Popular keywords:LN3C60LN3C60LN3C50LN3C50LN1F28LN1F28

Basic knowledge of smart cards

Release time:2018-04-10 09:54:37

1.1 Basic knowledge of smart cards

1.1.1 What is a smart card

The name of the smart card comes from the English noun“ Smart card” Also known as integrated circuit card, or IC card. It embeds an integrated circuit chip into a plastic substrate and packages it in the form of a card, similar in appearance to a magnetic card covered with a magnetic stripe.

The concept of IC card was proposed in the early 1970s. The French company BULL first created IC card products in 1976 and applied this technology to multiple industries such as finance, transportation, healthcare, and identity verification. It combines electronic and computer technology, improving the modernization of people's lives and work.

IC card chips have the ability to write and store data, and the contents of the IC card memory can be conditionally read externally as needed, for internal information processing and judgment purposes. According to the different integrated circuits embedded in the card, it can be divided into the following three categories:

The integrated circuit in the memory card is EEPROM (programmable read-only memory that can be electrically erased)

The integrated circuit in the logic encryption card has encryption logic and ZEPROM.

The integrated circuits in the CPU card include the central processing unit (CPU), EEPROM, random access memory (RAM), and on-chip operating system (COS) embedded in the read-only memory (ROM).

Strictly speaking, only CPU cards are true smart cards, but in this book, for the sake of comprehensiveness and application needs, we will study and discuss the three types of IC cards mentioned above.

According to the application field, IC cards are divided into two types: financial cards and non-financial cards.

Financial cards include credit cards and debit cards. Credit cards are mainly issued and managed by banks, and cardholders use them as payment tools for consumption, allowing them to use pre-set overdraft limit funds. Cash cards can be used as electronic passbooks and wallets, and overdrafts are not allowed.

Non financial cards often appear in various management and security management places, such as identity verification, health records, and employee attendance.

According to the form of data transmission between the card and the outside world, there are two types: contact type IC card and non-contact type IC card. The currently widely used is the contact type IC card, on which the IC chip has 8 contacts that can be in contact with the outside world. The integrated circuit of non-contact IC cards does not lead out contacts, so in addition to the circuits of the three types of IC cards mentioned above, it also includes RF transceiver circuits and related circuits.

Before the introduction of IC cards, magnetic cards had been widely used worldwide. In order to smoothly pass from the magnetic card to the IC card and for compatibility, the original function of the magnetic card was still retained on the IC card, which means that the magnetic stripe was still attached to the IC card. Therefore, the IC card can also be used as a magnetic card at the same time. The appearance of the IC card is: there are 8 contacts in the small square on the left side of the front, with convex characters below and a magnetic stripe on the back. Various patterns and even portraits can be printed on the front. The size of the card, the position and purpose of the contacts, the position of the magnetic stripe, and the data format are all clearly defined by corresponding international standards.

Whether it is a magnetic card or an IC card, there is a unique identification mark of the issuer and cardholder on the card, which is sometimes referred to as an identification card.

1.1. Interface devices for IC cards

In order to use the card, an interface device IFD (InterFace Device), also known as a read-write device, is required to work in conjunction with the IC card. IFD can be an independent device composed of a microprocessor, keyboard, display, and I\/O interface. This interface device provides power to the IC card through 8 contacts on the IC card and exchanges information with the IC card. IFD can also be a simple interface circuit, through which an IC card is connected to a general-purpose microcomputer. Whether it is a magnetic card or an IC card, the information that can be stored on the card is always limited, so most of the information needs to be stored in interface devices or computers. When shopping with a credit card, if it is within the allowed overdraft range, the goods can be taken out first and settled later; If a large sum of money is required, it must be confirmed by the bank and authorized by the store before the goods can be taken away. Due to the fact that the bank, credit card issuing company, and store are not located in the same place, communication lines and computers (hosts) are required to achieve the above process.

The security and response time of computer networks and communication lines are crucial for fast and reliable processing.

1.2 Fundamentals of Financial Card Applications

IC cards are mainly used as financial cards, and the main function of financial cards is to store and process data.

