WO2014063632A1 - 多应用智能卡管理系统及方法 - Google Patents

多应用智能卡管理系统及方法 Download PDF

Info

Publication number
WO2014063632A1
WO2014063632A1 PCT/CN2013/085800 CN2013085800W WO2014063632A1 WO 2014063632 A1 WO2014063632 A1 WO 2014063632A1 CN 2013085800 W CN2013085800 W CN 2013085800W WO 2014063632 A1 WO2014063632 A1 WO 2014063632A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
smart card
card management
card
activation
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/085800
Other languages
English (en)
French (fr)
Inventor
彭敏
周钰
郑建宾
严翔翔
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Publication of WO2014063632A1 publication Critical patent/WO2014063632A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/354Card activation or deactivation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/356Aspects of software for card payments
    • G06Q20/3563Software being resident on card
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/357Cards having a plurality of specified features
    • G06Q20/3574Multiple applications on card
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/357Cards having a plurality of specified features
    • G06Q20/3576Multiple memory zones on card

Definitions

  • the present invention relates to a smart card management system and method, and more particularly to a multi-application smart card management system and method. Background technique
  • the existing management platform of the multi-application smart card based on the GP (G loba l Platform) standard is based on the security domain, that is, each application in the smart card has a corresponding security domain (which is the owner of the application on the card) Representative).
  • such a GP-based smart card includes a primary security domain and a secondary security domain, and the security domain is attached to the primary security domain, that is, all rights from the security domain are assigned by the primary security domain, which results in the following results: An equal relationship.
  • the present invention proposes a multi-application smart card management system and method capable of making an entity of each application on a smart card have an equal relationship.
  • a multi-application smart card management system includes:
  • At least one application provider smart card management terminal each of the at least one application provider smart card management terminal constructing a card activation request based on the user's instruction and transmitting the card activation request to the multi-application smart card management server, wherein the card The activation request includes card information of the smart card to be activated, and each of the at least one application provider smart card management terminal performs a smart card activation after subsequently receiving card activation data transmitted from the multi-application smart card management server Live operation
  • the multi-application smart card management server receiving a card activation request from the at least one application provider smart card management terminal, and generating the card activation data based on the card information, and activating the card data And transmitting back to the corresponding application provider smart card management terminal, wherein the card activation data includes an application installation certificate verification key.
  • the card key is implanted in a chip of the smart card during smart card manufacture, and the smart card is in one-to-one correspondence with the card key.
  • the activating operation comprises: writing the card activation data into a smart card; the smart card verifying the card activation data by using the card key; if the verification is passed, storing The application installs a certificate verification key.
  • the application provider smart card management terminal associated with the smart card constructs an application registration request based on the user instruction, and transmits the application registration request to The multi-application smart card management server.
  • the multi-application smart card management server after receiving an application registration request from the at least one application provider smart card management terminal, the multi-application smart card management server generates an application installation certificate based on the application registration request, and Transmitting the application installation certificate back to the corresponding application provider smart card management terminal.
  • the application provider smart card management terminal After receiving the application installation certificate sent back by the multi-application smart card management server, the application provider smart card management terminal writes the application installation certificate and the application to be installed Corresponding smart card to perform application installation operations.
  • the application installation operation comprises: verifying the application installation certificate by using the application installation certificate verification key; if the verification is passed, installing the application to be installed.
  • a multi-application smart card management method includes the following steps:
