Authorization, offline payment, and collection method and device for offline payment
By generating and issuing user certificates through the server, the problem of needing to activate and top up offline wallet payments in advance is solved, enabling offline payment authorization even without internet access, thus improving the convenience and security of offline payments.
Patent Information
- Application Number
- CN202411702302.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-27
- Publication Date
- 2026-03-17
- Estimated Expiration
- 2041-09-27
AI Technical Summary
In existing technologies, offline wallet payments require pre-activation and top-up while the terminal device is connected to the internet, which leads to usage limitations, especially in unpredictable offline situations where offline payment services cannot be used in a timely manner.
The server detects the status of the target e-wallet account, generates and issues a user certificate, which includes the offline payment limit, signature and validity period, allowing offline accounts to authorize offline payments when connected to the internet, eliminating the need for pre-charging and activating the hardware wallet.
This allows offline accounts to make payments within their offline payment limits without needing to pre-charge or activate the hardware wallet, improving the convenience and flexibility of offline payments and avoiding financial losses and unnecessary network traffic consumption.
Smart Images

Figure CN119624443B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application filed on September 27, 2021, with application number 2021111475911 and titled "An Authorization, Offline Payment, Collection Method and Device for Offline Payment". Technical Field
[0002] This specification relates to the field of electronic payment technology, and in particular to an authorization method, offline payment method, and device for collecting payments from offline devices. Background Technology
[0003] Offline wallet payments (offline payments) are an important supplement to online payments. Offline payments typically occur in specific scenarios, such as on airplanes, in basements, and in mountainous areas.
[0004] Currently, offline wallet payment solutions require the terminal device to be connected to the internet to activate the offline wallet (i.e., open an offline account) and "top up" a certain amount of money into the offline wallet. Then, when the terminal device is offline, users can use the offline wallet payment service.
[0005] However, activating and topping up the offline wallet in advance imposes certain limitations on its practical application in offline wallet payment scenarios. Summary of the Invention
[0006] This specification provides one or more embodiments of an offline payment authorization, offline payment, and a method and apparatus for collecting payments from offline devices, so as to enable the authorization of offline payment functions without prior top-up.
[0007] According to the first aspect, an offline payment authorization method is provided, applied to a server, the method comprising:
[0008] When the current status of the target e-wallet account is detected to meet the preset certificate issuance conditions, the wallet account information, current account balance and current credit information of the target e-wallet account are obtained;
[0009] Based on the current account balance and the current credit information, determine the corresponding offline payment limit;
[0010] Using the server's private key, the aggregated information is signed to obtain an electronic wallet signature. The aggregated information includes the wallet account information, the offline payment limit, the issuance time, and the validity period.
[0011] Based on the aggregated information and the e-wallet signature, a user certificate is generated;
[0012] The user certificate is sent to the terminal device where the target e-wallet account is located, so that the offline account corresponding to the target e-wallet account can make offline payments within the offline payment limit based on the user certificate.
[0013] In one possible implementation, the preset certificate issuance conditions include at least one of the following conditions: the target e-wallet account's obtained user certificate has expired, and the terminal device is connected to the network.
[0014] During the first period before the expired user certificate, and while the terminal device is connected to the network;
[0015] In the second time period before the expired user certificate, and when the traffic usage status of the terminal device meets the preset idle condition;
[0016] The current account balance of the target e-wallet account and / or the changes in the current credit information meet certain conditions;
[0017] The target e-wallet account has not obtained a user certificate, and the data usage status of the terminal device meets the preset idle condition.
[0018] In one possible implementation, the wallet account information is: the hash value of the wallet account ID and wallet account name information corresponding to the target e-wallet account.
[0019] In one possible implementation, the current credit information includes at least one of the following: the current credit score and the current loanable amount.
[0020] In one possible implementation, the terminal device is equipped with a Trusted Execution Environment (TEE).
[0021] The step of sending the user certificate to the terminal device where the target e-wallet account is located includes:
[0022] The user certificate is distributed to the TEE of the terminal device so that the terminal device stores the user certificate in the TEE.
[0023] In one possible implementation, determining the corresponding offline payment limit based on the current account balance and the current credit information includes:
[0024] Based on the current account balance, the current credit information, and their respective weights, the current score of the target e-wallet account is determined.
[0025] Based on the current score, the offline payment limit corresponding to the target e-wallet account is determined.
[0026] In one possible implementation, determining the offline payment limit corresponding to the target e-wallet account based on the current score includes:
[0027] Based on the preset first correspondence between account scores and credit limit levels, the current credit limit level corresponding to the current score is determined;
[0028] Based on a preset second correspondence between credit limit levels and credit limit values, the credit limit value corresponding to the current credit limit level is determined as the offline payment limit.
[0029] In one possible implementation, it further includes:
[0030] Obtain the offline bill sent by the terminal device, wherein the offline bill is a bill generated by offline payment of the offline account, and includes at least the corresponding transaction amount and the wallet account information;
[0031] Based on the transaction amount and the wallet account information, the corresponding amount is deducted from the target e-wallet account;
[0032] Send a limit restoration message to the terminal device so that the current offline payment limit of the offline account is restored to the offline payment limit.
[0033] In one possible implementation, the offline bill further includes: corresponding merchant account information and merchant signature, wherein the merchant signature is obtained by signing the merchant account information and the transaction amount using the merchant's private key;
[0034] The step of deducting the corresponding amount from the target e-wallet account based on the transaction amount and the wallet account information includes:
[0035] The offline bill is verified using the merchant's public key corresponding to the merchant's private key;
[0036] If the verification is successful, the corresponding amount will be deducted from the target e-wallet account based on the transaction amount and the wallet account information.
[0037] According to the second aspect, an offline payment method is provided, applied to a terminal device, wherein the terminal device stores a user certificate issued by a server, the user certificate including at least an offline payment limit, issuance time, validity period, and e-wallet signature, and the method includes:
[0038] Upon receiving an offline payment instruction, it is determined whether the current transaction amount carried by the offline payment instruction is not greater than the current offline payment limit, wherein the current offline payment limit is determined based on the offline payment limit and the historical offline transaction amount;
[0039] If it is determined that the current transaction amount is not greater than the current offline payment limit, the user certificate is provided to the receiving device corresponding to the offline payment instruction;
[0040] Obtain transaction confirmation information provided by the payment receiving device, wherein the transaction confirmation information is sent by the payment receiving device after determining the validity of the user certificate based on the electronic wallet signature;
[0041] An offline invoice is generated based on the transaction confirmation information.
[0042] In one possible implementation, the terminal device includes a Trusted Execution Environment (TEE), the user certificate is stored in the TEE, and the method is executed in the TEE.
[0043] In one possible implementation, it further includes:
[0044] The validity of the user certificate is determined based on the receipt time of the offline payment instruction, the issuance time of the user certificate, and the validity period of the user certificate.
[0045] If the user certificate is found to be valid, the user certificate is provided to the payment receiving device.
[0046] In one possible implementation, it further includes:
[0047] Calculate the difference between the current offline payment limit and the current transaction amount;
[0048] The difference is determined as the new upper limit for current offline payments.
[0049] In one possible implementation, it further includes:
[0050] When connected to the internet, the offline bill is sent to the server so that the server can perform settlement based on the offline bill.
[0051] In one possible implementation, obtaining the transaction confirmation information provided by the payment receiving device includes:
[0052] The transaction confirmation information provided by the receiving device is obtained through short-distance transmission.
[0053] In one possible implementation, the transaction confirmation information includes: the merchant's account information, the current transaction amount, and the merchant's signature, wherein the merchant's signature is obtained by signing the merchant's account information and the current transaction amount using the merchant's private key;
[0054] The process of generating an offline bill based on the transaction confirmation information includes:
[0055] The transaction confirmation information is verified based on the merchant's public key corresponding to the merchant's private key;
[0056] If the verification is successful, an offline bill is generated based on the merchant account information, the current transaction amount, and the wallet account information.
[0057] According to a third aspect, a payment collection method for offline devices is provided, applied to a payment collection device, the method comprising:
[0058] Obtain a user certificate provided by an offline terminal device, wherein the user certificate is issued by a server and includes: the wallet account information of the e-wallet account corresponding to the terminal device, the offline payment amount, the issuance time and validity period of the user certificate, and the e-wallet signature;
[0059] The signature of the digital wallet is verified using the public key of the server.
[0060] If the verification is successful, the validity of the user certificate is determined based on the transaction time, the issuance time, and the validity period of this transaction.
[0061] If the user certificate is found to be valid, the corresponding transaction confirmation information for this transaction will be generated.
[0062] The transaction confirmation information is provided to the terminal device so that the terminal device can generate a corresponding offline bill based on the transaction confirmation information.
[0063] In one possible implementation, the transaction confirmation information includes at least: the merchant's account information, the transaction amount of this transaction, and the merchant's signature, wherein the merchant's signature is obtained by signing the merchant's account information and the current transaction amount using the merchant's private key.
[0064] In one possible implementation, providing the transaction confirmation information to the terminal device includes:
[0065] The transaction confirmation information is provided to the terminal device via short-distance transmission.
[0066] In one possible implementation, it further includes:
[0067] If the user certificate is determined to be invalid, a transaction failure message is generated;
[0068] The transaction failure information is provided to the terminal device.
[0069] According to the fourth aspect, an offline payment authorization device is provided, applied to a server, the device comprising:
[0070] The first acquisition module is configured to acquire the wallet account information, current account balance and current credit information of the target e-wallet account when the current status of the target e-wallet account meets the preset certificate issuance conditions.
[0071] The first determining module is configured to determine the corresponding offline payment limit based on the current account balance and the current credit information;
[0072] The first signature module is configured to use the server's private key to sign the aggregated information to obtain an electronic wallet signature. The aggregated information includes the wallet account information, the offline payment limit, the issuance time, and the validity period.
[0073] The first generation module is configured to generate a user certificate based on the aggregated information and the e-wallet signature;
[0074] The first sending module is configured to send the user certificate to the terminal device where the target e-wallet account is located, so that the offline account corresponding to the target e-wallet account can make offline payments within the offline payment limit based on the user certificate.
[0075] According to the fifth aspect, an offline payment device is provided, applied to a terminal device, the terminal device storing a user certificate issued by a server, the user certificate including at least an offline payment limit, issuance time, validity period, and electronic wallet signature, the device comprising:
[0076] The first judgment module is configured to, upon receiving an offline payment instruction, determine whether the current transaction amount carried by the offline payment instruction is not greater than the current offline payment limit, wherein the current offline payment limit is determined based on the offline payment limit and the historical offline transaction amount;
[0077] The first providing module is configured to provide the user certificate to the receiving device corresponding to the offline payment instruction if it is determined that the current transaction amount is not greater than the current offline payment limit.
[0078] The second obtaining module is configured to obtain transaction confirmation information provided by the receiving device, wherein the transaction confirmation information is sent by the receiving device after determining that the user certificate is valid based on the electronic wallet signature;
[0079] The second generation module is configured to generate offline bills based on the transaction confirmation information.
[0080] According to a sixth aspect, a payment receiving device for offline devices is provided, applied to a payment receiving device, the device comprising:
[0081] Obtain a user certificate provided by an offline terminal device, wherein the user certificate is issued by a server and includes: the wallet account information of the e-wallet account corresponding to the terminal device, the offline payment amount, the issuance time and validity period of the user certificate, and the e-wallet signature;
[0082] The third module is configured to verify the electronic wallet signature using the server's public key;
[0083] The second judgment module is configured to, if the verification passes, determine whether the user certificate is valid based on the transaction time of this transaction, the issuance time, and the validity period.
[0084] The third generation module is configured to generate transaction confirmation information corresponding to this transaction if the user certificate is found to be valid.
[0085] The second providing module is configured to provide the transaction confirmation information to the terminal device, so that the terminal device generates a corresponding offline bill based on the transaction confirmation information.
[0086] According to a seventh aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method described in the first aspect.
[0087] According to an eighth aspect, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method of the first aspect.
[0088] According to a ninth aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method described in the second aspect.
[0089] According to a tenth aspect, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method of the second aspect.
[0090] According to the eleventh aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method described in the third aspect.
[0091] According to a twelfth aspect, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method of the third aspect.
[0092] According to the method and apparatus provided in the embodiments of this specification, when the current state of the target e-wallet account meets the preset certificate issuance conditions, a user certificate corresponding to the target e-wallet account, including the offline payment limit, is generated using the wallet account information, current account balance, and current credit information of the target e-wallet account. This certificate is then issued to the terminal device where the target e-wallet account is located, enabling the offline account corresponding to the target e-wallet account to make offline payments within the offline payment limit based on the user certificate. In other words, the user certificate authorizes offline payments for the offline account, allowing offline payments within the offline payment limit without prior top-up or pre-deposit of funds. Furthermore, when this user certificate is issued for the first time to the target e-wallet account, it also eliminates the need to open an offline account corresponding to the target e-wallet account (i.e., eliminates the need to activate the corresponding hardware wallet), thus enabling offline payment authorization for the offline account without opening or prior top-up. Attached Figure Description
[0093] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0094] Figure 1 This is a schematic diagram illustrating the implementation framework of one embodiment disclosed in this specification;
[0095] Figure 2 A flowchart illustrating an offline payment authorization method provided in this embodiment;
[0096] Figure 3 A flowchart illustrating an offline payment method provided in this embodiment;
[0097] Figure 4 A flowchart illustrating a payment collection method for offline devices provided in an embodiment;
[0098] Figure 5 A schematic block diagram of an offline payment authorization device provided in an embodiment;
[0099] Figure 6 A schematic block diagram of an offline payment device provided in an embodiment;
[0100] Figure 7 This is a schematic block diagram of a payment collection device for offline devices provided in an embodiment. Detailed Implementation
[0101] The technical solutions of the embodiments of this specification will now be described in detail with reference to the accompanying drawings.
[0102] This specification discloses an offline payment authorization method and apparatus, an offline payment method and apparatus, and a payment collection method and apparatus for offline devices. The application scenarios and inventive concept of the offline payment authorization method are introduced below:
[0103] Currently, offline wallet payment solutions require the terminal device to be connected to the internet to activate the offline wallet (i.e., open an offline account) and "top up" a certain amount of money into the offline wallet. Then, when the terminal device is offline, users can use the offline payment service provided by the offline wallet.
[0104] Users often lack the habit of activating and topping up their offline wallets in advance, or are unsure if they will need offline payment services beforehand. In an example scenario: a user is traveling by plane and needs to make a purchase. At this time, the user's device is offline and has no internet connection. To use the offline wallet payment service, the user needs to pre-load money into their activated offline wallet while their device is connected to the internet. However, they often don't anticipate making purchases on the plane and therefore don't pre-load their offline wallets. Consequently, activating and topping up offline wallets in advance presents certain limitations for practical applications.
[0105] Therefore, this specification provides an offline payment authorization method, such as... Figure 1 The diagram shown illustrates an implementation framework of one embodiment disclosed in this specification, in which the server can detect the current status of multiple e-wallet accounts, such as... Figure 1 As shown, multiple e-wallet accounts can include e-wallet account 1, e-wallet account 2, ..., e-wallet account n. Each e-wallet account is an account of an e-wallet application running on a terminal device. The e-wallet application can include, but is not limited to, applications that support online payment functions, such as Alipay Wallet, mobile wallet applications, and bank terminal applications. To support offline payment, the terminal device also has a hardware wallet application, which can exist as a plugin for the e-wallet application or as standalone client software. When the hardware wallet application exists as standalone client software, the e-wallet application can be bound to the hardware wallet application, enabling the hardware wallet application to perform offline payments based on user certificates. In one implementation, the hardware wallet application can be a mobile phone-based offline wallet application, an offline wallet application based on a mobile SIM card from operators such as China Mobile and China Unicom, or an offline wallet application based on payment card hardware from various card vendors.
[0106] The server can use its status detection module to detect the status of e-wallet accounts, such as... Figure 1 As shown, when the server detects that the current state of e-wallet account 1 meets the preset certificate issuance conditions, it uses e-wallet account 1 as the target e-wallet account. Its first obtaining module obtains the target e-wallet account's wallet account information, current account balance, and current credit information. Its first determining module determines the offline payment limit corresponding to the target e-wallet account based on the current account balance and current credit information. Its first signing module uses the server's private key to sign the aggregated information, obtaining an e-wallet signature. The aggregated information includes wallet account information, offline payment limit, issuance time, and validity period. Its first generating module generates a user certificate corresponding to the target e-wallet account based on the aggregated information and the e-wallet signature. Its first sending module sends the user certificate to the terminal device where the target e-wallet account is located, enabling the offline account corresponding to the target e-wallet account to make offline payments within the offline payment limit based on the user certificate. This offline account is the account logged into the hardware wallet application and can make offline payments through the hardware wallet application.
[0107] In one implementation, the preset certificate issuance conditions include at least one of the following: 1. The target e-wallet account's previously obtained user certificate has expired, and the terminal device is connected to the internet; 2. During a first time period before the previously obtained user certificate expires, the terminal device is connected to the internet; 3. During a second time period before the previously obtained user certificate expires, the terminal device's data usage meets a preset idle condition; 4. The target e-wallet account's current account balance and / or current credit information changes to meet certain conditions; 5. The target e-wallet account has never obtained a user certificate, and the terminal device's data usage meets a preset idle condition. The second time period is longer than the first time period.
[0108] In this embodiment, the server can assess the corresponding offline payment limit based on the target e-wallet account's current account balance and credit information, then generate a valid user certificate and issue it to the terminal device where the target e-wallet account is located. This allows the offline account corresponding to the target e-wallet account to make offline payments within the offline payment limit based on the user certificate. In other words, the user certificate authorizes offline payments for the offline account, eliminating the need for pre-deposit or pre-loaded funds. Furthermore, when this user certificate is issued for the first time to the target e-wallet account, it also eliminates the need to open an offline account corresponding to the target e-wallet account (i.e., eliminates the need to activate the corresponding hardware wallet), thus authorizing offline payment functionality for the offline account without opening or pre-deposit.
[0109] The authorization method, offline payment method, and payment collection method for offline devices provided in this specification will be described in detail below with reference to specific embodiments. First, the authorization method for offline payment will be described.
[0110] Figure 2 A flowchart of an offline payment authorization method according to one embodiment of this specification is shown. This method can be implemented via a server, which can be any device, equipment, platform, device cluster, etc., with computing and processing capabilities. The method includes the following steps S210-S250:
[0111] S210: When the current state of the target e-wallet account meets the preset certificate issuance conditions, obtain the wallet account information, current account balance, and current credit information of the target e-wallet account. The target e-wallet account can be any e-wallet account whose current state meets the preset certificate issuance conditions. The e-wallet account is the account of an e-wallet application running on a terminal device. E-wallet applications include, but are not limited to, Alipay Wallet, mobile wallet applications, and bank terminal applications that support payment functions. The server is the server corresponding to the e-wallet application.
[0112] In one implementation, to prevent the leakage of privacy information of the target e-wallet account, the wallet account information can be: the hash value of the wallet account ID and wallet account name information corresponding to the target e-wallet account. For example, it can be the MD5 value of the wallet account ID and wallet account name information. The current credit information can represent the credit information corresponding to the target e-wallet account, and the current credit information can include at least one of the following: the current credit score and the current loanable limit.
[0113] In one exemplary scenario, the e-wallet application is the Alipay Wallet application, and the target e-wallet account is the Alipay Wallet account. Accordingly, the wallet account information can be: the hash value of the Alipay Wallet account ID and Alipay Wallet account name; the current account balance can be the current Alipay Wallet user balance; the current credit score can be the current Sesame Credit score; and the current loanable limit can be the current Huabei limit.
[0114] In one implementation, the preset certificate issuance conditions include at least one of the following: 1. The target e-wallet account's previously obtained user certificate has expired, and the terminal device is connected to the internet; 2. During a first time period before the previously obtained user certificate expires, the terminal device is connected to the internet; 3. During a second time period before the previously obtained user certificate expires, the terminal device's data usage meets a preset idle condition; 4. The target e-wallet account's current account balance and / or current credit information changes to meet certain conditions; 5. The target e-wallet account has never obtained a user certificate, and the terminal device's data usage meets a preset idle condition. The second time period is longer than the first time period.
[0115] It is understood that the preset certificate issuance conditions listed above are merely examples provided in this specification. Staff can set specific preset certificate issuance conditions according to actual needs, and this specification does not limit the scope of the examples. For example, the preset certificate issuance conditions may also include: the target e-wallet account has not obtained a user certificate, its current account balance and / or current credit information meet preset conditions (such as the current credit value exceeding a certain credit value, or the current loanable amount exceeding a certain amount, or the current account balance not being zero), and the terminal device is connected to the internet.
[0116] When the current state of the target e-wallet account is detected to meet any of the preset certificate issuance conditions, it can be considered that its current state meets the preset certificate issuance conditions, and then the server obtains the wallet account information, current account balance and current credit information of the target e-wallet account.
[0117] S220: Determine the corresponding offline payment limit based on the current account balance and current credit information. In this step, the current account balance can, to some extent, represent the spending power of the target e-wallet account (the higher the current account balance, the greater the spending power), and the current credit information can represent the creditworthiness of the target e-wallet account (the higher the current credit score and current loanable limit in the current credit information, the higher the creditworthiness), such as its repayment record. Therefore, based on the current account balance and current credit information, determine the offline payment limit corresponding to the target e-wallet account. This offline payment limit is the maximum limit that the offline account corresponding to the target e-wallet account can support for offline payments on its terminal device before each online repayment.
[0118] S230: Using the server's private key, sign the aggregated information to obtain the e-wallet signature. The aggregated information includes wallet account information, offline payment limit, issuance time, and validity period. It's important to understand that changes in the target e-wallet account's credit information and balance will affect its spending power and compliance (e.g., spending power decreases or increases), consequently changing the offline payment limit determined for the target e-wallet account. Therefore, a validity period can be set for the offline payment limit (i.e., the subsequently generated user certificate). Specifically, the validity period can be limited by the corresponding issuance time and validity period. Furthermore, to prevent the aggregated information from being tampered with, which could cause problems in the subsequent offline payment process, this step uses the server's private key to sign the aggregated information, obtaining the e-wallet signature. This e-wallet signature is used for identity verification and validity period verification when the offline account corresponding to the target e-wallet account makes offline payments.
[0119] The issuance time mentioned above represents the generation and distribution time of the user certificate. In one scenario, the user certificate generation and distribution occur on the same day. The validity period can be set based on experience; considering changes in the target e-wallet account information and the frequency of distribution, the validity period can be set to 3-7 days.
[0120] S240: Generate a user certificate based on summary information and e-wallet signature. In one implementation, summary information and e-wallet signature can be combined to generate a user certificate.
[0121] S250: The user certificate is distributed to the terminal device where the target e-wallet account is located, enabling the offline account corresponding to the target e-wallet account to make offline payments within the offline payment limit based on the user certificate. When the terminal device is connected to the internet, the server distributes the user certificate to the terminal device where the target e-wallet account is located. The terminal device obtains and stores the user certificate through the connected network. Subsequently, the offline account corresponding to the target e-wallet account can make offline payments based on the user certificate. Before the terminal device connects to the internet and performs offline payment settlement, the maximum amount that the offline account can make offline payments is the offline payment limit, which can be determined based on the offline payment limit and historical offline transaction amounts. Offline payment settlement refers to the server settling the offline transaction amount generated by the offline account during its offline period after the terminal device reconnects to the internet.
[0122] In one implementation, the terminal device has a hardware wallet application installed to enable offline payments. The offline account corresponding to the target e-wallet account is the account corresponding to the hardware wallet application. In one scenario, the hardware wallet application can exist as a plugin for the e-wallet application; alternatively, it can exist as a standalone client application. When the hardware wallet application exists as a standalone client application, the e-wallet application is bound to the hardware wallet application, enabling the hardware wallet application to perform offline payments based on user certificates.
[0123] In this embodiment, by issuing a user certificate to the terminal device where the target e-wallet account resides, the offline account corresponding to the target e-wallet account can make offline payments within the permitted offline payment limit based on the user certificate. Therefore, offline payments within the permitted offline payment limit can be achieved without prior top-up or pre-deposit of funds into the offline account. Furthermore, when this user certificate is issued for the first time to the target e-wallet account, it also eliminates the need to open an offline account corresponding to the target e-wallet account (i.e., eliminates the need to activate the corresponding hardware wallet), thus authorizing offline payment functionality for the offline account without opening an account or prior top-up.
[0124] Furthermore, in this embodiment, the authorization for offline payments without advance top-up to the offline account means that money is not pre-loaded into the offline account, thus avoiding the premature use of the user's liquid assets. It is understood that in this embodiment, the offline account can utilize user certificates to achieve "buy now, pay later," which avoids the problem of unrecoverable funds in the offline account in the event of damage to the corresponding hardware wallet or loss of the terminal device, thereby preventing financial loss for the user.
[0125] In one possible implementation, to protect the security of user certificates and prevent their leakage, the terminal device is equipped with a Trusted Execution Environment (TEE). Accordingly, the above-mentioned S250 may include: distributing the user certificate to the terminal device's TEE, so that the terminal device stores the user certificate in the TEE. In one case, the hardware wallet application may be installed in the terminal device's TEE.
[0126] In one possible implementation, step S220 may include the following steps 11-12:
[0127] Step 11: Based on the current account balance, current credit information and their respective weights, determine the current score of the target e-wallet account's account rating.
[0128] Step 12: Based on the current score, determine the offline payment limit corresponding to the target e-wallet account.
[0129] In this implementation, the server can pre-store the weights corresponding to the current account balance and current credit information. Subsequently, based on the current account balance and its corresponding weights, and the current credit information and its corresponding weights, the current score of the target e-wallet account is determined. One approach is to sum the product of the current account balance and its corresponding weights with the product of the current credit information and its corresponding weights to determine the current score. Alternatively, the server can first calculate the product of the current account balance and its corresponding weights as the first product value, then calculate the product of the current credit information and its corresponding weights as the second product value, and finally average the first and second product values as the current score. Subsequently, based on the current score, the offline payment limit corresponding to the target e-wallet account is determined. Another approach is for the server to pre-store a mapping relationship between scores and limits, and based on this mapping relationship, determine the limit corresponding to the current score as the offline payment limit.
[0130] Regarding the current account balance of the target e-wallet account, the account balance will fluctuate frequently as the account owner makes continuous purchases. If the account balance changes, the corresponding offline payment limit will also change, resulting in the server frequently generating and issuing user certificates for the target e-wallet account. This wastes server computing resources and increases network processing overhead on terminal devices, leading to a poor user experience. Therefore, in one possible implementation, step 12 may include the following steps 121-122:
[0131] Step 121: Based on the preset first correspondence between account score and credit limit level, determine the current credit limit level corresponding to the current score.
[0132] Step 122: Based on the preset second correspondence between credit limit level and credit limit value, determine the credit limit value corresponding to the current credit limit level as the offline payment limit.
[0133] In this implementation, credit limit levels are defined, and a first correspondence between account scores and credit limit levels, as well as a second correspondence between credit limit levels and credit limit values, are pre-built and stored. Subsequently, after the server obtains the current score, it determines the current credit limit level corresponding to the current score based on the first correspondence; and determines the credit limit value corresponding to the current credit limit level based on the second correspondence, which serves as the offline payment limit. By setting credit limit levels, the offline payment limit (user certificate change) is only changed when the current account balance and / or current credit information changes, resulting in a change in the credit limit level corresponding to the calculated current score. This avoids the server frequently generating and issuing user certificates for the target e-wallet account.
[0134] In another implementation, a direct correspondence can be established between account balance and credit information and credit limit. Then, based on this correspondence, the credit limit corresponding to the current account balance and current credit information can be determined as the offline payment limit corresponding to the target e-wallet account.
[0135] In one possible implementation, the method may further include the following steps 21-23:
[0136] Step 21: Obtain the offline bill sent by the terminal device. The offline bill is a bill generated by offline payment of the offline account and includes at least the corresponding transaction amount and wallet account information.
[0137] Step 22: Based on the transaction amount and wallet account information, deduct the corresponding amount from the target e-wallet account.
[0138] Step 23: Send a limit restoration message to the terminal device so that the offline account restores the current offline payment limit to the offline payment limit.
[0139] In this embodiment, after the server issues the user certificate to the terminal device where the target e-wallet account is located, the offline account corresponding to the target e-wallet account can make offline payments within the offline payment limit based on the user certificate. After the offline account makes an offline payment, a corresponding offline bill is generated. This offline bill includes at least the transaction amount corresponding to the offline payment and the wallet account information, so that offline payment settlement can be performed on the server side after the terminal device connects to the network. Specifically, after the terminal device connects to the network, it uploads the offline bill stored during its offline period to the server via the network. The server receives the offline bill and deducts the corresponding amount from the target e-wallet account based on the transaction amount and wallet account information included therein, thus realizing offline payment settlement.
[0140] Understandably, to prevent double-spending in offline accounts, the terminal device adjusts the current offline payment limit based on the transaction amount after each offline payment. For example, after obtaining a user certificate, the initial offline payment limit for the target e-wallet account is 300 (the offline payment limit corresponding to the user certificate). If the offline account makes an offline payment of 50, the terminal device adjusts the current offline payment limit to 250 (300-50). If the offline account makes another offline payment of 100, the terminal device adjusts the current offline payment limit to 150 (250-100), and so on.
[0141] Therefore, to ensure the normal operation of offline payment functionality for offline accounts, the server sends a credit limit restoration message to the terminal device after clearing the account. Upon receiving this message, the terminal device restores the offline payment limit of the offline account, returning it to the current offline payment limit.
[0142] In one scenario, the user certificate for the offline account corresponding to the target e-wallet account may expire while the terminal device is offline. In this case, after the server performs offline payment settlement for the offline account (i.e., completes step 22), it can directly regenerate a new user certificate for the target e-wallet account, without executing step 23. In other words, after the server settles the offline account, it can first determine whether the currently obtained user certificate for the offline account has expired. If it determines that the currently obtained user certificate for the offline account has not expired, it will proceed with step 23.
[0143] In one possible implementation, to prevent the offline bill from being tampered with or forged, the offline bill may further include: corresponding merchant account information and merchant signature, wherein the merchant signature is obtained by signing the merchant account information and transaction amount using the merchant's private key; wherein the corresponding merchant account information is the account information of the merchant corresponding to the offline account making the offline payment.
[0144] Step 22 may include the following steps 221-222:
[0145] Step 221: Verify the offline bill using the merchant's public key corresponding to the merchant's private key.
[0146] Step 222: If the verification is successful, the corresponding amount will be deducted from the target e-wallet account based on the transaction amount and wallet account information.
[0147] In this implementation, the server can use the merchant's public key corresponding to the merchant's private key to verify the offline bill and determine whether it has been tampered with. If the verification is successful, indicating that the offline bill has not been tampered with, the server deducts the corresponding amount from the target e-wallet account based on the transaction amount and wallet account information. If the verification fails, it can be determined that the offline bill has been tampered with, and the server locks the offline bill and performs subsequent specific processing operations. These specific processing operations could, for example, involve the server verifying the offline bill by querying the corresponding merchant's transaction records.
[0148] Corresponding to the above method embodiments, this specification also provides an offline payment method applied to a terminal device. The terminal device stores a user certificate issued by a server. The user certificate includes at least the offline payment limit, issuance time, validity period, and electronic wallet signature, such as... Figure 3As shown, the method may include steps S310-S340:
[0149] S310: Upon receiving an offline payment instruction, determine whether the current transaction amount carried by the offline payment instruction does not exceed the current offline payment limit. The current offline payment limit is determined based on the available offline payment amount and historical offline transaction amounts. In one scenario, the current offline payment limit can be the difference between the available offline payment amount and all historical offline transaction amounts. Historical offline transaction amounts include the transaction amounts corresponding to all offline payments made by the terminal device after the most recent restoration or confirmation of the available offline payment amount and before this offline payment.
[0150] In one exemplary offline payment scenario, the terminal device can receive an offline payment instruction by scanning a merchant's QR code, where the QR code contains the current transaction amount. In another exemplary offline payment scenario, the terminal device can receive an offline payment instruction based on user actions, such as the user entering the current transaction amount on a designated payment interface. In yet another exemplary offline payment scenario, the terminal device can present a payment code based on user actions for a payment receiving device to scan. After scanning the payment code, the payment receiving device can provide the current transaction amount to the terminal device. Upon receiving this current transaction amount, the terminal device considers itself to have received an offline payment instruction.
[0151] In one implementation, the terminal device can have a hardware wallet application installed, through which it can perform offline payments. In another implementation, the terminal device also has an e-wallet application installed. This hardware wallet application can exist as a plugin for the e-wallet application or as a standalone client application. When the hardware wallet application exists as a standalone client application, the e-wallet application is bound to it, enabling the hardware wallet application to perform offline payments based on user certificates.
[0152] The aforementioned server is the server corresponding to the e-wallet application. Terminal devices can obtain user certificates through the e-wallet application. The aforementioned offline payment limit is determined based on the account balance and credit information of the e-wallet account logged into the e-wallet application. The aforementioned user certificate may also include the e-wallet account information. This wallet account information can prove the account to which the user certificate belongs. The aforementioned e-wallet signature is obtained by signing the wallet account information, offline payment limit, issuance time, and validity period based on the server's private key. The issuance time ensures the timely generation and distribution of the user certificate, and the validity period limits the validity period of the user certificate.
[0153] S320: If it is determined that the current transaction amount is not greater than the current offline payment limit, the user certificate is provided to the receiving device corresponding to the offline payment instruction. In this step, if the terminal device determines that the current transaction amount is not greater than the current offline payment limit, it considers the transaction acceptable and accordingly provides the user certificate to the receiving device corresponding to the offline payment instruction. In one implementation, the terminal device can provide the user certificate to the receiving device corresponding to the offline payment instruction via short-range transmission. This short-range transmission method may include, but is not limited to: Bluetooth transmission, QR code transmission, and transmission based on NFC (Near Field Communication) technology.
[0154] S330: Receive transaction confirmation information from the receiving device. This transaction confirmation information is sent by the receiving device after verifying the validity of the user's certificate based on the electronic wallet signature.
[0155] S340: Generate offline bills based on transaction confirmation information.
[0156] After the terminal device provides the user certificate to the receiving device, the receiving device verifies the user certificate based on the e-wallet signature. Once the user certificate verification is successful and its validity is confirmed, the transaction is processed. After the transaction is completed, the receiving device generates a transaction confirmation message and provides it to the terminal device to notify the terminal device that the transaction (offline payment) was successful. The terminal device receives the transaction confirmation message from the receiving device and generates an offline invoice based on it. The server can then use the offline invoice to perform offline payment settlement for offline accounts.
[0157] In one scenario, the receiving device can provide transaction confirmation information to the terminal device via the aforementioned short-distance transmission method.
[0158] In this embodiment, when the terminal device determines that the upper limit of the current offline payment is greater than the current transaction amount, and thus the current transaction amount can be paid, the terminal device can provide the user certificate to the receiving device, thereby realizing offline payment through the user certificate.
[0159] In one possible implementation, to prevent user certificates from being stolen or tampered with, the terminal device may include a Trusted Execution Environment (TEE), where the user certificate can be stored, and the offline payment method is executed within the TEE. Correspondingly, to prevent the hardware wallet application from being maliciously compromised, the aforementioned hardware wallet application can be installed and run within the TEE. Considering the limited space resources of the TEE, the e-wallet application can run within a general execution environment (REE) of the terminal device.
[0160] In one possible implementation, the method may further include the following steps 31-32:
[0161] Step 31: Determine whether the user certificate is valid based on the offline payment instruction receiving time, the user certificate issuance time, and the validity period;
[0162] If the user certificate is found to be valid, the user certificate will be provided to the receiving device corresponding to the offline payment instruction.
[0163] In one implementation, if the terminal device determines that the current transaction amount is not greater than the current offline payment limit, it can execute step 31 to determine the validity of the user certificate based on the offline payment instruction's reception time, the user certificate's issuance time, and its validity period. Specifically, it checks whether the time corresponding to the issuance time plus the validity period is not earlier than the reception time. If the time is not earlier than the reception time, the user certificate is deemed valid, and it is then provided to the receiving device corresponding to the offline payment instruction via short-range transmission. This implementation avoids invalid interactions between the terminal device and the receiving device. For example, if the user certificate is determined to be invalid, the terminal device does not provide the user certificate to the receiving device, directly resulting in the inability to perform offline payment.
[0164] In another implementation, upon receiving an offline payment instruction, the terminal device first determines the validity of the user certificate based on the receipt time of the instruction, the issuance time of the user certificate, and its validity period. If the user certificate is valid, it then checks whether the current transaction amount carried in the offline payment instruction does not exceed the current offline payment limit. If the current transaction amount does not exceed the current offline payment limit, the user certificate is then provided to the receiving device corresponding to the offline payment instruction. If the user certificate is deemed invalid, subsequent steps are not executed.
[0165] To avoid double-spending in offline accounts, the terminal device needs to update its current offline payment limit after receiving transaction confirmation information from the receiving device, i.e., confirming the success of the offline payment. Accordingly, in one implementation, the method may further include the following steps 41-42:
[0166] Step 41: Calculate the difference between the current offline payment limit and the current transaction amount.
[0167] Step 42: Determine the difference as the new upper limit for current offline payments.
[0168] In the embodiments described in this specification, offline bills generated by offline payments based on user certificates during offline periods are stored locally on the terminal device. To prevent tampering with the offline bills, they can be stored in a TEE (Telegraphic Transfer Equipment). Subsequently, to ensure the normal use of the offline account, when the terminal device reconnects to the network, the offline bills are uploaded to the server, and the server performs settlement on the offline account based on the offline bills.
[0169] One implementation involves the terminal device automatically retrieving all offline bills not yet uploaded to the server from its local storage upon detecting an internet connection, and then automatically sending all offline bills to the server. Another implementation involves the terminal device automatically retrieving all offline bills not yet uploaded to the server from its local storage upon detecting an internet connection, displaying an offline bill prompt message to encourage the user to upload the offline bills, and then sending the offline bills to the server upon receiving an offline bill upload command from the user.
[0170] Accordingly, the method may further include the following steps: While connected to the internet, send the offline bill to the server so that the server can perform settlement based on the offline bill. Subsequently, after settlement, the server can further determine whether the user certificate obtained by the offline account is valid. If the user certificate is determined to be valid, send credit limit restoration information to the terminal device. After receiving the credit limit restoration information, the terminal device restores the current offline payment limit to the offline payment limit carried by the user certificate.
[0171] To prevent transaction confirmation information from being forged or tampered with, the terminal device can first verify the transaction confirmation information after obtaining it. Accordingly, in one possible implementation, the transaction confirmation information includes: the merchant's account information, the current transaction amount, and the merchant's signature. The merchant's signature is obtained by signing the merchant's account information and the current transaction amount using the merchant's private key.
[0172] S340 may include the following steps 51-52:
[0173] Step 51: Verify the transaction confirmation information based on the merchant's public key corresponding to the merchant's private key;
[0174] Step 52: If the verification is successful, generate an offline bill based on the merchant account information, the current transaction amount, and the wallet account information.
[0175] The merchant's public key corresponding to the merchant's private key can be pre-stored locally on the terminal device, or it can be provided to the terminal device by the receiving device during a transaction with the merchant. After receiving the transaction confirmation information, the terminal device verifies the transaction confirmation information based on the merchant's public key corresponding to the merchant's private key. If the verification is successful, it is determined that the merchant account information and the current transaction amount in the transaction confirmation information have not been tampered with. Based on the merchant account information, the current transaction amount, and the wallet account information, an offline statement is generated. This offline statement can include at least the merchant account information, the current transaction amount, and the wallet account information.
[0176] In another implementation, the offline bill may also include the merchant's signature. This allows the server to verify the offline bill using the merchant's public key corresponding to their private key before clearing the offline account. This verifies whether the merchant account information and transaction amount carried on the offline bill have been tampered with. Once the server confirms that the offline bill has not been altered and thus verifies the offline bill, it then clears the offline account by deducting the corresponding amount from the e-wallet account based on the transaction amount and the wallet account information carried on the offline bill. This prevents financial loss to the e-wallet account.
[0177] Corresponding to the above method embodiments, this specification also provides a payment collection method for offline devices, applied to payment collection devices, such as... Figure 4 As shown, the method includes the following steps S410-S450:
[0178] S410: Obtain a user certificate from an offline terminal device. The user certificate is issued by the server and includes: the wallet account information of the e-wallet account corresponding to the terminal device, the offline payment amount, the issuance time and validity period of the user certificate, and the e-wallet signature.
[0179] The user certificate is generated based on the offline payment authorization method provided in the above embodiments. The specific generation process can be found in the above embodiments of the offline payment authorization method, and will not be repeated here. The user certificate is generated by the server and distributed to the terminal device that is connected to the network. The terminal device stores it locally, for example, in its Trusted Execution Environment (TEE). Subsequently, when the terminal device is offline, it can perform offline payments based on this user certificate, i.e., conduct offline transactions with merchants.
[0180] In one scenario, when the terminal device is offline and conducting a transaction with a merchant (making an offline payment), the user certificate can be provided to the merchant's payment device via short-range transmission. The payment device then obtains the user certificate from the offline terminal device through this short-range transmission. Short-range transmission methods may include, but are not limited to: Bluetooth communication, QR code communication, and NFC (Near Field Communication) based transmission technology.
[0181] S420: Verify the e-wallet signature using the server's public key. The e-wallet signature is generated by signing the e-wallet account information, offline payment amount, user certificate issuance time, and validity period of the e-wallet account corresponding to the terminal device using the server's private key (i.e., the server private key mentioned in the above embodiment). The server's public key can be pre-stored locally on the receiving device, or it can be downloaded from the server after the receiving device obtains the user certificate.
[0182] The receiving device uses the server's public key to verify the e-wallet signature. This verifies whether the wallet account information, offline payment limit, and the issuance and validity period of the user certificate have been tampered with. If these elements are confirmed to be intact, the e-wallet signature verification is successful, and subsequent step S430 is executed. If any of these elements are found to have been tampered with, the e-wallet signature verification fails, and the transaction cannot proceed.
[0183] In one implementation, after determining that the e-wallet signature verification has failed, the receiving device can provide the terminal device with information indicating transaction failure. Alternatively, after determining that the e-wallet signature verification has failed, the receiving device can display information indicating that the user certificate is incorrect on its connected display screen. The user of the receiving device can then determine that the transaction payment has failed based on this information and take appropriate action. For example, it can remind the terminal device user that payment cannot be made and suggest that they try another payment method.
[0184] S430: If the verification passes, determine the validity of the user certificate based on the transaction time, issuance time, and validity period of this transaction. In this step, after confirming that the e-wallet signature verification has passed, the receiving device obtains the transaction time of this transaction and determines the validity of the user certificate based on the transaction time, issuance time, and validity period.
[0185] The process of determining the validity of a user certificate can be as follows: First, determine the first time based on the issuance time and validity period, and then determine if the transaction time is no later than this first time. Subsequently, if the transaction time is determined to be no later than the first time, the user certificate is deemed valid; otherwise, if the transaction time is determined to be later than the first time, the user certificate is deemed invalid.
[0186] S440: If the user certificate is found to be valid, generate the corresponding transaction confirmation information for this transaction. In this step, the receiving device, after verifying the validity of the user certificate, performs the transaction and generates the corresponding transaction confirmation information. This transaction confirmation information is used to indicate the success of the transaction. In one scenario, the transaction confirmation information may include at least: the merchant's account information, the transaction amount, and the merchant's signature. The merchant's signature is obtained by signing at least the merchant's account information and the current transaction amount using the merchant's private key. Subsequently, the terminal device and / or the server can verify whether the merchant's account information and the current transaction amount have been tampered with through the merchant's signature.
[0187] In another implementation, if the user certificate is deemed invalid, the payment device can generate a transaction failure message and provide it to the terminal device. Alternatively, after determining that the user certificate is invalid, the payment device can display information indicating the invalidity on its connected display screen. The user can then determine that the transaction has failed based on this information and take appropriate action, such as notifying the terminal device user that payment cannot be made and suggesting that they try another payment method.
[0188] S450: Provide transaction confirmation information to the terminal device so that the terminal device can generate a corresponding offline bill based on the transaction confirmation information. In one implementation, after the receiving device generates transaction confirmation information, it can provide the transaction confirmation information to the terminal device via short-range transmission. After receiving the transaction confirmation information, the terminal device generates a corresponding offline bill based on the transaction confirmation information.
[0189] In this embodiment, the payment receiving device performs the transaction after verifying the validity of the user certificate provided by the terminal device, thus facilitating transactions for the terminal device in an offline state.
[0190] The foregoing description describes specific embodiments of this specification; other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than those shown in the embodiments, and the desired result may still be achieved. Furthermore, the processes depicted in the drawings do not necessarily need to follow the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0191] Corresponding to the above method embodiments, this specification provides an offline payment authorization device 500, applied to a server, and its schematic block diagram is as follows. Figure 5 As shown, the device includes:
[0192] The first acquisition module 510 is configured to acquire the wallet account information, current account balance and current credit information of the target e-wallet account when the current status of the target e-wallet account meets the preset certificate issuance conditions.
[0193] The first determining module 520 is configured to determine the corresponding offline payment limit based on the current account balance and the current credit information;
[0194] The first signature module 530 is configured to use the server's private key to sign the aggregated information to obtain an electronic wallet signature. The aggregated information includes the wallet account information, the offline payment limit, the issuance time, and the validity period.
[0195] The first generation module 540 is configured to generate a user certificate based on the aggregated information and the e-wallet signature;
[0196] The first sending module 550 is configured to send the user certificate to the terminal device where the target e-wallet account is located, so that the offline account corresponding to the target e-wallet account can make offline payments within the offline payment limit based on the user certificate.
[0197] In one possible implementation, the preset certificate issuance conditions include at least one of the following conditions: the target e-wallet account's obtained user certificate has expired, and the terminal device is connected to the network.
[0198] During the first period before the expired user certificate, and while the terminal device is connected to the network;
[0199] In the second time period before the expired user certificate, and when the traffic usage status of the terminal device meets the preset idle condition;
[0200] The current account balance of the target e-wallet account and / or the changes in the current credit information meet certain conditions;
[0201] The target e-wallet account has not obtained a user certificate, and the data usage status of the terminal device meets the preset idle condition.
[0202] In one possible implementation, the wallet account information is: the hash value of the wallet account ID and wallet account name information corresponding to the target e-wallet account.
[0203] In one possible implementation, the current credit information includes at least one of the following: the current credit score and the current loanable amount.
[0204] In one possible implementation, the terminal device is equipped with a Trusted Execution Environment (TEE).
[0205] The first sending module 550 is specifically configured to send the user certificate to the TEE of the terminal device, so that the terminal device stores the user certificate in the TEE.
[0206] In one possible implementation, the first determining module 520 includes:
[0207] The first determining unit (not shown in the figure) is configured to determine the current score of the target e-wallet account based on the current account balance, the current credit information and their respective weights.
[0208] The second determining unit (not shown in the figure) is configured to determine the offline payment limit corresponding to the target e-wallet account based on the current score.
[0209] In one possible implementation, the second determining unit is specifically configured to determine the current credit limit level corresponding to the current score based on a preset first correspondence between account scores and credit limit levels.
[0210] Based on a preset second correspondence between credit limit levels and credit limit values, the credit limit value corresponding to the current credit limit level is determined as the offline payment limit.
[0211] In one possible implementation, the device further includes:
[0212] The fourth obtaining module (not shown in the figure) is configured to obtain the offline bill sent by the terminal device, wherein the offline bill is a bill generated by the offline account for offline payment, and includes at least the corresponding transaction amount and the wallet account information;
[0213] The amount deduction module (not shown in the figure) is configured to deduct the corresponding amount from the target e-wallet account based on the transaction amount and the wallet account information;
[0214] The second sending module (not shown in the figure) is configured to send credit limit restoration information to the terminal device so that the current offline payment limit of the offline account is restored to the offline payment limit.
[0215] In one possible implementation, the offline bill further includes: corresponding merchant account information and merchant signature, wherein the merchant signature is obtained by signing the merchant account information and the transaction amount using the merchant's private key;
[0216] The amount deduction module is specifically configured to use the merchant's public key corresponding to the merchant's private key to verify the offline bill;
[0217] If the verification is successful, the corresponding amount will be deducted from the target e-wallet account based on the transaction amount and the wallet account information.
[0218] Corresponding to the above method embodiments, this specification provides an offline payment device 600, applied to a terminal device. The terminal device stores a user certificate issued by a server. The user certificate includes at least the offline payment limit, issuance time, validity period, and electronic wallet signature. A schematic diagram of this device is shown below. Figure 6 As shown, the device includes:
[0219] The first judgment module 610 is configured to, upon receiving an offline payment instruction, determine whether the current transaction amount carried by the offline payment instruction is not greater than the current offline payment limit, wherein the current offline payment limit is determined based on the offline payment limit and the historical offline transaction amount;
[0220] The first providing module 620 is configured to provide the user certificate to the receiving device corresponding to the offline payment instruction if it is determined that the current transaction amount is not greater than the current offline payment limit.
[0221] The second obtaining module 630 is configured to obtain transaction confirmation information provided by the receiving device, wherein the transaction confirmation information is sent by the receiving device after determining that the user certificate is valid based on the electronic wallet signature;
[0222] The second generation module 640 is configured to generate an offline invoice based on the transaction confirmation information.
[0223] In one possible implementation, the terminal device includes a Trusted Execution Environment (TEE), the user certificate is stored in the TEE, and the method is executed in the TEE.
[0224] In one possible implementation, the device further includes:
[0225] The third judgment module (not shown in the figure) is configured to determine whether the user certificate is valid based on the reception time of the offline payment instruction, the issuance time of the user certificate, and the validity period.
[0226] The third providing module (not shown in the figure) is configured to provide the user certificate to the payment receiving device when the user certificate is determined to be valid.
[0227] In one possible implementation, the device further includes:
[0228] The calculation module (not shown in the figure) is configured to calculate the difference between the current offline payment limit and the current transaction amount;
[0229] The second determining module (not shown in the figure) is configured to determine the difference as the new upper limit for the current offline payment.
[0230] In one possible implementation, the device further includes:
[0231] The third sending module (not shown in the figure) is configured to send the offline bill to the server when the network is connected, so that the server can perform settlement based on the offline bill.
[0232] In one possible implementation, the second obtaining module 630 is specifically configured to obtain the transaction confirmation information provided by the receiving device through a short-distance transmission method.
[0233] In one possible implementation, the transaction confirmation information includes: the merchant's account information, the current transaction amount, and the merchant's signature, wherein the merchant's signature is obtained by signing the merchant's account information and the current transaction amount using the merchant's private key;
[0234] The second generation module 640 is specifically configured to verify the transaction confirmation information based on the merchant's public key corresponding to the merchant's private key;
[0235] If the verification is successful, an offline bill is generated based on the merchant account information, the current transaction amount, and the wallet account information.
[0236] Corresponding to the above method embodiments, this specification provides a payment receiving device 700 for offline devices, applied to payment receiving devices, and its schematic block diagram is as follows. Figure 7 As shown, the device includes:
[0237] The third acquisition module 710 is configured to acquire a user certificate provided by an offline terminal device. The user certificate is issued by the server and includes: wallet account information of the electronic wallet account corresponding to the terminal device, the amount that can be paid offline, the issuance time and validity period of the user certificate, and the electronic wallet signature.
