A data interaction method, device and related equipment

Through distributed identity technology and a verifiable credential circulation model, user terminals interact directly with the transaction system, solving the problem of user information being collected by third parties and achieving privacy protection and secure transactions.

CN114119024BActive Publication Date: 2026-03-24ZHONGCHAO CREDIT CARD IND DEV CO LTD HANGZHOU BLOCKCHAIN TECH RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-07
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, user information can easily be collected in large quantities by third parties, leading to privacy leaks and security risks. Traditional APP e-commerce platforms cannot effectively protect user privacy.

Method used

By employing distributed identity technology and a user identity wallet and verifiable credential circulation model, direct interaction between user terminals and the transaction system is achieved, avoiding the storage of user information on the supply terminal and utilizing the transaction system to complete identity verification and transaction authorization.

Benefits of technology

It effectively prevents user information from being collected by third-party platforms, protects user privacy, simplifies transaction processes, enhances information security, and supports a user-centric service model and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114119024B_ABST
    Figure CN114119024B_ABST
Patent Text Reader

Abstract

The application discloses a data interaction method, comprising: a user terminal initiates a transaction request to a supply terminal, and receives an order voucher fed back by the supply terminal according to the transaction request; an encryption operation is performed based on the order voucher and a user identity account voucher to construct a transaction authorization request voucher; the transaction authorization request voucher is sent to a transaction system, so that the transaction system issues a transaction authorization voucher according to a transaction authorization processing result corresponding to the transaction authorization request voucher after verifying the transaction authorization request voucher, and feeds back a verification result of the transaction authorization voucher to the supply terminal when receiving a transaction authorization voucher verification result request sent by the supply terminal. The technical scheme provided by the application can effectively avoid the mass collection of user information by a third party, thereby protecting user privacy and ensuring the security of user information. The application also discloses a data interaction device, equipment and computer readable storage medium, which have the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network transaction, in particular to a data interaction method, and relates to a data interaction device, equipment and computer readable storage medium. BACKGROUND

[0002] WEB payment is an electronic payment method relying on network, with real-time and zero distance as typical characteristics. The payment network includes payment network, card issuing bank, acquirer, and merchant. The payment network undertakes the function of fund clearing and settlement among the merchant, acquirer and card issuing bank; the card issuing bank and acquirer are responsible for fund transfer; and the merchant is a commodity trading party with creditor's right, which can initiate payment instructions according to the transaction. Generally, the merchant provides multiple payment methods (integrates the payment gateway of each bank) for the convenience of payment, and transmits the payment instruction to the corresponding bank payment gateway during the transaction, and then completes the related business of payment through the bank background facility to ensure the safety of payment, such as WeChat payment, Alipay, and cloud flash payment.

[0003] However, as a purchaser and payer, the user usually does not want his / her purchase behavior or account information to be collected and aggregated by irrelevant third parties in an unknowing manner. Although the traditional APP e-commerce platform can provide a good user purchase and smooth payment experience, the user must provide his / her payment account information to the third party irrelevant to payment, and the platform has a large amount of personal transaction track and payment account information, which not only easily causes data concentration monopoly, but also has potential security risks.

[0004] Therefore, how to effectively avoid mass collection of user information by third parties, protect user privacy and ensure user information security is a problem to be solved by those skilled in the art. SUMMARY

[0005] The purpose of the present application is to provide a data interaction method which can effectively avoid mass collection of user information by third parties, thereby protecting user privacy and ensuring user information security. Another purpose of the present application is to provide a data interaction device, equipment and computer readable storage medium, all of which have the above-mentioned beneficial effects.

[0006] In a first aspect, the present application provides a data interaction method, comprising:

[0007] The user terminal initiates a transaction request to the supply terminal, and receives an order voucher fed back by the supply terminal according to the transaction request;

[0008] Performing an encryption operation based on the order voucher and the user identity account voucher to construct a transaction authorization request credential;

[0009] sending the transaction authorization request credential to a transaction system, so that the transaction system issues a transaction authorization voucher according to a transaction authorization processing result corresponding to the transaction authorization request credential after the transaction authorization request credential is verified, and feeds back a verification result of the transaction authorization voucher to the supply terminal when receiving a transaction authorization voucher verification result request sent by the supply terminal.

[0010] Preferably, before the transaction authorization request credential is constructed based on the order voucher and the user identity account credential through the encryption operation, the method further comprises:

[0011] verifying the order voucher by using a public key registered by the supply terminal on an identity registration table, and performing the step of constructing the transaction authorization request credential based on the order voucher and the user identity account credential through the encryption operation after the verification is passed.

[0012] Preferably, the user terminal is deployed with a user identity wallet, and the user identity account credential is stored in the user identity wallet. The transaction authorization request credential is constructed based on the order voucher and the user identity account credential through the encryption operation, comprising:

[0013] obtaining the transaction authorization request credential by performing the encryption operation on the order voucher and the user identity account credential through the user identity wallet.

