Key distribution method and system
Abstract
A method and a system for key distribution are provided by the invention. The method includes that: the application provider management platform notifies its corresponding application provider secondary security domain set on the smartcard to generate a public/private key pair including a public key and a private key; the application provider management platform receives the public key which has been processed by the encryption using the pre-obtained application provider's public key and the signature of Controlling Authority Secondary security Domain (CASD) set on the smartcard from the application provider secondary security domain through the card issuer management platform; the application provider management platform verifies the signature, performs the decryption using the private key of the application provider, and gets the public key; after being processed by the encryption using the public key of the application provider secondary security domain and then the signature using the private key of the application provider for the encrypted data, the certificate of the application provider secondary security domain and the public key for the trusted root for external authentication are sent to the application provider secondary security domain from the application provider management platform through the card issuer management platform.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
9 claims: 1 independent, 8 dependent
- 1权 利 要 求 书 1. 一种密钥分发方法, 其特征在于, 包括: 应用提供商管理平台通知所述应用提供商管理平台对应的设置于 智能卡上的应用提供商从安全域生成包括公密钥和私密钥的公私密钥 对; 所述应用提供商管理平台通过卡发行商管理平台接收来自所述应 用提供商从安全域的经过预先获得的应用提供商的公钥加密、 以及经过 设置于智能卡上的可信任第三方从安全域即 CASD签名处理的所述公密 钥; 所述应用提供商管理平台验证签名并使用所述应用提供商的私钥 进行解密得到所述公密钥; 所述应用提供商管理平台将所述应用提供商从安全域的证书和用 于外部认证的可信任才艮的公钥 , 在经过所述应用提供商从安全域的公密 钥力。密、 以及经过所述应用提供商的私钥对力。密后的数据签名处理后通 过所述卡发行商管理平台发送至所述应用提供商从安全域, 完成对所述 从安全域密钥的分发。
- 2根据权利要求 1所述的方法, 其特征在于, 在所述应用提供商管理平台 通知所述应用提供商从安全域生成所述公私密钥对的处理之前 , 所述方 法还包括: 所述应用提供商管理平台 夺所述应用提供商的证书发送至所述应 用提供商从安全域, 以使所述应用提供商从安全域验证所述应用提供商 的证书; 在所述应用提供商的证书被验证通过的情况下,执行所述应用提供 商管理平台通知所述应用提供商从安全域生成所述公私密钥对的处理。
- 3根据权利要求 2所述的方法, 其特征在于, 所述应用提供商管理平台将 所述应用提供商的证书发送至所述应用提供商从安全域的处理具体包 括: 所述应用提供商管理平台获得所述 CASD的公钥; 所述应用提供商管理平台将所述应用提供商的证书利用所述 CASD 的公钥加密, 并将加密的所述应用提供商的证书通过卡发行商管 理平台发送至所述应用提供商从安全域。
- 4根据权利要求 3所述的方法, 其特征在于, 所述应用提供商管理平台获 得所述 CASD的公钥的处理具体包括: 所述应用提供商管理平台通过所述智能卡获得所述 CASD的证书; 所述应用提供商管理平台验证所述 CASD 的证书, 并获得所述 CASD的公钥。
- 5根据权利要求 2至 4中任一项所述的方法, 其特征在于, 在所述应用提 供商的证书被所述应用提供商从安全域验证通过后 , 所述方法还包括: 所述应用提供商从安全域通过所述应用提供商的证书获得所述应 用提供商的公钥。
- 6根据权利要求 5所述的方法, 其特征在于, 所述应用提供商管理平台将 所述应用提供商从安全域的证书和用于外部认证的所述可信任才艮的公钥 发送至所述应用提供商从安全域之后, 所述方法进一步包括: 所述应用提供商从安全域接收经过加密以及签名处理的所述应用 提供商从安全域的证书和用于外部认证的可信任根的公钥; 所述应用提供商从安全域利用所述应用提供商的公钥验证签名 ,在 验证通过的情况下, 利用所述应用提供商从安全域的私钥进行解密, 获 得所述应用提供商从安全域的证书和用于外部认证的所述可信任根公 钥。
- 7才艮据权利要求 6所述的方法, 其特征在于, 所述应用提供商管理平台向 应用提供商证书中心申请所述应用提供商从安全域的证书。
- 8根据权利要求 1所述的方法, 其特征在于, 在应用提供商管理平台获得 所述 CASD的公钥之前, 所述方法进一步包括: 卡发行商管理平台在所述智能卡上创建所述应用提供商从安全域, 并将所述应用提供商从安全域的基本信息发送至所述应用提供商管理平 台, 其中, 所述基本信息包括所述应用提供商从安全域的标识信息、 所 述应用提供商从安全域的配置信息。
- 9一种密钥分发系统, 其特征在于, 包括: 卡发行商管理平台, 其进一步包括: 创建模块 , 用于在智能卡上创建应用提供商从安全域; 信息发送模块 , 用于将所述应用提供商从安全域的基本信息 发送至应用提供商管理平台, 其中, 所述基本信息包括所述应用 提供商从安全域的标识信息以及配置信息; 应用提供商管理平台, 其进一步包括: 通知模块, 用于通知所述应用提供商从安全域生成包括公密 钥和私密钥的公私密钥对; 第一接收模块 , 用于接收来自所述应用提供商从安全域的所 述公密钥, 其中, 所述公密钥经过预先获得的应用提供商的公钥 加密、 以及经过设置于智能卡上的 CASD签名处理; 第一获取模块 , 用于验证签名并使用所述应用提供商的私钥 进行解密得到所述公密钥; 第一发送模块, 用于将经过所述公密钥加密、 以及经过所述 应用提供商的私钥对加密后的数据签名的所述应用提供商从安全 域的证书和用于外部认证的可信任才艮的公钥 , 发送至所述应用提 供商从安全域; 所述智能卡,位于移动终端, 包括所述应用提供商从安全域,其中, 所述应用提供商从安全域进一步包括: 第二获取模块, 用于获取所述应用提供商的公钥; 第二发送模块, 用于将经过所述应用提供商的公钥加密、 以 及经过 CASD签名处理的所述公密钥发送至所述应用提供商管理 平台; 第二接收模块 , 用于接收经过加密以及签名处理的所述应用 提供商从安全域的证书和用于外部认证的可信任根的公钥; 解密模块, 用于将所述接收模块接收的数据利用所述应用提 供商的公钥验证签名 , 并验证通过的情况下利用所述应用提供商 从安全域的私钥进行解密, 以获得所述应用提供商从安全域的证 书和用于外部认证的所述可信任才艮公钥。 0. 根据权利要求 9所述的系统, 其特征在于, 所述智能卡还包括: CASD, 用于验证所述应用提供商的证书以及签名所述公密钥。
Independent claims9
8 paragraphs, as filed
0001Key distribution method and system
0002TECHNICAL FIELD The present invention relates to the field of communications, and in particular, to a key distribution method and system. BACKGROUND OF THE INVENTION In the related art, Near Field Communication (NFC) is a short-range wireless communication technology operating at 13.56 MHz, which is defined by radio frequency identification (Radio Frequency Identification). The convergence of technology and interconnection technologies has evolved. After integrating NFC technology, a mobile communication terminal such as a mobile phone can simulate a contactless IC card for related applications of electronic payment; in addition, implementing the solution on a mobile communication terminal requires adding an NFC analog front end chip and an NFC antenna to the terminal. And use a smart card that supports electronic payment.
0003IC cards, especially non-contact IC cards, have been widely used in public transportation, access control, and small-scale electronic payment after more than ten years of development. At the same time, after more than 20 years of rapid development, mobile phones have been basically applied. It has gained popularity and brought great convenience to people's work and life. Therefore, combining mobile phones with non-contact IC card technology and applying mobile phones to the field of electronic payment will further expand the use of mobile phones, bring convenience to people's lives, and have broad application prospects. In the related art, in order to implement mobile electronic payment based on NFC technology, it is necessary to establish an electronic payment system for a mobile terminal, and implement management of electronic payment for the mobile terminal through the system, wherein the electronic payment system of the mobile terminal includes: distribution of the smart card, and electronic Download, install, and personalize payment applications, and use related technologies and management strategies to secure electronic payments. A security domain is a representation of an off-card entity (including card issuers and application providers) on a smart card that contains encryption keys to support secure channel protocol operation and card content management, if the electronic payment system supports the Global platform Card Specification V2 The .1.1 