1.2.1 Information Provided by IC Card

1. The readable information printed on the card is used to identify the issuer's logo, expiration date, customer name, account number, signature, etc. These information are the basis for the card to be used as a payment tool in financial transactions.

2. The protruding characters on machine-readable data cards are used to imprint bills, in order to provide transaction vouchers to sellers and customers. The card can also provide financial transaction accounts.

3. Provide machine-readable identifiers for authorization and data collection systems.

1.2.2 Example: Withdrawing money from an ATM

The following is an example of an automated teller machine (ATM).

An ATM is a machine placed in the lobby of a bank or store for customers to withdraw money automatically (some ATMs also have automatic deposit functions). The process of withdrawing cash from an ATM only takes a few seconds, requiring a total of four input actions:

1. Insert a financial card;

2. Enter personal identification code (PIN);

3. Choose the transaction type (withdrawal);

4. Provide the amount requested for withdrawal.

When the ATM detects no issues, it automatically outputs cards and cash, and prints vouchers. It can be seen that ATM is a convenient information processing system that can provide services 24 hours a day.

ATM is a computer system installed in a cabinet that processes four types of media: cards, currency, receipts, and envelopes (for deposits), and can communicate with connected remote computers. It has rigorous and reliable physical and logical security measures inside. Each of its transactions is typically subject to proper authorization and strict control, making ATM systems both simple to operate and complex to construct.

ATM connects the data on the magnetic stripe (for magnetic cards), such as the issuer and customer account identification codes (used to obtain automatic authorization information), to the issuing unit's computer and its account database through communication lines to check the number of the financial card (check the blacklist) to prevent others from using the reported lost or stolen financial card. At the same time, it checks the customer's account records to determine the amount available for payment, and updates the account records based on the transaction amount for the next use of the financial card. In addition, in order to avoid certain possible drawbacks (such as being reported lost but not yet blacklisted), it is also necessary to limit the number of times financial cards can be used within a day and the total amount of cash that can be withdrawn within a day. The vast majority of ATM machines also require entering a personal identifier PIN when withdrawing money, and sending the PIN to the computer to verify whether the cardholder is the owner of the card. If a PIN is transmitted in plain text over a communication line, there is a risk of eavesdropping. Therefore, it is necessary to encrypt the PIN, which requires providing an encryption algorithm and; Key” The encrypted PIN is transmitted over the communication line and decrypted at the receiving end, thus requiring key management and protection at the receiving end.

1.2.3 Allocation and Function Introduction of IC Card Storage Area

The storage capacity of IC cards is much larger than that of magnetic cards, usually divided into four storage areas.

1. Public (non confidential) storage areas contain common information such as issuance identifiers, cardholder accounts, etc.

2. The content stored in the external unreadable storage area is for internal decision-making purposes, such as PIN values, which are personalized and written during card issuance. After entering the correct PIN value, users are allowed to enter a new PIN value for modification, but under no circumstances are the PIN values stored in the card allowed to be transmitted to the outside world. Keys may also be stored in this storage area.

3. The confidential storage area contains account balances, types of services allowed for card use, and limits. After the cardholder inputs the correct PIN value, it is allowed to read the data in this storage area and write the correct data according to the application situation (such as modifying the balance).

4. The recording area contains the details of each transaction, called a log, which can be queried.

In addition to memory cards, there are logic circuits or microprocessors in other IC cards that provide secure and reliable services.

1.2.4 Introduction to Interface Device Memory Content

The interface device (also known as a read-write device or card reader) used in conjunction with smart cards should provide additional memory and logic circuits, and it may itself be a microcomputer.

The memory used for interface devices in the store contains the following contents:

1. The transaction data contains records of each transaction, which are usually summarized and sent to the account opening bank or issuing bank every evening for transfer and settlement purposes. Banks should ensure timely deposit of accounts payable into the seller's account.

2. The Illegal Card List (also known as the Blacklist or Stop Payment List) lists all accounts that have been reported lost, stolen, or overdrawn beyond their limit. This list is also submitted daily when submitting transaction details to the bank. At the same time, after summarizing, the bank should provide the modified blacklist to the seller. Any account listed on the blacklist or overdrawn must be further authorized and verified by the seller's dedicated telephone and bank before it can be accepted for trading. You can also refuse to handle it, and even confiscate the card according to the actual situation.

