WO2014187292A1 - 安全性信息交互系统、设备和方法 - Google Patents

安全性信息交互系统、设备和方法 Download PDF

Info

Publication number
WO2014187292A1
WO2014187292A1 PCT/CN2014/077776 CN2014077776W WO2014187292A1 WO 2014187292 A1 WO2014187292 A1 WO 2014187292A1 CN 2014077776 W CN2014077776 W CN 2014077776W WO 2014187292 A1 WO2014187292 A1 WO 2014187292A1
Authority
WO
WIPO (PCT)
Prior art keywords
information interaction
security information
security
communication channel
command
Prior art date
Application number
PCT/CN2014/077776
Other languages
English (en)
French (fr)
Inventor
郭伟
陈成钱
周钰
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Priority to US14/888,042 priority Critical patent/US10148765B2/en
Priority to EP14801484.8A priority patent/EP3001634A4/en
Publication of WO2014187292A1 publication Critical patent/WO2014187292A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/353Payments by cards read by M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/42Confirmation, e.g. check or permission by the legal debtor of payment
    • G06Q20/425Confirmation, e.g. check or permission by the legal debtor of payment using two different networks, one for transaction and one for security confirmation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0209Architectural arrangements, e.g. perimeter networks or demilitarized zones
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/104Peer-to-peer [P2P] networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/141Setup of application sessions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication

Definitions

  • the present invention relates to information interaction systems, devices and methods, and more particularly to security information interaction systems, devices and methods. Background technique
  • the basic working process of the prior art solution is as follows: when a security carrier (such as a SIM card, an SD card) needs to actively initiate a command to a security information interaction terminal (for example, a mobile terminal) to use the function that the security information interaction terminal can provide
  • a security carrier such as a SIM card, an SD card
  • the security information interaction terminal first needs to send a command to the security carrier and trigger a subsequent process according to the return value of the security carrier, that is, sending the instruction to the security carrier to obtain the command on the security carrier, thereby completing the correlation.
  • Security information interaction process when a security carrier (such as a SIM card, an SD card) needs to actively initiate a command to a security information interaction terminal (for example, a mobile terminal) to use the function that the security information interaction terminal can provide
  • the security information interaction terminal first needs to send a command to the security carrier and trigger a subsequent process according to the return value of the security carrier, that is, sending the instruction to the security carrier to obtain the command on the security carrier, thereby
  • the existing technical solution has the following problem: since the security information interaction terminal first needs to send a command to the security carrier and trigger the subsequent process according to the return value of the security carrier (ie, obtain the command on the security carrier), When the security bearer needs to initiate a command to the security information interaction terminal to use the function provided by the security information interaction terminal, the security information interaction terminal does not know the timing and cannot send the command accurately and timely to trigger the subsequent process. In addition, if the security information interaction terminal continuously queries the state of the security carrier by using a periodic polling mechanism, the following problems still occur: a large amount of security information is used to interact with the computing resources of the terminal, and the security carrier is still unable to autonomously Flexibly and proactively send commands.
  • the present invention proposes to enable a safe load A security information interaction system, device, and method that can actively and flexibly send commands to a security information interaction terminal.
  • the security information interaction system includes a security information interaction terminal and a security carrier, wherein the security carrier is established between the security information interaction terminal and the security carrier A communication channel and a second communication channel actively send commands to the security information interaction terminal to complete an associated security information interaction process.
  • the security bearer when the security bearer needs to actively send a command to the security information interaction terminal, the security bearer communicates to the security information interaction terminal via the first communication channel.
  • a notification event message is sent to initiate a session between the security information interaction terminal and the secure carrier.
  • the security information interaction terminal sends a command read instruction to the secure carrier via the second communication channel to obtain the security.
  • the carrier's command and then processes the acquired security carrier's commands and communicates the processing results back to the secure carrier.
  • the security bearer sends a status indication message to the security information interaction terminal after receiving the processing result from the security information interaction terminal, where the status indication The message indicates whether there are subsequent commands.
  • the security information interaction terminal receives and parses the status indication message, and if the status indication message indicates that a subsequent command exists, the security information interaction terminal is The second communication channel sends a command read command to the secure carrier to obtain a subsequent command of the secure carrier, and if the status indication message indicates that there is no subsequent command, the security information interactive terminal terminates The started session.
  • the first communication channel is a peer to peer mode communication channel.
  • the second communication channel is a communication channel of the command/response mode of the active information interactive terminal as an active party.
  • a security information interaction terminal capable of passing the security
  • the first communication channel and the second communication channel established between the sexual information interaction terminal and the security carrier receive and process the commands actively initiated by the security carrier to complete the related security information interaction process.
  • a security carrier capable of actively transmitting a command to the security information interaction terminal through a first communication channel and a second communication channel established between the security information interaction terminal and the security carrier to complete Related security information interaction process.
  • a security information interaction method comprising the following steps:
  • the security bearer actively sends a command to the security information interaction terminal through the first communication channel and the second communication channel to complete a related security information interaction process.
  • the security information interaction system, device and method disclosed by the present invention have the following advantages: the security carrier can actively and flexibly actively send commands to the security information interaction terminal, thereby significantly improving the efficiency of the security information interaction system.
  • FIG. 1 is a schematic structural diagram of a security information interaction system according to an embodiment of the present invention.
  • FIG. 2 is a flowchart of a security information interaction method according to an embodiment of the present invention. detailed description
  • the security information interaction system disclosed by the present invention includes a security information interaction terminal 1 and a security carrier 2, wherein the security carrier 2 can be stored and executed thereon for executing security information.
  • a carrier of the security application of the interaction process actively transmitting a command to the security information interaction terminal 1 through the first communication channel and the second communication channel established between the security information interaction terminal 1 and the security carrier 2
  • the security carrier 2 is directed to the first communication channel.
  • the security information interaction terminal 1 transmits a notification event message to initiate a session between the security information interaction terminal 1 and the security carrier 2.
  • the security information interaction terminal 1 after receiving the notification event message, the security information interaction terminal 1 sends a command read to the security carrier 2 via the second communication channel.
  • the instruction acquires the command of the secure carrier 2 and then processes the acquired command of the secure carrier 2 and transmits the result of the processing back to the secure carrier 2.
  • the security carrier 2 sends a status indication message to the security information interaction terminal 1 after receiving the processing result from the security information interaction terminal 1.
  • the status indication message indicates whether a subsequent command exists.
  • the security information interaction terminal 1 receives and parses the status indication message, and if the status indication message indicates that there is a subsequent command, the security The sexual information interaction terminal 1 transmits a command read command to the secure carrier 2 via the second communication channel to acquire a subsequent command of the secure carrier 2, and if the status indication message indicates that there is no subsequent command, the The security information interactive terminal 1 terminates the initiated session.
  • the secure carrier 2 is a SIM card or a smart SD card.
  • the security information communication terminal 1 is a mobile terminal (e.g., a smart phone) or a POS machine.
  • the first communication channel is a peer to peer mode communication channel, such as a SWP protocol based communication channel.
  • the second communication channel is a communication channel of the command/response mode of the security information interaction terminal 1 as an active party, such as based on the IS07816 protocol or The communication channel of the standard SD card interface protocol.
  • the security information interaction terminal 1 is a mobile phone
  • the security carrier 2 is a SIM card
