A kind of safety means and many application systems towards ubiquitous network
Technical field
The present invention relates to a kind of safety means towards ubiquitous network and system, especially relate to a kind of safety means towards ubiquitous network, many application systems and safety method.
Background technology
In Future Ten year, mobile phone will replace computer becomes next computer center, and the wireless city has solved the universal problem that ubiquitous calculating, many nets are merged, and has promoted ecommerce to move to Mobile business, mobile payment welcome explosive development golden age.Juniper Research estimates, by 2015, the mobile payment transaction volume will be broken through 1,700 hundred million dollars, and 2011 to be only be 60,000,000,000 dollars.Mobile payment will become the next Killer of mobile value-added service and use.The combination of NFC, UHF, Zigbee, WiFi technology and mobile payment is trend of the times, and is also imperative based on both innovation and application.The present invention proposes take intelligent terminal (smart mobile phone, panel computer etc.) as platform, take security module as carrier, take e-commerce platform as support, foundation realizes the slitless connection with existing card issuance management system, transaction clearance settlement system, integration banking system, DSS, data interchange platform towards the many application systems of mobile payment of the ubiquitous computing environment in wisdom city.Be different from general mobile-payment system, the present invention adopts NFC, UHF, Zigbee, WiFi to merge access technology, distributed cipher key technology, Embedded Middleware technology, many interfaces adaptation technique, mobile radio communication, wireless sense network, the Internet are organically blent, realize high secret and safe access, multipath fusion transmission, the conglomerate application integration in wisdom city.But this invention lacks ripe experience reference aspect system and model innovation, therefore, is no matter that radio-frequency (RF) identification, terminal are adaptive, application integration, security model, all needs technology upgrading and model innovation.In on 09 19th, 2011 disclosed No. 201210145966.5 Chinese invention patent application specifications, a kind of " based on the mobile-payment system of WiFi signal identification " disclosed, this scheme is based on the mobile-payment system of WiFi signal identification, it is characterized in that, the user catches the WiFi wireless signal of businessman by handset program, therefrom obtain the sign of the WiFi of businessman transmitter, user program is identified at according to this businessman's payment information of seeking binding in server, and finally completes payment.The access way of this invention is too single, do not consider that wisdom city under ubiquitous computing environment nets characteristics and the advantage of fusion more, and the technological means that lacks safety guarantee in scheme, this patent will by building the mechanism of using access platform, adopting Special safety module and PKI to combine, improve Security of the system by the verification of multiple-factor combined crosswise more; The reliability, stability and the robustness that provide multipath automatically to select and backup each other to guarantee system transmissions; Realize the full coupling of mobile phone terminal by cross-platform middleware Technology, realize seamless integrated with existing system making existing system be able to smooth transition by technology such as digital signature, living things feature recognitions.This will improve the safety of user account fund and information greatly, solve in different scenes the dynamic adjustment problem of access rights, the avoid overlapping construction wasting of resources that causes and the difficult situation that interconnects.