  • the multi-application smart card management server receives from the at least one application provider A card activation request of the card management terminal, and generating the card activation data based on the card information, and transmitting the card activation data back to the corresponding application provider smart card management terminal, wherein the card activation data includes an application installation Certificate verification key;
  • Each of the at least one application provider smart card management terminal performs an activation operation on the smart card after receiving the card activation data transmitted from the multi-application smart card management server.
  • each application on the multi-application smart card is completely independent of other applications, that is, the main body (e.g., the issuer or the application provider) of different applications on the card is completely equal.
  • the main body e.g., the issuer or the application provider
  • FIG. 1 is a schematic structural diagram of a multi-application smart card management system according to an embodiment of the present invention
  • FIG. 2 is a flowchart of a multi-application smart card management method according to an embodiment of the present invention. detailed description
  • the multi-application smart card management system disclosed by the present invention includes at least one application provider smart card management terminal 1 (for example, a smart card management terminal of a card issuer) and a multi-application smart card management server 2.
  • application provider smart card management terminal 1 for example, a smart card management terminal of a card issuer
  • multi-application smart card management server 2 for example, a multi-application smart card management server.
  • each of the at least one application provider smart card management terminal 1 constructs a card activation request based on an instruction of a user (eg, its corresponding issuer or application provider) and transmits the card activation request to the multi-application a smart card management server 2, wherein the card activation request includes card information (such as a card identifier) of a smart card to be activated (the smart card to be activated is in a sleep state, that is, the application cannot be loaded), and the at least one application provider smart card management Each of the terminals 1 performs an activation operation on the smart card after subsequently receiving the card activation data transmitted from the multi-application smart card management server 2.
  • the card activation request includes card information (such as a card identifier) of a smart card to be activated (the smart card to be activated is in a sleep state, that is, the application cannot be loaded)
  • the at least one application provider smart card management Each of the terminals 1 performs an activation operation on the smart card after subsequently receiving the card activation data transmitted from the
  • the multi-application smart card management server 2 receives a card activation request from the at least one application provider smart card management terminal 1 and generates the card activation data based on the card information, and transmits the card activation data back to the corresponding Application provider smart card management terminal 1,
  • the card activation data includes an application installation certificate verification key.
  • the card key is implanted in a chip of the smart card during smart card manufacture, and the smart card is in one-to-one correspondence with the card key (ie, The card key for each smart card is unique).
  • the card issuing system to which the multi-application smart card management server belongs pre-distributes the smart card-based chip serial number to generate the smart card corresponding
  • the card key is entrusted to the smart card manufacturer to embed the card key into the smart card chip.
  • the activating operation comprises: writing the card activation data into a smart card; the smart card verifying the card activation data using the card key; After the verification is passed, the application installation certificate verification key is stored (the card activation data is unique to its corresponding smart card and can only be decrypted by the unique card key of the corresponding smart card).
  • the application provider smart card management terminal 1 associated with the smart card constructs an application registration request based on a user instruction, and The application registration request is transmitted to the multi-application smart card management server 2.
  • the multi-application smart card management server 2 after receiving an application registration request from the at least one application provider smart card management terminal 1, the multi-application smart card management server 2 registers based on the application. Requesting to generate an application installation certificate, and transmitting the application installation certificate back to the corresponding application provider smart card management terminal 1.
  • the application provider smart card management terminal 1 After receiving the application installation certificate transmitted by the multi-application smart card management server 2, the application provider smart card management terminal 1 installs the application installation certificate.
