Payment method, apparatus and system based on hardware wallet

CN116415947BActive Publication Date: 2026-08-11THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0002]现有硬件钱包需要绑定手机号等身份信息才能使用,但是对于刚入境的外国人和老年人等不方便绑定手机号的用户来说,其使用方式并不方便

Benefits of technology

[0049]上述发明中的一个实施例具有如下优点或有益效果:通过接收支付请求,支付请求包括第一支付密码和付款钱包标识;根据付款钱包标识获取付款钱包信息,付款钱包信息包括付款钱包的支付密码模式和付款钱包绑定的关联钱包标识,支付密码模式用于判断付款钱包是否支持关联钱包的密码复用;在付款钱包支持关联钱包的密码复用的情况下,根据关联钱包标识获取关联钱包的第二支付密码;根据第一支付密码和第二支付密码对支付请求进行支付校验,并在支付校验通过的情况下,进行支付处理的技术方案,即可基于硬件钱包绑定的关联钱包的支付密码来进行支付,无需设置多个支付密码,从而避免了由于用户忘记支付密码而导致支付失败的情况的发生,实现了基于硬件钱包进行便捷支付,扩展了数字货币的应用场景。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116415947B_ABST
    Figure CN116415947B_ABST
Patent Text Reader

Abstract

This invention discloses a payment method, apparatus, and system based on a hardware wallet, relating to the field of digital currency technology. One specific embodiment of the method includes: receiving a payment request, the payment request including a first payment password and a payment wallet identifier; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including the payment wallet's payment password mode and a bound associated wallet identifier, the payment password mode being used to determine whether the payment wallet supports password reuse with associated wallets; if the payment wallet supports password reuse with associated wallets, obtaining a second payment password for the associated wallet based on the associated wallet identifier; performing payment verification on the payment request based on the first payment password and the second payment password, and performing payment processing if the payment verification passes. This embodiment enables convenient payment based on a hardware wallet, expanding the application scenarios of digital currency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital currency technology, and in particular to a payment method, apparatus and system based on a hardware wallet. Background Technology

[0002] Existing hardware wallets require users to link their mobile phone number or other identity information to use them. However, this is inconvenient for users who have just entered the country, such as foreigners, or the elderly, who find it difficult to link their mobile phone numbers. This limits the application scenarios of hardware wallets, thereby limiting the application scenarios of digital currencies. Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a payment method, device, and system based on a hardware wallet, which can make payments based on the payment password of the associated wallet bound to the hardware wallet, eliminating the need to set multiple payment passwords. This avoids payment failures due to users forgetting their payment passwords, realizes convenient payments based on hardware wallets, and expands the application scenarios of digital currency.

[0004] To achieve the above objectives, according to one aspect of the present invention, a payment method based on a hardware wallet is provided, the method being applied to a payer operating institution, the method comprising:

[0005] Receive a payment request, the payment request including a first payment password and a payment wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity;

[0006] The payment wallet information is obtained based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet.

[0007] If the payment wallet supports password reuse for associated wallets, the second payment password of the associated wallet is obtained based on the associated wallet identifier;

[0008] The payment request is verified based on the first payment password and the second payment password, and payment is processed if the verification is successful.

[0009] Optionally, the payment request further includes a first transaction count; before obtaining payment wallet information based on the payment wallet identifier, the request further includes: performing a first verification on the payment request based on the first transaction count.

[0010] Optionally, performing a first verification on the payment request based on the first transaction count includes: determining whether the first transaction count is greater than the second transaction count stored in the payment wallet; if the first transaction count is greater than the second transaction count, generating a decryption key based on the first transaction count and using the decryption key to decrypt the payment request; if decryption is successful, the first verification of the payment request passes; if the first transaction count is not greater than the second transaction count or decryption fails, the first verification of the payment request fails.

[0011] Optionally, generating a decryption key based on the first number of transactions includes: performing symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate a decryption key.

[0012] Optionally, the method further includes: incrementing the second transaction count after the payment processing is completed.

[0013] Optionally, the payment request further includes a message authentication code generated based on the payment information; after the first verification of the payment request passes, and before obtaining the payment wallet information based on the payment wallet identifier, the method further includes: performing a second verification on the payment request based on the message authentication code.

[0014] Optionally, performing a second verification on the payment request based on the message authentication code includes: obtaining payment information from the payment request; generating a first message authentication code based on the payment information; performing a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes; otherwise, the second verification fails.

[0015] Optionally, the payment information includes a payment amount; the payment processing includes: obtaining a first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet and having the receiving party's operating institution process the payment in the receiving wallet; otherwise, calculating the difference between the first balance and the payment amount, deducting the first balance from the payment wallet, deducting the difference from the second balance of the associated wallet, and having the receiving party's operating institution process the payment in the receiving wallet.

[0016] Optionally, before deducting the first balance from the payment wallet and the difference from the second balance of the associated wallet, the method further includes: confirming that the second balance of the associated wallet is greater than or equal to the difference; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0017] Optionally, it further includes: if the payment wallet does not support password reuse for associated wallets, obtaining a third payment password for the payment wallet; performing payment verification on the payment request based on the first payment password and the third payment password, and performing payment processing if the payment verification passes.

[0018] Optionally, the payment processing includes: obtaining a first balance in the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance in the payment wallet and having the receiving party's operating institution credit the payment wallet; otherwise, the payment fails.

[0019] According to another aspect of the present invention, a payment device based on a hardware wallet is provided, the device being applied to a payer operating institution, the device comprising:

[0020] A payment request receiving module is used to receive a payment request, the payment request including a first payment password and a payment wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity;

[0021] The wallet information acquisition module is used to acquire payment wallet information based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet.

[0022] The payment password acquisition module is used to acquire the second payment password of the associated wallet based on the associated wallet identifier when the payment wallet supports password reuse of associated wallets;

[0023] The payment verification processing module is used to verify the payment request based on the first payment password and the second payment password, and to process the payment if the payment verification is successful.

[0024] According to another aspect of the present invention, a payment method based on a hardware wallet is provided, comprising:

[0025] The hardware wallet receiving terminal sends a payment instruction to the payment wallet, which is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity;

[0026] The payment wallet generates a payment message according to the payment instruction and sends the payment message to the acceptance terminal;

[0027] The receiving terminal generates a payment request based on the payment message and sends the payment request, which includes a first payment password, a payment wallet identifier, and a receiving wallet identifier.

[0028] The paying party operator receives the payment request, obtains payment wallet information based on the payment wallet identifier, the payment wallet information includes the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet, the payment password mode is used to determine whether the payment wallet supports password reuse of associated wallets; if the payment wallet supports password reuse of associated wallets, obtains the second payment password of the associated wallet based on the associated wallet identifier; performs payment verification on the payment request based on the first payment password and the second payment password, and performs payment processing if the payment verification passes; and returns the payment processing result.

[0029] Optionally, the payment request further includes a first transaction count; before generating a payment message according to the payment instruction, the payment wallet further includes: incrementing the first transaction count stored in itself according to the payment instruction, and then generating an encryption key according to the first transaction count, the encryption key being used to encrypt the payment information; and before obtaining the payment wallet information according to the payment wallet identifier, the payment operator further includes: performing a first verification on the payment request according to the first transaction count.

[0030] Optionally, the payment wallet generating an encryption key based on the first number of transactions includes: the payment wallet performing symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate an encryption key.