3. Confidential data keys and authorized phone numbers are considered confidential data, and the keys are used to generate verification codes to prevent transaction logs from being modified. As for the authorization phone, when the seller wishes to complete certain excess transactions, they can use it to connect to the user's bank and obtain authorization from the bank before processing. If the phone communication line is busy, the waiting time for authorization may be very long, and even make customers feel intolerable, which will affect the promotion and application of financial cards. Advanced systems should rely on computer networks and communication lines to complete authorization

Function.

1.2.5 The process of using a smart card to complete a shopping transaction

The operation sequence is as follows:

1. The customer brings their financial card and purchased goods to the payment counter. And insert the financial card into a small suspicious device that can input a PIN.

2. The salesperson inputs the transaction amount through their own keyboard.

3. The transaction amount is displayed on the display panel of the keypad device.

4. The customer presses‐ on the keypad; The next specified key indicates recognition of the transaction amount.

5. The display panel of the keypad device instructs the customer to enter a PIN. Then the customer enters the PIN. After entering, it will automatically compare with the PIN in the card. If it matches, the financial card will be opened and ready to accept the transaction.

6. Then the interface device performs a series of internal processes, such as checking the blacklist, verifying whether the funds are sufficient, calculating the balance after the transaction, registering it in the transaction log record, and calculating the security check code to be added to the daily forget record to ensure data security. At the same time, write this transaction record into the financial card. Finally, print the receipt for the customer.

7. The display board indicates the end of the transaction, and the customer retrieves the goods and card.

1.2.6 Factors related to the development of smart cards and people

The relevant aspects involved in smart card operations include: cardholders or users, stores, card issuers and sales departments, card designers, sellers, and security maintenance.

1. Cardholders or users

User requirements:

· Easy to use: The location of the device, the time of use, and the steps of operation should be as convenient as possible. You can learn how to operate it as soon as you learn.

· Easy activation procedures: The issuance and personalized processing of cards based on PIN numbers are easy.

· Accelerate transaction time: Try to shorten the waiting time for a transaction or authorization as much as possible.

· Safe and reliable: Each transaction is correct and error free, and restarting after operational errors is convenient and reliable. Card loss, theft, and PIN value replacement are easy to handle.

· Operation instructions for cleaning the incinerator: The interface direction should be clearly indicated on the card, and the display screen should be clear and easy to read, avoiding the use of computer terminology and complex interactive operations.

2. Store

Store expectations:

· Easy personnel training, simple operation process and exception handling.

· Simple fault handling: Fault handling includes restarting after an error, handling exceptional situations or transactions that are disrupted, and alternative measures when normal solutions fail.

· Safe and reliable: The handling method for lost, stolen, and unpaid cards is simple and secure, and it is easy to detect various unsafe factors.

3. Card issuer and sales department

In addition to meeting the requirements of the store and users, information exchange between relevant parties (banks, stores, users) should be done well, as well as handling the situation where users forget their PIN.

4. Designers, Sellers, and Security Maintenance

The design objectives should meet the requirements of both users and the store. Electronic devices should be able to work continuously 24 hours a day and be easily tested to determine if the smart card is working properly. Mechanical design should ensure reliable operation of equipment and components. Design a handling method for exceptional situations and be able to quickly troubleshoot.

1.2.7 Types of Smart Cards

1. Pre establish a limit for overdrafts in the credit card, that is, pre-set the amount of funds that can be borrowed, and assume the responsibility of repaying at maturity and collecting interest. According to the different credit levels of cardholders, there are two types of credit cards: Gold Card and Prime Card. The former has a high overdraft limit.

2. Cash cards (payment cards) are used for savings accounts, and the funds used for card holding are the deposits already deposited in the bank by the cellar account.

3. ATM cards are cash or credit cards that can only be used at ATMs.

4. Prepaid cards are purchased based on their face value and can be purchased before use, such as prepaid cards for telephones and public systems, prepaid cards for electricity meters, etc.

