Usage method, terminal and system of a digital currency wallet application
The trust service management platform generates authentication data for digital currency wallets, enabling cross-institutional transaction verification and enhancing security by ensuring the legitimacy of wallet applications, thus expanding their usage scenarios.
Patent Information
- Application Number
- CN202111177783.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-09
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-10-09
AI Technical Summary
Existing digital currency wallet applications managed by different institutions cannot verify the legitimacy of each other, limiting the use cases and security of cross-institutional transactions.
A trust service management platform generates authentication data for digital currency wallets, which is used by management platforms to provide target authentication data to terminals, allowing cross-institutional transactions to verify the legitimacy of wallet applications using pre-set public keys.
Enhances the trustworthiness of cross-institutional digital currency wallet transactions and expands the usage scenarios, improving the security of digital currency transactions.
Smart Images

Figure CN114186994B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital currency, and in particular, to a usage method, a terminal, and a system for a digital currency wallet application. Background Art
[0002] The management of wallet applications has an important impact on the secure transaction of digital currency.
[0003] Currently, the wallet applications of digital currency are managed separately by their respective operating institutions.
[0004] In the process of implementing the present invention, the inventor found that there are at least the following problems in the prior art:
[0005] Since each operating institution provides the management service of the wallet application through its own system, in the case of cross-institutional transactions, the wallet applications provided by different operating institutions cannot verify the legitimacy of the application with each other, thus restricting the usage scenarios of hardware wallets and reducing the security of digital currency transactions. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a usage method, a terminal, and a system for a digital currency wallet application, which can generate authentication data of the digital currency wallet application through a trusted service management platform. The management platform corresponding to the digital currency wallet application can return target authentication data to the first terminal where the wallet application is located according to the authentication data, and then write the target authentication data into the wallet application through the first terminal. When conducting cross-institutional transactions, that is, when transactions are carried out between terminals corresponding to different management platforms, the trading terminals can use the pre-set public key to verify the authentication data in the wallet application, thereby verifying the legitimacy of the wallet application, improving the credibility of cross-institutional transactions of digital currency wallet applications, expanding the usage scenarios of digital currency wallet applications, and further improving the security of digital currency transactions.
[0007] Furthermore, the generation parameters of the authentication data include identification information and public key information of the wallet application, which can ensure the uniqueness and non-reusability of the generated authentication data. At the same time, the number of issued digital currency wallets of each operating institution can be counted through the number of generation requests of the authentication data, thereby realizing unified management.
[0008] To achieve the above object, according to the first aspect of the embodiments of the present invention, there is provided a usage method for a digital currency wallet application, which is applied to a first terminal and includes:
[0009] Sending a data generation request to the management platform corresponding to the wallet application, where the data generation request includes the public key and identification information of the wallet application;
[0010] Receive the target authentication data returned by the management platform according to the request generated from the data, where the target authentication data is generated according to the public key and the identification information;
[0011] In response to a transaction request from a second terminal, send the target authentication data to the second terminal so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms;
[0012] In the case of successful verification, conduct a transaction with the second terminal based on the digital currency in the wallet application.
[0013] Optionally, after receiving the target authentication data returned by the management platform according to the request generated from the data, it further includes:
[0014] Write the target authentication data into the wallet application.
[0015] Optionally, the target authentication data includes: authentication data provided by a trusted platform, and any one or two of the following: the authentication certificate of the management platform generated by the public key or the data corresponding to the authentication certificate; the authentication data is obtained by signing the public key of the wallet application and the identification information with the private key of the trusted platform.
[0016] To achieve the above object, according to the second aspect of the embodiments of the present invention, a method for using a digital currency wallet application is provided, which is applied to a second terminal and includes:
[0017] In response to a user trigger, send a transaction request to the first terminal;
[0018] Receive the target authentication data sent by the first terminal according to the transaction request, where the target authentication data is generated according to the public key and identification information of the wallet application in the first terminal;
[0019] Verify the target authentication data;
[0020] In the case of successful verification, conduct a transaction with the first terminal based on the digital currency in the wallet application of the first terminal.
[0021] Optionally, the verification of the target authentication data includes:
[0022] Parse out the authentication certificate of the management platform of the first terminal and the authentication data provided by the trusted platform from the target authentication data;
[0023] Verify the authentication certificate with the public key of the management platform;
[0024] and verifying the authentication data with the public key of the trusted platform;
[0025] When both the authentication certificate and the authentication data pass the verification, it is determined that the target authentication data passes the verification.
[0026] Optionally, the public key of the management platform corresponding to the first terminal and / or the public key of the trusted platform are pre-written into the wallet application of the second terminal.
[0027] Optionally, when it is determined that the target authentication data does not include the authentication certificate and the authentication data, it is determined that the target authentication data fails the verification.
[0028] According to the third aspect of the embodiments of the present invention, a first terminal is provided, including: a request sending module, a first receiving module, a data sending module, and a first transaction module; where
[0029] The request sending module is configured to send a data generation request to the management platform corresponding to the wallet application, and the data generation request includes the public key and identification information of the wallet application;
[0030] The first receiving module is configured to receive the target authentication data returned by the management platform according to the data generation request, and the target authentication data is generated according to the public key and the identification information;
[0031] The data sending module is configured to send the target authentication data to the second terminal in response to a transaction request of the second terminal, so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms;
[0032] The first transaction module is configured to conduct a transaction with the second terminal according to the digital currency in the wallet application when the verification passes.
[0033] According to the fourth aspect of the embodiments of the present invention, a second terminal is provided, including: a transaction request sending module, a second receiving module, a verification module, and a second transaction module; where
[0034] The transaction request sending module is configured to send a transaction request to the first terminal in response to user triggering;
[0035] The second receiving module receives the target authentication data sent by the first terminal according to the transaction request, and the target authentication data is generated according to the public key and identification information of the wallet application in the first terminal;
[0036] The verification module is configured to verify the target authentication data;
[0037] The second trading module is configured to, when the verification is passed, conduct a transaction with the first terminal based on the digital currency in the wallet application of the first terminal.