[0031] Optionally, the payment operator's first verification of the payment request based on the first transaction count includes: the payment operator determining whether the first transaction count is greater than the second transaction count stored in the payment wallet; if the first transaction count is greater than the second transaction count, generating a decryption key based on the first transaction count and using the decryption key to decrypt the payment request; if decryption is successful, the first verification of the payment request passes; if the first transaction count is not greater than the second transaction count or decryption fails, the first verification of the payment request fails.

[0032] Optionally, the payment operator generating the decryption key based on the first transaction count includes: the payment operator performing symmetric encryption on the first transaction count and the wallet key generated when the payment wallet was opened to generate the decryption key.

[0033] Optionally, the method further includes: after the payment processing is completed, the paying party operating institution increments the second transaction number.

[0034] Optionally, the payment request further includes a message authentication code generated based on the payment information; before the payment wallet generates a payment message based on the payment instruction, the payment wallet further includes: organizing the payment information based on the payment instruction and generating the message authentication code based on the payment information; after the first verification of the payment request passes and before obtaining the payment wallet information based on the payment wallet identifier, the payment operator further includes: performing a second verification of the payment request based on the message authentication code.

[0035] Optionally, the paying party operating institution performs a second verification on the payment request based on the message authentication code, including: the paying party operating institution obtains payment information from the payment request; generates a first message authentication code based on the payment information; performs a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes; otherwise, the second verification fails.

[0036] Optionally, the payment information includes the payment amount; the payment processing by the payer operating institution includes: the payer operating institution obtaining the first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet; otherwise, calculating the difference between the first balance and the payment amount, deducting the first balance from the payment wallet, and deducting the difference from the second balance of the associated wallet.

[0037] Optionally, before the payer deducts the first balance from the payment wallet and the difference from the second balance of the associated wallet, the payment operator further includes: confirming that the second balance of the associated wallet is greater than or equal to the difference; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0038] Optionally, it further includes: if the payment wallet does not support password reuse for associated wallets, the paying party operator obtains a third payment password for the payment wallet, performs payment verification on the payment request based on the first payment password and the third payment password, and performs payment processing if the payment verification passes.

[0039] Optionally, the payment processing by the payer operating institution includes: the payer operating institution obtaining a first balance in the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance in the payment wallet; otherwise, the payment fails.

[0040] Optionally, when the payer operating institution corresponding to the payment wallet and the payee operating institution corresponding to the receiving wallet are different institutions, the receiving terminal sending the payment request includes: the receiving terminal sending the payment request to the receiving operating institution; the payer operating institution receiving the payment request includes: the payer operating institution receiving the payment request sent by the receiving operating institution; the payer operating institution returning the payment processing result includes: the payer operating institution returning the payment processing result to the receiving operating institution; and, after the payer operating institution returns the payment processing result, the method further includes: the receiving operating institution performing accounting processing on the receiving wallet according to the payment processing result and returning the accounting processing result to the receiving terminal.

[0041] Optionally, if the payment processing result indicates that the paying party's operating institution has successfully deducted the payment, the receiving party's operating institution will perform accounting processing on the receiving wallet based on the payment processing result, including: the receiving party's operating institution will process the receipt of funds into the receiving wallet; if the payment processing result indicates that the paying party's operating institution has failed to make the payment, the receiving party's operating institution will perform accounting processing on the receiving wallet based on the payment processing result, including: the receiving party's operating institution will not perform any accounting processing on the receiving wallet.

[0042] According to another aspect of the present invention, a payment system based on a hardware wallet is provided, comprising:

[0043] A hardware wallet receiving terminal is used to: send a payment instruction to a payment wallet, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; generate a payment request based on a payment message, and send the payment request, wherein the payment request includes a first payment password, a payment wallet identifier, and a receiving wallet identifier;

[0044] The payment wallet is used to: generate a payment message according to the payment instruction and send the payment message to the receiving terminal;

[0045] The paying party operating institution is configured to: receive the payment request; obtain payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse for associated wallets; if the payment wallet supports password reuse for associated wallets, obtain the second payment password of the associated wallet based on the associated wallet identifier; perform payment verification on the payment request based on the first payment password and the second payment password, and if the payment verification passes, perform payment processing; and return the payment processing result.

[0046] Optionally, if the payer operating institution corresponding to the payment wallet and the payee operating institution corresponding to the receiving wallet are different institutions, the system further includes a payee operating institution, and the receiving terminal is further configured to: send the payment request to the payee operating institution; the payer operating institution is further configured to: receive the payment request sent by the payee operating institution; and return the payment processing result to the payee operating institution; the payee operating institution is configured to: perform accounting processing on the receiving wallet according to the payment processing result and return the accounting processing result to the receiving terminal.

[0047] According to another aspect of the present invention, a payment electronic device based on a hardware wallet is provided, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the payment method based on a hardware wallet provided in the embodiments of the present invention.

[0048] According to another aspect of the present invention, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the hardware wallet-based payment method provided in the embodiments of the present invention.

[0049] One embodiment of the above invention has the following advantages or beneficial effects: By receiving a payment request, which includes a first payment password and a payment wallet identifier; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse for associated wallets; if the payment wallet supports password reuse for associated wallets, obtaining a second payment password for the associated wallet based on the associated wallet identifier; and verifying the payment request based on the first and second payment passwords, and processing the payment if the verification passes, the technical solution allows payment to be made based on the payment password of the associated wallet bound to the hardware wallet, eliminating the need to set multiple payment passwords. This avoids payment failures due to users forgetting their payment passwords, enabling convenient payment based on hardware wallets and expanding the application scenarios of digital currency.

[0050] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0051] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:

[0052] Figure 1 This is a schematic diagram of the main steps of a hardware wallet-based payment method according to the first embodiment of the present invention;

[0053] Figure 2 This is a schematic diagram of the main steps of a hardware wallet-based payment method according to a second embodiment of the present invention;

[0054] Figure 3 This is a schematic diagram of the payment process based on a hardware wallet according to the third embodiment of the present invention;

[0055] Figure 4 This is a schematic diagram of the payment process based on a hardware wallet according to the fourth embodiment of the present invention;

[0056] Figure 5 This is a schematic diagram of the main modules of a hardware wallet-based payment device according to the fifth embodiment of the present invention;

[0057] Figure 6 This is a schematic diagram of the main components of a hardware wallet-based payment system according to the sixth embodiment of the present invention;

[0058] Figure 7 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;

[0059] Figure 8This is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present invention. Detailed Implementation

[0060] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0061] This invention provides a hardware wallet solution. The hardware wallet in this embodiment refers to a hardware wallet that is not associated with the user's identity at the time of issuance, but only with the issuing institution's public account. It has a unique hardware wallet number, stores digital identity credentials in the form of a secure chip, and stores the coin string in the operating institution's backend system.

[0062] After issuance, the hardware wallet in this embodiment of the invention can be bound to a personal wallet according to the user's choice, and the bound hardware wallet can be managed through the personal wallet. After the hardware wallet in this embodiment of the invention is associated with the personal wallet, multiple payment passwords will be used during the payment process. However, an increased number of payment passwords increases the user's memory burden, and if the user forgets a payment password, the payment will fail, severely limiting the application scenarios of digital currency.

