Digital currency transaction settlement method and device and gate machine
By introducing an independent secure storage medium and a compression encryption mechanism into the turnstile, the problems of storage and data reporting of blockchain digital currency under high transaction volume in the turnstile system are solved, realizing the efficient application and secure transaction of digital currency in the transportation field.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HENGBAO
- Filing Date
- 2021-05-27
- Publication Date
- 2026-08-04
AI Technical Summary
Existing turnstile systems struggle to effectively handle blockchain digital currency transactions under high transaction volumes, resulting in an excessive burden on storage and data reporting, which hinders the application of digital currencies in the transportation sector.
An independent secure storage medium is introduced into the gate to store the credential data of the user's digital currency device, and the data is sent to the back-end device in its entirety when the reporting conditions are met. At the same time, data security and integrity are ensured through compression calculation and encryption mechanisms.
It enables real-time transactions and efficient data reporting of digital currencies, reduces the burden on transaction processing units, meets the high transaction volume demands of the transportation sector, and improves data processing efficiency and security.
Smart Images

Figure CN115409504B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of digital currency technology, and more specifically, to a digital currency transaction settlement method, apparatus, and gate. Background Technology
[0002] Transportation cards are widely used in the transportation sector due to their convenience and security. Their features include: when passing through a turnstile, the PSAM (Purchase Secure Access Module) inside the turnstile performs secure calculations and authentication with the e-wallet application inside the transportation card through contactless communication technology. Then, the e-wallet application updates the balance data in the card, while the turnstile records the transaction, realizing offline "payment".
[0003] In the transportation sector, each turnstile handles a large number of transactions (during peak hours, each turnstile may process forty or even fifty transactions per minute). To ensure that the turnstiles can quickly open and close and guarantee normal passage for users, the turnstiles do not immediately upload the transaction data to the backend server for settlement (i.e., requesting the corresponding amount of currency from the bank managing the transportation cards) after obtaining the transaction information from the transportation card. Instead, the transaction data is uploaded during off-peak hours or when the system is not in operation. The backend then summarizes the transaction data and requests the corresponding amount of currency from the bank managing the transportation cards to achieve final clearing and reconciliation. Only then does the transportation management company complete the fund transaction from the bank and finalize the actual payment.
[0004] With the promotion of digital currencies, the dual offline application of digital currency hard wallets and IC (Integrated Circuit) cards has brought users a more convenient payment experience. Rail transit, as an important infrastructure in daily life, is a significant application scenario for digital currencies.
[0005] Currently, transactions between turnstiles and transportation cards are facilitated through e-wallet applications, which do not support the application of digital currencies combined with blockchain technology.
[0006] In current dual offline transaction solutions for digital currency applications, the transaction processing unit (such as PSAM cards, SE (security element), etc.) is integrated with the user's digital currency device through blockchain technology. For each transaction, the user's digital currency device generates voucher data (including the digital currency spent). Currently, each voucher data requires approximately 900 bytes and is recorded in the transaction processing unit in file format.
[0007] If this application solution is directly applied to the transportation sector, given the high transaction volume characteristic of the transportation sector, the transaction processing unit in the turnstile will face a significant burden, both in terms of storage and data reporting to the backend, thus severely impacting the implementation of digital currency in the transportation sector. Summary of the Invention
[0008] The purpose of this application is to provide a digital currency transaction settlement method, device, and gate, so as to realize the application of digital currency in the transportation field.
[0009] This application provides a digital currency transaction settlement method applied in a turnstile, comprising: receiving voucher data generated by a user-end digital currency device; the voucher data including digital currency paid by the user-end digital currency device; and saving the voucher data to a preset secure storage medium; the secure storage medium being set independently of the transaction processing unit of the turnstile.
[0010] In the aforementioned implementation process, when the turnstile engages in a transaction with a user's digital currency device, it receives the user's digital currency-containing voucher data and saves it to a secure storage medium. Thus, for the user's digital currency device, the transaction involves deducting digital currency; for the turnstile, it involves receiving digital currency, enabling real-time digital currency transactions without the need for payment through commercial banks. Furthermore, because the substantial voucher data is stored securely rather than within the turnstile's transaction processing unit, the burden on the transaction processing unit at each stage is reduced, allowing digital currency applications to meet the needs of the transportation sector and realize the application of digital currency in transportation.
[0011] Furthermore, the method further includes: when a preset reporting condition is triggered, sending each credential data in the secure storage medium to a preset backend device; after receiving a response message returned by the backend device, clearing each of the credential data stored in the secure storage medium; the response message indicates that the backend device has successfully saved each of the credential data.
[0012] In the above implementation process, by pre-setting reporting conditions, all voucher data in the secure storage medium is reported as a whole when the reporting conditions are triggered, and all reported voucher data is cleared after successful reporting, thus realizing the summary submission of digital currency to the back-end equipment. Furthermore, by setting reasonable reporting conditions, the summary submission process of digital currency from the turnstile to the back-end equipment does not affect the normal traffic processing of the turnstile, thereby meeting the data processing needs of the transportation sector.
