Transaction payment method, apparatus and electronic device

CN116433239BActive Publication Date: 2026-08-21THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202310272718.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-06-23
Filing Date
2023-03-20
Publication Date
2026-08-21
Estimated Expiration
2043-03-20

AI Technical Summary

Technical Problem

[0006]但是,上述方案主要聚焦在如何实现整个双离线过程,并未考虑付款方和收款方的安全问题,因此双离线支付的安全性较差

Benefits of technology

[0023]应当理解的是,本申请实施例的第二~四方面与本申请实施例的第一方面的技术方案一致,各方面及对应的可行实施方式所取得的有益效果相似,不再赘述。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116433239B_ABST
    Figure CN116433239B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a transaction payment method, device and electronic equipment, wherein in the above method, in the scenario that both the first electronic equipment and the second electronic equipment are in an offline state, after the first electronic equipment obtains the payment request of the second electronic equipment, the first electronic equipment sends a digital certificate of Renminbi to the second electronic equipment, receives the digital certificate of Renminbi sent by the second electronic equipment, verifies the digital certificate of Renminbi, determines that the verification is passed, signs transaction information using a private key, obtains a first signature, sends the transaction information and the first signature to the second electronic equipment, receives the transaction information, the first signature and a second signature sent by the second electronic equipment. Finally, the second signature is verified, and the transaction information, the first signature and the second signature are stored in the TEE, so that the payment using digital Renminbi can be realized in the scenario that both the first electronic equipment and the second electronic equipment are in an offline state, and the reliability and security in the payment process can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to a transaction payment method, device, and electronic device. Background Technology

[0002] In situations with poor or no network signal (such as natural disasters, high-speed rail, airplanes, underground shopping malls, etc.), when users have face-to-face transaction needs and do not have paper money, the dual offline payment capabilities of the digital yuan can meet their payment needs.

[0003] Existing technologies providing a dual offline payment solution for the digital yuan employ near-field communication (NFC) to complete offline transactions, while using unspent transaction outputs (UTXOs) on the blockchain to synchronize online transaction information. Specifically:

[0004] (1) Through NFC communication, the payer and payee send offline transaction information, including the digital currency and amount transferred, the payer's account, the payee's account, the transaction time, and the payer's private key signature;

[0005] (2) Once the network is restored, the payee and payer will upload the transaction information respectively and download and confirm the confirmation transaction information uploaded by the other party, thus completing the online synchronization of the blockchain UTXO ledger.

[0006] However, the above solutions mainly focus on how to achieve the entire offline process, without considering the security issues of the payer and the payee. Therefore, the security of offline payments is relatively poor. Summary of the Invention

[0007] This application provides a transaction payment method, device, and electronic device to enable payment using digital RMB in scenarios where both the payee and payer are offline, and to ensure the security of payment using digital RMB in a dual offline state.

[0008] In a first aspect, embodiments of this application provide a transaction payment method applied to a first electronic device used by the payee, where both the first electronic device and a second electronic device used by the payer are offline. The method includes: obtaining a payment request from the second electronic device to make a payment using digital RMB; responding to the payment request, sending a digital RMB certificate to the second electronic device for the second electronic device to verify the digital RMB certificate sent by the first electronic device, and receiving the digital RMB certificate sent by the second electronic device; wherein the digital RMB certificate originates from a digital RMB issuing server; verifying the digital RMB certificate sent by the second electronic device; and after determining that the digital RMB certificate sent by the second electronic device has passed verification, signing the transaction information using a private key stored in the first electronic device to obtain a first signature. The system sends transaction information and a first signature to a second electronic device; the private key stored in the first electronic device is issued by a third-party authentication server; the system receives transaction information, a first signature, and a second signature from the second electronic device; the transaction information, the first signature, and the second signature are obtained by the second electronic device after receiving the transaction information and the first signature from the first electronic device, verifying the first signature, and then using the private key stored in the second electronic device to sign the transaction information sent by the first electronic device to obtain the second signature, which is then sent to the first electronic device; the private key stored in the second electronic device is issued by a third-party authentication server; the system verifies the second signature and stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device.