[0014] Preferably, the transaction system comprises an account opening server, and the method further comprises:

[0015] sending a KYC registration request carrying user registration information to the account opening server, so that the account opening server issues the user identity account credential according to the KYC registration request, and saves the user registration information; wherein the user registration information comprises a user ID and a user public key.

[0016] receiving the user identity account credential fed back by the account opening server.

[0017] storing the user identity account credential in the user identity wallet.

[0018] Preferably, the transaction system verifies the transaction authorization request credential, comprising:

[0019] verifying the transaction authorization request credential by using the user registration information through the account opening server.

[0020] Preferably, the transaction system comprises a voucher center server, and after the transaction authorization voucher is issued according to the transaction authorization processing result corresponding to the transaction authorization request credential, the method further comprises:

[0021] store the transaction authorization credential to the credential center server.

[0022] Preferably, the transaction system further comprises a transaction processing server, which feeds back a verification result of the transaction authorization credential to the supply terminal upon receiving a transaction authorization credential verification result request sent by the supply terminal, comprising:

[0023] receiving the transaction authorization credential verification result request sent by the supply terminal through the transaction processing server;

[0024] requesting a transaction authorization credential proof corresponding to the transaction authorization credential from the credential center server according to the transaction authorization credential verification result request;

[0025] verifying the transaction authorization credential proof through the transaction processing server when the transaction authorization credential proof is obtained from the credential center server, and feeding back the verification result of the transaction authorization credential to the supply terminal after verification.

[0026] In a second aspect, the present application further discloses a data interaction device, comprising:

[0027] an order credential obtaining module, configured to initiate a transaction request by a user terminal to a supply terminal, and receive an order credential fed back by the supply terminal according to the transaction request;

[0028] a transaction authorization request credential issuing module, configured to perform an encryption operation based on the order credential and a user identity account credential, and construct a transaction authorization request credential;

[0029] a transaction authorization module, configured to send the transaction authorization request credential to a transaction system, so that the transaction system issues a transaction authorization credential according to a transaction authorization processing result corresponding to the transaction authorization request credential after verifying the transaction authorization request credential, and feeds back a verification result of the transaction authorization credential to the supply terminal upon receiving a transaction authorization credential verification result request sent by the supply terminal.

[0030] In a third aspect, the present application further discloses a data interaction device, comprising:

[0031] a memory, configured to store a computer program;

[0032] a processor, configured to execute the computer program to realize steps of any one of the data interaction methods.

[0033] In a fourth aspect, the present application also discloses a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of any of the above data interaction methods.

[0034] The data interaction method provided by the present application comprises the following steps: a user terminal initiates a transaction request to a supply terminal and receives an order voucher fed back by the supply terminal according to the transaction request; an encryption operation is performed based on the order voucher and a user identity account voucher to construct a transaction authorization request voucher; the transaction authorization request voucher is sent to a transaction system, so that the transaction system issues a transaction authorization voucher according to a transaction authorization processing result corresponding to the transaction authorization request voucher after the transaction authorization request voucher is verified, and feeds back a verification result of the transaction authorization voucher to the supply terminal when receiving a transaction authorization voucher verification result request sent by the supply terminal

[0035] The application of the technical solution provided by the present application is that when the user terminal and the supply terminal perform data transaction, the user terminal only needs to initiate a transaction request to the supply terminal, obtain the order voucher fed back by the supply terminal, perform an encryption operation on the order voucher and the user identity account voucher, construct a transaction authorization request voucher, and then send the transaction authorization request voucher to the transaction system. For the transaction system, a transaction authorization voucher can be issued according to a transaction authorization processing result corresponding to the transaction authorization request voucher after the transaction authorization request voucher is verified, and the data transaction is completed. For the supply terminal, the final transaction result can be obtained by sending a transaction authorization voucher verification result request to the transaction system. Obviously, the user terminal does not need to register an account and store information with the supply terminal, but the identity of the user terminal and the transaction information are verified by the transaction system, and then the data transaction between the user terminal and the supply terminal is completed, which can effectively avoid the collection of user information by a third-party platform, effectively protect the privacy of the user, and ensure the security of the user information.

[0036] The data interaction device, the apparatus and the computer readable storage medium provided by the present application all have the above beneficial effects, which will not be described here. BRIEF DESCRIPTION OF DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the prior art and the embodiments of the present application, the drawings used in the description of the prior art and the embodiments of the present application will be briefly introduced. Of course, the drawings related to the embodiments of the present application described below are only a part of the embodiments of the present application, and those skilled in the art can obtain other drawings according to the provided drawings without any creative effort, and the obtained drawings also belong to the protection scope of the present application.