  • the application to be installed is written into the corresponding smart card to perform an application installation operation.
  • the application installation operation includes: verifying the application installation certificate by using the application installation certificate verification key; if the verification is passed, installing the to-be-installed application.
  • the multi-application smart card management system disclosed by the invention has the following advantages:
  • the individual applications on the smart card are completely independent of other applications, ie the main body of the different applications on the card (such as the issuer or application provider) is completely equal.
  • the multi-application smart card management method disclosed by the present invention includes the following steps: (A1) Each of the at least one application provider smart card management terminal is based on a user (eg, its corresponding issuer or application provider) The instruction constructs a card activation request and transmits the card activation request to the multi-application smart card management server, wherein the card activation request includes card information of the smart card to be activated (the smart card to be activated is in a sleep state, that is, the application cannot be loaded) For example, a card identifier); (A2) the multi-application smart card management server receives a card activation request from the at least one application provider smart card management terminal, and generates the card activation data based on the card information, and the The card activation data is transmitted back to the corresponding application provider smart card management terminal, wherein the card activation data includes an application installation certificate verification key; (A3) each of the at least one application provider smart card management terminal is based on a user (eg, its corresponding issuer or application provider) The instruction constructs
  • the card key is implanted in a chip of the smart card during smart card manufacture, and the smart card is in one-to-one correspondence with the card key (ie, The card key for each smart card is unique).
  • the card issuance system to which the multi-application smart card management server belongs (the card issuance system is neutral) is pre-distributed based on the chip serial number of the smart card to generate the smart card corresponding
  • the card key is entrusted to the smart card manufacturer to embed the card key into the smart card chip.
  • the activating operation includes: writing the card activation data into a smart card; the smart card verifying the card activation data by using the card key; After the verification is passed, the application installation certificate verification key is stored (the card activation data is unique to its corresponding smart card and can only be decrypted by the unique card key of the corresponding smart card).
  • the multi-application smart card management method disclosed by the present invention further includes: (A4) when the application needs to be installed in the smart card, the application provider smart card management terminal associated with the smart card constructs an application registration request based on the user instruction, and Transmitting the application registration request to the multi-application wisdom Can manage the server.
  • the multi-application smart card management method disclosed by the present invention further comprises: (A5) after receiving an application registration request from the at least one application provider smart card management terminal, the multi-application smart card management server is based on the application The registration request generates an application installation certificate and transmits the application installation certificate back to the corresponding application provider smart card management terminal.
  • the multi-application smart card management method disclosed by the present invention further comprises: (A6) after receiving the application installation certificate sent back by the multi-application smart card management server, the application provider performs an application installation operation.
  • the application installation operation includes: verifying the application installation certificate by using the application installation certificate verification key; if the verification is passed, installing the to-be-installed application.
  • the multi-application smart card management method disclosed in the present invention has the following advantages: Each application on the multi-application smart card is completely independent of other applications, that is, the main body of different applications on the card (for example, the issuer or the application provider) is completely equality.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Stored Programmes (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明提出了多应用智能卡管理系统及方法。其中,所述系统包括至少一个应用提供方智能卡管理终端和多应用智能卡管理服务器,所述多应用智能卡管理服务器接收来自至少一个应用提供方智能卡管理终端的卡片激活请求,并基于所述卡片信息生成所述卡片激活数据,以及将所述卡片激活数据传送回对应的应用提供方智能卡管理终端,其中,所述卡片激活数据包括应用安装证书验证密钥。本发明所公开的多应用智能卡管理系统及方法能够使智能卡上的每个应用的主体具有平等关系。