Summary of the invention
One of purpose of the present invention is to provide a kind of safety means towards ubiquitous network, and this equipment can comprise a housing, major control chip MCU, ubiquitous network adapter and counterpart external device at least; MCU connects the ubiquitous network adapter by bus, and the transmitting-receiving instruction is controlled counterpart external device by the ubiquitous network adapter on bus; It is characterized in that described external equipment comprises a security module SE at least, also can comprise transceiver, amplifier, antenna or its combination, the mobile terminal that docks with the ubiquitous network adapter; Described SE is used for storage key, digital certificate, biological characteristic recognition information, individual privacy information, subscribed services information, and described subscribed services information comprises the preferential configuration information of network, security configuration information, the transaction configuration information that uses services selection in ubiquitous network; Described ubiquitous network adapter comprises the interface adapter of 3G, LTE, GSM, GPRS, WLAN, WiMax, RFID, Zigbee, NFC, Bluetooth, IrDA, SDIO, audio frequency, data wire and combination thereof, and this adapter adopts software middleware adapter, hardware adapter and combination thereof to accomplish to be connected with the ubiquitous of external environment condition equipment, system with safety means; Described external equipment is the equipment that docks with described interface adapter, comprises transceiver, amplifier, antenna, guarantees the reliable and stable of signal by the power of regulating transceiver, amplifier, antenna; Described major control chip MCU, described ubiquitous network adapter and the SE of being connected can be integrated into single-chip and be connected by integrated circuit with peripheral circuits such as transceiver, amplifiers, described antenna is the flexible antenna of magnetic conductivity, can flexural deformation with the structure of adaptive different safety means, signal is waltzed through magnetic conductive material or structure draws to guarantee the adaptive of signal.Described safety means can at least aly in storage card, SIM card, earphone, mobile terminal plug-in unit, mobile terminal suspension member, IC-card identity card, Citizen Card Item, USB memory device, charger be combined in twos, also can be embedded into mobile terminal, multi-functional fusion will greatly reduce product cost, innovation and application pattern, improve user's experience; Described instruction meets IS07816 standard, ISO14443 standard; Described security module SE meets EMV standard, PBOC2.0 standard, CUPMobile standard, compatible contactless quick debit/credit and uses QPBOC, contactless magnetic stripe and use seamlessly transitting that MSD is convenient to use.Because the shape of each Terminal Type is different, if the method by die sinking will cause cost high, if and described housing adopts soft material, telescopic mounting, the adaptive mobile terminal of discrete device combination, can with the manufacturer's standard of housing, be fit to extensive the manufacturing with satisfied needs cheaply.Described MCU, ubiquitous network adapter and counterpart external device are encapsulated in described housing or are attached on described housing by stickup, embedding, plug-in card, clamping, pressing mode, housing exists as a support component, can promote cost to reduce by printing advertisement, can also expand several functions such as wireless charging, card reader.
two of purpose of the present invention is to provide a kind of use towards many application systems of ubiquitous network safety means, and it comprises client, ubiquitous network adapter, merchant tenninal, authentication center, server and safety means, it is characterized in that described safety means comprise a housing at least, a major control chip MCU, the external equipment of an interface adapter and connection corresponding to it, described MCU connects described interface adapter by bus, described external equipment comprises a security module SE at least, described SE is the IC-card with Chip Operating System, described IC-card storage key, digital certificate, biological characteristic recognition information, individual privacy information, subscribed services information, described subscribed services information comprises that the network of use services selection in ubiquitous network is preferred, security configuration, mode of doing business, described interface adapter comprises the communications adapter of 3G, LTE, GSM, GPRS, WLAN, WiMax, RFID, Zigbee, NFC, Bluetooth, IrDA, SDIO, audio interface, data wire and combination thereof, described external equipment is the equipment that docks with described interface adapter, comprises transceiver, amplifier, antenna, described client comprises mobile phone, handheld terminal, panel computer and the application software mounted thereto of docking with described safety means, described merchant tenninal has comprised POS machine and application software mounted thereto, complete the service logic of businessman, the interface that complete described ubiquitous network adapter described client and described safety means, described merchant tenninal interconnect is adaptive, protocol conversion, transaction data transparent transmission function, realizes the fusion of many nets, Multipath Transmission, function interconnects, backups each other, described authentication center according to the security configuration in subscribed services information to the carrying out of transaction based on the multiple-factor cross-certification of PKI mechanism, according to demand for security in conjunction with multiple-factor combined crosswise verification cutting and optimize the PKI flow process and can farthest satisfy service needed on technology and the system, and dynamically adjust security strategy according to subscribed services information and ubiquitous network environment, described security strategy comprises at least based on identity, rule, role determines service level and priority, can dynamically adjust service level and priority according to rule according to identity, Counterchange roles, and can upgrade by licensing OTA the content of safety means storage, described server is realized many application integration, is responsible for the slitless connection with existing card issuance management system, transaction clearance settlement system, integration banking system, DSS, data interchange platform.Ubiquitous network access and communications that described ubiquitous network adapter provides are paid service; The user guarantees the safety of transaction by the transaction of described client, the initiation of described mobile phone transducer and described merchant tenninal by the mutual authentication of described safety means, described authentication center, described server; Described paid service comprises service charge, advertisement, paid service, if adopt this mode, publicly-owned or privately owned wireless facilities in the ubiquitous environment in wisdom city can register open out for the personal user to obtain remuneration, as have more, the Wifi focus covers widely, individual smart mobile phone also compensates obtaining for the people as the Wifi focus in the free time; Described transaction comprises accumulated point exchanging, integration exchange, reward voucher, consumes, pays the fees, payment, personal finance service, by user card punching can scores accumulated or electronic cash to server, can return profit to the user by integration exchange, accumulated point exchanging and other services of service, improve usage rate of the user, increase simultaneously the visit capacity of server, make it have advertisement new media potential quality, and then evolving advertisements displacement business in kind, with redeem points in kind or electronic cash.