[0009] In the aforementioned transaction payment method, when both the first and second electronic devices are offline, after the first electronic device receives a payment request from the second electronic device to use digital RMB for payment, it responds by sending a digital RMB certificate to the second electronic device and receiving the digital RMB certificate sent by the second electronic device. It then verifies the digital RMB certificate sent by the second electronic device. Once the verification is successful, it uses the private key stored in the first electronic device to sign the transaction information, obtaining a first signature. The first electronic device then sends the transaction information and the first signature to the second electronic device and receives the transaction information, the first signature, and the second signature sent by the second electronic device. Finally, it verifies the second signature and stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device. This allows for payment using digital RMB even when both the first and second electronic devices are offline, ensuring the reliability and security of both devices during the payment process.

[0010] In one possible implementation, after storing the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device, the method further includes: after the first electronic device is connected to the network, uploading the transaction information, the first signature, and the second signature to a third-party transaction server for the transaction server to verify the first signature and the second signature; after the first signature and the second signature pass the verification, uploading the transaction information to the digital RMB issuance server and receiving the transaction result corresponding to the transaction information sent by the issuance server; and receiving the transaction result corresponding to the transaction information sent by the transaction server.

[0011] In one possible implementation, before sending the RMB digital certificate to the second electronic device, the process includes: obtaining a request from a user to register for digital RMB and open a personal sub-wallet; wherein the user includes the user using the first electronic device; sending the request to the digital RMB issuing server; receiving the RMB digital certificate, public key, wallet identifier, account identifier, and a first public-private key pair derived from the issuing server from the issuing server; storing the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair sent by the issuing server in the trusted execution environment of the first electronic device; encrypting the account identifier, wallet identifier, and device identifier of the first electronic device using a public key pre-agreed with a third-party authentication server, and sending the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier to the authentication server; and receiving and saving the third-party digital certificate and the second public-private key pair sent by the authentication server.

[0012] In one possible implementation, the third-party digital certificate is obtained by the authentication server using its own private key to decrypt the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier. The server then verifies the decrypted account identifier, device identifier, and wallet identifier. Once the verification is successful, a second public-private key pair is generated. The server then uses its own private key to encrypt the public key and digital certificate validity period in the second public-private key pair to obtain a digital signature. Finally, the public key, digital certificate validity period, and digital signature in the second public-private key pair are combined to form a third-party digital certificate, which is then sent to the first electronic device.

[0013] In one possible implementation, receiving and storing the third-party digital certificate and the second public-private key pair sent by the authentication server includes: verifying the signature of the third-party digital certificate sent by the authentication server; generating a random number after the third-party digital certificate has passed verification; encrypting the account identifier, wallet identifier, device identifier of the first electronic device, and the random number using a public key pre-agreed with the authentication server; sending the encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number to the authentication server; receiving the encrypted private key sent by the authentication server; wherein the encrypted private key is obtained by the authentication server using its own stored private key to decrypt the encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number, and after confirming that the decrypted account identifier, device identifier, and wallet identifier have passed verification, encrypting the private key in the second public-private key pair using the decrypted random number and sending it to the first electronic device; decrypting the encrypted private key using the random number; and storing the third-party digital certificate and the second public-private key pair sent by the authentication server after confirming that the decrypted private key has passed verification.

[0014] In one possible implementation, the first electronic device and the second electronic device establish a connection via Bluetooth. Sending a digital RMB certificate to the second electronic device includes: sending a digital RMB certificate to the second electronic device via Bluetooth connection; receiving a digital RMB certificate sent by the second electronic device includes: receiving a digital RMB certificate sent by the second electronic device via Bluetooth connection.