[0038] According to a fifth aspect of an embodiment of the present invention, there is provided a management system for a digital currency wallet application, including: the first terminal provided in the third aspect above, the second terminal provided in the fourth aspect above, a management platform of the first terminal, and a trusted platform; wherein,
[0039] The management platform is configured to receive a data generation request sent by the first terminal and forward the data generation request to the trusted platform; the data generation request includes: a public key and identification information of a wallet application in the first terminal; after receiving the authentication data sent by the trusted platform, generate target authentication data according to the authentication data and the data corresponding to its own authentication certificate, and send the target authentication data to the first terminal;
[0040] The trusted platform is configured to generate authentication data according to the data generation request and send the authentication data to the management platform.
[0041] Optionally, the management platform is configured to use the data corresponding to its own authentication certificate and the authentication data as input parameters of the target authentication data to generate the target authentication data.
[0042] Optionally, the trusted platform is configured to sign the public key and identification information of the wallet application in the first terminal with its own private key to generate the authentication data.
[0043] Optionally, the trusted platform is configured to determine the number of wallet applications corresponding to the management platform according to the number of received data generation requests, and manage the generation of the target authentication data according to the number of wallet applications.
[0044] According to a sixth aspect of an embodiment of the present invention, there is provided an electronic device, including:
[0045] One or more processors;
[0046] A storage device configured to store one or more programs,
[0047] When the one or more programs are executed by the one or more processors, the one or more processors implement any of the methods provided in the method for using a digital currency wallet application in the first aspect or the second aspect above.
[0048] According to a seventh aspect of an embodiment of the present invention, there is provided a computer-readable medium having a computer program stored thereon, and when the program is executed by a processor, it implements any one of the methods provided in the first aspect or the second aspect above for using a digital currency wallet application.
[0049] One embodiment of the above invention has the following advantages or beneficial effects: The authentication data of the digital currency wallet application can be generated through a trusted service management platform. The management platform corresponding to the digital currency wallet application can return target authentication data to the first terminal where the wallet application is located according to the authentication data, and then write the target authentication data into the wallet application through the first terminal. When conducting cross-institutional transactions, that is, transactions between terminals corresponding to different management platforms, the trading terminals can use the pre-set public key to verify the authentication data in the wallet application, thereby verifying the legitimacy of the wallet application, improving the credibility of cross-institutional transactions of the digital currency wallet application, expanding the usage scenarios of the digital currency wallet application, and further enhancing the security of digital currency transactions.
[0050] Furthermore, the generation parameters of the authentication data include identification information and the public key information of the wallet application, which can ensure the uniqueness and non-reusability of the generated authentication data. At the same time, the number of digital currency wallets issued by each operating institution can be counted through the number of generation requests for the authentication data, thereby achieving unified management.
[0051] The further effects of the above non-conventional optional methods will be described in combination with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0053] Figure 1 is a flowchart of a method for using a digital currency wallet application applied to a first terminal provided by an embodiment of the present invention;
[0054] Figure 2 is a flowchart of a method for using a digital currency wallet application applied to a second terminal provided by an embodiment of the present invention;
[0055] Figure 3 is a flowchart of generating target authentication data provided by an embodiment of the present invention;
[0056] Figure 4 is a flowchart of generating another target authentication data provided by an embodiment of the present invention;
[0057] Figure 5 is a flowchart of verifying target authentication data provided by an embodiment of the present invention;
[0058] Figure 6 It is a schematic structural diagram of a first terminal corresponding to a digital currency wallet application provided by an embodiment of the present invention;
[0059] Figure 7 It is a schematic structural diagram of a second terminal corresponding to a digital currency wallet application provided by an embodiment of the present invention;
[0060] Figure 8 It is a schematic structural diagram of a management system of a digital currency wallet application provided by an embodiment of the present invention;
[0061] Figure 9 It is a schematic flowchart of a usage method of another digital currency wallet application provided by an embodiment of the present invention;
[0062] Figure 10 It is an exemplary system architecture diagram to which the embodiments of the present invention can be applied;
[0063] Figure 11 It is a schematic structural diagram of a computer system of a terminal device or a server suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0064] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted below.
[0065] It should be noted that, without conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0066] As Figure 1 shown, an embodiment of the present invention provides a usage method of a digital currency wallet application applied to a first terminal. The method may include the following steps S101 to S104:
[0067] Step S101: Send a data generation request to the management platform corresponding to the wallet application, where the data generation request includes the public key and identification information of the wallet application.
[0068] Step S102: Receive the target authentication data returned by the management platform according to the data generation request, where the target authentication data is generated according to the public key and the identification information.
[0069] Step S103: In response to a transaction request from the second terminal, send the target authentication data to the second terminal so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms.
[0070] Step S104: In the case of successful verification, conduct a transaction with the second terminal based on the digital currency in the wallet application.
[0071] Among them, the digital currency wallet in the embodiments of the present invention is set in a security chip, that is, the digital currency wallet is a hardware wallet, and this security chip can be an SE, IC, or SIM chip. Before using the digital currency wallet, a card writing device can be used to configure the digital currency hardware wallet through corresponding instructions. For example, the card writing device authorizes the security chip through Apdu instructions, applies for an application and loads the application for the hardware wallet, authorizes the application, and writes personalized data.
[0072] An application scenario of the present invention can be a scenario where the wallet applications of the first terminal A and the second terminal B conduct digital currency transactions. Here, the second terminal B can correspond to the same management platform as the first terminal A, or can correspond to a different management platform from the first terminal A. For example, the wallet application of the first terminal corresponding to Bank 1 conducts a transaction with the wallet application of the second terminal corresponding to Bank 1; or the wallet application of the first terminal corresponding to Bank 1 conducts a transaction with the wallet application of the second terminal corresponding to Bank 2.
