WO2010045777A1 - 电子支付***、更新智能卡对应的移动用户号码的方法 - Google Patents

电子支付***、更新智能卡对应的移动用户号码的方法 Download PDF

Info

Publication number
WO2010045777A1
WO2010045777A1 PCT/CN2009/000832 CN2009000832W WO2010045777A1 WO 2010045777 A1 WO2010045777 A1 WO 2010045777A1 CN 2009000832 W CN2009000832 W CN 2009000832W WO 2010045777 A1 WO2010045777 A1 WO 2010045777A1
Authority
WO
WIPO (PCT)
Prior art keywords
smart card
card
mobile
management platform
feature information
Prior art date
Application number
PCT/CN2009/000832
Other languages
English (en)
French (fr)
Inventor
马景旺
贾倩
余万涛
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2010045777A1 publication Critical patent/WO2010045777A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • G06Q20/3221Access to banking information through M-devices

Definitions

  • the present invention relates to an electronic payment system and a method of updating a mobile subscriber number corresponding to a smart card.
  • IC (Integral Circuit) cards especially non-contact IC cards, have been widely used in public transportation, access control, and small-scale electronic payment after more than a decade of development.
  • mobile phones have experienced rapid development over the years and have been widely used, bringing great convenience to people's work and life.
  • the functions of mobile phones are becoming more and more powerful, and there is a trend of integrating more functions.
  • the combination of mobile phones and non-contact: [C card technology, applied to the field of electronic payment, will further expand the use of mobile phones, giving people Life brings convenience and there is a broad application prospect.
  • NFC Near Field Communication
  • RFID Radio Frequency Identification
  • interconnection technology After integrating NFC technology, mobile terminals such as mobile phones can simulate contactless IC cards for electronic payment related applications. Implementing this solution on mobile terminals requires the addition of NFC analog front-end chips and NFC antennas, and the use of smart cards that support electronic payments.
  • the business framework of the mobile terminal short-range electronic payment system uses the multi-application framework of the Global Platform (Global Platform) specification, and multiple electronic payment applications can be installed on the smart card supporting the Global Platform specification.
  • the smart card is divided into several independent Security Domains to ensure mutual isolation and independence between multiple electronic payment applications, and each application provider manages its own security domain as well as applications, application data and the like.
  • V2.1.1/V2.2 referred to as GP2.1.1/GP2.2
  • the technical requirements of the security domain are specified. Due to the different schemes used by mobile terminals to implement electronic payment functions, the support mentioned here
  • the smart card of the Global Platform specification refers to an IC chip or smart card that conforms to GP2 ⁇ 1/GP2.2, and can be physically SIM/USIM (Subscriber Identification Module/Universal Subscriber Identity Module). Card, pluggable smart memory card or IC security chip integrated on the mobile terminal.
  • SIM/USIM Subscriber Identification Module/Universal Subscriber Identity Module
  • the smart card is an IC security chip integrated on the mobile terminal; when the mobile terminal uses the enhanced NFC (enhanced NFC) scheme, the mobile user card (SIM/USIM) Add support for electronic payments, and electronic payment applications are stored in SIM/USIM cards.
  • the secure channel protocol needs to support the Secure Channel ProtocoK Secure Channel Protocol based on the symmetric key) '02'; if the mobile terminal based on the near field communication technology electronically pays The system supports the GP2.2 specification, and the secure channel protocol needs to support the Secure Channel Protocol '10' based on the asymmetric key.
  • the card issuer and the application provider can select the security mechanism used by the electronic payment system according to the security policy requirements.
  • the mobile terminal short-range payment system may include a card issuer, an application provider, and a user from a service architecture.
  • Card issuer responsible for card issuance and management, with card management system, key management system and certificate management system; among them, certificate management system is required only when asymmetric key is supported.
  • the card issuer is responsible for managing the card's resources, lifecycle, keys, and certificates, and creating the application provider's security domain.
  • the card issuer can also have an application management system, which is responsible for providing and managing the card.
  • the business terminal management system and the service terminal are provided, and the service terminal provides the user with good services.
  • the card issuer can have an application provider management system through which the information about the application provider is managed, and the service authority of the application provider is specified.
  • Application Provider responsible for the provision and management of electronic payment applications. It can have an application management system, a key management system, and a certificate management system. Among them, the certificate management system is required only when asymmetric keys are supported.
  • the application provider provides various electronic payment applications, and manages the security domain corresponding to the application provider on the smart card, controls keys, certificates, data, and the like in the security domain, and provides a secure download function of the electronic payment application.
  • Application providers can be carriers, banks, Bus companies, retailers, etc.
  • the application provider can have a service terminal management system and a service terminal, and provide services to the user through the service terminal.
  • the user responsible for downloading, installing and using the electronic payment application.
  • the user operates the mobile terminal and the smart card through interaction with the card issuer or application provider, downloads and installs a new electronic payment application in the secure domain, and uses various electronic payment applications provided on the smart card for shopping and electronic transactions.
  • the card issuer management platform and the application provider management platform should be able to send a notification message to the mobile terminal through the mobile communication network.
  • the notification information is transmitted by the mobile terminal to the smart card, and then the smart card establishes a communication connection with the smart card management platform, and updates the key or electronic payment application.
  • the smart card management platform needs to record the mobile subscriber number corresponding to the mobile terminal using the smart card.
  • the smart card When the smart card is a pluggable memory card or a chip integrated on the mobile terminal, the smart card is detachable from the mobile user card (SIM/USIM) that identifies the mobile user.
  • SIM/USIM mobile user card
  • the smart card management platform sends a notification message and the like to the smart card through the mobile communication network, firstly, the mobile subscriber number corresponding to the mobile subscriber card used by the mobile terminal needs to be obtained, so that when the information is correctly sent to the smart record, the inconsistency may occur.