[0015] Secondly, embodiments of this application provide a transaction payment device, installed in a first electronic device used by the payee, where both the first electronic device and a second electronic device used by the payer are offline. The device includes: an acquisition module for acquiring a payment request from the second electronic device to make a payment using digital RMB; a sending module for sending a digital RMB certificate to the second electronic device in response to the payment request, so that the second electronic device can verify the digital RMB certificate sent by the first electronic device; a receiving module for receiving the digital RMB certificate sent by the second electronic device; wherein the digital RMB certificate originates from a digital RMB issuing server; a verification module for verifying the digital RMB certificate sent by the second electronic device; and a signature module for signing the transaction information using a private key stored in the first electronic device after the verification module determines that the digital RMB certificate sent by the second electronic device has passed verification. The system comprises the following modules: a first signature acquisition module; a sending module, which further transmits the transaction information and the first signature to a second electronic device; wherein the private key stored in the first electronic device is issued by a third-party authentication server; a receiving module, which receives the transaction information, the first signature, and the second signature transmitted by the second electronic device; wherein the transaction information, the first signature, and the second signature are transmitted by the second electronic device after receiving the transaction information and the first signature transmitted by the first electronic device, verifying the first signature, and after confirming that the first signature passes the verification, signing the transaction information transmitted by the first electronic device using the private key stored in the second electronic device to obtain the second signature, and then transmitting it to the first electronic device; wherein the private key stored in the second electronic device is issued by a third-party authentication server; a verification module, which further verifies the second signature; and a storage module, which stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device.

[0016] In one possible implementation, the sending module is further configured to, after the storage module stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device, upload the transaction information, the first signature, and the second signature to a third-party transaction server after the first electronic device is connected to the network, so that the transaction server can verify the first signature and the second signature. After the first signature and the second signature pass the verification, the sending module uploads the transaction information to the digital RMB issuance server and receives the transaction result corresponding to the transaction information sent by the issuance server. The receiving module is further configured to receive the transaction result corresponding to the transaction information sent by the transaction server.

[0017] In one possible implementation, the device further includes: an encryption module; an acquisition module, further configured to acquire a user's request to register for digital RMB and open a personal sub-wallet before the sending module sends the RMB digital certificate to the second electronic device; wherein the user includes the user using the first electronic device; a sending module, further configured to send the request to the digital RMB issuance server; a receiving module, further configured to receive the RMB digital certificate, public key, wallet identifier, account identifier, and a first public-private key pair derived from the issuance server sent by the issuance server; a storage module, further configured to store the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair sent by the issuance server in the trusted execution environment of the first electronic device; an encryption module, configured to encrypt the account identifier, wallet identifier, and device identifier of the first electronic device using a public key pre-agreed with a third-party authentication server; a sending module, further configured to send the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier to the authentication server; a receiving module, further configured to receive the third-party digital certificate and the second public-private key pair sent by the authentication server; and a storage module, further configured to save the third-party digital certificate and the second public-private key pair received by the receiving module.

[0018] In one possible implementation, the receiving module receives a third-party digital certificate by decrypting the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier using its own private key. The module then verifies the decrypted account identifier, device identifier, and wallet identifier. Once the verification is successful, a second public-private key pair is generated. The public key and digital certificate validity period in the second public-private key pair are then encrypted using the private key stored by the authentication server to obtain a digital signature. Finally, the public key, digital certificate validity period, and digital signature from the second public-private key pair are combined to form a third-party digital certificate, which is then sent to the first electronic device.

[0019] In one possible implementation, the receiving module includes: a signature verification submodule for verifying the signature of the third-party digital certificate sent by the authentication server; a generation submodule for generating a random number after the third-party digital certificate has passed signature verification; a key encryption submodule for encrypting the account identifier, wallet identifier, device identifier of the first electronic device, and the random number using a public key pre-agreed with the authentication server; an encryption sending submodule for sending the encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number to the authentication server; and a private key receiving submodule for receiving the private key sent by the authentication server. The authentication server uses its own stored private key to decrypt the encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number. After verifying that the decrypted account identifier, device identifier, and wallet identifier are valid, the authentication server uses the decrypted random number to encrypt the private key in the second public-private key pair before sending it to the first electronic device. A decryption submodule is used to decrypt the encrypted private key using the random number. A storage module is specifically used to save the third-party digital certificate and the second public-private key pair sent by the authentication server after verifying that the decrypted private key is valid.