  • the first communication channel is a communication channel based on the SWP protocol
  • the second communication channel is The communication channel based on the IS07816 protocol
  • the basic working process of the exemplary security information interaction system is as follows: (1) Establishing an IS07816-based protocol between the mobile phone and the SIM a communication channel, and the SIM card establishes a communication channel based on the SWP protocol with the NFC controller in the mobile phone; (2) when the SIM card needs to actively send a command to the mobile phone, the SIM card sends the mobile phone to the mobile phone through the communication channel based on the SWP protocol Notifying the event message to start the session; after receiving the notification event message, the mobile phone sends a Fetch command to the SIM card through the communication channel based on the IS07816 protocol to acquire the STK command from the SIM card and process the result, and the processed result is obtained.
  • the communication channel based on the IS07816 protocol continues to send a Fetch instruction to the SIM card to obtain the command and perform subsequent processing, and if there is no subsequent command, the SIM card returns a status word 9000 for the Terminal Response instruction, thereby indicating the end of the current session of the SIM card. ; (3) If the SIM card needs to start the next session, it can pass the base again. Communication channel SWP protocol to send a notification event message to the phone.
  • the security carrier can actively and flexibly send commands to the security information interaction terminal, which significantly improves the efficiency of the security information interaction system.
  • the present invention discloses a security information interaction terminal 1 capable of establishing a first communication channel between the security information interaction terminal 1 and the security carrier 2 And the second communication channel receives and processes the command initiated by the security carrier 2 to complete the related security information interaction process.
  • the security information interaction terminal 1 disclosed by the present invention transmits to the secure carrier 2 via the second communication channel.
  • the command reads the command to acquire the command of the secure carrier 2 and then processes the acquired command of the secure carrier 2 and transmits the result of the processing back to the secure carrier 2.
  • the security information interaction terminal 1 disclosed by the present invention receives and parses a status indication message from the security carrier 2, and if the status indication message indicates that a subsequent command exists, the security information interaction terminal 1 transmitting a command read command to the secure carrier 2 via the second communication channel to obtain a subsequent command of the secure carrier 2, and if the status indication message indicates that there is no subsequent command, the security information
  • the interactive terminal 1 terminates the initiated session.
  • the security information interaction terminal 1 disclosed in the present invention is a mobile terminal (for example, wisdom) Can phone) or POS.
  • the first communication channel is a peer-to-peer mode communication channel, such as a SWP protocol based communication channel.
  • the second communication channel is a communication channel of the command/response mode of the security information interaction terminal 1 as an active party, such as based on the IS07816 protocol or The communication channel of the standard SD card interface protocol.
  • the present invention discloses a security carrier 2 (i.e., a carrier on which a security application for performing a security information interaction process can be stored and executed) capable of passing security information
  • a security carrier 2 i.e., a carrier on which a security application for performing a security information interaction process can be stored and executed
  • the first communication channel and the second communication channel established between the interactive terminal 1 and the secure carrier 2 actively send commands to the security information interaction terminal 1 to complete the related security information interaction process.
  • the security carrier 2 when the security carrier 2 disclosed by the present invention needs to actively send a command to the security information interaction terminal 1, the security carrier 2 transmits to the security information interaction terminal 1 via the first communication channel.
  • the event message is notified to initiate a session between the security information interactive terminal 1 and the secure carrier 2.
  • the security bearer 2 of the present invention sends a status indication message to the security information interaction terminal 1 after receiving the processing result from the security information interaction terminal 1, wherein the status indication message Indicates if there are subsequent commands.
  • the security carrier 2 disclosed herein is a SIM card or a smart SD card.
  • the first communication channel is a peer to peer mode communication channel, such as a SWP protocol based communication channel.
  • the second communication channel is a communication channel of the command/response mode of the security information interaction terminal 1 as an active party, such as based on the IS07816 protocol or a standard SD card.
  • the communication channel of the interface protocol is a communication channel of the command/response mode of the security information interaction terminal 1 as an active party, such as based on the IS07816 protocol or a standard SD card.
  • the security information interaction method disclosed in the present invention includes the following steps: (A1) establishing a first communication channel and a second communication channel between the security information interaction terminal and the security bearer; (A2) a security carrier (i.e., a carrier on which a security application for performing a security information interaction process can be stored and executed) is actively transmitted to the security information interaction terminal through the first communication channel and the second communication channel Send commands to complete the relevant security information interaction process.
  • A1 establishing a first communication channel and a second communication channel between the security information interaction terminal and the security bearer
  • a security carrier i.e., a carrier on which a security application for performing a security information interaction process can be stored and executed
  • the step (A2) further includes: when the security bearer needs to actively send a command to the security information interaction terminal, the security bearer via The first communication channel sends a notification event message to the security information interaction terminal to initiate a session between the security information interaction terminal and the security bearer.
  • the step (A2) further includes: after receiving the notification event message, the security information interaction terminal transmits to the second communication channel to The secure carrier sends a command read command to retrieve the command of the secure bearer and then processes the retrieved security bearer command and communicates the processing result back to the secure bearer.
  • the step (A2) further includes: the security bearer receiving the processing result from the security information interaction terminal to the security information
  • the interactive terminal sends a status indication message, where the status indication message indicates whether there is a subsequent command.
  • the step (A2) further includes: the security information interaction terminal receiving and parsing the status indication message, and if the status indication message Instructing the presence of a subsequent command, the security information interaction terminal transmitting a command read command to the secure carrier via the second communication channel to obtain a subsequent command of the secure carrier, and if the status indication message indicates no If there is a subsequent command, the security information interaction terminal terminates the initiated session.
  • the security carrier is a SIM card or a smart SD card.
  • the security information interaction terminal is a mobile terminal (e.g., a smart phone) or a POS machine.
  • the first communication channel is a peer-to-peer mode communication channel, such as a SWP protocol based communication channel.
  • the second communication channel is a communication channel of the command/response mode of the security information interaction terminal as an active party, such as based on the IS07816 protocol or standard.
  • the communication channel of the SD card interface protocol is a communication channel of the command/response mode of the security information interaction terminal as an active party, such as based on the IS07816 protocol or standard.
  • the security information interaction method disclosed by the present invention has the following advantages: a security carrier
  • the command can be sent to the security information interaction terminal autonomously and flexibly, which significantly improves the efficiency of the security information interaction system.

