Digital voucher payment and signature integration system
Patent Information
- Application Number
- TW115201685
- Authority / Receiving Office
- TW · TW
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2026-02-24
- Publication Date
- 2026-08-11
- Estimated Expiration
- 2036-02-23
Smart Images

Figure TWG2TB001906199_001 
Figure TWG2TB001906199_002 
Figure TWG2TB001906199_003
Abstract
Claims
1. A digital certificate payment and signature integration system, comprising: a user device, including: a payment module for obtaining a rights certificate through an electronic payment process; and a storage module connected to the payment module for storing the rights certificate; wherein the user device logs into a member website through an input interface to generate member information and generates a registration request based on the member information; and a backend server connected to the input interface, receives the registration request, generates a binding challenge request based on the registration request, and encapsulates and transmits the binding challenge request and the member website to the input interface; A first hardware security identity recognition module is connected to the user device. After receiving the binding challenge request through the input interface, the first hardware security identity recognition module verifies the user's identity on the user device. Upon successful verification, it generates a public key and a corresponding private key. It then uses the private key to sign the public key and the member information to generate an authentication statement message. Based on the authentication statement message, the public key, and a digital identifier, it generates a public key certificate and transmits the public key certificate to the backend server for verification, thereby verifying the device credential of the user device. After successful verification on the backend server, it binds and stores the public key and the member information. The member information is generated using the digital identifier. The user device senses a server device through the rights certificate. The server device generates and transmits redemption information to the backend server based on the rights certificate. After verifying the redemption information, the backend server generates a verification success message to the server device, causing the server device to generate a redemption result.
2. The digital credential payment signature integration system as described in claim 1, wherein the backend server generates and transmits a redemption challenge response request to the user device based on the redemption information, enabling the user device to verify the user's identity; wherein after the user device passes the user identity verification, the first hardware security identity recognition module uses the private key to perform a user digital signature on the redemption challenge response request to generate a signature response message, and transmits the signature response message to the backend server through the user device, whereby the backend server uses the public key to verify the signature response message, and generates a verification success message to the server device after successful verification.
3. The digital credential payment signature integration system as described in claim 2, wherein the backend server comprises: a business logic module that receives the redemption information and generates a redemption challenge response request containing a transaction detail, a timestamp, and a random number based on the redemption information; and a security module connected to the business logic module, comprising a multi-factor authentication engine that generates a multi-factor authentication message to the user device based on the redemption information, enabling the user device to perform multi-factor authentication based on the user's identity.
4. The digital credential payment and signature integration system as described in claim 3, wherein the multi-factor authentication includes at least one of a password authentication, a fingerprint authentication, a facial recognition authentication, and a network identity recognition standard authentication; wherein the password authentication includes a fixed password authentication and a dynamic password authentication.
5. The digital credential payment and signature integration system as described in claim 1, wherein when the first hardware security identity module is connected to the user device, the input interface invokes a web standard, enabling an operating system of the user device to recognize the first hardware security identity module and transmit the binding challenge request to the first hardware security identity module through a client-to-authenticator protocol; wherein the web standard includes a WebAuthn web standard.
6. The digital credential payment and signature integration system as described in claim 1 further includes a second hardware security identity recognition module, which is located at a remote end and connected to the backend server to store the private key. The user device connects to the hardware security identity recognition module through the backend server to access the private key in the second hardware security identity recognition module.
7. The digital credential payment signature integration system as described in claim 1, wherein the user device transmits a private key unlocking request to the first hardware security identity module to obtain access to the private key stored in the first hardware security identity module.
8. The digital credential payment signature integration system as described in claim 7, wherein the first hardware security identity recognition module is located at a near end and connected to the user device via a port; wherein the first hardware security identity recognition module includes a roaming authenticator and uses a client-to-authenticator protocol to connect to the input interface of the user device to receive the public key credential and the signature response message.
9. The digital credential payment signature integration system as described in claim 8, wherein the hardware security identity module uses a discoverable credential to store the private key and the membership information.
10. The digital credential payment signature integration system as described in claim 9, wherein the first hardware security identity recognition module uses the private key to generate an authentication statement message.
11. The digital credential payment signature integration system as described in claim 1, wherein the first hardware security identity module generates the public key and the private key by means of a true random number generator.
12. The digital credential payment signature integration system as described in claim 2, wherein the first hardware security identity recognition module further includes a counter that monotonically increments to count the number of times the user's digital signature is generated.
13. The digital credential payment signature integration system as described in claim 1, wherein the user device includes a smartphone with a hardware security element.
14. The digital credential payment signature integration system as described in claim 1, wherein the private key is stored in the hardware security identity recognition module.
15. The digital credential payment signature integration system as described in claim 1, wherein the public key is stored in the backend server.
16. The digital credential payment signature integration system as described in claim 1, wherein the input interface includes a web browser, a user interface program, and an application.
17. The digital credential payment signature integration system as described in claim 6, wherein the back-end server forms an electronic receipt by combining a transaction record with a network identity standard assertion digest, and requests the second hardware security identity module to sign the electronic receipt using an internally stored institutional credential private key.