Data processing method and system based on internet of things, and payment voucher management platform

By generating secondary credentials associated with payment accounts and combining them with digital signatures and risk control, the problems of inconsistent experience and high risk of theft in IoT payments are solved, achieving unified payment management and security verification, and improving user experience and security.

CN114926156BActive Publication Date: 2026-01-13CHINA UNIONPAY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210092285.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-26
Publication Date
2026-01-13
Estimated Expiration
2042-01-26

AI Technical Summary

Technical Problem

In IoT payment scenarios, user payment experiences are inconsistent, operations are cumbersome, and the risk of account theft is high. Existing technologies are unable to provide consistent business security and simplified operation processes.

Method used

By generating a primary credential uniquely associated with the payment account and a secondary credential associated with the IoT device based on the device's unique identifier, these credentials are stored and distributed to the devices. Combined with digital signatures and risk control parameters, unified management and security verification of payment accounts are achieved.

Benefits of technology

It enables a unified payment experience across IoT devices, simplifies user operations, reduces the risk of account theft, and enhances payment security and business control capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114926156B_ABST
    Figure CN114926156B_ABST
Patent Text Reader

Abstract

The present application relates to a data processing method and system based on the Internet of Things. The data processing method comprises: generating a first-level credential uniquely associated with a payment account based on a received payment account, storing a first correspondence relationship between the payment account and the first-level credential; generating a second-level credential uniquely associated with an Internet of Things device based on the first-level credential and a received device unique identifier of the Internet of Things device, storing a second correspondence relationship between the first-level credential and the second-level credential, and distributing the second-level credential to the uniquely associated Internet of Things device; and receiving a processing request initiated based on the second-level credential, and obtaining a payment account corresponding to the second-level credential according to the first correspondence relationship and the second correspondence relationship. According to the data processing method and system based on the Internet of Things, the payment account can be uniformly managed and the security of payment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, and more specifically to a data processing method and system based on IoT. Background Technology

[0002] For IoT payment scenarios, current technical solutions typically involve directly binding the user device to the payment account, allowing the device to initiate payment transactions directly from the payment account. However, existing solutions have the following main shortcomings:

[0003] (1) Poor consistency in payment experience

[0004] Users' payment experience depends on the design of application software or human-computer interaction interfaces of various device manufacturers. The collection, storage and payment initiation processes of payment account information provided by different manufacturers will vary greatly, making it difficult to provide a unified payment experience and consistent business security.

[0005] (2) Cumbersome user operation

[0006] Because there are many types of IoT devices, users need to repeatedly collect payment account information in devices or applications provided by different manufacturers, and the device manufacturers' systems also need to connect with the payment account issuer's system to verify the account.

[0007] (3) High risk of payment account theft

[0008] User payment account information needs to be stored in the device or the application software provided by the device manufacturer. In the open IoT environment, there are numerous risks of attack. Once user payment account information is illegally stolen by others, it will bring serious financial risks to users. Summary of the Invention

[0009] In view of the above problems, the present invention aims to provide an Internet of Things-based data processing method and data processing system that can provide unified management of payment credentials linked to user accounts.

[0010] This invention discloses a data processing method based on the Internet of Things (IoT), which is applied in an IoT system with multiple IoT devices, characterized by comprising:

[0011] Based on the received payment account, a first-level credential is generated that is uniquely associated with the payment account, and the first correspondence between the payment account and the first-level credential is stored.

[0012] Based on the primary credential and the received device unique identifier of the IoT device, a secondary credential is generated that is uniquely associated with the IoT device. A one-to-one correspondence between the primary and secondary credentials is stored, and the secondary credential is distributed to the uniquely associated IoT device.

[0013] Receive a processing request initiated based on a secondary certificate, and obtain the payment account corresponding to the secondary certificate according to the first correspondence and the second correspondence.

[0014] Optionally, generating a secondary credential uniquely associated with the IoT device based on the primary credential and the received device unique identifier of the IoT device further includes: generating a digital signature for the secondary credential.

[0015] The second correspondence between the primary and secondary vouchers further includes storing the correspondence between the digital signatures of the secondary vouchers.

[0016] Optionally, distributing the secondary credential to the uniquely associated IoT device further includes: distributing the digital signature of the secondary credential together with the secondary credential to the uniquely associated IoT device.

[0017] Optionally, receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, includes:

[0018] Receive processing requests initiated based on secondary credentials and their digital signatures;

[0019] Verify whether the received secondary voucher and its digital signature match the digital signature correspondence stored in the second correspondence relationship; and

[0020] If the correspondence between the secondary voucher and the digital signature of the secondary voucher matches the correspondence between the secondary voucher and the digital signature of the secondary voucher stored in the second correspondence, the primary voucher is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

[0021] Optionally, the second correspondence between the primary voucher and the secondary voucher, which is stored in a one-to-one manner, further includes:

[0022] The second correspondence further stores the correspondence between the unique identification code of the IoT device and the primary and secondary credentials.