Abstract

一种安全性信息交互系统、设备和方法,所述方法包括:在安全性信息交互终端和安全载体之间建立第一通信信道和第二通信信道;所述安全载体通过所述第一通信信道和所述第二通信信道主动地向所述安全性信息交互终端发送命令以完成相关的安全性信息交互过程。通过所公开的安全性信息交互系统、设备和方法,安全载体可以自主灵活地主动向安全性信息交互终端发送命令,从而显著地提高了安全性信息交互系统的效率。

Description

安全性信息交互系统、 设备和方法 技术领域
本发明涉及信息交互系统、 设备和方法,更具体地,涉及安全性信息交互 系统、 设备和方法。 背景技术
目前,随着计算机和网络应用的日益广泛以及不同领域的业务种类的日益 丰富,用于安全性信息交互(即对安全性要求较高的信息交互,例如金融领域 中的交易处理过程)的系统、 设备和方法(尤其是基于移动终端的安全性信息 交互系统)变得越来越重要。
现有的技术方案的基本工作过程如下:当安全载体(例如 SIM卡、 SD卡) 需要向安全性信息交互终端(例如移动终端)主动发起命令以使用安全性信息 交互终端所能提供的功能时,需要安全性信息交互终端先向该安全载体发送命 令并根据安全载体对该命令的返回值来触发后续流程,即向所述安全载体发送 取指令而获取安全载体上的命令, 由此完成相关的安全性信息交互过程。
然而,现有的技术方案存在如下问题:由于需要安全性信息交互终端先向 安全载体发送命令并根据安全载体对该命令的返回值来触发后续流程(即获取 安全载体上的命令),故当安全载体需要向安全性信息交互终端主动发起命令 以使用安全性信息交互终端所能提供的功能时,会发生由于安全性信息交互终 端不知道该时机而无法准确和及时地下发命令以触发后续流程的情况,此外, 如果安全性信息交互终端采用周期性的轮询机制不断地查询安全载体的状态, 仍会产生如下问题:耗费大量的安全性信息交互终端的计算资源,并且安全载 体仍无法自主灵活地主动发送命令。
因此,存在如下需求:提供能够使得安全载体可以自主灵活地主动向安全 性信息交互终端发送命令的安全性信息交互系统、 设备和方法。 发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了能够使得安全载 体可以自主灵活地主动向安全性信息交互终端发送命令的安全性信息交互系 统、 设备和方法。
本发明的目的是通过以下技术方案实现的:
一种安全性信息交互系统,所述安全性信息交互系统包括安全性信息交互 终端和安全载体,其中 ,所述安全载体通过在所述安全性信息交互终端和所述 安全载体之间建立的第一通信信道和第二通信信道主动地向所述安全性信息 交互终端发送命令以完成相关的安全性信息交互过程。
在上面所公开的方案中 ,优选地,当所述安全载体需要向所述安全性信息 交互终端主动地发送命令时,所述安全载体经由所述第一通信信道向所述安全 性信息交互终端发送通知事件消息以启动所述安全性信息交互终端和所述安 全载体之间的会话。
在上面所公开的方案中 ,优选地,在接收到所述通知事件消息后,所述安 全性信息交互终端经由所述第二通信信道向所述安全载体发送命令读取指令 以获取所述安全载体的命令,并随后处理所获取的安全载体的命令以及将处理 结果传送回所述安全载体。
在上面所公开的方案中 ,优选地,所述安全载体在接收到来自所述安全性 信息交互终端的处理结果后向所述安全性信息交互终端发送状态指示报文,其 中 ,所述状态指示报文指示是否存在后续命令。
在上面所公开的方案中 ,优选地,所述安全性信息交互终端接收并解析所 述状态指示报文,并且如果所述状态指示报文指示存在后续命令,则所述安全 性信息交互终端经由所述第二通信信道向所述安全载体发送命令读取指令以 获取所述安全载体的后续命令,而如果所述状态指示报文指示不存在后续命 令,则所述安全性信息交互终端终止所启动的会话。
在上面所公开的方案中 ,优选地,所述第一通信信道是对等模式的通信信 道。
在上面所公开的方案中 ,优选地,所述第二通信信道是以所述安全性信息 交互终端作为主动方的命令 /响应模式的通信信道。
本发明的目的也可以通过以下技术方案实现:
一种安全性信息交互终端,所述安全性信息交互终端能够通过在所述安全 性信息交互终端和安全载体之间建立的第一通信信道和第二通信信道接收并 处理所述安全载体主动发起的命令以完成相关的安全性信息交互过程。
本发明的目的也可以通过以下技术方案实现:
一种安全载体,所述安全载体能够通过在安全性信息交互终端和所述安全 载体之间建立的第一通信信道和第二通信信道而主动地向所述安全性信息交 互终端发送命令以完成相关的安全性信息交互过程。
本发明的目的也可以通过以下技术方案实现:
一种安全性信息交互方法,所述方法包括下列步骤:
( A1 )在安全性信息交互终端和安全载体之间建立第一通信信道和第二通 信信道;
( A2 )所述安全载体通过所述第一通信信道和所述第二通信信道主动地向 所述安全性信息交互终端发送命令以完成相关的安全性信息交互过程。
本发明所公开的安全性信息交互系统、设备和方法具有下列优点:安全载 体可以自主灵活地主动向安全性信息交互终端发送命令,从而显著地提高了安 全性信息交互系统的效率。 附图说明
