Tag-based collection code payment method and payment device
By scanning the QR code in the payment device and interacting with the passive tag device to obtain security verification information, the problem of abuse and remote use of personal QR codes is solved, payment security is improved, and regulatory requirements are met.
Patent Information
- Application Number
- CN202210111031.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-29
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2042-01-29
AI Technical Summary
In existing technologies, personal payment QR codes pose risks of abuse and remote use, leading to distorted transaction information, affecting risk monitoring effectiveness, and lacking effective preventive measures.
After scanning the payment code in the payment device, the system interacts with the passive tag device using short-range communication to obtain security verification information, including signature data and tag certificate, and verifies the payment request to ensure that the payment code can only be used on-site.
It achieves the goal of preventing the abuse of QR codes and improving payment security while complying with the regulations of the People's Bank of China, and at the same time maintaining consistency with the existing QR code payment experience without affecting the user experience.
Smart Images

Figure CN114493581B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of collection code payment, and more particularly, to a label-based collection code payment method executed in a payment device, a payment device, a passive label, a payment background, a computer storage medium, and a computer program product. BACKGROUND
[0002] In recent years, personal collection barcodes have been widely used, effectively meeting the individualization and diversification payment needs of the public, and improving the efficiency of fund collection and payment of small and micro economies and street economy. However, at the same time, personal collection barcodes also have some risks. Some institutions use personal collection barcodes for a large number of production and operation, consumption transactions, which not only confuses the nature of the transaction, leading to distorted transaction information and affecting risk monitoring, but also is not conducive to using payment services to empower and value business activities.
[0003] In order to better play the inclusiveness and convenience of collection barcodes while preventing risks, the People's Bank of China issued the "Notice of the People's Bank of China on Strengthening the Management of Payment Receiving Terminals and Related Businesses" and made specific requirements: first, referring to the management of special merchants, personal collection barcode users with obvious business characteristics are required to provide merchant collection barcodes for such personal users, and to improve the quality of collection services for individual operators; second, personal static collection barcodes are prohibited for remote non-face-to-face collection in principle; third, the requirements for personal static collection barcodes are referred to for personal dynamic collection barcodes saved by screen capture, download and other means to prevent criminals from circumventing policy requirements by using personal dynamic collection barcodes; fourth, the conditions and scale of white list entry, the validity period, the number of uses and the transaction limit of personal static collection barcodes are required to be determined carefully to prevent white list abuse risks.
[0004] However, in the prior art, there is no effective solution to prevent the misuse / remote use of offline static two-dimensional codes. SUMMARY
[0005] According to an aspect of the present application, a label-based collection code payment method executed in a payment device is provided, the method comprising: scanning a collection code to obtain a link; interacting with a label device corresponding to the collection code based on a short-distance communication mode to obtain security verification information; and based on the security verification information, uploading a payment request to a payment background.
[0006] As a supplement or alternative to the above solution, in the above method, the collection code is a static collection two-dimensional code, and the payment device obtains a URL link by scanning the static collection two-dimensional code.
[0007] As a supplement or alternative to the above solutions, in the above method, the tag device is a passive tag.
[0008] As a supplement or alternative to the above solutions, in the above method, the interaction with the tag device corresponding to the collection code based on the short-distance communication mode to obtain the security check information includes: applying for the security check information from the tag device through the collection two-dimensional code ID attached in the URL link; and receiving the security check information including signature data and tag certificate from the tag device.
[0009] As a supplement or alternative to the above solutions, in the above method, the signature data is obtained by the tag device signing the collection two-dimensional code and the timestamp through the tag certificate when the collection two-dimensional code is successfully verified.
[0010] As a supplement or alternative to the above solutions, in the above method, based on the security check information, the payment request is sent to the payment background, which includes: the payment device accesses the URL link using the signature data and the tag certificate; after the payment background verifies the signature data and the tag certificate successfully, a payment page is received from the payment background; and a payment request is sent on the payment page.
[0011] As a supplement or alternative to the above solutions, the above method can further include: after scanning the collection code, and before interacting with the tag device to obtain the security check information, the payment device applies for a payment page from the payment background through the URL link; and receiving the payment page from the payment background, wherein the payment page carries an access token corresponding to the static collection two-dimensional code.
[0012] As a supplement or alternative to the above solutions, in the above method, the access token includes a background random number in plaintext form and an access password in ciphertext form.
[0013] As a supplement or alternative to the above solutions, in the above method, the access password is encrypted by a first key on the tag device ID, a first timestamp, a payment order number, and a payment device ID, wherein the first key is obtained by dispersing a master key corresponding to the tag device through the background random number.
[0014] As a supplement or alternative to the above solutions, in the above method, the interaction with the tag device corresponding to the collection code based on the short-distance communication mode to obtain the security check information includes: the payment device broadcasts the access token; and after the tag device verifies the access token, a payment voucher is received from the tag device.
[0015] As a supplement or alternative to the above solutions, in the above method, the payment credential is encrypted by a second key and the tag device ID, the payment taker two-dimensional code ID, the geographic location information, the payment ID, the access token, and the second timestamp, wherein the second key is generated by the tag random number generated by the tag device and the main key corresponding to the tag device dispersed by the background random number.
[0016] As a supplement or alternative to the above solutions, in the above method, based on the security check information, the payment request is sent to the payment background, including: after receiving the payment credential, the payment request is sent to the payment background, wherein the payment request includes the payment credential.
[0017] As a supplement or alternative to the above solutions, the above method can further include: receiving a payment result from the payment background.
[0018] As a supplement or alternative to the above solutions, the above method can further include: after scanning the payment taker code, receiving a payment page and label related information from the payment background, the label related information including a tag device MAC and a tag device ID.