[0020] In one possible implementation, the first electronic device and the second electronic device establish a connection via Bluetooth; the sending module is specifically used to send the RMB digital certificate to the second electronic device via Bluetooth; the receiving module is specifically used to receive the RMB digital certificate sent by the second electronic device via Bluetooth.

[0021] Thirdly, embodiments of this application provide an electronic device, including: at least one processor; and at least one memory communicatively connected to the processor, wherein: the memory stores program instructions executable by the processor, and the processor can execute the method provided in the first aspect by calling the program instructions.

[0022] Fourthly, embodiments of this application provide a non-transitory computer-readable storage medium that stores computer instructions that cause a computer to execute the method provided in the first aspect.

[0023] It should be understood that the second to fourth aspects of the embodiments of this application are consistent with the technical solutions of the first aspect of the embodiments of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be described again. Attached Figure Description

[0024] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 A flowchart illustrating a transaction payment method provided in one embodiment of this application;

[0026] Figure 2 A flowchart of a transaction payment method provided in another embodiment of this application;

[0027] Figure 3 A flowchart of a transaction payment method provided in another embodiment of this application;

[0028] Figure 4 A flowchart of a transaction payment method provided in another embodiment of this application;

[0029] Figure 5 A flowchart of a transaction payment method provided in another embodiment of this application;

[0030] Figure 6 This is a schematic diagram of the structure of a transaction payment device provided in one embodiment of this application;

[0031] Figure 7 A schematic diagram of the structure of a transaction payment device provided in another embodiment of this application;

[0032] Figure 8 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation

[0033] To better understand the technical solution of this application, the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0034] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.

[0035] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. The singular forms “a,” “the,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0036] For situations with poor network signal, no network access, or natural disasters (such as earthquakes and / or floods), the digital yuan's dual offline payment capability can meet people's daily payment needs. However, the digital yuan faces some security issues during dual offline payments, mainly falling into two categories: the security of the payer and the security of the payee. Therefore, this application provides a digital yuan transaction payment method that offers a relatively complete encryption and decryption process in scenarios where both the payer and payee are offline, ensuring the reliability and security of dual offline payments.

[0037] Figure 1 The flowchart below shows a digital RMB transaction payment method according to an embodiment of this application. The digital RMB transaction payment method can be applied to a first electronic device used by the payee, and both the first electronic device and the second electronic device used by the payer are offline.

[0038] like Figure 1 As shown, the above method may include:

[0039] Step 101: The first electronic device obtains the payment request from the second electronic device to make payment using digital RMB.

[0040] Specifically, when both the first electronic device and the second electronic device are offline, the first electronic device can obtain a payment request from the second electronic device to use digital RMB by scanning the QR code displayed on the screen of the second electronic device.

[0041] Step 102: In response to the aforementioned payment request, the first electronic device sends a digital certificate of RMB to the second electronic device, so that the second electronic device can verify the digital certificate of RMB sent by the first electronic device and receive the digital certificate of RMB sent by the second electronic device.

[0042] The RMB digital certificate comes from the issuing server of the digital RMB and can be used to verify the authenticity of the user's account and wallet.

[0043] Specifically, the first electronic device can establish a connection with the second electronic device via Bluetooth, send a digital certificate of RMB to the second electronic device via Bluetooth, and receive a digital certificate of RMB sent by the second electronic device via the aforementioned Bluetooth connection.

[0044] Step 103: The first electronic device verifies the RMB digital certificate sent by the second electronic device.