Description

多应用智能卡管理系统及方法 技术领域
本发明涉及智能卡管理系统及方法, 更具体地, 涉及多应用智能卡管理系 统及方法。 背景技术
目前,随着计算机和网络应用的日益广泛以及不同领域的业务种类的曰益 丰富, 对多应用智能卡的管理变得越来越重要。
现有的基于 GP (G loba l Platform)标准的多应用智能卡的管理平台是基于 安全域的,即智能卡中的每个应用都具有相应的安全域(其是该应用的拥有者 在卡上的代表) .
然而, 这样的基于 GP标准的智能卡包含主安全域和从安全域, 从安全域 依附于主安全域,即从安全域的所有权限均由主安全域赋予,这导致如下结果: 各个应用主体不是平等的关系。
因此,存在如下需求: 提供能够使智能卡上的每个应用的主体具有平等关 系(即智能卡上的每个应用的主体独自管理自己的应用,后加载到卡片中的应 用不受之前加载的卡片应用主体的控制) 的多应用智能卡管理系统及方法。 发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了能够使智能卡上 的每个应用的主体具有平等关系的多应用智能卡管理系统及方法。
本发明的目的是通过以下技术方案实现的:
一种多应用智能卡管理系统, 所述多应用智能卡管理系统包括:
至少一个应用提供方智能卡管理终端,所述至少一个应用提供方智能卡管 理终端中的每个基于用户的指令构造卡片激活请求并将所述卡片激活请求传 送到多应用智能卡管理服务器,其中所述卡片激活请求包括待激活的智能卡的 卡片信息,所述至少一个应用提供方智能卡管理终端中的每个在随后接收到来 自所述多应用智能卡管理服务器传送回的卡片激活数据后执行对智能卡的激 活操作;
多应用智能卡管理服务器,所述多应用智能卡管理服务器接收来自所述至 少一个应用提供方智能卡管理终端的卡片激活请求,并基于所述卡片信息生成 所述卡片激活数据,以及将所述卡片激活数据传送回对应的应用提供方智能卡 管理终端, 其中, 所述卡片激活数据包括应用安装证书验证密钥。
在上面所公开的方案中,优选地, 所述卡片密钥在智能卡制造期间被植入 所述智能卡的芯片中, 并且所述智能卡与所述卡片密钥一一对应。
在上面所公开的方案中, 优选地, 所述激活操作包括: 将所述卡片激活数 据写入智能卡中; 所述智能卡使用所述卡片密钥验证所述卡片激活数据; 如果 验证通过, 则存储所述应用安装证书验证密钥。
在上面所公开的方案中, 优选地, 当需要在智能卡中安装应用时, 与所述 智能卡相关联的应用提供方智能卡管理终端基于用户指令构造应用注册请求, 并将所述应用注册请求传送到所述多应用智能卡管理服务器。
在上面所公开的方案中,优选地,在接收到来自所述至少一个应用提供方 智能卡管理终端的应用注册请求后,所述多应用智能卡管理服务器基于所述应 用注册请求生成应用安装证书,并将所述应用安装证书传送回对应的应用提供 方智能卡管理终端。
在上面所公开的方案中,优选地,在接收到所述多应用智能卡管理服务器 传送回的应用安装证书后,所述应用提供方智能卡管理终端将所述应用安装证 书和待安装的应用写入对应的智能卡中以执行应用安装操作。
在上面所公开的方案中, 优选地, 所述应用安装操作包括: 使用所述应用 安装证书验证密钥验证所述应用安装证书; 如果验证通过, 则安装所述待安装 的应用。
本发明的目的也可以通过以下技术方案实现:
一种多应用智能卡管理方法,所述多应用智能卡管理方法包括下列步骤:
( A1 )至少一个应用提供方智能卡管理终端中的每个基于用户的指令构造 卡片激活请求并将所述卡片激活请求传送到多应用智能卡管理服务器,其中所 述卡片激活请求包括待激活的智能卡的卡片信息;