[0023] Optionally, receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, includes:

[0024] Receive processing requests initiated based on secondary credentials and the device's unique identifier based on the secondary credentials;

[0025] Verify whether the received secondary credential and device unique identifier match the correspondence between the secondary credential and device unique identifier stored in the second correspondence relationship; and

[0026] If the correspondence between the secondary credential and the device unique identifier matches the correspondence between the secondary credential and the device unique identifier stored in the second correspondence, the primary credential is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

[0027] Optionally, generating a second-level credential uniquely associated with the IoT device based on the first-level credential and the received device unique identifier of the IoT device also includes:

[0028] For secondary credentials uniquely associated with IoT devices, further pre-set risk control parameters.

[0029] The second correspondence between the primary voucher and the secondary voucher is further included in storing the correspondence between the risk control parameter and the secondary voucher.

[0030] Optionally, the risk control parameters are generated based on one or more of the following:

[0031] The device attributes, user attributes, payment account attributes, user settings, device type, and application scenarios of IoT devices.

[0032] Optionally, receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, includes:

[0033] Receive processing requests initiated based on secondary vouchers and risk control data;

[0034] Based on the second correspondence, obtain the pre-set risk control parameters corresponding to the secondary voucher;

[0035] Determine whether the received risk control data conforms to the preset risk control parameters;

[0036] If the received risk control data is determined to be in accordance with the pre-set risk control parameters, a first-level voucher is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

[0037] Optionally, generating a second-level credential uniquely associated with the IoT device based on the first-level credential and the received device unique identifier of the IoT device further includes:

[0038] Generate digital signatures for secondary vouchers, and further pre-set risk control parameters for these secondary vouchers.

[0039] The second correspondence between the primary and secondary vouchers further includes: storing the digital signature, unique device identifier, risk control parameters, and their correspondence with the secondary voucher in the second correspondence.

[0040] Optionally, receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, includes:

[0041] Receive processing requests based on secondary credentials, digital signatures of secondary credentials, device unique identifiers, and risk control parameters;

[0042] Based on the second correspondence, obtain the digital signature of the stored secondary certificate corresponding to the secondary certificate, the stored unique device identification code, and the pre-set risk control parameters;

[0043] The system determines whether the digital signature of the received secondary certificate is consistent with the digital signature of the secondary certificate already stored in the second correspondence relationship, whether the received unique device identifier is consistent with the unique device identifier already stored in the second correspondence relationship, and whether the received risk control data conforms to the preset risk control parameters.

[0044] If the received secondary credential's digital signature matches the digital signature of the secondary credential already stored in the second correspondence, if the received device unique identifier matches the device unique identifier already stored in the second correspondence, and if the received risk control data conforms to the preset risk control parameters, then the primary credential is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

[0045] The present invention discloses a payment voucher management platform, which is applied in an Internet of Things (IoT) system with multiple IoT devices, characterized in that it comprises:

[0046] The voucher generation device is used to generate a first-level voucher that is uniquely associated with the payment account based on the received payment account, and to store the first correspondence between the payment account and the first-level voucher.

[0047] A credential distribution device is configured to generate a secondary credential uniquely associated with an IoT device based on a primary credential and the received device unique identifier of the IoT device, and to store a one-to-one correspondence between the primary and secondary credentials, and to distribute the secondary credential to the uniquely associated IoT device; and

[0048] The credential verification device is used to receive processing requests initiated based on secondary credentials and obtain the payment account corresponding to the secondary credentials according to the first correspondence and the second correspondence stored in the storage device.

[0049] Optionally, in the credential distribution device, a digital signature of a secondary credential is further generated, and the correspondence between the secondary credential and the digital signature of the secondary credential is further stored in the second correspondence relationship.

[0050] Optionally, in the credential distribution device, the digital signature of the secondary credential is distributed together with the secondary credential to the uniquely associated IoT device.

[0051] Optionally, in the credential verification device, a processing request initiated based on a secondary credential and its digital signature is received; the received secondary credential and its digital signature are verified to conform to the correspondence between secondary credentials and their digital signatures stored in the second correspondence relationship; if the correspondence between the secondary credential and its digital signature conforms to the correspondence between secondary credentials and their digital signatures stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

[0052] Optionally, the second correspondence may further store the correspondence between the unique identification code of the IoT device and the primary and secondary credentials.

[0053] Optionally, in the credential verification device, a processing request initiated based on a secondary credential and a device unique identifier of the secondary credential is received; the received secondary credential and device unique identifier are verified to conform to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship; if the correspondence between secondary credentials and device unique identifiers conforms to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

[0054] Optionally, in the credential distribution device, risk control parameters are further pre-set and stored for the secondary credential uniquely associated with the IoT device, and the correspondence between the risk control parameters and the secondary credential is further stored in the second correspondence in the storage device.