[0038] Figure 1A flowchart of a data interaction method provided in the present application;

[0039] Figure 2 A flowchart of a transfer of verifiable credentials in network payment provided in the present application;

[0040] Figure 3 A flowchart of a transaction confirmation provided in the present application;

[0041] Figure 4 A flowchart of a user identity account credential issuance provided in the present application;

[0042] Figure 5 A flowchart of a request payment authorization provided in the present application;

[0043] Figure 6 A flowchart of a payment authorization credential issuance provided in the present application;

[0044] Figure 7 A flowchart of a payment authorization credential acquisition by a merchant system provided in the present application;

[0045] Figure 8 A flowchart of a data interaction in a data interaction system provided in the present application;

[0046] Figure 9 A structural diagram of a data interaction apparatus provided in the present application;

[0047] Figure 10 A structural diagram of a data interaction device provided in the present application. DETAILED DESCRIPTION

[0048] The core of the present application is to provide a data interaction method, which can effectively avoid mass collection of user information by third parties, thereby protecting user privacy and ensuring user information security. Another core of the present application is to provide a data interaction apparatus, device and computer readable storage medium, which also have the above beneficial effects.

[0049] In order to more clearly and completely describe the technical solutions in the embodiments of the present application, the technical solutions in the embodiments of the present application will be introduced below in conjunction with the drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0050] The present application provides a data interaction method.

[0051] Please refer toFigure 1 , Figure 1 A flowchart of a data interaction method provided in the present application, which can include:

[0052] S101: The user terminal initiates a transaction request to the supply terminal, and receives an order voucher fed back by the supply terminal according to the transaction request;

[0053] This step aims to realize the acquisition of the order voucher through the interaction between the user terminal and the supply terminal. Specifically, the user terminal can initiate a transaction request to the supply terminal after determining the transaction, which can be a payment request. For example, the user can initiate a payment request to the supply terminal after determining the goods to be purchased through the user terminal, and the supply terminal is the party that supplies (sells) the goods. For the supply terminal, it can generate an order voucher based on the transaction request after receiving the transaction request sent by the user terminal, which can include order number, merchant number, merchant payment account number, order total amount and other information, and then feed back the order voucher to the user terminal to make the user terminal perform payment and other transaction operations based on the order voucher.

[0054] S102: Perform encryption operation based on the order voucher and the user identity account voucher to construct a transaction authorization request credential;

[0055] This step aims to construct a transaction authorization request credential. Specifically, the user terminal can perform encryption operation based on the order voucher and the user identity account voucher to construct a transaction authorization request credential after receiving the order voucher fed back by the supply terminal, which includes user identity information and order voucher, and is used to request transaction authorization from the transaction system in order to complete data interaction with the supply terminal. The encryption process can adopt any implementation manner in the prior art, which will not be described herein.

[0056] It can be understood that the encryption operation processing based on the order voucher and the user identity account voucher can effectively ensure the security of data information in the transmission process, and can be used to indicate the transaction system to perform legality verification on the received data information before issuing the transaction authorization voucher, further ensuring the legality of the user terminal and the security of the transaction data.

[0057] S103: Send the transaction authorization request credential to the transaction system, so that the transaction system issues a transaction authorization voucher according to the transaction authorization processing result corresponding to the transaction authorization request credential after passing the verification of the transaction authorization request credential, and feeds back the verification result of the transaction authorization voucher to the supply terminal when receiving the transaction authorization voucher verification result request sent by the supply terminal.

[0058] The step is designed to send the transaction authorization request credential to the transaction system, so that the transaction system issues the transaction authorization credential, thereby completing the data interaction between the user terminal and the transaction system. Specifically, after the user terminal completes the encryption operation process based on the order credential and the user identity account credential, it can send the constructed transaction authorization request credential to the transaction system. Further, after the transaction system receives the transaction authorization request credential, it can first verify it. After verification, the transaction authorization credential can be issued according to the transaction authorization processing result corresponding to the transaction authorization request credential, thereby completing the data interaction between the user terminal and the transaction system. Finally, for the supply terminal, the verification result of the transaction authorization credential feedback by the transaction system can be obtained by sending a transaction authorization credential verification result request to the transaction system, that is, the verified transaction result between the user terminal and the supply terminal can be obtained.

[0059] It can be seen that the data interaction method provided in the present application, when the user terminal and the supply terminal perform data transaction, the user terminal only needs to initiate a transaction request to the supply terminal, obtain the order credential feedback by the supply terminal, and then perform encryption operation on the order credential and the user identity account credential. After constructing the transaction authorization request credential, the transaction authorization request credential is sent to the transaction system. For the transaction system, the transaction authorization credential can be issued by using the transaction authorization processing result corresponding to the transaction authorization request credential after the transaction authorization request credential is verified. The data transaction is completed. For the supply terminal, the final transaction result can be obtained by sending a transaction authorization credential verification result request to the transaction system. Obviously, the user terminal does not need to register an account and store information with the supply terminal, but the transaction system directly verifies the identity of the user terminal and the transaction information, thereby completing the data transaction between the user terminal and the supply terminal, which can effectively avoid the collection of user information by third-party platforms, effectively protect user privacy and ensure user information security.