[0019] As a supplement or alternative to the above solutions, in the above method, the label device corresponding to the payment taker code based on short distance communication mode is interacted to obtain security check information, including: receiving a broadcast message from the label device; checking the label device MAC and the label device ID in the broadcast message; after successful verification, sending a payment credential request to the label device; and receiving a payment credential from the label device.
[0020] As a supplement or alternative to the above solutions, in the above method, the payment credential request includes the label device ID, the random number contained in the broadcast message, the payment device ID and the payment account ID.
[0021] According to another aspect of the present application, a payment device is provided, comprising: a scanning device for scanning a payment taker code to obtain a link; an interaction device for interacting with a label device corresponding to the payment taker code based on a short distance communication mode to obtain security check information; and a payment request sending device for sending a payment request to a payment background based on the security check information.
[0022] As a supplement or alternative to the above solutions, in the above payment device, the payment taker code is a static payment taker two-dimensional code, and the scanning device obtains a URL link by scanning the static payment taker two-dimensional code.
[0023] As a supplement or alternative to the above solutions, in the above payment device, the label device is a passive label.
[0024] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the interaction device is configured to: apply for the security check information from the tag device through the payment receiving two-dimensional code ID attached in the URL link; and receive the security check information including signature data and tag certificate from the tag device.
[0025] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the signature data is obtained by the tag device by signing the payment receiving two-dimensional code and timestamp through the tag certificate when the payment receiving two-dimensional code is successfully checked.
[0026] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the payment request uploading device is configured to: access the URL link by using the signature data and the tag certificate; receive a payment page from the payment background after the payment background successfully checks the signature data and the tag certificate; and upload a payment request on the payment page.
[0027] As a supplement or alternative to the above-mentioned solutions, the above-mentioned payment device can further include: a payment page application device, configured to apply for a payment page from the payment background through the URL link after the scanning device scans the payment receiving code, and before the interaction device interacts with the tag device; and a first receiving device, configured to receive the payment page from the payment background, wherein the payment page carries an access token corresponding to the static payment receiving two-dimensional code.
[0028] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the access token includes a background random number in plaintext form and an access password in ciphertext form.
[0029] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the access password is obtained by encrypting a tag device ID, a first timestamp, a payment order number and a payment device ID by a first key, wherein the first key is obtained by dispersing a master key corresponding to the tag device through the background random number.
[0030] As a supplement or alternative to the above-mentioned solutions, in the above-mentioned payment device, the interaction device is configured to: broadcast the access token; and receive a payment voucher from the tag device after the tag device successfully checks the access token.
[0031] As a supplement or alternative to the above solutions, in the payment device, the payment voucher is encrypted by a second key and the tag device ID, the payment receiving two-dimensional code ID, the geographic location information, the payment ID, the access token, and the second timestamp, wherein the second key is dispersed by the tag random number generated by the tag device and the background random number and corresponds to the master key of the tag device.
[0032] As a supplement or alternative to the above solutions, in the payment device, the payment request sending device is configured to send a payment request to the payment background after receiving the payment voucher, wherein the payment request includes the payment voucher.
[0033] As a supplement or alternative to the above solutions, the payment device can further include a second receiving device for receiving a payment result from the payment background.
[0034] As a supplement or alternative to the above solutions, the payment device can further include a third receiving device for receiving a payment page and tag-related information from the payment background after scanning the payment receiving code, wherein the tag-related information includes a tag device MAC and a tag device ID.
[0035] As a supplement or alternative to the above solutions, in the payment device, the interaction device is configured to receive a broadcast message from the tag device, verify the tag device MAC and the tag device ID in the broadcast message, send a payment voucher request to the tag device after verification, and receive a payment voucher from the tag device.
[0036] As a supplement or alternative to the above solutions, in the payment device, the payment voucher request includes a tag device ID, a random number contained in the broadcast message, a payment device ID, and a payment account ID.
[0037] According to another aspect of the present application, a passive tag is provided, which includes a communication module for interacting with the payment device as described above based on a short-distance communication mode, a control module for generating security verification information, and an environmental energy conversion module for obtaining energy required by the passive tag through an environmental energy source.
[0038] As a supplement or alternative to the above solutions, in the passive tag, the control module is configured to verify the payment receiving two-dimensional code ID provided by the payment device, and generate the security verification information after verification, wherein the security verification information includes signature data and a tag certificate.
[0039] As a supplement or alternative to the above solutions, in the passive tag, the signature data is obtained by the control module signing the payment QR code and the timestamp by the tag certificate.
[0040] As a supplement or alternative to the above solutions, in the passive tag, the control module is configured to: verify an access token provided by the payment device; and generate the security check information after the verification is successful, wherein the security check information is a payment credential.
[0041] As a supplement or alternative to the above solutions, in the passive tag, the payment credential is encrypted by a key dispersing a master key corresponding to the passive tag by a tag random number and a background random number, and the key encrypts a tag device ID, a payment QR code ID, geographic location information, a payment ID, the access token, and a timestamp.
[0042] As a supplement or alternative to the above solutions, in the passive tag, the control module is configured to: verify a tag ID and a random number provided by the payment device; and generate a payment credential by hashing a tag device ID, a payment device ID, and a payment account ID after the verification is successful.
[0043] According to still another aspect of the present application, there is provided a payment backend, comprising: a payment device interaction module for interacting with a payment device as previously described; and a verification module for verifying security check information provided by the payment device.
[0044] As a supplement or alternative to the above solutions, in the payment backend, the verification module is configured to verify a tag certificate and signature data provided by the payment device.
[0045] As a supplement or alternative to the above solutions, in the payment backend, the payment device interaction module is configured to: return a payment page to the payment device after the verification module verifies successfully.
[0046] As a supplement or alternative to the above solutions, in the payment backend, the payment interaction module is configured to: receive an application for a payment page from the payment device; and return the payment page, wherein the payment page carries an access token corresponding to a static payment QR code.
[0047] As a supplement or alternative to the above solutions, in the payment backend, the access token comprises a background random number in plaintext form and an access password in ciphertext form.
