指令转发给安全芯片模块,根据安全芯片模块返回的解密后的业务指令,控制读写模块对公交一卡通卡片进行对应的读写操作。
所述第三方系统为网银或第三方支付系统,用于根据接收到的扣款请求,从对应的账户中扣除相应的充值金额,将扣款成功消息返回给业务平台;
所述PC机,用于链接到所述业务平台的充值业务页面,下载该页面预先绑定的OCX控件,根据用户输入的充值金额和账户信息,生成作为所述业务请求的充值请求并发送给业务平台,利用OCX控件,将一卡通服务器通过业务平台发来的作为业务指令的充值命令发送给POS机;
业务平台,在接收到充值请求后,将扣款请求发送给所述网银或第三方支付系统,在接收到扣款成功消息后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的充值密钥申请请求;
所述POS机,根据PC机发来的充值命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
所述第三方系统为商户系统,用于检测到用户通过PC机选择的商品和使用公交一卡通卡片支付的信息后,生成对应的商品订单发送给业务平台;
业务平台,进一步用于在成功接收到商品订单后,打开消费业务页面,在接收到PC机发来的支付请求后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的支付密钥申请请求;
所述PC机,用于链接到所述业务平台的消费业务页面,下载该消费业务页面预先绑定的OCX控件,将支付请求作为所述的业务请求发送给业务平台,根据OCX控件的指令,将业务平台发来的作为业务指令的扣款命令发送给POS机;
所述POS机,根据PC机发来的扣款命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
所述POS机,进一步在通过PC机连接到业务平台时,利用预先保存的密钥加密自身的身份信息并发送给PC机,利用预先保存的密钥对接收到的业务平台的身份信息进行解密,根据解密后的信息对业务平台进行认证,在POS机与业务平台的双向认证成功后,执行所述的将公交一卡通卡片身份信息发送给PC机;
PC机,进一步将接收到的POS机的身份信息发送给业务平台,将接收到的业务平台的身份信息发送给POS机;
所述业务平台,进一步利用预先保存的密钥对接收到的POS机的身份信息进行解密,根据解密后的信息对POS机进行认证,利用预先保存的密钥加密自身的身份信息并发送给PC机,在POS机与业务平台的双向认证成功后,执行所述的向一卡通服务器发送密钥申请请求的处理。
所述POS机,将自身保存的CA证书通过PC机和业务平台发送给一卡通服务器;
所述一卡通服务器,首先根据预先从认证中心获取的CA证书信息和业务平台发来的POS机的CA证书信息,对POS机进行认证,认证成功后,执行所述对公交一卡通卡片进行认证的处理。
所述业务平台与第三方系统通过互联网或者专网DDN连接进行信息交互。
一种本发明所述系统的业务实现方法,该方法包括:
A、POS机在对公交一卡通卡片认证通过后,将公交一卡通卡片身份信息发送给PC机,PC机向业务平台发送携带公交一卡通卡片身份信息的业务请求;
B、业务平台与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求;
C、一卡通服务器根据密钥申请请求中的公交一卡通卡片的识别信息对公交一卡通卡片进行认证,认证通过后,根据密钥请求向业务平台返回业务指令;
D、业务平台通过PC机将业务指令发送给POS机;
E、POS机根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作。
在步骤A中,在POS机对公交一卡通卡片认证通过后,并在将公交一卡通卡片身份信息发送给PC机之前,进一步包括:所述POS机利用预先保存的密钥对公交一卡通卡片身份信息进行加密;
在步骤C中,一卡通服务器在对公交一卡通卡片进行认证之前,进一步包括:一卡通服务器利用预先保存的密钥对密钥申请请求中的公交一卡通卡片身份信息进行解密;
在步骤C中,在根据密钥请求向业务平台返回业务指令之前,进一步包括:一卡通服务器利用预先保存的密钥对业务指令进行加密;
在步骤E中进一步包括:POS机接收到PC机发来的业务指令后,首先根据预先保存的密钥对业务指令进行解密。
所述第三方系统为网银或第三方支付系统;
在步骤A之前,进一步包括:PC链接到业务平台的充值业务页面,下载该页面预先绑定的OCX控件,激活POS机,接收用户输入的充值金额和账户信息;
所述业务请求为携带公交一卡通卡片身份信息、充值金额和账户信息的充值请求;
在步骤B中,所述业务平台与第三方系统交互的步骤包括:业务平台根据充值请求中的账户信息,将扣款请求发送给网银或第三方支付系统,网银或第三方支付系统根据充值金额在对应的账户中扣除相应的钱款,并向业务平台返回扣款成功消息;
所述业务指令为充值命令;
所述步骤E包括:POS机根据充值命令,修改公交一卡通卡片中的余额信息。
所述第三方系统为商户系统;
在步骤A之前,进一步包括:商户系统接收用户通过PC机选择的所需购买的商品信息及选择使用公交一卡通卡片支付信息,PC机链接到业务平台的消费业务页面,下载该页面预先绑定的OCX控件,激活POS机;
步骤B中,所述业务平台与第三方系统交互的步骤包括:商户系统生成对应的商品订单发送给业务平台,该商品订单中包括需支付金额信息;
所述密钥申请请求为携带公交一卡通卡片身份信息和支付金额信息的支付密钥申请请求;
所述业务指令为扣款命令;
所述步骤E包括:POS机根据扣款命令,修改公交一卡通卡片中的余额信息。
在步骤A之前进一步包括POS机与业务平台之间的双向认证,该认证过程包括如下方式中的任意一种:
方式一、
POS机通过PC机向业务平台发送鉴别指令;业务平台接收到鉴别指令后,产生随机数RB,通过PC机发送给POS机;POS机产生随机数RA,用业务平台的个性化密钥K1对RA和RB进行加密得到Token1=Enc(RA||RB, K1),POS机将Token1通过PC机发送给业务平台;业务平台用个性化密钥K1解密Token1得到RA’和RB’,比较RB’和RB,如不一致则业务平台对POS机的认证失败,结束当前流程;如一致,则业务平台产生随机数RC,用业务平台的个性化密钥K1对RA’和RC进行加密得到Token2=Enc(RA’||RC, K1),将Token2通过PC机发送给POS机;POS机用个性化密钥K1解密Token2后,比较RA’和RA是否一致,如不一致则POS对业务平台机的认证失败,结束当前流程;如一致则POS对业务平台机的认证成功,则双向认证成功,执行步骤A;
方式二、