结合附图 ,本发明的技术特征以及优点将会被本领域技术人员更好地理 解,其中 :
图 1是根据本发明的实施例的安全性信息交互系统的示意性结构图 ; 图 2是根据本发明的实施例的安全性信息交互方法的流程图。 具体实施方式
图 1是根据本发明的实施例的安全性信息交互系统的示意性结构图。如图 1 所示,本发明所公开的安全性信息交互系统包括安全性信息交互终端 1和安全 载体 2 ,其中 ,所述安全载体 2 (即可以在其上存储并运行用于执行安全性信息 交互过程的安全应用的载体)通过在所述安全性信息交互终端 1和所述安全载 体 2之间建立的第一通信信道和第二通信信道主动地向所述安全性信息交互终 端 1发送命令以完成相关的安全性信息交互过程。 优选地,在本发明所公开的安全性信息交互系统中 , 当所述安全载体 2需 要向所述安全性信息交互终端 1主动地发送命令时所述安全载体 2经由所述第 一通信信道向所述安全性信息交互终端 1发送通知事件消息以启动所述安全性 信息交互终端 1和所述安全载体 2之间的会话。
优选地,在本发明所公开的安全性信息交互系统中 ,在接收到所述通知事 件消息后所述安全性信息交互终端 1经由所述第二通信信道向所述安全载体 2 发送命令读取指令以获取所述安全载体 2的命令,并随后处理所获取的安全载 体 2的命令以及将处理结果传送回所述安全载体 2。
优选地,在本发明所公开的安全性信息交互系统中 ,所述安全载体 2在接 收到来自所述安全性信息交互终端 1的处理结果后向所述安全性信息交互终端 1发送状态指示报文,其中 ,所述状态指示报文指示是否存在后续命令。
优选地,在本发明所公开的安全性信息交互系统中 ,所述安全性信息交互 终端 1接收并解析所述状态指示报文,并且如果所述状态指示报文指示存在后 续命令则所述安全性信息交互终端 1经由所述第二通信信道向所述安全载体 2 发送命令读取指令以获取所述安全载体 2的后续命令,而如果所述状态指示报 文指示不存在后续命令,则所述安全性信息交互终端 1终止所启动的会话。
示例性地,在本发明所公开的安全性信息交互系统中 ,所述安全载体 2是 SIM卡或智能 SD卡。
示例性地,在本发明所公开的安全性信息交互系统中 ,所述安全性信息交 互终端 1是移动终端(例如智能手机)或 POS机。
示例性地,在本发明所公开的安全性信息交互系统中 ,所述第一通信信道 是对等模式的通信信道,诸如基于 SWP协议的通信信道。
示例性地,在本发明所公开的安全性信息交互系统中 ,所述第二通信信道 是以所述安全性信息交互终端 1作为主动方的命令 /响应模式的通信信道,诸如 基于 IS07816协议或标准 SD卡接口协议的通信信道。
在一个示例性的实施方式中 ,所述安全性信息交互终端 1是手机,所述安 全载体 2是 SIM卡,所述第一通信信道是基于 SWP协议的通信信道,所述第 二通信信道是基于 IS07816协议的通信信道,并且该示例性的安全性信息交 互系统的基本工作过程如下:( 1 )手机与 SIM之间建立基于 IS07816协议的 通信信道,并且 SIM卡与手机内的 NFC控制器建立基于 SWP协议的通信信 道;( 2 )当 SIM卡需要向手机主动地发送命令时, SIM卡通过所述基于 SWP 协议的通信信道向手机发送通知事件消息,以启动会话;手机收到该通知事件 消息后,通过所述基于 IS07816协议的通信信道向 SIM卡发送 Fetch指令以 从 SIM卡获取 STK命令并进行处理,并将处理完后的结果数据以 Terminal Response指令的形式通过所述基于 IS07816协议的通信信道传送回 SIM卡, 并且如果此时 SIM卡还有后续命令,则 SIM卡针对该 Terminal Response指 令返回状态字 91XX,随后手机通过所述基于 IS07816协议的通信信道向 SIM 卡继续发送 Fetch指令以获取命令并进行后续的处理,而如果无后续命令,则 SIM卡针对该 Terminal Response指令返回状态字 9000,从而指示 SIM卡的 当前会话的结束;( 3 ) SIM卡如果需要开始下一个会话,则可以再通过所述基 于 SWP协议的通信信道向手机发送通知事件消息即可。
由上可见,本发明所公开的安全性信息交互系统具有下列优点:安全载体 可以自主灵活地主动向安全性信息交互终端发送命令,显著地提高了安全性信 息交互系统的效率。
如图 1所示,本发明公开了一种安全性信息交互终端 1 ,所述安全性信息交 互终端 1能够通过在所述安全性信息交互终端 1和安全载体 2之间建立的第一 通信信道和第二通信信道接收并处理所述安全载体 2主动发起的命令以完成相 关的安全性信息交互过程。
优选地,在经由所述第一通信信道接收到来自所述安全载体 2的通知事件 消息后,本发明所公开的安全性信息交互终端 1经由所述第二通信信道向所述 安全载体 2发送命令读取指令以获取所述安全载体 2的命令,并随后处理所获取 的安全载体 2的命令以及将处理结果传送回所述安全载体 2。