Description of drawings
Fig. 1 is a kind of safety means structure principle chart towards ubiquitous network of the embodiment of the present invention one;
Fig. 2 is that a kind of use of embodiments of the invention two is towards many application systems structure principle chart of ubiquitous network safety means;
Embodiment
In actual use; mobile terminal also can be selected mobile phone, panel computer or PDA, and safety means can be with NFC function, the i Phone containment vessel that inserts the MicroSD financial IC card, NFC-SD finance IC card, NFC-SIM finance IC card, Wifi-TF finance IC card etc.
Embodiment one: a kind of safety means towards ubiquitous network, as shown in Figure 1, it comprises that this equipment can comprise at least that the housing 1 of PC plastics or silica gel material, major control chip AU6438BS are as MCU 2, interface adapter 3 and counterpart external device 4; MCU 2 connects the interface adapter 3 of 30 pins, 8 pins by usb bus 6, and the transmitting-receiving instruction is controlled counterpart external device 4 by interface adapter 3 on bus 6; It is characterized in that described external equipment 4 comprises a security module MicroSD financial IC card SE 5 at least, also comprises transceiver, amplifier, antenna, the iPhone mobile phone that docks with interface adapter 3 or Android mobile phone 7; Described SE 5 is used for storage key, digital certificate, biological characteristic recognition information, individual privacy information, subscribed services information, and described subscribed services information comprises the network mode of priority, safety method, method of commerce and the configuration information thereof that uses services selection in ubiquitous network; Interface adapter 3 comprises the communications adapter of Wifi, NFC, Bluetooth, SDIO, audio frequency, data wire and combination thereof, adopts the software middleware adapter to coordinate the method for hardware adapter to accomplish that safety means are connected with external environment condition equipment POS, the ubiquitous of Wifi focus; Described external equipment 4 is the equipment that docks with described interface adapter 3, comprises transceiver, amplifier, antenna, guarantees the reliable and stable of signal by the power of regulating transceiver, amplifier, antenna; Described major control chip MCU 2, described interface adapter and the SE of being connected can be integrated into single-chip and be connected by integrated circuit with peripheral circuits such as transceiver, amplifiers, as the MicroSD financial IC card with the Wifi function, described antenna is the Plastic Package flexible antenna of magnetic conductivity, for the mobile phone of security module 5 below battery, can draw to guarantee the adaptive of signal ubiquitous signal is waltzed through magnetic conductive material by bending, distortion, extension antenna.Described safety means 5 can at least aly in storage card, SIM card, earphone, mobile terminal plug-in unit, mobile terminal suspension member, IC-card identity card, Citizen Card Item, USB memory device, charger be combined in twos, also can be embedded into mobile terminal, multi-functional fusion will greatly reduce product cost, innovation and application pattern, improve user's experience; Described instruction meets IS07816 standard, ISO14443 standard; Described security module SE meets EMV standard, PBOC2.0 standard, CUPMobile standard, compatible contactless quick debit/credit and uses QPBOC, contactless magnetic stripe and use seamlessly transitting that MSD is convenient to use.Because the shape of each Terminal Type is different, if the method by die sinking will cause cost high, if and described housing adopts the adaptive mobile terminal 7 of method of silica gel material, chute or discrete device combination, can with the manufacturer's standard of housing 1, be fit to extensive the manufacturing with satisfied needs cheaply.MCU 2, interface adapter 3 and counterpart external device 4 are encapsulated in housing 1 or are attached on housing 1 by stickup, embedding, plug-in card, clamping, pressing mode by Shooting Technique, housing 1 exists as a support component, can print partner's advertisement and promote cost to reduce, can also expand several functions such as wireless charging, card reader; Described SE can adopt financial IC card, Citizen Card Item, social security card, prepaid card, member card, identity card, consumption card, the card of paying the fees, and docks with mobile phone 7 by inserting housing.