[0055] Optionally, the risk control parameters are generated based on one or more of the following:

[0056] The device attributes, user attributes, payment account attributes, user settings, device type, and application scenarios of IoT devices.

[0057] Optionally, in the credential verification device, a processing request initiated based on a secondary credential and risk control data is received, a pre-set risk control parameter corresponding to the secondary credential is obtained based on the second correspondence, the received risk control data is determined to be consistent with the pre-set risk control parameters, and if the received risk control data is consistent with the pre-set risk control parameters, a primary credential is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

[0058] Optionally, in the voucher distribution device, a digital signature of a secondary voucher is generated and risk control parameters are further preset for the secondary voucher. In the storage device, the digital signature of the secondary voucher, the device unique identifier, the risk control parameters, and the correspondence between the secondary voucher and the secondary voucher are further stored in the second correspondence.

[0059] Optionally, in the credential verification device, a processing request initiated based on a secondary credential, its digital signature, a unique device identifier, and risk control parameters is received; the stored digital signature, stored unique device identifier, and pre-set risk control parameters of the secondary credential corresponding to the secondary credential are obtained based on the second correspondence; it is determined whether the received digital signature of the secondary credential is consistent with the digital signature of the secondary credential stored in the second correspondence, whether the received unique device identifier is consistent with the unique device identifier stored in the second correspondence, and whether the received risk control data conforms to the pre-set risk control parameters; if the received digital signature of the secondary credential is consistent with the digital signature of the secondary credential stored in the second correspondence, the received unique device identifier is consistent with the unique device identifier stored in the second correspondence, and the received risk control data conforms to the pre-set risk control parameters, a primary credential is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

[0060] The present invention discloses an Internet of Things (IoT) based data processing system, characterized in that it comprises: multiple IoT devices, a payment transfer system, and a payment voucher management platform.

[0061] The plurality of IoT devices are used to initiate payment processing requests.

[0062] The payment transfer system is used to transfer the payment processing request to the payment voucher management platform.

[0063] The payment voucher management platform includes:

[0064] The digital credential server is used to generate a primary credential uniquely associated with the payment account based on the received payment account, and to generate a secondary credential uniquely associated with the IoT device based on the primary credential and the device unique identifier of the received IoT device.

[0065] A storage device is used to store a first correspondence between payment accounts and primary vouchers, and to store a second correspondence between primary vouchers and secondary vouchers.

[0066] A credential distribution device for distributing the secondary credential to uniquely associated Internet of Things (IoT) devices; and

[0067] The credential verification device is used to receive a processing request initiated based on a secondary credential from an Internet of Things device, and to obtain the payment account corresponding to the secondary credential according to the first correspondence and the second correspondence stored in the storage device.

[0068] The present invention provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the aforementioned Internet of Things-based data processing method.

[0069] A computer device according to one aspect of the present invention includes: a memory; a processor; and a computer program stored in the memory and executable on the processor, the execution of which causes the processor to implement the Internet of Things-based data processing method when executing the computer program. Attached Figure Description

[0070] Figure 1 This is a summary flowchart illustrating the Internet of Things-based data processing method of the present invention.

[0071] Figure 2 This is a block diagram illustrating the structure of the Internet of Things-based data processing system of the present invention.

[0072] Figure 3 This is a schematic diagram illustrating a specific embodiment of the Internet of Things-based data processing system that applies the present invention. Detailed Implementation

[0073] The following are some embodiments of the present invention, intended to provide a basic understanding of the invention. They are not intended to identify key or decisive elements of the invention or to limit the scope of protection sought.

[0074] For purposes of brevity and illustrative purposes, the principles of the invention are described herein primarily with reference to exemplary embodiments thereof. However, those skilled in the art will readily recognize that the same principles are equivalently applicable to all types of Internet of Things-based data processing methods and systems, and that these same principles can be implemented therein, and that any such variations do not depart from the true spirit and scope of this patent application.

[0075] Furthermore, reference is made in the following description to the accompanying drawings, which illustrate specific exemplary embodiments. Electrical, mechanical, logical, and structural modifications may be made to these embodiments without departing from the spirit and scope of the invention. Moreover, while features of the invention are disclosed in conjunction with only one of several embodiments, this feature may be combined with one or more other features of other embodiments if desired and / or advantageous for any given or identifiable function. Therefore, the following description should not be considered limiting in any sense, and the scope of the invention is defined by the appended claims and their equivalents.

[0076] Terms such as “possessing” and “comprising” indicate that, in addition to having units (modules) and steps that are directly and explicitly stated in the specification and claims, the technical solution of the present invention does not exclude the presence of other units (modules) and steps that are not directly or explicitly stated.