业务平台存储根公钥Ru、业务平台的私钥Tv和用根私钥签发的证书CER_T;POS机存储根公钥Ru、POS机的私钥Rv和用根私钥签发的证书CER_R;POS机通过PC机向业务平台发送鉴别请求指令;业务平台产生随机数RB,通过PC机发送给POS机;POS机产生随机数RA,用自己的私钥Rv对RA||RB||UID进行签名得到SgnData1,并将数据块Token1=RA||RB||UID||SgnData1||CER_R通过PC机发送给业务平台;业务平台用根公钥Ru验证证书CER_R,如验证通过,用该证书中POS机的公钥验证数字签名SgnData1,如果验证通过则完成对POS机的身份认证,否则POS机身份鉴别不通过,结束当前流程;
业务平台用自己的私钥Tv对RA||UID进行签名得到SgnData2,并将RA||UID||SgnData2||CER_T通过PC机发送给POS机;POS机用根公钥Ru验证业务平台的证书CER_T,如果验证通过,用该证书中业务平台的公钥验证数字签名SgnData2,如果验证通过则完成对业务平台的身份认证,双向认证成功,执行步骤A,否则业务平台身份认证不通过,结束当前流程。
由此可见,本发明至少具有以下优点:
1、在本发明中,相对于现有技术的公交一卡通业务系统增加了PC机、业务平台和第三方系统,POS机不再与一卡通服务器进行直接通信,而是通过PC机登陆业务平台,从而完成与第三方系统和一卡通服务器的通信,具体地,用户可以通过PC机,触发业务平台与第三方系统进行信息交互,从而从第三方系统处获得更多的业务应用,扩展了公交一卡通业务的应用,为用户的使用带来方便。
2、在本发明中,能够对公交一卡通卡片进行充值,而本发明的充值方式,只需用户将公交一卡通卡片放入POS机,POS机与PC相连,在PC机上输入相应的充值金额和可支付的账户信息即可,本发明就可以自动从账户中扣除相应的充值金额为公交一卡通卡片进行充值。可见,本发明的充值方法,无需用户到指定的充值网点,无需用户携带现金进行充值,从而使得用户能够实现随时随地非现金方式进行公交一卡通卡片充值,为用户的使用带来很大的方便。
3、在本发明中,用户只需将公交一卡通卡片放入POS机,POS机与PC相连,通过PC机在商户系统中选择相应的商品和公交一卡通卡片支付方式,就能够利用公交一卡通卡片进行网上购物的支付,从而大大扩展了公交一卡通业务的应用,为用户的使用带来了很大的方便。
4、在本发明中,不仅POS机与公交一卡通卡片之间、一卡通服务器与POS机之间能够完成认证,保证其信息传输的安全性,而且,POS机也可以与为其服务的业务平台进行相互认证,一卡通服务器也可以对业务平台进行认证,认证的方式灵活多样,比如可以是利用对称算法加密认证也可以是利用非对称算法加密认证,从而进一步保证了本发明实现公交一卡通业务的安全性,提升了系统性能。
附图说明
图1是现有技术中公交一卡通业务的系统结构图;
图2是本发明中公交一卡通业务的系统基本结构图;
图3是在本发明中公交一卡通业务系统的第一种具体实现结构图;
图4是本发明实施例1的流程图;
图5是在本发明中公交一卡通业务系统的第二种具体实现结构图;
图6是本发明实施例2的流程图。
具体实施方式
为使本发明的目的、技术方案和优点更加清楚,下面结合附图及具体实施例对本发明作进一步地详细描述。
本发明提出了一种公交一卡通业务系统。图2是本发明中公交一卡通业务系统的基本结构图。参见图2,本发明系统的基本结构中包括:公交一卡通卡片,POS机,PC机,业务平台、第三方系统以及一卡通服务器,
POS机,用于对公交一卡通卡片进行认证,认证通过后,将公交一卡通卡片身份信息发送给PC机,根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作;
PC机,用于向业务平台发送携带公交一卡通卡片身份信息的业务请求,将业务平台发来的业务指令发送给POS机;
业务平台,用于与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求,将一卡通服务器发来的业务指令发送给PC机;
一卡通服务器,根据密钥申请请求中的公交一卡通卡片的身份信息对公交一卡通卡片进行认证,认证通过后,根据密钥申请请求向业务平台返回业务指令。
相应地,本发明还提出了一种利用公交一卡通业务系统的业务实现方法,该方法的核心思想是:POS机在对公交一卡通卡片认证通过后,将公交一卡通卡片身份信息发送给PC机,PC机向业务平台发送携带公交一卡通卡片身份信息的业务请求;业务平台与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求;一卡通服务器根据密钥申请请求中的公交一卡通卡片的身份信息对公交一卡通卡片进行认证,认证通过后,根据密钥申请请求向业务平台返回业务指令;业务平台通过PC机将业务指令发送给POS机;POS机根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作。
可见,在本发明中,相对于现有技术的公交一卡通业务系统增加了PC机、业务平台和第三方系统,POS机不再与一卡通服务器进行直接通信,而是通过PC机登陆业务平台,从而完成与第三方系统和一卡通服务器的通信,具体地,用户可以通过PC机,触发业务平台与第三方系统进行信息交互,从而从第三方系统处获得更多的业务应用,扩展了公交一卡通业务的应用,为用户的使用带来方便。
在本发明的具体实现中,可以利用图2所示的公交一卡通业务系统实现多种业务应用,比如,对公交一卡通卡片的随时非现金充值;利用公交一卡通卡片进行网上购物;利用公交一卡通卡片进行超市刷卡消费等等。
下面举两个具体的实施例来分别详细说明对公交一卡通卡片随时非现金充值的具体实现过程,以及利用公交一卡通卡片进行网上购物的具体实现过程。
实施例1:
本实施例详细说明对公交一卡通卡片随时非现金充值的具体实现过程。
图3是在本发明中公交一卡通业务系统的第一种具体实现结构图;图4是本发明实施例1的流程图。参见图3,本发明实现对公交一卡通卡片随时非现金充值时,本发明系统中的第三方系统为网银或第三方支付系统(比如支付宝等),此时,参见图4,该实现过程具体包括以下步骤:
步骤401:预先为业务平台的各业务页面绑定客户端安装软件(OCX)控件。
本步骤中,OCX控件是用于与POS机进行信息交互,以指示POS机完成业务操作的软件。由于后续POS机是直接连接到PC机,因此,为了使得业务平台能够控制POS机的操作,为业务平台的业务页面绑定OCX控件,当POS机通过PC机连接到业务平台的任意业务页面后,PC机能够得到页面绑定的OCX控件,从而与POS机交互,指示POS机完成业务操作。
步骤402:公交一卡通卡片用户将公交一卡通卡片放入POS机并将POS机连接到PC机上,并通过PC机登陆到业务平台的充值业务页面,选择充值功能。
本步骤中,POS机可以通过USB接口连接到PC机上。
步骤403:PC机从业务平台下载与充值业务页面绑定的OCX控件,该PC机中的OCX控件激活POS机,并检测POS机。
步骤404:POS机进行寻卡处理,读取公交一卡通卡片的身份信息,根据读取的身份信息对公交一卡通卡片进行认证,认证通过后,将公交一卡通卡片身份信息发送给PC机。
步骤405:PC机接收用户输入的充值金额和账户信息,向业务平台发送携带公交一卡通卡片身份信息、充值金额和账户信息的充值请求。