[0073] In an embodiment of the present invention, taking the case where the first terminal and the second terminal correspond to different management platforms as an example. For example, the wallet application a of the first terminal A is issued by Bank 1, and the wallet application b of the second terminal B is issued by Bank 2. During a payment process, the first terminal A needs to pay a certain amount of digital currency in the wallet application a to the wallet application b of the second terminal B. Before conducting the transaction, the second terminal B must verify the target authentication data in the wallet application a of the first terminal A to ensure the legitimacy and security of the wallet application a of the first terminal A. Among them, the target authentication data is generated based on the public key and identification information of the wallet application a of the first terminal A. The generation process is that the first terminal A sends a data generation request to the management platform corresponding to the wallet application a, and the management platform returns the target authentication data to the first terminal A according to the data generation request. Here, the target authentication data is generated based on the public key of the wallet application of the first terminal A and the identification information corresponding to the first terminal A. After receiving the transaction request from the second terminal B, the first terminal A sends the target authentication data to the second terminal B for verification. In the case of successful verification, the first terminal A pays the corresponding amount of digital currency in the wallet application a to the wallet application b of the second terminal B, thereby completing the payment process.
[0074] It is understandable that when conducting transactions between terminals of different management platforms, target authentication data can be used for verification. Therefore, the credibility of cross-platform transactions of digital currency wallet applications can be improved, the usage scenarios of wallet applications can be expanded, and the transaction security of wallet applications can be enhanced.
[0075] Among them, the public key of the wallet application is the public key in a pair of public and private keys generated according to the wallet application when the wallet application applies for opening. Its private key is stored in the security chip corresponding to the wallet application to ensure its security. The public key and the corresponding identification information are sent to the management platform corresponding to the wallet application as a data generation request for the wallet application. The identification information can be the identification of the wallet application, the identification of the security chip of the corresponding first terminal, and the identification of the corresponding management platform.
[0076] During the digital currency transaction process, the security requirements for digital currency wallet applications are relatively high. Therefore, before enabling the digital currency wallet application, that is, when the digital currency wallet application is opened, it is necessary to apply for target authentication data for the wallet application. The obtained target authentication data can be written into the security chip of the first terminal or written into the wallet application of the first terminal. In order to enable the wallet applications of different terminals to receive the target authentication data of each other more quickly and conveniently to complete the transaction during the digital currency transaction process, in an embodiment of the present invention, the following method can be adopted. After receiving the target authentication data returned by the management platform according to the data generation request, it further includes: writing the target authentication data into the wallet application.
[0077] It is understandable that in order to ensure the security of wallet application transactions on different management platforms, multiple encrypted data can be used to generate target authentication data, so that multiple verifications can be used during the transaction process to ensure transaction security. Therefore, in an embodiment of the present invention, the target authentication data includes: authentication data provided by a trusted platform, and any one or two of the following: the authentication certificate of the management platform generated through the public key or the data corresponding to the authentication certificate; the authentication data is obtained by signing the public key of the wallet application and the identification information with the private key of the trusted platform.
[0078] Among them, the authentication certificate of the management platform, that is, the authentication certificate applied for and issued by the management platform to its own CA (Certificate Authority) system according to the public key of the wallet application. For example, in the wallet application issued by Bank 1, the authentication certificate is issued by the CA system of Bank 1; in the wallet application issued by Bank 2, the authentication certificate is issued by the CA system of Bank 2.
[0079] Data corresponding to the authentication certificate, i.e., data used by the CA system of the management platform to generate the data corresponding to the authentication certificate.
[0080] The authentication data provided by the trusted platform is generated in the same way for wallet applications of different management platforms. For example, the trusted platform can be a trusted service management platform, which uses the same private key and algorithm to generate authentication data for wallet applications issued by different banks (such as Bank 1, Bank 2, Bank 3, Bank 4, etc.). Among them, the signature private key of the authentication data is the private key held by the trusted service management platform, and the signature algorithm is a unified algorithm. However, the signature parameters used when generating the authentication data are different. The signature parameters are the public key of the wallet application and its corresponding identification information. In other words, the generated authentication data contains the signature information of the public key of the wallet application and the identification information, thus ensuring the uniqueness and non-reusability of the authentication data. For example, when generating authentication data for a hardware wallet application issued by Bank 1, the parameters used for signing are the public key of the wallet application of Bank 1, the identification of the wallet application, the identification of the security chip of the first terminal corresponding to the wallet application, and the identification of Bank 1.
[0081] After writing the target authentication data into the wallet application of the first terminal, the wallet application is in an available state. At this time, it can be recharged with digital currency for trading purposes. When the first terminal receives a transaction request sent by the second terminal, it sends the target authentication data to the second terminal so that the second terminal can verify the target authentication data. The verification process can be as Figure 2 shown. If the verification passes, the transaction continues.
[0082] Figure 2 Embodiment of the present invention provides a usage method for a digital currency wallet application applied to a second terminal. The method may include the following steps S201 to S204:
[0083] Step S201: In response to a user trigger, send a transaction request to the first terminal.
[0084] Step S202: Receive the target authentication data sent by the first terminal according to the transaction request. The target authentication data is generated according to the public key and identification information of the wallet application in the first terminal.
[0085] Step S203: Verify the target authentication data.
[0086] Step S204: In the case of successful verification, conduct a transaction with the first terminal according to the digital currency in the wallet application of the first terminal.
[0087] Taking the scenario where the wallet application a of the first terminal A pays a certain amount of digital currency to the wallet application b of the second terminal B as an example, in response to the user's trigger, the second terminal B sends a transaction request to the first terminal A, receives the target authentication data in the wallet application a sent by the first terminal A, verifies the target authentication data. If the verification passes, it receives the digital currency paid by the wallet application a of the first terminal A to complete the transaction.
[0088] In step S203, when verifying the target authentication data, the method provided by an embodiment of the present invention can be adopted, including: parsing out the authentication certificate corresponding to the management platform of the first terminal and the authentication data provided by the trusted platform from the target authentication data; verifying the authentication certificate with the public key of the management platform; and verifying the authentication data with the public key of the trusted platform; when both the authentication certificate and the authentication data pass the verification, it is determined that the target authentication data passes the verification. Among them, the public key of the management platform corresponding to the first terminal and / or the public key of the trusted platform are pre-written into the wallet application of the second terminal.