[0045] Specifically, verifying the RMB digital certificate sent by the second electronic device can be done by using the public key issued by the aforementioned issuing server to decrypt the RMB digital certificate. If decryption is successful, it can be determined that the wallet and account of the user using the second electronic device are authenticated and that the wallet and account of the user using the second electronic device are genuine and valid.

[0046] Step 104: After the first electronic device confirms that the RMB digital certificate sent by the second electronic device has passed the verification, it uses the private key stored in the first electronic device to sign the transaction information, obtains the first signature, and sends the transaction information and the first signature to the second electronic device.

[0047] The private key stored in the first electronic device was issued by a third-party authentication server.

[0048] Step 105: The first electronic device receives the transaction information, first signature, and second signature sent by the second electronic device.

[0049] The aforementioned transaction information, first signature, and second signature are obtained by the second electronic device after receiving the transaction information and first signature sent by the first electronic device. The second electronic device verifies the first signature, and after confirming that the first signature passes the verification, it uses the private key stored in the second electronic device to sign the transaction information sent by the first electronic device, obtains the second signature, and then sends it to the first electronic device. Similarly, the private key stored in the second electronic device is also issued by a third-party authentication server.

[0050] Step 106: The first electronic device verifies the second signature and stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device.

[0051] Specifically, the verification of the second signature can be performed by using the public key corresponding to the private key issued by the aforementioned third-party authentication server to decrypt the second signature, obtain the decrypted second signature, and then verify the decrypted second signature.

[0052] In the aforementioned digital RMB transaction payment method, when both the first and second electronic devices are offline, after the first electronic device receives a payment request from the second electronic device to use digital RMB for payment, it responds by sending a digital RMB certificate to the second electronic device and receiving the digital RMB certificate sent by the second electronic device. It then verifies the digital RMB certificate sent by the second electronic device. Once the verification is successful, it uses the private key stored in the first electronic device to sign the transaction information, obtaining a first signature. The first electronic device then sends the transaction information and its first signature to the second electronic device and receives the transaction information, the first signature, and the second signature sent by the second electronic device. Finally, it verifies the second signature and stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device. This allows for payment using digital RMB even when both the first and second electronic devices are offline, ensuring the reliability and security of both devices during the payment process.

[0053] Figure 2 A flowchart of a digital RMB transaction payment method provided for another embodiment of this application is shown below. Figure 2 As shown, this application Figure 1 In the illustrated embodiment, after step 106, the following may also be included:

[0054] Step 201: After the first electronic device is connected to the network, the first electronic device uploads the transaction information, the first signature, and the second signature to a third-party transaction server for the transaction server to verify the first signature and the second signature. After the first signature and the second signature are verified, the first electronic device uploads the transaction information to the digital RMB issuance server and receives the transaction result corresponding to the transaction information sent by the issuance server.

[0055] Step 202: The first electronic device receives the transaction result corresponding to the transaction information sent by the transaction server.

[0056] Figure 3 A flowchart of a digital RMB transaction payment method provided in another embodiment of this application is shown below. Figure 3 As shown, this application Figure 1 In the illustrated embodiment, before step 102, the following steps are also included:

[0057] Step 301: The first electronic device receives a request from a user to register for digital RMB and open a personal sub-wallet; wherein, the aforementioned user includes the user using the first electronic device.

[0058] Step 302: The first electronic device sends the above request to the digital RMB issuance server.

[0059] Step 303: The first electronic device receives the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair derived from the issuing server sent by the issuing server.

[0060] The RMB digital certificate, public key, wallet identifier, account identifier (which may also be called account token in some embodiments) and the first public-private key pair derived from the issuing server sent by the issuing server are used to ensure the authenticity and validity of the user's account and wallet.

[0061] Step 304: The first electronic device stores the RMB digital certificate, public key, wallet identifier, account identifier and the first public-private key pair sent by the issuing server into the trusted execution environment of the first electronic device.