[0077] Figure 1 This is a summary flowchart illustrating the Internet of Things-based data processing method of the present invention.

[0078] like Figure 1 As shown, the data processing method based on the Internet of Things of the present invention includes:

[0079] Voucher generation step S100: Generate a first-level voucher uniquely associated with the payment account based on the received payment account, and store the first correspondence between the payment account and the first-level voucher;

[0080] Credential distribution step S200: Based on the primary credential and the received device unique identifier of the IoT device, a secondary credential uniquely associated with the IoT device is generated, and a second correspondence relationship of one-to-one between the primary credential and the secondary credential is stored; the secondary credential is then distributed to the uniquely associated IoT device; and

[0081] Voucher verification step S300: Receive a processing request initiated based on a secondary voucher, and obtain the payment account corresponding to the secondary voucher according to the first correspondence and the second correspondence.

[0082] In order to improve the security and reliability of the IoT-based data processing method of the present invention, the following checks (1) to (3) can be added. Among them, any check of any item in (1) to (3) can be added, or any check of any item in (1) to (3) can be combined arbitrarily.

[0083] (1) In order to verify whether a secondary voucher is genuine, the following verification of the authenticity of the secondary voucher can be added:

[0084] In the voucher generation step S100, a digital signature of a secondary voucher is further generated, and the correspondence between the secondary voucher and the digital signature of the secondary voucher is further stored in the second correspondence relationship.

[0085] In the credential distribution step S200, the digital signature of the secondary credential is distributed together with the secondary credential to the uniquely associated IoT device.

[0086] In the credential verification step S300, a processing request initiated based on a secondary credential and its digital signature is received; it is verified whether the received secondary credential and its digital signature conform to the correspondence between secondary credentials and their digital signatures stored in the second correspondence relationship; and if the correspondence between the secondary credential and its digital signature conforms to the correspondence between secondary credentials and their digital signatures stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

[0087] (2) To verify the consistency of IoT devices, the following verification of the unique identifier of IoT devices can be added:

[0088] In the credential generation step S100, the second correspondence further stores the correspondence between the unique identification code of the IoT device and the primary and secondary credentials.

[0089] In the credential verification step S300, a processing request initiated based on a secondary credential and a device unique identifier of the secondary credential is received; it is verified whether the received secondary credential and device unique identifier conform to the correspondence between secondary credential and device unique identifier stored in the second correspondence relationship; and if the correspondence between secondary credential and device unique identifier conforms to the correspondence between secondary credential and device unique identifier stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

[0090] (2) To enhance risk control, the following risk control checks can be added:

[0091] In the voucher generation step S100, for the secondary voucher uniquely associated with the IoT device, risk control parameters are further preset, and the correspondence between the risk control parameters and the secondary voucher is further stored in the second correspondence relationship.

[0092] The risk control parameters are generated based on one or more of the following:

[0093] The device attributes, user attributes, payment account attributes, user settings, device type, and application scenarios of IoT devices.

[0094] In the voucher verification step S300, a processing request initiated based on a secondary voucher and risk control data is received; a pre-set risk control parameter corresponding to the secondary voucher is obtained based on the second correspondence; it is determined whether the received risk control data conforms to the pre-set risk control parameter; if it is determined that the received risk control data conforms to the pre-set risk control parameter, a primary voucher is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

[0095] Specifically, when generating secondary credentials for IoT devices, a series of payment business control parameters can be set for the secondary credentials corresponding to the device based on the collected device attributes, user attributes, account attributes, and user settings on the application interface, as well as factors such as the type of device and typical payment scenarios used. These parameters include amount limits, payment initiation scenario limits, time limits, and frequently used location area limits. When a payment occurs, relevant payment scenario information is obtained from the payment transaction. This information is compared with the pre-set risk control parameters to obtain the verification result. Alternatively, the transaction can be output to an external risk control system to view the historical transaction history of the device, account, and user. The risk control system's risk control model can then perform risk scoring and rating on the transaction as a reference for whether to approve it.

[0096] Figure 2 This is a block diagram illustrating the structure of the Internet of Things-based data processing system of the present invention.

[0097] like Figure 2 As shown, the payment voucher management platform of the present invention includes:

[0098] The voucher generation device 100 is used to generate a first-level voucher uniquely associated with the payment account based on the received payment account, and to store a first correspondence relationship between the payment account and the first-level voucher.

[0099] A credential distribution device 200 is configured to generate a secondary credential uniquely associated with an IoT device based on a primary credential and the received device unique identifier of the IoT device, and to store a one-to-one correspondence between the primary and secondary credentials, and to distribute the secondary credential to the uniquely associated IoT device; and

[0100] The credential verification device 300 is used to receive a processing request initiated based on a secondary credential and obtain the payment account corresponding to the secondary credential according to the first correspondence and the second correspondence stored in the storage device.