[0089] For example, the second terminal B corresponds to Bank 2, and its wallet application is b. The first terminal A corresponds to Bank 1, and its wallet application is a. The wallet application b parses out the authentication certificate of the wallet application a issued by the CA system of Bank 1 and the authentication data provided by the trusted service management platform from the target authentication data in the wallet application a sent by the first terminal A; then verifies the authentication certificate of the wallet application a with the public key of the CA system of Bank 1. After the verification passes, it then verifies the authentication data with the public key of the trusted service management platform. If both pass the verification, the transaction can continue. If any one of the verifications fails, the transaction is terminated.
[0090] For the sake of fast and convenient verification, when each wallet application is opened, the public keys of the management platforms corresponding to one or more wallet applications and the public key of the trusted service management platform can be pre-written into the wallet application. For example, the second terminal B corresponds to Bank 2. When its wallet application b is opened, the public key of the CA system of Bank 2 can be first written into the wallet application b, and then the public keys of one or more different management platforms (such as Bank 1, Bank 2, Bank 3, Bank 4, etc.) that support digital currency wallet applications are written into the wallet application b, so as to verify the authentication certificates issued by other management platforms corresponding to the wallet application when trading with wallet applications of different management platforms. At the same time, the public key of the trusted service management platform is also written into the wallet application b.
[0091] During the verification process, wallet application b uses the public keys of the CA system of Bank 1 and the public key of the trusted service management platform stored by itself to verify the authentication certificate issued by the CA system of Bank 1 and the authentication data provided by the trusted service management platform sent by wallet application a. Among them, the public key of the CA system of Bank 1 and the public key of the trusted service management platform are written into wallet application b of the second terminal B when wallet application b is opened.
[0092] After both the authentication certificate and the authentication data pass the verification, before continuing the transaction, wallet application a of the first terminal A can encrypt the transaction data using the private key of the wallet application stored in the security chip and send the encrypted transaction data to the second terminal B. Wallet application b of the second terminal B decrypts the transaction data according to the public key of the wallet application in the verified authentication certificate to determine the authenticity of the transaction data, so as to determine to receive the corresponding amount of digital currency paid by wallet application a.
[0093] In an embodiment of the present invention, there may also be a situation where the authentication certificate and the authentication data cannot be parsed from the target authentication data, or the target authentication data does not include the authentication certificate or the authentication data after parsing. At this time, the following method can be adopted. When it is determined that the target authentication data does not include the authentication certificate and the authentication data, it is determined that the target authentication data fails the verification.
[0094] According to the embodiments of the present invention, a method for using a digital currency wallet application is provided. The authentication data of the digital currency wallet application can be generated through the trusted service management platform. The management platform corresponding to the digital currency wallet application can return the target authentication data to the first terminal where the wallet application is located according to the authentication data, and then write the target authentication data into the wallet application through the first terminal. When conducting cross-institutional transactions, that is, transactions between terminals corresponding to different management platforms, the trading terminals can use the preset public key to verify the authentication data in the wallet application, thereby verifying the legitimacy of the wallet application, improving the credibility of cross-institutional transactions of the digital currency wallet application, expanding the usage scenarios of the digital currency wallet application, and further improving the security of digital currency transactions.
[0095] Furthermore, the generation parameters of the authentication data include identification information and the public key information of the wallet application, which can ensure the uniqueness and non-reusability of the generated authentication data. At the same time, the number of issued digital currency wallets of each operating institution can be counted through the number of generation requests of the authentication data, so as to achieve unified management.
[0096] The following combines the above-mentioned various embodiments and takes the use of a hardware wallet application as an example to elaborate in detail on the generation process of the target authentication data in the usage method of the digital currency wallet application provided by each embodiment of the present invention. In one embodiment of the present invention, the generation process of the target authentication data may have Figure 3 and Figure 4 two types.
[0097] Figure 3 The process of Figure 3 takes the authentication data of the trusted platform and the data used by the management platform to generate the authentication certificate as input parameters for the final target authentication data to generate the final target authentication data.
[0098] As Figure 3 shown, this embodiment may include the following steps:
[0099] Step S301: The security chip installs the hardware wallet application, generates a public-private key pair, and calculates a certificate application file.
[0100] After installing the wallet application, the public key of the CA system of the management platform and the public key of the trusted platform can also be written into the wallet application for subsequent verification processes. The public key of the CA system of the management platform can be the public keys of one or more different management platforms that support the digital currency wallet application.
[0101] Among the generated public-private key pair of the wallet application, the private key of the wallet application is stored in the security chip, and the public key of the wallet application is forwarded to the trusted platform through the management platform of the wallet application.
[0102] The certificate application file is also the application data for the wallet application to apply for an authentication certificate from the CA system of the management platform, that is, the data used by the management platform to generate the authentication certificate.
[0103] Step S302: The first terminal initiates a request to open the hardware wallet application.
[0104] Among them, the opening request indicates a data generation request for generating the target authentication data. The data generation request includes: the public key and identification information of the wallet application in the first terminal.
[0105] Step S303: The wallet management platform receives the opening request and applies to the trusted platform for authentication data.
[0106] After receiving the opening request, the management platform sends the public key and identification information of the wallet application to the trusted platform and applies to the trusted platform for authentication data.
[0107] Step S304: The trusted platform generates authentication data.
[0108] After receiving the public key and identification information of the wallet application sent by the management platform, the trusted platform can use its own private key and a unified signature algorithm to sign the public key and identification information of the wallet application, and send the signed data to the management platform as authentication data. Among them, the signature algorithm can be the SM2 algorithm (elliptic curve public key cryptography algorithm).
[0109] Step S305: The wallet management platform uses the authentication data and the certificate application file to apply to the CA system for the target authentication data of the wallet application.
