Authentication method, payment method, device and apparatus
By setting up security chips and device tokens in IoT devices, the device identity and payment information are securely bound together, solving the problem of low transaction security in IoT device payment scenarios, supporting offline transactions and improving convenience.
Patent Information
- Application Number
- CN202210096244.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-01-26
AI Technical Summary
IoT devices offer low transaction security in payment scenarios and cannot support offline transactions, while relying on IC cards leads to complex operations.
By setting up security chips and device tokens in IoT devices, and generating and saving a first token and a second token through the authentication process between the mobile device and the server, the device identity and payment information are securely bound, improving transaction security and supporting offline transactions.
It improves the payment security of IoT devices, supports offline transactions, reduces reliance on IC cards, and enhances transaction convenience and security.
Smart Images

Figure CN114463012B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of payment security, and particularly relates to an authentication method, a payment method, a device and equipment. BACKGROUND
[0002] With the rapid development of the Internet of Things technology, the types of Internet of Things devices in the market are more diversified, the manufacturers are more, and the management is more complex, so that the Internet of Things devices involved in the payment scene are at higher risk.
[0003] The current Internet of Things devices only support online transactions in the payment scene, and the transaction security is low. SUMMARY
[0004] The embodiments of the present application provide an authentication method, a payment method, a device and equipment, which can improve the transaction security of the Internet of Things device in the payment scene.
[0005] In a first aspect, the embodiments of the present application provide an authentication method applied to an Internet of Things device, the Internet of Things device is built-in with a first token, and the method comprises the following steps:
[0006] sending identity information of the Internet of Things device to a mobile device, so that the mobile device sends the identity information and payment information of a user to a first server for authentication;
[0007] receiving first information sent by the first server, the first information comprising a first token and association information between the second token and the identity information and the payment information, wherein the first token is determined by the first server after the identity information is authenticated, and the second token is generated by a second server after the payment information is authenticated;
[0008] storing the first information in a secure chip.
[0009] In some embodiments, the Internet of Things device is provided with a secure chip,
[0010] Before the identity information of the Internet of Things device is sent to the mobile device, the method further comprises the following steps:
[0011] generating a pair of keys through the secure chip, the keys comprising a first public key and a first private key;
[0012] sending the first public key to the first server;
[0013] sending the identity information of the Internet of Things device to the mobile device, comprising:
[0014] encrypting the identity information through the first private key and sending the encrypted identity information to the mobile device, so that the mobile device sends the identity information to the first server, and the first server authenticates the identity information through the first public key.
[0015] In some embodiments, the first token is stored in the secure chip in an encrypted manner.
[0016] In some embodiments, the payment information corresponds to one or more payment cards, and the second token is one or more, and the second token corresponds to the payment card one by one.
[0017] In a second aspect, the embodiments of the present application provide an authentication method, applied to a first server, and the method comprises:
[0018] receiving identity information of the Internet of Things device and payment information of the user sent by the mobile device;
[0019] authenticating the identity information through a preset rule;
[0020] after the identity information is authenticated, sending the payment information to a second server for authentication;
[0021] receiving a second token sent by the second server, the second token being generated by the second server after the payment information is authenticated;
[0022] sending, to the Internet of Things device and the mobile device, association information obtained by associating the first token and the second token with the identity information and the payment information.
[0023] In some embodiments, the identity information is information encrypted by a first private key, and the first private key is generated by a secure chip of the Internet of Things device.
[0024] authenticating the identity information through a preset rule, comprising:
[0025] authenticating the identity information through a first public key, the first public key being generated by the secure chip and corresponding to the first private key.
[0026] In some embodiments, before receiving the identity information of the Internet of Things device and the payment information of the user sent by the mobile device, the method further comprises:
[0027] receiving a first public key sent by the Internet of Things device;
[0028] saving the first public key.
[0029] In some embodiments, the payment information corresponds to one or more payment cards, and the second token is one or more, and the second token corresponds to the payment card one by one.
[0030] In a third aspect, the embodiments of the present application provide an authentication method, applied to a mobile device, and the method comprises:
[0031] obtaining identity information of the Internet of Things device and payment information of the user, the Internet of Things device being built-in with a first token;
[0032] The identity information and the payment information are sent to the first server, so that the first server sends the payment information to the second server for authentication after the identity information is authenticated;
[0033] The second information sent by the first server is received, and the second information includes a first token, a second token, and association information between the identity information and the payment information, wherein the first token is determined by the first server according to the identity information, and the second token is generated by the second server after the payment information is authenticated.
[0034] In some embodiments, the identity information of the Internet of Things device and the payment information of the user are obtained, comprising:
[0035] An identification code of the Internet of Things device is obtained, and the identification code includes the identity information of the Internet of Things device and a page address;
[0036] According to the identification code, the identity information is parsed and obtained, and the first interface corresponding to the page address is jumped to;
[0037] The payment information input by the user from the first interface is received.
[0038] In some embodiments, the security chip is arranged in the Internet of Things device, and the first token is stored in the security chip.
[0039] In some embodiments, the payment information corresponds to one or more payment cards, and the second token is one or more, and the second token corresponds to the payment card one by one.
[0040] In a fourth aspect, the embodiments of the present application provide a payment method applied to a first server, and the method comprises:
[0041] A transaction request sent by an Internet of Things device is received, and the transaction request includes transaction information corresponding to a transaction event, a first token and identity information of the Internet of Things device, and the transaction information includes payment information;
[0042] The first token is parsed from the transaction request;
[0043] According to the first token and pre-stored mapping information in the first server, a corresponding second token is determined, and the pre-stored mapping information is association information between the first token, the second token, the identity information and the payment information;
[0044] The second token and the transaction information are sent to the second server, so that the second server verifies the payment information corresponding to the second token, and the balance deduction operation of the corresponding transaction event is performed by a third server based on the payment information and the balance change information is generated;
[0045] The balance change information sent by the second server is received to be forwarded to the Internet of Things device.
[0046] In some embodiments, the transaction request is information encrypted by a first private key on the Internet of Things device, the first private key being generated by a security chip of the Internet of Things device;
[0047] The first token is parsed from the transaction request, including:
[0048] The transaction request is decrypted by the first public key to parse the first token from the transaction request, the first public key being generated by the security chip and corresponding to the first private key.
[0049] In a fifth aspect, the embodiments of the present application provide an authentication device applied to a mobile device, the device comprising:
[0050] The first obtaining module is configured to obtain identity information of the Internet of Things device and payment information of a user, the Internet of Things device being built-in with a first token;
[0051] The first sending module is configured to send the identity information and the payment information to a first server, so that the first server sends the payment information to a second server for authentication after the identity information is authenticated by the first server;
[0052] The first receiving module is configured to receive first information sent by the first server, the first information comprising the first token, a second token and association information between the identity information and the payment information, wherein the first token is determined by the first server according to the identity information, and the second token is generated by the second server after the payment information is authenticated by the second server.
[0053] In a sixth aspect, the embodiments of the present application provide an authentication device applied to an Internet of Things device, the Internet of Things device being built-in with a first token, and the device comprising:
[0054] The second sending module is configured to send identity information of the Internet of Things device to the mobile device, so that the mobile device sends the identity information and payment information of a user to a first server for authentication;
[0055] The second receiving module is configured to receive second information sent by the first server, the second information comprising the first token, a second token and association information between the identity information and the payment information, wherein the first token is determined by the first server after the identity information is authenticated by the first server, and the second token is generated by the second server after the payment information is authenticated by the second server.
[0056] The saving module is configured to save the second information in the security chip.
[0057] In a seventh aspect, the embodiments of the present application provide an authentication device applied to a first server, and the device comprising:
[0058] The third receiving module is configured to receive identity information of the Internet of Things device and payment information of a user sent by the mobile device.
[0059] The first authentication module is configured to authenticate the identity information according to a preset rule.
[0060] The third sending module is configured to send the payment information to the second server for authentication after the identity information is authenticated.
[0061] The fourth receiving module is configured to receive a second token sent by the second server, the second token being generated by the second server after the payment information is authenticated.
[0062] The fourth sending module is configured to send the association information of the first token and the second token after being associated with the identity information and the payment information to the Internet of Things device and the mobile device.
[0063] In an eighth aspect, an embodiment of the present application provides a payment device applied to a first server, and the device comprises:
[0064] The fifth receiving module is configured to receive a transaction request sent by the Internet of Things device, the transaction request comprising transaction information corresponding to a transaction event, a first token of the Internet of Things device and identity information, and the transaction information comprising payment information.
[0065] The first parsing module is configured to parse the first token from the transaction request.
[0066] The determining module is configured to determine a corresponding second token according to the first token and preset mapping information in the first server, the preset mapping information being association information of the first token, the second token, the identity information and the payment information.
[0067] The fifth sending module is configured to send the second token and the transaction information to the second server, so that, after the second server verifies that the payment information corresponding to the second token is correct, the third server performs a balance deduction operation on the transaction event based on the payment information and generates balance change information.
[0068] The sixth receiving module is configured to receive the balance change information sent by the second server and forward the balance change information to the Internet of Things device.
[0069] In a ninth aspect, an embodiment of the present application provides an electronic device, and the device comprises a processor and a memory storing computer program instructions.
[0070] The processor executes the computer program instructions to implement the method of any embodiment of the first aspect, the second aspect, the third aspect or the fourth aspect.