  • the problem of successfully sending information such as keys and electronic payment applications to smart cards.
  • the technical problem to be solved by the present invention is to overcome the deficiencies of the prior art, and provide an electronic payment system capable of updating a mobile subscriber number corresponding to a smart card and a method for updating a mobile subscriber number corresponding to the smart card, so that the card issuer management platform and application
  • the provider management platform is able to send information to the smart card using the correct mobile subscriber number.
  • the present invention provides a method for updating a mobile subscriber number corresponding to a smart card, the method comprising the following steps: a request message for collecting information; the mobile terminal returns characteristic information of the mobile user card to the smart card;
  • the smart card uses the over-the-air OTA technology to manage the smart card C, and the smart card management platform according to the received mobile user card.
  • the feature information updates the mobile subscriber number corresponding to the locally recorded smart card;
  • the feature information of the mobile subscriber card is: an international mobile subscriber identity code IMSI or a mobile subscriber number.
  • step C if the feature information of the mobile user card is IMSI, the smart card management platform acquires the mobile subscriber number corresponding to the IMSI from the OTA server after receiving the IMSI reported by the smart card.
  • step C if the feature information of the mobile subscriber card is an IMSI, the smart card management platform sends the IMSI to the mobile network operator after receiving the IMSI reported by the smart card; the mobile network operator will query The mobile subscriber number corresponding to the IMSI is returned to the smart card management platform.
  • step C after the smart card management platform receives the feature information of the mobile user card reported by the smart card, the response message is sent to the smart card;
  • the smart card After receiving the response message, the smart card stores the feature information of the mobile subscriber card it reports.
  • step C if the smart card management platform is a card issuer management platform, the smart card stores the feature information of the mobile user card in the primary security domain.
  • step C if the smart card management platform is an application provider management platform, the smart card stores the feature information of the mobile user card in a secondary security domain corresponding to the application provider.
  • the present invention also provides an electronic payment system, comprising: a smart card management platform and a mobile terminal; the mobile terminal includes a smart card and a mobile user card for electronic payment; the system further comprises: an OTA server and a mobile communication network;
  • the smart card is configured to acquire feature information of the mobile user card from the mobile terminal when starting or starting, and not storing feature information of the mobile user card or characteristic information of the stored mobile user card in the smart card. Reporting to the smart card management platform by the mobile terminal, the mobile communication network, and the OTA server when the feature information of the mobile user card acquired from the mobile terminal is inconsistent
  • the smart card management platform is configured to update, according to the received feature information of the mobile user card, a mobile user number corresponding to the smart card recorded locally;
  • the feature information of the mobile subscriber card is: IMSI or mobile subscriber number.
  • the system wherein the mobile communication network includes a short message gateway, and the mobile terminal is connected to the OTA server through a short message gateway, and sends feature information of the mobile user card reported by the smart card to the smart card management platform. .
  • the mobile communication network includes a general wireless packet service gateway or a packet data service node gateway
  • the mobile terminal is connected to the OTA server through a general wireless packet service gateway or a packet data service node gateway
  • the feature information of the mobile user card reported by the smart card is sent to the smart card management platform.
  • the smart card management platform is further configured to send a response message to the smart card after receiving the feature information of the mobile user card on the smart card;
  • the smart card is further configured to store, after receiving the response message, feature information of the mobile user card that is reported by the smart card.
  • the system wherein the smart card management platform comprises an application provider management platform and a card issuer management platform.
  • system and method of the present invention can enable a card issuer to manage platforms and applications.
  • the purpose of the smart card is indeed sent.
  • 1 is a schematic structural diagram of an electronic payment system of a mobile terminal according to an embodiment of the present invention
  • 2 is a flow chart of a method for updating a mobile subscriber number corresponding to a smart card according to an embodiment of the present invention.
  • the basic idea of the present invention is that when a smart card for electronic payment (referred to as an electronic payment smart card) is activated, an IMSI (International Mobile Subscriber Identification Number) is obtained from the mobile terminal, and the IMSI is sent to the smart card.
  • the management platform the smart card management platform obtains the mobile subscriber number corresponding to the smart card according to the received IMSI.
  • the present invention is based on the mobile terminal electronic payment system architecture shown in FIG. 1.
  • the payment system includes: a card issuer management platform, a card issuer CA system, one or more application provider management platforms, an application provider CA system, and an OTA. (Over The Air, over the air) servers, mobile communication networks and mobile terminals.
  • the card issuer management platform includes: a card management system, an application management system, a key management system, a certificate management system, and an application provider management system; wherein, the certificate management system supports asymmetricity in a mobile terminal electronic payment system based on near field communication technology Used in the case of a key; the certificate management system is connected to the card issuer CA system.
  • the application provider management platform includes: an application management system, a key management system, and a certificate management system; wherein, the certificate management system is used when the mobile terminal electronic payment system supports an asymmetric key; the certificate management system and the application provider CA system connection.
  • a mobile subscriber card and a smart card for electronic payment are provided in the mobile terminal.
  • the smart card In order to implement the security management of the smart card and the download of the payment application, the smart card needs to establish communication with the card issuer management platform and the application provider management platform.
  • the communication between the smart card and the management platform can be realized in the following manner:
