Smart card personalization in multistation environment
Abstract
Problem to be solved.To cause a smart card personalization system to provide an interface to smart card personalization stations and to external computing or data resources which are not available directly.
Solution.A card issuer management system prepares card objects and assigns a unique card object identifier. A smart card personalization server receives the card objects from the card issuer management system. A smart card personalization controller receives the unique card object identifiers and routes the card object identifiers to waiting personalization stations. The personalization stations use the card object identifier to request data and services from the smart card personalization server in order to personalize the smart card. The smart card personalization server supports multiple active personalization station sessions.
Copyright (C)2010,JPO&INPIT

Term
Projected expiry 17 March 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1In a method of controlling the programming of a portable programmed data carrier in a system having a plurality of personalized stations, a step of receiving a card object from a card issuer management system, wherein the card object is said portable. A step consisting of information for programming a programmed data carrier, a step of receiving a programming request from one of the personalized stations, and the personalized station being portable using the card object. A method comprising controlling the personalized station to program a programmed data carrier. 複数の個人専用化ステーションを有するシステムにおいて携帯可能なプログラムされるデータキャリアのプログラミングを制御する方法において、 カードオブジェクトをカード発行者管理システムから受信するステップであって、該カードオブジェクトが前記携帯可能なプログラムされるデータキャリアをプログラムするための情報から成るステップと、 前記個人専用化ステーションの一つからプログラミング要求を受信するステップと、 前記カードオブジェクトを使用して前記個人専用化ステーションが前記携帯可能なプログラムされるデータキャリアをプログラムするように前記個人専用化ステーションを制御するステップと、を含む方法。
47 paragraphs, as filed
The present invention relates generally to data storage devices, and more specifically to the control of personalization of smart cards in a multi-station environment.
As the number of organizations issuing transaction cards to consumers, customers or employees grows, there is a need for cards designed to meet the service or application requirements specific to that organization. These organizations also need cards that contain data about cardholders. Current transaction cards encode such data within a magnetic stripe on the back of the card, but the amount of data that can be placed on the magnetic stripe is limited. A new type of transaction card embeds a microprocessor computer chip inside the card's plastic to greatly increase the card's data storage capacity. In addition, advanced card applications specific to card issuers can run on a variety of chips, and the chips may include a type of operating system. Transaction cards with embedded chips are more commonly referred to in the industry as so-called "smart cards" as portable programmed data carriers. Chips in smart cards are generally programmed with initialization and / or personalized data at the same time that the surface of the card is embossed and / or printed.
Initialization data consists of three main types of information: application data, security data, and print data. Application data is common to all cards for a given card application and contains application program code and variables. Security data prevents unauthorized use of the card and is usually given in the form of a "safety key". Printed data such as logos, barcodes, and various numerical information are placed on the surface of the card. Some or all of the same data may be highlighted on the surface. Optical technology can also be used to make part or all of the card surface a data storage medium accessible by a suitable optical reader.
Smart cards are also programmed with information unique to each cardholder through a process called "personalization." Personalized information for smart cards is similar to the personalized information currently contained on non-smart cards, such as the cardholder's name, membership number, card expiration date and photo. Due to its increased storage capacity, smart card chips have a graphic representation of personal signatures other than the basic information of standard transaction cards, data that defines the service type given to cardholders, and of those services. It can have additional data in it, including transaction limits.
Current systems that perform smart card initialization and / or personalization include controllers or personal computers connected to personalization stations. All smart card programming data required for the personalization process is sent from the controller or personal computer to the personalization station that programs the smart card. An application running on a personalized station controls smart card programming. Many current personalized stations have limited capacity to handle increasingly sophisticated personalized processes due to the increasing size and functionality of smart card computer chips. Such limitations include the memory, processing power and buffer size of the personalized station.
In addition, personalized stations may require access to security services or external resources that provide access to card data. External resources, especially security services, are a costly infrastructure to repeat for each personalized station. Communication between a personalized station and an external resource is also limited by the speed of the communication link between them. In addition, there is only one application development environment available at personalized stations, often lacking development tools.
Therefore, there is a need for a personalized system that overcomes the limits of memory capacity and processing flexibility of current personalized stations. There is also a need for personalized systems that can share external resources among multiple personalized stations.