[0110] The management platform uses the authentication data sent by the trusted platform and the certificate application file generated in step S301 as parameters to apply to its own CA system for the target authentication data of the wallet application. The generated target authentication data is sent to the first terminal. At this time, the target authentication data contains the authentication data provided by the trusted platform. The target authentication data is in the form of a CA certificate.
[0111] Step S306: The first terminal receives the target authentication data with the authentication data, and writes the target authentication data into the hardware wallet application for subsequent transaction verification.
[0112] Figure 3 The process is to use the authentication data of the trusted platform and the data used by the management platform to generate the authentication certificate as the input parameters of the final target authentication data to generate the final target authentication data. Among them, the finally generated target authentication data can be in the form of a CA certificate. It can be understood that although the authentication certificate of the management platform can be in the form of a CA certificate, and the finally generated target authentication data can also be in the form of a CA certificate, the data corresponding to the two CA certificates is different. Among them, the CA certificate corresponding to the management platform does not include the authentication data sent by the trusted platform, while the CA certificate corresponding to the final target authentication data is generated by combining the authentication data sent by the trusted platform and the data used by the management platform to generate the authentication certificate. That is, the CA certificate corresponding to the final target authentication data is double-signed by the trusted platform and the management platform, thus better ensuring the security of the authentication data.
[0113] In addition to the above method of generating the target authentication data, an embodiment of the present invention also provides another process for generating the target authentication data, as Figure 4 shown. In the process of generating the target authentication data, the authentication certificate generated by the CA system of the management platform corresponding to the wallet application and the authentication data provided by the trusted platform are respectively sent to the first terminal. That is, the management platform sends the authentication data and the authentication certificate as independent data to the first terminal.
[0114] The above process may include the following steps:
[0115] Step S401: The secure chip installs the hardware wallet application, generates a public-private key pair, and calculates a certificate application file.
[0116] After installing the wallet application, the public key of the CA system of the management platform and the public key of the trusted platform can also be written into the wallet application for subsequent verification processes. The public key of the CA system of the management platform can be the public key of one or more management platforms that support the digital currency wallet application.
[0117] Among the generated public-private key pair of the wallet application, the private key of the wallet application is stored in the secure chip, and the public key of the wallet application is forwarded to the trusted platform through the management platform of the wallet application. The trusted platform can use the public key as one of the parameters for generating authentication data.
[0118] The certificate application file is also the application data for the wallet application to apply for an authentication certificate from the CA system of the management platform.
[0119] Step S402: The first terminal initiates a request to open the hardware wallet application.
[0120] Among them, the opening request indicates a data generation request for generating target authentication data. The data generation request includes: the public key and identification information of the wallet application in the first terminal.
[0121] Step S403: The wallet management platform receives the opening request, applies to the trusted platform for authentication data, and applies to the CA system for an authentication certificate.
[0122] Step S404: The trusted platform generates authentication data.
[0123] After receiving the public key and identification information of the wallet application sent by the management platform, the trusted platform can use its own private key and a unified signature algorithm to sign the public key and identification information of the wallet application, and send the signed data to the management platform as authentication data. The signature algorithm can be the SM2 algorithm.
[0124] Step S405: The CA system generates an authentication certificate.
[0125] The CA system of the management platform generates an authentication certificate for the wallet application according to the certificate application file in step S401, and the management platform sends the authentication certificate to the first terminal.
[0126] In the embodiment of the present invention, step S404 and step S405 are not in sequence. That is to say, step S404 can be executed first, and then step S405; step S405 can also be executed first, and then step S404; or step S404 and step S405 can be executed simultaneously.
[0127] Step S406: The first terminal receives the authentication data and the authentication certificate, and writes the authentication data and the authentication certificate into the hardware wallet application for subsequent transaction verification.
[0128] After the first terminal receives the authentication data provided by the trusted platform forwarded by the management platform and the authentication certificate sent by the management platform, it writes the authentication data and the authentication certificate into the wallet application respectively.
[0129] Through Figure 4 the generation process of the target authentication data, the management platform can send the authentication certificate of the management platform and the authentication data of the trusted platform to the first terminal respectively. The first terminal can quickly and conveniently write the authentication data of the trusted platform into the wallet application, achieving the purpose of cross-platform verification of the authentication data and improving the security of digital currency transactions.
[0130] In addition, during the process of generating the authentication data, the trusted platform can determine the number of digital currency wallets issued by each management platform by counting the number of authentication data generation requests sent by different management platforms. When the trusted platform determines that the total number of digital currency wallets issued by a management platform exceeds the specified number, it can refuse to provide authentication data for the wallet applications exceeding the number, thereby managing the number of digital currency wallets issued by each management platform and achieving the purpose of unified management. For example, the trusted service management platform counts the number of wallets issued by Bank 1 based on the number of authentication data generation requests received from Bank 1. After the total number of its wallets reaches the specified number, it does not process the subsequent received authentication data generation requests and feedbacks the information of non-processing to limit the total number of wallets issued by the bank and achieve the purpose of unified management.
[0131] Figure 5 This is the verification flowchart of the target authentication data provided by an embodiment of the present invention, and the steps are as follows:
[0132] Step S501: The payee wallet application initiates a payment request.
[0133] Step S502: The payer wallet application receives the payment request and returns the target authentication data including the authentication certificate and the authentication data of the wallet application.
[0134] The authentication certificate of the wallet application is issued by the CA system of the management platform corresponding to the payer wallet application. The authentication data is provided by the trusted platform.
[0135] Step S503: The payee wallet application receives the target authentication data.
[0136] After the payee wallet application receives the target authentication data, it parses the authentication certificate of the wallet application and the authentication data from the target authentication data.
[0137] Step S504: Determine whether the authentication certificate of the wallet application passes the verification.
[0138] The payee wallet application verifies the authentication certificate according to the public key of the management platform CA system corresponding to the payer stored by itself. If the verification passes, proceed to step S505. If not, terminate the transaction process.
[0139] Step S505: Determine whether the authentication data passes the verification.