步骤406:业务平台根据充值请求中的账户信息,将扣款请求发送给对应的网银或第三方支付系统。
步骤407:对应的网银或第三方支付系统根据接收到的扣款请求,从对应的账户中扣除相应的充值金额,将扣款成功消息返回给业务平台。
步骤408:业务平台接收到扣款成功消息后,首先发起POS机在一卡通服务器处的CA认证,认证通过后,向一卡通服务器发送携带公交一卡通卡片身份信息以及充值金额信息的充值密钥申请请求。
步骤409:一卡通服务器根据公交一卡通卡片身份信息对该卡片进行认证,认证通过后,生成充值命令,利用预先保存的密钥对充值命令进行加密,然后发送给业务平台。
步骤410:业务平台将该充值命令发送给PC机,PC机中的OCX控件将该充值命令发送给POS机。
步骤411:POS机根据充值命令,为公交一卡通卡片充值,即修改公交一卡通卡片中的余额信息。
至此,则完成了利用POS机随时方便地对公交一卡通卡片充值,并且,充值时使用的是网银或第三方支付系统,而无需用户到指定的充值网点使用现金进行充值。
为了进一步保证通卡公司处一卡通服务器所维护的公交一卡通卡片的信息准确,本发明还可以进一步包括如下步骤412-413。
步骤412:POS机利用预先保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器。
步骤413:一卡通服务器进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
实施例2:
本实施例详细说明利用公交一卡通卡片进行网上购物的具体实现过程。
图5是在本发明中公交一卡通业务系统的第二种具体实现结构图;图6是本发明实施例2的流程图。参见图5,本发明利用公交一卡通卡片随时进行网上购物时,本发明系统中的第三方系统为与业务平台签约的商户系统,此时,参见图6,该实现过程具体包括以下步骤:
步骤601:预先为业务平台的各业务页面绑定客户端安装软件(OCX)控件。
本步骤中,OCX控件是用于与POS机进行信息交互,以指示POS机完成业务操作的软件。由于后续POS机是直接连接到PC机,因此,为了使得业务平台能够控制POS机的操作,为业务平台的业务页面绑定OCX控件,当POS机通过PC机连接到业务平台的任意业务页面后,PC机能够得到页面绑定的OCX控件,从而与POS机交互,指示POS机完成业务操作。
步骤602:公交一卡通卡片用户通过PC机登陆到商户系统,选择所需购买的商品,并且选择使用公交一卡通卡片支付。
步骤603:商户系统根据用户的选择,生成对应的商品订单发送给业务平台。
该商品订单中包括所需购买的商品的金额,即支付金额信息。
步骤604:业务平台在接收到商品订单后,打开消费业务页面。
步骤605:用户将公交一卡通卡片放入POS机并将POS机连接到PC机上,通过PC机登陆到业务平台的消费业务页面。
本步骤中,POS机可以通过USB接口连接到PC机上。
步骤606:PC机从业务平台下载与消费业务页面绑定的OCX控件,该PC机中的OCX控件激活POS机,并检测POS机。
步骤607:POS机进行寻卡处理,读取公交一卡通卡片的身份信息,根据读取的身份信息对公交一卡通卡片进行认证,认证通过后,将公交一卡通卡片身份信息发送给PC机。
步骤608:PC机向业务平台发送携带公交一卡通卡片身份信息的支付请求。
步骤609:业务平台接收到支付请求后,首先发起POS机在一卡通服务器处的CA认证,认证通过后,向一卡通服务器发送携带公交一卡通卡片身份信息、支付金额信息的支付密钥申请请求。
步骤610:一卡通服务器根据公交一卡通卡片身份信息对该公交卡进行认证,认证通过后,利用预先保存的密钥对扣款命令进行加密,然后发送给业务平台。
步骤611:业务平台将该扣款命令发送给PC机,PC机中的OCX控件将该扣款命令发送给POS机。
步骤612:POS机根据扣款命令,从公交一卡通卡片中扣除对应的金额,即修改公交一卡通卡片中的余额信息。
至此,则完成了利用POS机随时方便地进行网上购物。
为了进一步保证通卡公司处一卡通服务器所维护的公交一卡通卡片的信息准确,本发明还可以进一步包括如下步骤613-614。
步骤613:POS机利用预先保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器。
步骤614:一卡通服务器进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
需要说明的是,在上述图4和图6所示过程中(参见步骤408和步骤609),业务平台与一卡通服务器进行交互之前,可以由一卡通服务器对POS机进行CA认证,从而保证POS机的合法性。为了实现该CA认证,本发明需要预先执行如下处理:向认证中心(CA)提交POS机注册建立请求,CA建立该POS机的注册信息,将注册结果包括参考号和授权码返回给POS机,最后向POS机分发CA证书,该CA证书的分发途径有多种,比如,一种是带外分发,即离线方式,将分配给POS机的CA证书存储在存储介质中,POS机从该存储介质中获取相应的CA证书;另一种是带内分发,POS机连接到CA,向CA提供参考号和授权码,CA验证该参考号和授权码正确后,将CA证书发送给POS机,这样,POS机则获取了CA证书;另外,还需要将CA证书保存在一卡通服务器中,此后,就可以利用步骤408和步骤609的过程,由一卡通服务器对POS机进行CA认证,以确保POS机的合法性。
还需要说明的是,为了进一步增加本发明系统的安全性,保证业务平台和POS机的利益,不可被仿制,在本发明的一个较佳实施例中,还可以增加业务平台与POS机之间的双向认证过程,在POS机连接到业务平台准备对公交一卡通卡片进行充值和网上购物之前,必须要先进行平台和POS之间的认证,业务平台的密钥放在加密机中,POS机的密钥放在主控MCU中;POS机用密钥加密认证信息发给业务平台认证身份,业务平台用密钥解密确认身份;反之亦然,业务平台用密钥加密认证信息发给POS机认证身份,POS机用密钥解密认证身份。在双方身份认证后再进行充值或网上购物操作,如果有一方没有通过认证则禁止进行其他操作。具体双向认证的方法可以包括如下两种方法:
方法一、在POS机通过PC机连接到业务平台时,POS机通过PC机向业务平台发送鉴别指令;业务平台接收到鉴别指令后,产生随机数RB(随机数长度可以为密码算法分组长度的一半),通过PC机发送给POS机;POS机产生随机数RA(随机数长度可以为密码算法分组长度的一半),用业务平台的个性化密钥K1对RA和RB进行加密得到Token1=Enc(RA||RB, K1),POS机将Token1通过PC机发送给业务平台;业务平台用个性化密钥K1解密Token1得到RA’和RB’,比较RB’和RB,如不一致则业务平台对POS机的认证失败,结束与该POS机的交互;如一致,则业务平台产生随机数RC,用业务平台的个性化密钥K1对RA’和RC进行加密得到Token2=Enc(RA’||RC, K1),将Token2通过PC机发送给POS机;POS机用个性化密钥K1解密Token2后,比较RA’和RA是否一致,如不一致则POS对业务平台机的认证失败,结束与业务平台的交互;如一致则POS对业务平台机的认证成功,则双向鉴别通过,否则,双向鉴别不通过。