[0060] In an embodiment of the present application, before the encryption operation based on the order credential and the user identity account credential is performed, the order credential is verified by using the public key registered by the supply terminal on the identity registration table, and after the verification is passed, the steps of performing encryption operation based on the order credential and the user identity account credential and constructing the transaction authorization request credential.

[0061] In the embodiment of the present application, after receiving the order voucher fed back by the supply terminal, the user terminal can first verify the order voucher before performing the encryption operation based on the order voucher and the user identity account voucher, so as to effectively ensure the authenticity of the source of the order voucher. Specifically, before feeding the order voucher to the user terminal, the supply terminal can first perform signature processing on the order voucher by using a private key, and then feed the signed order voucher to the user terminal; after receiving the order voucher, the user terminal can verify it by using the public key corresponding to the private key, and sign it by using the user identity information after the verification is passed. The public key corresponding to the private key is registered on the identity registration table by the supply terminal, and the user terminal can directly obtain the public key from the identity registration table.

[0062] In an embodiment of the present application, the user terminal is deployed with a user identity wallet, and the user identity account voucher is stored in the user identity wallet. The encryption operation based on the order voucher and the user identity account voucher and the construction of the transaction authorization request voucher can include: performing the encryption operation on the order voucher and the user identity account voucher by the user identity wallet to obtain the transaction authorization request voucher.

[0063] In the embodiment of the present application, the user terminal can be deployed with a user identity wallet, the data management of the corresponding user can be realized by the user identity wallet, and the user identity account voucher is stored in the user wallet. Based on this, the operation of performing the encryption operation based on the order voucher and the user identity account voucher by the user terminal can be executed by the user identity wallet. In addition, based on the user identity wallet, the above-mentioned verification operation, storage operation and encryption operation on the order voucher can also be realized.

[0064] In an embodiment of the present application, the transaction system includes an account opening server, and the data interaction method can further include: sending a KYC (Know Your Customer, a real-name authentication mechanism) registration request carrying user registration information to the account opening server, so that the account opening server issues a user identity account voucher according to the KYC registration request, and saves the user registration information; wherein the user registration information includes a user ID and a user public key; receiving the user identity account voucher fed back by the account opening server; storing the user identity account voucher in the user identity wallet.

[0065] In the embodiment of the present application, an implementation method is provided for a user terminal to register identity with an account opening server of a transaction system and obtain a user identity account credential. Specifically, an account opening server can be deployed in the transaction system to provide account opening and card opening services for the user terminal. Based on this, the user terminal can send a KYC registration request to the account opening server, the request containing corresponding user registration information. Further, the account opening server can issue a user identity account credential for the user terminal based on the request after receiving the KYC registration request, and obtain the user registration information in the request through request parsing, wherein the user registration information includes a user ID and a user public key. Further, the user registration information is saved for subsequent user identity account credential verification. Finally, the user terminal can store the user identity account credential issued by the account opening server in its own user identity wallet for subsequent implementation of transaction authorization request credential acquisition.

[0066] In an embodiment of the present application, the transaction system can verify the transaction authorization request credential, which can include verifying the transaction authorization request credential by the account opening server using the user registration information.

[0067] As described above, the account opening server can save the user registration information in the KYC registration request for subsequent user identity account credential verification. Therefore, when the transaction system verifies the transaction authorization request credential sent by the user terminal, the account opening server can verify the transaction authorization request credential using the user registration information stored by itself, which is the user information registered by the user terminal when opening an account and card in the account opening server, i.e., the user registration information under the KYC authentication mechanism.

[0068] In an embodiment of the present application, the transaction system includes a credential center server, and after issuing a transaction authorization credential according to the transaction authorization processing result corresponding to the transaction authorization request credential, the transaction system can further include storing the transaction authorization credential in the credential center server.

[0069] In the embodiment of the present application, the credential center server can be deployed in the transaction system, and the credential center server can be used to store the transaction authorization credential for subsequent supply terminal request acquisition.

[0070] In an embodiment of the present application, the transaction system further comprises a transaction processing server, which feeds back the verification result of the transaction authorization credential to the supply terminal upon receiving the transaction authorization credential verification result request sent by the supply terminal, which can comprise: receiving the transaction authorization credential verification result request sent by the supply terminal through the transaction processing server; requesting the transaction authorization credential proof corresponding to the transaction authorization credential from the credential center server according to the transaction authorization credential verification result request; verifying the transaction authorization credential proof through the transaction processing server when the transaction authorization credential proof presented by the credential center server is obtained, and feeding back the verification result of the transaction authorization credential to the supply terminal after verification.