[0071] In a tenth aspect, a computer storage medium is provided, and the computer storage medium stores computer program instructions. When the computer program instructions are executed by a processor, the method in any of the embodiments of the first aspect, the second aspect, the third aspect, or the fourth aspect is implemented.
[0072] In an eleventh aspect, a computer program product is provided, and instructions in the computer program product are executed by a processor of an electronic device, so that the electronic device performs the method in any of the embodiments of the first aspect, the second aspect, the third aspect, or the fourth aspect.
[0073] The embodiments of the present application provide an authentication method, a payment method, a device and equipment. In the authentication method, identity information of an Internet of Things device and payment information of a user are acquired by a mobile device, the Internet of Things device is internally provided with a first token; the identity information and the payment information are sent to a first server, so that the first server, after passing the authentication of the identity information, sends the payment information to a second server for authentication; the second server generates a second token and sends the second token to the first server after passing the authentication of the payment information, and generates first information and second information based on association information between the first token, the second token and the payment information, and sends the first information and the second information to the mobile device and the Internet of Things device respectively, so as to complete the authentication. The first token is a device token of the Internet of Things device, and the second token is a business token corresponding to the payment information. In the payment process, the transaction security can be improved based on the binding relationship between the token and the payment information. BRIEF DESCRIPTION OF DRAWINGS
[0074] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. Those skilled in the art can also obtain other drawings according to these drawings without creating any creative labor.
[0075] Figure 1 FIG. 1 is a flowchart of an authentication method provided by an embodiment of the present application;
[0076] Figure 2 FIG. 2 is a flowchart of an authentication method in a specific example of the present application;
[0077] Figure 3 FIG. 3 is a flowchart of an authentication method provided by another embodiment of the present application;
[0078] Figure 4 FIG. 4 is a flowchart of an authentication method provided by another embodiment of the present application;
[0079] Figure 5 FIG. 5 is a flowchart of an authentication method provided by another embodiment of the present application;
[0080] Figure 6 is a flowchart of a payment method according to an embodiment of the present application;
[0081] Figure 7 is a flowchart of a payment method according to an embodiment of the present application;
[0082] Figure 8 is a structural diagram of an authentication device according to an embodiment of the present application;
[0083] Figure 9 is a structural diagram of an authentication device according to another embodiment of the present application;
[0084] Figure 10 is a structural diagram of an authentication device according to still another embodiment of the present application;
[0085] Figure 11 is a structural diagram of a payment device according to an embodiment of the present application;
[0086] Figure 12 is a structural diagram of an electronic device according to yet another embodiment of the present application. DETAILED DESCRIPTION
[0087] The features and exemplary embodiments of the various aspects of the present application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely intended to explain the present application, and are not intended to limit the present application. The present application can be implemented without some of the specific details described below. The following description of the embodiments is merely provided to give a better understanding of the present application by showing examples of the present application.
[0088] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another, without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, an element preceded by "comprises... a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article, or apparatus that comprises the stated elements.
[0089] Currently, the payment method used by the Internet of Things device in the payment scenario is that the Internet of Things device sends a payment request containing device identification and payment amount to a server, and the server queries the associated payment account according to the device identification and deducts the payment amount from the payment account.
[0090] The payment method has the disadvantages of low payment security and inability of the Internet of Things device to have independent payment capability.
[0091] In addition, the current Internet of Things device only supports online transactions in the payment scenario and cannot support offline transactions without the participation of a POS (Point of Sales) device. Because of the current payment technology, the Internet of Things device needs to rely on an IC card (Integrated Circuit Card) for offline transactions, and needs to initiate a transaction based on the IC card with the help of a POS device, which reduces the convenience of front-end operation and increases the complexity of the operation process.
[0092] To solve the problems in the prior art, the embodiments of the present application provide an authentication method, a payment method, a device and an apparatus. The security chip and the device token provided in the Internet of Things device are used to realize secure payment. First, the authentication method provided by the embodiments of the present application is introduced.
[0093] Figure 1 A flowchart of the authentication method provided by an embodiment of the present application is shown. As shown in Figure 1 The authentication method is applied to an Internet of Things device, the Internet of Things device has a first token built-in, and the method includes steps S101-S103:
[0094] S101. Provide identity information of the Internet of Things device to a mobile device, so that the mobile device sends the identity information and payment information of a user to a first server for authentication.
[0095] S102. Receive first information sent by the first server, the first information including association information between the first token, the second token and the payment information, wherein the first token is determined by the first server after the identity information is authenticated, and the second token is generated by the second server after the payment information is authenticated.
[0096] S103. Save the first information.
[0097] In the authentication method of the embodiments of the present application, the identity information of the Internet of Things device and the payment information of the user are acquired by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, that is, the token of the Internet of Things device does not need to be transmitted, and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined; then the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is returned to the first server after the authentication is passed, and the binding of the corresponding Internet of Things device is completed by the first server, that is, the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment is realized, authentication between the device token (i.e. the first token, the same below) of the Internet of Things device and the server is completed to ensure the security of subsequent payment.
[0098] In some specific embodiments, in order to enhance the payment security, the hardware capability of the Internet of Things device can be increased. Optionally, in the embodiments of the present application, the processor of the Internet of Things device, such as MCU (Micro Controller Unit), is connected with the secure chip SE (Secure Element), and the secure chip SE is pre-stored with a security domain to establish the security basis of the Internet of Things device.
[0099] It can be understood that the security domain can be verified for legality and security by the server to which the Internet of Things device belongs, and the verification of the security domain can adopt mature technologies in the art, which will not be described here.
[0100] For example, the secure chip SE of the Internet of Things device can be used as the transaction security shield of the device, and the hardware capability of the Internet of Things device is improved based on the high security performance of the secure chip SE. The first token is stored in the secure chip SE in an encrypted manner, and the first token is used as the device token of the Internet of Things device and can be pre-stored in the Internet of Things device together with the secure chip before the device is put into use, such as being injected by a payment card manufacturer or an Internet of Things device manufacturer.
[0101] The first token, i.e. the device token of the Internet of Things device, has a unique correspondence with the Internet of Things device, and each Internet of Things device has a device token, so that the device token of the Internet of Things device is unique in the global.
[0102] Optionally, after the security domain of the secure chip SE is verified, the authentication method of the embodiments of the present application can further include S104-S105 before step S101:
[0103] S104. Generating a pair of keys by the secure chip, the keys comprising a first public key and a first private key;
[0104] S105. Sending the first public key to the first server.
[0105] For example, the secure chip SE generates a pair of asymmetric keys, the keys comprising a first public key and a first private key, wherein the first private key is stored in the secure chip, and the first public key is sent to the first server for storage.
[0106] Thus, in step S101, the identity information of the Internet of Things device is provided to the mobile device, which can specifically include:
[0107] The identity information is encrypted by the first private key and sent to the mobile device, so that after the mobile device sends the identity information to the first server, the identity information is authenticated by the first public key.
[0108] In step S101, the Internet of Things identity information can include one or more of a device ID (Identity Document, identity code), a device manufacturer ID, and a device chip ID (i.e. a chip serial number corresponding to the above-mentioned MCU on the device). In some examples, when the identity information of the Internet of Things device is provided to the mobile device, the identity information of the Internet of Things device can be obtained by displaying an identification code of the Internet of Things device for the mobile device to obtain, or the Internet of Things device provides an MCU access interface for the mobile device to obtain the identity information of the Internet of Things device.
[0109] As shown in the reference Figure 2 When the identity information is provided by the identification code, the identification code can include request information, so that the mobile device scans the identification code to initiate a request to the Internet of Things device, and then the Internet of Things device returns the identity information to the mobile device based on the request, and the mobile device receives the identity information and obtains the payment information input by the user through the first interface.
[0110] The identification code can include identity information such as the device ID and the device manufacturer ID of the Internet of Things device and a page address link. The mobile device obtains the identity information of the Internet of Things device by scanning the identification code, and jumps to the first interface corresponding to the page address to receive the payment information input by the user from the first interface.
[0111] Or the Internet of Things device provides an MCU access interface, and the mobile device obtains the identity information of the Internet of Things device through the access interface, and then obtains the payment information input by the user through the first interface.
[0112] Exemplarily, the identification code can be a two-dimensional code, or other forms of graphical code; the identification code can be a static code, or a dynamic code; the identification code can be displayed on a display screen of the Internet of Things device, or displayed in other forms; the embodiments of the present application are not limited to the above.
[0113] Exemplarily, the identity information acquired by the mobile device is information encrypted by the first private key stored in the secure chip SE of the Internet of Things device, which can avoid the risk of malicious analysis attack caused by information leakage during information transmission in the authentication process.
[0114] Exemplarily, the payment information input by the user can include one or more of the card number of the payment card (such as a bank card), the anti-counterfeit code (such as the security code CVN2, Card Validation Number 2), and the verification code. In one specific example, the payment information can include one or more payment cards.
[0115] In the embodiments of the present application, by Figure 2 In step S203 shown in FIG. 2, the mobile device sends the identity information of the Internet of Things device and the payment information of the user to the first server, and the first server authenticates the legality of the identity information. After the identity information of the Internet of Things device is authenticated, the second server authenticates the payment of the user.
[0116] Exemplarily, the first server can be an Internet of Things device management platform. The first server pre-stores in the database the mapping relationship between the Internet of Things device and the first public key and the device Token corresponding thereto. Referring to Figure 2 When the first server receives the identity information of the Internet of Things device sent by the mobile terminal, in step S204, the identity information is decrypted and authenticated by the first public key. If the decryption is successful, the identity of the Internet of Things device is legal, and the authentication is passed. Otherwise, it is illegal, and the authentication of the Internet of Things identity fails.