  • the smart card establishes communication with the smart card management platform through the mobile terminal and the mobile communication network, and generally uses OTA technology to realize communication between the smart card and the smart card management platform.
  • the mobile terminal can establish a communication connection with the smart card management platform by using a short message gateway or a GPRS/PDSN (General Packet Radio Service/Packet Data Serving Node) gateway in the mobile communication network; and the OTA server; In this way, mobile terminals and smart cards Need to support OTA function.
  • GPRS/PDSN General Packet Radio Service/Packet Data Serving Node
  • the smart card is a pluggable memory card or an IC chip integrated on the mobile terminal;
  • the mobile user card used by the mobile terminal may be a SIM/USIM card, and uses IMSI as the feature information for identifying the mobile user card.
  • a storage area (which may be referred to as a mobile subscriber card feature information storage area) may be set in the smart card for recording the IMSI of the mobile subscriber card used by the current mobile terminal.
  • the smart card may send the IMSI to the smart card in the corresponding response message after receiving the request message.
  • the smart card is activated for the first time or when it is determined that the mobile user card used by the mobile terminal is changed.
  • the mobile terminal needs to support the packet data service or the short message service, and the smart card uses the OTA technology to pass the mobile terminal and The smart card management platform establishes a communication connection.
  • FIG. 2 is a flowchart of a method for updating a mobile subscriber number corresponding to a smart card according to an embodiment of the present invention, where the body includes the following steps:
  • the mobile terminal starts the smart card, and the smart card initializes.
  • the startup of the smart card can be divided into two cases.
  • One case is: a smart card is inserted or fixed in the mobile terminal when the computer is turned on, and the mobile terminal registers the mobile communication network with the feature information (for example, IMSI) of the mobile user card after the power is turned on. Then, the mobile terminal starts the smart card, and the smart card performs the initialization operation after the startup; the other case is: the smart card is a hot-swappable memory card, and after the mobile terminal is powered on and normally registered to the mobile communication network, the user inserts the smart card into the mobile terminal. The mobile terminal detects the smart card and then starts the smart card.
  • IMSI feature information
  • the smart card sends a mobile user card feature information request message to the mobile terminal. After receiving the request message, the mobile terminal returns the IMSI of the mobile user card to the smart card by using the mobile user card feature information response message.
  • the mobile subscriber card feature information storage area is located in a primary security domain of the smart card.
  • step 204 The smart card compares the IMSI saved in the mobile user card feature information storage area with the currently used IMSI returned by the mobile terminal: If the two IMSIs are the same, indicating that the mobile user card used by the mobile terminal does not change, then the process proceeds to the step If the two IMSIs are different, indicating that the mobile user card currently used by the mobile terminal has changed, step 205 is executed to start the upper process of the mobile user card IMSI.
  • the smart card uses OTA technology to establish a communication connection with the card issuer management platform through the mobile terminal.
  • the smart card can implement OTA through packet data service or short message service.
  • the card issuer management platform Since the security domain corresponding to the card issuer is the primary security domain, the card issuer management platform sends a SELECT (select) command to the smart card, and selects the primary security domain of the smart card as the current security domain.
  • the smart card's primary security domain establishes a secure communication connection with the card issuer management platform, and completes the authentication of both parties and the negotiation of the session key.
  • the smart card primary security domain and the card issuer management platform can establish secure communication according to the requirements of Secure Channel Protocol '02 in Appendix F of the Global Platform Card Specification V2.2. Connection;
  • the smart card primary security domain and the card issuer management platform may be in accordance with the requirements of the Secure Channel Protocol '10 in Appendix F of the Global Platform Card Specification V2.2. Establish a secure communication connection.
  • the smart card sends the IMSI of the mobile subscriber card to the card issuer management platform through the above secure communication connection.
  • the card issuer management platform After receiving the IMSI of the mobile user card sent by the smart card, the card issuer management platform obtains the mobile user number corresponding to the mobile user card.
  • the mobile subscriber number corresponding to the mobile subscriber card may not be obtained, and the corresponding mobile subscriber number may be acquired by using the recorded IMSI when it is needed.
  • the card issuer management platform can obtain the mobile user number corresponding to the mobile user card by using one of the following two methods:
  • the mobile subscriber number corresponding to the mobile subscriber card can be obtained, and the card issuer management platform obtains the mobile subscriber number corresponding to the IMSI from the OTA server; the mobile network operator queries the mobile subscriber card according to the IMSI. After the corresponding mobile subscriber number, the mobile subscriber number is returned to the card issuer management platform.
  • the card issuer management platform records the IMSI and mobile subscriber number of the mobile subscriber card corresponding to the smart card in the database.
  • the card issuer management platform sends a response message to the smart card, and the smart card records the IMSI of the mobile user card currently used by the mobile terminal.
  • the smart card completes the subsequent startup operation.
  • the mobile subscriber number can be used as the feature information of the mobile subscriber card; the smart card directly requests the mobile terminal to obtain the mobile subscriber number, and reports the mobile subscriber number to the management platform; thus, the operation platform can obtain the operation of obtaining the mobile subscriber number according to the IMSI. .
  • the mobile user card feature information storage area should be set in the secondary security zone corresponding to the application provider. The number, and then send a notification message to the smart card.
  • the IMSI feature information storage area records the IMSI. Of course, if the IMSI fails to send, the card may be sent. The IMSI recorded by the dealer management platform is not accurate.
  • the card issuer management platform and the application provider management platform can obtain the mobile subscriber number of the mobile subscriber card currently used by the mobile terminal in time, and bind the smart card to the mobile subscriber card used by the mobile terminal. , the purpose of correctly transmitting information such as notification messages to the smart card.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