[0071] In the embodiments of the present application, a transaction processing server can also be deployed in the transaction system, which is used to realize data interaction between the transaction system and the supply terminal. Specifically, after the supply terminal feeds back the order credential to the user terminal, it can initiate a transaction authorization credential verification result request to the transaction processing server of the transaction system to request the transaction result between the supply terminal and the user terminal; further, the transaction processing server can forward the transaction authorization credential verification result request to the credential center server to request the credential center server to present the transaction authorization credential proof corresponding to the transaction authorization credential, and verify the transaction authorization credential proof, and when the verification is passed, the verification result of the transaction authorization credential proof can be fed back to the supply terminal, so that the supply terminal can obtain the transaction result between the supply terminal and the user terminal, and the data interaction between the user terminal and the supply terminal is realized through the transaction system.

[0072] The verification process of the transaction authorization credential proof by the transaction processing server can be realized by VC-AuthN-OIDC (a kind of information verification method). VC-AuthN-OIDC is a standardized definition relying on OIDC (OpenId Connect, identity authentication) and is an extension of OIDC, which provides a new method for users to authenticate using verifiable credentials. This method eliminates the dependence on any single Open ID provider, transfers more control to the user, enhances privacy and simplifies the user experience, and relies on token information to determine subsequent authorization operations without collecting and saving user information unrelated to business.

[0073] Based on the above embodiments, another data interaction method is provided in the embodiments of the present application.

[0074] The data interaction method provided in the embodiments of the present application adopts distributed identity technology, takes the user as the center, and realizes the interaction between the merchant system and the user, the user and the card issuing bank (opening bank), and the payment processing system and the merchant system based on the verifiable credential circulation model. The specific implementation process is as follows:

[0075] Reference Figure 2 , Figure 2 A network payment verifiable credential flow diagram provided by the present application, the core of the scheme is DID (Decentralized Identifier, Distributed Digital Identity Identifier) credential flow, and the credential information interaction is realized through point-to-point DID communication. According to the roles in the payment ecology and the relationship between them, the payment system can be disassembled into multiple point-to-point message units. The following is explained according to the merchant system (payee, i.e. the above-mentioned supply terminal) and the user (payer, i.e. the above-mentioned user terminal), the user and the card issuing bank (opening bank, i.e. the above-mentioned opening service terminal), the payment processing system (payment processing service terminal) and the merchant system.

[0076] 1. Merchant system and user:

[0077] Reference Figure 3 , Figure 3 A transaction confirmation process diagram provided by the present application. In a user-centered transaction scenario, user data is controlled by the user himself, and the user's bank account information and other private data are controlled by the user's identity wallet. There is no need for the user to register and save on the merchant system, reducing the collection of user information by the merchant system. The user and the merchant system can communicate through a proxy-based DID message channel. In the case of user confirmation of payment, the merchant system can directly send the signed order credentials to the user. The credentials should include order number, merchant number, merchant payment account number, order total amount (including shipping) and other information. The user can verify the order credentials through the public key registered by the merchant system on the identity registry to ensure the authenticity of the order source. At the same time, the stored order credentials are used for subsequent payment request initiation and after-sales order service traceability.

[0078] 2. User and card issuing bank:

[0079] In order to initiate a payment request related to purchase, the user needs to prove his legal identity as a payer to the card issuing bank and provide the corresponding transaction confirmation. In the case of requiring to cooperate with the purchase background investigation, it also needs to consider submitting the order credentials that meet the requirements of the payment business.

[0080] Based on this, in order to realize the transaction confirmation related payment request, the user can perform anonymous credential processing on the received order credentials to obtain payment authorization request credentials including payment account, payee account and transfer amount, and submit them to the card issuing bank. Since the user and the card issuing bank have implemented KYC registration in advance, they maintain their payment account credentials in the form of public key, so the user can sign the order credentials with the user's identity information, so that the card issuing bank can verify it, Figure 4As shown is a user identity account credential issuing process schematic diagram provided by the present application, which has high security and anti-fraud effect.

[0081] Referring to Figure 5 , Figure 5 As shown is a payment authorization request process schematic diagram provided by the present application, a user can construct a payment authorization request credential based on an identity wallet, and send it to an issuing bank through DID communication, which is verified by the issuing bank and processed.