specification, Secure Channel Protocol supports Secure Channel Protocol '02, (based on symmetric key); if the electronic payment system supports the Global platform Card Specification V2.2 specification, the secure channel protocol supports Secure Channel Protocol '10, (based on asymmetric secrets) key). Security i or responsible for its own key management, which ensures that applications and data from different application providers can coexist on the same card. When the key of the security domain adopts an asymmetric key system, the keys and certificates on the security domain need to include: the public key (also called public key) and the private key (also called private key) of the security domain. , the certificate of the security domain, and the trusted public key used to authenticate the certificate of the entity outside the card. The application provider's security domain on the smart card is the slave security domain. Before downloading and installing the application provider's electronic payment application to the smart card, You need to create the application provider's secondary security domain on the smart card first through the smart card master security domain owned by the card issuer, and then set the key from the security domain. The secure domain key is confidential and requires reliable and secure methods and techniques to import the relevant keys and certificates into the secure domain to enable secure distribution of keys from the secure domain, where the creation of the secure domain requires the card The publisher management platform indicates the creation of the primary security domain on the smart card, And after the security domain is created, The initial key from the security domain needs to be set up and distributed by the card issuer management platform. One method adopted from security domain creation and key distribution is: smart card and card issuer management platform establish communication, application provider management platform establishes communication with card issuer management platform; card issuer management platform indicates smart card master security The domain is established from the security domain, and the public and private key pairs from the security domain are generated by the slave security domain on the card and sent to the card issuer management platform, and then the card issuer management platform sends the key generated from the security domain to the application. The provider management platform, the application provider management platform issues the certificate from the security domain according to the public key of the security domain. Through the card issuer management platform, the security domain certificate and the trusted certificate public key are imported into the slave security domain, thereby completing the distribution of the security domain key. However, in this case, when the card issuer management platform is responsible for data transmission, it is possible to obtain the transmitted security domain key data, and may use the obtained key pair to perform operations from the security domain, thus applying the application provider electronic payment application. The security poses a threat. Therefore, there is an urgent need for a technical solution to solve the problem of unsecure distribution of secret domain keys. SUMMARY OF THE INVENTION The present invention has been made in view of the problem of unsafe distribution of a security domain key in the related art, Accordingly, it is a primary object of the present invention to provide a key distribution method and system that avoids the problem of obtaining a key insecure from a secure domain key by a card issuer management platform. According to an aspect of the present invention, a key distribution method is provided. The key distribution method according to the present invention includes: the application provider management platform notifying the application provider corresponding to the application provider management platform that the smart card is configured to generate a public-private key pair including the public key and the private key from the security domain; The provider management platform receives the public key encryption of the pre-obtained application provider from the security domain by the application provider through the card issuer management platform, and the public key processed by the CASD signature set on the smart card; application provider management The platform verifies the signature and decrypts using the application provider's private key to obtain the public key; the application provider management platform provides the application provider from the security domain's certificate and the trusted authentication public key for external authentication. The public key encryption of the security domain and the encrypted data signature processing by the application provider's private key are sent to the application provider from the security domain through the card issuer management platform to complete the distribution of the security domain key. . According to another aspect of the present invention, a key distribution system is also provided. The key distribution system according to the present invention comprises: a card issuer management platform, comprising: a creation module for creating an application provider slave security domain on the smart card; and an information sending module for using the application provider from the security domain The basic information is sent to the application provider management platform, where the basic information includes the identification information of the application provider from the security domain, the configuration information of the application provider from the security domain, and the application provider management platform, which includes: a notification module, configured The application provider configured on the smart card corresponding to the application provider management platform generates a public-private key pair including a public key and a private key from the security domain; and the first receiving module is configured to receive the security domain from the application provider. a