The present invention is directed to the shortcomings recognized above and other shortcomings, which can be understood by reading and reviewing the following specification. The present invention is a computerized system for controlling the programming of a portable programmed data carrier across all of a plurality of personalized stations. The system gets services from one of many more resources, transfers card information to one of the personalized stations, and personalized server interface that controls the programming of portable programmed data carriers. including. The system also includes a personalized station interface for receiving card information from a personalized server interface and programming a portable programmed data carrier.
A method of controlling the programming of a portable programmed data carrier in a system having a plurality of programming stations is also described in the present invention. The method also involves receiving one or more card objects from the card issuer's management system. A card object consists of information that programs a portable programmed data carrier. The method also includes receiving programming requests from the programming station and utilizing the card object to control the programming station to program the programming station with a portable programmed data carrier.
A computerized system that includes means of receiving one or more card objects from a card issuer's management system is alternative described in the present invention. Computerized systems also include means of receiving programming requests from the programming station and utilizing card objects to control the programming station to program portable programmed data carriers.
A smart card personalization system has a data field that represents a card object that contains information for programming a portable programmed data carrier and an additional data field that contains a unique card object identifier to identify the card object. Use a data structure consisting of.
Therefore, the smart card personalization system of the present invention shares external resources among a plurality of personalization stations. Other aspects and advantages of the present invention will become apparent by reading the drawings and the detailed description below.
<figref num="1">It is a block diagram which shows the Example of the smart card issuance processing which incorporates the smart card personalization server of this invention.</figref><figref num="2">It is a functional block diagram which shows the input / output connection of the embodiment of the smart card personalized server shown in FIG.</figref><figref num="3">It is a block diagram which shows one Example of the smart card personalization software of this invention.</figref><figref num="4">It is a high-level flowchart of an embodiment of software that realizes the function of a smart card personalized server.</figref>
In the detailed description of the examples below, reference is made to the accompanying drawings, which form a portion thereof and are shown by the particular embodiment represented in the figure in which the present invention can be practiced. These examples are described in sufficient detail to allow one of ordinary skill in the art to practice the invention, and other examples may be used, and structural, logical and electrical changes are in the spirit of the invention. It should be understood that it can be changed without departing from the scope. The following detailed description should therefore not be taken in a limited sense and the scope of the invention is limited only by the appended claims.
The leading digit of the reference number appearing in a drawing usually corresponds to the drawing number, except that the same component appearing in a plurality of drawings is identified by the same reference number.
The system of the present invention utilizes a personalized server to control smart card personalization in an environment having a plurality of personalized stations. The personalized server is not directly available to multiple card personalized stations and is usually a card personalized station, or is repeated for each card personalized station with inefficient external arithmetic or data resources. Provides an interface to.
The detailed description of the present invention is divided into four parts. The first part provides an outline of an embodiment of a smart card issuing system incorporating the smart card personalized server of the present invention. The second part describes the functional specifications of the software components of the exemplary embodiment of the smart card personalized system. The third part shows an exemplary communication sequence between the personalized station interface software and the personalized server software for the smart card personalization process. The fourth part is a conclusion including a summary of the advantages of the present invention.
(Outline of Smart Card Personalization System) FIG. 1 shows a component of a smart card issuance process incorporating an embodiment of the smart card personalization server of the present invention. The smart card personalization server 100 receives a card object from the card issuer management system 150. The smart card personalization controller 120 receives the card object identifier of each card object passed from the card issuer management system 150 to the smart card personalization server 100. The smart card personalization controller 120 sends each card object identifier to one of the plurality of personalization stations 130. Each personalized station 130 uses the card object identifier to request data and services from the smart card personalized server 100 to personalize the smart card 160.
The card issuer management system 150 manages the data of the cardholder, the type of card to be issued, the card application to be embedded in the card, and what personalized device for issuing a card for a specific cardholder. Decide whether to use.
The smart card personalized server 100 is shown in FIG. 1 as a computer running the personalized server software, as further described below. Personalized server software is under operating systems such as Unix®, Windows® 95 or Windows® NT, and industry standard workstation and / or personal computer hardware. Execute on the wear. As described below, the smart card personalization server 100 provides an interface to the card personalization station 130 and an external arithmetic or data resource 180.