电子支付***、 更新智能卡对应的移动用户号码的方法
技术领域
本发明涉及一种电子支付***、 以及更新智能卡对应的移动用户号码的 方法。
背景技术
IC ( Integrate Circuit, 集成电路)卡, 特别是非接触式 IC卡经过十多年 的发展, 已经被广泛应用于公交、 门禁、 小额电子支付等领域。 与此同时, 手机经历多年的迅速发展, 已得到广泛普及, 给人们的工作及生活带来了很 大的便利。 目前, 手机的功能越来越强大, 并存在集成更多功能的趋势, 将 手机和非接触式: [C卡技术相结合, 应用于电子支付领域, 会进一步扩大手机 的使用范围, 给人们的生活带来便捷, 存在着广阔的应用前景。
近场通信技术( Near Field Communication,简称 NFC )是工作于 13.56MHz 的一种近距离无线通信技术, 由 RFID ( Radio Frequency Identification, 射频 识别)技术及互连技术融合演变而来。 手机等移动终端集成 NFC技术后, 可 以模拟非接触式 IC卡, 用于电子支付的有关应用。 在移动终端上实现该方案 需要增加 NFC模拟前端芯片和 NFC天线, 并使用支持电子支付的智能卡。
为实现基于 NFC技术的移动电子支付, 需要建立移动终端电子支付系 统, 通过该***实现对移动终端电子支付的管理, 包括: 智能卡的发行、 智 能卡密钥的管理、 电子支付应用的下载、 安装和个人化( Personalization ) 、 釆用相关技术和管理策略实现电子支付的安全性等功能。
移动终端近距离电子支付***的业务框架釆用 Global Platform (全球平 台)规范的多应用框架, 在支持 Global Platform规范的智能卡上可以安装多 个电子支付应用。 智能卡被分隔为若干个独立的安全域(Security Domain ) , 以保证多个电子支付应用之间的相互隔离和独立性, 各个应用提供商管理各 自的安全域以及应用、应用数据等。在 Global Platform Card Specification (全 球平台卡规范) V2.1.1/V2.2 (简称 GP2.1.1/GP2.2 ) 中, 对安全域的技术要求 进行了规定。 由于移动终端实现电子支付功能时所釆用的方案不同, 这里提到的支持
Global Platform规范的智能卡指的是符合 GP2丄 1/GP2.2的 IC芯片或智能卡, 从物理形式上可以为 SIM/USIM ( Subscriber Identification Module/Universal Subscriber Identity Module, 用户识别模块 /通用用户识别模块)卡、 可插拔的 智能存储卡或者集成在移动终端上的 IC安全芯片。 当移动终端釆用 NFC方 案实现电子支付功能时, 智能卡为集成在移动终端上的 IC安全芯片; 当移动 终端釆用 eNFC( enhanced NFC,增强型 NFC )方案时,移动用户卡( SIM/USIM ) 增加对电子支付的支持, 电子支付应用保存在 SIM/USIM卡中。
如果基于近场通信技术的移动终端电子支付***支持 GP2丄 1 规范, 安 全通道协议需要支持基于对称密钥的 Secure Channel ProtocoK安全通道协议 ) '02' ; 如果基于近场通信技术的移动终端电子支付***支持 GP2.2规范, 安 全通道协议需要支持基于非对称密钥的 Secure Channel Protocol ' 10'。 在电子 支付***的实施过程中, 卡发行商、 应用提供商可以根据安全策略需求选择 电子支付***所釆用的安全机制。
移动终端近距离支付***从业务架构上可以包括卡发行商、 应用提供商 和用户。
卡发行商: 负责卡的发行和管理, 拥有卡管理***、 密钥管理***和证 书管理***等; 其中, 仅在支持非对称密钥的情况下才需使用证书管理***。 卡发行商负责对卡的资源、 生命周期、 密钥和证书进行管理, 对应用提供商 的安全域进行创建。 卡发行商也可以拥有应用管理***, 负责提供并管理卡 拥有业务终端管理***和业务终端, 通过业务终端向用户提供 Λ良务。 为了支 持对应用提供商的管理, 卡发行商可以拥有应用提供商管理***, 通过该管 理***管理应用提供商的有关信息, 规定应用提供商的业务权限等。
应用提供商: 负责电子支付应用的提供和管理, 可以拥有应用管理***、 密钥管理***、 证书管理***; 其中, 仅在支持非对称密钥的情况下才需使 用证书管理***。 应用提供商提供各种电子支付应用, 并对智能卡上与应用 提供商对应的安全域进行管理, 对该安全域内的密钥、 证书、 数据等进行控 制, 提供电子支付应用的安全下载功能。 应用提供商可以是运营商、 银行、 公交公司、 零售商户等。 另外, 应用提供商可以拥有业务终端管理***和业 务终端, 通过业务终端向用户提供 Λ良务。
用户: 负责电子支付应用的下载、 安装和使用。 用户通过与卡发行商或 应用提供商的交互, 对移动终端和智能卡进行操作, 在安全域内下载并安装 新的电子支付应用, 使用智能卡上提供的各种电子支付应用进行购物和电子 交易。
在智能卡投入使用后,如果智能卡的密钥或者电子支付应用需要更新时, 卡发行商管理平台和应用提供商管理平台 (统称为智能卡管理平台 )应该可 以通过移动通信网络发送通知消息给移动终端, 再由移动终端将通知信息传 送给智能卡, 然后由智能卡建立和智能卡管理平台的通信连接, 进行密钥或 者电子支付应用的更新等。 在这种情况下, 智能卡管理平台需要记录使用智 能卡的移动终端所对应的移动用户号码。