[0117] In step S204, after the first server authenticates the identity information of the Internet of Things device, the first token corresponding to the Internet of Things device is determined based on the parsed identity information. At the same time, in step S205, the first server also sends the payment information of the user to the second server. Exemplarily, the second server can be a transaction platform of the operating party of the payment card (such as the UnionPay transaction platform corresponding to the UnionPay card). The second server verifies the card number, the anti-counterfeit code, and the verification code in the payment information to confirm the legality of the payment information.
[0118] It can be understood that the authentication of the legality of the payment card by the server corresponding to the operating party of the payment card is a mature technology in the art, which will not be described here.
[0119] Referring toFigure 2 After the second server authenticates the payment information of the user to be legal through step S206, the second server generates a second token corresponding to the payment information. For example, the second token is a business token, and the second token has a one-to-one correspondence with the payment card in the payment information. When the payment information includes information of one payment card, one first token can be generated. When the payment information includes information of multiple payment cards, multiple second tokens can be generated respectively corresponding to the payment cards.
[0120] Through step S207, the second token generated by the second server is returned to the first server. Through step S208, the first server binds the first token corresponding to the Internet of Things device determined above, the second token returned by the second server, and the corresponding identity information and payment information, generates corresponding association information, and stores the association information in the first server. In the association information, one first token can correspond to one or more second tokens, that is, in the embodiment of the application, one Internet of Things device is allowed to bind multiple payment cards for subsequent transactions, which meets the multi-card payment needs of the user. In one example, in order to improve the convenience of subsequent payment, one of the payment cards can be set as a default payment card in the binding process of the association information, and the corresponding default payment card can be marked in the association information.
[0121] After the first server generates the association information, the Internet of Things device receives the association information (i.e., the first information) sent by the first server through step S102, and securely saves the first information in the Internet of Things device through step S103. The association information can also be sent to the mobile device and displayed to the user.
[0122] In the embodiment of the application, the first information is securely saved in the Internet of Things device, and the payment information in the first information saved in the secure chip SE can be used to initiate transaction payment in a subsequent payment scenario. The Internet of Things device has a hardware capability for secure payment, expands the transaction attribute of the Internet of Things device, and improves the secure payment capability of the device. In this way, the Internet of Things device authenticated by the identity information and the payment information can have a separate payment capability in the subsequent payment process. On the one hand, compared with traditional online transactions, the Internet of Things device in the embodiment of the application can initiate transaction payment based on the hardware foundation established by the secure chip according to the payment information and the first token authenticated by the platform, which ensures transaction security and avoids the risk of malicious cracking of information in the transmission process. On the other hand, the first information authenticated by the authentication method of the embodiment of the application is saved in the Internet of Things device and used in the subsequent transaction payment scenario. Compared with traditional offline transactions relying on IC cards, the Internet of Things device in the embodiment of the application can initiate transactions based on payment information of payment cards without relying on physical card bodies of IC cards, which is conducive to improving transaction convenience.
[0123] Optionally, to meet the various needs of users, the embodiments of the present application can also allow the user to update the payment information stored in the Internet of Things device. Specifically, in the embodiments of the present application, if the user needs to add a new payment card to the Internet of Things device for request authentication binding, or wants to delete the bound payment card, the authentication method can also include steps S301-S303 as shown in the following table: Figure 3
[0124] S301. Provide the identity information and payment information of the Internet of Things device to the mobile device, so that the mobile device generates updated payment information according to the payment information, and sends the updated payment information and identity information to the first server for authentication.
[0125] The mobile terminal can access the MCU access interface of the Internet of Things device by scanning the identification code to obtain the identity information of the Internet of Things device, and jump to the second interface to display the payment information of the existing payment card stored on the Internet of Things device.
[0126] The user can generate corresponding updated payment information by inputting new payment cards or deleting payment cards and other operations based on the payment information displayed on the second interface of the mobile device. For example, the second interface displays the payment information of the originally set payment card 1, the user inputs the payment information of payment card 2 and payment card 3 on the second interface, and marks the payment information of payment card 2 with the mark of the default payment card, deletes the payment information of payment card 1, and generates updated payment information corresponding to payment card 2 and payment card 3. The mobile device sends the identity information and updated payment information to the first server for authentication.
[0127] S302. Receive the third information sent by the first server, the third information including the association information between the first token, the third token, the identity information and the updated payment information, wherein the first token is determined by the first server after the identity information is authenticated, and the third token is generated by the second server after the updated payment information is authenticated.
[0128] S303. Save the third information.
[0129] In this embodiment, the authentication process of the first server to the identity information of the Internet of Things device is the same as the identity information authentication process in the above embodiment, the authentication process of the second server to the updated payment information is the same as the authentication process of the payment information in the above embodiment, the second server generates a new technical token, i.e., a third token, after the authentication of the updated payment information, returns to the second server, and the first token, the third token, the identity information and the updated payment information are bound by the second server to generate new association information (i.e., third information), which is sent to the Internet of Things device for storage and sent to the mobile device for display to the user.
[0130] Figure 4 A flowchart of an authentication method provided by an embodiment of the application is shown. As shown in the flowchart, the authentication method is applied to a first server, and the method comprises steps S401-S405: Figure 4
[0131] S401. Receiving identity information of an Internet of Things device and payment information of a user sent by a mobile device;
[0132] S402. Authenticating the identity information through a preset rule;
[0133] S403. After the identity information is authenticated, sending the payment information to a second server for authentication;
[0134] S404. Receiving a second token sent by the second server, the second token being generated by the second server after the authentication of the payment information;
[0135] S405. Sending association information obtained by associating a first token and the second token with the identity information and the payment information to the Internet of Things device and the mobile device.
[0136] In the embodiment of the present application, the first server can be an Internet of Things device management platform, and the first server can uniformly manage a plurality of Internet of Things devices. In the authentication method of the present application, the identity information of the Internet of Things device and the payment information of the user are obtained by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, that is, the token of the Internet of Things device does not need to be transmitted, and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined; then the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is generated and returned to the first server after the authentication is passed, and the binding of the corresponding Internet of Things device is completed by the first server, that is, the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment, authentication is completed between the device token (i.e. the first token, the same below) of the Internet of Things device and the server, and the security of subsequent payment is guaranteed.
[0137] Optionally, in order to enhance the payment security, the processor of the Internet of Things device, such as MCU (Micro Controller Unit), is connected with the secure chip SE (Secure Element), and the secure chip SE is pre-stored with a security domain to establish the security basis of the Internet of Things device.
[0138] For example, the secure chip SE of the Internet of Things device can be used as the transaction security shield of the device, and based on the high security performance of the secure chip SE, the hardware capability of the Internet of Things device is improved. The first token is stored in the secure chip SE in an encrypted manner. The first token has a unique correspondence with the Internet of Things device, and each Internet of Things device has a device token, that is, the device token of the Internet of Things device has global uniqueness.
[0139] In addition to securely storing the first token, the secure chip of the Internet of Things device is also used to generate a pair of asymmetric keys. The keys include a first public key and a first private key, the first private key is stored in the secure chip, and the first public key is sent to the first server for storage. Therefore, before step S401, the method can further include:
[0140] receiving the first public key sent by the Internet of Things device;
[0141] storing the first public key.
[0142] The mapping between the identity information of the Internet of Things device and the first token thereof can be pre-stored in the database in the first server, and after receiving the first public key, the first public key and the corresponding identity information of the Internet of Things device are associated and stored.
[0143] After the first server saves the first public key, the first server receives the identity information of the Internet of Things device and the payment information of the user sent by the mobile device through step S401. The identity information of the Internet of Things device can include a device ID (Identity Document), a device manufacturer ID, and a device chip ID. The payment information of the user can include one or more of the card number of a payment card (such as a bank card), an anti-counterfeit code (such as a security code CVN2, Card Validation Number 2), and a verification code. In one specific example, the payment information can include one or more payment cards.
[0144] For example, in order to improve the security of the authentication information, the identity information can be information encrypted by a first private key stored in a secure chip of the Internet of Things device. After receiving the identity information of the Internet of Things device and the payment information of the user, the first server can authenticate the identity information through a predetermined rule through step S402. Specifically, step S402 can include:
[0145] authenticating the identity information through a first public key, wherein the first public key is generated for the secure chip and corresponds to the first private key.
[0146] The identity information encrypted by the first private key is a piece of ciphertext. If the ciphertext can be decrypted by the first public key corresponding to the first private key, the identity of the Internet of Things device is legal, and the authentication is passed. If the decryption fails, the identity of the Internet of Things device is not legal, and the authentication of the Internet of Things identity fails.
[0147] After authenticating the legal identity of the Internet of Things device, the plaintext of the identity information is decrypted, and the first server can match the corresponding first token from the database based on the plaintext. And the first server sends the payment information to the second server through step S403 for authentication. In one example, the second server can be a transaction platform of the operating party of the payment card (such as the UnionPay transaction platform corresponding to the UnionPay card). The second server verifies the card number, anti-counterfeit code, and verification code in the payment information to confirm the legality of the payment information.
[0148] After the second server authenticates the legal payment information of the user, the second server generates a second token corresponding to the payment information. For example, the second token serves as a business Token and has a one-to-one correspondence with the payment card in the payment information. When the payment information includes information of one payment card, one first token can be generated. When the payment information includes information of multiple payment cards, multiple second tokens can be generated corresponding to the payment cards.