[0140] The payee wallet application verifies the authentication data according to the public key of the trusted platform stored by itself. If the verification passes, proceed to step S506. If not, terminate the transaction process.
[0141] Step S506: Continue the transaction process.
[0142] When both the authentication certificate and the authentication data pass the verification, continue the transaction process.
[0143] Step S507: Terminate the transaction process.
[0144] When either the authentication certificate or the authentication data fails the verification, terminate the transaction process.
[0145] Of course, it can be understood that there may also be a case where the target authentication data does not include the authentication certificate and the authentication data. In this case, it can also be determined that the target authentication data fails the verification, thereby terminating the transaction process.
[0146] As Figure 6 shown, an embodiment of the present invention provides a first terminal 600, including: a request sending module 601, a first receiving module 602, a data sending module 603, and a first transaction module 604; wherein,
[0147] The request sending module 601 is configured to send a data generation request to the management platform corresponding to the wallet application, where the data generation request includes the public key and identification information of the wallet application;
[0148] The first receiving module 602 is configured to receive target authentication data returned by the management platform according to the data generation request, where the target authentication data is generated according to the public key and the identification information;
[0149] The data sending module 603 is configured to send the target authentication data to the second terminal in response to a transaction request of the second terminal, so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms;
[0150] The first transaction module 604 is configured to, when the verification is passed, conduct a transaction with the second terminal according to the digital currency in the wallet application.
[0151] In an embodiment of the present invention, the first receiving module 602, after receiving the target authentication data returned by the management platform according to the data, further includes: writing the target authentication data into the wallet application.
[0152] In an embodiment of the present invention, the first receiving module 602 is configured to determine that the received target authentication data includes: authentication data provided by a trusted platform, and any one or two of the following: an authentication certificate of the management platform generated by the public key or data corresponding to the authentication certificate; the authentication data is obtained by signing the public key of the wallet application and the identification information with the private key of the trusted platform.
[0153] As Figure 7 shown, an embodiment of the present invention provides a second terminal 700, including: a transaction request sending module 701, a second receiving module 702, a verification module 703, and a second transaction module 704; wherein,
[0154] The transaction request sending module 701 is configured to send a transaction request to the first terminal in response to a user trigger;
[0155] The second receiving module 702 is configured to receive the target authentication data sent by the first terminal according to the transaction request, and the target authentication data is generated according to the public key and identification information of the wallet application in the first terminal;
[0156] The verification module 703 is configured to verify the target authentication data;
[0157] The second transaction module 704 is configured to, when the verification is passed, conduct a transaction with the first terminal according to the digital currency in the wallet application of the first terminal.
[0158] In an embodiment of the present invention, the verification module 703 is configured to parse out the authentication certificate corresponding to the management platform of the first terminal and the authentication data provided by the trusted platform from the target authentication data; verify the authentication certificate with the public key of the management platform; and verify the authentication data with the public key of the trusted platform; when both the authentication certificate and the authentication data pass the verification, determine that the target authentication data passes the verification.
[0159] In an embodiment of the present invention, the verification module 703 is configured to determine that the public key of the management platform corresponding to the first terminal and / or the public key of the trusted platform are pre-written into the wallet application of the second terminal.
[0160] In an embodiment of the present invention, the verification module 703 is configured to determine that the target authentication data fails to pass the verification when it is determined that the target authentication data does not include the authentication certificate and the authentication data.
[0161] As Figure 8 shown, an embodiment of the present invention provides a management system 800 for a digital currency wallet application, including: the first terminal 600 provided in any of the above embodiments, the second terminal 700 provided in any of the above embodiments, the management platform 801 of the first terminal, and the trusted platform 802; wherein,
[0162] The management platform 801 is configured to receive a data generation request sent by the first terminal and forward the data generation request to the trusted platform; the data generation request includes: the public key and identification information of the wallet application in the first terminal; after receiving the authentication data sent by the trusted platform, generate target authentication data according to the authentication data and the data corresponding to its own authentication certificate, and send the target authentication data to the first terminal;
[0163] The trusted platform 802 is configured to generate authentication data according to the data generation request and send the authentication data to the management platform.
[0164] In an embodiment of the present invention, the management platform 801 is configured to use the data corresponding to its own authentication certificate and the authentication data as input parameters of the target authentication data to generate the target authentication data.
[0165] In an embodiment of the present invention, the trusted platform 802 is configured to sign the public key and identification information of the wallet application in the first terminal by using its own private key to generate the authentication data.
[0166] In an embodiment of the present invention, the trusted platform 802 is configured to determine the number of wallet applications corresponding to the management platform according to the number of received data generation requests, and manage the generation of the target authentication data according to the number of wallet applications.
[0167] Next, taking the usage method of the management system of the digital currency wallet application as an example, the usage method of the digital currency wallet application provided by the embodiment of the present invention will be further described. As Figure 9 shown, the method mainly includes the following steps:
[0168] Step S901: The first terminal sends a data generation request to its corresponding management platform.
[0169] The data generation request includes the public key of the wallet application of the first terminal and identification information.
[0170] Step S902: The management platform forwards the data generation request to the trusted platform.
[0171] Step S903: The trusted platform generates authentication data and sends the authentication data to the management platform.
[0172] The trusted platform uses its own private key to sign the public key of the wallet application and the identification information sent by the management platform to generate authentication data, and sends the authentication data to the management platform.
[0173] Step S904: The management platform generates target authentication data and sends the target authentication data to the first terminal.
[0174] The target authentication data can be a CA certificate generated based on the authentication data of the trusted platform and the data used by the management platform to generate the authentication certificate, or the target authentication data that includes the two independent data of the authentication data and the authentication certificate of the management platform.
[0175] Step S905: The first terminal writes the target authentication data into the wallet application.
[0176] Step S906: The second terminal sends a transaction request to the first terminal.
[0177] Step S907: In response to the transaction request of the second terminal, the first terminal sends the target authentication data to the second terminal.
[0178] Step S908: The second terminal verifies whether the target authentication data passes. If it passes, it sends a request to continue the transaction.