[0101] Alternatively, as a variation, the functions of the voucher generation device 100 in generating a primary voucher uniquely associated with the payment account based on the received payment account, and the voucher distribution device 200 in generating a secondary voucher uniquely associated with the IoT device based on the primary voucher and the received IoT device's unique identifier, can also be implemented by a unified device. For example, a digital voucher server can be set up, which generates a primary voucher uniquely associated with the payment account based on the received payment account and generates a secondary voucher uniquely associated with the IoT device based on the primary voucher and the received IoT device's unique identifier.

[0102] The payment voucher management platform of this invention establishes a centralized and unified payment account voucher management center. This platform connects to the systems of IoT device manufacturers or integrates with their systems, thereby linking payment accounts with IoT devices. The core functions of this payment voucher management platform include: first, generating, distributing, and managing payment vouchers (i.e., primary and secondary vouchers) based on payment accounts, users, and devices; and second, performing authenticity verification, business control, and risk detection on payment transactions initiated by IoT devices using payment vouchers during the payment process.

[0103] In this invention, a user authorizes a payment account to a specific IoT device through a payment credential management platform, generating a digital credential directly related to the device's attributes, which serves as the sole legal credential for subsequent payments initiated by the IoT device.

[0104] In this invention, the credential system adopts a two-level setup. The credential generation device 100 of the payment credential management platform, based on user authorization, obtains the payment account from the payment account issuer and generates a primary credential for the payment account. This primary credential corresponds one-to-one with the payment account and can be shared by multiple IoT devices. Based on user authorization, the credential distribution device 200 derives a secondary credential from the primary credential on the IoT device. This secondary credential is associated with device attributes and corresponds one-to-one with the IoT device. The secondary credential is distributed to and stored in the IoT device, and is submitted when the IoT device initiates a payment.

[0105] In this invention, the payment process involves the verification of secondary vouchers by the voucher verification device 300 within the payment voucher management platform. When an IoT device meets the payment triggering conditions, it initiates a payment transaction. During this transaction, the IoT device submits a secondary voucher, which is protected by a signature on the device itself. This secondary voucher is then sent to the payment network via the IoT device manufacturer or integrated service system. Within the payment network, the secondary voucher is sent to the payment voucher management platform for verification. Simultaneously, the platform identifies the scenario information submitted during the transaction to determine whether the use of the secondary voucher complies with pre-set business control rules and invokes risk control services to implement risk control measures.

[0106] The following describes a specific embodiment of the Internet of Things-based data processing system of the present invention.

[0107] Figure 3 This is a schematic diagram illustrating a specific embodiment of the Internet of Things-based data processing system that applies the present invention.

[0108] like Figure 3 As shown, the data processing method based on the Internet of Things of the present invention mainly consists of the following three parts:

[0109] 1. Voucher generation process

[0110] 1) Users authorize their payment accounts for IoT payments through the application client provided by the account issuer 40 or the payment voucher management platform 30.

[0111] 2) Users apply for an authorized account within the client provided by the payment voucher management platform 30. The payment voucher management platform 30 then forwards the user's application to the account issuer 40 for account verification and selection. Alternatively, users can directly select an account within the application client of the account issuer 40 and authorize it to the payment voucher management platform 30.

[0112] 3) After the user authorization is completed, the payment voucher management platform 30 generates a first-level voucher that is uniquely corresponding to the payment account selected by the user, and stores the generated first-level voucher locally.

[0113] 2. Voucher Distribution Process

[0114] 1) The user initiates a credential distribution request.

[0115] Users can initiate a credential distribution application in two ways: Method 1: The user initiates the operation through the application software (e.g., an APP) provided by the device manufacturer's system 20. In this case, the application software of the IoT device 10 calls the service page or address of the payment credential management platform 30. The user selects a primary credential on the payment credential management platform 30's page, and then the payment credential management platform 30 generates a secondary credential for the IoT device 10. Method 2: The user initiates the operation through the application software provided by the payment credential management platform 30. In this case, the user can directly see the primary credential, select it, and then select the IoT device for which a secondary credential needs to be generated. The application software of the payment credential management platform 30 then calls the service page provided by the IoT device 10. After the user confirms the credential generation on the IoT device 10's page, the payment credential management platform 30 generates the secondary credential.

[0116] 2) The IoT device 10 collects the attribute information of the IoT device 10 according to the data standards and encoding methods provided by the payment voucher management platform 30, generates a unique device identification code (also known as a device attribute code), and uses the key allocated by the payment voucher management platform 2 and the agreed algorithm to encrypt and sign the unique device identification code, and applies to the payment voucher management platform 30 for a secondary payment voucher (uniquely associated with the device).

[0117] 3) The payment voucher management platform 30 transmits the secondary voucher to the device manufacturer system 20 and distributes it to the designated IoT device 10. The IoT device 10 should use the key provided by the payment voucher management platform 30 to verify the secondary voucher and ensure that the secondary voucher is a legitimate payment voucher generated by the payment voucher management platform 30.