优选地,本发明所公开的安全性信息交互终端 1接收并解析来自所述安全 载体 2的状态指示报文,并且如果所述状态指示报文指示存在后续命令,则所 述安全性信息交互终端 1经由所述第二通信信道向所述安全载体 2发送命令读 取指令以获取所述安全载体 2的后续命令,而如果所述状态指示报文指示不存 在后续命令,则所述安全性信息交互终端 1终止所启动的会话。
示例性地,在本发明所公开的安全性信息交互终端 1是移动终端(例如智 能手机)或 POS机。
示例性地,在本发明所公开的安全性信息交互终端中 ,所述第一通信信道 是对等模式的通信信道,诸如基于 SWP协议的通信信道。
示例性地,在本发明所公开的安全性信息交互终端中 ,所述第二通信信道 是以所述安全性信息交互终端 1作为主动方的命令 /响应模式的通信信道,诸如 基于 IS07816协议或标准 SD卡接口协议的通信信道。
如图 1所示,本发明公开了一种安全载体 2 ,所述安全载体 2 (即可以在其 上存储并运行用于执行安全性信息交互过程的安全应用的载体)能够通过在安 全性信息交互终端 1和所述安全载体 2之间建立的第一通信信道和第二通信信 道主动地向所述安全性信息交互终端 1发送命令以完成相关的安全性信息交互 过程。
优选地, 当本发明所公开的安全载体 2需要向所述安全性信息交互终端 1 主动地发送命令时,所述安全载体 2经由所述第一通信信道向所述安全性信息 交互终端 1发送通知事件消息以启动所述安全性信息交互终端 1和所述安全载 体 2之间的会话。
优选地,本发明所公开的安全载体 2在接收到来自所述安全性信息交互终 端 1的处理结果后向所述安全性信息交互终端 1发送状态指示报文,其中 ,所述 状态指示报文指示是否存在后续命令。
示例性地,本发明所公开的安全载体 2是 SIM卡或智能 SD卡。
示例性地,在本发明所公开的安全载体中 ,所述第一通信信道是对等模式 的通信信道,诸如基于 SWP协议的通信信道。
示例性地,在本发明所公开的安全载体中 ,所述第二通信信道是以所述安 全性信息交互终端 1作为主动方的命令 /响应模式的通信信道 , 诸如基于 IS07816协议或标准 SD卡接口协议的通信信道。
图 2是根据本发明的实施例的安全性信息交互方法的流程图。 如图 2所示, 本发明所公开的安全性信息交互方法包括下列步骤:( A1 )在安全性信息交互 终端和安全载体之间建立第一通信信道和第二通信信道;( A2 )所述安全载体 (即可以在其上存储并运行用于执行安全性信息交互过程的安全应用的载体) 通过所述第一通信信道和第二通信信道主动地向所述安全性信息交互终端发 送命令以完成相关的安全性信息交互过程。
优选地,在本发明所公开的安全性信息交互方法中 ,所述步骤( A2 )进 一步包括: 当所述安全载体需要向所述安全性信息交互终端主动地发送命令 时,所述安全载体经由所述第一通信信道向所述安全性信息交互终端发送通知 事件消息以启动所述安全性信息交互终端和所述安全载体之间的会话。
优选地,在本发明所公开的安全性信息交互方法中 ,所述步骤( A2 )进 一步包括:在接收到所述通知事件消息后,所述安全性信息交互终端经由所述 第二通信信道向所述安全载体发送命令读取指令以获取所述安全载体的命令, 并随后处理所获取的安全载体的命令以及将处理结果传送回所述安全载体。
优选地,在本发明所公开的安全性信息交互方法中 ,所述步骤( A2 )进 一步包括:所述安全载体在接收到来自所述安全性信息交互终端的处理结果后 向所述安全性信息交互终端发送状态指示报文,其中 ,所述状态指示报文指示 是否存在后续命令。
优选地,在本发明所公开的安全性信息交互方法中 ,所述步骤( A2 )进 一步包括:所述安全性信息交互终端接收并解析所述状态指示报文,并且如果 所述状态指示报文指示存在后续命令,则所述安全性信息交互终端经由所述第 二通信信道向所述安全载体发送命令读取指令以获取所述安全载体的后续命 令,而如果所述状态指示报文指示不存在后续命令,则所述安全性信息交互终 端终止所启动的会话。
示例性地,在本发明所公开的安全性信息交互方法中 ,所述安全载体是 SIM卡或智能 SD卡。
示例性地,在本发明所公开的安全性信息交互方法中 ,所述安全性信息交 互终端是移动终端(例如智能手机)或 POS机。
示例性地,在本发明所公开的安全性信息交互方法中 ,所述第一通信信道 是对等模式的通信信道,诸如基于 SWP协议的通信信道。
示例性地,在本发明所公开的安全性信息交互方法中 ,所述第二通信信道 是以所述安全性信息交互终端作为主动方的命令 /响应模式的通信信道,诸如 基于 IS07816协议或标准 SD卡接口协议的通信信道。
由上可见,本发明所公开的安全性信息交互方法具有下列优点:安全载体 可以自主灵活地主动向安全性信息交互终端发送命令,显著地提高了安全性信 息交互系统的效率。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不 局限于上述的实施方式。 应该认识到:在不脱离本发明主旨和范围的情况下, 本领域技术人员可以对本发明做出不同的变化和修改。