The server 100 controls a card printer, an embossing device, and an integrated or add-on smart card interface device collectively represented in FIG. 1 as a plurality of personalized stations 130. The personalized station 130 also includes mass card printers / embossing devices, low volume card printers / embossing devices, automated teller machines (ATMs), point-of-sale (POS) terminals, unmanned stores, personal computers, network computers, and online electricity. Represents a device such as a communication device. The physical connection between each device and the smart card personalized server 100 depends on the device manufacturer and model. Common industry standard connections include series RS232, SCSI (Small Computer System Interface), Ethernet®, and series TTL (Transistor Transistor Logic). In addition, some devices require a dedicated bus connection.
The connection between the smart card personalized server 100 and the card management system 150 and station 130 is a standard local area network, wide area network, dedicated telephone line or other remote communication infrastructure used for data transfer. It can also be realized by. Alternative connections are obvious to those of skill in the art and are within the scope of the present invention.
FIG. 2 is a block diagram of an embodiment of a smart card personalized system showing a logical input / output connection of the smart card personalized server 100. Cardholder data 202 entered and maintained by the card issuer contains unique information about each cardholder, such as name, membership number, card expiration date, and applicable services. The card issuer management system 150 collects the data required for each card personalized job. The data for each job can be stored in card object data storage, such as a database, with each card object 208 accessible by a unique card object identifier. The job can be, for example, a logical grouping of similar card objects.
Card object 208 includes data and commands for magnetic stripe coding, embossing, printing, packaging and smart card personalization, for example, without limitation. An exemplary card object is shown below.
<maths num="1"><img file="JP2010146597A_D0001.tif" /></maths>
The exemplary card object begins with the embossing command "EMB" followed by the corresponding cardholder data to be embossed on the card. The second line of the card object example shown above is the coding instruction "ENC" followed by the data corresponding to the corresponding cardholder data to be encoded on the magnetic stripe of the card. The third line of the card object example is the instruction "PIC" for printing a photo on the card, followed by the position of the cardholder's photo. The fourth line of the card object example is the smart card part "SCRD" of the card object. The smart card portion of card object 208 consists of a unique card object identifier.
The card issuer management system 150 sends the card object 208 to the smart card personalized server 100. The smart card personalized server 100 expects the personalized data to be in a specific format. Since the card object 208 depends on the format defined by the card issuer but is often different from the format expected on the server 100, the card object 208 is converted on the server 100 if necessary. One method of converting card objects is described in US Patent Application No. 08/755459, "Smart Card Personalization Systems and Devices," filed November 22, 1996.
The smart card personalization server 100 provides an interface to the external security service 204 and the additional data resource 206 as it is needed to execute the smart card personalization job. The software program of the smart card personalized server 100 can be combined with the data resource 206 by a standard data query instruction that provides access to the data stored in the data resource. The communication protocol between the software program of the smart card personalized server 100 and the external security service 204 and the data resource 206 varies depending on the basic data management system or security system used.
The smart card personalization server 100 also provides an interface to each of the plurality of card personalization stations 130. The smart card personalization controller 120 sends the card object identifier to one of the standby personalization stations 130. The personalization station 130 passes the card object identifier to the server 100 to initiate access to the data, security, or support services required to complete the smart card personalization. Upon receiving the card object identifier from the personalization station 130, the smart card personalization server 100 converts the card object indicated by the card object identifier. The conversion of the card object by the smart card personalization server 100 is a sequence of instructions and / or data passed to the personalization station 130. The personalization station 130 sends the instructions and data received from the server 100 directly to the smart card 160. A processing example showing how the server 100 controls actual card programming is described below.
(Specification of personalized software) FIG. 3 is a block diagram showing an embodiment of the smart card personalized server 100 of FIG. The system of the present invention uses the personalization server 100 to control smart card personalization in an environment having a plurality of personalization stations 130 connected to the personalization server 100. The personalized server 100 provides an interface to the card personalized station 130 and external arithmetic or data resources 204, 206 as shown in FIG.
An application running on the card issuer management system 150 prepares a card object 303 and assigns a card object identifier to each object. Information about the card object is archived in the card object database 302 until called by the personalization server 100 to personalize the smart card.