[0118] The specific verification process includes, for example, the payment voucher management platform 30 using its local private key to calculate the signature and placing it in the secondary voucher when generating the secondary voucher. The public key corresponding to the private key is given in advance to each device manufacturer's system 20 (which will then distribute it to the IoT device 10). When the IoT device 10 receives the secondary voucher, it uses the public key to verify the signature.

[0119] 3. Voucher verification process (including payment processing process)

[0120] 1) The Internet of Things (IoT) device 10 senses user needs, such as parts wear and tear, consumable replenishment needs, supply replenishment needs, and equipment maintenance needs, through sensors, and directly generates a payment order; or the IoT device 10 sends the needs to the backup manufacturer system 20, which generates the order.

[0121] 2) The IoT device 10 or the manufacturer's system 20 selects a secondary credential that has been pre-set and authorized by the user and stored in the IoT device 10 or the manufacturer's system 20 to initiate a payment transaction.

[0122] 3) The payment transaction is transmitted from the merchant and payment acceptance institution 50 to the payment transfer center 60. The payment transfer center 60 transmits the secondary voucher and transaction attribute information to the payment voucher management platform 30 for verification and business control processing. After the verification is passed, the secondary voucher is converted into a payment account and transmitted to the account issuer 40 through the payment transfer center 60 to complete the transaction authorization.

[0123] The verification process specifically includes:

[0124] 1) The payment voucher management platform 30 obtains secondary vouchers and payment transaction attribute information from the payment transfer center 60.

[0125] 2) The payment voucher management platform verifies the authenticity of the secondary voucher, verifies the consistency of the association with the IoT device that initiated the payment, and verifies whether the current payment transaction attributes meet the preset business control attributes of the secondary voucher.

[0126] 3) The payment voucher management platform 30 returns the transaction identification and business control results to the payment transfer center 60. The payment transfer center 60 determines whether to forward the payment transaction to the account issuer 40 to complete the payment based on whether the relevant verification has been passed.

[0127] According to the payment voucher management platform of the present invention, a unified user account binding and management platform can be provided. Specifically, it can connect numerous IoT device manufacturers through the payment voucher management platform, and realize account binding to IoT devices according to a unified technical standard. IoT device manufacturers only need to focus on collecting and converting user order requirements, while the payment voucher management platform focuses on binding accounts with IoT devices, decoupling the account binding process from the device end, and ensuring consistent user processing and operation experience across different devices.

[0128] The payment credential management platform according to the present invention can improve the automation level of IoT payments. Specifically, the payment credential management platform can push payment accounts to multiple IoT devices at once, realizing automated account binding; secondly, it provides users with a payment account binding authorization management interface, allowing users to manage the binding authorization information of payment accounts on different devices in dedicated client software (such as a mobile APP).

[0129] The payment credential management platform of the present invention can improve the security of IoT payments. Specifically, by using a dedicated digital credential to replace the payment account stored on the device, this digital credential is associated with the device and represents a unique payment credential for a specific payment account on that specific device. All subsequent payments made by that device are initiated using this digital credential, which enables verification of payment authenticity, controllable payment amount, and compliance with payment scenario. Thus, it can prevent the risk of cross-theft caused by the leakage of digital credentials.

[0130] The above examples primarily illustrate the IoT-based data processing method and system of the present invention. Although only some specific embodiments of the invention have been described, those skilled in the art should understand that the invention can be implemented in many other forms without departing from its spirit and scope. Therefore, the examples and embodiments shown are to be considered illustrative rather than restrictive, and the invention may encompass various modifications and substitutions without departing from the spirit and scope of the invention as defined by the appended claims.

Claims

1. A data processing method based on the Internet of Things (IoT), applied in an IoT system with multiple IoT devices, characterized in that, The method includes: Based on the received payment account, a first-level credential is generated that is uniquely associated with the payment account, and the first correspondence between the payment account and the first-level credential is stored. Based on the primary credential and the received unique device identifier of the IoT device, a secondary credential is generated that is uniquely associated with the IoT device. A one-to-one correspondence between the primary and secondary credentials is stored, and the secondary credential is distributed to the uniquely associated IoT device. Receive a processing request initiated based on a secondary credential, and obtain the payment account corresponding to the secondary credential according to the first and second correspondence relationships. The second correspondence between the storage of primary vouchers and secondary vouchers, which is a one-to-one correspondence, further includes: The second correspondence further stores the correspondence between the unique identification code of the IoT device and the primary and secondary credentials. The process of receiving a processing request based on a secondary credential and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences includes: Receive processing requests initiated based on secondary credentials and the device's unique identifier based on the secondary credentials; Verify whether the received secondary credential and device unique identifier match the correspondence between the secondary credential and device unique identifier stored in the second correspondence relationship; and If the correspondence between the secondary credential and the device unique identifier matches the correspondence between the secondary credential and the device unique identifier stored in the second correspondence, the primary credential is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

2. The data processing method based on the Internet of Things as described in claim 1, characterized in that, Generating a second-level credential uniquely associated with the IoT device based on the first-level credential and the received device unique identifier of the IoT device further includes: generating a digital signature for the second-level credential. The second correspondence between the primary and secondary vouchers further includes storing the correspondence between the digital signatures of the secondary vouchers.