embodiment two: a kind of many application systems of using towards the ubiquitous network safety means, and as shown in Figure 2, it comprises client 1, ubiquitous network adapter 2, merchant tenninal 3, authentication center 4, server 5 and safety means SE 6 at least for it, it is characterized in that described safety means 6 comprise a PC plastic casing at least, a major control chip AU6438BS is as MCU, 30 pins, the iphone mobile phone of the interface adapter of 8 pins and connection corresponding to it, described MCU connects described interface adapter by bus, described external equipment comprises a MicroSD financial IC card security module SE at least, described SE is the IC-card with Chip Operating System, described IC-card storage key, digital certificate, biological characteristic recognition information, individual privacy information, subscribed services information, described subscribed services information comprises the network method for optimizing that uses services selection in ubiquitous network, safety method, method of commerce, described interface adapter comprises the communications adapter of 3G, LTE, GSM, GPRS, WLAN, WiMax, RFID, Zigbee, NFC, Bluetooth, IrDA, SDIO, audio interface, data wire and combination thereof, described external equipment is also to comprise with described interface adapter docking transceiver, amplifier, antenna, described client 1 comprises mobile phone, handheld terminal, panel computer and the APP application software mounted thereto of docking with described safety means 6, described merchant tenninal has comprised POS machine and application software mounted thereto, complete the service logic of businessman, as consumption, payment, the interface that complete described ubiquitous network adapter 2 described client and described safety means, described merchant tenninal interconnect is adaptive, protocol conversion, transaction data transparent transmission function, realizes the fusion of many nets, Multipath Transmission, function interconnects, backups each other, described authentication center according to the security configuration in subscribed services information to the carrying out of transaction based on the multiple-factor cross-certification of PKI mechanism, according to demand for security in conjunction with multiple-factor combined crosswise verification cutting and optimize the PKI flow process and can farthest satisfy service needed on technology and the system, and dynamically adjust security strategy according to subscribed services information and ubiquitous network environment, described security strategy comprises at least based on identity, rule, role determines service level and priority, can dynamically adjust service level and priority according to rule according to identity, Counterchange roles, and can upgrade by licensing OTA the content of safety means storage, described server is realized many application integration, is responsible for the slitless connection with existing card issuance management system, transaction clearance settlement system, integration banking system, DSS, data interchange platform.Ubiquitous network access and communications that described ubiquitous network adapter provides are paid service; The user guarantees the safety of transaction by the transaction of described client, the initiation of described mobile phone transducer and described merchant tenninal by the mutual authentication of described safety means, described authentication center, described server; Described paid service comprises service charge, advertisement, paid service, if adopt this mode, publicly-owned or privately owned wireless facilities in the ubiquitous environment in wisdom city can register open out for the personal user to obtain remuneration, as have more, the Wifi focus covers widely, individual smart mobile phone also compensates obtaining for the people as the Wifi focus in the free time; Described transaction comprises accumulated point exchanging, integration exchange, reward voucher, consumes, pays the fees, payment, personal finance service, by user card punching can scores accumulated or electronic cash to server, can return profit to the user by integration exchange, accumulated point exchanging and other services of service, improve usage rate of the user, increase simultaneously the visit capacity of server, make it have advertisement new media potential quality, and then evolving advertisements displacement business in kind, with redeem points in kind or electronic cash.
Those skilled in the art can also carry out various modifications to above content under the condition that does not break away from the definite the spirit and scope of the present invention of claims.Therefore scope of the present invention is not limited in above explanation, but determined by the scope of claims.The modification of various kinds.Therefore scope of the present invention is not limited in above explanation, but determined by the scope of claims.