方法二、业务平台初始化或发行时,存储根公钥Ru、业务平台自己的私钥Tv和用根私钥签发的证书CER_T。POS机存储根公钥Ru、POS机自己的私钥Rv和用根私钥签发的证书CER_R。POS机通过PC机向业务平台发送鉴别请求指令;业务平台产生随机数RB,通过PC机发送给POS机;POS机产生随机数RA,用自己的私钥Rv对RA||RB||UID进行签名得到SgnData1,并将数据块Token1=RA||RB||UID||SgnData1||CER_R通过PC机发送给业务平台;业务平台用根公钥Ru验证证书CER_R,如验证通过,用该证书中POS机的公钥验证数字签名SgnData1,如果验证通过则完成对POS机的身份认证,进行下一步操作,否则POS机身份鉴别不通过,本次鉴别过程中止;
业务平台用自己的私钥Tv对RA||UID进行签名得到SgnData2,并将RA||UID||SgnData2||CER_T通过PC机发送给POS机;POS机用根公钥Ru验证业务平台的证书CER_T,如果验证通过,用该证书中业务平台的公钥验证数字签名SgnData2,如果验证通过则完成对业务平台的身份认证,否则业务平台身份认证不通过,本次鉴别过程中止。
上述业务平台与POS机之间的双向认证过程对于图4所示流程,可以发生在步骤402中,也就是说,在POS机通过PC机登陆到业务平台的充值业务页面时,执行上述的双向认证过程,认证成功后,执行后续步骤。对于图6所示流程,可以发生在步骤605中,也就是说,在POS机通过PC机登陆到业务平台的消费业务页面时,执行上述的双向认证过程,认证成功后,执行后续步骤。
以上描述了本发明方法在实现充值业务和网上购物业务时的具体流程。
在实际的业务实现中,本发明对于公交一卡通业务系统的具体实现细节至少包括如下具体系统实现方式中的任意一种或多种的组合:
一、为了保证POS机与一卡通服务器之间所传输信息的安全性,在本发明系统的具体实现中,可以对所传输信息进行加密处理,具体的系统实现方式包括:
一卡通服务器,进一步在向业务平台返回业务指令之前,利用保存的密钥对该业务指令进行加密;此时,相应地,POS机内部可以包括:天线、读写模块、安全芯片模块和处理模块;其中,
读写模块,用于读取公交一卡通卡片的身份信息,通过处理模块转发给安全芯片模块;
安全芯片模块,根据公交一卡通卡片身份信息,对公交一卡通卡片进行认证,认证通过后,通过处理模块将公交一卡通卡片身份信息发送给PC机,以及在不可访问的密钥区保存密钥,利用密钥对处理模块发来的业务指令进行解密,将解密后的数据返回给处理模块;
处理模块,将PC机发来的业务指令转发给安全芯片模块,根据安全芯片模块返回的业务指令,控制读写模块对公交一卡通卡片进行对应的读写操作。
二、在本发明系统的具体实现中,可以利用本发明系统实现随时方便地对公交卡一卡通卡片进行充值,而无须用户到指定充值网点使用现金进行充值,此时,本发明系统中的第三方系统为网银或第三方支付系统,具体的系统实现方式包括:
网银或第三方支付系统,具体是根据接收到的扣款请求,从对应的账户中扣除相应的充值金额,将扣款成功消息返回给业务平台;
PC机,具体用于链接到所述业务平台的充值业务页面,从该页面中下载OCX控件,根据用户输入的充值金额和账户信息,生成作为所述业务请求的充值请求并发送给业务平台,利用OCX控件,将一卡通服务器通过业务平台发来的作为业务指令的充值命令发送给POS机;
业务平台,在接收到充值请求后,将扣款请求发送给所述网银或第三方支付系统,在接收到扣款成功消息后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的充值密钥申请请求;
所述POS机,根据PC机发来的充值命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息修改自身保存的公交一卡通卡片的余额信息。
三、在本发明系统的具体实现中,可以利用公交卡一卡通卡片进行网上购物,此时,本发明系统中的第三方系统为商户系统,具体的系统实现方式包括:
商户系统具体在检测到用户通过PC机选择的商品和使用公交一卡通卡片支付的信息后,生成对应的商品订单发送给业务平台;
业务平台,进一步用于在接收到商品订单后,打开消费业务页面,在接收到PC机发来的支付请求后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的支付密钥申请请求;
所述PC机,用于链接到业务平台的消费业务页面,从业务平台的消费业务页面中下载OCX控件,将支付请求作为所述的业务请求发送给业务平台,根据OCX控件的指令,将业务平台发来的作为业务指令的扣款命令发送给POS机;
所述POS机,根据PC机发来的扣款命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息修改自身保存的公交一卡通卡片的余额信息。
四、为了进一步保证业务平台和POS机的利益不可被仿制,特在本发明系统的POS机和业务平台中加入加密设计,业务平台和POS机之间可以进行双向认证,具体的系统实现方式包括:
所述POS机,进一步在通过PC机连接到业务平台时,利用预先保存的密钥加密自身的身份信息并发送给PC机,利用预先保存的密钥对接收到的业务平台的身份信息进行解密,根据解密后的信息对业务平台进行认证,在POS机与业务平台的双向认证成功后,执行所述的将公交一卡通卡片身份信息发送给PC机;
PC机,进一步将接收到的POS机的身份信息发送给业务平台,将接收到的业务平台的身份信息发送给POS机;
所述业务平台,进一步利用预先保存的密钥对接收到的POS机的身份信息进行解密,根据解密后的信息对POS机进行认证,利用预先保存的密钥加密自身的身份信息并发送给PC机,在POS机与业务平台的双向认证成功后,执行所述的向一卡通服务器发送密钥申请请求的处理。
五、为了进一步保证与一卡通服务器进行交互的POS机的合法性,防止黑客攻击,本发明系统中可以由一卡通服务器对POS进行认证,具体的系统实现方式包括:
所述POS机,将自身保存的CA证书通过PC机和业务平台发送给一卡通服务器;
所述一卡通服务器,首先根据预先从认证中心获取的CA证书信息和业务平台发来的POS机的CA证书信息,对POS机进行认证,认证成功后,执行所述对公交一卡通卡片进行认证的处理。
在本发明中,业务平台与PC机之间可以通过TCP/IP连接进行上述的信息交互;业务平台与第三方系统(比如网银、第三方支付系统或者商户系统)之间可以通过互联网或者专网(DDN)连接进行信息交互。
总之,以上所述仅为本发明的较佳实施例而已,并非限定本发明的保护范围。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (12)