当智能卡为可插拔的存储卡或集成在移动终端上的芯片时, 智能卡与标 识移动用户身份的移动用户卡(SIM/USIM )是可分离的。 智能卡管理平台通 过移动通信网络发送通知消息等信息给智能卡时, 首先需要获得移动终端上 使用的移动用户卡所对应的移动用户号码, 这样才能将信息正确发送到智能 的记录不一致时, 会出现不能将密钥、 电子支付应用等信息成功发送到智能 卡的问题。
发明内容
本发明所要解决的技术问题是, 克服现有技术的不足, 提供一种可更新 智能卡对应的移动用户号码的电子支付***和更新智能卡对应的移动用户号 码的方法, 使卡发行商管理平台、 应用提供商管理平台能够使用正确的移动 用户号码向智能卡发送信息。
为了解决上述问题, 本发明提供一种更新智能卡对应的移动用户号码的 方法, 该方法包括以下步骤: 征信息的请求消息; 移动终端将移动用户卡的特征信息返回给智能卡;
B、如果智能卡中未存储移动用户卡的特征信息、或存储的特征信息与移 动终端返回的特征信息不一致,智能卡釆用空中下载 OTA技术向智能卡管理 C、智能卡管理平台根据接收到的移动用户卡的特征信息更新本地记录的 智能卡对应的移动用户号码;
所述移动用户卡的特征信息为:国际移动用户识别码 IMSI或者移动用户 号码。
上述的方法, 其步骤 C中, 如果所述移动用户卡的特征信息为 IMSI, 则 智能卡管理平台接收到智能卡上报的 IMSI后, 从 OTA服务器获取与所述 IMSI对应的移动用户号码。
上述的方法, 其步骤 C中, 如果所述移动用户卡的特征信息为 IMSI, 则 智能卡管理平台接收到智能卡上报的 IMSI后, 将所述 IMSI发送给移动网络 运营商;移动网络运营商将查询到的所述 IMSI对应的移动用户号码返回给智 能卡管理平台。
上述的方法, 其步骤 C中, 智能卡管理平台接收到的智能卡上报的移动 用户卡的特征信息后, 向智能卡发送响应消息;
接收到所述响应消息后, 智能卡存储其上报的所述移动用户卡的特征信 息。
上述的方法, 其步骤 C中, 如果智能卡管理平台是卡发行商管理平台, 则智能卡将所述移动用户卡的特征信息存储在主安全域。
上述的方法,其步骤 C中,如果智能卡管理平台是应用提供商管理平台, 则智能卡将所述移动用户卡的特征信息存储在与应用提供商对应的从安全 域。
本发明还提供一种电子支付***, 包含: 智能卡管理平台和移动终端; 所述移动终端中包含用于电子支付的智能卡和移动用户卡; 该***还包含: OTA服务器和移动通信网络; 其中: 所述智能卡用于在启动时或启动后从所述移动终端获取所述移动用户卡 的特征信息, 并当所述智能卡中未存储移动用户卡的特征信息、 或存储的移 动用户卡的特征信息与从移动终端获取的所述移动用户卡的特征信息不一致 时, 通过所述移动终端、移动通信网络和 OTA服务器向智能卡管理平台上报
所述智能卡管理平台用于根据接收到的移动用户卡的特征信息更新本地 记录的所述智能卡对应的移动用户号码;
所述移动用户卡的特征信息为: IMSI或者移动用户号码。
所述的***, 其中, 所述移动通信网络中包含短信网关, 所述移动终端 通过短信网关与所述 OTA服务器相连,将所述智能卡上报的移动用户卡的特 征信息发送给所述智能卡管理平台。
所述的***, 其中, 所述移动通信网络中包含通用无线分组业务网关或 分组数据业务节点网关, 所述移动终端通过通用无线分组业务网关或分组数 据业务节点网关与所述 OTA服务器相连,将所述智能卡上报的移动用户卡的 特征信息发送给所述智能卡管理平台。
所述的***, 其中, 所述智能卡管理平台还用于在接收到的所述智能卡 上>¾的所述移动用户卡的特征信息后, 向所述智能卡发送响应消息;
所述智能卡还用于在接收到所述响应消息后, 存储其上报的所述移动用 户卡的特征信息。 所述的***, 其中, 所述智能卡管理平台包括应用提供商管理平台和卡 发行商管理平台。
综上所述, 釆用本发明的***和方法, 可以使卡发行商管理平台、 应用
Figure imgf000007_0001
确发送给智能卡的目的。
附图概述
图 1是本发明实施例移动终端电子支付***架构示意图; 图 2是本发明实施例更新智能卡对应的移动用户号码的方法流程图。
本发明的较佳实施方式
本发明的基本思路是, 当用于电子支付的智能卡(简称电子支付智能卡) 启动时, 从移动终端获取 IMSI ( International Mobile Subscriber Identification Number, 国际移动用户识别码) , 并将 IMSI上 4艮给智能卡管理平台, 智能 卡管理平台根据接收到的 IMSI得到智能卡对应的移动用户号码。
下面将结合附图和实施例对本发明进行详细描述。
本发明基于图 1所示的移动终端电子支付***架构,该支付***中包括: 卡发行商管理平台、 卡发行商 CA***、 一个或多个应用提供商管理平台、 应用提供商 CA***、 OTA ( Over The Air, 空中下载)服务器、 移动通信网 络和移动终端。 卡发行商管理平台包括: 卡管理***、 应用管理***、 密钥管理***、 证书管理***、 应用提供商管理***; 其中, 证书管理***在基于近场通信 技术的移动终端电子支付***支持非对称密钥的情况下使用; 证书管理*** 和卡发行商 CA***连接。
应用提供商管理平台包括: 应用管理***、 密钥管理***、 证书管理系 统; 其中, 证书管理***在移动终端电子支付***支持非对称密钥的情况下 使用; 证书管理***和应用提供商 CA***连接。
移动终端中设置有移动用户卡和用于电子支付的智能卡。
为了实现智能卡的安全性管理和支付应用的下载, 智能卡需要和卡发行 商管理平台以及应用提供商管理平台建立通信。 可以通过以下方式实现智能 卡和管理平台的通信: 智能卡通过移动终端和移动通信网络与智能卡管理平台建立通信, 一般 釆用 OTA技术实现智能卡和智能卡管理平台的通信。移动终端可以通过移动 通信网络中的短信网关或 GPRS/PDSN ( General Packet Radio Service/Packet Data Serving Node, 通用无线分组业务 /分组数据业务节点) 网关、 和 OTA服 务器与智能卡管理平台建立通信连接; 釆用这种方式时, 移动终端和智能卡 需要支持 OTA功能。