[0082] 3. Payment processing system and merchant system:

[0083] Referring to Figure 6 and Figure 7 , Figure 6 As shown is a payment authorization credential issuing process schematic diagram provided by the present application, Figure 7 As shown is a merchant system payment authorization credential obtaining process schematic diagram provided by the present application. After receiving the user's payment authorization request, the issuing bank will verify the payment authorization request credential submitted by the user, confirm that the order payment request is indeed initiated by the user and the user is a KYC user, and if the account fund status meets the needs, the payment authorization credential can be issued (in the case of PUSH payment (bank-initiated transaction), the payment authorization credential can also be issued as a completed payment behavior). Here, the merchant system needs to obtain the payment authorization result, but since the subject of the payment authorization credential is not the merchant system, the payment authorization credential will not be sent to the merchant system, but will be stored in the credential center of the payment system. The merchant system can request verification and present the payment authorization credential verification status information to the credential center through the identity authentication service of the payment processing system to obtain the user's payment result.

[0084] Based on Figures 3 to 7 As shown in each process schematic diagram, the overall system data transaction process schematic diagram can be obtained, as shown in Figure 8 , Figure 8 As shown is a data interaction process schematic diagram in a data interaction system provided by the present application.

[0085] As can be seen, the data interaction method provided by the present application has the following advantages:

[0086] (1) Support user-centered service mode:

[0087] With distributed identity technology, a user-centric service model can be achieved, whether it is e-commerce or payment transfer, which is embodied as direct interaction between service providers and their service subjects, without the need to indirectly achieve through another system. For example, after the user confirms the shopping cart information and initiates payment, the payment service will be directly between the buyer (payer) and the payment service provider, and the payment service provider can directly communicate with the service subject to obtain further customer information and provide corresponding personalized payment solutions (such as discounts).

[0088] (2) Simplify business processes:

[0089] Because distributed identity supports point-to-point decentralized secure communication, the business process in traditional network payment can be greatly simplified. In this scheme, the personal order is directly submitted to the payment processing party (card issuer or account opening bank) in the form of a payment authorization request after being confirmed (signed) by the purchaser himself, and the payment processing party verifies the authenticity of the order source and the account status of the requester to decide to proceed with the payment authorization process, which does not need to be submitted to the payer's card issuer through the merchant's acquirer processing system. Similarly, the verifiable voucher circulation model based on distributed identity can also simplify the PULL (bank-initiated transaction) fund circulation steps: the merchant does not need to pass the customer's card issuer authorization payment to trigger the fund circulation, and the merchant acquirer system can automatically query the authorized payment voucher registry, verify the voucher, and complete the fund collection.

[0090] (3) Realize data regression to the owner:

[0091] Users can manage their own data through identity wallets and decide whether to provide it to related transaction parties during the transaction process, which realizes the separation of user data and services, data regression to the owner, and effective protection of user identity privacy. In the online purchase and payment process, it may be reflected in the user providing his own age proof to the merchant through the identity wallet instead of presenting an identity card, and the user providing his own payment account voucher and order payment amount information to the payment service provider through the identity wallet instead of the order details.

[0092] (4) Support privacy protection and behavior cannot be aggregated:

[0093] Distributed identity is composed of ID and voucher, the ID layer supports machine trust, responsible for establishing a secure channel for both parties, and the voucher layer realizes the additional description of identity attributes. ID and voucher can be decoupled and recombined, and the minimum disclosure of identity can also be easily realized according to the needs to support privacy protection. With distributed identity technology, the identity of the user entity is independently expressed in different scenarios as the role of the user entity, and because different public key infrastructures are used, different service providers in different scenarios cannot achieve the aggregation of user behavior through joint implementation.

[0094] (5) Support data trusted flow:

[0095] In addition to the identity data of the user, the behavior data generated by the user in the digital system can be returned to the user, and then forwarded by the user based on the signed identity after switching, so as to realize the flow of trusted data, thereby supporting the needs of distributed business cooperation. In order to ensure the authenticity of the data source and the authenticity of the data owner, the DIDComm protocol (Decentralized Identifier Communication Protocol) based on DPKI (Decentralized Public Key Infrastructure) and the cryptographic operation based on verifiable credentials can be used for processing.

[0096] (6) Support flexible scalability:

[0097] Distributed is an organizational approach that has its own development space compared to centralized. Whether it is life or intelligence, it shows rich diversity and builds the strength of the group through distribution. A large number of small unit systems can be easily accessed in the existing distributed system at any time. For a distributed identity system, as long as each entity communicates with a standardized protocol through a standardized proxy software and transmits standardized credential data, it can be accessed in the existing distributed system at any time, and the business handled by the distributed system is realized by a custom message protocol.

[0098] The application also provides a data interaction device, please refer to Figure 9 , Figure 9 The structure diagram of the data interaction device provided by the application can include:

[0099] The order certificate acquisition module 1 is configured to initiate a transaction request from the user terminal to the supply terminal, and receive the order certificate fed back by the supply terminal according to the transaction request;

[0100] The transaction authorization request credential issuing module 2 is configured to perform an encryption operation based on the order certificate and the user identity account certificate, and construct a transaction authorization request credential;

[0101] The transaction authorization module 3 is configured to send the transaction authorization request credential to the transaction system, so that the transaction system issues a transaction authorization certificate according to the transaction authorization processing result corresponding to the transaction authorization request credential after verifying the transaction authorization request credential, and feeds back the verification result of the transaction authorization certificate to the supply terminal when receiving the transaction authorization certificate verification result request sent by the supply terminal.