[0179] The second terminal uses the public key of the management platform corresponding to the first terminal stored in itself to verify whether the authentication certificate of the management platform in the target authentication data passes. If it passes, it continues to verify whether the authentication data provided by the trusted platform passes. If it passes, it sends a request to continue the transaction to the first terminal.
[0180] Step S909: The first terminal sends the transaction data to the second terminal, and the second terminal conducts a transaction with the first terminal according to the transaction data.
[0181] Among them, the first terminal can encrypt the transaction data using the private key in the security chip and send the encrypted transaction data to the second terminal. The second terminal can decrypt the transaction data using the public key of the wallet application included in the target authentication data and then conduct the transaction.
[0182] According to the management system of the digital currency wallet application provided by the embodiments of the present invention, the authentication data of the digital currency wallet application can be generated through a trusted service management platform. The management platform corresponding to the digital currency wallet application can return target authentication data to the first terminal where the wallet application is located according to the authentication data, and then write the target authentication data into the wallet application through the first terminal. When conducting cross-institutional transactions, that is, when trading between terminals corresponding to different management platforms, the trading terminals can use the pre-set public key to verify the authentication data in the wallet application, thereby verifying the legitimacy of the wallet application, improving the credibility of cross-institutional transactions of the digital currency wallet application, expanding the usage scenarios of the digital currency wallet application, and further enhancing the security of digital currency transactions.
[0183] Furthermore, the generation parameters of the authentication data include identification information and the public key information of the wallet application, which can ensure the uniqueness and non-reusability of the generated authentication data. At the same time, the number of digital currency wallets issued by each operating institution can be counted through the number of generation requests for the authentication data, thereby realizing unified management.
[0184] Figure 10 An exemplary system architecture 1000 of the usage method of the digital currency wallet application or the usage device of the digital currency wallet application to which the embodiments of the present invention can be applied is shown.
[0185] As Figure 10 shown, the system architecture 1000 may include terminal devices 1001, 1002, 1003, a network 1004, and servers 1005, 1006. The network 904 is used to provide a medium for communication links between the terminal devices 1001, 1002, 1003 and the servers 1005, 1006. The network 1004 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0186] Users can use the terminal devices 1001, 1002, 1003 to interact with the server 1005 through the network 1004 to receive or send messages, etc. Moreover, the servers 1005 and 1006 can also interact with each other through the network 1004. For example, the server 1005 can forward a data generation request to the server 1006 through the network 1004.
[0187] The terminal devices 1001, 1002, 1003 can be various electronic devices with a display screen and supporting information browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0188] Server 1005 may be a server that provides various services, such as a background management server that supports data generation requests made by users using terminal devices 1001, 1002, and 1003. Server 1006 may be a trusted management server that provides authentication data. The background management server may analyze and process data such as received data generation requests and feedback the processing results to the terminal devices.
[0189] It should be noted that the usage method of the digital currency wallet application provided in the embodiments of the present invention is generally executed by terminals 1001, 1002, and 1003. Correspondingly, the usage device of the digital currency wallet application is generally set in terminals 1001, 1002, and 1003. Correspondingly, the management platform and the trusted platform are generally set in servers 1005 and 1006.
[0190] It should be understood that Figure 10 the numbers of the terminal devices, networks, and servers in
[0191] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 11 is a schematic structural diagram of a computer system 1100 of a terminal device suitable for implementing the embodiments of the present invention. Figure 11 The terminal device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0192] As Figure 11 shown, the computer system 1100 includes a central processing unit (CPU) 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage section 1108 into a random access memory (RAM) 1103. In the RAM 1103, various programs and data required for the operation of the system 1100 are also stored. The CPU 1101, the ROM 1102, and the RAM 1103 are connected to each other through a bus 1104. An input / output (I / O) interface 1105 is also connected to the bus 1104.
[0193] The following components are connected to the I / O interface 1105: an input section 1106 including a keyboard, a mouse, etc.; an output section 1107 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 1108 including a hard disk, etc.; and a communication section 1109 including a network interface card such as a LAN card, a modem, etc. The communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the I / O interface 1105 as required. A removable medium 1111 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is installed on the drive 1110 as required so that a computer program read therefrom is installed into the storage section 1108 as required.
[0194] Specifically, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1109, and / or installed from the removable medium 1111. When the computer program is executed by a central processing unit (CPU) 1101, the above-described functions defined in the system of the present invention are executed.
[0195] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0196] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0197] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes a sending module, a receiving module, and a transaction module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the sending module can also be described as "the module for requesting sending".
[0198] As another aspect, the present invention also provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist alone without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device includes: sending a data generation request to the management platform corresponding to the wallet application, the data generation request including the public key and identification information of the wallet application; receiving the target authentication data returned by the management platform according to the data generation request, the target authentication data being generated according to the public key and the identification information; in response to a transaction request from a second terminal, sending the target authentication data to the second terminal, so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms; and in the case of successful verification, conducting a transaction with the second terminal according to the digital currency in the wallet application.
[0199] According to the technical solution of the embodiments of the present invention, the authentication data of the digital currency wallet application can be generated by the trusted service management platform. The management platform corresponding to the digital currency wallet application can return the target authentication data to the first terminal where the wallet application is located according to the authentication data, and then write the target authentication data into the wallet application through the first terminal. When conducting cross-institutional transactions, that is, transactions between terminals corresponding to different management platforms, the transaction terminals can use the preset public key to verify the authentication data in the wallet application, thereby verifying the legitimacy of the wallet application, improving the credibility of cross-institutional transactions of the digital currency wallet application, expanding the usage scenarios of the digital currency wallet application, and further improving the security of digital currency transactions.
[0200] Furthermore, the generation parameters of the authentication data include identification information and the public key information of the wallet application, which can ensure the uniqueness and non-reusability of the generated authentication data. At the same time, the number of digital currency wallets issued by each operating institution can be counted through the number of data generation requests for the authentication data, thereby realizing unified management.