[0013] Furthermore, the step of sending the credential data in the secure storage medium to the preset backend device includes: performing compression calculations on each of the credential data in the secure storage medium to obtain a credential data compression value; sending the credential data compression value and each of the credential data to the backend device, so that the backend device can verify whether the received credential data is the credential data in the secure storage medium based on the credential data compression value, and return the response message when the verification is successful.
[0014] In the above implementation structure, the voucher data to be reported in the secure storage medium is compressed to obtain the voucher data compression value. Then, the voucher data compression value and the voucher data are sent to the backend device together. This allows the backend device to verify the integrity and correctness of the received voucher data based on the voucher data compression value, thereby improving the security of data and digital currency in the entire reporting process.
[0015] Further, before sending the compressed value of the voucher data and each of the voucher data to the backend device, the method further includes: reading the transaction flow in the transaction processing unit of the gate; correspondingly, sending the compressed value of the voucher data and each of the voucher data to the backend device, so that the backend device can verify whether the received voucher data is the voucher data in the secure storage medium according to the compressed value of the voucher data, and returning the response message when the verification is successful, including: sending the compressed value of the voucher data, the transaction flow, and each of the voucher data to the backend device, so that the backend device can verify whether the received voucher data is the voucher data in the secure storage medium according to the compressed value of the voucher data, and verify whether the total amount of digital currency in the voucher data is correct according to the transaction flow, and returning the response message when both verifications are successful.
[0016] In practical applications, backend devices often need to obtain transaction records from the turnstiles for reconciliation and to ensure accurate accounting. In the above implementation, the transaction records stored by the transaction processing unit do not require modification to the existing turnstile's transaction record storage logic, thus reducing modifications to the turnstiles and facilitating the widespread application of the solution in the transportation sector. Furthermore, by reporting transaction records, backend devices can perform reconciliation, thereby improving the overall reliability of the solution.
[0017] Furthermore, after receiving the response message returned by the backend device, the method further includes: clearing the transaction log in the transaction processing unit.
[0018] It should be understood that once the backend equipment has successfully received the transaction data, the transaction data within the gate loses its value. Furthermore, the storage space within the transaction processing unit is extremely limited, making storage resources very precious. Through the above implementation process, efficient management of the transaction processing unit is achieved, improving the utilization rate of its storage resources.
[0019] Furthermore, before sending the compressed voucher data value, the transaction flow, and each of the voucher data to the backend device, the method further includes: encrypting the compressed voucher data value and the transaction flow in the transaction processing unit of the gate using a preset first key; correspondingly, sending the compressed voucher data value, the transaction flow, and each of the voucher data to the backend device includes: sending the encrypted compressed voucher data value, the transaction flow, and each of the voucher data to the backend device.
[0020] In the above implementation process, the compressed value of the voucher data and the transaction record are encrypted using a preset first key. This ensures data security, and the backend equipment can also authenticate the gate's identity by verifying whether the decryption is successful. Furthermore, by not encrypting the large volume of voucher data in the above implementation process, efficient data processing is facilitated, improving data processing efficiency and making it suitable for implementation in the transportation sector.
[0021] Furthermore, before receiving the credential data generated by the user-end digital currency device, the method further includes: receiving a first negotiation parameter generated by the user-end digital currency device and generating a second negotiation parameter; generating a second key based on the first negotiation parameter and the second negotiation parameter; generating an authentication ciphertext using the second key, and sending the second negotiation parameter and the authentication ciphertext to the user-end digital currency device, so that the user-end digital currency device can use the second negotiation parameter and the first negotiation parameter to generate the second key, decrypt the authentication ciphertext, and after successful decryption, encrypt the credential data using the second key; correspondingly, receiving the credential data generated by the user-end digital currency device includes: receiving the encrypted credential data from the user-end digital currency device; and decrypting the credential data using the second key.
[0022] In the above implementation process, the gate and the user-end digital currency device negotiate a second key based on negotiation parameters to encrypt and transmit the certificate data, which improves the transaction security between the gate and the user-end digital currency device.
[0023] This application embodiment also provides a digital currency transaction settlement device applied in a turnstile, comprising: a receiving module and a processing module; the receiving module is used to receive voucher data generated by a user-end digital currency device; the voucher data includes digital currency paid by the user-end digital currency device; the processing module is used to save the voucher data to a preset secure storage medium; the secure storage medium is set independently of the transaction processing unit of the turnstile.
[0024] This application embodiment also provides a gate, including: a main controller, a secure storage medium, and a transaction processing unit; the secure storage medium is set independently of the transaction processing unit; the main controller is used to receive credential data generated by a user-end digital currency device and send it to the transaction processing unit; the credential data includes digital currency paid by the user-end digital currency device; the transaction processing unit is used to store the credential data in the secure storage medium.
[0025] Furthermore, the main controller is also configured to retrieve the credential data from the secure storage medium and send it to a preset backend device when a preset reporting condition is triggered; and to clear each of the credential data stored in the secure storage medium after receiving a response message from the backend device; the response message indicates that the backend device has successfully saved each of the credential data.