The personalized environment of the present invention is composed of two complementary software components. The first is personalized station interface software 304 running on the processor of personalized station 130. The second is personalized server software 305, which processes personalized card objects and runs on the processor of personalized server 100, which uses both local and external resources.
The initialization process 306 launches a personalized job by starting the personalized server 100 and optionally sending data such as embossed or magnetic stripe coded data to the personalized station 130. To do. The personalized server software 305 supplies multiple card personalized processes 308. Each card personalization process 308 represents a personalization job that occurs at one of the personalization stations 130. Each of the card personalization processes 308 is logically connected to one of the personalization stations 130.
The personalized station interface software 304 gives the personalized server software 305 a unique card object identifier to invoke access to services available by the server software 305. The personalized server software 305 obtains all the necessary job information and data elements that should be used in the personalization of the smart card. The personalized station interface software 304 implements the personalization of the card using the services available by the personalized server software 305, which is required until the personalization is completed. Upon completion of the job, the personalized station interface software 304 is notified by the server software 305 of completion.
Services provided by server software 305 include data service 312, security service 310 and support service 314. Data Service 312 includes any generally available means of acquiring and accessing data for each personalized job. Data service 312 retrieves data archived in the card object database 302 on the card issuer management system 150 and from additional external data resources, as shown in Figure 2. The data may be in the form of files, databases or, for example, data structures.
Security service 310 interfaces with a variety of different external resources that provide security features. Security features provided by external resources include any commonly available means of protecting information or restricting access to smart card chips until the required security conditions are met. The security function example uses one or more "safety keys" programmed in the chip to prevent unauthorized use of the card. Appropriate "security key" data is obtained by the smart card personalized server software 305 from the security key record maintained by the card issuer or external security resources and then transferred to the personalized station interface software 304. To. Security service 310 also provides security features that can be used, for example, to ensure data integrity and secrecy during data transmission to and from personalized station 130.
Support service 314 performs the processing of tasks that were previously performed by the personalized station 130 in the system or could not be performed at all due to the limitations of the personalized station. Support service 314 includes any commonly used features that can be shared between each process, such as data conversion and validation. An example of support service 314 is the validation process dated 2000. An additional example of Support Service 314 is formatting 10 numeric strings with numbers representing phone numbers so that the area code is in parentheses.
Personalized server software 305 includes one or more high-speed processors, data communication capabilities compatible with purpose personalized stations, access to external resources such as security or file servers, and a multitasking operating system. It runs on a computer system. The smart card personalization process 308 is identified as a component of the personalization server software 305 and uses its own virtual memory and is resourced by threading or other common methods well known to those skilled in the art. As appropriate.
In summary, the personalized server software moves the processing tasks for smart card initialization and personalization from the personalized station to the personalized server. The personalized station interface software is responsible for servicing individual commands from the personalized server software.
(Personalized Software Communication Processing) FIG. 4 shows a communication sequence between the personalized station interface software 304 and the personalized server software 305 to complete the personalization of the smart card. The smart card personalization process is initiated at step 402 when the personalized station interface software 304 receives a unique card object identifier from the smart card personalized controller, as shown in FIG. At step 404, the personalized station interface software 304 requests the commands and data needed to personalize the card by sending the card object identifier to the server software 305. Upon receiving the card object identifier, the server software 305 initiates a personalized session with the personalized station interface software 304 in step 406.
Based on the card object identifier, the server software 305 retrieves the card-specific data and commands that are becoming personalized in step 408 and sends them to the personalized station interface software 304. Data and commands are retrieved locally from a smart card personalized server or from additional external data resources such as those shown in Figure 2, including the card issuer management system 150.
In one embodiment, the personalized station interface software 304 is idle until it receives commands and data from the personalized server software 305. Upon receiving the command and data, the personalized station interface software 304 passes the command and data directly to the smart card, and at step 412 returns the data and / or status signal to the server software 305 as an affirmative response. An example of the data returned by the personalized station interface software 304 is a card-specific sequence number and a random number. The data in such cases can be used as part of the functionality provided by security services such as authentication algorithms. At step 414, the server software 305 processes the status signal and / or data returned by the personalized station interface software 304.