public key, wherein the public key is encrypted by a public key of the application provider obtained in advance, and processed by a CASD signature set on the smart card; the first obtaining module is configured to verify the signature and use the private key of the application provider Decrypting to obtain a public key; a first sending module, used to pass the application provider from the security domain Key encryption, as well as through private trusted application provider application provider signed data encrypted certificate from the security domain and an external authentication only Burgundy's public key, Sending to the application provider from the security domain; the smart card, located in the mobile terminal, including the application provider from the security domain, wherein the application provider further includes: a second obtaining module, configured to obtain the public key of the application provider; a sending module, configured to send the public key encrypted by the application provider and the public key processed by the CASD signature to the application provider management platform; and the second receiving module is configured to receive the application provider that is encrypted and signed. a certificate from the security domain and a public key of the trusted root for external authentication; a decryption module for authenticating the data received by the receiving module with the application provider's public key and verifying the use of the application provider The private key of the security domain is decrypted to obtain the certificate of the application provider from the security i or the trusted public key for external authentication. With the above technical solution of the present invention, the application provider encrypts the generated secure domain key generated on the card from the security domain by using the public key of the pre-obtained application provider, and sends it to the application provider management platform, and the application provider management platform Encrypting and transmitting to the slave domain from the security certificate of the security domain and the public key of the trusted domain from the security domain's public key by the pre-obtained application provider; the card issuer management platform is responsible for application provider management Data transfer between the platform and the application provider from the secure domain, However, the card issuer management platform cannot obtain the private key of the application provider and the application provider from the security domain. Therefore, the data cannot be decrypted to obtain the key from the security domain. The isolation of the card issuer management platform is realized, and the security of the application provider from the secure domain key distribution is effectively guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings, which are set to illustrate,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 is a block diagram showing the structure of a mobile terminal electronic payment system according to an embodiment of the present invention; FIG. 2 is a block diagram of a key distribution system according to an embodiment of the system of the present invention; A flowchart of a key distribution method of an embodiment of the inventive method; FIG. 4 is a flow chart of a selection processing scheme of a key distribution method according to an embodiment of the method of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The main idea of the present invention is that an application provider encrypts and transmits a slave security domain key generated on a card from a security domain using a public key of a previously obtained application provider to the application provider management platform; The application provider management platform pre-acquires the public key of the application provider from the security domain, And using the public key to encrypt and send the application provider's certificate from the security domain and the trusted public key for external authentication to the slave security domain, so that the card issuer management platform cannot obtain the application provider and The application provider takes the private key of the security domain and cannot decrypt the data, so the key from the security domain cannot be obtained. The CASD on the smart card is only responsible for the verification of the certificate and the signature of the data. It does not know the private key of the application provider and the application provider from the security domain, and cannot decrypt the data, and thus cannot obtain the key from the security domain. Therefore, the application provider implements the isolation of the card issuer management platform from the key distribution process of the security domain, thereby effectively ensuring the security of the application provider from the security domain key distribution. The preferred embodiments of the present invention are described in the following with reference to the accompanying drawings, which are intended to illustrate and illustrate the invention. System Implementation As shown in FIG. 1, a mobile terminal electronic payment system according to an embodiment of the present invention is mainly composed of a card issuer management platform 1, an application provider management platform 2, and a mobile terminal 3 including a smart card, which may exist in the system. Application provider management platform. The card issuer management platform 1 includes a card management system 10, an application management system 11, a key management system 12, a certificate management system 13, and an application provider management system 14, Wherein, the certificate management system 13 is used when the mobile terminal electronic payment system based on the near field communication technology supports the asymmetric key, and the certificate management system 13 and the card issuer CA (Certificate Center) system are connected; the application supply and management function; The application provider management system 14 can manage information about the application provider, specify the service authority of