[0026] This application also provides a readable storage medium that stores one or more programs that can be executed by one or more devices with data processing capabilities to implement any of the above-mentioned digital currency transaction settlement methods. Attached Figure Description
[0027] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 A schematic diagram of the structure between a gate and a user-end digital currency device provided in this application embodiment;
[0029] Figure 2 A flowchart illustrating a digital currency transaction settlement method provided in this application embodiment;
[0030] Figure 3 An interactive schematic diagram of an entry process provided in an embodiment of this application;
[0031] Figure 4 An interactive schematic diagram of an outbound process provided in an embodiment of this application;
[0032] Figure 5 An interactive schematic diagram of a reporting process provided for an embodiment of this application;
[0033] Figure 6 This is a schematic diagram of the structure of a digital currency transaction settlement device provided in an embodiment of this application. Detailed Implementation
[0034] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0035] Example 1:
[0036] This application provides a transaction settlement method for digital currency applicable to the transportation sector. See also... Figure 1 As shown, in the method provided in this application, the gate includes a main controller, a secure storage medium, and a transaction processing unit, while the user-end digital currency device has a hardware wallet for realizing digital currency management and transactions.
[0037] In the embodiments of this application, the main controller may be a component with data processing function, such as an MCU (Microcontroller Unit) or a CPU (Central Processing Unit / Processor), but this is not a limitation.
[0038] In the embodiments of this application, the secure storage medium can be implemented using components with data storage capabilities such as floppy disks, optical disks, hard disks, flash memory, USB flash drives, and SD (Secure Digital Memory Card) cards, but this is not a limitation.
[0039] It should be noted that, in this embodiment, the secure storage medium can be a component located within the gate, or it can be an external device that is communicatively connected to the gate. However, the secure storage medium is an independent component separate from the transaction processing unit.
[0040] In the embodiments of this application, the transaction processing unit may be a PSAM or an SE or other unit with transaction processing capabilities, but this is not a limitation.
[0041] Furthermore, in this embodiment of the application, the user-end digital currency device can be a device such as a mobile phone, IC card, tablet computer, or smartwatch, but this is not a limitation.
[0042] Based on the turnstiles provided above, please refer to... Figure 2 As shown, Figure 2 This is a flowchart illustrating a digital currency transaction settlement method applied to a turnstile, as provided in this application embodiment, including:
[0043] S201: Receive voucher data generated by the user's digital currency device.
[0044] It should be noted that in this embodiment, the credential data includes the digital currency paid by the user's digital currency device. It should be understood that digital currency refers to a quantified currency that can be directly used as a transaction entity and has monetary value. In this embodiment, the digital currency can be DCEP (Digital Currency Electronic Payment), but this is not a limitation.
[0045] S202: Save the voucher data to the preset secure storage medium.
[0046] It should be noted that, in this embodiment of the application, the secure storage medium can save the credential data in the form of a file. For example, a credential file can be set up. When the secure storage medium receives credential data, it can add the received credential data to the credential file, thus achieving the saving of the credential data. It should be understood that in practical applications, multiple credential files can also be set up to save different credential data.
[0047] In this way, for the user-end digital currency device, the transaction involves deducting digital currency during the transaction, while for the turnstile, it involves receiving digital currency, thus enabling real-time transactions based on digital currency without the need for payment through commercial banks. Furthermore, because the large amount of voucher data is stored securely on a medium rather than within the transaction processing unit of the turnstile, the burden on the transaction processing unit at each stage is reduced. This allows digital currency-based applications to meet the needs of the transportation sector and realize the application of digital currency in transportation.
[0048] In this embodiment of the application, in order to ensure the security of digital currency during the transaction process, after the gate establishes a communication connection with the user's digital currency device, it can negotiate to obtain a key, and then use the negotiated key to transmit the credential data confidentially, thereby ensuring the security of the data transmission process.
[0049] For example, after establishing a communication connection with the user's digital currency device, the gate can receive a first negotiation parameter generated by the user's digital currency device, and the gate can generate a second negotiation parameter. Then, the gate can generate a second key according to the first and second negotiation parameters in a set manner, and use the second key to generate authentication ciphertext. Then, the gate sends the second negotiation parameter and authentication ciphertext to the user's digital currency device.
[0050] After receiving the second negotiation parameters and authentication ciphertext from the gate, the user-end digital currency device can generate a second key according to the second negotiation parameters and its own first negotiation parameters, following a pre-defined method. Then, it decrypts the authentication ciphertext using the generated second key. If decryption is successful, the negotiation is considered successful. The user-end digital currency device can then use the second key to encrypt the voucher data and send it to the gate. The gate can then decrypt the voucher data using the second key, thereby verifying the voucher data and completing the encrypted data exchange.
[0051] In this embodiment of the application, the decrypted credential data can be saved to a secure storage device.
[0052] It should be noted that in the embodiments of this application, there may be only one second key, that is, both encryption and decryption are implemented using the same key. Alternatively, the second key may be a key pair, with one key dedicated to encryption and the other dedicated to decryption.