本实施例中, 智能卡为可插拔的存储卡或集成在移动终端上的 IC芯片; 移动终端使用的移动用户卡可以为 SIM/USIM卡,并使用 IMSI作为识别移动 用户卡的特征信息。
智能卡中可以设置一个存储区 (可以称为移动用户卡特征信息存储区) 用于记录当前移动终端使用的移动用户卡的 IMSI。 为了使智能卡可以获取到 移动终端所使用的移动用户卡的 IMSI, 在智能卡启动时或启动后, 智能卡可 终端接收到该请求消息后, 在对应的响应消息中将 IMSI发送给智能卡。
智能卡在第一次启用或者在判定移动终端使用的移动用户卡发生改变 为了实现智能卡将 IMSI发送给智能卡管理平台,移动终端需要支持分组数据 业务或者短消息业务,智能卡釆用 OTA技术通过移动终端与智能卡管理平台 建立通信连接。
图 2是本发明实施例更新智能卡对应的移动用户号码的方法流程图, 本 体包括如下步骤:
201 : 移动终端启动智能卡, 智能卡进行初始化。
智能卡的启动可以分为两种情况, 一种情况为: 开机时移动终端中已插 入或固定设置有智能卡, 开机后移动终端使用移动用户卡的特征信息(例如, IMSI ) 注册到移动通信网络, 然后移动终端启动智能卡, 智能卡进行启动后 的初始化操作; 另一种情况为: 智能卡为支持热插拔的存储卡, 移动终端已 经开机并正常注册到移动通信网络后, 用户将智能卡***到移动终端, 移动 终端检测到智能卡, 然后启动智能卡。
202: 智能卡向移动终端发送移动用户卡特征信息请求消息; 移动终端接 收到该请求消息后, 通过移动用户卡特征信息响应消息将移动用户卡的 IMSI 返回给智能卡。 203: 智能卡获取到移动终端当前使用的移动用户卡的 IMSI后, 读取智 能卡内的移动用户卡特征信息存储区, 判断该存储区是否已存储移动用户卡 的 IMSI: 如果该存储区没有存储移动用户卡的 IMSI, 则跳转至步骤 205; 否 则执行步骤 204。
上述移动用户卡特征信息存储区位于智能卡的主安全域。
204: 智能卡将移动用户卡特征信息存储区中保存的 IMSI与移动终端返 回的当前使用的 IMSI进行比较: 如果两个 IMSI相同, 说明移动终端使用的 移动用户卡没有发生变化, 则跳转至步骤 212; 如果两个 IMSI不同, 说明移 动终端当前使用的移动用户卡发生了变化, 则执行步骤 205, 启动移动用户 卡 IMSI的上 流程。
205: 智能卡釆用 OTA技术通过移动终端与卡发行商管理平台建立通信 连接。
智能卡可以通过分组数据业务或短信业务实现 OTA。
206: 由于卡发行商对应的安全域为主安全域, 因此卡发行商管理平台向 智能卡发送 SELECT (选择)命令, 选择智能卡的主安全域作为当前的安全 域。
207: 智能卡的主安全域与卡发行商管理平台建立安全通信连接, 并完成 双方的身份验证和对话密钥的协商。
当智能卡安全域密钥釆用对称密钥体制时, 智能卡主安全域和卡发行商 管理平台之间可以按照 Global Platform Card Specification V2.2 附录 F中的 Secure Channel Protocol '02, 的要求建立安全通信连接; 当智能卡安全域密 钥釆用非对称密钥体制时, 智能卡主安全域和卡发行商管理平台之间可以按 照 Global Platform Card Specification V2.2 附录 F中的 Secure Channel Protocol '10, 的要求建立安全通信连接。
208: 智能卡将移动用户卡的 IMSI通过上述安全通信连接发送给卡发行 商管理平台。
209: 卡发行商管理平台接收到智能卡发送的移动用户卡的 IMSI后, 获 取移动用户卡对应的移动用户号码。 当然, 本步骤中也可以不获取移动用户卡对应的移动用户号码, 等到需 要使用时再使用记录的 IMSI获取对应的移动用户号码。
卡发行商管理平台可以釆用下面两种方法之一获取移动用户卡对应的移 动用户号码:
一、 OTA服务器和移动终端建立通信连接后, 可以获得移动用户卡对应 的移动用户号码, 卡发行商管理平台从 OTA服务器获取 IMSI对应的移动用 户号码; 动网络运营商根据 IMSI查询到移动用户卡对应的移动用户号码后将移动用 户号码返回给卡发行商管理平台。
210: 卡发行商管理平台在数据库中记录与智能卡对应的移动用户卡的 IMSI和移动用户号码。
211 : 卡发行商管理平台向智能卡发送响应消息, 智能卡记录移动终端当 前使用的移动用户卡的 IMSI。
212: 智能卡完成后续的启动操作。
需要注意的是, 本发明除了应用于电子支付智能卡(也称为金融智能卡) 夕卜, 还可以应用于其它类型的智能卡(例如门禁等) 。
此外, 可以将移动用户号码作为移动用户卡的特征信息; 智能卡直接向 移动终端请求获取移动用户号码, 并将移动用户号码上报给管理平台; 这样 可以省去管理平台根据 IMSI获取移动用户号码的操作。 用提供商管理平台上报 IMSI, 则移动用户卡特征信息存储区应当设置在应用 提供商对应的从安全域。 号码, 然后再向智能卡发送通知消息等信息。 户卡特征信息存储区记录该 IMSI, 当然, 如果 IMSI发送失败可能造成卡发 行商管理平台记录的 IMSI不准确。
工业实用性
釆用本发明的***和方法, 可以使卡发行商管理平台、 应用提供商管理 平台及时获取移动终端当前使用的移动用户卡的移动用户号码, 将智能卡和 移动终端使用的移动用户卡进行绑定, 实现将通知消息等信息正确发送给智 能卡的目的。