For example, in step 408, server software 305 sends a "select" command. The personalized station interface software 304 is not used in step 410 until it receives a "select" command from the server. At step 412, the personalized station interface software 304 passes a "select" command to the smart card and returns a status signal to the server software 305 as an acknowledgment. After receiving the acknowledgment in step 414, the server software 305 sends a "write" command and related data to the personalized station interface software 304 in step 408. The personalized station interface software 304 is not used in step 410 until it receives a "write" command from the server software 305. At stage 412, the personalized station passes a "select" command to the smart card and returns a status signal to the server software 305 as an acknowledgment. The loop from stage 408 to stage 410 to stage 412 to stage 414 continues until personalization is complete.
When the smart card has been personalized, the server software 305 sends a "format complete" command to the personalized station interface software 304 in step 416. The personalized station interface software 304 is not used in step 418 until it receives a "format complete" command from the server software 305. At step 420, the personalized station interface software 304 sends an acknowledgment of the "format complete" command to the server software 305 and the smart card. The personalization process is completed in step 422 when the server software 305 receives an acknowledgment.
(Conclusion) In summary, the system of the present invention uses a personalization server to control smart card personalization in an environment having multiple personalization stations. The personalized server provides an interface to multiple card personalized stations and external arithmetic or data resources, but the external arithmetic or data resources are usually not directly available to the card personalized station, or each card is individual. Not cost effective to replicate on a dedicated station. The personalized server unloads the smart card initialization and personalized task processing from the personalized station to the personalized server. The personalized station is responsible for servicing individual orders from the personalized server.
The advantage of the present invention is that the personalized server can support sessions of multiple running personalized stations. A further advantage is that the programming logic required at the personalized station is reduced to the programming logic that manages the data transfer.
Other mechanisms for controlling the smart card personalization process will be apparent to those skilled in the art. It should be understood that the above description is exemplary and intended not to be limiting. Reviewing the above description will reveal many other embodiments to those skilled in the art. Therefore, the scope of the present invention should be determined with respect to the scope of the appended claims, along with the full scope of the equivalents to which such claims are entitled.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO9739424A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JPH07334631A | Cites | Japan | Examiner |
| JPH08147421A | Cites | Japan | Examiner |
| JPH08212310A | Cites | Japan | Examiner |
22 members in 11 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 09076022 | United States of America | – | |
| 7602298 | United States of America | A | |
| 7602298 | United States of America | A | |
| 1998076022 | – | – | – |
| US19980076022 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| CA2331494A1 | Canada | A1 | |
| CA2709296A1 | Canada | A1 | |
| WO9959109A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3898599A | Australia | A | |
| TW381242B | Taiwan Province of China | B | |
| BR9910382A | Brazil | A | |
| EP1078336A1 | European Patent Office (EPO) | A1 | |
| US6196459B1 | United States of America | B1 | |
| KR20010043515A | Republic of Korea | A | |
| US2001007333A1 | United States of America | A1 | |
| CN1310831A | China | A | |
| JP2002514826A | Japan | A | |
| MY117046A | Malaysia | A | |
| US2004256451A1 | United States of America | A1 | |
| US7500601B2 | United States of America | B2 | |
| US2010001064A1 | United States of America | A1 | |
| CN1310831B | China | B | |
| JP2010146597AThis record | Japan | A | |
| CA2331494C | Canada | C | |
| JP4806081B2 | Japan | B2 | |
| US2012267435A1 | United States of America | A1 | |
| CA2709296C | Canada | C |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Written permission of extension of timeA602 | A602 | |
| Written request for extension of timeA601 | A601 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2010146597
- Publication, DOCDB
- 2010146597
- Publication, EPODOC
- JP2010146597
- Application
- 61547
- Application, DOCDB
- 2010061547
- Application, EPODOC
- JP20100061547
Titles2
- Japanese
- マルチステーション環境におけるスマートカードの個人専用化
- English
- Personalization of smart cards in a multi-station environment
Classification
- CPC, 5
- G07F7/1008
- G06F3/08
- G06Q20/341
- G06Q20/355
- G06K19/07716
- IPC, 4
- G06K17 00
- G06Q40 00
- G06Q20 34
- G07F7 10