Claims

权利要求
1. 一种安全性信息交互系统,所述安全性信息交互系统包括安全性信息 交互终端和安全载体,其中 ,所述安全载体通过在所述安全性信息交互终端和 所述安全载体之间建立的第一通信信道和第二通信信道主动地向所述安全性 信息交互终端发送命令以完成相关的安全性信息交互过程。
2. 根据权利要求 1所述的安全性信息交互系统,其特征在于,当所述安全 载体需要向所述安全性信息交互终端主动地发送命令时,所述安全载体经由所 述第一通信信道向所述安全性信息交互终端发送通知事件消息以启动所述安 全性信息交互终端和所述安全载体之间的会话。
3. 根据权利要求 2所述的安全性信息交互系统,其特征在于,在接收到所 述通知事件消息后,所述安全性信息交互终端经由所述第二通信信道向所述安 全载体发送命令读取指令以获取所述安全载体的命令,并随后处理所获取的安 全载体的命令以及将处理结果传送回所述安全载体。
4. 根据权利要求 3所述的安全性信息交互系统,其特征在于,所述安全载 体在接收到来自所述安全性信息交互终端的处理结果后向所述安全性信息交 互终端发送状态指示报文,其中 ,所述状态指示报文指示是否存在后续命令。
5. 根据权利要求 4所述的安全性信息交互系统,其特征在于,所述安全性 信息交互终端接收并解析所述状态指示报文,并且如果所述状态指示报文指示 存在后续命令,则所述安全性信息交互终端经由所述第二通信信道向所述安全 载体发送命令读取指令以获取所述安全载体的后续命令,而如果所述状态指示 报文指示不存在后续命令,则所述安全性信息交互终端终止所启动的会话。
6. 根据权利要求 5所述的安全性信息交互系统,其特征在于,所述第一通 信信道是对等模式的通信信道。
7. 根据权利要求 6所述的安全性信息交互系统,其特征在于,所述第二通 信信道是以所述安全性信息交互终端作为主动方的命令 /响应模式的通信信 道。
8. 一种安全性信息交互终端,所述安全性信息交互终端能够通过在所述 安全性信息交互终端和安全载体之间建立的第一通信信道和第二通信信道接 收并处理所述安全载体主动发起的命令以完成相关的安全性信息交互过程。
9. 一种安全载体,所述安全载体能够通过在安全性信息交互终端和所述 安全载体之间建立的第一通信信道和第二通信信道而主动地向所述安全性信 息交互终端发送命令以完成相关的安全性信息交互过程。
10. 一种安全性信息交互方法,所述方法包括下列步骤:
( A1 )在安全性信息交互终端和安全载体之间建立第一通信信道和第二通 信信道;
( A2 )所述安全载体通过所述第一通信信道和所述第二通信信道主动地 向所述安全性信息交互终端发送命令以完成相关的安全性信息交互过程。
PCT/CN2014/077776 2013-05-21 2014-05-19 安全性信息交互系统、设备和方法 WO2014187292A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US14/888,042 US10148765B2 (en) 2013-05-21 2014-05-19 Security information interaction system, device and method
EP14801484.8A EP3001634A4 (en) 2013-05-21 2014-05-19 SYSTEM, DEVICE AND METHOD FOR SECURITY INFORMATION INTERACTIONS

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310189339.6 2013-05-21
CN201310189339.6A CN104184699B (zh) 2013-05-21 2013-05-21 安全性信息交互系统、设备和方法

Publications (1)

Publication Number Publication Date
WO2014187292A1 true WO2014187292A1 (zh) 2014-11-27

Family

ID=51932860

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/077776 WO2014187292A1 (zh) 2013-05-21 2014-05-19 安全性信息交互系统、设备和方法

Country Status (4)