Claims

权 利 要 求 书
1、 一种更新智能卡对应的移动用户号码的方法, 该方法包括以下步骤: 征信息的请求消息; 所述移动终端将所述移动用户卡的特征信息返回给所述 智能卡;
B、如果所述智能卡中未存储所述移动用户卡的特征信息、或存储的所述 移动用户卡的特征信息与所述移动终端返回的特征信息不一致, 所述智能卡 釆用空中下载 OTA技术向智能卡管理平台上报所述移动终端返回的所述移 动用户卡的特征信息;
C、所述智能卡管理平台根据接收到的所述移动用户卡的特征信息更新本 地记录的智能卡对应的移动用户号码;
所述移动用户卡的特征信息为:国际移动用户识别码 IMSI或者移动用户 号码。
2、 如权利要求 1所述的方法, 其步骤 C中:
如果所述移动用户卡的特征信息为 IMSI, 则所述智能卡管理平台接收到 所述智能卡上报的 IMSI后,从 OTA服务器获取与所述 IMSI对应的移动用户 号码。
3、 如权利要求 1所述的方法, 其步骤 C中:
如果所述移动用户卡的特征信息为 IMSI, 则所述智能卡管理平台接收到 所述智能卡上报的 IMSI后, 将所述 IMSI发送给移动网络运营商; 所述移动 网络运营商将查询到的所述 IMSI对应的移动用户号码返回给所述智能卡管 理平台。
4、 如权利要求 1所述的方法, 其步骤 C中:
所述智能卡管理平台接收到的所述智能卡上报的所述移动用户卡的特征 信息后, 向所述智能卡发送响应消息;
接收到所述响应消息后, 所述智能卡存储其上报的所述移动用户卡的特 征信息。
5、 如权利要求 1或 4所述的方法, 其步骤 C中:
如果所述智能卡管理平台是卡发行商管理平台, 则所述智能卡将所述移 动用户卡的特征信息存储在主安全域。
6、 如权利要求 1或 4所述的方法, 其步骤 C中:
如果所述智能卡管理平台是应用提供商管理平台, 则所述智能卡将所述 移动用户卡的特征信息存储在与所述应用提供商对应的从安全域。
7、一种用于电子支付***的智能卡, 用于实现更新智能卡对应的移动用 户号码, 所述智能卡设置为在启动时或启动后从所述移动终端获取移动用户 卡的特征信息, 并当所述智能卡中未存储所述移动用户卡的特征信息、 或存 信息不一致时, 所述智能卡通过所述移动终端、移动通信网络和 OTA服务器
从而使所述智能卡管理平台根据接收到的所述移动用户卡的特征信息更 新本地记录的所述智能卡对应的移动用户号码;
所述移动用户卡的特征信息为: IMSI或者移动用户号码。
8、 如权利要求 7所述的智能卡, 所述智能卡还设置为: 在接收到所述智 能卡管理平台接收到所述智能卡上报的所述移动用户卡的特征信息而向所述 智能卡发送的响应消息后, 存储其上^^的所述移动用户卡的特征信息。
9、一种用于电子支付***的移动通信网络, 用于实现更新智能卡对应的 移动用户号码,
所述移动通信网络包含短信网关,移动终端通过所述短信网关与 OTA服 务器相连, 将如权利要求 7所述的智能卡上报的所述移动用户卡的特征信息 发送给所述智能卡管理平台。
10、 如权利要求 9所述的移动通信网络, 其中,
所述移动通信网络还包含通用无线分组业务网关或分组数据业务节点网 关, 所述移动终端通过所述通用无线分组业务网关或所述分组数据业务节点 网关与所述 OTA服务器相连,将所述智能卡上报的所述移动用户卡的特征信 息发送给所述智能卡管理平台。
11、 一种用于电子支付***的智能卡管理平台, 用于实现更新智能卡对 应的移动用户号码,
所述智能卡管理平台设置为根据由如权利要求 7所述的智能卡上报的所 述移动用户卡的特征信息更新本地记录的所述智能卡对应的移动用户号码; 所述智能卡管理平台还设置为在接收到所述智能卡上报的所述移动用户 卡的特征信息后, 向所述智能卡发送响应消息, 以使所述智能卡在接收到所 述响应消息后存储其上"¾的所述移动用户卡的特征信息。
12、 如权利要求 11所述的智能卡管理平台, 其中, 所述智能卡管理平台 还包括应用提供商管理平台和卡发行商管理平台。
13、 一种用于电子支付***的移动终端, 其包括如权利要求 7所述的智 能卡和移动用户卡。
PCT/CN2009/000832 2008-10-24 2009-07-24 电子支付***、更新智能卡对应的移动用户号码的方法 WO2010045777A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200810173204.X 2008-10-24
CN200810173204.XA CN101727706B (zh) 2008-10-24 2008-10-24 电子支付***、更新智能卡对应的移动用户号码的方法