[0048] As a supplement or alternative to the above scheme, in the above payment background, the access password is encrypted by a first key to the tag device ID, a first timestamp, a payment order number, and a payment device ID, wherein the first key is a master key corresponding to the tag device dispersed by the background random number.
[0049] As a supplement or alternative to the above scheme, in the above payment background, the verification module is configured to verify the payment voucher included in the payment request sent by the payment device.
[0050] As a supplement or alternative to the above scheme, in the above payment background, the payment voucher is encrypted by a second key to the tag device ID, a payment QR code ID, geographic location information, a payment ID, the access token, and a second timestamp, wherein the second key is a master key corresponding to the tag device dispersed by a tag random number and the background random number.
[0051] According to another aspect of the present application, a computer storage medium is provided, the medium comprising instructions which, when executed, perform the method as described above.
[0052] According to another aspect of the present application, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the method as described above.
[0053] The tag-based payment code payment scheme of the embodiments of the present application proposes that after scanning a payment code (e.g., a static payment QR code), the payment device interacts with the tag device corresponding to the payment code based on a short-distance communication mode to obtain security verification information. Subsequently, the subsequent payment process is performed based on the security verification information. In this way, by binding the tag device (e.g., a passive tag) with the payment code (e.g., a static payment code), it is ensured that the payment code can only be used nearby, solving the problem of abuse of personal payment codes and complying with the regulations of the People's Bank of China. In addition, the above payment scheme can be consistent with the existing code scanning payment experience, and will not have a negative impact on the user experience.
[0054] In addition, the passive tag provided by one or more embodiments of the present application can collect radio waves transmitted from the network side, capture and collect energy, so as to complete the corresponding calculation and transmission tasks without the need for additional batteries or external power supply. BRIEF DESCRIPTION OF DRAWINGS
[0055] The above and other objects and advantages of the present application will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which like or similar elements and structures are denoted by like reference numerals throughout.
[0056] Figure 1A flowchart of a label-based payment code payment method performed in a payment device according to one embodiment of the present application is shown;
[0057] Figure 2 A structural diagram of a payment device according to one embodiment of the present application is shown;
[0058] Figure 3 A structural diagram of a passive label according to one embodiment of the present application is shown;
[0059] Figure 4 A structural diagram of a payment backend according to one embodiment of the present application is shown;
[0060] Figure 5 An architecture diagram of a passive label-based static payment code secure payment system according to one embodiment of the present application is shown;
[0061] Figure 6 A schematic diagram of a passive label-based static payment code secure payment method according to one embodiment of the present application is shown;
[0062] Figure 7 A schematic diagram of a passive label-based static payment code secure payment method according to another embodiment of the present application is shown; and
[0063] Figure 8 A schematic diagram of a passive label-based static payment code secure payment method according to yet another embodiment of the present application is shown. DETAILED DESCRIPTION
[0064] Embodiments of the present application will be further described below with reference to the drawings and embodiments. The following embodiments are used to illustrate the present application but should not be used to limit the scope of the present application.
[0065] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the terms "first", "second", "third" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance. In addition, the skilled person in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.
[0066] Figure 1 A flowchart of a label-based payment code payment method 1000 performed in a payment device according to an embodiment of the present application is shown. As shown in FIG. 10, the method 1000 comprises the following steps: Figure 1
[0067] In step S110, a payment code is scanned to obtain a link.
[0068] In step S120, a label device corresponding to the payment code is interacted with based on a short-distance communication mode to obtain security check information.
[0069] In step S130, a payment request is uploaded to a payment background based on the security check information.
[0070] In the context of the present application, a "payment device" refers to a device with payment function, which is capable of scanning a payment code (e.g. a static payment QR code) to perform a subsequent payment process. In one or more embodiments, the payment device can be a smart phone, a smart watch, an IPAD, etc.
[0071] In step S110, the payment code can be a static payment QR code, and the payment device obtains a URL link by scanning the static payment QR code. URL is the abbreviation of uniform resource locator, which refers to a uniform resource location system, and is a method for specifying the location of information on the web service program of the Internet. The URL link can be used to describe various information resources in a unified format, including files, server addresses and directories, etc. The format of the URL can consist of the following three parts: the first part is the protocol (or service mode); the second part is the IP address of the host where the resource is stored (sometimes including the port number); the third part is the specific address of the host resource, such as directory and file name, etc. The first part and the second part are separated by the ":" symbol, and the second part and the third part are separated by the " / " symbol. The first part and the second part are indispensable, and the third part can be omitted sometimes.
[0072] In one or more embodiments, the label device is a passive label. Here, the passive label can also be referred to as a passive Internet of Things label, which has no built-in battery. The so-called "passive Internet of Things" is essentially passive at the terminal node, which does not have a power cord or a built-in battery, but obtains energy from the environment, such as an Internet of Things based on radio electromagnetic energy capture technology. The passive Internet of Things terminal captures and collects energy by collecting the radio waves transmitted from the network side, so as to complete data collection, transmission and distributed computing.
[0073] In the context of the present application, the tag device corresponds to the payment device. In one embodiment, the tag device is in a passive state when it is out of a certain range of the payment device, and extracts power required for its operation from radio frequency energy emitted by the payment device (e.g. radio waves transmitted from the network side) when it is within the certain range of the payment device.
[0074] In step S120, the tag device corresponding to the collection code based on the short distance communication mode is interacted with. Here, the "short distance communication mode" can include, but is not limited to, Bluetooth, wifi, and other low-power short distance communication modes.
[0075] In the context of the present application, the tag device can check the information provided by the payment device (or payment terminal) (e.g. collection QR code ID, access token, etc.) to provide "security check information" to the payment device, to ensure that the collection code is used on site and not remotely used after being photographed, and to improve payment security.