[0201] The above specific embodiments do not limit the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub - combinations and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method of using a digital currency wallet application, characterized in that, Applied to a first terminal, including: Sending a data generation request to a management platform corresponding to the wallet application, where the data generation request includes the public key and identification information of the wallet application; Receiving target authentication data returned by the management platform according to the data generation request, where the target authentication data is generated based on the public key and the identification information; the target authentication data includes: authentication data provided by a trusted platform, and any one or both of the following: an authentication certificate of the management platform generated through the public key or data corresponding to the authentication certificate; the authentication data is obtained by signing the public key and the identification information of the wallet application with the private key of the trusted platform, and the signature parameters are the public key of the wallet application and its corresponding identification information; In response to a transaction request from a second terminal, sending the target authentication data to the second terminal, so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms; In the case of successful verification, conducting a transaction with the second terminal based on the digital currency in the wallet application.
2. The method according to claim 1, wherein After receiving the target authentication data returned by the management platform according to the data generation request, further including: Writing the target authentication data into the wallet application.
3. A method for using a digital currency wallet application, characterized in that, Applied to a second terminal, including: In response to user triggering, sending a transaction request to the first terminal; Receiving the target authentication data sent by the first terminal according to the transaction request, where the target authentication data is generated based on the public key and identification information of the wallet application in the first terminal; the target authentication data includes: authentication data provided by a trusted platform, and any one or both of the following: an authentication certificate of the management platform generated through the public key or data corresponding to the authentication certificate; the authentication data is obtained by signing the public key and the identification information of the wallet application with the private key of the trusted platform, and the signature parameters are the public key of the wallet application and its corresponding identification information; Verifying the target authentication data; In the case of successful verification, conducting a transaction with the first terminal based on the digital currency in the wallet application of the first terminal.
4. The method according to claim 3, characterized in that, The verifying of the target authentication data includes: Parsing out the authentication certificate of the management platform of the first terminal and the authentication data provided by the trusted platform from the target authentication data; Verifying the authentication certificate through the public key of the management platform; And verifying the authentication data through the public key of the trusted platform; In the case where both the authentication certificate and the authentication data are successfully verified, determining that the target authentication data is successfully verified.
5. The method according to claim 4, wherein The public key of the management platform corresponding to the first terminal and / or the public key of the trusted platform are pre-written into the wallet application of the second terminal.
6. The method according to claim 4, wherein In the case where it is determined that the target authentication data does not include the authentication certificate and the authentication data, determining that the target authentication data fails to be verified.
7. A first terminal, characterized in that, Including: A request sending module, a first receiving module, a data sending module, and a first transaction module; wherein, The request sending module is configured to send a data generation request to a management platform corresponding to the wallet application, and the data generation request includes the public key and identification information of the wallet application; The first receiving module is configured to receive target authentication data returned by the management platform according to the data generation request, and the target authentication data is generated according to the public key and the identification information; the target authentication data includes: authentication data provided by a trusted platform, and any one or both of the following: an authentication certificate of the management platform generated by the public key or data corresponding to the authentication certificate; the authentication data is obtained by signing the public key and the identification information of the wallet application with the private key of the trusted platform, and the signature parameters are the public key of the wallet application and its corresponding identification information; The data sending module is configured to, in response to a transaction request of a second terminal, send the target authentication data to the second terminal, so that the second terminal verifies the target authentication data; the second terminal and the first terminal correspond to different management platforms; The first transaction module is configured to, when the verification is passed, conduct a transaction with the second terminal according to the digital currency in the wallet application.
8. A second terminal, characterized in that, It includes: A transaction request sending module, a second receiving module, a verification module, and a second transaction module; wherein, The transaction request sending module is configured to, in response to a user trigger, send a transaction request to the first terminal; The second receiving module is configured to receive target authentication data sent by the first terminal according to the transaction request, and the target authentication data is generated according to the public key and identification information of the wallet application in the first terminal; the target authentication data includes: authentication data provided by a trusted platform, and any one or both of the following: an authentication certificate of the management platform generated by the public key or data corresponding to the authentication certificate; the authentication data is obtained by signing the public key and the identification information of the wallet application with the private key of the trusted platform, and the signature parameters are the public key of the wallet application and its corresponding identification information; The verification module is configured to verify the target authentication data; The second transaction module is configured to, when the verification is passed, conduct a transaction with the first terminal according to the digital currency in the wallet application of the first terminal.
9. A management system for a digital currency wallet application, characterized in that, It includes: The first terminal according to claim 7, the second terminal according to claim 8, the management platform of the first terminal, and a trusted platform; wherein, The management platform is configured to receive a data generation request sent by the first terminal and forward the data generation request to the trusted platform; the data generation request includes: the public key and identification information of the wallet application in the first terminal; after receiving the authentication data sent by the trusted platform, generate target authentication data according to the authentication data and the data corresponding to its own authentication certificate, and send the target authentication data to the first terminal; the target authentication data includes: the authentication data provided by the trusted platform, and any one or both of the following: the authentication certificate of the management platform generated through the public key or the data corresponding to the authentication certificate; the authentication data is obtained by signing the public key and the identification information of the wallet application with the private key of the trusted platform, and the signature parameters are the public key of the wallet application and its corresponding identification information. The trusted platform is configured to generate authentication data according to the data generation request and send the authentication data to the management platform.
10. The system according to claim 9, wherein The management platform is configured to use the data corresponding to its own authentication certificate and the authentication data as input parameters of the target authentication data to generate the target authentication data.
11. The system according to claim 9, wherein The trusted platform is configured to determine the number of wallet applications corresponding to the management platform according to the number of received data generation requests, and manage the generation of the target authentication data according to the number of wallet applications.
12. An electronic device, characterized in that, Comprising: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-2 or 3-6.
13. A computer-readable medium having a computer program stored thereon, characterized in that, The program, when executed by the processor, implements the method according to any one of claims 1-2 or 3-6.
Citation Information
Patent Citations
Digital currency wallet offline transaction method and system, and user identity identification card
CN111275411A