Publications (1)

Publication Number Publication Date
WO2010045777A1 true WO2010045777A1 (zh) 2010-04-29

Family

ID=42118908

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/000832 WO2010045777A1 (zh) 2008-10-24 2009-07-24 电子支付***、更新智能卡对应的移动用户号码的方法

Country Status (2)

Country Link
CN (1) CN101727706B (zh)
WO (1) WO2010045777A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103581873A (zh) * 2012-07-25 2014-02-12 中国电信股份有限公司 智能卡与用户识别模块安全绑定的方法、***和管理平台
CN103619013A (zh) * 2013-12-04 2014-03-05 孙国华 手机与智能卡交互应用的安全绑定方法
CN104753909B (zh) * 2013-12-31 2016-12-07 腾讯科技(深圳)有限公司 信息更新后的鉴权方法、装置及***

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5915226A (en) * 1996-04-19 1999-06-22 Gemplus Card International Prepaid smart card in a GSM based wireless telephone network and method for operating prepaid cards
KR100749247B1 (ko) * 2006-02-24 2007-08-13 (주) 엘지텔레콤 모바일 쇼핑서비스 데이터베이스 서버에 저장된 ic 칩사용자의 원장 정보에 기록된 휴대폰 번호를 실제 사용하고있는 번호로 변경하는 방법
KR100845325B1 (ko) * 2007-04-10 2008-07-10 주식회사 케이티프리텔 무선 자동 등록을 이용한 wcdma 단말기 가입자 전화번호 변경 방법

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101171604A (zh) * 2005-03-07 2008-04-30 诺基亚公司 包括智能卡模块和近场通信装置的方法和移动终端设备
GB0506570D0 (en) * 2005-03-31 2005-05-04 Vodafone Plc Facilitating and authenticating transactions
CN101193372B (zh) * 2006-11-20 2010-10-13 太思科技股份有限公司 双卡组合的安全方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5915226A (en) * 1996-04-19 1999-06-22 Gemplus Card International Prepaid smart card in a GSM based wireless telephone network and method for operating prepaid cards
KR100749247B1 (ko) * 2006-02-24 2007-08-13 (주) 엘지텔레콤 모바일 쇼핑서비스 데이터베이스 서버에 저장된 ic 칩사용자의 원장 정보에 기록된 휴대폰 번호를 실제 사용하고있는 번호로 변경하는 방법
KR100845325B1 (ko) * 2007-04-10 2008-07-10 주식회사 케이티프리텔 무선 자동 등록을 이용한 wcdma 단말기 가입자 전화번호 변경 방법

Also Published As

Publication number Publication date
CN101727706B (zh) 2013-06-05
CN101727706A (zh) 2010-06-09

Similar Documents

Publication Publication Date Title
US12022571B2 (en) Profile between devices in wireless communication system
RU2630419C2 (ru) Интегрированный мобильный доверенный менеджер услуг
KR101514754B1 (ko) non-UICC SE를 구비한 이동통신 단말기에 중요 정보를 OTA 프로비저닝 하는 시스템 및 방법
EP2352252B1 (en) Key distribution method and system
US9161218B2 (en) System and method for provisioning over the air of confidential information on mobile communicative devices with non-UICC secure elements
US8265599B2 (en) Enabling and charging devices for broadband services through nearby SIM devices
US8781131B2 (en) Key distribution method and system
KR20130116905A (ko) 모바일 지갑 및 그의 관련 정보 관리 시스템 및 방법
US11422786B2 (en) Method for interoperating between bundle download process and eSIM profile download process by SSP terminal
US20100275269A1 (en) Procedure for the preparation and performing of a post issuance process on a secure element
WO2010051715A1 (zh) 智能卡从安全域初始密钥分发方法、***及移动终端
US11963261B2 (en) Method and apparatus for recovering profile in case of device change failure
TW564627B (en) System and method for authentication in public networks
WO2010051714A1 (zh) 智能卡从安全域密钥更新分发方法、***及移动终端
WO2010045821A1 (zh) 密钥更新方法和***
US10007902B2 (en) Communications network, computer system, computer-implemented method, and computer program product for providing a femtocell-based infrastructure for mobile electronic payment
WO2010051713A1 (zh) 智能卡的从安全域初始密钥分发方法和***、移动终端
JP5626102B2 (ja) 端末装置、及び端末装置における使用制限解除方法
WO2010045777A1 (zh) 电子支付***、更新智能卡对应的移动用户号码的方法
CN116097636A (zh) 用于设备之间的链接或配置文件传输的装置和方法
WO2010051716A1 (zh) 一种智能卡从安全域密钥更新分发方法、***及移动终端
EP4027602A1 (en) Mutual device-to-device authentication method and device during device-to-device bundle or profile transfer
US20220385670A1 (en) Method and device for setting state of bundle after transfer of bundle between apparatuses
US20220278985A1 (en) Method and device for transferring bundle between devices
JP2007128394A (ja) 基地局装置、端末装置および通信システム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09821498

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09821498

Country of ref document: EP

Kind code of ref document: A1