  1. 一种公交一卡通业务系统,其特征在于,该系统包括:公交一卡通卡片,POS机,PC机,业务平台、第三方系统以及一卡通服务器;
    POS机,用于对公交一卡通卡片进行认证,认证通过后,将公交一卡通卡片身份信息发送给PC机,根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作;
    PC机,用于向业务平台发送携带公交一卡通卡片身份信息的业务请求,将业务平台发来的业务指令发送给POS机;
    业务平台,用于与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求,将一卡通服务器发来的业务指令发送给PC机;
    一卡通服务器,根据密钥申请请求中的公交一卡通卡片的身份信息对公交一卡通卡片进行认证,认证通过后,根据密钥申请请求向业务平台返回业务指令。
  2. 根据权利要求1所述的公交一卡通业务系统,其特征在于,所述一卡通服务器,进一步在向业务平台返回业务指令之前,利用保存的密钥对该业务指令进行加密;
    所述POS机包括:天线、读写模块、安全芯片模块和处理模块;其中,
    读写模块,用于读取公交一卡通卡片的身份信息,通过处理模块转发给安全芯片模块;
    安全芯片模块,根据公交一卡通卡片身份信息,对公交一卡通卡片进行认证,认证通过后,通过处理模块将公交一卡通卡片身份信息发送给PC机,以及在不可访问的密钥区保存密钥,利用密钥对处理模块发来的业务指令进行解密,将解密后的数据返回给处理模块;
    处理模块,将PC机发来的业务指令转发给安全芯片模块,根据安全芯片模块返回的解密后的业务指令,控制读写模块对公交一卡通卡片进行对应的读写操作。
  3. 根据权利要求1所述的公交一卡通业务系统,其特征在于,所述第三方系统为网银或第三方支付系统,用于根据接收到的扣款请求,从对应的账户中扣除相应的充值金额,将扣款成功消息返回给业务平台;
    所述PC机,用于链接到所述业务平台的充值业务页面,下载该页面预先绑定的OCX控件,根据用户输入的充值金额和账户信息,生成作为所述业务请求的充值请求并发送给业务平台,利用OCX控件,将一卡通服务器通过业务平台发来的作为业务指令的充值命令发送给POS机;
    业务平台,在接收到充值请求后,将扣款请求发送给所述网银或第三方支付系统,在接收到扣款成功消息后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的充值密钥申请请求;
    所述POS机,根据PC机发来的充值命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
    一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
  4. 根据权利要求1所述的公交一卡通业务系统,其特征在于,所述第三方系统为商户系统,用于检测到用户通过PC机选择的商品和使用公交一卡通卡片支付的信息后,生成对应的商品订单发送给业务平台;
    业务平台,进一步用于在成功接收到商品订单后,打开消费业务页面,在接收到PC机发来的支付请求后,执行向一卡通服务器发送携带公交一卡通卡片身份信息的支付密钥申请请求;
    所述PC机,用于链接到所述业务平台的消费业务页面,下载该消费业务页面预先绑定的OCX控件,将支付请求作为所述的业务请求发送给业务平台,根据OCX控件的指令,将业务平台发来的作为业务指令的扣款命令发送给POS机;
    所述POS机,根据PC机发来的扣款命令,修改公交一卡通卡片中的余额信息,修改成功后,利用保存的密钥对公交一卡通卡片当前的余额信息进行加密,通过PC机和业务平台发送给一卡通服务器;
    一卡通服务器,进一步利用保存的密钥对接收到的公交一卡通卡片的余额信息进行解密,根据解密后的信息更新自身保存的公交一卡通卡片的余额信息。
  5. 据权利要求1至4中任意一项所述的公交一卡通业务系统,其特征在于,
    所述POS机,进一步在通过PC机连接到业务平台时,利用预先保存的密钥加密自身的身份信息并发送给PC机,利用预先保存的密钥对接收到的业务平台的身份信息进行解密,根据解密后的信息对业务平台进行认证,在POS机与业务平台的双向认证成功后,执行所述的将公交一卡通卡片身份信息发送给PC机;
    PC机,进一步将接收到的POS机的身份信息发送给业务平台,将接收到的业务平台的身份信息发送给POS机;
    所述业务平台,进一步利用预先保存的密钥对接收到的POS机的身份信息进行解密,根据解密后的信息对POS机进行认证,利用预先保存的密钥加密自身的身份信息并发送给PC机,在POS机与业务平台的双向认证成功后,执行所述的向一卡通服务器发送密钥申请请求的处理。
  6. 据权利要求1至4中任意一项所述的公交一卡通业务系统,其特征在于,
    所述POS机,将自身保存的CA证书通过PC机和业务平台发送给一卡通服务器;
    所述一卡通服务器,首先根据预先从认证中心获取的CA证书信息和业务平台发来的POS机的CA证书信息,对POS机进行认证,认证成功后,执行所述对公交一卡通卡片进行认证的处理。
  7. 据权利要求1至4中任意一项所述的公交一卡通业务系统,其特征在于,所述业务平台与PC机通过TCP/IP连接进行信息交互;
    所述业务平台与第三方系统通过互联网或者专网DDN连接进行信息交互。
  8. 种权利要求1所述系统的业务实现方法,其特征在于,该方法包括:
    A、POS机在对公交一卡通卡片认证通过后,将公交一卡通卡片身份信息发送给PC机,PC机向业务平台发送携带公交一卡通卡片身份信息的业务请求;