the application provider, and the like. Further, the card issuer management platform 1 owned by the card issuer uses the certificate management system 13 only in the case of supporting an asymmetric key. The card issuer management platform 1 is responsible for managing the resources and lifecycle, keys, and certificates of the card, and is responsible for creating the slave security domain of the application provider. The application provider management platform 2 includes an application management system 20, a key management system 21, and a certificate management system 22, Wherein, the certificate management system 22 is used in the case where the mobile payment system supports an asymmetric key, the certificate management system 22 and the application provider CA system are connected, and the certificate management system 22 is used only in the case of supporting an asymmetric key. Moreover, the application provider can provide various service applications through the application provider management platform 2, and manage the security domain corresponding to the card, control the application key, certificate, data, etc. of the security domain, and provide the application. Secure download function. The application provider can be an operator, a bank, a bus company, a retailer, and the like. In addition, the application provider can have a business terminal management system and a service terminal, and can provide monthly services to the user through the service terminal. The mobile terminal 3 is provided with a smart card (not shown) supporting electronic payment, and in order to implement the security management of the smart card and the downloading and installation functions of the payment application, the smart card requires the card issuer management platform 1 and the application provider management platform. 2 Establish communication. The communication between the smart card and the management platform (the above-mentioned card issuer management platform 1 and the application provider management platform 2) can be achieved in two ways: (1) The smart card establishes communication through the mobile terminal using the mobile communication network and the management platform, generally using over-the-air downloading (Over The Air, The cartridge is called OTA. Technology enables communication between smart cards and management platforms. (2) Realize the connection between the smart card and the management platform through the business terminal of the management platform. The service terminal is configured with a contactless card reader or a card reader that directly reads the smart card, and the service terminal can establish communication with the management platform, thereby realizing communication between the smart card and the management platform. In the above mobile payment system, the user can download, install, and use the electronic payment application, and the user operates the mobile terminal and the smart card by interacting with the card issuer management platform or the application provider management platform, and downloading in the secure domain and Install new applications, using the various business applications provided by the card publisher management platform or the application provider management platform. The mobile terminal electronic payment system based on the near field communication technology supports a multi-electronic payment application, and multiple electronic payment applications can be installed on the smart card. In order to realize the security of the payment application, the smart card adopts the Global Platform Card Specification V2.1.1 V2.2 specification, and the smart card is divided into several independent security i or to ensure isolation and independence between multiple applications, each application provider Manage their own security domains as well as applications, application data, and more. The smart card that supports the Global Platform specification mentioned here refers to the Global Platform Card Specification V2.1. 2.2 Specification of IC chips or smart cards, The physical form can be a SIM/USIM card, a pluggable smart memory card or an IC chip integrated on the mobile terminal. A security domain is a representation of the card's external entities (including card issuers and application providers) on the card, which contain encryption keys to support secure channel protocol operation and card content management. The security domain is responsible for its own key management, which ensures that applications and data from different application providers can coexist on the same card. When the key of the security domain adopts an asymmetric key system, the keys and certificates on the security domain need to include: the public key (also called public key) and the private key (also called private key) of the security domain. , the certificate of the security domain, the public key of the trusted certificate used to authenticate the certificate of the entity outside the card. The security domain of the application provider on the smart card is the secondary security domain. Before downloading and installing the application provider's electronic payment application to the smart card, The application provider's secondary security domain needs to be created on the smart card first through the smart card master security domain owned by the card issuer. Then set the key from the security domain. The security domain key is confidential and requires reliable and secure methods and techniques to import the relevant keys and certificates into the secondary security domain for secure distribution of security domain keys. From the security domain, the card issuer management platform needs to indicate the creation of the primary security domain on the smart card, and after the security domain is created, The initial key from the security domain needs to be set up and distributed by the card issuer management platform. Based on the above electronic payment system, an embodiment of the present invention provides a key distribution system. 