[0063] To address the technical problems existing in the prior art, this invention provides a payment method, device, and system based on a hardware wallet. The implementation principle is as follows: A hardware wallet receiving terminal (POS machine) located at the payee sends a payment instruction to the hardware wallet. The hardware wallet has a bound associated wallet, which is a normally issued wallet associated with the user's identity; it can be a software wallet or a hardware wallet. The hardware wallet generates a payment message and returns it to the receiving terminal. The receiving terminal generates a payment request based on the payment message and sends it to the payee's operating institution. The payee's operating institution confirms the payer's operating institution based on the payment request and sends the payment request to the payer's operating institution. After verifying the information, the payer's operating institution determines that the hardware wallet's payment password mode reuses the associated wallet's payment password. It then searches for the corresponding associated wallet information based on the hardware wallet information, verifies the payment password against the associated wallet's payment password, and deducts the payment upon successful verification. A successful deduction message is sent to the payee's operating institution. The payee's operating institution processes the payment in the payee's wallet and returns the result to the receiving terminal, which displays the payment result. In this way, payments can be made based on the payment password of the associated wallet linked to the hardware wallet, eliminating the need to set multiple payment passwords. This avoids payment failures due to users forgetting their payment passwords, enabling convenient payments based on hardware wallets and expanding the application scenarios of digital currency.

[0064] Figure 1 This is a schematic diagram illustrating the main steps of a hardware wallet-based payment method according to a first embodiment of the present invention. Figure 1 As shown, the payment method based on a hardware wallet in the first embodiment of the present invention is applied to the payment operator and mainly includes the following steps:

[0065] Step S101: Receive a payment request, the payment request including a first payment password and a payment wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity;

[0066] Step S102: Obtain payment wallet information based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet.

[0067] Step S103: If the payment wallet supports password reuse for associated wallets, obtain the second payment password of the associated wallet based on the associated wallet identifier;

[0068] Step S104: Verify the payment request based on the first payment password and the second payment password, and process the payment if the payment verification is successful.

[0069] According to the technical solution of this invention, the associated wallet can be a software wallet or a hardware wallet. The software wallet refers to a digital currency app running on a terminal, such as a digital yuan app or a digital euro app.

[0070] According to one embodiment of the present invention, the payment request further includes a first transaction count; and before obtaining payment wallet information based on the payment wallet identifier, the method further includes: performing a first verification on the payment request based on the first transaction count.

[0071] According to another embodiment of the present invention, the first verification of the payment request based on the first transaction count includes: determining whether the first transaction count is greater than the second transaction count stored in the payment wallet; if the first transaction count is greater than the second transaction count, generating a decryption key based on the first transaction count, and using the decryption key to decrypt the payment request; if the decryption is successful, the first verification of the payment request passes; if the first transaction count is not greater than the second transaction count or the decryption fails, the first verification of the payment request fails.

[0072] According to another embodiment of the present invention, generating a decryption key based on the first transaction count includes: performing symmetric encryption on the first transaction count and the wallet key generated when the payment wallet was opened to generate a decryption key.

[0073] According to another embodiment of the present invention, the payment method based on a hardware wallet further includes: incrementing the second transaction count after the payment processing is completed.

[0074] According to another embodiment of the present invention, the payment request further includes a message authentication code generated based on the payment information; and, after the first verification of the payment request passes and before obtaining the payment wallet information based on the payment wallet identifier, the method further includes: performing a second verification on the payment request based on the message authentication code.

[0075] According to another embodiment of the present invention, performing a second verification on the payment request based on the message authentication code includes: obtaining payment information from the payment request; generating a first message authentication code based on the payment information; performing a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes; otherwise, the second verification fails.

[0076] According to another embodiment of the present invention, the payment information includes a payment amount; and the payment processing includes: obtaining a first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet and causing the receiving party operating institution to process the payment in the receiving wallet; otherwise, calculating the difference between the first balance and the payment amount, deducting the first balance from the payment wallet, deducting the difference from the second balance of the associated wallet, and causing the receiving party operating institution to process the payment in the receiving wallet.

[0077] According to another embodiment of the present invention, before deducting the first balance from the payment wallet and deducting the difference from the second balance of the associated wallet, the method further includes: confirming that the second balance of the associated wallet is greater than or equal to the difference; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0078] According to another embodiment of the present invention, the payment method based on a hardware wallet further includes: obtaining a third payment password of the payment wallet when the payment wallet does not support password reuse of associated wallets; performing payment verification on the payment request based on the first payment password and the third payment password, and performing payment processing if the payment verification passes.

[0079] According to another embodiment of the present invention, the payment processing includes: obtaining a first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet and causing the receiving party's operating institution to process the payment in the receiving wallet; otherwise, the payment fails.

[0080] According to the technical solution of this invention, by receiving a payment request, which includes a first payment password and a payment wallet identifier; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse of the associated wallet; if the payment wallet supports password reuse of the associated wallet, obtaining a second payment password of the associated wallet based on the associated wallet identifier; and verifying the payment request based on the first payment password and the second payment password, and performing payment processing if the payment verification passes, this technical solution enables payment based on the payment password of the associated wallet bound to the hardware wallet, eliminating the need to set multiple payment passwords, thereby avoiding payment failures due to users forgetting their payment passwords. This achieves convenient payment based on a hardware wallet and expands the application scenarios of digital currency.

[0081] Figure 2 This is a schematic diagram illustrating the main steps of a hardware wallet-based payment method according to a second embodiment of the present invention. Figure 2 As shown, the payment method based on a hardware wallet according to the second embodiment of the present invention mainly includes the following steps:

[0082] Step S201: The hardware wallet receiving terminal sends a payment instruction to the payment wallet, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity;

[0083] Step S202: The payment wallet generates a payment message according to the payment instruction and sends the payment message to the receiving terminal;

[0084] Step S203: The receiving terminal generates a payment request based on the payment message and sends the payment request, which includes a first payment password, a payment wallet identifier, and a receiving wallet identifier;

[0085] Step S204: The paying party operating institution receives the payment request, obtains payment wallet information based on the payment wallet identifier, the payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet, the payment password mode is used to determine whether the payment wallet supports password reuse of associated wallets; if the payment wallet supports password reuse of associated wallets, obtains the second payment password of the associated wallet based on the associated wallet identifier; performs payment verification on the payment request based on the first payment password and the second payment password, and performs payment processing if the payment verification passes; returns the payment processing result.

[0086] According to one embodiment of the present invention, the payment request further includes a first transaction count; and, before the payment wallet generates a payment message according to the payment instruction, the payment wallet further includes: incrementing the first transaction count stored in itself according to the payment instruction, and then generating an encryption key according to the first transaction count, the encryption key being used to encrypt the payment information; and, before the payer operating institution obtains the payment wallet information according to the payment wallet identifier, the payer operating institution further includes: performing a first verification on the payment request according to the first transaction count.

[0087] According to another embodiment of the present invention, the payment wallet generating an encryption key based on the first number of transactions includes: the payment wallet performing symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate an encryption key.

[0088] According to another embodiment of the present invention, the payment operator performs a first verification of the payment request based on the first transaction count, which includes: the payment operator determining whether the first transaction count is greater than a second transaction count stored in the payment wallet; if the first transaction count is greater than the second transaction count, generating a decryption key based on the first transaction count, and using the decryption key to decrypt the payment request; if the decryption is successful, the first verification of the payment request passes; if the first transaction count is not greater than the second transaction count or the decryption fails, the first verification of the payment request fails.