[0102] As can be seen, the data interaction device provided in this application embodiment allows the user terminal to initiate a transaction request to the supply terminal when conducting data transactions with the supply terminal. The user terminal obtains the order voucher from the supply terminal, performs encryption calculations on the voucher and the user's identity account voucher, constructs a transaction authorization request credential, and sends it to the transaction system. The transaction system, after verifying the transaction authorization request credential, issues a transaction authorization credential using the transaction authorization processing result corresponding to the credential, thus completing the data transaction. The supply terminal obtains the final transaction result by sending a transaction authorization credential verification result request to the transaction system. Clearly, the user terminal does not need to register an account or store information with the supply terminal; instead, the transaction system directly verifies the user terminal's identity and transaction information, thereby completing the data transaction between the user terminal and the supply terminal. This effectively prevents user information from being collected by third-party platforms, effectively protecting user privacy and ensuring user information security.

[0103] In a preferred embodiment, the data interaction device may further include an order credential verification module, which is used to verify the order credential using the public key registered on the identity registry by the supply terminal before performing encryption operations based on the order credential and the user identity account credential to construct the transaction authorization request credential. After the verification is successful, the step of performing encryption operations based on the order credential and the user identity account credential to construct the transaction authorization request credential is executed.

[0104] In a preferred embodiment, the user terminal is equipped with a user identity wallet, and the user identity account credentials are stored in the user identity wallet. In this case, the transaction authorization request credential issuance module 2 can be specifically used to perform encryption operations on the order credentials and user identity account credentials through the user identity wallet to obtain the transaction authorization request credential.

[0105] In a preferred embodiment, the trading system includes an account opening server. The data interaction device may further include a registration module for sending a KYC registration request carrying user registration information to the account opening server, so that the account opening server issues a user identity account credential based on the KYC registration request and saves the user registration information; wherein, the user registration information includes a user ID and a user public key; receiving the user identity account credential fed back by the account opening server; and storing the user identity account credential in the user identity wallet.

[0106] For a description of the device provided in this application, please refer to the above method embodiments; further details will not be provided here.

[0107] This application also provides a data interaction device, please refer to... Figure 10 , Figure 10 This application provides a schematic diagram of the structure of a data interaction device, which may include:

[0108] a memory for storing the computer program;

[0109] a processor for implementing the steps of any one of the above data interaction methods when executing the computer program.

[0110] As shown in Figure 10 FIG. 1 is a schematic diagram of a composition structure of a data interaction device. The data interaction device can include a processor 10, a memory 11, a communication interface 12, and a communication bus 13. The processor 10, the memory 11, and the communication interface 12 can complete mutual communication through the communication bus 13.

[0111] In the embodiments of the present application, the processor 10 can be a central processing unit (CPU), an application specific integrated circuit, a digital signal processor, a field programmable gate array, or other programmable logic devices, etc.

[0112] The processor 10 can invoke a program stored in the memory 11. Specifically, the processor 10 can execute the operations in the embodiments of the data interaction method.

[0113] The memory 11 is used to store one or more programs. The program can include program code, and the program code includes computer operation instructions. In the embodiments of the present application, the memory 11 at least stores a program for implementing the following functions:

[0114] The user terminal initiates a transaction request to the supply terminal, and receives an order voucher fed back by the supply terminal according to the transaction request;

[0115] Based on the order voucher and the user identity account voucher, an encryption operation is performed to construct a transaction authorization request credential;

[0116] The transaction authorization request credential is sent to a transaction system, so that the transaction system issues a transaction authorization voucher according to a transaction authorization processing result corresponding to the transaction authorization request credential after verifying the transaction authorization request credential, and feeds back a verification result of the transaction authorization voucher to the supply terminal when receiving a transaction authorization voucher verification result request sent by the supply terminal.

[0117] In a possible implementation manner, the memory 11 can include a program storage area and a data storage area. The program storage area can store an operating system and at least one application program required by a function, etc. The data storage area can store data created in a use process.

[0118] In addition, the memory 11 can include a high-speed random access memory, and can also include a non-volatile memory, for example, at least one magnetic disk storage device or other volatile solid-state storage device.

[0119] The communication interface 12 can be an interface of a communication module, used for connecting with other devices or systems.

[0120] Of course, it should be noted that, Figure 10 The structure shown does not constitute a limitation on the data interaction device in the embodiments of the present application, and in actual applications, the data interaction device can include more or fewer components than Figure 10 those shown, or combine certain components.