3. The data processing method based on the Internet of Things as described in claim 2, characterized in that, Distributing the secondary credential to the uniquely associated IoT device further includes: distributing the digital signature of the secondary credential along with the secondary credential to the uniquely associated IoT device.

4. The data processing method based on the Internet of Things as described in claim 3, characterized in that, Receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, including: Receive processing requests initiated based on secondary credentials and their digital signatures; Verify whether the received secondary voucher and its digital signature match the digital signature correspondence stored in the second correspondence relationship; and If the correspondence between the secondary voucher and the digital signature of the secondary voucher matches the correspondence between the secondary voucher and the digital signature of the secondary voucher stored in the second correspondence, the primary voucher is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

5. The data processing method based on the Internet of Things as described in claim 1, characterized in that, The generation of a second-level credential uniquely associated with an IoT device based on the first-level credential and the received device unique identifier of the IoT device also includes: For secondary credentials uniquely associated with IoT devices, further pre-set risk control parameters. The second correspondence between the primary voucher and the secondary voucher is further included in storing the correspondence between the risk control parameter and the secondary voucher.

6. The data processing method based on the Internet of Things as described in claim 5, characterized in that, The risk control parameters are generated based on one or more of the following: The device attributes, user attributes, payment account attributes, user settings, device type, and application scenarios of IoT devices.

7. The data processing method based on the Internet of Things as described in claim 6, characterized in that, Receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, including: Receive processing requests initiated based on secondary vouchers and risk control data; Based on the second correspondence, obtain the pre-set risk control parameters corresponding to the secondary voucher; Determine whether the received risk control data conforms to the preset risk control parameters; If the received risk control data is determined to be in accordance with the pre-set risk control parameters, a first-level voucher is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

8. The data processing method based on the Internet of Things as described in claim 1, characterized in that, The generation of a second-level credential uniquely associated with the IoT device based on the first-level credential and the received device unique identifier of the IoT device further includes: Generate digital signatures for secondary vouchers, and further pre-set risk control parameters for these secondary vouchers. The second correspondence between the primary and secondary vouchers further includes: storing the digital signature, unique device identifier, risk control parameters, and their correspondence with the secondary voucher in the second correspondence.

9. The data processing method based on the Internet of Things as described in claim 8, characterized in that, Receiving a processing request initiated based on a secondary credential, and obtaining the payment account corresponding to the secondary credential according to the first and second correspondences, including: Receive processing requests based on secondary credentials, digital signatures of secondary credentials, device unique identifiers, and risk control parameters; Based on the second correspondence, obtain the digital signature of the stored secondary certificate corresponding to the secondary certificate, the stored unique device identification code, and the pre-set risk control parameters; The system determines whether the digital signature of the received secondary certificate is consistent with the digital signature of the secondary certificate already stored in the second correspondence relationship, whether the received unique device identifier is consistent with the unique device identifier already stored in the second correspondence relationship, and whether the received risk control data conforms to the preset risk control parameters. If the received secondary credential's digital signature matches the digital signature of the secondary credential already stored in the second correspondence, if the received device unique identifier matches the device unique identifier already stored in the second correspondence, and if the received risk control data conforms to the preset risk control parameters, then the primary credential is obtained according to the second correspondence, and then the payment account is obtained according to the first correspondence.

10. A payment voucher management platform, applied in an Internet of Things (IoT) system with multiple IoT devices, characterized in that, include: The voucher generation device is used to generate a first-level voucher that is uniquely associated with the payment account based on the received payment account, and to store the first correspondence between the payment account and the first-level voucher. A credential distribution device is used to generate a secondary credential uniquely associated with an IoT device based on a primary credential and the received device unique identifier of an IoT device, and to store a second correspondence relationship in which the primary credential and the secondary credential are one-to-one, and to distribute the secondary credential to the uniquely associated IoT device, wherein storing the second correspondence relationship in which the primary credential and the secondary credential are one-to-one further includes storing the correspondence relationship between the device unique identifier of the IoT device and the primary credential and the secondary credential in the second correspondence relationship. as well as The credential verification device is used to receive processing requests initiated based on secondary credentials, and to obtain the payment account corresponding to the secondary credentials according to the first and second correspondences stored in the storage device. In the credential verification device, a processing request initiated based on a secondary credential and a device unique identifier of the secondary credential is received; the received secondary credential and device unique identifier are verified to conform to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship; if the correspondence between secondary credentials and device unique identifiers conforms to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

11. The payment voucher management platform as described in claim 10, characterized in that, In the credential distribution device, a digital signature of a secondary credential is further generated, and the correspondence between the secondary credential and the digital signature of the secondary credential is further stored in the second correspondence relationship.