[0089] According to another embodiment of the present invention, the payment operator generates a decryption key based on the first number of transactions by performing symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate a decryption key.

[0090] According to another embodiment of the present invention, the payment method based on a hardware wallet further includes: the payer operating institution incrementing the second transaction count after the payment processing is completed.

[0091] According to another embodiment of the present invention, the payment request further includes a message authentication code generated based on the payment information; and, before the payment wallet generates a payment message according to the payment instruction, the payment wallet further includes: organizing the payment information according to the payment instruction and generating the message authentication code based on the payment information; and, after the first verification of the payment request is passed and before obtaining the payment wallet information based on the payment wallet identifier, the payment operator further includes: performing a second verification of the payment request based on the message authentication code.

[0092] According to another embodiment of the present invention, the payment operator performs a second verification on the payment request based on the message authentication code, including: the payment operator obtains payment information from the payment request; generates a first message authentication code based on the payment information; performs a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes; otherwise, the second verification fails.

[0093] According to another embodiment of the present invention, the payment information includes a payment amount; the payment processing by the payer operating institution includes: the payer operating institution obtaining a first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet; otherwise, calculating the difference between the first balance and the payment amount, deducting the first balance from the payment wallet, and deducting the difference from the second balance of the associated wallet.

[0094] According to another embodiment of the present invention, before the payer operating institution deducts the first balance from the payment wallet and the difference from the second balance of the associated wallet, the method further includes: the payer operating institution confirming that the second balance of the associated wallet is greater than or equal to the difference; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0095] According to another embodiment of the present invention, the payment method based on a hardware wallet further includes: when the payment wallet does not support password reuse of associated wallets, the payment operator obtains a third payment password of the payment wallet, performs payment verification on the payment request based on the first payment password and the third payment password, and performs payment processing if the payment verification passes.

[0096] According to another embodiment of the present invention, the payment processing by the payer operating institution includes: the payer operating institution obtaining a first balance of the payment wallet; determining whether the first balance is greater than or equal to the payment amount; if so, deducting the payment amount from the first balance of the payment wallet; otherwise, the payment fails.

[0097] According to another embodiment of the present invention, when the payer operating institution corresponding to the payment wallet and the payee operating institution corresponding to the receiving wallet are different institutions, the receiving terminal sending the payment request includes: the receiving terminal sending the payment request to the receiving operating institution; the payer operating institution receiving the payment request includes: the payer operating institution receiving the payment request sent by the receiving operating institution; the payer operating institution returning the payment processing result includes: the payer operating institution returning the payment processing result to the receiving operating institution; and after the payer operating institution returns the payment processing result, the method further includes: the receiving operating institution performing accounting processing on the receiving wallet according to the payment processing result and returning the accounting processing result to the receiving terminal.

[0098] According to another embodiment of the present invention, if the payment processing result is that the paying party's operating institution has successfully deducted the payment, then the receiving party's operating institution performs accounting processing on the receiving wallet according to the payment processing result, including: the receiving party's operating institution performs crediting processing on the receiving wallet; if the payment processing result is that the paying party's operating institution has failed to pay, then the receiving party's operating institution performs accounting processing on the receiving wallet according to the payment processing result, including: the receiving party's operating institution does not perform any accounting processing on the receiving wallet.

[0099] Figure 3 This is a schematic diagram of a payment process based on a hardware wallet according to the third embodiment of the present invention. In this embodiment, the receiving wallet corresponds to a different receiving party operating institution, and the paying wallet corresponds to a different paying party operating institution. For example... Figure 3 The payment process of the third embodiment of the present invention mainly includes the following steps:

[0100] Step 1: The hardware wallet's receiving terminal (such as the recipient's POS machine) sends a payment instruction to the payment wallet (hardware wallet). The payment instruction contains payment amount information. The payment instruction can be sent after the receiving terminal and the payment wallet establish a network connection based on near-field communication methods such as NFC and Bluetooth or other network connection methods. Alternatively, the SIM card / SE card / IC card carrying the payment wallet may display a QR code, which the receiving terminal scans to obtain the payment wallet information before sending the instruction.

[0101] Step 2: Upon receiving a payment instruction, the payment wallet increments its stored transaction counter (which records the number of transactions and increases with each transaction), generates a session encryption key and a transaction index (transaction ID, randomly generated to uniquely identify a transaction), and retrieves the payment wallet identifier, receiving wallet identifier, payment amount, and user-entered payment password. It then organizes the transaction counter value (transaction count), transaction index, payment wallet identifier, receiving wallet identifier, payment amount, and user-entered payment password into payment information. Next, it calculates the Message Authentication Code (MAC) (a keyed hash function used in cryptography to verify the integrity of message data between communicating entities) based on the payment information. Finally, it encrypts the payment information and the MAC using the encryption key to form ciphertext, using the transaction counter value (transaction count) and the payment wallet identifier as plaintext to form the payment message. The encryption key is a dynamic key generated by symmetric encryption using the transaction counter value (transaction count) and the wallet key generated when the payment wallet was opened.

[0102] Step 3: The payment wallet returns the payment message generated in Step 2 to the receiving terminal;

[0103] Step 4: The receiving terminal generates a payment request based on the received payment message and sends it to the payee's operating institution;

[0104] Step 5: The receiving operator determines the paying operator based on the payment wallet identifier in the payment request. Here, the paying operator is different from the receiving operator. In this step, the payment request can also be format-converted to convert the payment request from the receiving terminal into a payment request conforming to the inter-operator request message format. During this process, the content of the payment message remains unchanged; therefore, format adjustments or message encapsulation operations can be ignored. Furthermore, encryption and decryption operations can be performed when the payment request is transferred from one executing entity to another (e.g., from the receiving terminal to the receiving operator), but these are not highly relevant to the technical solution of this invention and can therefore be ignored here.

[0105] Step 6: The receiving institution sends the payment request to the interconnection platform, which is a public platform that allows data exchange with different currency operating institutions during the currency circulation process;

[0106] Step 7: The interconnection platform forwards the payment request to the payer's operating institution;

[0107] Step 8: Upon receiving the payment request, the paying party's operating institution first obtains the transaction counter value (number of transactions) from the payment request and generates a decryption password based on this value to decrypt the payment request. Then, it verifies whether the transaction counter value is greater than the transaction counter value on the paying party's operating institution's end, whether the MAC address is correct, and the payment wallet balance. Next, it obtains the payment password mode of the payment wallet. If the payment password mode supports password reuse between linked wallets, it searches for the corresponding linked wallet information based on the payment wallet identifier, compares the payment password in the payment request with the linked wallet's payment password, and performs verification. If the verification passes, it deducts funds from the payment wallet and processes the accounting. If the payment wallet balance is insufficient, it replenishes the difference from the linked wallet before deduction. If the payment password mode does not support password reuse between linked wallets, it compares the payment password in the payment request with the payment wallet's payment password. If the verification passes and the payment wallet balance is sufficient, it deducts funds from the payment wallet and processes the accounting; otherwise, the payment fails.

[0108] Step 9: The paying party's operating institution sends the payment processing result to the interconnection platform, which includes whether the deduction was successful or the payment failed;

[0109] Step 10: The interconnection platform forwards the payment processing result to the receiving party's operating institution;

[0110] Step 11: After receiving the payment processing result, if the payment processing result is successful deduction, the receiving wallet will be credited and accounting will be processed, and then step 12 will be executed; otherwise, step 12 will be executed directly.

[0111] Step 12: The receiving operator returns the payment processing result to the payment terminal;

[0112] Step 13: The payment terminal displays the payment processing result to the user.

[0113] Figure 4 This is a schematic diagram of a hardware wallet-based payment process according to the fourth embodiment of the present invention. In this embodiment, the paying party operating institution corresponding to the payment wallet and the receiving party operating institution corresponding to the receiving wallet are the same; therefore, the wallet operating institution in this embodiment is represented by the receiving / paying party operating institution. Figure 4 The payment process of the fourth embodiment of the present invention mainly includes the following steps:

[0114] Step 1: The hardware wallet's receiving terminal (such as the recipient's POS machine) sends a payment instruction to the payment wallet (hardware wallet). The payment instruction contains payment amount information. The payment instruction can be sent after the receiving terminal and the payment wallet establish a network connection based on near-field communication methods such as NFC and Bluetooth or other network connection methods. Alternatively, the SIM card / SE card / IC card carrying the payment wallet may display a QR code, which the receiving terminal scans to obtain the payment wallet information before sending the instruction.

[0115] Step 2: Upon receiving a payment instruction, the payment wallet increments its stored transaction counter (which records the number of transactions and increases with each transaction), generates a session encryption key and a transaction index (transaction ID, randomly generated to uniquely identify a transaction), and retrieves the payment wallet identifier, receiving wallet identifier, payment amount, and user-entered payment password. It then organizes the transaction counter value (transaction count), transaction index, payment wallet identifier, receiving wallet identifier, payment amount, and user-entered payment password into payment information. Next, it calculates the Message Authentication Code (MAC) (a keyed hash function used in cryptography to verify the integrity of message data between communicating entities) based on the payment information. Finally, it encrypts the payment information and the MAC using the encryption key to form ciphertext, using the transaction counter value (transaction count) and the payment wallet identifier as plaintext to form the payment message. The encryption key is a dynamic key generated by symmetric encryption using the transaction counter value (transaction count) and the wallet key generated when the payment wallet was opened.

[0116] Step 3: The payment wallet returns the payment message generated in Step 2 to the receiving terminal;

[0117] Step 4: The receiving terminal generates a payment request based on the received payment message and sends it to the payee / payer's operating institution;

[0118] Step 5: The payer / payer operating institution determines that the payer operating institution and the payee operating institution are the same based on the payment wallet identifier in the payment request; therefore, the payer operating institution is the payee operating institution. In this step, when the payment request is transferred from one executing entity to another (e.g., from the receiving terminal to the payer / payer operating institution), encryption and decryption operations can be performed, but these are not highly relevant to the technical solution of this invention and can therefore be ignored here.

[0119] Step 6: Based on the payment request, the payer / payer operating institution first obtains the transaction counter value (number of transactions) from the payment request, and generates a decryption password based on the transaction counter value (number of transactions) to decrypt the payment request. Then, it verifies whether the transaction counter value is greater than the transaction counter value on the payer's operating institution's side, whether the MAC address is correct, and the payment wallet balance, etc. Next, it obtains the payment password mode of the payment wallet. If the payment password mode supports the reuse of payment passwords from associated wallets, it searches for the corresponding associated wallet information based on the payment wallet identifier, compares the payment password in the payment request with the associated wallet's payment password for verification. If the verification is successful, it deducts funds from the payment wallet and processes the account. If the payment wallet balance is insufficient, it replenishes the difference from the associated wallet before deducting funds. If the payment password mode does not support the reuse of payment passwords from associated wallets, it compares the payment password in the payment request with the payment wallet's payment password for verification. If the verification is successful and the payment wallet balance is sufficient, it deducts funds from the payment wallet and processes the account; otherwise, the payment fails. In other words, the payment processing result includes successful deduction and payment failure.

[0120] Step 7: The payee / payer operating institution will process the payment according to the payment processing result. If the payment processing result is successful, the institution will record the payment in the receiving wallet and perform accounting processing, and then proceed to Step 8; otherwise, proceed directly to Step 8.

[0121] Step 8: The payee / payer's operating institution returns the payment processing result to the payment terminal;

[0122] Step 9: The payment terminal displays the payment processing result to the user.

[0123] Figure 5 This is a schematic diagram of the main modules of a hardware wallet-based payment device according to a fifth embodiment of the present invention. Figure 5As shown, the payment device 500 based on a hardware wallet in the fifth embodiment of the present invention is applied to the payment operator and mainly includes a payment request receiving module 501, a wallet information acquisition module 502, a payment password acquisition module 503, and a payment verification processing module 504.

[0124] The payment request receiving module 501 is used to receive a payment request, which includes a first payment password and a payment wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity.

[0125] The wallet information acquisition module 502 is used to acquire payment wallet information based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet.

[0126] The payment password acquisition module 503 is used to acquire the second payment password of the associated wallet based on the associated wallet identifier when the payment wallet supports password reuse of associated wallets;

[0127] The payment verification processing module 504 is used to perform payment verification on the payment request based on the first payment password and the second payment password, and to perform payment processing if the payment verification is successful.

[0128] According to one embodiment of the present invention, the payment request further includes a first transaction count; the payment device 500 based on the hardware wallet may further include a request verification module (not shown in the figure), used to: perform a first verification on the payment request based on the first transaction count before obtaining payment wallet information based on the payment wallet identifier.

[0129] According to another embodiment of the present invention, the request verification module (not shown in the figure) can also be used to: determine whether the first transaction count is greater than the second transaction count of the payment wallet stored therein; if the first transaction count is greater than the second transaction count, generate a decryption key based on the first transaction count, and use the decryption key to decrypt the payment request; if the decryption is successful, the first verification of the payment request passes; if the first transaction count is not greater than the second transaction count or the decryption fails, the first verification of the payment request fails.

[0130] According to another embodiment of the present invention, the request verification module (not shown in the figure) can also be used to: perform symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet is opened to generate a decryption key.

[0131] According to another embodiment of the present invention, the payment device 500 based on a hardware wallet may further include a transaction count increment module (not shown in the figure) for: incrementing the second transaction count after the payment processing is completed.

[0132] According to another embodiment of the present invention, the payment request further includes a message authentication code generated based on the payment information; the request verification module (not shown in the figure) can also be used to: perform a second verification on the payment request based on the message authentication code after the first verification of the payment request passes, and before obtaining the payment wallet information based on the payment wallet identifier.

[0133] According to another embodiment of the present invention, the request verification module (not shown in the figure) can also be used to: obtain payment information from the payment request; generate a first message authentication code based on the payment information; perform a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes, otherwise the second verification fails.

[0134] According to another embodiment of the present invention, the payment information includes a payment amount; the payment verification processing module 504 can also be used to: obtain a first balance of the payment wallet; determine whether the first balance is greater than or equal to the payment amount; if so, deduct the payment amount from the first balance of the payment wallet and enable the receiving party operating institution to process the payment in the receiving wallet; otherwise, calculate the difference between the first balance and the payment amount, deduct the first balance from the payment wallet, deduct the difference from the second balance of the associated wallet, and enable the receiving party operating institution to process the payment in the receiving wallet.

[0135] According to another embodiment of the present invention, the payment verification processing module 504 can also be used to: confirm that the second balance of the associated wallet is greater than or equal to the difference before deducting the first balance from the payment wallet and deducting the difference from the second balance of the associated wallet; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0136] According to another embodiment of the present invention, the payment password acquisition module 503 can also be used to: acquire a third payment password of the payment wallet when the payment wallet does not support password reuse of associated wallets; the payment verification processing module 504 can also be used to: perform payment verification on the payment request according to the first payment password and the third payment password, and perform payment processing if the payment verification passes.

[0137] According to another embodiment of the present invention, the payment verification processing module 504 can also be used to: obtain the first balance of the payment wallet; determine whether the first balance is greater than or equal to the payment amount; if so, deduct the payment amount from the first balance of the payment wallet and enable the receiving party operating institution to process the payment wallet; otherwise, the payment fails.

[0138] Figure 6 This is a schematic diagram of the main components of a hardware wallet-based payment system according to the sixth embodiment of the present invention. Figure 6 As shown, the payment system 600 based on a hardware wallet in the sixth embodiment of the present invention mainly includes a hardware wallet acceptance terminal 601, a payment wallet 602, and a payment operator 603. The hardware wallet acceptance terminal 601 is also referred to as the acceptance terminal 601.

[0139] The hardware wallet receiving terminal 601 is used to: send a payment instruction to a payment wallet, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; generate a payment request based on a payment message, and send the payment request, wherein the payment request includes a first payment password, a payment wallet identifier, and a receiving wallet identifier;

[0140] Payment wallet 602 is used to: generate a payment message according to the payment instruction, and send the payment message to the acceptance terminal 601;

[0141] The payer operating institution 603 is configured to: receive the payment request; obtain payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse for associated wallets; if the payment wallet supports password reuse for associated wallets, obtain the second payment password of the associated wallet based on the associated wallet identifier; perform payment verification on the payment request based on the first payment password and the second payment password, and if the payment verification passes, perform payment processing; and return the payment processing result.

[0142] According to one embodiment of the present invention, when the paying party operating institution corresponding to the payment wallet and the receiving party operating institution corresponding to the receiving wallet are different institutions, such as... Figure 6As shown, the payment system 600 based on a hardware wallet in this embodiment of the invention further includes a payee operating institution 604. The receiving terminal 601 is further configured to: send the payment request to the payee operating institution 604; the payer operating institution 603 is further configured to: receive the payment request sent by the payee operating institution 604; and return the payment processing result to the payee operating institution 604; the payee operating institution 604 is configured to: perform accounting processing on the payee wallet according to the payment processing result and return the accounting processing result to the receiving terminal 601.

[0143] According to one embodiment of the present invention, the payment request further includes a first transaction count; before generating a payment message according to the payment instruction, the payment wallet 602 is further configured to: increment the first transaction count stored in itself according to the payment instruction, and then generate an encryption key according to the first transaction count, the encryption key being used to encrypt the payment information; and before obtaining the payment wallet information according to the payment wallet identifier, the payer operating institution 603 is further configured to: perform a first verification on the payment request according to the first transaction count.

[0144] According to another embodiment of the present invention, when generating an encryption key based on the first number of transactions, the payment wallet 602 is further configured to: perform symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate an encryption key.

[0145] According to another embodiment of the present invention, when the payment operator 603 performs a first verification on the payment request based on the first number of transactions, it is further configured to: determine whether the first number of transactions is greater than the second number of transactions stored in the payment wallet; if the first number of transactions is greater than the second number of transactions, generate a decryption key based on the first number of transactions and use the decryption key to decrypt the payment request; if the decryption is successful, the first verification of the payment request passes; if the first number of transactions is not greater than the second number of transactions or the decryption fails, the first verification of the payment request fails.

[0146] According to another embodiment of the present invention, when the payment operator 603 generates the decryption key based on the first number of transactions, it is further configured to: perform symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet is opened to generate the decryption key.

[0147] According to another embodiment of the present invention, the payer operating institution 603 is also used to increment the second transaction number after the payment processing is completed.

[0148] According to another embodiment of the present invention, the payment request further includes a message authentication code generated based on the payment information; and, before generating a payment message according to the payment instruction, the payment wallet 602 is further configured to organize the payment information according to the payment instruction and generate the message authentication code according to the payment information; after the first verification of the payment request is passed and before obtaining the payment wallet information according to the payment wallet identifier, the payer operating institution 603 is further configured to: perform a second verification of the payment request according to the message authentication code.

[0149] According to another embodiment of the present invention, when the payer operating institution 603 performs a second verification on the payment request based on the message authentication code, it is further configured to: obtain payment information from the payment request; generate a first message authentication code based on the payment information; perform a second verification on the payment request by comparing the first message authentication code and the message authentication code; if the comparison result is consistent, the second verification passes; otherwise, the second verification fails.

[0150] According to another embodiment of the present invention, the payment information includes a payment amount; when processing the payment, the payer operating institution 603 is further configured to: obtain a first balance of the payment wallet; determine whether the first balance is greater than or equal to the payment amount; if so, deduct the payment amount from the first balance of the payment wallet; otherwise, calculate the difference between the first balance and the payment amount, deduct the first balance from the payment wallet, and deduct the difference from the second balance of the associated wallet.

[0151] According to another embodiment of the present invention, before deducting the first balance from the payment wallet and the difference from the second balance of the associated wallet, the payer operating institution 603 is further configured to: confirm that the second balance of the associated wallet is greater than or equal to the difference; and, if the second balance of the associated wallet is less than the difference, the payment fails.

[0152] According to another embodiment of the present invention, the payer operating institution 603 is further configured to: obtain a third payment password of the payment wallet when the payment wallet does not support password reuse of associated wallets, perform payment verification on the payment request based on the first payment password and the third payment password, and perform payment processing if the payment verification passes.

[0153] According to another embodiment of the present invention, when the payment operator 603 performs payment processing, it is further configured to: obtain a first balance of the payment wallet; determine whether the first balance is greater than or equal to the payment amount; if so, deduct the payment amount from the first balance of the payment wallet; otherwise, the payment fails.

[0154] According to another embodiment of the present invention, if the payment processing result is that the payment deduction by the payer operating institution is successful, the payee operating institution 604 is further configured to: perform an accounting entry process on the payee wallet when performing accounting processing on the payee wallet according to the payment processing result;

[0155] If the payment processing result is that the payment by the paying party operating institution fails, the receiving party operating institution 604, when performing accounting processing on the receiving wallet based on the payment processing result, is also used to: not perform any accounting processing on the receiving wallet.

[0156] According to the technical solution of this invention, by receiving a payment request, which includes a first payment password and a payment wallet identifier; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse of the associated wallet; if the payment wallet supports password reuse of the associated wallet, obtaining a second payment password of the associated wallet based on the associated wallet identifier; and verifying the payment request based on the first payment password and the second payment password, and performing payment processing if the payment verification passes, this technical solution enables payment based on the payment password of the associated wallet bound to the hardware wallet, eliminating the need to set multiple payment passwords, thereby avoiding payment failures due to users forgetting their payment passwords. This achieves convenient payment based on a hardware wallet and expands the application scenarios of digital currency.

[0157] Figure 7 An exemplary system architecture 700 is shown that can be applied to a hardware wallet-based payment method or a hardware wallet-based payment device according to embodiments of the present invention.

[0158] like Figure 7 As shown, system architecture 700 may include terminal devices 701, 702, and 703, a network 704, and a server 705. Network 704 serves as the medium for providing communication links between terminal devices 701, 702, and 703 and server 705. Network 704 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0159] Users can use terminal devices 701, 702, and 703 to interact with server 705 via network 704 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 701, 702, and 703, such as commercial banking applications, digital currency wallet applications, payment software, etc. (for example only).

[0160] Terminal devices 701, 702, and 703 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0161] Server 705 can be a server providing various services, such as a backend management server (for example only) that supports payment requests received by users using terminal devices 701, 702, and 703. The backend management server can process the received payment requests and other data by obtaining payment wallet information based on the payment wallet identifier. This payment wallet information includes the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse for associated wallets. If the payment wallet supports password reuse for associated wallets, a second payment password for the associated wallet is obtained based on the associated wallet identifier. The payment request is then verified using the first and second payment passwords. If the payment verification passes, payment processing is performed, and the processing result (e.g., payment processing result – for example only) is fed back to the terminal device.

[0162] It should be noted that the payment method based on a hardware wallet provided in this embodiment of the invention is generally executed by the server 705, and correspondingly, the payment device based on a hardware wallet is generally set in the server 705.

[0163] It should be understood that Figure 7 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0164] The following is for reference. Figure 8 It shows a schematic diagram of the structure of a computer system 800 suitable for implementing terminal devices or servers of the present invention. Figure 8 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.

[0165] like Figure 8 As shown, the computer system 800 includes a central processing unit (CPU) 801, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 802 or programs loaded from storage section 808 into random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the system 800. The CPU 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0166] The following components are connected to I / O interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to I / O interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 810 as needed so that computer programs read from it can be installed into storage section 808 as needed.

[0167] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by central processing unit (CPU) 801, it performs the functions defined above in the system of this invention.

[0168] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0169] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0170] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a payment request receiving module, a wallet information acquisition module, a payment password acquisition module, and a payment verification processing module. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a payment request receiving module can also be described as "a module for receiving payment requests."

[0171] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to include: receiving a payment request, the payment request including a first payment password and a payment wallet identifier, wherein the payment wallet is a hardware wallet bound to an associated wallet, the associated wallet being a wallet associated with a user's identity; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including a payment password mode of the payment wallet and an associated wallet identifier bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse for associated wallets; if the payment wallet supports password reuse for associated wallets, obtaining a second payment password for the associated wallet based on the associated wallet identifier; performing payment verification on the payment request based on the first payment password and the second payment password, and performing payment processing if the payment verification passes.

[0172] According to the technical solution of this invention, by receiving a payment request, which includes a first payment password and a payment wallet identifier; obtaining payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the identifier of the associated wallet bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse of the associated wallet; if the payment wallet supports password reuse of the associated wallet, obtaining a second payment password of the associated wallet based on the associated wallet identifier; and verifying the payment request based on the first payment password and the second payment password, and performing payment processing if the payment verification passes, this technical solution enables payment based on the payment password of the associated wallet bound to the hardware wallet, eliminating the need to set multiple payment passwords, thereby avoiding payment failures due to users forgetting their payment passwords. This achieves convenient payment based on a hardware wallet and expands the application scenarios of digital currency.

[0173] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A hardware wallet-based payment method, characterized by, The method is applied to the payer's operating institution, and the method includes: Receive a payment request, the payment request including a first payment password, a payment wallet identifier and a receiving wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; The payment wallet information is obtained based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet. If the payment wallet supports password reuse for associated wallets, the second payment password of the associated wallet is obtained based on the associated wallet identifier; The payment request is verified based on the first payment password and the second payment password, and payment is processed if the verification is successful.

2. The method of claim 1, wherein, The payment request also includes a first transaction count; Before obtaining payment wallet information based on the payment wallet identifier, the process also includes: The payment request is first verified based on the first number of transactions.

3. The method of claim 2, wherein, The first verification of the payment request based on the first number of transactions includes: Determine whether the first number of transactions is greater than the second number of transactions stored in the payment wallet; If the first number of transactions is greater than the second number of transactions, a decryption key is generated based on the first number of transactions, and the decryption key is used to decrypt the payment request; If decryption is successful, the first verification of the payment request passes. If the first number of transactions is not greater than the second number of transactions or if decryption fails, the first verification of the payment request will fail.

4. The method of claim 3, wherein, The decryption key generated based on the first number of transactions includes: The first number of transactions and the wallet key generated when the payment wallet was opened are symmetrically encrypted to generate a decryption key.

5. The method of claim 3, wherein, The method further includes: After payment processing is completed, increment the second transaction count.

6. The method of claim 3, wherein, The payment request also includes a message authentication code generated based on the payment information; After the first verification of the payment request passes, and before obtaining the payment wallet information based on the payment wallet identifier, the process further includes: The payment request is then verified a second time based on the message authentication code.

7. The method of claim 6, wherein, The second verification of the payment request based on the message authentication code includes: Obtain payment information from the payment request; A first message authentication code is generated based on the payment information; The payment request is verified by comparing the first message authentication code and the message authentication code. If the comparison results are consistent, the second check passes; otherwise, the second check fails.

8. The method according to claim 6, characterized in that, The payment information includes the payment amount; payment processing includes: Obtain the first balance of the payment wallet; Determine whether the first balance is greater than or equal to the payment amount; If so, the payment amount is deducted from the first balance of the payment wallet, and the receiving party's operating institution processes the payment into the receiving wallet; Otherwise, calculate the difference between the first balance and the payment amount, deduct the first balance from the payment wallet, deduct the difference from the second balance of the associated wallet, and have the receiving party's operating institution process the payment in the receiving wallet.

9. The method according to claim 8, characterized in that, Before deducting the first balance from the payment wallet and the difference from the second balance of the associated wallet, the method further includes: Confirm that the second balance of the associated wallet is greater than or equal to the difference; Furthermore, if the second balance of the associated wallet is less than the difference, the payment fails.

10. The method according to claim 1, characterized in that, Also includes: If the payment wallet does not support password reuse for associated wallets, obtain the third payment password for the payment wallet; The payment request is verified based on the first payment password and the third payment password, and payment is processed if the payment verification passes.

11. The method according to claim 10, characterized in that, Payment processing includes: Obtain the first balance of the payment wallet; Determine whether the first balance is greater than or equal to the payment amount; If so, the payment amount is deducted from the first balance of the payment wallet, and the receiving party's operating institution processes the payment into the receiving wallet; Otherwise, the payment will fail.

12. A payment device based on a hardware wallet, characterized in that, The device is used by a payer operating institution, and the device includes: A payment request receiving module is used to receive payment requests, the payment request including a first payment password, a payment wallet identifier, and a receiving wallet identifier, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; The wallet information acquisition module is used to acquire payment wallet information based on the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet. The payment password acquisition module is used to acquire the second payment password of the associated wallet based on the associated wallet identifier when the payment wallet supports password reuse of associated wallets; The payment verification processing module is used to verify the payment request based on the first payment password and the second payment password, and to process the payment if the payment verification is successful.