(A2) 所述多应用智能卡管理服务器接收来自所述至少一个应用提供方智 能卡管理终端的卡片激活请求, 并基于所述卡片信息生成所述卡片激活数据, 以及将所述卡片激活数据传送回对应的应用提供方智能卡管理终端, 其中, 所 述卡片激活数据包括应用安装证书验证密钥;
(A3) 所述至少一个应用提供方智能卡管理终端中的每个在接收到来自所 述多应用智能卡管理服务器传送回的卡片激活数据后执行对智能卡的激活操 作。
本发明所公开的多应用智能卡管理系统及方法具有以下优点:多应用智能 卡上的各个应用完全不受其他应用的控制, 即卡片上不同应用的主体(例如发 卡行或应用提供方) 完全平等。 附图说明
结合附图, 本发明的技术特征以及优点将会被本领域技术人员更好地理 解, 其中:
图 1是根据本发明的实施例的多应用智能卡管理系统的示意性结构图; 图 2是根据本发明的实施例的多应用智能卡管理方法的流程图。 具体实施方式
图 1是根据本发明的实施例的多应用智能卡管理系统的示意性结构图。 如 图 1所示, 本发明所公开的多应用智能卡管理系统包括至少一个应用提供方智 能卡管理终端 1(例如发卡方的智能卡管理终端)和多应用智能卡管理服务器 2。 其中, 所述至少一个应用提供方智能卡管理终端 1中的每个基于用户 (例如其 对应的发卡方或应用提供方)的指令构造卡片激活请求并将所述卡片激活请求 传送到所述多应用智能卡管理服务器 2 , 其中所述卡片激活请求包括待激活的 智能卡(该待激活的智能卡处于休眠状态, 即不能加载应用)的卡片信息(例 如卡片标识符 ),所述至少一个应用提供方智能卡管理终端 1中的每个在随后接 收到来自所述多应用智能卡管理服务器 2传送回的卡片激活数据后执行对智能 卡的激活操作。 所述多应用智能卡管理服务器 2接收来自所述至少一个应用提 供方智能卡管理终端 1的卡片激活请求, 并基于所述卡片信息生成所述卡片激 活数据,以及将所述卡片激活数据传送回对应的应用提供方智能卡管理终端 1 , 其中, 所述卡片激活数据包括应用安装证书验证密钥。
优选地,在本发明所公开的多应用智能卡管理系统中, 所述卡片密钥在智 能卡制造期间被植入所述智能卡的芯片中,并且所述智能卡与所述卡片密钥一 一对应 (即每个智能卡的卡片密钥是唯一的)。
示例性地,在本发明所公开的多应用智能卡管理系统中, 所述多应用智能 卡管理服务器所隶属的发卡系统(该发卡系统是中立的)预先基于智能卡的芯 片序列号分散生成该智能卡对应的卡片密钥,并委托智能卡制造商将所述卡片 密钥植入智能卡芯片中。
优选地,在本发明所公开的多应用智能卡管理系统中,所述激活操作包括: 将所述卡片激活数据写入智能卡中;所述智能卡使用所述卡片密钥验证所述卡 片激活数据; 如果验证通过, 则存储所述应用安装证书验证密钥(卡片激活数 据对其对应的智能卡而言是唯一的,并且只能由所对应的智能卡的唯一的卡片 密钥解密)。
优选地,在本发明所公开的多应用智能卡管理系统中, 当需要在智能卡中 安装应用时, 与所述智能卡相关联的应用提供方智能卡管理终端 1基于用户指 令构造应用注册请求,并将所述应用注册请求传送到所述多应用智能卡管理服 务器 2。
优选地,在本发明所公开的多应用智能卡管理系统中,在接收到来自所述 至少一个应用提供方智能卡管理终端 1的应用注册请求后, 所述多应用智能卡 管理服务器 2基于所述应用注册请求生成应用安装证书, 并将所述应用安装证 书传送回对应的应用提供方智能卡管理终端 1。
优选地,在本发明所公开的多应用智能卡管理系统中,在接收到所述多应 用智能卡管理服务器 2传送回的应用安装证书后, 所述应用提供方智能卡管理 终端 1将所述应用安装证书和待安装的应用写入对应的智能卡中以执行应用安 装操作。