[0149] After the second server generates the second token, the first server receives the second token sent by the second server through step S404, and binds the first token and the second token with the decrypted identity information and the payment information to generate corresponding association information, which is saved in the database of the first server and sent to the Internet of Things device and the mobile device through step S405. The Internet of Things device saves the association information to initiate subsequent transaction payment based on the association information, and the mobile device can display the association information to the user for viewing.
[0150] In the embodiment of the application, the identity information of the Internet of Things device is authenticated by the first server, and then the payment information is authenticated by the second server, thereby ensuring the security of the information. The identity information and the payment information of the Internet of Things device are associated with the unique device token of the Internet of Things device and fed back to the Internet of Things device for storage. In this way, in a subsequent payment scenario, transaction payment can be initiated by the payment information saved in the security chip SE of the Internet of Things device, so that the Internet of Things device has a separate payment capability. On the one hand, compared with traditional online transactions, the Internet of Things device in the embodiment of the application can initiate transaction payment based on the hardware foundation established by the security chip according to the payment information and the first token authenticated by the platform, thereby ensuring the security of the transaction and avoiding the risk of malicious cracking of the information in the transmission process. On the other hand, the association information authenticated by the authentication method in the embodiment of the application is saved in the Internet of Things device and used in a subsequent transaction payment scenario. Compared with traditional offline transactions that rely on IC cards, the Internet of Things device in the embodiment of the application can initiate transactions based on the payment information of the payment card without relying on the physical card body of the IC card, thereby improving the convenience of transactions.
[0151] Optionally, to meet the needs of users, the authentication method in the embodiment of the application can also allow the user to update the payment information saved in the Internet of Things device. Specifically, in the embodiment of the application, if the user needs to add a new payment card to the Internet of Things device and request authentication and binding, or wants to delete the bound payment card, the authentication method can further include steps S406-S410:
[0152] S406. Receive the identity information of the Internet of Things device and the updated payment information of the user sent by the mobile device.
[0153] The mobile terminal can obtain the identity information of the Internet of Things device by scanning the identification code or accessing the MCU access interface of the Internet of Things device, and jump to the second interface to display the payment information of the existing payment card saved on the Internet of Things device.
[0154] The user can generate corresponding updated payment information on the basis of the payment information displayed on the second interface of the mobile device by inputting new payment cards or deleting payment cards, and send the identity information and the updated payment information to the first server for authentication.
[0155] S407. authenticating the identity information through a preset rule;
[0156] S408. sending the updated payment information to the second server for authentication after the identity information is authenticated;
[0157] S409. receiving a third token sent by the second server, the third token being generated after the second server authenticates the updated payment information;
[0158] S410. sending the association information after the first token and the third token are associated with the identity information and the updated payment information to the Internet of Things device and the mobile device.
[0159] In the embodiment, the authentication process of the first server on the identity information of the Internet of Things device is the same as the authentication process of the identity information in step S402 of the above embodiment, the authentication process of the second server on the updated payment information is the same as the authentication process of the payment information in the above embodiment, the second server generates a new technical token, i.e. the third token, after the authentication of the updated payment information is passed, returns to the second server, and the first token, the third token, the identity information and the updated payment information are bound by the second server to generate new association information (i.e. the third information), which is sent to the Internet of Things device for storage and sent to the mobile device for display to the user.
[0160] Figure 5 A flowchart of an authentication method provided by an embodiment of the application is shown. As shown in Figure 5 The method is applied to a mobile device, and the method comprises steps S501-S503.
[0161] S501. obtaining identity information of an Internet of Things device and payment information of a user, the Internet of Things device being built-in with a first token;
[0162] S502. sending the identity information and the payment information to a first server, so that the first server authenticates the identity information and sends the payment information to a second server for authentication after the identity information is authenticated;
[0163] S503. receiving the second information sent by the first server, the second information comprising a first token and association information between the second token and the payment information and the identity information, wherein the first token is determined by the first server according to the identity information, and the second token is generated by the second server after the payment information is authenticated.
[0164] In the authentication method of the embodiments of the present application, the identity information of the Internet of Things device and the payment information of the user are obtained by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, i.e., the token of the Internet of Things device does not need to be transmitted and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined. Then, the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is returned to the first server after the authentication is passed. The first server completes the binding of the corresponding Internet of Things device, i.e., the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment, authentication is completed between the device token (i.e., the first token, the same below) of the Internet of Things device and the server, which guarantees the security of subsequent payment.
[0165] For example, in order to enhance the security of payment, the processor of the Internet of Things device, such as MCU (Micro Controller Unit), is connected with the secure chip SE (Secure Element). The secure chip SE is pre-stored with a security domain to establish the security foundation of the Internet of Things device.
[0166] For example, the secure chip SE of the Internet of Things device can be used as the transaction security shield of the device, based on its own high security performance, to improve the hardware capability of the Internet of Things device. The first token is stored in the secure chip SE in an encrypted manner. The first token has a unique correspondence with the Internet of Things device, and each Internet of Things device has a device token, i.e., the device token of the Internet of Things device has global uniqueness.
[0167] In addition to the first token stored in the secure chip in a secure manner, the secure chip is also used to generate a key, which is an asymmetric key. The key comprises a first public key and a first private key. The first private key is stored in the secure chip, and the first public key is sent to the first server for storage. Therefore, in step S501, the identity information of the Internet of Things device and the payment information of the user are obtained. The identity information can be encrypted information encrypted by the first private key in the secure chip of the Internet of Things device, which can avoid the risk of information leakage and malicious analysis attack during information transmission in the authentication process.
[0168] For example, the payment information input by the user can include one or more of a card number of a payment card (such as a bank card), an anti-counterfeit code (such as a security code CVN2, Card Validation Number 2), and a verification code.
[0169] In some examples, when the mobile device acquires the identity information of the Internet of Things device, the identity information of the Internet of Things device can be acquired through identification code analysis of the identity information of the Internet of Things device, or through an MCU access interface provided by the Internet of Things device.
[0170] Optionally, if the identity information of the Internet of Things device is acquired through identification code analysis of the identity information of the Internet of Things device, the identification code can include acquisition request information, so that the mobile device initiates a request to the Internet of Things device by scanning the identification code, and then the Internet of Things device returns the identity information to the mobile device based on the request, and the mobile device receives the identity information and acquires the payment information input by the user through the first interface.
[0171] Alternatively, optionally, the identification code can include identity information such as a device ID and a device manufacturer ID of the Internet of Things device and a page address link, and step S501 can specifically include steps S5011-S5013:
[0172] S5011. Acquire the identification code of the Internet of Things device, the identification code including identity information of the Internet of Things device and a page address;
[0173] S5012. According to the identification code, analyze the identity information and jump to the first interface corresponding to the page address;
[0174] S5013. Receive payment information input by the user from the first interface.
[0175] The mobile device acquires the identity information of the Internet of Things device by scanning the identification code, and jumps to the first interface corresponding to the page address to receive the payment information input by the user from the first interface. This embodiment can improve the convenience of payment information input through the code scanning input mode.
[0176] For example, the identification code can be a two-dimensional code or other forms of graphical code; the identification code can be a static code or a dynamic code; the identification code can be displayed on the display screen of the Internet of Things device or other forms; the embodiments of the present application are not limited to this.
[0177] After the mobile device acquires the identity information and the payment information, the mobile device sends the identity information and the payment information to the first server through step S502. In the first server, the legality of the identity information is first authenticated. After the identity information of the Internet of Things device is authenticated, the first server sends the payment information to the second server, and the payment of the user is authenticated through the second server.
[0178] For example, the first server can be an Internet of Things device management platform. The first server pre-stores a mapping relationship between the Internet of Things device and the first public key and the device token corresponding to the Internet of Things device in the database. When the first server receives the identity information of the Internet of Things device sent by the mobile terminal, the identity information is decrypted and authenticated through the first public key. If the decryption is successful, the identity of the Internet of Things device is legal, and the authentication is passed. Otherwise, the identity of the Internet of Things device is illegal, and the authentication fails.
[0179] After the first server authenticates the identity information of the Internet of Things device, the first token corresponding to the Internet of Things device is determined based on the parsed identity information. At the same time, the first server also sends the payment information of the user to the second server. For example, the second server can be a transaction platform of an operating party of a payment card (such as a UnionPay transaction platform corresponding to a UnionPay card). The second server verifies the card number, the anti-fake code, and the verification code in the payment information to confirm the legality of the payment information.
[0180] After the second server authenticates that the payment information of the user is legal, the second token corresponding to the payment information is generated. For example, the second token, as a business token, has a one-to-one correspondence with the payment card in the payment information. When the payment information includes information of one payment card, one first token can be generated. When the payment information includes information of multiple payment cards, multiple second tokens can be generated corresponding to the payment cards.
[0181] The second token generated by the second server is returned to the first server. The first token corresponding to the Internet of Things device determined above, the second token returned by the second server, and the corresponding identity information and payment information are bound by the first server to generate corresponding association information. Then, the mobile device can receive the second information (i.e., the association information) sent by the first server through step S503, and display the second information for the user to view.
[0182] In the second information, one first token can correspond to one or more second tokens, that is, in the embodiment of the present application, one Internet of Things device is allowed to bind multiple payment cards for subsequent transactions to meet the multi-card payment needs of the user. In one example, to improve the convenience of subsequent payment, one of the payment cards can be set as a default payment card during the binding of the above association information, and the corresponding default payment card can be marked in the association information.
[0183] In the embodiments of the present application, based on the authentication method between the Internet of Things device implemented by the mobile device and the platform, the payment information in the associated information saved in the secure chip SE can be used to initiate transaction payment in the subsequent payment scene. In this way, the Internet of Things device authenticated by the identity information and the payment information can have individual payment capability in the subsequent payment process. On the one hand, compared with traditional online transactions, the Internet of Things device in the embodiments of the present application can initiate transaction payment based on the hardware foundation established by the secure chip according to the payment information and the first token authenticated by the platform, which is saved securely, to ensure transaction security and avoid the risk of malicious cracking attack of transaction information in the transmission process. On the other hand, the associated information authenticated by the authentication method in the embodiments of the present application is saved in the Internet of Things device, which is used in the scene of subsequent transaction payment. Compared with traditional offline transactions relying on IC cards, the Internet of Things device in the embodiments of the present application can initiate transactions based on the payment information of the payment card, which can be independent of the dependence on the physical card body of the IC card in the front end, thereby improving the convenience of transactions.
[0184] Optionally, to meet the various needs of users, the embodiments of the present application can also allow users to update the payment information saved in the Internet of Things device. Specifically, in the embodiments of the present application, if a user needs to add a new payment card to the Internet of Things device for request authentication and binding, or wants to delete the bound payment card, the authentication method can further include steps S504-S506:
[0185] S504. Obtain the identity information of the Internet of Things device and the updated payment information of the user, wherein the Internet of Things device is built-in with a first token;
[0186] S505. Send the identity information and the updated payment information to the first server, so that the first server sends the updated payment information to the second server for authentication after the identity information is authenticated;
[0187] S303. Receive the fourth information sent by the first server, wherein the fourth information includes the first token and the associated information between the third token and the identity information and the updated payment information, wherein the first token is determined by the first server according to the identity information, and the third token is generated by the second server after the updated payment information is authenticated.
[0188] The mobile terminal can obtain the identity information of the Internet of Things device by scanning the identification code or accessing the MCU access interface of the Internet of Things device, and jump to the second interface to display the payment information of the existing payment card saved on the Internet of Things device.
[0189] The user can generate corresponding updated payment information by inputting a new payment card or deleting a payment card and the like on the basis of the payment information displayed on the second interface of the mobile device. The mobile device sends the identity information and the updated payment information to the first server for authentication.
[0190] In the embodiment, the authentication process of the identity information of the Internet of Things device by the first server is the same as the authentication process of the identity information in the above-mentioned embodiments, the authentication process of the updated payment information by the second server is the same as the authentication process of the payment information in the above-mentioned embodiments, and the second server generates a new technical token, i.e., a third token, after the authentication of the updated payment information passes, and returns to the second server. The first token, the third token, the identity information and the updated payment information are bound by the second server to generate new association information (i.e., fourth information), which is sent to the Internet of Things device for storage and sent to the mobile device for display to the user.
[0191] It can be understood that the same association information in the above-mentioned embodiments can be represented by different technical terms after being sent to different devices, for example, the first information and the second information can include the same association information, and the third information and the fourth information can include the same association information.
[0192] Exemplarily, the above-mentioned Internet of Things device can be an electronic license plate.
[0193] After the authentication and binding of the Internet of Things device and the payment information are completed through the information interaction among the Internet of Things device, the mobile device, the first server and the second server, the Internet of Things device can be involved in the transaction payment scene, and the transaction security can be ensured. Therefore, the present application also provides a payment method.
[0194] Figure 6 A flowchart of a payment method provided by an embodiment of the present application is shown. As shown in Figure 6 The method is applied to a first server, and the method includes steps S601-S605:
[0195] S601. receiving a transaction request sent by an Internet of Things device, the transaction request including transaction information of a corresponding transaction event, a first token and identity information of the Internet of Things device, the transaction information including payment information;
[0196] S602. obtaining the first token from the transaction request;
[0197] S603. determining a corresponding second token according to the first token and pre-stored mapping information in the first server, the pre-stored mapping information being association information of the first token, the second token and the payment information;
[0198] S604. Send the second token and the transaction information to the second server, so that after the second server verifies the payment information corresponding to the second token, the third server performs the balance deduction operation for the corresponding transaction event based on the payment information and generates balance change information;
[0199] S605. Receive balance change information sent by the second server and forward it to the IoT device.
[0200] The first server in this application embodiment can be an IoT device management platform. In the payment method of this application embodiment, transaction payment is initiated based on authenticated identity information, payment information, and a first token stored in the security chip. Compared to traditional online transactions, this ensures the legality of transaction information and improves transaction security. Compared to traditional IC card transactions, the method in this application embodiment can realize a transaction process initiated based on payment card information but without relying on the physical card body, thus improving payment convenience.
[0201] Optionally, in the embodiments of this application, reference is made to... Figure 7 As shown, during a transaction, in step S701, the IoT device encapsulates the transaction information of the corresponding transaction event, the first token of the IoT device stored in the security chip, and the identity information to generate a data packet for a transaction request, and sends it to the first server.
[0202] The transaction information may include the time of the current transaction event, the event identifier, payment information (such as the payment information of the default payment card), and the payment amount.
[0203] The transaction request data packet contains transaction information, the first token of the IoT device, and identity information, which can be encrypted using the first private key in the security chip to ensure the security of sensitive information.
[0204] Correspondingly, after receiving the transaction request sent by the IoT device in step S601, the first server parses the first token from the transaction request in step S602, which may specifically include the following steps:
[0205] The transaction request is decrypted using the first public key to parse the first token from the transaction request. The first public key is generated by the security chip and corresponds to the first private key.
[0206] The first server pre-stores association information including a first public key, a first token, a second token, IoT device identity information, and payment information. The first public key is used to decrypt the data packet of the transaction request, revealing the plaintext of the first token, identity information, and transaction information. Then, in step S603, the corresponding second token is determined based on the first token and the pre-stored mapping information in the first server; this pre-stored mapping information is the association information.
[0207] After confirming the second token corresponding to the transaction request, the first server sends a message containing the second token and the transaction information to the second server through step S604. The second server can be a transaction platform of the operating party of the payment card (such as the UnionPay transaction platform corresponding to the UnionPay card). The second server has pre-stored mapping relationship data between the second token and the payment information, and then the second server determines the legality of the corresponding payment information according to the second token in the message through step S702. Figure 7
[0208] After verifying the legality of the payment information, the second server sends the payment amount and the payment information (such as the payment card number) in the transaction information to the third server through step S703. The third server can be a card issuing institution system. The third server performs a balance deduction operation on the corresponding transaction event based on the payment information and the payment amount through step S704, and generates balance change information of the payment card. The third server returns to the second server through steps S705-S707, and the second server returns step by step.
[0209] Therefore, the first server receives the balance change information sent by the second server through step S605 to forward to the Internet of Things device to complete the transaction payment.
[0210] In addition, the term "and / or" in this paper is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.
[0211] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A and can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0212] Figure 8 A structure diagram of an authentication device provided by an embodiment of the present application is shown. As shown in the figure, the device is applied to an Internet of Things device, the Internet of Things device is built-in with a first token, and the device includes: Figure 8
[0213] The first sending module 801 is configured to provide the identity information of the Internet of Things device to the mobile device, so that the mobile device sends the identity information and the payment information of the user to the first server for authentication.
[0214] The first receiving module 802 is configured to receive second information sent by the first server, the second information comprising association information between the first token and the second token and the identity information and the payment information, wherein the first token is determined after the identity information is authenticated by the first server, and the second token is generated after the payment information is authenticated by the second server.
[0215] The saving module 803 is configured to save the first information.
[0216] In the embodiment of the present application, the identity information of the Internet of Things device and the payment information of the user are obtained by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, that is, the token of the Internet of Things device does not need to be transmitted, and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined. Then, the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is generated and returned to the first server after the authentication is passed. The first server completes the binding of the corresponding Internet of Things device, that is, the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment is realized, authentication is completed between the device token (i.e. the first token, the same below) of the Internet of Things device and the server based on the device token, thereby guaranteeing the security of subsequent payment.
[0217] Optionally, in the embodiment of the present application, the processor of the Internet of Things device, such as the MCU (Micro Controller Unit, microcontroller unit), is connected to the security chip SE (Secure Element). The security chip SE is pre-stored with a security domain to establish the security foundation of the Internet of Things device.
[0218] For example, the security chip SE of the Internet of Things device can be used as the transaction security shield of the device, based on its own high security performance, to improve the hardware capability of the Internet of Things device. The first token is encrypted and stored in the security chip SE.
[0219] The first token, i.e. the device Token of the Internet of Things device, has a unique correspondence with the Internet of Things device. Each Internet of Things device has a device Token, so the device Token of the Internet of Things device is unique in the global.
[0220] Optionally, in the embodiment of the present application, the apparatus can further comprise:
[0221] The first generating module is configured to generate a pair of keys by the security chip, the keys comprising a first public key and a first private key.
[0222] The sixth sending module is configured to send the first public key to the first server.
[0223] Correspondingly, the first sending module 801 can be specifically configured to:
[0224] The identity information is encrypted by the first private key and then sent to the mobile device, so that the mobile device sends the identity information to the first server and authenticates the identity information by the first public key.
[0225] For example, the identity information of the Internet of Things can include one or more of a device ID (Identity Document, identity identification code), a device manufacturer ID, and a device chip ID (in this example, the serial number of the chip corresponding to the MCU on the device).
[0226] The payment information input by the user can include one or more of the card number of a payment card (such as a bank card), an anti-counterfeit code (such as a security code CVN2, Card Validation Number 2), and a verification code. In one specific example, the payment information can include one or more payment cards.
[0227] For example, the second token serves as a business token and has a one-to-one correspondence with the payment card in the payment information. When the payment information includes information of one payment card, a first token can be generated. When the payment information includes information of multiple payment cards, multiple second tokens can be generated corresponding to the payment cards.
[0228] Optionally, in the embodiment of the present application, the apparatus can further include:
[0229] The second providing module is configured to provide the identity information of the Internet of Things and the payment information to the mobile device, so that the mobile device generates updated payment information according to the payment information and sends the updated payment information and the identity information to the first server for authentication.
[0230] The seventh receiving module is configured to receive third information sent by the first server, the third information including association information between the first token, the third token, the identity information, and the updated payment information, wherein the first token is determined by the first server after the identity information is authenticated, and the third token is generated by the second server after the updated payment information is authenticated.
[0231] The second saving module is configured to save the third information.
[0232] Figure 9 A structure diagram of an authentication apparatus provided by the embodiment of the present application is shown. As shown in FIG. 8, the authentication apparatus includes a first receiving module 801, a first sending module 802, a first saving module 803, a second receiving module 804, a second sending module 805, a second saving module 806, a third receiving module 807, a third sending module 808, a fourth receiving module 809, a fourth sending module 810, a fifth receiving module 811, a sixth receiving module 812, a seventh receiving module 813, an eighth receiving module 814, a ninth receiving module 815, a tenth receiving module 816, an eleventh receiving module 817, a twelfth receiving module 818, a thirteenth receiving module 819, a fourteenth receiving module 820, a fifteenth receiving module 821, a sixteenth receiving module 822, a seventeenth receiving module 823, an eighteenth receiving module 824, a nineteenth receiving module 825, a twentieth receiving module 826, a twenty-first receiving module 827, a twenty-second receiving module 828, a twenty-third receiving module 829, a twenty-fourth receiving module 830, a twenty-fifth receiving module 831, a twenty-sixth receiving module 832, a twenty-seventh receiving module 833, a twenty-eighth receiving module 834, a twenty-ninth receiving module 835, a thirtieth receiving module 836, a thirty-first receiving module 837, a thirty-second receiving module 838, a thirty-third receiving module 839, a thirty-fourth receiving module 840, a thirty-fifth receiving module 841, a thirty-sixth receiving module 842, a thirty-seventh receiving module 843, a thirty-eighth receiving module 844, a thirty-ninth receiving module 845, a fortieth receiving module 846, a forty-first receiving module 847, a forty-second receiving module 848, a forty-third receiving module 849, a forty-fourth receiving module 850, a forty-fifth receiving module 851, a forty-sixth receiving module 852, a forty-seventh receiving module 853, a forty-eighth receiving module 854, a forty-ninth receiving module 855, a fiftieth receiving module 856, a fifty-first receiving module 857, a fifty-second receiving module 858, a fifty-third receiving module 859, a fifty-fourth receiving module 860, a fifty-fifth receiving module 861, a fifty-sixth receiving module 862, a fifty-seventh receiving module 863, a fifty-eighth receiving module 864, a fifty-ninth receiving module 865, a sixtieth receiving module 866, a sixty-first receiving module 867, a sixty-second receiving module 868, a sixty-third receiving module 869, a sixty-fourth receiving module 870, a sixty-fifth receiving module 871, a sixty-sixth receiving module 872, a sixty-seventh receiving module 873, a sixty-eighth receiving module 874, a sixty-ninth receiving module 875, a seventieth receiving module 876, a seventy-first receiving module 877, a seventy-second receiving module 878, a seventy-third receiving module 879, a seventy-fourth receiving module 880, a seventy-fifth receiving module 881, a seventy-sixth receiving module 882, a seventy-seventh receiving module 883, a seventy-eighth receiving module 884, a seventy-ninth receiving module 885, an eightieth receiving module 886, an eighty-first receiving module 887, an eighty-second receiving module 888, an eighty-third receiving module 889, an eighty-fourth receiving module 890, an eighty-fifth receiving module 891, an eighty-sixth receiving module 892, an eighty-seventh receiving module 893, an eighty-eighth receiving module 894, an eighty-ninth receiving module 895, a ninetieth receiving module 896, a ninety-first receiving module 897, a ninety-second receiving module 898, a ninety-third receiving module 899, a ninety-fourth receiving module 900, a ninety-fifth receiving module 901, a ninety-sixth receiving module 902, a ninety-seventh receiving module 903, a ninety-eighth receiving module 904, a ninety-ninth receiving module 905, a hundredth receiving module 906, a first sending module 907, a second sending module 908, a third sending module 909, a fourth sending module 910, a fifth sending module 911, a sixth sending module 912, a seventh sending module 913, an eighth sending module 914, a ninth sending module 915, a tenth sending module 916, an eleventh sending module 917, a twelfth sending module 918, a thirteenth sending module 919, a fourteenth sending module 920, a fifteenth sending module 921, a sixteenth sending module 922, a seventeenth sending module 923, an eighteenth sending module 924, a nineteenth sending module 925, a twentieth sending module 926, a twenty-first sending module 927, a twenty-second sending module 928, a twenty-third sending module 929, a twenty-fourth sending module 930, a twenty-fifth sending module 931, a twenty-sixth sending module 932, a twenty-seventh sending module 933, a twenty-eighth sending module 934, a twenty-ninth sending module 935, a thirtieth sending module 936, a thirty-first sending module 937, a thirty-second sending module 938, a thirty-third sending module 939, a thirty-fourth sending module 940, a thirty-fifth sending module 941, a thirty-sixth sending module 942, a thirty-seventh sending module 943, a thirty-eighth sending module 944, a thirty-ninth sending module 945, a fortieth sending module 946, a forty-first sending module 947, a forty-second sending module 948, a forty-third sending module 949, a forty-fourth sending module 950, a forty-fifth sending module 951, a forty-sixth sending module 952, a forty-seventh sending module 953, a forty-eighth sending module 954, a forty-ninth sending module 955, a fiftieth sending module 956, a fifty-first sending module 957, a fifty-second sending module 958, a fifty-third sending module 959, a fifty-fourth sending module 960, a fifty-fifth sending module 961, a fifty-sixth sending module 962, a fifty-seventh sending module 963, a fifty-eighth sending module 964, a fifty-ninth sending module 965, a sixtieth sending module 966, a sixty-first sending module 967, a sixty-second sending module 968, a sixty-third sending module 969, a sixty-fourth sending module 970, a sixty-fifth sending module 971, a sixty-sixth sending module 972, a sixty-seventh sending module 973, a sixty-eighth sending module 974, a sixty-ninth sending module 975, a seventieth sending moduleFigure 9 The device is applied to a first server, and the device comprises:
[0233] A second receiving module 901 is configured to receive identity information of an Internet of Things device and payment information of a user sent by a mobile device.
[0234] A first authentication module 902 is configured to authenticate the identity information according to a preset rule.
[0235] A second sending module 903 is configured to send the payment information to a second server for authentication after the identity information is authenticated.
[0236] A third receiving module 904 is configured to receive a second token sent by the second server, wherein the second token is generated by the second server after the payment information is authenticated.
[0237] A third sending module 905 is configured to send, to the Internet of Things device and the mobile device, association information obtained by associating the first token and the second token with the identity information and the payment information.
[0238] In the embodiment of the present application, the first server can be an Internet of Things device management platform, and the first server can uniformly manage a plurality of Internet of Things devices. The identity information of the Internet of Things device and the payment information of the user are obtained by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, that is, the token of the Internet of Things device does not need to be transmitted, and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined; then the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is returned to the first server after the authentication is passed, and the binding of the corresponding Internet of Things device is completed by the first server, that is, the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment is realized, authentication between the device token (i.e., the first token, the same below) of the Internet of Things device and the server is completed, and the security of subsequent payment is guaranteed.
[0239] Optionally, in the embodiment of the present application, a processor of the Internet of Things device, such as a MCU (Micro Controller Unit, microcontroller unit), is connected to a secure chip SE (Secure Element), and the secure chip SE is pre-stored with a security domain to establish a security basis of the Internet of Things device.
[0240] Exemplarily, the security chip SE of the Internet of Things device can serve as a transaction security shield of the device, and based on the high security performance of the security chip SE, the hardware capability of the Internet of Things device is improved. The first token is stored in the security chip SE in an encrypted manner.
[0241] The first token, that is, the device Token of the Internet of Things device, has a unique correspondence relationship with the Internet of Things device. Each Internet of Things device has one device Token, and therefore the device Token of the Internet of Things device is globally unique.
[0242] Optionally, in the embodiment of the present application, the apparatus can further include:
[0243] The eighth receiving module is configured to receive the first public key sent by the Internet of Things device.
[0244] The third saving module is configured to save the first public key.
[0245] The first server can pre-store the mapping between the identity information of the Internet of Things device and the first token of the Internet of Things device in a database, and after receiving the first public key, the first server can store the first public key and the corresponding identity information of the Internet of Things device in association.
[0246] Exemplarily, the identity information of the Internet of Things device can include one or more of a device ID (Identity Document, identity identification code), a device manufacturer ID, and a device chip ID.