    B、业务平台与第三方系统交互,交互成功后,根据PC机发来的业务请求向一卡通服务器发送携带公交一卡通卡片身份信息的密钥申请请求;
    C、一卡通服务器根据密钥申请请求中的公交一卡通卡片的身份信息对公交一卡通卡片进行认证,认证通过后,根据密钥申请请求向业务平台返回业务指令;
    D、业务平台通过PC机将业务指令发送给POS机;
    E、POS机根据PC机发来的业务指令,对公交一卡通卡片进行对应的读写操作。
  9. 据权利要求8所述的方法,其特征在于,在步骤A中,在POS机对公交一卡通卡片认证通过后,并在将公交一卡通卡片身份信息发送给PC机之前,进一步包括:所述POS机利用预先保存的密钥对公交一卡通卡片身份信息进行加密;
    在步骤C中,一卡通服务器在对公交一卡通卡片进行认证之前,进一步包括:一卡通服务器利用预先保存的密钥对密钥申请请求中的公交一卡通卡片身份信息进行解密;
    在步骤C中,在根据密钥请求向业务平台返回业务指令之前,进一步包括:一卡通服务器利用预先保存的密钥对业务指令进行加密;
    在步骤E中进一步包括:POS机接收到PC机发来的业务指令后,首先根据预先保存的密钥对业务指令进行解密。
  10. 据权利要求8所述的方法,其特征在于,所述第三方系统为网银或第三方支付系统;
    在步骤A之前,进一步包括:PC链接到业务平台的充值业务页面,下载该页面预先绑定的OCX控件,激活POS机,接收用户输入的充值金额和账户信息;
    所述业务请求为携带公交一卡通卡片身份信息、充值金额和账户信息的充值请求;
    在步骤B中,所述业务平台与第三方系统交互的步骤包括:业务平台根据充值请求中的账户信息,将扣款请求发送给网银或第三方支付系统,网银或第三方支付系统根据充值金额在对应的账户中扣除相应的钱款,并向业务平台返回扣款成功消息;
    所述业务指令为充值命令;
    所述步骤E包括:POS机根据充值命令,修改公交一卡通卡片中的余额信息。
  11. 据权利要求8所述的方法,其特征在于,所述第三方系统为商户系统;
    在步骤A之前,进一步包括:商户系统接收用户通过PC机选择的所需购买的商品信息及选择使用公交一卡通卡片支付信息,PC机链接到业务平台的消费业务页面,下载该页面预先绑定的OCX控件,激活POS机;
    步骤B中,所述业务平台与第三方系统交互的步骤包括:商户系统生成对应的商品订单发送给业务平台,该商品订单中包括需支付金额信息;
    所述密钥申请请求为携带公交一卡通卡片身份信息和支付金额信息的支付密钥申请请求;
    所述业务指令为扣款命令;
    所述步骤E包括:POS机根据扣款命令,修改公交一卡通卡片中的余额信息。
  12. 据权利要求8至11中任意一项所述的方法,其特征在于,在步骤A之前进一步包括POS机与业务平台之间的双向认证,该认证过程包括如下方式中的任意一种:
    方式一、
    POS机通过PC机向业务平台发送鉴别指令;业务平台接收到鉴别指令后,产生随机数RB,通过PC机发送给POS机;POS机产生随机数RA,用业务平台的个性化密钥K1对RA和RB进行加密得到Token1=Enc(RA||RB, K1),POS机将Token1通过PC机发送给业务平台;业务平台用个性化密钥K1解密Token1得到RA’和RB’,比较RB’和RB,如不一致则业务平台对POS机的认证失败,结束当前流程;如一致,则业务平台产生随机数RC,用业务平台的个性化密钥K1对RA’和RC进行加密得到Token2=Enc(RA’||RC, K1),将Token2通过PC机发送给POS机;POS机用个性化密钥K1解密Token2后,比较RA’和RA是否一致,如不一致则POS对业务平台机的认证失败,结束当前流程;如一致则POS对业务平台机的认证成功,则双向认证成功,执行步骤A;
    方式二、
    业务平台存储根公钥Ru、业务平台的私钥Tv和用根私钥签发的证书CER_T;POS机存储根公钥Ru、POS机的私钥Rv和用根私钥签发的证书CER_R;POS机通过PC机向业务平台发送鉴别请求指令;业务平台产生随机数RB,通过PC机发送给POS机;POS机产生随机数RA,用自己的私钥Rv对RA||RB||UID进行签名得到SgnData1,并将数据块Token1=RA||RB||UID||SgnData1||CER_R通过PC机发送给业务平台;业务平台用根公钥Ru验证证书CER_R,如验证通过,用该证书中POS机的公钥验证数字签名SgnData1,如果验证通过则完成对POS机的身份认证,否则POS机身份鉴别不通过,结束当前流程;
    业务平台用自己的私钥Tv对RA||UID进行签名得到SgnData2,并将RA||UID||SgnData2||CER_T通过PC机发送给POS机;POS机用根公钥Ru验证业务平台的证书CER_T,如果验证通过,用该证书中业务平台的公钥验证数字签名SgnData2,如果验证通过则完成对业务平台的身份认证,双向认证成功,执行步骤A,否则业务平台身份认证不通过,结束当前流程。
PCT/CN2010/000245 2009-12-01 2010-02-26 一种公交一卡通业务系统及其实现方法 WO2011066704A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910238774A CN101739771A (zh) 2009-12-01 2009-12-01 一种公交一卡通业务系统及其实现方法
CN200910238774.7 2009-12-01