[0076] In one embodiment, step S120 includes: applying for the security check information from the tag device through the collection QR code ID attached in the URL link; and receiving the security check information including signature data and tag certificate from the tag device.
[0077] In one embodiment, the signature data is obtained by the tag device by signing the collection QR code and timestamp through the tag certificate when the collection QR code is successfully checked.
[0078] In this embodiment, step S130 includes: the payment device accesses the URL link using the signature data and the tag certificate; receiving a payment page (e.g. H5 page) from the payment background after the payment background successfully checks the signature data and the tag certificate; and sending a payment request on the payment page.
[0079] In one or more embodiments, although Figure 1 not shown in FIG. 1, the above method 1000 can further include, between step S110 and step S120: the payment device applies for a payment page from the payment background through the URL link; and receiving the payment page from the payment background, wherein the payment page carries an access token corresponding to the static collection QR code.
[0080] In one embodiment, the access token includes a background random number in plaintext form and an access password in ciphertext form. In one embodiment, the access password is encrypted by a first key from the tag device ID, a first timestamp, a payment order number, and a payment device ID, wherein the first key is dispersed from a master key corresponding to the tag device by the background random number. Here, the dispersion operation on the master key can use a key dispersion algorithm. The key dispersion algorithm refers to dispersing a double-length (one length key is 8 bytes) master key (MK) to data to derive a double-length DES encryption key (DK). The algorithm is widely used in current financial IC cards and other industries with high security requirements. The DK derivation process is as follows: first, derive the left half of DK, the specific method is: 1, the rightmost 8 bytes of the dispersed data are taken as input data; 2, the MK is taken as the encryption key; 3, the input data is operated by 3DES with the MK to obtain the left half of DK. Next, derive the right half of DK, the specific method is as follows: 1, the rightmost 8 bytes of the dispersed data are inverted as input data; 2, the MK is taken as the encryption key; 3, the input data is operated by 3DES with the MK to obtain the right half of DK. Finally, the left and right parts of DK are each 8 bytes, which are combined into a double-length DK key, which is the dispersed DK key to be used.
[0081] In the above embodiment, step S120 includes: the payment device broadcasting the access token; and receiving a payment voucher from the tag device after the tag device passes the access token verification. In one embodiment, the payment voucher is encrypted by a second key from the tag device ID, the recipient two-dimensional code ID, the geographic location information, the payment ID, the access token, and a second timestamp, wherein the second key is dispersed from a master key corresponding to the tag device by a tag random number generated by the tag device and the background random number. Here, the dispersion operation on the master key can use the key dispersion algorithm as described above.
[0082] In one embodiment, step S130 includes: after receiving the payment voucher, sending a payment request to the payment background, wherein the payment request includes the payment voucher.
[0083] Although Figure 1 Not shown in the method 1000, in one or more embodiments, the above method 1000 can further include: receiving a payment result from the payment background.
[0084] In one or more embodiments, the above method 1000 can further include: after scanning the recipient code, receiving a payment page and tag-related information from the payment background, the tag-related information including tag device MAC and tag device ID, etc.
[0085] In this embodiment, step S120 includes: receiving a broadcast message (e.g., including tag ID and random number, etc.) from the tag device; verifying the tag device MAC and tag device ID in the broadcast message; after successful verification, sending a payment credential request (e.g., including tag device ID, random number, payment device ID, payment account ID, etc.) to the tag device; and receiving a payment credential from the tag device.
[0086] Through the description of the various embodiments above, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, which includes any mechanism for storing or transmitting information in a computer-readable form. For example, machine-readable media include read-only memory (ROM), random access memory (RAM), disk storage media, optical storage media, flash storage media, electrical, optical, acoustic, or other forms of propagation signals (e.g., carrier waves, infrared signals, digital signals, etc.). The computer software product includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0087] Figure 2 A schematic diagram of a payment device 2000 according to an embodiment of the present invention is shown. Figure 2 As shown, the payment device 2000 includes a scanning device 210, an interaction device 220, and a payment request uploading device 230. The scanning device 210 scans a QR code to obtain a link; the interaction device 220 interacts with the tag device corresponding to the QR code using short-range communication to obtain security verification information; and the payment request uploading device 230 uploads a payment request to the payment backend based on the security verification information.
[0088] In the context of this invention, "payment device" refers to a device with payment functionality that can scan a payment code (e.g., a static payment QR code) to execute subsequent payment processes. In one or more embodiments, the payment device may be a smartphone, smartwatch, iPad, etc.
[0089] In one or more embodiments, the scanning device 210 is configured to scan a payment code to obtain a link, where the payment code can be a static payment QR code, and the payment device obtains the URL link by scanning the static payment QR code. URL is the abbreviation of uniform resource locator, which means uniform resource locator system, and it is a representation method used to specify the location of information on the web service program of the Internet. Using URL link can describe various information resources in a unified format, including files, server addresses and directories, etc. The format of URL can be composed of the following three parts: the first part is the protocol (or called service mode); the second part is the IP address of the host where the resource is stored (sometimes including the port number); the third part is the specific address of the host resource, such as directory and file name, etc. The first part and the second part are separated by the “: / / ” symbol, and the second part and the third part are separated by the “ / ” symbol. The first part and the second part are indispensable, and the third part can be omitted sometimes.
[0090] In one or more embodiments, the tag device is a passive tag. Here, the passive tag can also be referred to as a passive Internet of Things tag, which does not have an internal battery. The so-called “passive Internet of Things” is essentially a passive terminal node, which does not have a power supply line or an internal battery, but obtains energy from the environment, such as an Internet of Things based on radio electromagnetic energy capture technology. The passive Internet of Things terminal captures and collects energy by collecting the radio waves transmitted from the network side, so as to complete data collection, transmission and distributed computing.