[0121] The present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of any one of the above data interaction methods.

[0122] The computer readable storage medium can include a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0123] For the computer readable storage medium provided by the present application, please refer to the above method embodiments, which will not be described here.

[0124] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method part.

[0125] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of the two. In order to clearly show the interchangeability of hardware and software, the components and steps of each example have been described in the above description. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0126] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in random access memory (RAM), flash memory, read-only memory (ROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, hard disk can be used for tangibly embodying the software module.

[0127] The technical solutions provided by the present application are described above. The principles and implementation manners of the present application are described by using specific examples in the present document. The above description of the embodiments is only used to help understand the method of the present application and its core idea. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, some improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A data interaction method, characterized in that, include: The user terminal initiates a transaction request to the supply terminal and receives the order voucher from the supply terminal in response to the transaction request; Based on the order voucher and user identity account voucher, perform encryption operations to construct a transaction authorization request credential; The transaction authorization request credential is sent to the transaction system so that after the transaction authorization request credential is verified, the transaction system issues a transaction authorization certificate according to the transaction authorization processing result corresponding to the transaction authorization request credential, and when it receives the transaction authorization certificate verification result request sent by the supply terminal, it feeds back the verification result of the transaction authorization certificate to the supply terminal. The user terminal is equipped with a user identity wallet, and the user identity account credential is stored in the user identity wallet. The step of constructing a transaction authorization request credential based on the order credential and the user identity account credential through encryption operation includes: performing encryption operation on the order credential and the user identity account credential through the user identity wallet to obtain the transaction authorization request credential. The transaction system includes an account opening server, and the method further includes: sending a KYC registration request carrying user registration information to the account opening server, so that the account opening server issues the user identity account credential based on the KYC registration request and saves the user registration information; wherein, the user registration information includes a user ID and a user public key; receiving the user identity account credential fed back by the account opening server; and storing the user identity account credential in the user identity wallet; The transaction system verifies the transaction authorization request credentials by: verifying the transaction authorization request credentials using the user registration information through the account opening server.

2. The data interaction method according to claim 1, characterized in that, Before constructing the transaction authorization request credential by performing encryption calculations based on the order credential and the user identity account credential, the method further includes: The order credential is verified using the public key registered by the supply terminal on the identity registry. After successful verification, the step of constructing a transaction authorization request credential by performing encryption operations based on the order credential and the user identity account credential is executed.

3. The data interaction method according to claim 1, characterized in that, The transaction system includes a certificate center server. After issuing a transaction authorization certificate based on the transaction authorization processing result corresponding to the transaction authorization request certificate, it further includes: The transaction authorization certificate is stored in the certificate center server.

4. The data interaction method according to claim 3, characterized in that, The transaction system also includes a transaction processing server. Upon receiving a transaction authorization certificate verification result request from the supply terminal, the server sends the verification result of the transaction authorization certificate back to the supply terminal, including: The transaction processing server receives the transaction authorization certificate verification result request sent by the supply terminal. Based on the verification result of the transaction authorization certificate, a request is made to the certificate center server to provide the transaction authorization certificate proof corresponding to the transaction authorization certificate; When the transaction authorization certificate is obtained from the certificate center server, the transaction processing server verifies the transaction authorization certificate and, after successful verification, feeds back the verification result of the transaction authorization certificate to the supply terminal.

5. A data interaction device, characterized in that, include: The order voucher acquisition module is used for the user terminal to initiate a transaction request to the supply terminal and to receive the order voucher returned by the supply terminal according to the transaction request. The transaction authorization request credential issuance module is used to perform encryption operations based on the order credential and the user identity account credential to construct the transaction authorization request credential. The transaction authorization module is used to send the transaction authorization request credential to the transaction system, so that after the transaction authorization request credential is verified, the transaction system issues a transaction authorization certificate according to the transaction authorization processing result corresponding to the transaction authorization request credential, and when it receives the transaction authorization certificate verification result request sent by the supply terminal, it feeds back the verification result of the transaction authorization certificate to the supply terminal. The user terminal is equipped with a user identity wallet, and the user identity account credential is stored in the user identity wallet. The transaction authorization request credential issuance module is specifically used to perform encryption operations on the order credential and the user identity account credential through the user identity wallet to obtain the transaction authorization request credential. The transaction system includes an account opening server, and the device further includes a registration module for sending a KYC registration request carrying user registration information to the account opening server, so that the account opening server issues the user identity account credential based on the KYC registration request and saves the user registration information; wherein, the user registration information includes a user ID and a user public key; receiving the user identity account credential fed back by the account opening server; and storing the user identity account credential in the user identity wallet; The transaction authorization module is specifically used by the transaction system to verify the transaction authorization request credentials using the user registration information through the account opening server.

6. A data interaction device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the data interaction method as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the data interaction method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Account initialization method and device

    CN108737435A