Publications (1)

Publication Number Publication Date
WO2011066704A1 true WO2011066704A1 (zh) 2011-06-09

Family

ID=42146120

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/000245 WO2011066704A1 (zh) 2009-12-01 2010-02-26 一种公交一卡通业务系统及其实现方法

Country Status (3)

Country Link
CN (3) CN101739771A (zh)
HK (1) HK1134751A2 (zh)
WO (1) WO2011066704A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110532788A (zh) * 2019-08-09 2019-12-03 广州科伊斯数字技术有限公司 一种旋转显示led屏的加密方法

Families Citing this family (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101739771A (zh) * 2009-12-01 2010-06-16 孙伟 一种公交一卡通业务系统及其实现方法
CN102467796B (zh) * 2011-11-18 2014-08-27 陈飞 一种基于身份识别的公交卡充值系统
CN102542225A (zh) * 2011-12-05 2012-07-04 天津市通卡公用网络系统有限公司 跨平台的智能卡在º¿操作系统及方法
CN102799916A (zh) * 2012-07-17 2012-11-28 福建物联天下信息科技有限公司 基于射频识别的信息分享方法
CN103684768A (zh) * 2012-09-10 2014-03-26 中国银联股份有限公司 一种pos系统以及在pos系统内进行双向认证的方法
CN103400461B (zh) * 2013-07-22 2016-02-17 孙伟 Pos机、卡片业务实现的系统及方法
CN103400460B (zh) * 2013-07-22 2017-06-06 建亿通(北京)数据处理信息有限公司 移动pos机、卡片业务实现的系统及方法
CN103400266A (zh) * 2013-07-22 2013-11-20 孙伟 双界面卡模块结合体设备、卡片业务实现系统及方法
CN104700261B (zh) * 2013-12-10 2018-11-27 中国银联股份有限公司 Pos终端的安全入网初始化方法及其系统
CN105184970B (zh) * 2015-08-27 2018-09-04 余荣军 公交ic卡网络支付系统及其支付方法
CN108038962B (zh) * 2015-09-01 2020-09-25 深圳市昇伟电子科技有限公司 采用arm9处理器的基于一卡通的远程售电系统及工作方法
CN105185002B (zh) * 2015-09-09 2018-06-12 建亿通(北京)数据处理信息有限公司 移动终端、业务平台及卡片业务系统
CN105160776B (zh) * 2015-09-09 2017-07-21 建亿通(北京)数据处理信息有限公司 城市一卡通卡、业务平台、卡片业务系统及实现方法
CN105184565A (zh) * 2015-09-09 2015-12-23 建亿通(北京)数据处理信息有限公司 一种卡片业务实现的方法、业务平台及系统
CN114240421A (zh) 2016-01-25 2022-03-25 创新先进技术有限公司 基于移动终端eSE的信用支付方法及装置
WO2017166067A1 (zh) * 2016-03-29 2017-10-05 李昕光 充值系统
CN106296145A (zh) * 2016-08-05 2017-01-04 广东岭南通股份有限公司 交通卡互联网充值方法及装置
CN106485490A (zh) * 2016-10-19 2017-03-08 济南浪潮高新科技投资发展有限公司 一种基于ocx控件实现的pos付款方法
CN106384234A (zh) * 2016-10-31 2017-02-08 济南浪潮高新科技投资发展有限公司 一种基于pos机实现资金支付风险管理的方法
CN106682894A (zh) * 2016-11-30 2017-05-17 广东工业大学 一种基于手机nfc的全国一卡通互联互通支付方法
CN107093241A (zh) * 2017-05-02 2017-08-25 支码开门科技有限公司 电子车锁及车锁控制方法
CN107749085A (zh) * 2017-10-25 2018-03-02 北京匡恩网络科技有限责任公司 票卡、使用票卡的方法和机器可读存储介质
CN108053200A (zh) * 2017-12-28 2018-05-18 新开普电子股份有限公司 城市一卡通管理系统
CN110460562A (zh) * 2018-05-08 2019-11-15 无锡酷银科技有限公司 一种pos终端远程激活方法及系统
CN110414982A (zh) * 2019-07-10 2019-11-05 武汉城市一卡通有限公司 一种一卡通交易方法及系统
CN110830486B (zh) * 2019-11-13 2022-11-25 深圳市亲邻科技有限公司 基于多端通信的读卡、写卡方法、装置以及多端通信系统
CN112862480B (zh) * 2021-01-25 2023-05-30 支付宝(杭州)信息技术有限公司 基于近场通信的交通卡处理方法及装置
CN114038132A (zh) * 2021-11-11 2022-02-11 武汉天喻信息产业股份有限公司 一种基于网口的离线收款终端、系统以及收款和提现方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1647088A (zh) * 2002-03-14 2005-07-27 欧洲计算机网环球公司 用于通过销售点网络上的数据网络接入点购买商品和服务的系统和方法
CN2938244Y (zh) * 2006-04-11 2007-08-22 北京兴华邦科技有限公司 一种智能卡pos机
CN101458853A (zh) * 2007-12-11 2009-06-17 结行信息技术(上海)有限公司 一种在线pos系统和智能卡在线支付方法