2 is a structural block diagram of a key distribution system according to an embodiment of the system of the present invention, as shown in FIG. 2, The key distribution system according to the present embodiment includes: a card issuer management platform 200, an application provider management platform 210, and a smart card 220. Card issuer management platform 200, It further includes: creating a module, An application provider slave security domain is created on the smart card; an information sending module is configured to send the application provider basic information from the security domain to the application provider management platform, where the basic information includes an identifier of the application provider from the security domain. In the embodiment of the present invention, before the electronic payment application of the application provider is downloaded in the smart card, the application provider management platform needs to check whether the smart card has the security of the application provider. area. If the corresponding slave security domain does not exist, the application provider management platform needs to request the card issuer management platform to create the slave security domain of the application provider on the smart card. Application provider management platform 210, Connected to the card issuer management platform 200, The method further includes: a notification module, configured to notify an application provider corresponding to the application provider management platform to generate a public-private key pair including a public key and a private key from the security domain; and a first receiving module, configured to: Receiving a public key from the application provider from the security domain, wherein the public key is encrypted by the public key of the application provider obtained in advance, and processed by the CASD signature set on the smart card; the first obtaining module is configured to verify the signature And decrypting using the private key of the application provider to obtain a public key; the first sending module is configured to encrypt the public key encrypted by the application provider from the security domain and the encrypted data by the application provider's private key pair The application provider sends the certificate from the security domain and the public key of the trusted root for external authentication to the application provider from the security domain; the smart card 220, Connected to the card issuer management platform 200, The smart card 220 is located at the mobile terminal, and includes an application provider from the security domain, where the application provider further includes: a second acquisition block, The second sending module is configured to send the public key encrypted by the application provider and the public key processed by the CASD signature to the application provider management platform; the second receiving module uses Receiving an encrypted and signed application provider certificate from a secure domain and a trusted public key for external authentication; a decryption module, The data used by the receiving module is used to verify the signature by using the public key of the application provider, and the authentication is performed by using the private key of the security domain by the application provider. And, the smart card 220 further includes: a CASD, It is used to verify the application provider's certificate and the signature public key. Preferably, in practical applications, the smart card can conform to the Global Platform Card Specification 2.2 specification, and the smart card security domain adopts an asymmetric key system, and the keys that need to be imported from the security domain are created: from the security i or the public key and private The key, the security from the security domain ^ certificate and the external authentication used in April (One Public Key for Trust Point for External Authentication, PK.TP_EX.AUT ). From the security i or the public key and private key generated by the application provider from the security i or on the card, the security domain certificate is generated by the application provider management platform from the security domain public key, the root of the trust used by the external authentication The public key is provided by the CA that issued the application provider certificate. It can be obtained from the application provider management platform, which is used to authenticate the application provider certificate from the security domain. The public and private keys of the security domain can be generated by the RSA algorithm. The length of the public and private keys is 1024 bits. As can be seen from the above description, in the key distribution system of the present invention, the application provider encrypts the secure domain key generated on the card from the security domain using the public key of the application provider obtained in advance and sends it to the application. Business management platform, the application provider management platform uses the pre-acquired application provider to encrypt and send the certificate from the security domain and the trusted public key to the secure domain from the security domain's public key; the card issuer Although the management platform is responsible for data transmission between the application provider management platform and the application provider from the security domain, the card issuer management platform cannot obtain the private key of the application provider and the application provider from the security domain, and thus cannot decrypt the data. Get the key from the security domain, The isolation of the card issuer management platform is realized, and the security of the application provider from the secure domain key distribution is effectively guaranteed. Method Embodiment In the present embodiment, a key distribution method is provided for a communication system including an application provider management platform of an application provider, a card issuer management platform, and a mobile terminal. 