[0053] It should also be noted that, in this embodiment, the first negotiation parameter may include a random number generated by the user-side digital currency device and a negotiation factor (given data for key negotiation, which may be data with defined content in the user-side digital currency device). Similarly, the second negotiation parameter may include a random number generated by the gate and a negotiation factor (which may be data given within the gate).
[0054] It should be noted that in this embodiment of the application, when the user-end digital currency device sends the certificate data, it can also use a preset private key to sign the certificate data (for example, it can sign the digital currency in the certificate data). After receiving the certificate data, the gate uses the corresponding preset public key to verify the signature, thereby ensuring the legality of the certificate data.
[0055] In this embodiment of the application, optionally, after establishing a communication connection with the user's digital currency device and before receiving the voucher data generated by the user's digital currency device, the gate may first obtain the balance information of the digital currency in the user's digital currency device. If the balance information of the digital currency in the user's digital currency device does not meet the preset balance conditions, the transaction can be terminated and a reminder can be issued.
[0056] For example, in the embodiments of this application, the balance condition may be, but is not limited to, one of the following: there is no outstanding payment, the balance is greater than the preset minimum balance threshold, and the balance is greater than the amount to be transacted this time.
[0057] It should be understood that the solutions in this application embodiment can be applied to various scenarios in the transportation field. For example, in a rail transit scenario, the solutions in this application embodiment can be applied to exit gates. In this case, the gate can obtain the entry transaction record from the user's digital currency device to obtain the user's entry position and calculate the amount to be transacted. Furthermore, in scenarios such as public transportation, the transaction amount is usually a pre-set fixed amount, so the amount to be transacted is pre-set within the gate.
[0058] It should be noted that, in the embodiments of this application, the gate and the user-end digital currency device can establish a communication connection through short-range communication methods such as NFC (Near Field Communication), ZigBee, Bluetooth, SIMpass (a dual-interface SIM (Subscriber Identity Module) card), and RF-SIM (a SIM card that enables short-to-medium range wireless communication), thereby enabling offline payment.
[0059] In order to avoid the consumption of processing resources within the gate due to the reporting of voucher data and other data, thereby affecting the transaction efficiency between the gate and the user's digital currency device, in this embodiment of the application, reporting conditions can be preset, so that when the reporting conditions are triggered, the voucher data in the secure storage medium is sent to the preset backend device, thereby realizing the submission of digital currency in the gate.
[0060] It should be noted that, in this embodiment of the application, the back-end device can be a pre-set device for managing funds.
[0061] It should also be noted that, in this embodiment, after successfully receiving and saving the transaction vouchers reported by the gate, the backend device can return a response message to the gate indicating that the backend device has successfully saved the voucher data. Upon receiving the response message from the backend device, the gate can then clear the voucher data stored in the secure storage medium, thereby ensuring the successful submission of the digital currency.
[0062] It should also be noted that, in the embodiments of this application, the reporting conditions may be, but are not limited to, at least one of the following: the current time is a preset time (such as a certain time during the shutdown period), or no communication connection has been established with the user's digital currency device within a preset duration.
[0063] It is worth noting that, in this embodiment of the application, when the reporting condition is triggered, the gate can also perform compression calculations on each credential data in the secure storage medium to obtain a compressed credential data value. It should be understood that this compressed credential data value corresponds to all credential data in the secure storage medium that needs to be reported.
[0064] For example, in this application embodiment, a hash value calculation method can be used to calculate the hash value of all credential data that needs to be reported in the secure storage medium, and then use the calculated hash value as the credential data compression value.
[0065] It should be understood that the above method of obtaining the compressed value of voucher data by calculating the hash value is only one feasible method of calculating the compressed value of voucher data exemplified in the embodiments of this application, and is not intended to be a limitation.
[0066] Then, the compressed value of the voucher data and all the voucher data that need to be reported in the secure storage medium can be sent to the backend device.
[0067] After receiving the compressed voucher data value and the voucher data, the backend device can verify whether the received voucher data is voucher data in the secure storage medium based on the compressed voucher data value, and return a response message when the verification is successful.
[0068] For example, the backend device can use the same method to calculate the compressed voucher data value of the received voucher data from the gate. Then, it compares the calculated compressed voucher data value with the received compressed voucher data value. If they match, it indicates that the received voucher data is complete and correct, and subsequent operations can proceed. If they do not match, the gate can be required to re-report, or an alarm can be triggered.
[0069] It should be noted that, in this embodiment of the application, the credential data in the secure storage medium can be saved in the form of a file (hereinafter referred to as a credential file). In this case, the credential data compression value can be obtained simply by calculating the compression value of the relevant credential file to be reported. Furthermore, when reporting, the credential file can be reported directly, thereby improving data exchange efficiency by reporting the entire file.
[0070] It should be noted that, in this embodiment of the application, before sending the compressed value of the voucher data and each voucher data to the backend device, the gate can also read the transaction flow in the transaction processing unit of the gate and send the compressed value of the voucher data, the transaction flow and each voucher data to the backend device.