优选地,在本发明所公开的多应用智能卡管理系统中, 所述应用安装操作 包括:使用所述应用安装证书验证密钥验证所述应用安装证书;如果验证通过, 则安装所述待安装的应用。
由上可见, 本发明所公开的多应用智能卡管理系统具有如下优点: 多应用 智能卡上的各个应用完全不受其他应用的控制, 即卡片上不同应用的主体(例 如发卡行或应用提供方) 完全平等。
图 2是根据本发明的实施例的多应用智能卡管理方法的流程图。 如图 2所 示, 本发明所公开的多应用智能卡管理方法包括下列步骤: (A1 ) 至少一个应 用提供方智能卡管理终端中的每个基于用户(例如其对应的发卡方或应用提供 方)的指令构造卡片激活请求并将所述卡片激活请求传送到多应用智能卡管理 服务器, 其中所述卡片激活请求包括待激活的智能卡(该待激活的智能卡处于 休眠状态, 即不能加载应用 )的卡片信息(例如卡片标识符); (A2) 所述多应 用智能卡管理服务器接收来自所述至少一个应用提供方智能卡管理终端的卡 片激活请求, 并基于所述卡片信息生成所述卡片激活数据, 以及将所述卡片激 活数据传送回对应的应用提供方智能卡管理终端, 其中, 所述卡片激活数据包 括应用安装证书验证密钥;(A3) 所述至少一个应用提供方智能卡管理终端中 的每个在接收到来自所述多应用智能卡管理服务器传送回的卡片激活数据后 执行对智能卡的激活操作。
优选地,在本发明所公开的多应用智能卡管理方法中, 所述卡片密钥在智 能卡制造期间被植入所述智能卡的芯片中,并且所述智能卡与所述卡片密钥一 一对应 (即每个智能卡的卡片密钥是唯一的)。
示例性地,在本发明所公开的多应用智能卡管理方法中, 所述多应用智能 卡管理服务器所隶属的发卡系统(该发卡系统是中立的)预先基于智能卡的芯 片序列号分散生成该智能卡对应的卡片密钥,并委托智能卡制造商将所述卡片 密钥植入智能卡芯片中。
优选地,在本发明所公开的多应用智能卡管理方法中,所述激活操作包括: 将所述卡片激活数据写入智能卡中;所述智能卡使用所述卡片密钥验证所述卡 片激活数据; 如果验证通过, 则存储所述应用安装证书验证密钥(卡片激活数 据对其对应的智能卡而言是唯一的,并且只能由所对应的智能卡的唯一的卡片 密钥解密)。
优选地, 本发明所公开的多应用智能卡管理方法进一步包括: (A4 ) 当需 要在智能卡中安装应用时,与所述智能卡相关联的应用提供方智能卡管理终端 基于用户指令构造应用注册请求,并将所述应用注册请求传送到所述多应用智 能卡管理服务器。
优选地, 本发明所公开的多应用智能卡管理方法进一步包括: (A5 )在接 收到来自所述至少一个应用提供方智能卡管理终端的应用注册请求后,所述多 应用智能卡管理服务器基于所述应用注册请求生成应用安装证书,并将所述应 用安装证书传送回对应的应用提供方智能卡管理终端。
优选地, 本发明所公开的多应用智能卡管理方法进一步包括: (A6 )在接 收到所述多应用智能卡管理服务器传送回的应用安装证书后,所述应用提供方 执行应用安装操作。
优选地,在本发明所公开的多应用智能卡管理方法中, 所述应用安装操作 包括:使用所述应用安装证书验证密钥验证所述应用安装证书;如果验证通过, 则安装所述待安装的应用。
由上可见, 本发明所公开的多应用智能卡管理方法具有如下优点: 多应用 智能卡上的各个应用完全不受其他应用的控制, 即卡片上不同应用的主体(例 如发卡行或应用提供方) 完全平等。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不 局限于上述的实施方式。 应该认识到: 在不脱离本发明主旨和范围的情况下,