[0247] The payment information input by the user can include one or more of the card number of a payment card (such as a bank card), an anti-counterfeit code (such as a security code CVN2, Card Validation Number 2), and a verification code. In one specific example, the payment information can include one or more payment cards.
[0248] Exemplarily, the second token serves as a business Token, and has a one-to-one correspondence relationship with the payment card in the payment information. When the payment information includes information of one payment card, one first token can be generated; when the payment information includes information of multiple payment cards, multiple second tokens can be generated respectively corresponding to the payment cards.
[0249] Optionally, in the embodiment of the present application, the apparatus can further include:
[0250] The ninth receiving module is configured to receive the identity information of the Internet of Things device and the updated payment information of the user sent by the mobile device.
[0251] The second authentication module is configured to authenticate the identity information through a preset rule.
[0252] The ninth sending module is configured to send the updated payment information to the second server for authentication after the identity information is authenticated;
[0253] The tenth receiving module is configured to receive a third token sent by the second server, the third token being generated by the second server after the updated payment information is authenticated;
[0254] The tenth sending module is configured to send, to the Internet of Things device and the mobile device, association information obtained by associating the first token and the third token with the identity information and the updated payment information.
[0255] Figure 10 A structure diagram of an authentication device is shown. As shown in the figure, the device is applied to a mobile device, and the device includes: Figure 10
[0256] The first obtaining module 1001 is configured to obtain identity information of an Internet of Things device and payment information of a user, the Internet of Things device being built-in with a first token.
[0257] The fourth sending module 1002 is configured to send the identity information and the payment information to a first server, so that the first server authenticates the identity information and sends the payment information to a second server for authentication after the identity information is authenticated.
[0258] The fourth receiving module 1003 is configured to receive first information sent by the first server, the first information including association information between a first token, a second token and the identity information and the payment information, wherein the first token is determined by the first server according to the identity information, and the second token is generated by the second server after the payment information is authenticated.
[0259] In the embodiment, the identity information of the Internet of Things device and the payment information of the user are obtained by the mobile device and sent to the first server for authentication. After the identity information of the Internet of Things device is authenticated by the first server, the first token of the Internet of Things device can be determined based on the identity information, that is, the token of the Internet of Things device does not need to be transmitted, and the correspondence between the identity information of the Internet of Things device and the first token can be pre-stored in the first server. After the identity information of the Internet of Things device is authenticated to be legal, the first token corresponding to the device can be determined; then the payment information is sent to the second server, the legality of the payment information is authenticated by the second server, and the second token is returned to the first server after the authentication is passed, and the binding of the corresponding Internet of Things device is completed by the first server, that is, the first token, the second token and the payment information are associated and sent to the Internet of Things device for storage. In this way, before payment is realized, authentication between the device token (i.e., the first token, the same below) of the Internet of Things device and the server is completed, and the security of subsequent payment is guaranteed.
[0260] Optionally, in the embodiment of the present application, the processor of the Internet of Things device, such as the MCU (Micro Controller Unit), is connected to the secure chip SE (Secure Element), and the secure chip SE is pre-stored with a security domain to establish the security foundation of the Internet of Things device.
[0261] Exemplarily, the secure chip SE of the Internet of Things device can serve as the transaction security shield of the device, and based on its own high security performance, the hardware capability of the Internet of Things device is improved. The first token is stored in the secure chip SE.
[0262] The first token, i.e., the device Token of the Internet of Things device, has a unique corresponding relationship with the Internet of Things device, and each Internet of Things device has one device Token, so that the device Token of the Internet of Things device is globally unique.
[0263] Optionally, in the embodiment of the present application, the apparatus can further include:
[0264] The second acquisition module is configured to acquire the identification code of the Internet of Things device, wherein the identification code includes the identity information of the Internet of Things device and a page address;
[0265] The second analysis module is configured to analyze the identity information according to the identification code and jump to the first interface corresponding to the page address;
[0266] The eleventh receiving module is configured to receive the payment information input by the user from the first interface.
[0267] Exemplarily, the identity information of the Internet of Things device can include one or more of the device ID (Identity Document), the device manufacturer ID, and the device chip ID (the serial number of the chip corresponding to the MCU on the device in the example).
[0268] The payment information input by the user can include one or more of the card number of the payment card (such as a bank card), the anti-counterfeit code (such as the security code CVN2, Card Validation Number 2), and the verification code.
[0269] Exemplarily, the second token as the business Token has a one-to-one corresponding relationship with the payment card in the payment information. When the payment information includes the information of one payment card, one first token can be generated; when the payment information includes the information of multiple payment cards, multiple second tokens can be generated corresponding to the payment cards.
[0270] Optionally, in the embodiments of the present application, the device can further include:
[0271] The third obtaining module is configured to obtain identity information of the Internet of Things device and updated payment information of the user, the Internet of Things device being built-in with a first token;
[0272] The eleventh sending module is configured to send the identity information and the updated payment information to the first server, so that the first server sends the updated payment information to the second server for authentication after the identity information is authenticated by the first server;
[0273] The twelfth receiving module is configured to receive fourth information sent by the first server, the fourth information including a first token and association information between the third token and the identity information and the updated payment information, wherein the first token is determined by the first server according to the identity information, and the third token is generated by the second server after the updated payment information is authenticated by the second server.
[0274] Figure 11 A structure diagram of a payment device is shown. As shown in the figure, the device is applied to a first server, and the device includes: Figure 11
[0275] The fifth receiving module 1101 is configured to receive a transaction request sent by an Internet of Things device, the transaction request being initiated based on payment information saved by the Internet of Things device, and the transaction request including transaction information of a corresponding transaction event, a first token and identity information of the Internet of Things device;
[0276] The first analysis module 1102 is configured to analyze the first token from the transaction request;
[0277] The determination module 1103 is configured to determine a corresponding second token according to the first token and pre-stored mapping information in the first server, the pre-stored mapping information being association information of the first token, the second token and the payment information;
[0278] The fifth sending module 1104 is configured to send the second token and the transaction information to the second server, so that the second server performs a balance deduction operation on a corresponding transaction event based on the payment information and generates balance change information after the payment information corresponding to the second token is verified by the second server;
[0279] The sixth receiving module 1105 is configured to receive the balance change information sent by the second server, and forward the balance change information to the Internet of Things device.
[0280] The first server in the embodiments of the present application can be an Internet of Things device management platform. In the embodiments of the present application, the transaction payment is initiated based on the authenticated identity information and payment information and the first token stored in the security chip, which, compared with traditional online transactions, guarantees the legitimacy of transaction information and improves transaction security; compared with traditional IC card transactions, the method of the embodiments of the present application can implement a transaction process initiated based on payment information of a payment card but not dependent on a physical card body of the payment card, thereby improving payment convenience.
[0281] It should be noted that all related contents of each step involved in the method embodiments described above can be cited to the function description of the corresponding function module and can achieve the corresponding technical effects. For brief description, it will not be repeated here.
[0282] Figure 12 A hardware structure schematic diagram of an electronic device provided by the embodiments of the present application is shown.
[0283] The electronic device can include a processor 1201 and a memory 1202 storing computer program instructions.
[0284] Specifically, the processor 1201 described above can include a central processing unit (CPU), or a specific integrated circuit (Application Specific Integrated Circuit, ASIC), or can be configured to implement one or more integrated circuits of the embodiments of the present application.
[0285] The memory 1202 can include a mass storage for data or instructions. By way of example and not limitation, the memory 1202 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 1202 can include removable or non-removable (or fixed) media. Where appropriate, the memory 1202 can be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, the memory 1202 is a non-volatile solid-state memory.
[0286] The memory can include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software that, when executed (e.g., by one or more processors), is operable to perform the operations described with reference to the authentication method or the payment method according to any of the embodiments described above.
[0287] The processor 1201 implements the authentication method or the payment method of any of the embodiments described above by reading and executing computer program instructions stored in the memory 1202.
[0288] In one example, the electronic device can further include a communication interface 1203 and a bus 1210. As shown, the processor 1201, the memory 1202, and the communication interface 1203 are connected by the bus 1210 and complete communication with each other. Figure 12
[0289] The communication interface 1203 is mainly used to realize the communication between the modules, devices, units, and / or equipment in the embodiments of the present application.
[0290] The bus 1210 includes hardware, software, or both, which couples the components of the electronic device to each other. By way of example, and not limitation, the bus can include an accelerated graphics port (AGP) or other graphics bus, an enhanced industry standard architecture (EISA) bus, a front-side bus (FSB), a HyperTransport (HT) interconnect, an industry standard architecture (ISA) bus, an InfiniBand (IB) interconnect, a low pin count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a serial advanced technology attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or combination of two or more of these. Where appropriate, the bus 1210 can include one or more buses. Although the present embodiments describe and show a particular bus, the present application contemplates any suitable bus or interconnect.
[0291] In addition, in combination with the authentication method or the payment method in the above-described embodiments, the embodiments of the present application can provide a computer storage medium to implement. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by a processor to implement the authentication method or the payment method of any of the above-described embodiments.
[0292] In addition, in combination with the authentication method or the payment method in the above embodiments, an embodiment of the present application can provide a computer program product for implementation. Instructions in the computer program product are executed by a processor of an electronic device, so that the electronic device executes the authentication method or the payment method of any of the above embodiments.
[0293] It should be noted that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted. In the above embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.
[0294] The functional modules shown in the structural block diagram described above can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.
[0295] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be executed simultaneously.