3 is a flow chart of a key distribution method according to an embodiment of the present invention, As shown in FIG. 3, the method includes the following steps S302 to S308: Step S302, The application provider management platform notifies the application provider corresponding to the application provider management platform that is configured on the smart card to generate a public-private key pair including the public key and the private key from the security domain; Step S304, The application provider management platform receives the public key encryption of the pre-obtained application provider from the security domain by the application provider through the card issuer management platform, and the CASD signature processing from the secure domain through the trusted third party set on the smart card. Public key; step S306, The application provider management platform verifies the signature and decrypts using the private key of the application provider to obtain a public key; step S308, The application provider management platform encrypts the application provider's certificate from the security domain and the public key of the trusted certificate for external authentication, the public key of the security domain through the application provider, and the private key of the application provider. After the encrypted data is signed and processed, it is sent to the application provider from the security domain through the card issuer management platform to complete the distribution of the security domain key. According to the above embodiment, the card issuer management platform and the CASD are unable to obtain the private key of the application provider and the application provider from the security i or The card issuer management platform and CASD cannot decrypt the key data, so the key data from the security domain cannot be obtained, and the isolation of the card issuer management platform is realized, thereby effectively ensuring the secure distribution of the security domain key. Details of each of the above processes are further described below.
0004(a) Step S302 According to the present invention, in order to achieve the need for confidentiality, a trusted third party needs to be introduced on the smart card. The third party has a Controlling Authority from the Security Domain (CASD) on the smart card, and the trusted third party provides the service from the security domain to the application provider via the CASD. Controlling Authority is either from security i or in compliance with the requirements of the Global Platform Card Specification V2.2. CASD provides an independent service interface for application providers from the security domain, including certificate verification, signature, data decryption, and more. Preferably, the trusted third party is a certificate authority (CA) that issues a certificate to each application provider. The CA has a separate CASD on the smart card. The keys and certificates in the CASD include: the public and private keys of CASD, the certificate of CASD, the public key of the CA trusted certificate used to verify the application provider certificate, and the public and private keys of the CASD of the CA on the smart card. The CA generates, the certificate of the CASD is generated by the CA according to the public key of the CASD, and the public key of the CA trusted root is provided by the CA. The CASD can be created and initialized in a secure manner when the smart card is issued. The CA writes the public key of the CASD security i or the public key, the certificate and the CA trusted certificate in the CASD security domain. The private key of the CASD is It can only be updated on the smart card and cannot be read. Therefore, the card issuer management platform and the application provider management platform cannot obtain the CASD private key. According to the present invention, the card issuer management platform is first required to notify the smart card master security domain to create a slave security domain. After creating from the security domain, The card issuer management platform sends basic information of the security domain to the application provider management platform. The application provider management platform then obtains the CASD certificate, verifies the authenticity of the CASD certificate and obtains the CASD public key from the certificate. The application provider management platform can use the public key to encrypt the data sent to the application provider from the security domain. After receiving the encrypted data from the security domain, the application provider decrypts the data by calling the service interface provided by CASD. CASD uses CASD. The private key decrypts the data and returns the decrypted data to the application provider from the security domain. And, the application provider management platform sends its own certificate to the application provider from the security domain through the card issuer management platform. The application provider verifies the application provider's certificate from the security domain by calling the certificate verification interface provided by CASD. The CASD verifies the application provider's certificate using the CA's trusted public key, and if the verification passes, returns the application provider's identification information (ID) and the application provider's public key to the application provider's secondary security domain. The application provider management platform notifies the application provider to generate a public-private key pair including a public key (public key) and a private key (private key) on the smart card from the secure domain. The application provider generates the public key and the private key from the security domain by calling the interface that generates the key on the smart card, encrypts the generated key with the application provider's public key, and then signs the encrypted data through the CASD security domain, and then Send to the application provider management platform. (2) Step S304 and step S306 After the application provider management platform receives the key data from the application provider from the security domain, the signature is verified and the data is decrypted using the private key of the application provider, thereby obtaining the application provider from the security. The public key of the domain.