Claims

权利要求
1. 一种多应用智能卡管理系统, 所述多应用智能卡管理系统包括: 至少一个应用提供方智能卡管理终端,所述至少一个应用提供方智能卡管 理终端中的每个基于用户的指令构造卡片激活请求并将所述卡片激活请求传 送到多应用智能卡管理服务器,其中所述卡片激活请求包括待激活的智能卡的 卡片信息,所述至少一个应用提供方智能卡管理终端中的每个在随后接收到来 自所述多应用智能卡管理服务器传送回的卡片激活数据后执行对智能卡的激 活操作;
多应用智能卡管理服务器,所述多应用智能卡管理服务器接收来自所述至 少一个应用提供方智能卡管理终端的卡片激活请求,并基于所述卡片信息生成 所述卡片激活数据,以及将所述卡片激活数据传送回对应的应用提供方智能卡 管理终端, 其中, 所述卡片激活数据包括应用安装证书验证密钥。
2. 根据权利要求 1所述的多应用智能卡管理系统, 其特征在于, 所述卡片 密钥在智能卡制造期间被植入所述智能卡的芯片中,并且所述智能卡与所述卡 片密钥——对应。
3. 根据权利要求 2所述的多应用智能卡管理系统, 其特征在于, 所述激活 操作包括: 将所述卡片激活数据写入智能卡中; 所述智能卡使用所述卡片密钥 验证所述卡片激活数据; 如果验证通过, 则存储所述应用安装证书验证密钥。
4. 根据权利要求 3所述的多应用智能卡管理系统, 其特征在于, 当需要在 智能卡中安装应用时,与所述智能卡相关联的应用提供方智能卡管理终端基于 用户指令构造应用注册请求,并将所述应用注册请求传送到所述多应用智能卡 管理服务器。
5. 根据权利要求 4所述的多应用智能卡管理系统, 其特征在于, 在接收到 来自所述至少一个应用提供方智能卡管理终端的应用注册请求后,所述多应用 智能卡管理服务器基于所述应用注册请求生成应用安装证书,并将所述应用安 装证书传送回对应的应用提供方智能卡管理终端。
6. 根据权利要求 5所述的多应用智能卡管理系统, 其特征在于, 在接收到 所述多应用智能卡管理服务器传送回的应用安装证书后,所述应用提供方智能 卡管理终端将所述应用安装证书和待安装的应用写入对应的智能卡中以执行 应用安装操作。
7. 根据权利要求 6所述的多应用智能卡管理系统, 其特征在于, 所述应用 安装操作包括: 使用所述应用安装证书验证密钥验证所述应用安装证书; 如果 验证通过, 则安装所述待安装的应用。
8.—种多应用智能卡管理方法,所述多应用智能卡管理方法包括下列步 骤:
( A1 )至少一个应用提供方智能卡管理终端中的每个基于用户的指令构造 卡片激活请求并将所述卡片激活请求传送到多应用智能卡管理服务器,其中所 述卡片激活请求包括待激活的智能卡的卡片信息;
(A2) 所述多应用智能卡管理服务器接收来自所述至少一个应用提供方智 能卡管理终端的卡片激活请求, 并基于所述卡片信息生成所述卡片激活数据, 以及将所述卡片激活数据传送回对应的应用提供方智能卡管理终端, 其中, 所 述卡片激活数据包括应用安装证书验证密钥;
(A3) 所述至少一个应用提供方智能卡管理终端中的每个在接收到来自所 述多应用智能卡管理服务器传送回的卡片激活数据后执行对智能卡的激活操 作。
PCT/CN2013/085800 2012-10-25 2013-10-23 多应用智能卡管理系统及方法 Ceased WO2014063632A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210412189.6 2012-10-25
CN201210412189.6A CN103778448B (zh) 2012-10-25 2012-10-25 多应用智能卡管理系统及方法

Publications (1)

Publication Number Publication Date
WO2014063632A1 true WO2014063632A1 (zh) 2014-05-01

Family

ID=50544026

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/085800 Ceased WO2014063632A1 (zh) 2012-10-25 2013-10-23 多应用智能卡管理系统及方法

Country Status (2)