13. A payment method based on a hardware wallet, characterized in that, include: The hardware wallet receiving terminal sends a payment instruction to the payment wallet, which is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; The payment wallet generates a payment message according to the payment instruction and sends the payment message to the acceptance terminal; The receiving terminal generates a payment request based on the payment message and sends the payment request, which includes a first payment password, a payment wallet identifier, and a receiving wallet identifier. The paying party operating institution receives the payment request and obtains the payment wallet information according to the payment wallet identifier. The payment wallet information includes the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet. The payment password mode is used to determine whether the payment wallet supports password reuse of the associated wallet. If the payment wallet supports password reuse for associated wallets, obtain the second payment password of the associated wallet based on the associated wallet identifier; perform payment verification on the payment request based on the first payment password and the second payment password, and if the payment verification passes, perform payment processing; and return the payment processing result.

14. The method according to claim 13, characterized in that, The payment request also includes a first transaction count; Before generating a payment message according to the payment instruction, the payment wallet also includes: The payment wallet increments its stored first transaction count according to the payment instruction, and then generates an encryption key based on the first transaction count. The encryption key is used to encrypt the payment information. Furthermore, before obtaining the payment wallet information based on the payment wallet identifier, the payment operator also includes: The paying party's operating institution performs a first verification on the payment request based on the first number of transactions.

15. The method according to claim 14, characterized in that, The payment wallet generates an encryption key based on the first number of transactions, including: The payment wallet performs symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate an encryption key.

16. The method according to claim 14, characterized in that, The payment provider's operating institution performs a first verification of the payment request based on the first number of transactions, including: The paying party's operating institution determines whether the first number of transactions is greater than the second number of transactions stored in the payment wallet itself; If the first number of transactions is greater than the second number of transactions, a decryption key is generated based on the first number of transactions, and the decryption key is used to decrypt the payment request; If decryption is successful, the first verification of the payment request passes. If the first number of transactions is not greater than the second number of transactions or if decryption fails, the first verification of the payment request will fail.

17. The method according to claim 16, characterized in that, The decryption key generated by the payer's operating institution based on the first number of transactions includes: The payer's operating institution performs symmetric encryption on the first number of transactions and the wallet key generated when the payment wallet was opened to generate a decryption key.

18. The method according to claim 16, characterized in that, The method further includes: The payer operating institution increments the second transaction count after the payment is processed.

19. The method according to claim 16, characterized in that, The payment request also includes a message authentication code generated based on the payment information; Before generating a payment message according to the payment instruction, the payment wallet also includes: The payment wallet organizes the payment information according to the payment instruction and generates the message authentication code based on the payment information; After the first verification of the payment request is passed, and before obtaining the payment wallet information based on the payment wallet identifier, the payment operator further includes: The paying party's operating institution performs a second verification on the payment request based on the message authentication code.

20. The method according to claim 19, characterized in that, The paying party's operating institution performs a second verification on the payment request based on the message authentication code, including: The paying party's operating institution obtains payment information from the payment request; A first message authentication code is generated based on the payment information; The payment request is verified by comparing the first message authentication code and the message authentication code. If the comparison results are consistent, the second check passes; otherwise, the second check fails.

21. The method according to claim 19, characterized in that, The payment information includes the payment amount; the payment processing by the paying party's operating institution includes: The paying party's operating institution obtains the first balance of the payment wallet; Determine whether the first balance is greater than or equal to the payment amount; If so, the payment amount is deducted from the first balance of the payment wallet; Otherwise, calculate the difference between the first balance and the payment amount, deduct the first balance from the payment wallet, and deduct the difference from the second balance of the associated wallet.

22. The method according to claim 21, characterized in that, Before the payer operating institution deducts the first balance from the payment wallet and the difference from the second balance of the associated wallet, the method further includes: The paying party's operating institution confirms that the second balance of the associated wallet is greater than or equal to the difference; Furthermore, if the second balance of the associated wallet is less than the difference, the payment fails.

23. The method according to claim 13, characterized in that, Also includes: If the payment wallet does not support password reuse for associated wallets, the payment operator obtains the third payment password of the payment wallet, performs payment verification on the payment request based on the first payment password and the third payment password, and processes the payment if the payment verification passes.

24. The method according to claim 23, characterized in that, The payment processing by the payer's operating institution includes: The paying party's operating institution obtains the first balance of the payment wallet; Determine whether the first balance is greater than or equal to the payment amount; If so, the payment amount is deducted from the first balance of the payment wallet; Otherwise, the payment will fail.

25. The method according to claim 13, characterized in that, When the payer's operating institution corresponding to the payment wallet and the payee's operating institution corresponding to the receiving wallet are different institutions. The payment request being sent by the acceptance terminal includes: the acceptance terminal sending the payment request to the payee operating institution; The payment request received by the payer operating institution includes: the payer operating institution receiving the payment request sent by the payee operating institution; The payment processing result returned by the payer's operating institution includes: the payer's operating institution returning the payment processing result to the payee's operating institution; Furthermore, after the payer's operating institution returns the payment processing result, the process also includes: the payee's operating institution performing accounting processing on the payment wallet based on the payment processing result and returning the accounting processing result to the receiving terminal.

26. The method according to claim 25, characterized in that, If the payment processing result indicates that the payer's operating institution has successfully deducted the payment, the payee's operating institution will perform accounting processing on the payee wallet based on the payment processing result, including: The receiving party's operating organization processes the receipt of funds into the receiving wallet; If the payment processing result indicates that the payment by the payer's operating institution has failed, the payee's operating institution will perform accounting processing on the payee wallet based on the payment processing result, including: The receiving party's operating organization does not perform any accounting processing on the receiving wallet.

27. A payment system based on a hardware wallet, characterized in that, include: A hardware wallet receiving terminal is used to: send a payment instruction to a payment wallet, wherein the payment wallet is a hardware wallet that has been bound to an associated wallet, and the associated wallet is a wallet associated with the user's identity; generate a payment request based on a payment message, and send the payment request, wherein the payment request includes a first payment password, a payment wallet identifier, and a receiving wallet identifier; The payment wallet is used to: generate a payment message according to the payment instruction and send the payment message to the receiving terminal; The paying party operating institution is configured to: receive the payment request, obtain payment wallet information based on the payment wallet identifier, the payment wallet information including the payment password mode of the payment wallet and the associated wallet identifier bound to the payment wallet, the payment password mode being used to determine whether the payment wallet supports password reuse of the associated wallet; If the payment wallet supports password reuse for associated wallets, obtain the second payment password of the associated wallet based on the associated wallet identifier; perform payment verification on the payment request based on the first payment password and the second payment password, and if the payment verification passes, perform payment processing; and return the payment processing result.

28. The system according to claim 27, characterized in that, If the payer's operating institution corresponding to the payment wallet and the payee's operating institution corresponding to the receiving wallet are different institutions, the system also includes a payee's operating institution. The acceptance terminal is also used to: send the payment request to the receiving party's operating institution; The payer operating institution is also configured to: receive the payment request sent by the payee operating institution; and return the payment processing result to the payee operating institution; The receiving party's operating institution is used to: perform accounting processing on the receiving wallet based on the payment processing result and return the accounting processing result to the receiving terminal.

29. A payment electronic device based on a hardware wallet, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-11 and / or 13-26.

30. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-11 and / or 13-26.

Citation Information

Patent Citations

  • Method and system for performing online payment by using digital currency chip card

    CN107230072A

  • Password automatic unified management system and method

    CN111859369A

  • Off-line payment authorization method and device, off-line payment method and device and collection method and device

    CN113850579A