0005(3) Step S308. Based on the foregoing processing, the application provider management platform issues the certificate of the application provider from the security domain from the public key of the security domain according to the obtained application provider, and uses the application provider to provide the application from the public key of the security domain. The cipher encrypts the certificate of the security domain and the public key of the trusted root, and signs the encrypted data using the private key of the application provider. The message is then sent to the application provider from the security domain. After the application provider receives the data from the security domain, it uses the application provider's public key to verify the signature and uses the application provider to decrypt the data from the secure private key. Thereby obtaining the security domain certificate and the trusted public key, the application provider performs the setting of the security domain certificate and the trusted root public key according to the message indication from the security domain, thereby completing the distribution of the application provider from the security domain key. Through the above description, it can be concluded that when the card issuer management platform transmits the communication data of the application provider management platform and the security domain, since the application provider and the private key of the security domain are not grasped, the data cannot be decrypted and cannot be obtained. Key from the security domain; and for CASD on the smart card, Since it is only responsible for the verification of the certificate and the signature of the data, the application provider and the private key from the security domain are not known. The data cannot be decrypted, so the key from the security domain cannot be obtained. Through the above embodiments, the isolation of the card issuer management platform is realized, and the secure distribution of the security key by the application provider is effectively ensured. In the above process, the application provider can create the secure domain and the key distribution process can be implemented through the OTA. The application provider management platform and the card issuer management platform establish a connection with the smart card through the OTA method. Transfer related commands and data through OTA. Moreover, the creation of the security domain by the application provider and the process of distributing the key can also be completed by the service terminal of the card issuer. The smart card establishes a connection through the card publisher's business terminal and the card issuer management platform and the application provider management platform, and the service terminal transmits data such as commands and responses between the smart card and the management platform. The command sent by the application provider to the smart card is sent to the smart card by the card issuer management platform, and the response sent by the smart card is obtained from the card issuer management platform. The key distribution processing according to the present embodiment will be described below with reference to specific application examples. FIG. 4 is a flowchart of a preferred processing scheme of the key distribution method according to the embodiment of the present invention. As shown in FIG. 4, the processing specifically includes the following steps S402 to S428: Step S402, The card issuer management platform creates an application provider from a secure domain. The process of creating an application provider from the security domain may include: (1) The card issuer management platform sends a SELECT (selection) message to the smart card, and selects the primary security domain of the smart card.
0006(2) The card issuer management platform and the smart card master security domain establish an SCP 10 secure channel in accordance with the requirements of the Global Platform Card Specification V2.2 Appendix F Secure Channel Protocol '10, and complete the authentication of both parties and the negotiation of the session key. (3) The card issuer management system sends an application provider to the primary security domain to create a message from the security domain.
0007INSTALL[for Install]. The primary security domain creates an application provider from the security domain according to the instructions. The application provider management platform may have the same ID (APSD ID) as the application provider management platform.
0008(4) After the application provider is created from the security domain, The card issuer management platform sends the created application provider from the basic information of the security domain to the application provider management platform, and the basic information includes the application provider's ID from the security domain (APSD ID) and the configuration of the application provider from the security domain. information. After the application provider management platform receives the basic information of the application provider from the security domain, The information of the application provider from the security domain needs to be saved in the database of the application provider management platform. Step S404, The application provider management platform obtains the certificate of the smart card CASD from the smart card. The application provider can send a GET DATA message to the smart card to obtain a certificate for the CASD. Step S406, The application provider management platform verifies the CASD certificate and obtains the CASD's public key. The application provider management platform can verify the authenticity of the CASD certificate using the CA's trusted root public key and obtain the CASD public key from the CASD certificate. Step S408, The application provider management platform uses its own certificate to use STORE DATA (data storage) messages and sends them to the application provider from the security domain through the card issuer management platform. In order to achieve security when sending a certificate, the application provider management platform can use the CASD public key to force the application provider's certificate to be dense. Step S410, The application provider requests the CASD to verify the application provider's certificate from the security domain. Step S412, The CASD returns the verification result, the application provider's ID, and the application provider's public key from the security domain to the application provider. Step S414, After determining the authenticity of the application provider certificate, the STORE DATA response is sent from the security domain to the application provider management platform. Step S416, The application provider management platform notifies the application provider to generate public and private keys from the secure domain. Step S418, The application provider generates the public key and the private key from the security domain by calling the interface that generates the key on the card, and the generated public key