[0071] Therefore, the backend device can verify whether the received voucher data is the same as the voucher data in the secure storage medium based on the voucher data compression value, and at the same time verify whether the total amount of digital currency in the voucher data is correct based on the transaction flow. When both verifications pass, a response message is returned.
[0072] Meanwhile, in this embodiment, the transaction flow is still stored through the transaction processing unit, which does not change the existing gate's logic for storing transaction flow, thereby reducing modifications to the gate and facilitating the promotion of the solution in the transportation field.
[0073] It should be understood that once the backend device has successfully received the transaction log, the transaction log within the gate loses its value. Furthermore, the storage space within the transaction processing unit is extremely limited, making storage resources very valuable. Therefore, in an optional embodiment of this application, after receiving the response message from the backend device, the gate can clear the transaction log from the transaction processing unit to achieve efficient management of the transaction processing unit and improve the utilization rate of its storage resources.
[0074] In this embodiment of the application, in order to ensure data security while improving output processing efficiency during the reporting process, in an optional implementation of this embodiment of the application, the gate can use a preset first key to encrypt the compressed value of the voucher data and the transaction flow, thereby sending the encrypted compressed value of the voucher data, the transaction flow and the unencrypted voucher data to the back-end device.
[0075] At this point, by encrypting the compressed value of the voucher data and the transaction record using a preset first key, data security is ensured, and the backend equipment can also authenticate the gate's identity by verifying whether the data can be correctly decrypted. Furthermore, since the voucher data, which contains large amounts of data, is not encrypted, efficient data processing is facilitated, improving data processing efficiency and making it suitable for implementation in the transportation sector.
[0076] It should be understood that in another feasible embodiment of the present application, the gate may also use a preset first key to encrypt the credential data compression value, transaction flow and credential data, thereby sending the encrypted credential data compression value, transaction flow and credential data to the back-end device.
[0077] It is important to understand that the first key is a key that is pre-set in the gate and the back-end equipment.
[0078] It should be noted that before sending credential data and other information to the backend device, the turnstile can first send its own identification ID to the backend device, so that the backend device can verify whether the turnstile is in a preset identification list. If it is, the turnstile is allowed to report information.
[0079] It should also be noted that before sending the credential data and other information to the back-end device, the turnstile can first send the authentication ciphertext encrypted with the first key to the back-end device, so that the back-end device can decrypt the authentication ciphertext using the first key, thereby using the authentication ciphertext to verify the validity of the first key in the turnstile and the back-end device.
[0080] It should be noted that in the context of rail transit, the above process can be applied to exit gates. For entry gates, no transaction is required between them and the user's digital currency device, but the entry transaction record needs to be kept.
[0081] For example, after establishing a communication connection with the user's digital currency device, the entrance gate can send entrance initialization information, including the entrance time and site information, to the user's digital currency device for recording and obtaining the entrance transaction record.
[0082] During this process, identity authentication can also be performed between the entrance gate and the user's digital currency device to ensure the reliability of both parties' identities.
[0083] For example, a user-end digital currency device can send its personal certificate and signature to the entry gate. The entry gate can verify the personal certificate and signature, thereby verifying the identity of the user-end digital currency device. Similarly, the entry gate can also send its own gate certificate and signature to the user-end digital currency device for verification, thereby verifying the identity of the entry gate. If either party fails the identity verification, the entire data interaction process ends, and the device detecting the identity problem can issue an alarm.
[0084] It's important to note that in rail transit scenarios, since the user's digital currency device identity has already been verified at the entrance gates, identity verification based on certificates and signatures is no longer required at the exit gates (although the aforementioned method can still be used for verification again). However, in scenarios like buses with only one gate, the gate can still use the above method for identity verification before digital currency transactions to ensure the reliability of both parties involved in the transaction.
[0085] Furthermore, in this embodiment, after establishing a communication connection with the user's digital currency device, the entry gate can first obtain the balance information of the user's digital currency device before sending entry initialization information to the device. Based on this balance information, it can then determine whether the user's digital currency device meets the entry requirements. Subsequent operations are only performed if the entry requirements are met. If the entry requirements are not met, a prompt message can be issued.
[0086] In this application embodiment, the entry requirements may be, but are not limited to, one of the following: no outstanding fees, and a balance greater than a preset minimum balance threshold.
[0087] It should be noted that in the embodiments of this application, the encryption, decryption, verification and other related steps can all be completed by the transaction processing unit in the gate.
[0088] The digital currency transaction settlement method provided in this application involves a turnstile receiving and storing the user's digital currency voucher data in a secure storage medium after obtaining the user's digital currency voucher data during a transaction. This allows the user's digital currency device to deduct funds during the transaction, while the turnstile receives the funds, enabling real-time digital currency transactions without the need for commercial bank settlement. Furthermore, because the substantial voucher data is stored in a secure storage medium, rather than within the turnstile's transaction processing unit, the burden on the transaction processing unit at each stage is reduced. This allows digital currency applications to meet the needs of the transportation sector and realize the application of digital currency in transportation.