Country Link
CN (1) CN103778448B (zh)
WO (1) WO2014063632A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105516181A (zh) * 2015-12-29 2016-04-20 邵军利 安全设备管理系统及方法
CN107341393A (zh) 2016-04-29 2017-11-10 腾讯科技(深圳)有限公司 应用程序安装包的检测方法和装置
CN106874808B (zh) * 2017-01-17 2019-12-13 新智数字科技有限公司 一种激活ic卡的方法及ic卡
CN113935405A (zh) * 2021-09-24 2022-01-14 金邦达有限公司 多方联合发卡的数据校验方法、计算机装置及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101231768A (zh) * 2008-01-25 2008-07-30 北京深思洛克数据保护中心 一种多应用智能卡及实现智能卡多应用的方法
CN102025710A (zh) * 2009-09-11 2011-04-20 中国银联股份有限公司 多应用智能卡及智能卡多应用管理系统和方法
CN102087716A (zh) * 2011-03-02 2011-06-08 武汉天喻信息产业股份有限公司 一种多应用Java智能卡
CN102096841A (zh) * 2009-12-14 2011-06-15 Nxp股份有限公司 安装有计算机代码的集成电路和系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101500224B (zh) * 2008-01-31 2012-06-06 中国移动通信集团公司 电信智能卡的多应用管理服务器、多应用管理方法及系统
CN101753590A (zh) * 2008-11-28 2010-06-23 爱思开电讯投资(中国)有限公司 一种用于远程管理应用的装置和方法
CN101511051B (zh) * 2008-12-31 2012-09-19 北京握奇数据系统有限公司 电信智能卡的应用业务下载方法、系统及设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101231768A (zh) * 2008-01-25 2008-07-30 北京深思洛克数据保护中心 一种多应用智能卡及实现智能卡多应用的方法
CN102025710A (zh) * 2009-09-11 2011-04-20 中国银联股份有限公司 多应用智能卡及智能卡多应用管理系统和方法
CN102096841A (zh) * 2009-12-14 2011-06-15 Nxp股份有限公司 安装有计算机代码的集成电路和系统
CN102087716A (zh) * 2011-03-02 2011-06-08 武汉天喻信息产业股份有限公司 一种多应用Java智能卡

Also Published As

Publication number Publication date
CN103778448B (zh) 2017-10-27
CN103778448A (zh) 2014-05-07

Similar Documents

Publication Publication Date Title
JP5969048B2 (ja) グローバルプラットフォーム仕様を使用した発行元セキュリティドメインの鍵管理のためのシステム及び方法
CN106161359B (zh) 认证用户的方法及装置、注册可穿戴设备的方法及装置
US10855460B2 (en) In-vehicle computer system, vehicle, key generation device, management method, key generation method, and computer program
US11068578B2 (en) Subtoken management system for connected devices
TWI534731B (zh) 用於資產之安全元件交易及管理之裝置及方法
US10108409B2 (en) Systems and methods for updatable applets
CN109997119B (zh) 安全元件安装和设置
CN106603461A (zh) 一种业务认证的方法、装置和系统
CN103198030A (zh) 访问安全存储器的方法、安全存储器和包括安全存储器的系统
US20160048460A1 (en) Remote load and update card emulation support
CN105427106B (zh) 电子现金数据的授权处理方法、支付处理方法及虚拟卡
CN103854180A (zh) 信用凭证生成方法及其系统、应用授权方法及其系统
US20170359358A1 (en) Method for making contactless transactions secure
EP4128687B1 (en) Device provisioning using a supplemental cryptographic identity
CN104022886A (zh) 应用于停车场的安全认证方法、相关装置和系统
WO2014063632A1 (zh) 多应用智能卡管理系统及方法
US20240320376A1 (en) Digital entity processing method, electronic device, storage medium
CN103093139B (zh) Ic卡智能燃气表信息安全管理模块
WO2015007184A1 (zh) 多应用智能卡及智能卡多应用管理方法
KR20200090490A (ko) 디지털 키 공유 시스템에서 이모빌라이저 토큰을 업데이트하는 장치 및 방법
US20210184865A1 (en) In-vehicle controller and method for embedding certificate for same
KR101581663B1 (ko) 공인인증기관 연동 인증 및 부인 방지 방법 및 시스템
CN108600218B (zh) 一种远程授权系统和远程授权方法
US20250200553A1 (en) Method for did authentication using smart card and smart card device
CN112861108B (zh) 一种联盟链数据处理方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13849579

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 210815)

122 Ep: pct application non-entry in european phase

Ref document number: 13849579

Country of ref document: EP

Kind code of ref document: A1