is encrypted by the application provider's public key, and then the encrypted data is signed by the CASD. Step S420, The application provider sends the encrypted application provider from the security domain to the application provider management platform from the public key of the security domain. Step S422, The application provider management platform verifies the signature and decrypts the data using the application provider's private key. Obtain the public key of the application provider from the security domain. Step S424, The certificate management system in the application provider management platform sends the public key and the application provider's certificate request information from the security domain to the application provider CA. After the CA issues the certificate from the secure domain, it returns the certificate to the certificate management system. Step S426, The application provider management platform sends the application provider's public key from the security domain's certificate and the trusted root for external authentication to the secondary security domain via the PUT KEY command. In PUT KEY 4, the application provider can encrypt the certificate of the security domain and the public key of the trusted root from the security key of the application domain using the public key of the security domain, and then use the private key of the application provider to encrypt the data. Sign it. Step S428, After receiving the PUT KEY command from the security domain, the application provider verifies the data signature and decrypts the data using its own private key to obtain the certificate of the application provider from the security domain and the public key of the trusted certificate. The application provider then sets up the certificate and public key from the security domain. After the setup is complete, The application provider sends a PUT KEY response message from the security domain to the application provider management platform. Moreover, after the above steps are completed, the process of downloading and installing the electronic payment application can be continued from between the security domain and the application provider management platform. In summary, with the technical solution of the present invention, in the key distribution system of the present invention, the application provider performs the secure domain key generated on the card from the security domain by using the public key of the application provider obtained in advance. Encrypted and sent to the application provider management platform, the application provider management platform encrypts and sends to the application provider from the security domain's certificate and the trusted root's public key from the security domain's public key using the pre-obtained application provider. From the security domain; the card issuer management platform is responsible for the data transfer between the application provider management platform and the application provider from the security domain, but the card issuer management platform cannot obtain the private key of the application provider and the application provider from the security domain. , Therefore, the data cannot be decrypted to obtain the key from the security domain. The isolation of the card issuer management platform is realized, and the security of the application provider from the secure domain key distribution is effectively guaranteed. Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device, or they may be separately fabricated into individual integrated circuit modules, or they may be Multiple modules or steps are made into a single integrated circuit module. Thus, the invention is not limited to any specific combination of hardware and software. The above is only the preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and changes can be made to the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the scope of the present invention are intended to be included within the scope of the present invention.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| CN105991532A | Cited by | China | – | Search report |
| JP2014530578A | Cited by | Japan | – | Search report |
| CN105991531A | Cited by | China | – | Search report |
| CN1841996A | Cites | China | A | International search |
| CN1841996A | Cites | China | A | International search |
| CN1996832A | Cites | China | A | International search |
| CN1996832A | Cites | China | A | International search |
| US6611913B1 | Cites | United States of America | A | International search |
| US6611913B1 | Cites | United States of America | A | International search |
| WU SINAN ET AL.: "Analysis of Near Field Communication Technology", JOURNAL OF UNIVERSITY OF ELECTRONIC SCIENCE AND TECHNOLOGY OF CHINA, vol. 36, no. 6, December 2007 (2007-12-01), pages 1296 - 1299, XP008146844 | Non-patent | – | – | International search |
12 members in 6 offices
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO2010048829A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| CN101729493A | China | A | |
| EP2341659A1 | European Patent Office (EPO) | A1 | |
| KR20110083658A | Republic of Korea | A | |
| US2011211699A1 | United States of America | A1 | |
| JP2012507220A | Japan | A | |
| CN101729493B | China | B | |
| KR101188529B1 | Republic of Korea | B1 | |
| EP2341659A4 | European Patent Office (EPO) | A4 | |
| US8532301B2 | United States of America | B2 | |
| JP5508428B2 | Japan | B2 | |
| EP2341659B1 | European Patent Office (EPO) | B1 |
6 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Entry into the national phaseENP | ENP | KR | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2010/048829
- Application
- 73222
Titles2
- English
- KEY DISTRIBUTION METHOD AND SYSTEM
- French
- PROCÉDÉ ET SYSTÈME DE DISTRIBUTION DE CLÉ
Classification
- CPC, 8
- H04L9/3268
- H04L9/08
- H04L9/30
- H04L9/0819
- H04L9/0822
- H04L9/0825
- H04L9/0877
- H04L9/32
- IPC, 1
- H04L9 32
Designated states140
- Regional, 75
- Botswana
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Mozambique
- Namibia
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
- Tajikistan
- Turkmenistan
and 51 moreShow fewer
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
- Latvia
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 65
- United Arab Emirates
- Antigua and Barbuda
- Albania
- Angola
- Australia
- Bosnia and Herzegovina
- Barbados
- Bahrain
- Brazil
- Belize
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Dominican Republic
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Guatemala
and 41 moreShow fewer
- Honduras
- Indonesia
- Israel
- India
- Japan
- Comoros
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- Republic of Korea
- Lao People’s Democratic Republic
- Saint Lucia
- Sri Lanka
- Liberia
- Libya
- Morocco
- Montenegro
- Madagascar
- Mongolia
- Mexico
- Malaysia
- Nigeria
- Nicaragua
- New Zealand
- Oman
- Peru
- Papua New Guinea
- Philippines
- Serbia
- Seychelles
- Singapore
- Sao Tome and Principe
- El Salvador
- Syrian Arab Republic
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- South Africa