[0091] In the context of the present application, the tag device corresponds to the payment device. In one embodiment, when the payment device is outside a certain range, the tag device is in a passive state, and when the payment device is within a certain range, the tag device extracts the power required for its work from the radio frequency energy (such as radio waves transmitted from the network side) emitted by the payment device.
[0092] The interaction device 220 is configured to interact with the tag device corresponding to the payment code based on a short-distance communication mode to obtain security verification information. Here, the “short-distance communication mode” can include but is not limited to Bluetooth, wifi, and other low-power short-distance communication modes.
[0093] In the context of the present application, the tag device can verify the information (such as payment QR code ID, access token, etc.) provided by the payment device (or payment terminal) to provide the payment device with “security verification information” to ensure that the payment code is used on site and not used remotely after being photographed, and to improve payment security.
[0094] In one embodiment, the interaction device 220 is configured to: apply for the security check information from the tag device via the payment QR code ID attached in the URL link; and receive the security check information including signature data and tag certificate from the tag device.
[0095] For example, the signature data can be obtained by the tag device signing the payment QR code and time stamp via the tag certificate when the payment QR code is successfully checked.
[0096] In the above embodiment, the payment request uploading device 230 is configured to: access the URL link by using the signature data and the tag certificate; receive a payment page from the payment background after the payment background successfully checks the signature data and the tag certificate; and upload a payment request on the payment page.
[0097] Although Figure 2 Although not shown in FIG. 2, the payment device 2000 can further include a payment page applying device configured to apply for a payment page from the payment background via the URL link after the scanning device scans the payment code and before the interaction device interacts with the tag device, and a first receiving device configured to receive the payment page from the payment background, wherein the payment page carries an access token corresponding to the static payment QR code.
[0098] In one embodiment, the access token includes a background random number in plaintext form and an access password in ciphertext form. For example, the access password is encrypted by a first key from information such as a tag device ID, a first time stamp, a payment order number, and a payment device ID, wherein the first key is obtained by dispersing a master key corresponding to the tag device via the background random number. Here, the dispersing operation on the master key can use a key dispersing algorithm. The key dispersing algorithm refers to dispersing a master key (MK) of double length (one length key is 8 bytes) to derive a DES encryption key (DK) of double length. The algorithm is widely used in financial IC cards and other industries with high security requirements. The DK derivation process is as follows: first, derive the left half of DK, and the specific method is: 1. take the rightmost 8 bytes of the dispersed data as input data; 2. take MK as the encryption key; 3. use MK to perform 3DES operation on the input data to obtain the left half of DK. Next, derive the right half of DK, and the specific method is as follows: 1. take the rightmost 8 bytes of the dispersed data as input data; 2. take MK as the encryption key; 3. use MK to perform 3DES operation on the input data to obtain the right half of DK. Finally, combine the left and right parts of DK each with 8 bytes to form a double-length DK key, which is the dispersed DK key to be used.
[0099] In the above embodiment, the interaction device 220 is configured to: broadcast the access token; and receive a payment credential from the tag device after the tag device verifies the access token. For example, the payment credential can be generated by encrypting information such as the tag device ID, payment QR code ID, geographical location information, payment ID, the access token, and a second timestamp using a second key. The second key is generated by distributing a tag random number generated by the tag device and a background random number with a master key corresponding to the tag device. Here, the key distribution operation for the master key can employ the key distribution algorithm described above, which will not be elaborated further.
[0100] In the above embodiments, the payment request sending device 230 can be configured to send a payment request to the payment backend after receiving the payment voucher, wherein the payment request includes the payment voucher.
[0101] Furthermore, despite Figure 2 As not shown in the diagram, in one or more embodiments, the payment device 2000 may further include: a second receiving device for receiving payment results from the payment backend.
[0102] In one or more embodiments, the payment device 2000 may further include: a third receiving device, configured to receive a payment page and tag-related information from the payment backend after scanning the payment code, wherein the tag-related information includes tag device MAC and tag device ID, etc.
[0103] In this embodiment, the interaction device 220 can be configured to: receive a broadcast message (e.g., including tag ID and random number, etc.) from the tag device; verify the tag device MAC and tag device ID in the broadcast message; after successful verification, send a payment credential request (e.g., including tag device ID, random number, payment device ID, payment account ID, etc.) to the tag device; and receive a payment credential from the tag device.
[0104] Figure 3 A schematic diagram of the structure of a passive tag 3000 according to an embodiment of the present invention is shown. Figure 3 As shown, the passive tag 3000 includes a communication module 310, a control module 320, and an environmental energy conversion module 330. The communication module 310 is used to interact with the payment device using a short-range communication method; the control module 320 is used to generate security verification information; and the environmental energy conversion module 330 is used to obtain the energy required by the passive tag from an environmental energy source.
[0105] For example, the passive tag 3000 provides security verification services when payment devices scan offline static QR codes for payment. The communication module 310 is responsible for communication with the payment device, including but not limited to low-power, short-range communication methods such as Bluetooth and Wi-Fi. The control module 320 is responsible for access token verification, payment credential generation, and the storage and calculation of payment-related keys. The environmental energy conversion module 330 obtains the required power from various environmental energy sources (micro-light energy, temperature gradient, radio frequency, vibration, etc.), and the collected energy is optimized and stored by a micro-energy management chip, solving the device's self-powering problem.
[0106] In one embodiment, the control module 320 is configured to: verify the QR code ID provided by the payment device; and, upon successful verification, generate the security verification information, wherein the security verification information includes signature data and a tag certificate. For example, the signature data is obtained by the control module 320 signing the QR code and timestamp using the tag certificate.
[0107] In one embodiment, the control module 320 is configured to: verify the access token provided by the payment device; and, upon successful verification, generate the security verification information, wherein the security verification information is a payment credential. For example, the payment credential is generated by encrypting the tag device ID, the payment QR code ID, the geographical location information, the payment ID, the access token, and the timestamp using a key, wherein the key is generated by distributing the master key corresponding to the passive tag using a tag random number and a background random number.
[0108] Figure 4 A schematic diagram of the structure of a payment backend 4000 according to an embodiment of the present invention is shown. Figure 4 As shown, the payment backend 4000 includes a payment device interaction module 410 and a verification module 420. The payment device interaction module 410 is used to interact with the payment device; and the verification module 420 is used to verify the security verification information provided by the payment device.
[0109] In one embodiment, the verification module 420 is configured to verify the tag certificate and signature data provided by the payment device. In this embodiment, the payment device interaction module 410 is configured to return a payment page to the payment device after the verification module successfully verifies the data.
[0110] In one embodiment, the payment interaction module 410 is configured to: receive a payment page request from the payment device; and return to the payment page, wherein the payment page carries an access token corresponding to the static payment QR code. For example, the access token includes a background random number in plaintext and an access password in encrypted form. The access password can, for example, be generated by encrypting information such as the tag device ID, a first timestamp, a payment order number, and the payment device ID using a first key, wherein the first key is generated by distributing the background random number with the master key corresponding to the tag device.
[0111] In this embodiment, the verification module 420 is configured to verify the payment credentials included in the payment request sent by the payment device. For example, the payment credentials are generated by encrypting information such as the tag device ID, the QR code ID, the geographical location information, the payment ID, the access token, and the second timestamp using a second key. The second key is generated by distributing the tag random number and the background random number with the master key corresponding to the tag device.
[0112] The device embodiments described above are merely illustrative. The modules described as separate components may not be physically separate; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0113] Figure 5 An architecture diagram of a static QR code-based secure payment system based on passive tags, according to an embodiment of the present invention, is shown. Figure 5 As shown, a static QR code-based secure payment system using passive tags can consist of four parts: a passive micro-tag, a QR code for payment, a payment device, and a payment backend. The passive micro-tag may include, for example, a communication module, an MCU module (control module), and a radio wave energy conversion module. It provides security verification services when the payment device scans the offline static QR code for payment. The communication module is responsible for communication with the payment device, including but not limited to low-power, short-range communication methods such as Bluetooth and Wi-Fi. The MCU module is responsible for access token verification, payment credential generation, and the storage and calculation of payment-related keys. The environmental energy conversion module obtains the required power from various environmental energy sources (micro-light energy, temperature gradient, radio frequency, vibration, etc.), and the collected energy is optimized and stored by a micro-energy management chip, solving the device's self-powering problem. The payment QR code is an offline static QR code that provides the payment URL link. The payment device, such as a mobile phone, provides payment services to the user. The payment backend is responsible for verifying the payment credential and completing the transaction.
[0114] Figure 6 A schematic diagram of a static QR code secure payment method based on a passive tag according to an embodiment of the present invention is shown.
[0115] Here, the static QR code payment security method based on passive tags refers to introducing passive IoT tags on the basis of the original offline static QR code payment solution. The passive IoT tags interact with the payment device to ensure that the static QR code is used on-site and not used remotely after being photographed, thereby improving payment security, ensuring the authenticity of transaction information, improving the effectiveness of risk monitoring, and ultimately empowering and adding value to business activities through payment services.
[0116] Continue to refer to Figure 6 A secure payment method based on passive tags using static QR codes may include the following steps:
[0117] First, the payment device scans the QR code for payment to obtain the URL link;
[0118] Secondly, the payment device requests a tag certificate from the passive tag via broadcast using the QR code ID attached to the URL.
[0119] Next, the tag verifies whether the QR code ID for receiving payment is correct. If the verification is successful, it signs the payment (QR code ID + timestamp) against the tag certificate and returns the signature data and tag certificate.
[0120] Then, the payment device, carrying the signature data and tag certificate, accesses the corresponding URL link;
[0121] Finally, after the payment backend successfully verifies the certificate, it returns to the payment H5 page and guides the user to complete the subsequent payment steps.
[0122] Figure 7 A schematic diagram of a static QR code-based secure payment method based on passive tags according to another embodiment of the present invention is shown. This embodiment can handle scenarios requiring higher security.
[0123] Continue to refer to Figure 7 A secure payment method based on passive tags using static QR codes may include the following steps:
[0124] First, the payment device scans the QR code for payment to obtain the URL link;
[0125] Secondly, the payment device requests an H5 payment interface from the payment backend via a URL;
[0126] Next, the payment backend returns to the H5 interface, carrying the passive tag access token corresponding to the payment QR code: backend random number (plaintext) + access password ((passive tag ID + timestamp 1 + payment order number + payment device ID), which is encrypted by key 1 formed by distributing the master key corresponding to the tag with the backend random number to form ciphertext).
[0127] Then, the payment device broadcasts a passive tag access token. After receiving the access token, the passive micro tag generates key 1 by distributing the plaintext through the background random number. After decrypting the ciphertext, it verifies whether the passive tag ID is consistent with its own and whether the timestamp 1 is within the valid time (refer to setting it within 5 seconds of the current time).
[0128] Then, after the verification is passed, a random number for the tag is generated and a payment voucher key is generated (formed by distributing the master key through the random number for the tag and the random number for the background). The key is then encrypted with key 2 (information such as the passive tag ID, the QR code ID for receiving payment, the geographical location information, the payment device ID, the access token for this session, and timestamp 2) and returned to the payment device.
[0129] Then, the user enters the payment amount on the payment device and submits the payment order along with the payment amount, merchant number, payment order information, etc.
[0130] Finally, the payment backend verifies the validity of the payment voucher and completes the payment deduction.
[0131] Figure 8 A schematic diagram of a static QR code secure payment method based on a passive tag, according to another embodiment of the present invention, is shown. The static QR code secure payment method based on a passive tag may include the following steps:
[0132] First, the user scans the QR code to receive payment on the payment device (such as a payment app) to obtain the URL, and then requests information such as the payment interface, tag ID, and tag MAC.
[0133] Secondly, the payment device or app can use the phone's Bluetooth to enter listening mode.
[0134] Next, the IoT tag bound to the payment terminal broadcasts tag information (including tag ID and random number, etc.) at regular intervals.
[0135] Then, the payment device receives the tag broadcast information, verifies the tag MAC and tag ID, and after successful verification, sends the tag device ID, random number, payment device ID, payment account ID and other information to the IoT tag to request a payment credential.
[0136] Next, the IoT tag device verifies the tag device ID and the random number. If the verification is successful, it performs a hash operation on the tag device ID, payment device ID, payment account ID, and other information to obtain a face-to-face payment credential, which is then returned to the payment device.
[0137] Then, the user enters the payment amount, and the payment device sends the payment bill and payment voucher to the payment backend together;
[0138] Subsequently, the payment service platform verifies the face-to-face payment voucher and completes the payment;
[0139] Finally, the payment service platform returns the payment result to the payment app.
[0140] In summary, the tag-based QR code payment scheme of this invention proposes that after scanning a QR code (e.g., a static QR code), the payment device interacts with the tag device corresponding to the QR code using short-range communication to obtain security verification information. Subsequently, the payment process is carried out based on this security verification information. In this way, by binding the tag device (e.g., a passive tag) to the QR code (e.g., a static QR code), it is ensured that the QR code can only be used in the vicinity, solving the problem of misuse of personal QR codes and complying with the regulations of the People's Bank of China. Furthermore, the above payment scheme maintains consistency with existing QR code payment experiences and will not negatively impact user experience.
[0141] Furthermore, the passive tags provided by one or more embodiments of the present invention can collect radio waves transmitted from the network side, capture and collect energy, thereby completing the corresponding computing and transmission tasks without the need for additional batteries or external power supplies.
[0142] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (devices), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0143] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0144] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0145] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application. Clearly, those skilled in the art can make various alterations and variations to this application without departing from its spirit and scope. Thus, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A tag-based QR code payment method executed in a payment device, characterized in that, The method includes: The payment device scans the QR code to obtain a link; The payment device interacts with the tag device corresponding to the payment code via short-range communication to obtain security verification information from the tag device, wherein the security verification information is used to ensure that the payment code is being used on-site; and Based on the security verification information, the payment device sends a payment request to the payment backend. Wherein, the payment code is a static payment QR code, and the payment device obtains a URL link by scanning the static payment QR code, and The payment device interacts with the tag device corresponding to the payment code using short-range communication to obtain security verification information from the tag device, including: The security verification information is requested from the tag device via the payment QR code ID attached to the URL link; and The security verification information, including signature data and tag certificate, is received from the tag device.
2. The method as described in claim 1, wherein, The tagging device is a passive tag.
3. The method as described in claim 1, wherein, The signature data is obtained by the tag device signing the payment QR code and the timestamp using the tag certificate when the payment QR code is successfully verified.
4. The method of claim 3, wherein, The payment device sends a payment request to the payment backend based on the security verification information, including: The payment device uses the signature data and the tag certificate to access the URL link; After the payment backend successfully verifies the signature data and the tag certificate, the payment device receives the payment page from the payment backend; and The payment device sends a payment request on the payment page.
5. The method of claim 1, further comprising: After scanning the QR code, and before interacting with the tag device to obtain security verification information, the payment device requests a payment page from the payment backend via the URL link; and The payment device receives the payment page from the payment backend, wherein the payment page carries an access token corresponding to the static payment QR code.
6. The method of claim 5, wherein, The access token includes a background random number in plaintext and an access password in ciphertext.
7. The method of claim 6, wherein, The access password is generated by encrypting the tag device ID, the first timestamp, the payment order number, and the payment device ID using a first key, wherein the first key is generated by distributing the master key corresponding to the tag device using a random number from the background.
8. The method according to any one of claims 5 to 7, wherein, The payment device interacts with the tag device corresponding to the payment code based on short-range communication in order to obtain security verification information from the tag device, including: The payment device broadcasts the access token; and After the access token is verified by the tag device, the payment device receives the payment credential from the tag device.
9. The method of claim 8, wherein, The payment credential is generated by encrypting the tag device ID, the payment QR code ID, the geographical location information, the payment ID, the access token, and the second timestamp using a second key. The second key is generated by distributing the tag random number generated by the tag device and the background random number with the master key corresponding to the tag device.
10. The method of claim 9, wherein, The payment device sends a payment request to the payment backend based on the security verification information, including: Upon receiving the payment voucher, the payment device sends a payment request to the payment backend, wherein the payment request includes the payment voucher.
11. The method of claim 1, further comprising: The payment device receives the payment result from the payment backend.
12. The method of claim 1, further comprising: After scanning the QR code, the payment device receives the payment page and tag-related information from the payment backend. The tag-related information includes the tag device MAC and tag device ID.
13. The method of claim 12, wherein, The payment device interacts with the tag device corresponding to the payment code based on short-range communication in order to obtain security verification information from the tag device, including: The payment device receives broadcast messages from the tag device; The payment device verifies the tag device MAC and tag device ID in the broadcast message; After successful verification, the payment device sends a payment credential request to the tag device; and The payment device receives the payment credential from the tag device.
14. The method of claim 13, wherein, The payment credential request includes the tag device ID, the random number contained in the broadcast message, the payment device ID, and the payment account ID.
15. A payment device, characterized in that, The payment device includes: A scanning device used to scan a payment code in order to obtain a link; An interactive device is configured to interact with a tag device corresponding to the payment code via short-range communication to obtain security verification information from the tag device, wherein the security verification information is used to ensure that the payment code is being used on-site; and The payment request uploading device is used to upload a payment request to the payment backend based on the security verification information. Wherein, the payment code is a static payment QR code, and the scanning device obtains the URL link by scanning the static payment QR code, and The interactive device is configured as follows: The security verification information is requested from the tag device via the payment QR code ID attached to the URL link; and The security verification information, including signature data and tag certificate, is received from the tag device.
16. The payment device as claimed in claim 15, wherein, The tagging device is a passive tag.
17. The payment device as claimed in claim 15, wherein, The signature data is obtained by the tag device signing the payment QR code and the timestamp using the tag certificate when the payment QR code is successfully verified.
18. The payment device as claimed in claim 17, wherein, The payment request sending device is configured to: The URL link is accessed using the signature data and the tag certificate. After the signature data and the tag certificate are successfully verified in the payment backend, the payment page is received from the payment backend; and Submit a payment request on the payment page.
19. The payment device of claim 15, further comprising: A payment page request device is used to request a payment page from the payment backend via the URL link after the scanning device scans the payment code and before the interaction device interacts with the tag device. A first receiving device is configured to receive the payment page from the payment backend, wherein the payment page carries an access token corresponding to the static payment QR code.
20. The payment device as claimed in claim 19, wherein, The access token includes a background random number in plaintext and an access password in ciphertext.
21. The payment device as claimed in claim 20, wherein, The access password is generated by encrypting the tag device ID, the first timestamp, the payment order number, and the payment device ID using a first key, wherein the first key is generated by distributing the master key corresponding to the tag device using a random number from the background.
22. The payment device as claimed in any one of claims 19 to 21, wherein, The interactive device is configured to: Broadcast the access token; and After the access token is verified by the tag device, a payment credential is received from the tag device.
23. The payment device as claimed in claim 22, wherein, The payment credential is generated by encrypting the tag device ID, the payment QR code ID, the geographical location information, the payment ID, the access token, and the second timestamp using a second key. The second key is generated by distributing the tag random number generated by the tag device and the background random number with the master key corresponding to the tag device.
24. The payment device as claimed in claim 23, wherein, The payment request sending device is configured to: Upon receiving the payment voucher, a payment request is sent to the payment backend, wherein the payment request includes the payment voucher.
25. The payment device of claim 15, further comprising: The second receiving device is used to receive the payment result from the payment backend.
26. The payment device of claim 15, further comprising: The third receiving device is used to receive the payment page and tag-related information from the payment backend after scanning the payment code. The tag-related information includes the tag device MAC and the tag device ID.
27. The payment device as claimed in claim 26, wherein, The interactive device is configured to: Receive broadcast messages from the tag device; Verify the tag device MAC and tag device ID in the broadcast message; After successful verification, a payment credential request is sent to the tag device; and Receive payment vouchers from the label device.
28. The payment device as claimed in claim 27, wherein, The payment credential request includes the tag device ID, the random number contained in the broadcast message, the payment device ID, and the payment account ID.
29. A passive tag, characterized in that, The passive tags include: A communication module for interacting with the payment device as described in any one of claims 15 to 28 based on a short-range communication method; A control module is used to generate security verification information, wherein the security verification information is used to ensure that the payment code is used on-site; and An environmental energy conversion module is used to obtain the energy required by the passive tag through an environmental energy source.
30. The passive tag as described in claim 29, wherein, The control module is configured to: Verify the QR code ID provided by the payment device; and Upon successful verification, the security verification information is generated, which includes signature data and tag certificate.
31. The passive tag as described in claim 30, wherein, The signature data is obtained by the control module signing the payment QR code and timestamp using the tag certificate.
32. The passive tag as described in claim 29, wherein, The control module is configured to: Verify the access token provided by the payment device; and Upon successful verification, the security verification information is generated, wherein the security verification information is a payment credential.
33. The passive tag as described in claim 32, wherein, The payment credential is encrypted using a key pair containing the tag device ID, payment QR code ID, geographic location information, payment ID, access token, and timestamp. The key is generated by distributing the master key corresponding to the passive tag using a tag random number and a background random number.
34. The passive tag as described in claim 29, wherein, The control module is configured to: Verify the tag ID and random number provided by the payment device; and After successful verification, a payment credential is generated by performing a hash operation on the tag device ID, payment device ID, and payment account ID.
35. A payment backend, characterized in that, The payment backend includes: Payment device interaction module, for interacting with the payment device as described in any one of claims 15 to 28; and The verification module is used to verify the security verification information provided by the payment device, wherein the security verification information is used to ensure that the payment code is used on-site.
36. The payment backend as described in claim 35, wherein, The verification module is configured to verify the tag certificate and signature data provided by the payment device.
37. The payment backend as described in claim 36, wherein, The payment device interaction module is configured to return a payment page to the payment device after the verification module successfully verifies the payment.
38. The payment backend as described in claim 35, wherein, The payment device interaction module is configured as follows: Receive a payment page request from the payment device; and Return to the payment page, which carries an access token corresponding to the static payment QR code.
39. The payment backend as described in claim 38, wherein, The access token includes a background random number in plaintext and an access password in ciphertext.
40. The payment backend as described in claim 39, wherein, The access password is generated by encrypting the tag device ID, the first timestamp, the payment order number, and the payment device ID using a first key. The first key is generated by distributing the master key corresponding to the tag device using a random number from the background.
41. The payment backend as described in claim 40, wherein, The verification module is configured to verify the payment credentials included in the payment request sent by the payment device.
42. The payment backend as described in claim 41, wherein, The payment credential is generated by encrypting the tag device ID, the payment QR code ID, the geographical location information, the payment ID, the access token, and the second timestamp using a second key. The second key is generated by distributing the tag random number and the background random number with the master key corresponding to the tag device.
43. A computer storage medium, characterized in that, The medium includes instructions that, when executed, perform the method as described in any one of claims 1 to 14.
44. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 14.
Citation Information
Patent Citations
Payment method and device, electronic device and payment label
CN109359968A
Label with transaction function, terminal and mobile device
CN111967870A