12. The payment voucher management platform as described in claim 11, characterized in that, In the credential distribution device, the digital signature of the secondary credential is distributed together with the secondary credential to the uniquely associated Internet of Things (IoT) device.

13. The payment voucher management platform as described in claim 12, characterized in that, In the credential verification device, a processing request initiated based on a secondary credential and its digital signature is received; the received secondary credential and its digital signature are verified to conform to the correspondence between the secondary credential and its digital signature stored in the second correspondence relationship; if the correspondence between the secondary credential and its digital signature conforms to the correspondence between the secondary credential and its digital signature stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

14. The payment voucher management platform as described in claim 10, characterized in that, In the credential distribution device, risk control parameters are further pre-set and stored for the secondary credential uniquely associated with the Internet of Things device, and the correspondence between the risk control parameters and the secondary credential is further stored in the second correspondence in the storage device.

15. The payment voucher management platform as described in claim 14, characterized in that, The risk control parameters are generated based on one or more of the following: The device attributes, user attributes, payment account attributes, user settings, device type, and application scenarios of IoT devices.

16. The payment voucher management platform as described in claim 15, characterized in that, In the credential verification device, a processing request initiated based on a secondary credential and risk control data is received. Based on the second correspondence, a pre-set risk control parameter corresponding to the secondary credential is obtained. It is determined whether the received risk control data conforms to the pre-set risk control parameter. If the received risk control data conforms to the pre-set risk control parameter, a primary credential is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

17. The payment voucher management platform as described in claim 10, characterized in that, In the voucher distribution device, a digital signature of a secondary voucher is generated and risk control parameters are further preset for the secondary voucher. In the storage device, the digital signature of the secondary voucher, the device unique identifier, the risk control parameters and the correspondence between the secondary voucher and the secondary voucher are further stored in the second correspondence relationship.

18. The payment voucher management platform as described in claim 17, characterized in that, In the credential verification device, a processing request initiated based on a secondary credential, its digital signature, a unique device identifier, and risk control parameters is received. Based on the second correspondence, the device obtains the stored digital signature, the stored unique device identifier, and the pre-set risk control parameters corresponding to the secondary credential. The device determines whether the received digital signature matches the stored digital signature in the second correspondence, whether the received unique device identifier matches the stored unique device identifier in the second correspondence, and whether the received risk control data conforms to the pre-set risk control parameters. If the received digital signature matches the stored digital signature in the second correspondence, the received unique device identifier matches the stored unique device identifier in the second correspondence, and the received risk control data conforms to the pre-set risk control parameters, a primary credential is obtained according to the second correspondence, and then a payment account is obtained according to the first correspondence.

19. A data processing system based on the Internet of Things, characterized in that, include: Multiple IoT devices, payment transfer systems, and payment voucher management platforms. The plurality of IoT devices are used to initiate payment processing requests. The payment transfer system is used to transfer the payment processing request to the payment voucher management platform. The payment voucher management platform includes: The digital credential server is used to generate a primary credential uniquely associated with the payment account based on the received payment account, and to generate a secondary credential uniquely associated with the IoT device based on the primary credential and the device unique identifier of the received IoT device. A storage device is used to store a first correspondence between payment accounts and primary vouchers, and to store a second correspondence between primary vouchers and secondary vouchers. A credential distribution device for distributing the secondary credential to uniquely associated Internet of Things (IoT) devices; and The credential verification device is used to receive a processing request initiated based on a secondary credential from an IoT device, and to obtain the payment account corresponding to the secondary credential according to the first correspondence and the second correspondence stored in the storage device. In the credential verification device, a processing request initiated based on a secondary credential and a device unique identifier of the secondary credential is received; the received secondary credential and device unique identifier are verified to conform to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship; if the correspondence between secondary credentials and device unique identifiers conforms to the correspondence between secondary credentials and device unique identifiers stored in the second correspondence relationship, a primary credential is obtained according to the second correspondence relationship, and then a payment account is obtained according to the first correspondence relationship.

20. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the Internet of Things-based data processing method as described in any one of claims 1 to 9.

21. A computer device, comprising: Memory; processor; and a computer program stored on the memory and executable on the processor, characterized in that, The execution of the computer program enables the processor to implement the Internet of Things-based data processing method according to any one of claims 1 to 9 when executing the computer program.

Citation Information

Patent Citations

  • Methods and systems for provisioning mobile devices with payment credentials

    US20150046339A1