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7096494B1 (en) * 1998-05-05 2006-08-22 Chen Jay C Cryptographic system and method for electronic transactions
JP2006527430A (ja) * 2003-06-04 2006-11-30 マスターカード インターナショナル インコーポレーテッド 商業取引における顧客認証システム及び方法
JP2005050263A (ja) * 2003-07-31 2005-02-24 Matsushita Electric Ind Co Ltd 携帯端末及びサービス処理方法
CN1547144A (zh) * 2003-12-10 2004-11-17 北京矽谷学人科技有限公司 互联网安全支付系统
CN101436332A (zh) * 2008-12-19 2009-05-20 福建今日特价网络有限公司 一种支付系统及其支付方法
CN101739771A (zh) * 2009-12-01 2010-06-16 孙伟 一种公交一卡通业务系统及其实现方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1647088A (zh) * 2002-03-14 2005-07-27 欧洲计算机网环球公司 用于通过销售点网络上的数据网络接入点购买商品和服务的系统和方法
CN2938244Y (zh) * 2006-04-11 2007-08-22 北京兴华邦科技有限公司 一种智能卡pos机
CN101458853A (zh) * 2007-12-11 2009-06-17 结行信息技术(上海)有限公司 一种在线pos系统和智能卡在线支付方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
GUO JIE: "APPLICATION SCHEME FOR SELF-ASSISTANT CHARGING SYSTEM FOR BUS IC CARD", FINANCIAL COMPUTER OF HUANAN, 10 October 2005 (2005-10-10), pages 101, 102 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110532788A (zh) * 2019-08-09 2019-12-03 广州科伊斯数字技术有限公司 一种旋转显示led屏的加密方法
CN110532788B (zh) * 2019-08-09 2023-03-10 广州科伊斯数字技术有限公司 一种旋转显示led屏的加密方法

Also Published As

Publication number Publication date
CN101739771A (zh) 2010-06-16
CN102034323B (zh) 2012-11-28
CN201910100U (zh) 2011-07-27
HK1134751A2 (en) 2010-05-07
CN102034323A (zh) 2011-04-27

Similar Documents

Publication Publication Date Title
WO2011066704A1 (zh) 一种公交一卡通业务系统及其实现方法
WO2018086515A1 (zh) 可离线验证安全信息标签构造验证方法与装置
WO2014139403A1 (zh) 一种终端主密钥tmk安全下载方法及系统
WO2016126052A2 (ko) 인증 방법 및 시스템
WO2019019378A1 (zh) 业务处理方法、装置、适配器及计算机可读存储介质
WO2016137277A1 (en) Electronic device providing electronic payment function and operating method thereof
WO2019051866A1 (zh) 权益信息管理方法、装置、设备及计算机可读存储介质
WO2019015232A1 (zh) 汇款处理方法、系统及计算机可读存储介质
WO2014030959A1 (en) Information providing method, mobile terminal and display device for the same
WO2020235782A1 (ko) 분산 환경에서의 신원 인증 방법
EP2893690A1 (en) Data security management system
WO2019001110A1 (zh) 权限认证方法、系统、设备及计算机可读存储介质
WO2018233367A1 (zh) 立案方法、装置、终端和计算机可读存储介质
WO2019019376A1 (zh) 业务流程管理方法、装置、设备及计算机可读存储介质
WO2017036009A1 (zh) 线上线下健康服务联盟优惠推广处理系统及方法
WO2017036006A1 (zh) 线上线下健康服务产品推广处理系统及方法
WO2019037395A1 (zh) 密钥管理方法、装置及可读存储介质
WO2018201696A1 (zh) 社保卡保单的保费续缴方法、装置、设备及存储介质
WO2015081763A1 (zh) 一种虚拟设备的授权使用方法及装置
WO2019132555A1 (ko) 이모지가 포함된 메시지를 송수신하는 전자 장치 및 그 전자 장치를 제어하는 방법
WO2019000800A1 (zh) 制证方法、装置、设备及计算机可读存储介质
WO2017012198A1 (zh) 基于电子检查单的检查机构自动匹配方法和网络医院平台
WO2018030828A1 (ko) 카드정보가 매칭된 가상개인정보를 이용한 보안 운송장 발급관리 시스템 및 방법
WO2020105892A1 (ko) 디바이스가 디지털 키를 공유하는 방법
WO2019006900A1 (zh) 线上清算方法、装置、设备及计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10834137

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10834137

Country of ref document: EP

Kind code of ref document: A1