Country Link
US (1) US10148765B2 (zh)
EP (1) EP3001634A4 (zh)
CN (1) CN104184699B (zh)
WO (1) WO2014187292A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114503105A (zh) * 2019-09-25 2022-05-13 联邦科学和工业研究组织 用于浏览器应用的密码服务

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101576983A (zh) * 2009-06-16 2009-11-11 深圳市星龙基电子技术有限公司 一种基于移动终端的电子支付方法和系统
CN102053917A (zh) * 2010-12-29 2011-05-11 北京握奇数据系统有限公司 一种降低内存占用的智能卡及其处理指令的方法
CN202026326U (zh) * 2010-12-17 2011-11-02 北京中创智信科技有限公司 数字签名装置
CN102917357A (zh) * 2011-08-05 2013-02-06 国民技术股份有限公司 一种认证方法及装置

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8271948B2 (en) * 2006-03-03 2012-09-18 Telefonaktiebolaget L M Ericsson (Publ) Subscriber identity module (SIM) application toolkit test method and system
CN101261708A (zh) * 2008-04-21 2008-09-10 中兴通讯股份有限公司 基于支持eNFC功能移动终端的在线支付方法和系统
CN101330690B (zh) * 2008-07-25 2011-06-08 大唐微电子技术有限公司 一种实现用户识别模块非接触应用的移动终端与方法
CN101393666B (zh) * 2008-08-29 2011-08-24 中兴通讯股份有限公司 eNFC移动终端及其电子支付控制方法
CN101354802B (zh) * 2008-09-05 2010-12-22 中国网通集团宽带业务应用国家工程实验室有限公司 消费记录信息的处理方法及系统
CN101957921A (zh) * 2010-09-21 2011-01-26 中兴通讯股份有限公司 射频识别应用信息的显示方法、装置和系统
EP2461551A1 (en) * 2010-12-06 2012-06-06 Gemalto SA Method of managing asynchronous entities

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101576983A (zh) * 2009-06-16 2009-11-11 深圳市星龙基电子技术有限公司 一种基于移动终端的电子支付方法和系统
CN202026326U (zh) * 2010-12-17 2011-11-02 北京中创智信科技有限公司 数字签名装置
CN102053917A (zh) * 2010-12-29 2011-05-11 北京握奇数据系统有限公司 一种降低内存占用的智能卡及其处理指令的方法
CN102917357A (zh) * 2011-08-05 2013-02-06 国民技术股份有限公司 一种认证方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3001634A4 *

Also Published As

Publication number Publication date
EP3001634A1 (en) 2016-03-30
US20160080503A1 (en) 2016-03-17
US10148765B2 (en) 2018-12-04
CN104184699B (zh) 2018-06-22
CN104184699A (zh) 2014-12-03
EP3001634A4 (en) 2016-11-09

Similar Documents

Publication Publication Date Title
EP2858332B1 (en) Method and device for establishing a connection
US9124494B2 (en) Method and apparatus of performing remote management of a managed machine
EP3662638B1 (en) Transport method selection for delivery of server notifications
US8117318B2 (en) Electronic apparatus and communication control method
US10574518B2 (en) Method and apparatus of performing remote management of a managed machine
WO2016173434A1 (zh) 基于nfc的通信方法和装置
WO2011088779A1 (zh) 实现移动终端上不同应用程序的进程之间通信的装置和方法
US20110117847A1 (en) Electronic apparatus and communication control method
JP2016524880A (ja) Nfc無線周波数通信制御方法、装置、およびシステム
WO2010022642A1 (zh) eNFC移动终端及其电子支付控制方法
US9319492B2 (en) Method and an apparatus for controlling messages between host and controller
CN104797004A (zh) 主从设备间实现自动组网的方法
WO2014187292A1 (zh) 安全性信息交互系统、设备和方法
KR101952793B1 (ko) 가입자 아이덴티티 모듈(sim)액세스 프로파일(sap)의 개선들
JP4891393B2 (ja) コールの起点を反転するシステム及び/又は方法
JP2011250241A (ja) 通信装置及びその動作方法
TWI539319B (zh) Security Information Exchange System, Equipment and Method Based on Secure Carrier Active Command
WO2012130010A1 (zh) 流量控制方法及装置
CN113032123B (zh) 一种远程npl运行环境的线程调度方法、系统及相关装置
GB2617297A (en) Bluetooth connection method and system, intelligent terminal and computer storage medium
CN107770230B (zh) 超文本传输协议请求的处理方法、装置及Web服务器
WO2015029559A1 (en) Communications system
KR101328903B1 (ko) 확장 인증 프로토콜 패킷 유실에 따른 사용자 단말의초기화 방법
WO2011143850A1 (zh) 反馈设备管理服务器处理结果的方法、终端设备及系统
OA16900A (en) Method, device and system for establishing conversation relation.

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14801484

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14888042

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2014801484

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE