Resource transfer method and device, equipment and medium

Through the close-range communication and public key signature mechanism combined with resource characteristics and biometric verification, the security and reliability problems in the resource transfer process are solved, and secure resource transfer in offline state is realized.

CN120258788APending Publication Date: 2025-07-04TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410018502.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

Existing resource transfer methods cannot guarantee the security and reliability of the resource transfer process, which can easily lead to malicious resource transfer.

Method used

Receive resource transfer requests through short-distance communication, use the digital signature mechanism of public and private keys, and combine resource feature extraction strategies and biometric verification to ensure the legality and integrity of resource transfer requests.

Benefits of technology

During the resource transfer process, malicious tampering of virtual resources is avoided, the security and reliability of resource transfer are guaranteed, and resource transfer at the initiator of resource transfer request is supported in offline state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120258788A_ABST
    Figure CN120258788A_ABST
Patent Text Reader

Abstract

The invention relates to a resource transfer method and device, equipment and a medium. The method comprises the following steps: receiving a resource transfer request initiated by a first terminal through a near field communication mode; a public key, a digital signature and at least one virtual resource indicated by the resource transfer request are determined, the digital signature is obtained by encrypting first resource feature information by the first terminal by using a private key matched with the public key, and the first resource feature information is obtained after the first terminal determines at least one virtual resource to be transferred. Extracting features based on respective resource identifiers of at least one virtual resource to be transferred through a preset resource feature extraction strategy; extracting features of at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information; and when the second resource feature information is consistent with the first resource feature information, carrying out resource transfer based on at least one virtual resource indicated by the resource transfer request. By adopting the method, malicious resource transfer can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of computer technology and resource processing, and particularly to a resource transfer method, apparatus, device, and medium. Background Art

[0002] Resource transfer refers to the process of transferring a resource from one party to another. In traditional technologies, a terminal initiating a resource transfer usually sends a resource transfer request carrying the resource to be transferred to a receiving terminal in an online manner, that is, when the terminal initiating the resource transfer is connected to the network. Subsequently, the receiving terminal of the resource transfer request will directly perform resource transfer processing based on the resource carried in the resource transfer request, and transfer the resource from the terminal initiating the resource transfer request to the terminal responding to the resource request.

[0003] However, the current resource transfer method cannot guarantee the security and reliability of the resource during the transfer process, and it is easy to cause malicious transfer of the resource. Summary of the Invention

[0004] Based on this, it is necessary to provide a resource transfer method, apparatus, device, and medium that can avoid malicious resource transfer for the above technical problems.

[0005] In a first aspect, the present application provides a resource transfer method, and the method includes:

[0006] Receiving a resource transfer request initiated by a first terminal through a short-range communication method;

[0007] Determining a public key, a digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting first resource feature information using a private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy, and different virtual resources have different resource identifiers;

[0008] Extracting features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information;

[0009] When the second resource feature information is consistent with the first resource feature information, performing resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0010] In a second aspect, the present application provides a resource transfer method, and the method includes:

[0011] Determine at least one virtual resource to be transferred, where different copies of virtual resources have different resource identifiers;

[0012] Extract features from the at least one virtual resource to be transferred through a preset resource feature extraction strategy to obtain first resource feature information;

[0013] Use a preset private key to encrypt the first resource feature information to obtain a digital signature;

[0014] Obtain a resource transfer request, where the resource transfer request carries the digital signature and a public key that matches the private key;

[0015] Send the resource transfer request to a second terminal through a short-range communication method. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, perform resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0016] In a third aspect, the present application provides a resource transfer device, and the device includes:

[0017] A receiving module, configured to receive a resource transfer request initiated by a first terminal through a short-range communication method;

[0018] A first determination module, configured to determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal using a private key that matches the public key to encrypt first resource feature information. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset resource feature extraction strategy, based on the resource identifiers of the at least one virtual resource to be transferred. Different copies of virtual resources have different resource identifiers;

[0019] A first extraction module, configured to extract features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information;

[0020] A transfer module, configured to perform resource transfer based on the at least one virtual resource indicated by the resource transfer request when the second resource feature information is consistent with the first resource feature information.

[0021] In one embodiment, the transfer module is also used to determine the target digital certificate indicated by the resource transfer request; send the target digital certificate to the certificate registration end, the target digital certificate is used to instruct the certificate registration end to search for a digital certificate consistent with the target digital certificate from a certificate repository, and the certificate repository also stores object biometric information associated with the digital certificate; when a digital certificate consistent with the target digital certificate is found from the certificate repository, the first object biometric information associated with the target digital certificate is obtained from the certificate registration end; the second object biometric information of the object that initiated the resource transfer request is collected; when the second object biometric information is consistent with the first object biometric information, the step of performing resource transfer based on at least one virtual resource indicated by the resource transfer request is executed.

[0022] In one embodiment, the transfer module is also used to obtain the encryption key agreed with the certificate registration end; perform binary conversion on the target digital certificate and the encryption key respectively to obtain binary certificate data and binary key data; perform a bitwise XOR operation on the binary certificate data and the binary key data to obtain certificate encrypted data; and send the certificate encrypted data to the certificate registration end, wherein the certificate encrypted data is used to instruct the certificate registration end to decrypt the certificate encrypted data based on the encryption key to obtain the target digital certificate.

[0023] In one embodiment, the transfer module is also used to perform a bitwise XOR operation on the binary certificate data and the binary key data to obtain initial certificate encrypted data, wherein the initial certificate encrypted data includes multiple bytes; obtain a preset byte pair record table, wherein the byte pair record table records multiple preset byte pairs, each byte pair includes two different bytes; for each byte in the initial certificate encrypted data, replace the targeted byte with a byte in the byte pair record table that forms a byte pair with the targeted byte; when the multiple bytes included in the initial certificate encrypted data are replaced respectively, the certificate encrypted data is obtained.

[0024] In one embodiment, the resource feature extraction strategy is a hash function, and the first extraction module is also used to perform a hash operation on at least one virtual resource indicated by the resource transfer request through the preset hash function to obtain a hash value corresponding to the at least one virtual resource indicated by the resource transfer request; and determine the second resource feature information based on the hash value corresponding to the at least one virtual resource indicated by the resource transfer request.

[0025] In one embodiment, a resource management chip is provided in the first terminal, and a hardware resource container for storing virtual resources is provided in the resource management chip. At least one virtual resource to be transferred is determined by the first terminal from the hardware resource container.

[0026] In one embodiment, a resource management application is pre-installed in the first terminal, and a software resource container for storing virtual resources is provided in the resource management application. At least one virtual resource to be transferred is determined by the first terminal from the software resource container.

[0027] Fourthly, the present application provides a resource transfer device, and the device includes:

[0028] A second determination module, configured to determine at least one virtual resource to be transferred, and different virtual resources have different resource identifiers;

[0029] A second extraction module, configured to extract features from at least one virtual resource to be transferred through a preset resource feature extraction strategy, and obtain first resource feature information;

[0030] An encryption module, configured to encrypt the first resource feature information using a preset private key to obtain a digital signature;

[0031] An acquisition module, configured to acquire a resource transfer request, where the resource transfer request carries the digital signature and a public key matching the private key;

[0032] A sending module, configured to send the resource transfer request to a second terminal by means of short-range communication. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy, obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on at least one virtual resource indicated by the resource transfer request.

[0033] In one embodiment, the obtaining module is further configured to obtain a target digital certificate; send the target digital certificate to the second terminal, where the target digital certificate is used to instruct the second terminal to send the target digital certificate to the certificate registration end, so that the certificate registration end searches for a digital certificate consistent with the target digital certificate from the certificate repository, and object biometric information associated with the digital certificate is also stored in the certificate repository. When a digital certificate consistent with the target digital certificate is found from the certificate repository, the first object biometric information associated with the target digital certificate is sent to the second terminal; receive the prompt information sent by the second terminal indicating that the resource transfer is successful, where the prompt information is generated by the second terminal after determining that the second object biometric information is consistent with the first object biometric information and performing resource transfer based on at least one virtual resource indicated by the resource transfer request, and the second object biometric information is biometric information collected by the second terminal for the object that initiated the resource transfer request.

[0034] In one embodiment, the obtaining module is further configured to send a certificate registration request to the certificate registration end, where the certificate registration request is used to instruct the certificate registration end to collect the object biometric information of the object that initiated the certificate registration request. After the collected object biometric information passes the verification, a target digital certificate is generated, and the target digital certificate and the collected object biometric information are associated and stored in the certificate repository; receive the target digital certificate sent by the certificate registration end.

[0035] In one embodiment, the resource feature extraction strategy is a hash function, and the second extraction module is further configured to perform a hash operation on at least one virtual resource to be transferred through the preset hash function to obtain a hash value corresponding to at least one virtual resource to be transferred; determine first resource feature information according to the hash value corresponding to at least one virtual resource to be transferred.

[0036] In one embodiment, the private key includes a first key parameter and a second key parameter. The first key parameter is determined based on the product of a preset first prime number and a preset second prime number. The second key parameter is determined based on a quantity parameter and a preset first integer. The quantity parameter is the number of positive integers that are less than or equal to the first key parameter and are relatively prime to the first key parameter. The first integer is less than the quantity parameter and is relatively prime to the quantity parameter; the encryption module is further configured to convert the first resource feature information into a second integer, where the second integer is less than the first key parameter; encrypt the second integer according to the first key parameter and the second key parameter to obtain a digital signature.

[0037] In one embodiment, the first resource feature information is binary feature data represented in binary form. The binary feature data includes a plurality of binary bits. The encryption module is further configured to group the plurality of binary bits to obtain a plurality of binary bit combinations; for each binary bit combination, convert the binary bits included in the targeted binary bit combination into a numerical value represented in decimal form to obtain an integer corresponding to the targeted binary bit combination; and splice the integers corresponding to the plurality of binary bit combinations respectively to obtain a second integer.

[0038] In one embodiment, the encryption module is further configured to determine a first signature parameter according to the second key parameter and the second integer; perform a modulo operation on the first signature parameter and the first key parameter to obtain a second signature parameter; and determine a digital signature according to the second signature parameter.

[0039] In a fifth aspect, the present application provides a computer device, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the method embodiments of the present application are implemented.

[0040] In a sixth aspect, the present application provides a computer-readable storage medium, storing a computer program. When the computer program is executed by a processor, the steps in the method embodiments of the present application are implemented.

[0041] In a seventh aspect, the present application provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps in the method embodiments of the present application are implemented.

[0042] The above resource transfer method, device, equipment, and medium receive a resource transfer request initiated by a first terminal through a short-range communication method, and determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset resource feature extraction strategy, based on the resource identifiers of the at least one virtual resource to be transferred. Different virtual resources have different resource identifiers. By using the preset resource feature extraction strategy, features are extracted from the at least one virtual resource indicated by the resource transfer request to obtain the second resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on the at least one virtual resource indicated by the resource transfer request. Compared with traditional resource transfer methods, this application receives resource transfer requests through short-range communication methods, which can support resource transfer requests initiated by the initiating end in an offline state. Before sending a resource transfer request, the initiating end of the resource transfer request signs at least one virtual resource to be transferred using the private key, and sends the digital signature and at least one virtual resource indicated by the resource transfer request to the resource receiving end, so that after the resource receiving end passes the integrity verification of the at least one virtual resource received based on the digital signature, resource transfer is performed based on the at least one virtual resource received, avoiding malicious tampering of virtual resources during transmission, ensuring the security and reliability of virtual resources during the resource transfer process, and thus avoiding malicious transfer of resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 FIG. is an application environment diagram of the resource transfer method in an embodiment;

[0044] Figure 2 FIG. is a schematic flowchart of the resource transfer method applied to a second terminal in an embodiment;

[0045] Figure 3 FIG. is a comparison schematic diagram of physical resources and virtual resources in an embodiment;

[0046] Figure 4 FIG. is a schematic diagram of a scenario for realizing virtual resource transfer by tapping in an embodiment;

[0047] Figure 5 FIG. is a schematic diagram of a scenario for realizing virtual resource transfer by tapping in another embodiment;

[0048] Figure 6 FIG. is an application environment diagram of the resource transfer method in another embodiment;

[0049] Figure 7 FIG. is a schematic diagram of a hardware resource container in an embodiment;

[0050] Figure 8 Schematic diagram of the interface of the resource management application in an embodiment;

[0051] Figure 9 Schematic diagram of the software resource container in an embodiment;

[0052] Figure 10 Schematic flow chart of the resource transfer method applied to the first terminal in an embodiment;

[0053] Figure 11 Schematic diagram of the acquisition scenario of the object biometric information in an embodiment;

[0054] Figure 12 Schematic flow chart of the resource transfer method in another embodiment;

[0055] Figure 13 Schematic block diagram of the resource transfer device in an embodiment;

[0056] Figure 14 Schematic block diagram of the resource transfer device in another embodiment;

[0057] Figure 15 Internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0058] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0059] The resource transfer method provided by the present application can be applied to an application environment as shown in Figure 1 . Among them, the first terminal 102 communicates with the second terminal 104 through a short-range communication method. Among them, the first terminal 102 and the second terminal 104 can be but are not limited to various desktop computers, laptop computers, smart phones, tablet computers, vehicle-mounted terminals, intelligent voice interaction devices, aircraft, smart home appliances and portable wearable devices. The smart home appliances can be smart speakers, smart TVs, smart air conditioners, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc.

[0060] The second terminal 104 can receive a resource transfer request initiated by the first terminal 102 through a short-range communication method; determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal 102 encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the first terminal 102, after determining at least one virtual resource to be transferred, extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy. Different virtual resources have different resource identifiers. The second terminal 104 can extract features from the at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information. If the second resource feature information is consistent with the first resource feature information, the second terminal 104 can perform resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0061] In one embodiment, as Figure 2 shown, a resource transfer method is provided. This method can be applied to the second terminal. It can be understood that the second terminal is the terminal that receives the virtual resources to be transferred during the resource transfer process, and includes the following steps:

[0062] Step 202, receive a resource transfer request initiated by the first terminal through a short-range communication method.

[0063] Among them, the short-range communication method refers to the technology for communication between two devices within a short range. The short range can specifically be the distance between two devices being less than a preset distance. For example, the short-range communication method can include at least one of NFC (Near Field Communication) and Bluetooth connection, etc. The first terminal is the terminal that initiates the resource transfer request. It can be understood that the first terminal is the terminal that wants to transfer local virtual resources outward. The resource transfer request is a computer instruction for requesting virtual resource transfer. Virtual resources are virtual resources, and different virtual resources have different resource identifiers, and the resource identifier is used to uniquely identify the virtual resource.

[0064] Specifically, the first terminal and the second terminal can communicate through a short-range communication method. The first terminal can determine at least one virtual resource to be transferred, extract features of the at least one virtual resource to be transferred through a preset resource feature extraction strategy, and obtain first resource feature information. The first terminal can use a preset private key to encrypt the first resource feature information to obtain a digital signature. The first terminal can obtain a resource transfer request, where the resource transfer request carries the digital signature and a public key matching the private key. The first terminal can send the resource transfer request to the second terminal through a short-range communication method. The second terminal can receive the resource transfer request initiated by the first terminal through a short-range communication method. The resource feature extraction strategy is a strategy for extracting feature information of at least one virtual resource. The first resource feature information is the feature information of the at least one virtual resource to be transferred.

[0065] To facilitate further understanding of the virtual resources in this application and better distinguish traditional physical resources from the virtual resources in this application, the following explanations are provided. As Figure 3 shown, a resource issuing institution can issue physical resources and virtual resources. For physical resources, when a user has many physical resources but does not often use them, the user can go to the resource issuing institution to open a resource account and store the physical resources in the resource issuing institution. When the user needs to use them, the user can go to the resource issuing institution to retrieve the physical resources. In a resource payment scenario, the user can also bind the resource account opened in the resource issuing institution to a payment application. When it is necessary to pay for resources, the user can scan a code through the payment application to deduct the physical resources to be paid from the resource account. For virtual resources, after being issued by the resource issuing institution, they can be directly bound to the user's payment application. When it is necessary to pay for resources, the user can scan a code through the payment application to deduct the virtual resources to be paid.

[0066] In one embodiment, as Figure 4 shown, 401 is the first terminal in a virtual resource transfer scenario, and 402 is the second terminal in a virtual resource transfer scenario. The first terminal 401 and the second terminal 402 can achieve the transfer of virtual resources by touching each other, that is, transfer the virtual resources from the first terminal 401 to the second terminal 402. It can be understood that touching each other is essentially realized based on the short-range communication method NFC of the first terminal 401 and the second terminal 402.

[0067] In one embodiment, as Figure 5As shown in the figure, 501 is the first terminal in the virtual resource transfer scenario, and 502 is the second terminal in the virtual resource transfer scenario. The first terminal 501 and the second terminal 502 can transfer virtual resources by touching each other, that is, transfer the virtual resources from the first terminal 501 to the second terminal 502. It can be understood that touching each other is essentially implemented based on the near-field communication method NFC of the first terminal 501 and the second terminal 502.

[0068] Step 204: Determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the first terminal extracting features based on the resource identifiers of at least one virtual resource to be transferred through a preset resource feature extraction strategy after determining at least one virtual resource to be transferred. Different virtual resources have different resource identifiers.

[0069] Specifically, the second terminal can obtain the public key and digital signature carried in the resource transfer request, and obtain at least one virtual resource indicated by the resource transfer request, so as to obtain at least one virtual resource indicated by the resource transfer request. It can be understood that at least one virtual resource to be transferred in the first terminal is the virtual resource that the first terminal needs to transfer outwards, and at least one virtual resource indicated by the resource transfer request is the virtual resource that the second terminal actually obtains. It can be understood that if the virtual resource is not tampered with during the transmission process, at least one virtual resource indicated by the resource transfer request is the same as at least one virtual resource to be transferred in the first terminal. If the virtual resource is maliciously tampered with during the transmission process, at least one virtual resource indicated by the resource transfer request is different from at least one virtual resource to be transferred in the first terminal.

[0070] In one embodiment, the preset resource feature extraction strategy is a preset hash function. The first terminal can determine at least one virtual resource to be transferred, and extract features from at least one virtual resource to be transferred through the preset hash function to obtain the first resource feature information. The first terminal can use the preset private key to encrypt the first resource feature information to obtain the digital signature.

[0071] In one embodiment, the preset resource feature extraction strategy is a preset artificial intelligence algorithm. The first terminal can determine at least one virtual resource to be transferred, and extract features from at least one virtual resource to be transferred through the preset artificial intelligence algorithm to obtain the first resource feature information. The first terminal can use the preset private key to encrypt the first resource feature information to obtain the digital signature.

[0072] Step 206: Extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain the second resource feature information.

[0073] Specifically, the second terminal may extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy, and obtain second resource feature information. It can be understood that the second resource feature information is the feature information of at least one virtual resource indicated by the resource transfer request.

[0074] Step 208, when the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on at least one virtual resource indicated by the resource transfer request.

[0075] Specifically, the second terminal may compare the second resource feature information with the first resource feature information. When the second resource feature information is consistent with the first resource feature information, it indicates that the virtual resource has not been tampered with during transmission, and at least one virtual resource indicated by the resource transfer request is the same as at least one virtual resource to be transferred in the first terminal. Furthermore, the second terminal may perform resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0076] In one embodiment, the second terminal may perform resource transfer based on at least one virtual resource indicated by the resource transfer request, obtain a resource transfer result, and store the resource transfer result in the blockchain network to prevent the resource transfer result from being tampered with.

[0077] In the above resource transfer method, a resource transfer request initiated by a first terminal is received through a short-range communication method, and a public key, a digital signature, and at least one virtual resource indicated by the resource transfer request are determined. The digital signature is obtained by the first terminal encrypting the first resource feature information using a private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy. Different virtual resources have different resource identifiers. The at least one virtual resource indicated by the resource transfer request is extracted for features through the preset resource feature extraction strategy to obtain second resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on the at least one virtual resource indicated by the resource transfer request. Compared with traditional resource transfer methods, in this application, the resource transfer request is received through a short-range communication method, which supports resource transfer by the initiating end of the resource transfer request in an offline state. Before sending the resource transfer request, the initiating end of the resource transfer request signs at least one virtual resource to be transferred using the private key, and sends the digital signature and the at least one virtual resource indicated by the resource transfer request to the resource receiving end, so that after the resource receiving end passes the integrity verification of the at least one virtual resource received based on the digital signature, resource transfer is performed based on the at least one virtual resource received, avoiding malicious tampering of the virtual resources during transmission, ensuring the security and reliability of the virtual resources during the resource transfer process, and thus avoiding malicious transfer of resources.

[0078] In one embodiment, the method further includes: determining a target digital certificate indicated by the resource transfer request; sending the target digital certificate to a certificate registration end, where the target digital certificate is used to instruct the certificate registration end to search for a digital certificate consistent with the target digital certificate in a certificate repository, and object biometric information associated with the digital certificate is also stored in the certificate repository; when a digital certificate consistent with the target digital certificate is found in the certificate repository, obtaining first object biometric information associated with the target digital certificate from the certificate registration end; collecting second object biometric information of the object that initiates the resource transfer request; and when the second object biometric information is consistent with the first object biometric information, performing the step of performing resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0079] Among them, the first object biometric information is object biometric information having an association relationship with the target digital certificate. The second object biometric information is object biometric information collected for the object that initiates the resource transfer request.

[0080] Specifically, the first terminal may send a resource transfer request carrying a target digital certificate to the second terminal. The second terminal may obtain the target digital certificate carried in the resource transfer request and send the target digital certificate to the certificate registration end. After receiving the target digital certificate, the certificate registration end may search for a digital certificate consistent with the target digital certificate in the certificate repository. It can be understood that the certificate repository also stores object biometric information associated with the digital certificate. When a digital certificate consistent with the target digital certificate is found in the certificate repository, the certificate registration end may send the first object biometric information associated with the target digital certificate to the second terminal. The second terminal may receive the first object biometric information associated with the target digital certificate sent by the certificate registration end. The second terminal may collect the second object biometric information of the object initiating the resource transfer request and compare the second object biometric information with the first object biometric information. When the second object biometric information is consistent with the first object biometric information, the second terminal may perform a resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0081] Continue to refer to Figure 5 , the object initiating the resource transfer request is in front of the first terminal 501, and the second terminal 502 may also collect the object biometric information of the object to obtain the second object biometric information. After verifying that the second object biometric information is consistent with the first object biometric information, the second terminal performs a resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0082] In one embodiment, as Figure 6As shown, the second terminal can receive a resource transfer request initiated by the first terminal through a short-range communication method, and determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset resource feature extraction strategy, based on the resource identifiers of each of the at least one virtual resource to be transferred. Different virtual resources have different resource identifiers. The second terminal can extract features from the at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information. When the second resource feature information is consistent with the first resource feature information, the target digital certificate indicated by the resource transfer request is determined. The second terminal can send the target digital certificate to the certificate registration end. The target digital certificate is used to instruct the certificate registration end to find a digital certificate that is consistent with the target digital certificate in the certificate repository. The certificate repository also stores object biometric information associated with the digital certificate. It can be understood that before initiating the resource transfer request, the first terminal can send a certificate registration request to the certificate registration end to obtain the target digital certificate. When a digital certificate that is consistent with the target digital certificate is found in the certificate repository, the second terminal can obtain the first object biometric information associated with the target digital certificate from the certificate registration end. The second terminal can collect the second object biometric information of the object that initiates the resource transfer request. When the second object biometric information is consistent with the first object biometric information, the second terminal can perform resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0083] In one embodiment, the second terminal can directly send the target digital certificate to the certificate registration end. It can be understood that directly sending the target digital certificate to the certificate registration end means that the second terminal does not encrypt the target digital certificate, but directly sends the target digital certificate itself to the certificate registration end.

[0084] In the above embodiment, by determining the target digital certificate indicated by the resource transfer request and sending the target digital certificate to the certificate registration end, the first object biometric information associated with the target digital certificate is obtained from the certificate registration end. The second object biometric information of the object that initiates the resource transfer request is collected; when the second object biometric information collected for the object that initiates the resource transfer request is consistent with the first object biometric information, it indicates that the identity of the object that initiates the resource transfer request is legal. After determining that the identity of the object that initiates the resource transfer request is legal, and then performing resource transfer based on the at least one virtual resource indicated by the resource transfer request, the security and reliability of virtual resource transfer can be improved.

[0085] In one embodiment, sending a target digital certificate to a certificate registration end includes: obtaining an encryption key agreed with the certificate registration end; respectively performing binary conversion on the target digital certificate and the encryption key to obtain binary certificate data and binary key data; performing a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain certificate encryption data; sending the certificate encryption data to the certificate registration end, where the certificate encryption data is used to instruct the certificate registration end to decrypt the certificate encryption data based on the encryption key to obtain the target digital certificate.

[0086] Among them, the binary certificate data is the binary data obtained by performing binary conversion on the target digital certificate. The binary key data is the binary data obtained by performing binary conversion on the encryption key.

[0087] Specifically, the second terminal can obtain the encryption key agreed with the certificate registration end in advance and perform binary conversion on the encryption key to obtain binary key data. The second terminal can perform binary conversion on the target digital certificate to obtain binary certificate data. Furthermore, the second terminal can perform a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain certificate encryption data. It can be understood that the certificate encryption data is also data represented in binary form. The second terminal can send the certificate encryption data to the certificate registration end, and the certificate registration end can receive the encrypted data and decrypt the certificate encryption data based on the encryption key agreed with the second terminal in advance to obtain the target digital certificate.

[0088] In one embodiment, the second terminal can perform a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain initial certificate encryption data and directly use the initial certificate encryption data as the certificate encryption data.

[0089] In the above embodiment, by obtaining the encryption key agreed with the certificate registration end, performing a bitwise exclusive OR operation on the binary certificate data of the target digital certificate and the binary key data of the encryption key to obtain certificate encryption data, and sending the certificate encryption data to the certificate registration end. After obtaining the certificate encryption data, the certificate registration end decrypts the certificate encryption data based on the encryption key to obtain the target digital certificate, which can avoid the target digital certificate being tampered with during the transmission process, resulting in the abnormal progress of resource transfer, and improve the accuracy of resource transfer.

[0090] In one embodiment, a bitwise exclusive OR operation is performed on binary certificate data and binary key data to obtain certificate encryption data, including: performing a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain initial certificate encryption data, where the initial certificate encryption data contains multiple bytes. Obtain a preset byte pair record table, in which multiple preset byte pairs are recorded, and each byte pair contains two different bytes; for each byte in the initial certificate encryption data, replace the targeted byte with the byte in the byte pair record table that forms a byte pair with the targeted byte; after each of the multiple bytes contained in the initial certificate encryption data is replaced, certificate encryption data is obtained.

[0091] Specifically, the second terminal can perform a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain initial certificate encryption data, where the initial certificate encryption data contains multiple bytes. It can be understood that the initial certificate encryption data is also data represented in binary form, and one byte contains eight binary bits. The second terminal can obtain a preset byte pair record table, where multiple preset byte pairs are recorded in the byte pair record table, and each byte pair contains two different bytes. For each byte in the initial certificate encryption data, the second terminal can replace the targeted byte with the byte in the byte pair record table that forms a byte pair with the targeted byte. After each of the multiple bytes contained in the initial certificate encryption data is replaced, the second terminal can obtain certificate encryption data.

[0092] In the above embodiment, initial certificate encryption data is obtained by performing a bitwise exclusive OR operation on binary certificate data and binary key data. Furthermore, for each byte in the initial certificate encryption data, by replacing the targeted byte with the byte in the preset byte pair record table that forms a byte pair with the targeted byte. After each of the multiple bytes contained in the initial certificate encryption data is replaced, certificate encryption data is obtained, which can improve the reliability of the certificate encryption data, thereby further improving the accuracy of resource transfer.

[0093] In one embodiment, the resource feature extraction strategy is a hash function. Through the preset resource feature extraction strategy, features of at least one virtual resource indicated by the resource transfer request are extracted to obtain second resource feature information, including: performing a hash operation on at least one virtual resource indicated by the resource transfer request through the preset hash function to obtain the hash value corresponding to at least one virtual resource indicated by the resource transfer request; determining the second resource feature information according to the hash value corresponding to at least one virtual resource indicated by the resource transfer request.

[0094] Specifically, the preset resource feature extraction strategy is a preset hash function. The second terminal may use at least one virtual resource indicated by the resource transfer request as the input of the hash function, and perform a hash operation on at least one virtual resource indicated by the resource transfer request through the hash function to obtain the hash value corresponding to at least one virtual resource indicated by the resource transfer request. Furthermore, the second terminal may determine the second resource feature information according to the hash value corresponding to at least one virtual resource indicated by the resource transfer request.

[0095] In one embodiment, the second terminal may directly use the hash value corresponding to at least one virtual resource indicated by the resource transfer request as the second resource feature information.

[0096] In one embodiment, the second terminal may transform the hash value corresponding to at least one virtual resource indicated by the resource transfer request according to a preset transformation strategy, and use the obtained result of the transformation as the second resource feature information.

[0097] In the above embodiments, by performing a hash operation on at least one virtual resource indicated by the resource transfer request through a preset hash function, the hash value corresponding to at least one virtual resource indicated by the resource transfer request is obtained, and the second resource feature information is determined according to the hash value corresponding to at least one virtual resource indicated by the resource transfer request, which improves the reliability of the digital signature, thereby further avoiding malicious tampering of virtual resources during the transmission process, and further ensuring the security and reliability of virtual resources during the resource transfer process.

[0098] In one embodiment, a resource management chip is provided in the first terminal, and a hardware resource container for storing virtual resources is provided in the resource management chip. At least one virtual resource to be transferred is determined by the first terminal from the hardware resource container.

[0099] Specifically, a resource management chip is provided in the first terminal, and a hardware resource container for storing virtual resources is provided in the resource management chip. The first terminal may determine at least one virtual resource to be transferred from the hardware resource container.

[0100] In one embodiment, in the payment scenario of virtual resources, the hardware resource container may also display the quantity of payment virtual resources, the remaining quantity of virtual resources in the hardware resource container, and the number of offline available times. As Figure 7 shown, the quantity of virtual resources to be transferred determined by the first terminal from the hardware resource container, that is, the payment is 2.00, the remaining quantity of virtual resources in the hardware resource container, that is, the balance is 127.05, and the number of offline available times of the hardware resource container is 4 times.

[0101] In the above embodiments, by storing virtual resources in the hardware resource container of the resource management chip, since the hardware resource container is implemented based on hardware logic and is not easily vulnerable to malicious attacks, the security of storing virtual resources can be improved.

[0102] In one embodiment, a resource management application is pre-installed in the first terminal. A software resource container for storing virtual resources is set in the resource management application. At least one virtual resource to be transferred is determined by the first terminal from the software resource container.

[0103] Specifically, a resource management application is pre-installed in the first terminal. A software resource container for storing virtual resources is set in the resource management application. The first terminal can determine at least one virtual resource to be transferred from the software resource container.

[0104] In one embodiment, in a virtual resource payment scenario, the first terminal is a payment terminal. As Figure 8 shown, the resource management application can be installed on the payment terminal. The payment terminal can display a resource management page, that is, the "My" page, through the resource management application. A virtual resource viewing entry can be displayed in the resource management page, that is, the "Virtual Resources" displayed in the "My" page. The resource management application can enter the "Software Resource Container" page in response to a trigger operation on the "Virtual Resources". As Figure 9 shown, virtual resource 901 can be displayed in the "Software Resource Container" page. Among them, the virtual resource 901 can include detailed virtual resource information such as the resource issuing agency, the resource quantity, and the resource identifier. The payment terminal can transfer the virtual resource 901 through a tap operation in response to a trigger operation on the "Tap to Pay" control.

[0105] In the above embodiments, by storing virtual resources in the software resource container of the resource management application, resource management can be facilitated and resource management efficiency can be improved.

[0106] In one embodiment, as Figure 10 shown, a resource transfer method is provided. This method can be applied to the first terminal. It can be understood that the first terminal is the terminal that initiates a resource transfer request during the resource transfer process, including the following steps:

[0107] Step 1002: Determine at least one virtual resource to be transferred, and different virtual resources have different resource identifiers.

[0108] Step 1004: Extract features from at least one virtual resource to be transferred through a preset resource feature extraction strategy to obtain first resource feature information.

[0109] Step 1006: Use a preset private key to encrypt the first resource feature information to obtain a digital signature.

[0110] Step 1008: Obtain a resource transfer request, where the resource transfer request carries a digital signature and a public key that matches the private key.

[0111] Step 1010: Send the resource transfer request to the second terminal via a short-range communication method. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from the at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information, and use the public key to decrypt the digital signature to obtain first resource feature information. When the second resource feature information is consistent with the first resource feature information, perform a resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0112] Specifically, the first terminal and the second terminal can communicate via a short-range communication method. The first terminal can send a resource transfer request to the second terminal via a short-range communication method. The second terminal can receive the resource transfer request initiated by the first terminal via a short-range communication method, and obtain the public key and digital signature carried by the resource transfer request, as well as obtain at least one virtual resource indicated by the resource transfer request to get at least one virtual resource indicated by the resource transfer request. The second terminal can extract features from the at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information. The second terminal can compare the second resource feature information with the first resource feature information. When the second resource feature information is consistent with the first resource feature information, it indicates that the virtual resource has not been tampered with during transmission, and the at least one virtual resource indicated by the resource transfer request is the same as the at least one virtual resource to be transferred in the first terminal. Furthermore, the second terminal can perform a resource transfer based on the at least one virtual resource indicated by the resource transfer request.

[0113] In the above embodiment, by determining at least one virtual resource to be transferred, different virtual resources have different resource identifiers, and extracting features from at least one virtual resource to be transferred through a preset resource feature extraction strategy, a first resource feature information is obtained. The first resource feature information is encrypted using a preset private key to obtain a digital signature. A resource transfer request is obtained, and the resource transfer request carries a digital signature and a public key matching the private key. A resource transfer request is sent to a second terminal through a short-distance communication method, the resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy, obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, a resource transfer is performed based on at least one virtual resource indicated by the resource transfer request. Compared with the traditional resource transfer method, the present application receives a resource transfer request through a short-distance communication method, and can support the resource transfer request initiator to perform resource transfer in an offline state. Before sending a resource transfer request, the initiator of the resource transfer request signs at least one virtual resource to be transferred using a private key, and sends the digital signature and at least one virtual resource indicated by the resource transfer request to the resource receiver, so that the resource receiver performs an integrity check on the at least one virtual resource received based on the digital signature, and then performs resource transfer based on the at least one virtual resource received, thereby avoiding malicious tampering of the virtual resources during transmission, ensuring the security and reliability of the virtual resources during the resource transfer process, and thus avoiding malicious transfer of resources.

[0114] In one embodiment, the method also includes: obtaining a target digital certificate; sending the target digital certificate to the second terminal, the target digital certificate is used to instruct the second terminal to send the target digital certificate to the certificate registration end, so that the certificate registration end searches for a digital certificate consistent with the target digital certificate from a certificate repository, the certificate repository also stores object biometric information associated with the digital certificate, when a digital certificate consistent with the target digital certificate is found from the certificate repository, the first object biometric information associated with the target digital certificate is sent to the second terminal; receiving prompt information sent by the second terminal to indicate that the resource transfer is successful, the prompt information is generated by the second terminal after determining that the second object biometric information is consistent with the first object biometric information, and performing resource transfer based on at least one virtual resource indicated by the resource transfer request, the second object biometric information is biometric information collected by the second terminal for the object that initiated the resource transfer request.

[0115] Specifically, the first terminal may send a resource transfer request carrying a target digital certificate to the second terminal. The second terminal may obtain the target digital certificate carried in the resource transfer request and send the target digital certificate to the certificate registration end. After receiving the target digital certificate, the certificate registration end may search for a digital certificate consistent with the target digital certificate in the certificate repository. It can be understood that the certificate repository also stores object biometric information associated with the digital certificate. When a digital certificate consistent with the target digital certificate is found in the certificate repository, the certificate registration end may send the first object biometric information associated with the target digital certificate to the second terminal. The second terminal may receive the first object biometric information associated with the target digital certificate sent by the certificate registration end. The second terminal may collect the second object biometric information of the object initiating the resource transfer request and compare the second object biometric information with the first object biometric information. When the second object biometric information is consistent with the first object biometric information, the second terminal may perform resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0116] In one embodiment, the second terminal may receive a resource transfer request initiated by the first terminal through a short-range communication method and determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal using the private key matching the public key to encrypt the first resource feature information. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset resource feature extraction strategy, based on the resource identifiers of each of the at least one virtual resource to be transferred. Different virtual resources have different resource identifiers. The second terminal may extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information. When the second resource feature information is consistent with the first resource feature information, the target digital certificate indicated by the resource transfer request is determined. The second terminal may send the target digital certificate to the certificate registration end. The target digital certificate is used to instruct the certificate registration end to search for a digital certificate consistent with the target digital certificate in the certificate repository. The certificate repository also stores object biometric information associated with the digital certificate. When a digital certificate consistent with the target digital certificate is found in the certificate repository, the second terminal may obtain the first object biometric information associated with the target digital certificate from the certificate registration end. The second terminal may collect the second object biometric information of the object initiating the resource transfer request. When the second object biometric information is consistent with the first object biometric information, the second terminal may perform resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0117] In the above embodiments, by determining the target digital certificate indicated by the resource transfer request and sending the target digital certificate to the certificate registration end, the first object biometric information associated with the target digital certificate is obtained from the certificate registration end. The second object biometric information of the object initiating the resource transfer request is collected; when the second object biometric information collected for the object initiating the resource transfer request is consistent with the first object biometric information, it indicates that the identity of the object initiating the resource transfer request is legal. After determining that the identity of the object initiating the resource transfer request is legal, the resource transfer is performed based on at least one virtual resource indicated by the resource transfer request, which can improve the security and reliability of the virtual resource transfer.

[0118] In one embodiment, obtaining the target digital certificate includes: sending a certificate registration request to the certificate registration end, where the certificate registration request is used to instruct the certificate registration end to collect the object biometric information of the object initiating the certificate registration request. After the collected object biometric information passes the verification, a target digital certificate is generated, and the target digital certificate is associated with the collected object biometric information and stored in the certificate repository; receiving the target digital certificate sent by the certificate registration end.

[0119] Among them, the certificate registration request is a computer instruction for requesting to register a digital certificate.

[0120] Specifically, the first terminal can send a certificate registration request to the certificate registration end. After receiving the certificate registration request, the certificate registration end can collect the object biometric information of the object initiating the certificate registration request and perform a legality verification on the collected object biometric information. After the collected object biometric information passes the verification, the certificate registration end can generate a target digital certificate and associate the target digital certificate with the collected object biometric information and store it in the certificate repository. Furthermore, the certificate registration end can send the target digital certificate to the first terminal, and the first terminal can receive the target digital certificate sent by the certificate registration end.

[0121] In one embodiment, the third-party device stores the object biometric information of the preset object, and the third-party device also stores the object identifier associated with the object biometric information. The certificate registration terminal can communicate with the third-party device to obtain the object biometric information associated with the object identifier of the object initiating the certificate registration request from the third-party device, and compare the collected object biometric information with the object biometric information obtained from the third-party device. If the collected object biometric information is consistent with the object biometric information obtained from the third-party device, it is determined that the legality verification of the collected object biometric information passes. If the collected object biometric information is inconsistent with the object biometric information obtained from the third-party device, it is determined that the legality verification of the collected object biometric information fails.

[0122] In one embodiment, as Figure 11 shown, after receiving a certificate registration request, the certificate registration end may collect the object biometric information of the object that initiates the certificate registration request. For example, the object biometric information may include at least one of fingerprint information, palmprint information, iris information, face information, etc.

[0123] In the above embodiment, by sending a certificate registration request to the certificate registration end, so that the certificate registration end collects the object biometric information of the object that initiates the certificate registration request, after the collected object biometric information is verified, a target digital certificate is generated, and the target digital certificate is associated with the collected object biometric information and stored in the certificate repository, which further improves the accuracy of the subsequent legality verification of the identity of the object that initiates the resource transfer request, thereby further improving the security and reliability of virtual resource transfer.

[0124] In one embodiment, the resource feature extraction strategy is a hash function. Through the preset resource feature extraction strategy, features of at least one virtual resource to be transferred are extracted to obtain first resource feature information, including: performing a hash operation on at least one virtual resource to be transferred through the preset hash function to obtain a hash value corresponding to at least one virtual resource to be transferred; determining the first resource feature information according to the hash value corresponding to at least one virtual resource to be transferred.

[0125] Specifically, the preset resource feature extraction strategy is a preset hash function. The first terminal may use at least one virtual resource to be transferred as the input of the hash function, so as to perform a hash operation on at least one virtual resource to be transferred through the hash function to obtain a hash value corresponding to at least one virtual resource to be transferred. Furthermore, the first terminal may determine the first resource feature information according to the hash value corresponding to at least one virtual resource to be transferred.

[0126] In one embodiment, the first terminal may directly use the hash value corresponding to at least one virtual resource to be transferred as the first resource feature information.

[0127] In one embodiment, the first terminal may transform the hash value corresponding to at least one virtual resource to be transferred according to a pre-set transformation strategy, and use the result of the transformation as the first resource feature information.

[0128] In the above embodiment, by performing a hash operation on at least one virtual resource to be transferred through the preset hash function to obtain a hash value corresponding to at least one virtual resource to be transferred, and determining the second resource feature information according to the hash value corresponding to at least one virtual resource to be transferred, it is possible to further prevent virtual resources from being maliciously tampered with during transmission, and further ensure the security and reliability of virtual resources during the resource transfer process.

[0129] In one embodiment, the private key includes a first key parameter and a second key parameter. The first key parameter is determined based on the product of a preset first prime number and a preset second prime number. The second key parameter is determined based on a quantity parameter and a preset first integer. The quantity parameter is the number of positive integers that are less than or equal to the first key parameter and are relatively prime to the first key parameter. The first integer is less than the quantity parameter and is relatively prime to the quantity parameter. Using the preset private key to encrypt the first resource feature information to obtain a digital signature includes: converting the first resource feature information into a second integer, where the second integer is less than the first key parameter; encrypting the second integer according to the first key parameter and the second key parameter to obtain the digital signature.

[0130] In one embodiment, the first terminal can obtain the preset first prime number and the preset second prime number, and determine the first key parameter based on the product of the first prime number and the second prime number. The first terminal can determine the number of positive integers that are less than or equal to the first key parameter and are relatively prime to the first key parameter based on the first key parameter to obtain the quantity parameter. The first terminal can select an integer from the integers that are less than the quantity parameter and are relatively prime to the quantity parameter as the first integer. The first terminal can determine the second key parameter based on the quantity parameter and the first integer. The first terminal can convert the first resource feature information into a second integer, where the second integer is less than the first key parameter. Furthermore, the first terminal can encrypt the second integer according to the first key parameter and the second key parameter to obtain the digital signature.

[0131] In one embodiment, the first resource feature information is hexadecimal feature data represented in hexadecimal form. The hexadecimal feature data includes multiple hexadecimal digits. Converting the first resource feature information into a second integer includes: grouping the multiple hexadecimal digits to obtain multiple hexadecimal digit combinations; for each hexadecimal digit combination, converting the hexadecimal digits included in the targeted hexadecimal digit combination into a numerical value represented in decimal form to obtain the integer corresponding to the targeted hexadecimal digit combination; concatenating the integers corresponding to the multiple hexadecimal digit combinations to obtain the second integer.

[0132] In the above embodiment, by converting the first resource feature information into a second integer that is less than the first key parameter in the private key, and encrypting the second integer according to the first key parameter and the second key parameter in the private key to obtain the digital signature, the complexity of the digital signature can be improved, thereby avoiding the digital signature being tampered with during transmission, and further improving the accuracy of virtual resource transfer.

[0133] In one embodiment, the first resource feature information is binary feature data represented in binary form. The binary feature data includes a plurality of binary bits. Converting the first resource feature information into a second integer includes: grouping the plurality of binary bits to obtain a plurality of binary bit combinations; for each binary bit combination, converting the binary bits included in the targeted binary bit combination into a numerical value represented in decimal form to obtain an integer corresponding to the targeted binary bit combination; and concatenating the integers corresponding to the plurality of binary bit combinations to obtain the second integer.

[0134] Among them, the binary feature data is binary data representing the first resource feature information in binary form.

[0135] Specifically, the first terminal can group the plurality of binary bits included in the binary feature data to obtain a plurality of binary bit combinations, where each binary bit combination includes at least one binary bit. For each binary bit combination, convert the binary bits included in the targeted binary bit combination into a numerical value represented in decimal form to obtain an integer corresponding to the targeted binary bit combination. Furthermore, the first terminal can concatenate the integers corresponding to the plurality of binary bit combinations to obtain the second integer.

[0136] In the above embodiment, by grouping the plurality of binary bits, a plurality of binary bit combinations are obtained. For each binary bit combination, the binary bits included in the targeted binary bit combination are converted into a numerical value represented in decimal form to obtain an integer corresponding to the targeted binary bit combination. Furthermore, by concatenating the integers corresponding to the plurality of binary bit combinations, the second integer is obtained, which can further enhance the complexity of the digital signature, further avoid the digital signature being tampered with during transmission, and thus further improve the accuracy of virtual resource transfer.

[0137] In one embodiment, encrypting the second integer according to the first key parameter and the second key parameter to obtain a digital signature includes: determining a first signature parameter according to the second key parameter and the second integer; performing a modulo operation on the first signature parameter and the first key parameter to obtain a second signature parameter; and determining the digital signature according to the second signature parameter.

[0138] Among them, the first signature parameter is a parameter determined according to the second key parameter and the second integer. The second signature parameter is a numerical value obtained by performing a modulo operation on the first signature parameter and the first key parameter.

[0139] In one embodiment, the first terminal may determine a first signature parameter according to a second key parameter and a second integer. The first terminal may perform a modulo operation on the first signature parameter and the first key parameter, that is, take the modulo of the first signature parameter with respect to the first key parameter, and use the obtained modulus as the second signature parameter. Further, the first terminal may directly use the second signature parameter as the digital signature.

[0140] In one embodiment, the digital signature may be calculated by the following formula:

[0141] ;

[0142] ;

[0143] ;

[0144] ;

[0145] where p represents a first prime number, q represents a second prime number, n represents a first key parameter, represents a quantity parameter, e represents a first integer, m represents a second integer, d represents a second key parameter, and s represents a digital signature. It can be understood that represents the first signature parameter, mod represents the modulo operation, represents the second signature parameter, and s represents the digital signature. It can also be understood that the private key of this application is (n, d), and the public key is (n, e).

[0146] In the above embodiment, determining the first signature parameter according to the second key parameter and the second integer, performing a modulo operation on the first signature parameter and the first key parameter to obtain the second signature parameter, and determining the digital signature according to the second signature parameter can further increase the complexity of the digital signature, further avoid the digital signature from being tampered with during transmission, and thus further improve the accuracy of virtual resource transfer.

[0147] As Figure 12 shown, in one embodiment, a resource transfer method is provided. This method can be applied to a second terminal, and the method specifically includes the following steps:

[0148] Step 1202, receive a resource transfer request initiated by the first terminal through a short-range communication method.

[0149] Step 1204, determine the public key, digital signature, and at least one virtual resource indicated by the resource transfer request.

[0150] Among them, the digital signature is obtained by the first terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset hash function, based on the resource identifiers of the at least one virtual resource to be transferred. Different virtual resources have different resource identifiers.

[0151] Step 1206: Perform a hash operation on at least one virtual resource indicated by the resource transfer request through a preset hash function to obtain the hash value corresponding to the at least one virtual resource indicated by the resource transfer request.

[0152] Step 1208: Determine the second resource feature information according to the hash value corresponding to the at least one virtual resource indicated by the resource transfer request.

[0153] Step 1210: When the second resource feature information is consistent with the first resource feature information, determine the target digital certificate indicated by the resource transfer request. The target digital certificate is used to instruct the certificate registration end to search in the certificate repository for a digital certificate that is the same as the target digital certificate. The certificate repository also stores the object biometric information associated with the digital certificate.

[0154] Step 1212: Obtain the encryption key agreed upon with the certificate registration end, and perform binary conversion on the target digital certificate and the encryption key respectively to obtain binary certificate data and binary key data.

[0155] Step 1214: Perform a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain the initial certificate encryption data. The initial certificate encryption data contains multiple bytes.

[0156] Step 1216: Obtain a preset byte pair record table. The byte pair record table records multiple preset byte pairs, and each byte pair contains two different bytes.

[0157] Step 1218: For each byte in the initial certificate encryption data, replace the targeted byte with the byte in the byte pair record table that forms a byte pair with the targeted byte.

[0158] Step 1220: After each of the multiple bytes contained in the initial certificate encryption data has been replaced, obtain the certificate encryption data.

[0159] Step 1222: Send the certificate encryption data to the certificate registration end. The certificate encryption data is used to instruct the certificate registration end to decrypt the certificate encryption data based on the encryption key to obtain the target digital certificate.

[0160] Step 1224, when a digital certificate identical to the target digital certificate is found in the certificate repository, obtain the first object biometric information associated with the target digital certificate from the certificate registration end.

[0161] Step 1226, collect the second object biometric information of the object that initiates the resource transfer request.

[0162] Step 1228, when the second object biometric information is identical to the first object biometric information, perform resource transfer based on at least one virtual resource indicated by the resource transfer request.

[0163] This application also provides an application scenario that applies the above resource transfer method. Specifically, this resource transfer method can be applied to the scenario of virtual resource payment. It can be understood that the first terminal is the resource payment terminal, and the second terminal is the resource receiving terminal. The resource transfer request is a resource payment request. Specifically, the resource receiving terminal can receive the resource payment request initiated by the resource payment terminal through a short-range communication method. Determine the public key, digital signature, and at least one virtual resource indicated by the resource payment request. The digital signature is obtained by the resource payment terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the resource payment terminal extracting features based on the resource identifiers of at least one virtual resource to be paid through a preset hash function after determining at least one virtual resource to be paid. Different virtual resources have different resource identifiers. Perform a hash operation on at least one virtual resource indicated by the resource payment request through a preset hash function to obtain the hash value corresponding to at least one virtual resource indicated by the resource payment request. Determine the second resource feature information according to the hash value corresponding to at least one virtual resource indicated by the resource payment request.

[0164] When the second resource characteristic information is consistent with the first resource characteristic information, the resource receiving terminal can determine the target digital certificate indicated by the resource payment request; the target digital certificate is used to instruct the certificate registration end to search for a digital certificate consistent with the target digital certificate from the certificate repository, and the certificate repository also stores the object biometric information associated with the digital certificate. Obtain the encryption key agreed with the certificate registration end, perform binary conversion on the target digital certificate and the encryption key respectively, and obtain binary certificate data and binary key data. Perform bitwise XOR operation on the binary certificate data and the binary key data to obtain initial certificate encrypted data, which contains multiple bytes. Obtain a preset byte pair record table, which records multiple preset byte pairs, and each byte pair contains two different bytes. For each byte in the initial certificate encrypted data, replace the targeted byte with a byte in the byte pair record table that forms a byte pair with the targeted byte. When the multiple bytes contained in the initial certificate encrypted data are replaced, the certificate encrypted data is obtained. Send the certificate encrypted data to the certificate registration end, and the certificate encrypted data is used to instruct the certificate registration end to decrypt the certificate encrypted data based on the encryption key to obtain the target digital certificate.

[0165] When a digital certificate consistent with the target digital certificate is found in the certificate repository, the resource receiving terminal can obtain the first object biometric information associated with the target digital certificate from the certificate registration terminal. The second object biometric information of the object that initiated the resource payment request is collected. When the second object biometric information is consistent with the first object biometric information, resource payment is made based on at least one virtual resource indicated by the resource payment request.

[0166] It can be understood that receiving a resource payment request by means of short-range communication can support the resource payment initiator to make resource payment in an offline state. Before sending a resource payment request, the resource payment initiator uses a private key to sign at least one virtual resource to be paid, and sends the digital signature and at least one virtual resource indicated by the resource payment request to the resource receiving end, so that the resource receiving end performs a integrity check on at least one virtual resource received based on the digital signature, and then makes a resource payment based on at least one virtual resource received, thereby avoiding malicious tampering of virtual resources during transmission, ensuring the security and reliability of virtual resources during the resource payment process, and thus avoiding malicious payment of resources.

[0167] The present application further provides an application scenario that applies the above resource transfer method. Specifically, the resource transfer method can be applied to the scenario of virtual resource donation. It can be understood that the first terminal is the resource donation terminal, and the second terminal is the resource receiving terminal. The resource transfer request is a resource donation request. Specifically, through a short-range communication method, a resource donation request initiated by the resource donation terminal is received, and the public key, digital signature, and at least one virtual resource indicated by the resource donation request are determined. The digital signature is obtained by the resource donation terminal encrypting the first resource feature information using the private key that matches the public key. The first resource feature information is obtained by the resource donation terminal, after determining at least one virtual resource to be donated, extracting features based on the resource identifiers of each of the at least one virtual resource to be donated through a preset resource feature extraction strategy. Different virtual resources have different resource identifiers. Through the preset resource feature extraction strategy, features of the at least one virtual resource indicated by the resource donation request are extracted to obtain the second resource feature information. When the second resource feature information is consistent with the first resource feature information, resource donation is performed based on the at least one virtual resource indicated by the resource donation request.

[0168] It can be understood that receiving the resource donation request through the short-range communication method can support the resource donation request initiator to perform resource donation in an offline state. Before sending the resource donation request, the resource donation request initiator signs the at least one virtual resource to be donated using the private key, and sends the digital signature and the at least one virtual resource indicated by the resource donation request to the resource receiving terminal, so that after the resource receiving terminal passes the integrity verification of the received at least one virtual resource based on the digital signature, resource donation is performed based on the received at least one virtual resource, avoiding malicious tampering of the virtual resources during the transmission process, ensuring the security and reliability of the virtual resources during the resource donation process, and thus avoiding malicious donation of resources.

[0169] It should be understood that although the steps in the flowcharts of the above embodiments are shown in sequence, these steps are not necessarily executed in sequence. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above embodiments may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0170] In one embodiment, as Figure 13 shown, a resource transfer device 1300 is provided. The device specifically includes:

[0171] The receiving module 1302 is configured to receive a resource transfer request initiated by the first terminal through a short distance communication method;

[0172] The first determination module 1304 is used to determine the public key, digital signature and at least one virtual resource indicated by the resource transfer request, the digital signature is obtained by the first terminal using a private key matching the public key to encrypt the first resource feature information, the first resource feature information is obtained by the first terminal extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy after determining the at least one virtual resource to be transferred, and different virtual resources have different resource identifiers;

[0173] The first extraction module 1306 is used to extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy to obtain second resource feature information;

[0174] The transfer module 1308 is configured to perform resource transfer based on at least one virtual resource indicated by the resource transfer request when the second resource characteristic information is consistent with the first resource characteristic information.

[0175] In one embodiment, the transfer module 1308 is also used to determine the target digital certificate indicated by the resource transfer request; send the target digital certificate to the certificate registration end, the target digital certificate is used to instruct the certificate registration end to search for a digital certificate consistent with the target digital certificate from the certificate repository, and the certificate repository also stores object biometric information associated with the digital certificate; when a digital certificate consistent with the target digital certificate is found from the certificate repository, the first object biometric information associated with the target digital certificate is obtained from the certificate registration end; the second object biometric information of the object initiating the resource transfer request is collected; when the second object biometric information is consistent with the first object biometric information, the step of performing resource transfer based on at least one virtual resource indicated by the resource transfer request is executed.

[0176] In one embodiment, the transfer module 1308 is also used to obtain the encryption key agreed upon with the certificate registration end; perform binary conversion on the target digital certificate and the encryption key respectively to obtain binary certificate data and binary key data; perform bitwise XOR operation on the binary certificate data and the binary key data to obtain certificate encrypted data; send the certificate encrypted data to the certificate registration end, and the certificate encrypted data is used to instruct the certificate registration end to decrypt the certificate encrypted data based on the encryption key to obtain the target digital certificate.

[0177] In one embodiment, the transfer module 1308 is further configured to perform a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain initial certificate encryption data, where the initial certificate encryption data includes multiple bytes; obtain a preset byte pair record table, where multiple preset byte pairs are recorded in the byte pair record table, and each byte pair includes two different bytes; for each byte in the initial certificate encryption data, replace the targeted byte with the byte that forms a byte pair with the targeted byte in the byte pair record table; after each of the multiple bytes included in the initial certificate encryption data is replaced, obtain the certificate encryption data.

[0178] In one embodiment, the resource feature extraction policy is a hash function, and the first extraction module 1306 is further configured to perform a hash operation on at least one virtual resource indicated by the resource transfer request through a preset hash function to obtain a hash value corresponding to at least one virtual resource indicated by the resource transfer request; determine the second resource feature information according to the hash value corresponding to at least one virtual resource indicated by the resource transfer request.

[0179] In one embodiment, a resource management chip is provided in the first terminal, and a hardware resource container for storing virtual resources is provided in the resource management chip. At least one virtual resource to be transferred is determined by the first terminal from the hardware resource container.

[0180] In one embodiment, a resource management application is pre-installed in the first terminal, and a software resource container for storing virtual resources is provided in the resource management application. At least one virtual resource to be transferred is determined by the first terminal from the software resource container.

[0181] The above resource transfer device receives a resource transfer request initiated by a first terminal through a short-range communication method, and determines a public key, a digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting the first resource feature information using a private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy, and different virtual resources have different resource identifiers. By using the preset resource feature extraction strategy, features are extracted from the at least one virtual resource indicated by the resource transfer request to obtain second resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on the at least one virtual resource indicated by the resource transfer request. Compared with traditional resource transfer methods, this application receives resource transfer requests through short-range communication, and can support resource transfer requests to be initiated in an offline state. Before sending a resource transfer request, the resource transfer request initiator signs at least one virtual resource to be transferred using a private key, and sends the digital signature and the at least one virtual resource indicated by the resource transfer request to the resource receiver, so that after the resource receiver passes the integrity verification of the received at least one virtual resource based on the digital signature, resource transfer is performed based on the received at least one virtual resource, avoiding malicious tampering of virtual resources during transmission, and ensuring the security and reliability of virtual resources during the resource transfer process, thereby avoiding malicious transfer of resources.

[0182] In one embodiment, as Figure 14 shown, a resource transfer device 1400 is provided, and the device specifically includes:

[0183] A second determination module 1402, configured to determine at least one virtual resource to be transferred, and different virtual resources have different resource identifiers;

[0184] A second extraction module 1404, configured to extract features from the at least one virtual resource to be transferred through a preset resource feature extraction strategy to obtain first resource feature information;

[0185] An encryption module 1406, configured to encrypt the first resource feature information using a preset private key to obtain a digital signature;

[0186] An acquisition module 1408, configured to acquire a resource transfer request, where the resource transfer request carries a digital signature and a public key that matches the private key;

[0187] The sending module 1410 is used to send a resource transfer request to the second terminal via a short-range communication method. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from at least one virtual resource indicated by the resource transfer request through a preset resource feature extraction strategy, obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on the at least one virtual resource indicated by the resource transfer request.

[0188] In one embodiment, the acquisition module 1408 is also used to obtain a target digital certificate; send the target digital certificate to the second terminal, the target digital certificate is used to instruct the second terminal to send the target digital certificate to the certificate registration end, so that the certificate registration end searches for a digital certificate consistent with the target digital certificate from the certificate repository, the certificate repository also stores object biometric information associated with the digital certificate, when a digital certificate consistent with the target digital certificate is found from the certificate repository, the first object biometric information associated with the target digital certificate is sent to the second terminal; receive prompt information sent by the second terminal to indicate that the resource transfer is successful, the prompt information is generated by the second terminal after determining that the second object biometric information is consistent with the first object biometric information, and performing resource transfer based on at least one virtual resource indicated by the resource transfer request, the second object biometric information is biometric information collected by the second terminal for the object that initiated the resource transfer request.

[0189] In one embodiment, the acquisition module 1408 is also used to send a certificate registration request to the certificate registration end, and the certificate registration request is used to instruct the certificate registration end to collect the object biometric information of the object that initiates the certificate registration request, and after the collected object biometric information is verified, generate a target digital certificate, and associate the target digital certificate with the collected object biometric information and store it in the certificate repository; receive the target digital certificate sent by the certificate registration end.

[0190] In one embodiment, the resource feature extraction strategy is a hash function, and the second extraction module 1404 is also used to perform a hash operation on at least one virtual resource to be transferred through a preset hash function to obtain a hash value corresponding to the at least one virtual resource to be transferred; and determine the first resource feature information based on the hash value corresponding to the at least one virtual resource to be transferred.

[0191] In one embodiment, the private key includes a first key parameter and a second key parameter. The first key parameter is determined based on the product of a preset first prime number and a preset second prime number. The second key parameter is determined based on a quantity parameter and a preset first integer. The quantity parameter is the number of positive integers that are less than or equal to the first key parameter and are relatively prime to the first key parameter. The first integer is less than the quantity parameter and is relatively prime to the quantity parameter. The encryption module 1406 is further configured to convert the first resource feature information into a second integer, where the second integer is less than the first key parameter; and encrypt the second integer according to the first key parameter and the second key parameter to obtain a digital signature.

[0192] In one embodiment, the first resource feature information is binary feature data represented in binary form. The binary feature data includes a plurality of binary bits. The encryption module 1406 is further configured to group the plurality of binary bits to obtain a plurality of binary bit combinations; for each binary bit combination, convert the binary bits included in the targeted binary bit combination into a numerical value represented in decimal form to obtain an integer corresponding to the targeted binary bit combination; and splice the integers corresponding to the plurality of binary bit combinations respectively to obtain a second integer.

[0193] In one embodiment, the encryption module 1406 is further configured to determine a first signature parameter according to the second key parameter and the second integer; perform a modulo operation on the first signature parameter and the first key parameter to obtain a second signature parameter; and determine the digital signature according to the second signature parameter.

[0194] The above-mentioned resource transfer device determines at least one virtual resource to be transferred, and different virtual resources have different resource identifiers. By using a preset resource feature extraction strategy, it extracts features from the at least one virtual resource to be transferred to obtain first resource feature information. It uses a preset private key to encrypt the first resource feature information to obtain a digital signature. It obtains a resource transfer request, which carries the digital signature and a public key that matches the private key. Through a short-range communication method, it sends the resource transfer request to a second terminal. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from the at least one virtual resource indicated by the resource transfer request by using a preset resource feature extraction strategy to obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, it performs resource transfer based on the at least one virtual resource indicated by the resource transfer request. Compared with traditional resource transfer methods, in this application, the resource transfer request is received through a short-range communication method, which supports the resource transfer request initiator to perform resource transfer in an offline state. Before sending the resource transfer request, the resource transfer request initiator signs the at least one virtual resource to be transferred by using the private key, and sends the digital signature and the at least one virtual resource indicated by the resource transfer request to the resource receiver, so that after the resource receiver passes the integrity verification of the at least one virtual resource received based on the digital signature, it then performs resource transfer based on the at least one virtual resource received, avoiding malicious tampering of the virtual resource during the transmission process, ensuring the security and reliability of the virtual resource during the resource transfer process, and thus avoiding malicious transfer of resources.

[0195] Each module in the above-mentioned resource transfer device can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above-mentioned modules.

[0196] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 15As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a resource transfer method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0197] Those skilled in the art can understand that Figure 15 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0198] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0199] In one embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0200] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0201] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0202] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0203] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0204] The above-described embodiments only represent several implementation manners of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of the patent of this application should be subject to the appended claims.

Claims

1. A resource transfer method, characterized in that, The method includes: Receiving a resource transfer request initiated by a first terminal through a short-range communication method; Determining a public key, a digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal encrypting first resource feature information using a private key that matches the public key. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, extracting features based on the resource identifiers of the at least one virtual resource to be transferred through a preset resource feature extraction strategy. Different virtual resources have different resource identifiers; Extracting features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information; When the second resource feature information is consistent with the first resource feature information, performing resource transfer based on the at least one virtual resource indicated by the resource transfer request.

2. The method according to claim 1, wherein The method further includes: Determining a target digital certificate indicated by the resource transfer request; Sending the target digital certificate to a certificate registration end. The target digital certificate is used to instruct the certificate registration end to search for a digital certificate that is consistent with the target digital certificate in a certificate repository. The certificate repository also stores object biometric information associated with the digital certificate; When a digital certificate that is consistent with the target digital certificate is found in the certificate repository, obtaining first object biometric information associated with the target digital certificate from the certificate registration end; Collecting second object biometric information of the object that initiated the resource transfer request; When the second object biometric information is consistent with the first object biometric information, performing the step of performing resource transfer based on the at least one virtual resource indicated by the resource transfer request.

3. The method according to claim 2, characterized in that The sending the target digital certificate to the certificate registration end includes: Obtaining an encryption key agreed upon with the certificate registration end; Performing binary conversion on the target digital certificate and the encryption key respectively to obtain binary certificate data and binary key data; Performing a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain certificate encryption data; Sending the certificate encryption data to the certificate registration end. The certificate encryption data is used to instruct the certificate registration end to decrypt the certificate encryption data based on the encryption key to obtain the target digital certificate.

4. The method according to claim 3, wherein The performing a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain certificate encryption data includes: Performing a bitwise exclusive OR operation on the binary certificate data and the binary key data to obtain initial certificate encryption data, where the initial certificate encryption data contains multiple bytes; Obtaining a preset byte pair record table, where the byte pair record table records multiple preset byte pairs, and each byte pair contains two different bytes; For each byte in the initial certificate encryption data, replacing the targeted byte with the byte that forms a byte pair with the targeted byte in the byte pair record table; After each of the multiple bytes included in the initial certificate encryption data is replaced, certificate encryption data is obtained.

5. The method according to claim 1, wherein The resource feature extraction strategy is a hash function. By using the preset resource feature extraction strategy to extract features from at least one virtual resource indicated by the resource transfer request, to obtain second resource feature information, including: Performing a hash operation on at least one virtual resource indicated by the resource transfer request through the preset hash function to obtain hash values corresponding to at least one virtual resource indicated by the resource transfer request; Determining second resource feature information according to the hash values corresponding to at least one virtual resource indicated by the resource transfer request.

6. The method according to any one of claims 1 to 5, characterized in that A resource management chip is provided in the first terminal, and a hardware resource container for storing virtual resources is provided in the resource management chip. The at least one virtual resource to be transferred is determined by the first terminal from the hardware resource container.

7. The method according to any one of claims 1 to 5, characterized in that A resource management application is pre-installed in the first terminal, and a software resource container for storing virtual resources is provided in the resource management application. The at least one virtual resource to be transferred is determined by the first terminal from the software resource container.

8. A resource transfer method, characterized in that, The method includes: Determining at least one virtual resource to be transferred, where different virtual resources have different resource identifiers; Extracting features from the at least one virtual resource to be transferred through a preset resource feature extraction strategy to obtain first resource feature information; Using a preset private key to encrypt the first resource feature information to obtain a digital signature; Obtaining a resource transfer request, where the resource transfer request carries the digital signature and a public key matching the private key; Sending the resource transfer request to a second terminal through a short-range communication method. The resource transfer request is used to instruct the second terminal to determine at least one virtual resource indicated by the resource transfer request, extract features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, resource transfer is performed based on the at least one virtual resource indicated by the resource transfer request.

9. The method according to claim 8, wherein The method further includes: Obtaining a target digital certificate; Sending the target digital certificate to the second terminal. The target digital certificate is used to instruct the second terminal to send the target digital certificate to a certificate registration end, so that the certificate registration end searches for a digital certificate consistent with the target digital certificate from a certificate repository. Object biometric information associated with the digital certificate is also stored in the certificate repository. When a digital certificate consistent with the target digital certificate is found in the certificate repository, the first object biometric information associated with the target digital certificate is sent to the second terminal. Receiving a prompt message sent by the second terminal indicating successful resource transfer, where the prompt message is generated by the second terminal after determining that the second object biometric information is consistent with the first object biometric information and performing resource transfer based on at least one virtual resource indicated by the resource transfer request, and the second object biometric information is biometric information collected by the second terminal for the object initiating the resource transfer request.

10. The method according to claim 9, wherein The obtaining of the target digital certificate includes: Sending a certificate registration request to the certificate registration end, where the certificate registration request is used to instruct the certificate registration end to collect the object biometric information of the object initiating the certificate registration request, and after verifying the collected object biometric information, generating a target digital certificate and associatively storing the target digital certificate and the collected object biometric information in the certificate repository; Receiving the target digital certificate sent by the certificate registration end.

11. The method according to claim 8, wherein The resource feature extraction strategy is a hash function, and the obtaining of the first resource feature information by extracting features from at least one virtual resource to be transferred through a preset resource feature extraction strategy includes: Performing a hash operation on at least one virtual resource to be transferred through the preset hash function to obtain the hash value corresponding to at least one virtual resource to be transferred; Determining the first resource feature information according to the hash value corresponding to at least one virtual resource to be transferred.

12. The method according to any one of claims 8 to 11, characterized in that The private key includes a first key parameter and a second key parameter. The first key parameter is determined based on the product of a preset first prime number and a preset second prime number. The second key parameter is determined based on a quantity parameter and a preset first integer. The quantity parameter is the number of positive integers less than or equal to the first key parameter that are relatively prime to the first key parameter. The first integer is less than the quantity parameter and is relatively prime to the quantity parameter; The encrypting of the first resource feature information using a preset private key to obtain a digital signature includes: Converting the first resource feature information into a second integer, where the second integer is less than the first key parameter; Encrypting the second integer according to the first key parameter and the second key parameter to obtain a digital signature.

13. The method according to claim 12, wherein The first resource feature information is binary feature data represented in binary form, and the binary feature data includes multiple binary bits. The converting of the first resource feature information into a second integer includes: Grouping the multiple binary bits to obtain multiple binary bit combinations; For each binary bit combination, converting the binary bits included in the targeted binary bit combination into a numerical value represented in decimal form to obtain the integer corresponding to the targeted binary bit combination; Concatenating the integers corresponding to the multiple binary bit combinations to obtain a second integer.

14. The method according to claim 12, wherein The encrypting of the second integer according to the first key parameter and the second key parameter to obtain a digital signature includes: Determining a first signature parameter according to the second key parameter and the second integer; Perform a modulo operation on the first signature parameter and the first key parameter to obtain a second signature parameter; Determine a digital signature according to the second signature parameter.

15. A resource transfer device, characterized in that, The device includes: A receiving module, configured to receive a resource transfer request initiated by a first terminal through a short-range communication method; A first determination module, configured to determine a public key, a digital signature, and at least one virtual resource indicated by the resource transfer request. The digital signature is obtained by the first terminal using a private key matching the public key to encrypt first resource feature information. The first resource feature information is obtained by the first terminal, after determining at least one virtual resource to be transferred, through a preset resource feature extraction strategy, based on the resource identifiers of the at least one virtual resource to be transferred. Different virtual resources have different resource identifiers; A first extraction module, configured to extract features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information; A transfer module, configured to, when the second resource feature information is consistent with the first resource feature information, perform resource transfer based on the at least one virtual resource indicated by the resource transfer request.

16. A resource transfer device, characterized in that, The device includes: A second determination module, configured to determine at least one virtual resource to be transferred. Different virtual resources have different resource identifiers; A second extraction module, configured to extract features from the at least one virtual resource to be transferred through a preset resource feature extraction strategy to obtain first resource feature information; An encryption module, configured to encrypt the first resource feature information using a preset private key to obtain a digital signature; An acquisition module, configured to acquire a resource transfer request. The resource transfer request carries the digital signature and a public key matching the private key; A sending module, configured to send the resource transfer request to a second terminal through a short-range communication method. The resource transfer request is used to instruct the second terminal to determine the at least one virtual resource indicated by the resource transfer request, extract features from the at least one virtual resource indicated by the resource transfer request through the preset resource feature extraction strategy to obtain second resource feature information, and use the public key to decrypt the digital signature to obtain the first resource feature information. When the second resource feature information is consistent with the first resource feature information, perform resource transfer based on the at least one virtual resource indicated by the resource transfer request.

17. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 14 are implemented.

18. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 14 are implemented.

19. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 14 are implemented.