In addition, there are cards such as those used inside large hotels. After entering the hotel, guests can use the card to keep accounts for accommodation, dining, entertainment, etc., and check out when leaving the hotel.

1.3 Security Issues of Smart Cards

The role of smart cards is to replace cash or checks in the circulation field. With the promotion and use of smart cards, the use of them for fraud or cheating will continue to increase. To solve the security problems that arise, a compromise solution needs to be proposed between providing reasonable effectiveness and protection guarantees and the required costs and investments.

1.3.1 Basic Issues Affecting Smart Card Security

The following basic issues need to be addressed among numerous smart card security concerns:

1. The information flow between smart cards and interface devices enables these circulating information to be intercepted and analyzed, thereby allowing for replication or insertion of false signals.

2. Simulate smart cards (or counterfeit smart cards) to simulate the information between the smart card and the interface device, so that the interface device cannot determine whether it is a legitimate or simulated smart card.

3. In the transaction, the company replaces the smart card using a legitimate smart card during the authorization process, and replaces it with another card before the transaction data is written, so the transaction data is written to the substitute card.

4. Modify the date for controlling balance updates in the credit card. When using the credit card, the current date needs to be entered for the card to determine whether it is the first use of the day, that is, whether the valid balance item should be updated to the highest authorized balance (as mentioned earlier, the maximum amount allowed to be withdrawn within a day). If the date for controlling balance updates (the last use date) is modified and advanced, the interface device will mistakenly believe that it is the first withdrawal of the day, and update the valid balance to the highest authorized balance. Therefore, using a stolen card to determine the highest authorized amount is also harmful in that it can be repeatedly cheated (before the bank proposes a new blacklist).

5. Cheating behavior of store employees: The data written into the card by the interface device is incorrect, or the employee privately writes one transaction as two transactions. Therefore, the interface device is not allowed to be borrowed, dismantled or modified without authorization.

1.3.2 Safety measures

For safety protection, the following measures are generally taken:

1. Mutual verification of the legality of cardholders, cards, and interface devices,

2. Important data is encrypted and transmitted.

3. Set up a secure zone in the card and interface device, which includes logic circuits or external unreadable storage areas. Any harmful and non compliant operations will automatically prohibit further operation of the card.

4. Relevant personnel shall clarify their respective responsibilities and strictly abide by them.

5. Set up a stop payment list (blacklist).

1.3.3 Key and Authentication

1. Two commonly used password algorithms in IC card systems

(1) Symmetric key cryptography algorithm

Or Secret Key Cryptography Algorithm (DES)

(2) Asymmetric key cryptography algorithm or public key cryptography algorithm (RSA)

One of these two password algorithms can be used for mutual authentication and data encryption between cardholders, smart cards, and interface devices. Encryption is also related to decryption and encryption management, while key management includes key generation, distribution, storage, and destruction. Encrypt the transmitted information to prevent theft and alteration, thereby avoiding losses. Encrypt and protect stored information so that only those who have access to the key can read it.

2. Certification

To prevent information from being tampered with, forged, or later denied, especially for the transmitted information, encryption authentication becomes even more important.

(1) Information verification prevents information from being tampered with, protects the integrity of information, and requires the discovery of modified data at the time of receipt. For example, certain algorithms can be used to generate additional verification codes for verification at the receiving point.

(2) Digital signature (electronic signature) requirement: The recipient must be able to confirm the sender's signature; After the sender signs, they cannot deny their own signature; When a conflict arises, the notary public (second party) can arbitrate the issue between the sender and receiver.

To achieve digital signatures, it is generally required to use a public key solution.

(3) Identity authentication: Use password or personal identification number PIN for authentication. A more reliable method is to use biometric features.

1.3.4 Cheating on Cards

From the usage of magnetic cards, there are two situations that cause losses to the issuing bank,

1. The bad debt cardholder will not pay the bill when it arrives.

Cheating is caused by criminal behavior, so some preventive measures are taken in the factory to prevent plastic card death. For example, VISA card has taken the following measures: there is a holographic pigeon shape on the front; Fine background printing; A non convex identification number with a signature strip on the card. When the signature is changed, the signature strip immediately displays VOID (void).