[0238] The first verification module 720 is configured to verify the electronic wallet signature using the public key of the server;
[0239] The second judgment module 730 is configured to, if the verification is successful, determine whether the user certificate is valid based on the transaction time of this transaction, the issuance time, and the validity period.
[0240] The third generation module 740 is configured to generate transaction confirmation information corresponding to this transaction if the user certificate is found to be valid.
[0241] The second providing module 750 is configured to provide the transaction confirmation information to the terminal device, so that the terminal device generates a corresponding offline invoice based on the transaction confirmation information.
[0242] In one possible implementation, the transaction confirmation information includes at least: the merchant's account information, the transaction amount of this transaction, and the merchant's signature, wherein the merchant's signature is obtained by signing the merchant's account information and the current transaction amount using the merchant's private key.
[0243] In one possible implementation, the second providing module 750 is specifically configured to provide the transaction confirmation information to the terminal device via short-distance transmission.
[0244] In one possible implementation, the device further includes:
[0245] The fourth generation module (not shown in the figure) is configured to generate transaction failure information if the user certificate is determined to be invalid.
[0246] The fourth providing module (not shown in the figure) is configured to provide the transaction failure information to the terminal device.
[0247] The above-described apparatus embodiments correspond to the method embodiments, and detailed descriptions can be found in the description of the method embodiments section, which will not be repeated here. The apparatus embodiments are derived based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments; detailed descriptions can be found in the corresponding method embodiments.
[0248] This specification also provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the offline payment authorization method provided in this specification.
[0249] This specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the offline payment authorization method provided in this specification.
[0250] This specification also provides a computer-readable storage medium storing a computer program that, when executed in a computer, causes the computer to perform the offline payment method described in this specification.
[0251] This specification also provides a computing device, including a memory and a processor. The memory stores executable code, and when the processor executes the executable code, it implements the offline payment method provided in this specification.
[0252] This specification also provides a computer-readable storage medium storing a computer program that, when executed in a computer, causes the computer to perform the payment collection method for offline devices described in this specification.
[0253] This specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the payment collection method for offline devices provided in this specification.
[0254] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for storage media and computing devices are basically similar to the method embodiments, so they are described more simply; relevant parts can be referred to the descriptions of the method embodiments.
[0255] Those skilled in the art will recognize that the functions described in the embodiments of the present invention in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.
[0256] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, or improvements made based on the technical solutions of the present invention should be included within the scope of protection of the present invention.
Claims
1. An authorization method of offline payment, applied to a server, the method comprising: evaluating a corresponding offline payment limit of a target e-wallet account based on a current account balance and current credit information of the target e-wallet account, and generating a user certificate with a validity period; issuing the user certificate to a terminal device where the target e-wallet account is located, so that an offline account corresponding to the target e-wallet account can make offline payment within the offline payment limit based on the user certificate; obtaining an offline bill sent by the terminal device, wherein the offline bill is a bill generated by offline payment of the offline account, and at least includes corresponding transaction amount and wallet account information of the target e-wallet account; deducting corresponding amount from the target e-wallet account based on the transaction amount and the wallet account information.
2. The method of claim 1, further comprising: sending limit recovery information to the terminal device to restore the upper limit of the current offline payment of the offline account to the offline payment limit.
3. The method of claim 1, wherein, The offline bill further includes corresponding merchant account information and a merchant signature, and the merchant signature is obtained by signing the merchant account information and the transaction amount with a merchant private key. The step of deducting corresponding amount from the target e-wallet account based on the transaction amount and the wallet account information comprises: verifying the offline bill with a corresponding merchant public key of the merchant private key; and deducting corresponding amount from the target e-wallet account based on the transaction amount and the wallet account information if the verification is passed.
4. An offline payment method, applied to a terminal device, the terminal device storing a user certificate with a validity period issued by a server, the user certificate including an offline payment limit of an e-wallet account corresponding to the terminal device, the method comprising: in a case of receiving an offline payment instruction, judging whether a current transaction amount carried by the offline payment instruction is not greater than an upper limit of current offline payment, wherein the upper limit of current offline payment is determined based on the offline payment limit and historical offline transaction amount; if it is judged that the current transaction amount is not greater than the upper limit of current offline payment, providing the user certificate to a payee device corresponding to the offline payment instruction; obtaining transaction confirmation information provided by the payee device, wherein the transaction confirmation information is sent by the payee device in a case that the payee device determines that the user certificate is valid; generating an offline bill based on the transaction confirmation information.
5. The method of claim 4, wherein the terminal device is further provided with a hardware wallet application, the offline account is an account logged into the hardware wallet application, and the offline payment is made through the hardware wallet application.
6. The method of claim 4, wherein, The step of providing the user certificate to the payee device corresponding to the offline payment instruction comprises: providing the user certificate to the payee device corresponding to the offline payment instruction through short-distance transmission.
7. A method of collecting money for offline devices, applied to the payee device of claim 4, the method comprising: obtaining a user certificate with a validity period provided by an offline terminal device, wherein the user certificate is issued by a server; generating transaction confirmation information corresponding to the current transaction in the case of judging that the user certificate is valid; providing the transaction confirmation information to the terminal device, so that the terminal device generates a corresponding offline bill based on the transaction confirmation information. 8.An authorization device for offline payment, applied to a server, the device comprising: an evaluation generation module configured to evaluate a corresponding offline payment limit of a target electronic wallet account based on a current account balance and current credit information of the target electronic wallet account, and to generate a user certificate with a validity period; an issuing module configured to issue the user certificate to a terminal device where the target electronic wallet account is located, so that an offline account corresponding to the target electronic wallet account can make offline payment within the offline payment limit based on the user certificate; obtaining an offline bill sent by the terminal device, wherein the offline bill is a bill generated by the offline account for offline payment, and at least includes corresponding transaction amount and wallet account information of the target electronic wallet account; and deducting a corresponding amount from the target electronic wallet account based on the transaction amount and the wallet account information. 9.An offline payment device, applied to a terminal device, the terminal device storing a user certificate with a validity period issued by a server, the user certificate including an offline payment limit of an electronic wallet account corresponding to the terminal device, the device comprising: a first judgment module configured to judge whether a current transaction amount carried by an offline payment instruction is not greater than an upper limit of current offline payment in the case of receiving the offline payment instruction, wherein the upper limit of current offline payment is determined based on the offline payment limit and a historical offline transaction amount; a first providing module configured to provide the user certificate to a payee device corresponding to the offline payment instruction if it is judged that the current transaction amount is not greater than the upper limit of current offline payment; a transaction confirmation information obtaining module configured to obtain transaction confirmation information provided by the payee device, wherein the transaction confirmation information is sent by the payee device in the case of judging that the user certificate is valid; an offline bill generation module configured to generate an offline bill based on the transaction confirmation information. 10.A payee device for offline devices, applied to the payee device of claim 9, the device comprising: a certificate obtaining module configured to obtain a user certificate with a validity period provided by an offline terminal device; a transaction confirmation information generation module configured to generate transaction confirmation information corresponding to the current transaction in the case of judging that the user certificate is valid; a second providing module configured to provide the transaction confirmation information to the terminal device, so that the terminal device generates a corresponding offline bill based on the transaction confirmation information.
11. A computing device comprising a memory and a processor, wherein, The memory stores executable codes, and the processor executes the executable codes to implement the method of any one of claims 1-7.
Citation Information
Patent Citations
Method and system for providing authorization through mobile terminal
CN104063790A
Secure offline payment system
CN106133769A