[0089] Example 2:
[0090] Based on Embodiment 1, this embodiment takes the implementation process of a rail transit scenario as an example, with the user-end digital currency device being a card with a digital currency hardware wallet, to further illustrate this application.
[0091] See Figure 3 As shown, upon entering the station:
[0092] First, the main controller of the entrance gate reads the digital currency balance information of the card and determines whether the card balance is greater than the minimum ticket price. If so, it proceeds with the next steps. If not, it displays an insufficient balance message.
[0093] Next, the main controller of the entrance gate sends an entry initialization message to the card, carrying the current time and station information. After receiving the entry initialization message, the card returns its personal certificate and signature.
[0094] Next, the main controller sends the card's personal certificate and signature to the PSAM card, which then verifies the card's personal certificate and signature.
[0095] After the signature verification is successful, the PSAM card sends the gate certificate and signature to the user's card through the main controller.
[0096] The card verifies the gate certificate and signature. Once verified, it generates an entry log based on the entry initialization information and returns the verification result.
[0097] After receiving the verification result, the main controller opens the gate.
[0098] See Figure 4 As shown, when exiting the station:
[0099] The main controller of the exit gate reads the digital currency balance information of the card and the entry transaction record, and calculates the amount to be deducted based on the entry station information in the entry transaction record.
[0100] Check if the card balance is greater than or equal to the amount to be deducted. If yes, proceed with the next steps. If not, indicate insufficient balance.
[0101] When the balance in the card is greater than or equal to the amount to be deducted, the main controller sends outbound initialization information to the card, which includes the current time and the amount to be deducted.
[0102] After receiving the outbound initialization information, the card returns the first random number and the first negotiation factor.
[0103] The main controller sends the first random number and the first negotiation factor to the PSAM card, which generates the second random number and the second negotiation factor. Based on the first random number, the first negotiation factor, the second random number, and the second negotiation factor, a second key is generated. The second key is used to generate the authentication ciphertext, and the second random number, the second negotiation factor, and the authentication ciphertext are returned to the card.
[0104] The card generates a second key based on a first random number, a first negotiation factor, a second random number, and a second negotiation factor. The second key is used to decrypt the authentication ciphertext. After successful decryption, voucher data (containing the digital currency amount to be deducted) is generated according to the amount to be deducted. The voucher data is then encrypted using the second key and sent to the gate.
[0105] The main controller sends the encrypted credential data to the PSAM card. The PSAM card decrypts the credential data, verifies whether the amount of digital currency in the credential data is correct, and returns the verification result.
[0106] If the verification result is correct, a transaction record is generated based on the exit initialization information and the amount to be deducted. The decrypted voucher data is stored in the voucher file in the secure storage medium inside the gate, and the gate is opened.
[0107] See Figure 5 As shown, when summarizing fund reports:
[0108] The gate controller indexes all credential files in the secure storage medium and performs compression calculations to obtain the compressed credential data value.
[0109] The main controller sends the current time and the compressed value of the credential data to the PSAM card.
[0110] The PSAM card sends the gate's identification ID and authentication ciphertext encrypted with a preset first key to the backend device.
[0111] The backend device verifies the identifier ID and authentication ciphertext, and returns an initialization response. The initialization response is encrypted using the first key.
[0112] The PSAM card verifies the initialization response information (decrypts the initialization response information). After successful decryption, the first key is used to encrypt the credential data compression value and transaction record, and the result is returned to the main controller.
[0113] The main controller sends the credential file, encrypted credential data compression value, and transaction log from the secure storage medium to the back-end device.
[0114] The back-end equipment verifies the voucher file based on the compressed voucher data and transaction records, and returns the verification result.
[0115] The PSAM card verifies the results. If the verification result is correct, it returns a completed result message to the backend device. After confirming the result message, the backend device returns a confirmation result.
[0116] After receiving the confirmation result, the gate clears the uploaded transaction records from the PSAM card, and the main controller controls the security storage medium to clear the uploaded credential files.
[0117] Through the above scheme, digital currency can be successfully applied to the rail transit sector, effectively avoiding the bottleneck of PSAM storage capacity in the application of digital currency in the rail transit sector, and achieving fund reporting and aggregation without reducing communication speed.
[0118] Example 3:
[0119] Based on the same inventive concept, this application also provides a digital currency transaction settlement device 100. Please refer to [link / reference]. Figure 6 As shown, Figure 6 It shows the use of Figure 2 The illustrated method pertains to a digital currency transaction settlement device. It should be understood that the specific functions of device 100 are described above; to avoid repetition, detailed descriptions are omitted here. Device 100 includes at least one software function module that can be stored in memory or embedded in the operating system of device 100 in the form of software or firmware. Specifically:
[0120] See Figure 6 As shown, the device 100 is used in a turnstile and includes: a receiving module 101 and a processing module 102. Wherein:
[0121] The receiving module 101 is used to receive voucher data generated by the user-end digital currency device; the voucher data includes the digital currency paid by the user-end digital currency device.
[0122] The processing module 102 is used to save the voucher data to a preset secure storage medium; the secure storage medium is set independently of the transaction processing unit of the gate.
[0123] In one feasible embodiment of this application, the processing module 102 is further configured to send each credential data in the secure storage medium to a preset backend device when a preset reporting condition is triggered; and, after receiving a response message returned by the backend device, clear each of the credential data stored in the secure storage medium; the response message indicates that the backend device has successfully saved each of the credential data.
[0124] In one example of the above feasible implementation, the processing module 102 is specifically used to perform compression calculation on each of the credential data in the secure storage medium to obtain a credential data compression value; send the credential data compression value and each of the credential data to the backend device, so that the backend device can verify whether the received credential data is the credential data in the secure storage medium according to the credential data compression value, and return the response message when the verification is successful.
[0125] In an optional example of the above-described method, the processing module 102 is specifically configured to: read the transaction flow in the transaction processing unit of the gate before sending the compressed value of the voucher data and each of the voucher data to the backend device; send the compressed value of the voucher data, the transaction flow, and each of the voucher data to the backend device, so that the backend device can verify whether the received voucher data is the voucher data in the secure storage medium according to the compressed value of the voucher data, and verify whether the total amount of digital currency in the voucher data is correct according to the transaction flow, and return the response message when both verifications pass.
[0126] In the above optional example, the processing module 102 is further configured to clear the transaction log in the transaction processing unit after receiving the response message returned by the backend device.
[0127] In the above optional example, the processing module 102 is specifically used to encrypt the compressed voucher data value and the transaction flow in the transaction processing unit of the gate respectively using a preset first key before sending the compressed voucher data value, the transaction flow and each of the voucher data to the back-end device; and to send the encrypted compressed voucher data value, the transaction flow and each of the voucher data to the back-end device.
[0128] In this embodiment of the application, the receiving module 101 is further configured to receive the first negotiation parameters generated by the user-end digital currency device and generate the second negotiation parameters before receiving the certificate data generated by the user-end digital currency device;
[0129] The processing module 102 is configured to generate a second key based on the first negotiation parameters and the second negotiation parameters; generate authentication ciphertext using the second key, and send the second negotiation parameters and the authentication ciphertext to the user-end digital currency device, so that the user-end digital currency device can generate the second key using the second negotiation parameters and the first negotiation parameters to decrypt the authentication ciphertext, and after successful decryption, encrypt the voucher data using the second key; receive the encrypted voucher data from the user-end digital currency device; and decrypt the voucher data using the second key.
[0130] It should be understood that, for the sake of brevity, some of the content described in Embodiment 1 will not be repeated in this embodiment.
[0131] Example 4:
[0132] This embodiment provides a turnstile, the structure of which can be found in [reference needed]. Figure 1 As shown, it includes a main controller, a secure storage medium, and a transaction processing unit.
[0133] The main controller is used to receive the voucher data generated by the user-end digital currency device and send it to the transaction processing unit; the voucher data includes the digital currency paid by the user-end digital currency device.
[0134] The transaction processing unit is used to verify the legality of the voucher data, and after successful verification, stores the voucher data in the secure storage medium.
[0135] It should be understood that the main controller is also used to retrieve the credential data from the secure storage medium and send it to a preset backend device when a preset reporting condition is triggered; and to clear each of the credential data stored in the secure storage medium after receiving a response message from the backend device; the response message indicates that the backend device has successfully saved each of the credential data.
[0136] Understandable. Figure 1 The structure shown is for illustrative purposes only; the turnstile may also include components larger than those shown. Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown can include, for example, short-range wireless communication modules such as Bluetooth and NFC, and access control components such as gates.
[0137] It should be noted that the methods shown in the first and second embodiments of this application can be implemented through the cooperation of the main controller, secure storage medium and transaction processing unit inside the gate, which will not be described in detail here.
[0138] This embodiment also provides a readable storage medium, such as a floppy disk, optical disk, hard disk, flash memory, USB flash drive, SD (Secure Digital Memory Card), MMC (Multimedia Card), etc. This readable storage medium stores one or more programs that implement the above steps. These programs can be executed by one or more devices with data processing capabilities (such as the main controller and transaction processing unit within the gate) to implement the methods and processes in Embodiment 1 and / or Embodiment 2. Further details will not be elaborated here.
[0139] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0140] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0141] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0142] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0143] In this article, "multiple" refers to two or more.
[0144] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for transaction settlement of digital currency, characterized in that, Applied in turnstiles, including: Receive voucher data generated by a user-end digital currency device; the voucher data includes the digital currency paid by the user-end digital currency device; The voucher data is saved to a preset secure storage medium; the secure storage medium is set up independently of the transaction processing unit of the gate; Before receiving the credential data generated by the user's digital currency device, the method further includes: Receive the first negotiation parameters generated by the user-end digital currency device, and generate the second negotiation parameters; A second key is generated based on the first negotiation parameters and the second negotiation parameters; The second key is used to generate authentication ciphertext, and the second negotiation parameter and the authentication ciphertext are sent to the user-end digital currency device so that the user-end digital currency device can use the second negotiation parameter and the first negotiation parameter to generate the second key to decrypt the authentication ciphertext, and after successful decryption, use the second key to encrypt the credential data. Correspondingly, the receipt data generated by the user's digital currency device includes: Receive the encrypted certificate data from the user-end digital currency device; The credential data is decrypted using the second key.
2. The digital currency transaction settlement method as described in claim 1, characterized in that, The method further includes: When the preset reporting conditions are triggered, the data of each credential in the secure storage medium is sent to the preset backend device; Upon receiving a response message from the backend device, the system clears all the credential data stored in the secure storage medium; the response message indicates that the backend device has successfully saved all the credential data.
3. The digital currency transaction settlement method as described in claim 2, characterized in that, Sending the credential data from the secure storage medium to the preset backend device includes: The credential data in the secure storage medium is compressed to obtain the credential data compression value. The compressed value of the credential data and each of the credential data are sent to the backend device, so that the backend device can verify whether the received credential data is the credential data in the secure storage medium based on the compressed value of the credential data, and return the response message when the verification is successful.
4. The digital currency transaction settlement method as described in claim 3, characterized in that, Before sending the compressed value of the voucher data and each of the voucher data to the backend device, the method further includes: Read the transaction log from the transaction processing unit of the gate; Correspondingly, the compressed value of the voucher data and each of the voucher data are sent to the backend device, so that the backend device can verify whether the received voucher data is the same as the voucher data in the secure storage medium based on the compressed value of the voucher data, and return the response message when the verification is successful, including: The compressed value of the voucher data, the transaction record, and each of the voucher data are sent to the backend device, so that the backend device can verify whether the received voucher data is the same as the voucher data in the secure storage medium based on the compressed value of the voucher data, and verify whether the total amount of digital currency in the voucher data is correct based on the transaction record. If both verifications pass, the response message is returned.
5. The digital currency transaction settlement method as described in claim 4, characterized in that, After receiving the response message returned by the backend device, the method further includes: Clear the transaction log in the transaction processing unit.
6. The digital currency transaction settlement method as described in claim 4, characterized in that, Before sending the compressed voucher data, the transaction log, and each of the voucher data to the backend device, the method further includes: The compressed value of the voucher data and the transaction flow in the transaction processing unit of the gate are encrypted using a preset first key. Correspondingly, the compressed value of the voucher data, the transaction log, and each of the voucher data are sent to the backend device, including: The encrypted compressed value of the voucher data, the transaction log, and each of the voucher data are sent to the backend device.
7. A transaction settlement device for digital currency, characterized in that, Applied in turnstiles, it includes: a receiving module and a processing module; The receiving module is used to receive voucher data generated by the user-end digital currency device; the voucher data includes the digital currency paid by the user-end digital currency device; The processing module is used to save the voucher data to a preset secure storage medium; the secure storage medium is set independently of the transaction processing unit of the gate; The receiving module is further configured to receive a first negotiation parameter generated by the user-end digital currency device and generate a second negotiation parameter before receiving the voucher data generated by the user-end digital currency device. The processing module is further configured to generate a second key based on the first negotiation parameter and the second negotiation parameter; generate authentication ciphertext using the second key, and send the second negotiation parameter and the authentication ciphertext to the user-end digital currency device, so that the user-end digital currency device can generate the second key using the second negotiation parameter and the first negotiation parameter, decrypt the authentication ciphertext, and encrypt the voucher data using the second key after successful decryption; receive the encrypted voucher data from the user-end digital currency device; and decrypt the voucher data using the second key.
8. A turnstile, characterized in that, include: Main controller, secure storage medium, and transaction processing unit; The secure storage medium is provided independently of the transaction processing unit; The main controller is used to receive the voucher data generated by the user-end digital currency device and send it to the transaction processing unit; the voucher data includes the digital currency paid by the user-end digital currency device. The transaction processing unit is used to store the credential data into the secure storage medium; The transaction processing unit is further configured to generate a second key based on the first negotiation parameter and the second negotiation parameter; generate an authentication ciphertext using the second key; and send the second negotiation parameter and the authentication ciphertext to the user-end digital currency device, so that the user-end digital currency device can generate the second key using the second negotiation parameter and the first negotiation parameter, decrypt the authentication ciphertext, and encrypt the voucher data using the second key after successful decryption. Receive the encrypted certificate data from the user-end digital currency device; The second key is used to decrypt the credential data; wherein the first negotiation parameter is generated by the user-end digital currency device, and the second negotiation parameter is generated by the transaction processing unit.
9. The turnstile as described in claim 8, characterized in that, The main controller is also configured to retrieve the credential data from the secure storage medium and send it to a preset backend device when a preset reporting condition is triggered; and to clear each of the credential data stored in the secure storage medium after receiving a response message from the backend device; the response message indicates that the backend device has successfully saved each of the credential data.