[0296] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0297] The above description is only specific implementation of the present application. For the convenience and brevity of description, the specific working process of the above-described system, module and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described herein. It should be understood that the protection scope of the present application is not limited in this way. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.
Claims
1. An authentication method characterized by, The application is applied to an Internet of Things device, which is an electronic license plate, the Internet of Things device is internally provided with a first token and a security chip, the first token is stored in the security chip in an encrypted manner, and the method comprises the following steps: Identity information of the Internet of Things device is provided to a mobile device, so that the mobile device sends the identity information and payment information of a user to a first server for authentication, the Internet of Things device is bound with multiple payment cards, and the payment information comprises the multiple payment cards; First information sent by the first server is received, the first information comprises association information between the first token, a second token, the identity information and the payment information, the first token is determined after the identity information is authenticated by the first server, the second token is generated after the payment information is authenticated by a second server, the second token is multiple, and the second token corresponds to the payment cards in a one-to-one manner; The first information is saved in the security chip.
2. The method of claim 1, wherein, The Internet of Things device is provided with a security chip, Before the identity information of the Internet of Things device is provided to the mobile device, the method further comprises the following steps: A pair of keys are generated through the security chip, the keys comprise a first public key and a first private key; The first public key is sent to the first server; The identity information is sent to the mobile device after being encrypted by the first private key, so that the mobile device sends the identity information to the first server and authenticates the identity information by the first public key. The application is applied to a first server, and the method comprises the following steps:
3. An authentication method characterized by, Identity information of an Internet of Things device and payment information of a user sent by a mobile device are received, the Internet of Things device is an electronic license plate, the Internet of Things device is internally provided with a first token and a security chip, the first token is stored in the security chip in an encrypted manner, the Internet of Things device is bound with multiple payment cards, and the payment information comprises the multiple payment cards; The identity information is authenticated by a preset rule; After the identity information is authenticated, the payment information is sent to a second server for authentication; A second token sent by the second server is received, the second token is generated after the payment information is authenticated by the second server, the second token is multiple, and the second token corresponds to the payment cards in a one-to-one manner; Association information, in which a first token and the second token are associated with the identity information and the payment information, is sent to the Internet of Things device and the mobile device. The identity information is encrypted by a first private key, and the first private key is generated by a security chip of the Internet of Things device; 4. The method of claim 3, wherein, The identity information is authenticated by a first public key, and the first public key is generated by the security chip and corresponds to the first private key. Before the identity information of the Internet of Things device and the payment information of the user sent by the mobile device are received, the method further comprises the following steps: The first public key sent by the Internet of Things device is received; 5. The method of claim 4, wherein, The first public key is saved. The application is applied to a mobile device, and the method comprises the following steps: 6. An authentication method characterized by, Identity information of an Internet of Things device and payment information of a user are acquired, the Internet of Things device is built-in with a first token and a secure chip, the Internet of Things device is an electronic license plate, the first token is stored in the secure chip in an encrypted manner, and the payment information includes a plurality of payment cards; The identity information and the payment information are sent to a first server, so that the first server sends the payment information to a second server for authentication after the identity information is authenticated; Second information sent by the first server is received, the second information including association information between a first token, a second token and the identity information and the payment information, wherein the first token is determined by the first server according to the identity information, the second token is generated by the second server after the payment information is authenticated, the Internet of Things device is bound to a plurality of payment cards, and the second token is a plurality of second tokens, each of which corresponds to a payment card.
7. The method of claim 6, wherein, The identity information of the Internet of Things device and the payment information of the user are acquired, including: An identification code of the Internet of Things device is acquired, the identification code including identity information of the Internet of Things device and a page address; The identity information is parsed according to the identification code, and a first interface corresponding to the page address is jumped to; Payment information input by a user from the first interface is received.
8. A payment method, characterized by The method is applied to a first server, and includes: A transaction request sent by an Internet of Things device is received, the transaction request including transaction information of a corresponding transaction event, a first token and identity information of the Internet of Things device, the transaction information including payment information, the Internet of Things device being bound to a plurality of payment cards, the payment information including the plurality of payment cards, the Internet of Things device being an electronic license plate, the Internet of Things device being built-in with the first token and a secure chip, and the first token being stored in the secure chip in an encrypted manner; The first token is parsed from the transaction request; A corresponding second token is determined according to the first token and pre-stored mapping information in the first server, the pre-stored mapping information being association information of the first token, the second token, the identity information and the payment information, the second token being a plurality of second tokens, and each of the second tokens corresponding to a payment card; The second token and the transaction information are sent to a second server, so that, after the payment information corresponding to the second token is verified by the second server, a balance deduction operation corresponding to the transaction event is performed by a third server based on the payment information and balance change information is generated; The balance change information sent by the second server is received to be forwarded to the Internet of Things device.
9. The method of claim 8, wherein, The transaction request is information encrypted by a first private key on the Internet of Things device, and the first private key is generated by a secure chip of the Internet of Things device; The first token is parsed from the transaction request, including: The transaction request is decrypted by a first public key to parse the first token from the transaction request, the first public key being generated by the secure chip and corresponding to the first private key.
10. An authentication apparatus characterized by comprising: The application is applied to an Internet of Things device, which is an electronic license plate, the Internet of Things device is internally provided with a first token and a secure chip, the first token is stored in the secure chip in an encrypted manner, and the device comprises: A first sending module is configured to provide identity information of the Internet of Things device to a mobile device, so that the mobile device sends the identity information and payment information of a user to a first server for authentication, the Internet of Things device is bound to a plurality of payment cards, and the payment information comprises the plurality of payment cards; A first receiving module is configured to receive second information sent by the first server, the second information comprising association information between the first token, the second token and the identity information and the payment information, wherein the first token is determined by the first server after the identity information is authenticated, the second token is generated by a second server after the payment information is authenticated, the second token is a plurality of tokens, and the second token corresponds to the payment card in a one-to-one manner; A saving module is configured to save first information in the secure chip.
11. An authentication apparatus characterized by comprising: The application is applied to a first server, and the device comprises: A second receiving module is configured to receive identity information of an Internet of Things device and payment information of a user sent by a mobile device, the Internet of Things device is an electronic license plate, the Internet of Things device is internally provided with a first token and a secure chip, the first token is stored in the secure chip in an encrypted manner, the Internet of Things device is bound to a plurality of payment cards, and the payment information comprises the plurality of payment cards; A first authentication module is configured to authenticate the identity information by a preset rule; A second sending module is configured to send the payment information to a second server for authentication after the identity information is authenticated; A third receiving module is configured to receive a second token sent by the second server, the second token is generated by the second server after the payment information is authenticated, the second token is a plurality of tokens, and the second token corresponds to the payment card in a one-to-one manner; A third sending module is configured to send association information after the first token and the second token are associated with the identity information and the payment information to the Internet of Things device and the mobile device.
12. An authentication apparatus characterized by comprising: The application is applied to a mobile device, and the device comprises: A first obtaining module is configured to obtain identity information of an Internet of Things device and payment information of a user, the Internet of Things device is internally provided with a first token and a secure chip, the Internet of Things device is an electronic license plate, the first token is stored in the secure chip in an encrypted manner, and the payment information comprises a plurality of payment cards; A fourth sending module is configured to send the identity information and the payment information to a first server, so that the first server authenticates the identity information, and sends the payment information to a second server for authentication after the identity information is authenticated; The fourth receiving module is used for receiving first information sent by the first server, the first information comprising association information between a first token, a second token and the identity information and the payment information, wherein the first token is determined by the first server according to the identity information, the second token is generated by the second server after the payment information is authenticated, the Internet of Things device is bound with multiple payment cards, the second token is multiple, and the second token corresponds to the payment cards one by one.
13. A payment device, characterized by The device applied to the first server comprises: The fifth receiving module is used for receiving a transaction request sent by the Internet of Things device, the transaction request comprising transaction information of a corresponding transaction event, a first token and identity information of the Internet of Things device, the transaction information comprising payment information, the Internet of Things device being bound with multiple payment cards, the payment information comprising multiple payment cards, the Internet of Things device being an electronic license plate, the Internet of Things device being internally provided with the first token and a secure chip, and the first token being stored in the secure chip in an encrypted manner; The first analyzing module is used for analyzing the first token from the transaction request; The determining module is used for determining a corresponding second token according to the first token and pre-stored mapping information in the first server, the pre-stored mapping information being association information between the first token, the second token, the identity information and the payment information, the second token being multiple, and the second token corresponding to the payment cards one by one; The fifth sending module is used for sending the second token to the second server, so that, after the second server verifies the payment information corresponding to the second token, the third server performs a balance deduction operation corresponding to the transaction event based on the payment information and generates balance change information; The sixth receiving module is used for receiving the balance change information sent by the second server and forwarding the balance change information to the Internet of Things device.
14. An electronic device, comprising: The electronic device comprises a processor and a memory storing computer program instructions; The processor executes the computer program instructions to implement the method in any one of claims 1-2, or claims 3-5, or claims 6-7, or claims 8-9.
15. A computer storage medium, comprising, The computer storage medium stores computer program instructions, and the computer program instructions are executed by the processor to implement the method in any one of claims 1-2, or claims 3-5, or claims 6-7, or claims 8-9.
16. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device executes the method in any one of claims 1-2, or claims 3-5, or claims 6-7, or claims 8-9.
Citation Information
Patent Citations
Payment method, device and equipment
CN111429126A
Computer system and computer-implemented method for secure payment transaction
US20190392430A1