Other personal identifiers such as photos and fingerprints can also be made as needed.

In addition to cards, magnetic stripes are also problematic. For example, the records on magnetic stripes have the following characteristics: readable, modifiable, falsifiable, imitable, and erasable.

In order to avoid losses caused by cheating, authorization verification is required when using magnetic cards, especially when exceeding the current limit.

Reading information from IC cards is more difficult than magnetic cards, especially smart cards, which can be encrypted and verified to make it difficult to impersonate or forge. Therefore, compared to magnetic cards, it can be used offline. But in reality, there is no absolute secret, because objectively there are strong opponents who can find a decryption method even if they have encryption methods. It's just a matter of how much it costs and whether it's worth it. Even good designs have varying degrees of vulnerability that can be easily broken.

1.4 International standards for identification cards

Due to the fact that credit cards can be used both domestically and internationally, it is urgent to establish international and national standards, and national standards should strive to be consistent with international standards.

Identification card is a type of card that can recognize its issuer and holder. The most commonly used payment service in Jinchang is credit cards, which are a type of identification card. Identification cards are divided into two types: magnetic cards and IC cards.

1.4.1 International standards for magnetic cards

1. Physical properties include the material, construction, characteristics, and nominal size of the card

All dimensions should comply with the international standard ISO7816:1985.

2. The characters that protrude significantly on the front of the embossed card are called embossed marks, which are used for data transmission. This transmission can be done through an embossing machine or by visual or machine reading. The embossed characters include the identification number, cardholder's name, and address. Common IDs‐ The position of the embossed characters on the L-shaped card should comply with the international standard SO7SII; 3: The regulations of 1985.

The selection of embossed characters and their fonts should comply with ISO tO73— I and ISO LO73‐ 2 and ISO7811‐ The regulations for the 7B font described in Appendix B and Appendix C, as well as the spacing and height of embossed characters, comply with the international standard ISO7811; 1: The regulations of 1985. The printing specifications for embossed characters comply with the provisions of ISO1831:1980.

3. There are corresponding international standards ISO7811 for the physical and performance characteristics, encoding techniques, and encoding character sets of magnetic materials on magnetic strips; 2: 1985. On the magnetic stripe: there are three tracks in total, the first and second tracks are read-only tracks, and the third track is a read-write track, which comply with the international standard ISO7811— 4: 1985 and ISO7811‐ 5: 1985.

1.4.2 International standards for IC cards (contact type)

1. The physical characteristics shall comply with the physical characteristics of various identification cards specified in ISO7816:1987 and all size requirements of financial transaction cards specified in ISO7813. In addition, it shall also comply with the international standard ISO7816— 1: Additional characteristics, mechanical strength, and electrostatic testing methods specified in 1987.

2. Contact size and position.

Should comply with the international standard ISO 7816‐ 2: The regulations in 1988.

3. Electrical signals and transmission protocols.

The power and information exchange between IC cards and interface devices should comply with ISO\/IEC7816— 3: The regulations of 1989.

4. Inter industry exchange commands.

There are corresponding international standards ISO\/IEC7816‐ 4: 1994. But this version has not yet been officially approved.

5. The numbering system and registration process of application identifiers should comply with the international standard ISO\/IEC7816; 5: The regulations in 1994.

The international standards for IC cards are one of the key points of this book, which will be described in Chapters 3 and 4.

It is worth mentioning that international standards are constantly enriched and improved, and even those that have already been adopted may still have the possibility of modification. Readers should pay attention to the latest versions of international standards.

\tCopyright 2018 a-life.cn All Rights Reserved
网站ICP备案号:粤ICP备2023103279号

Support:Website | zk71  | Manage

此站支持多站浏览

此站支持多站浏览

多端浏览

Shenzhen Yixiu Decoration Co., Ltd. Address: Xin'an Street, Bao'an District, Shenzhen Postal Code: 116033 Phone: 0755-88849616 Fax: 0755-88849616