[0062] Step 305: The first electronic device uses a public key pre-agreed with a third-party authentication server to encrypt the account identifier, the wallet identifier, and the device identifier of the first electronic device, and sends the encrypted account identifier, the encrypted device identifier, and the encrypted wallet identifier to the authentication server.

[0063] The device identifier of the first electronic device can be the International Mobile Equipment Identity (IMEI) of the first electronic device. The IMEI is commonly referred to as the mobile phone serial number or mobile phone "serial number". It is used to identify each independent mobile communication device such as a mobile phone in the mobile phone network, which is equivalent to the electronic device's ID card.

[0064] Step 306: The first electronic device receives and saves the third-party digital certificate and the second public-private key pair sent by the authentication server.

[0065] The following is combined with Figure 4 The specific processes of steps 305 to 306 will be explained. Figure 4 A flowchart illustrating a digital RMB transaction payment method provided in another embodiment of this application. Figure 4 The following example illustrates the process of a first electronic device initiating authentication with a third-party authentication server. It can be understood that the process of a second electronic device initiating authentication with a third-party authentication server is the same as that of the first electronic device, and will not be repeated here. Figure 4 As shown, it may include:

[0066] Step 401 is the same as step 305.

[0067] Step 402: The third-party authentication server uses its own stored private key to decrypt the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier, and verifies the decrypted account identifier, device identifier, and wallet identifier.

[0068] Specifically, the authentication server can compare the decrypted account identifier, device identifier, and wallet identifier with the account identifier, device identifier, and wallet identifier stored in the registration database connected to the authentication server. If they match, the decrypted account identifier, device identifier, and wallet identifier have passed verification; if they do not match, the decrypted account identifier, device identifier, and wallet identifier have failed verification, and the authentication server can return an error code: error.

[0069] Step 403: After verifying that the account identifier, device identifier, and wallet identifier obtained through decryption have passed the verification, the authentication server generates a second public-private key pair.

[0070] Step 404: The authentication server uses its own private key to encrypt the public key and the digital certificate validity period in the second public-private key pair to obtain a digital signature.

[0071] Specifically, before encrypting the public key and digital certificate validity period in the second public-private key pair using the private key stored by the authentication server itself, the authentication server can use a hash algorithm to hash the public key and digital certificate validity period in the second public-private key pair. Then, the authentication server uses its own stored private key to encrypt the hashed public key and digital certificate validity period.

[0072] Step 405: The authentication server combines the public key from the second public-private key pair, the digital certificate validity period, and the digital signature to form a third-party digital certificate.

[0073] Step 406: The authentication server sends the third-party digital certificate to the first electronic device.

[0074] Step 407: The first electronic device verifies the signature of the third-party digital certificate sent by the authentication server.

[0075] Specifically, if the third-party digital certificate passes the verification, step 408 is executed; if the third-party digital certificate fails the verification, the first electronic device re-initiates the authentication request.

[0076] Step 408: After the aforementioned third-party digital certificate passes verification, the first electronic device generates a random number.

[0077] Step 409: The first electronic device uses a public key pre-agreed with the authentication server to encrypt the account identifier, the wallet identifier, the device identifier of the first electronic device, and the random number.

[0078] Step 410: The first electronic device sends the encrypted account identifier, the encrypted device identifier, the encrypted wallet identifier, and the encrypted random number to the aforementioned authentication server.

[0079] Step 411: The authentication server uses its stored private key to decrypt the encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number; and verifies the decrypted account identifier, device identifier, and wallet identifier.

[0080] In this embodiment, if the account identifier, device identifier, and wallet identifier obtained through decryption fail verification, an error code is returned: error.

[0081] Step 412: After verifying that the account identifier, device identifier, and wallet identifier obtained through decryption have passed the verification, the authentication server uses the random number obtained through decryption to encrypt the private key in the second public-private key pair mentioned above.

[0082] Specifically, after verifying that the account identifier, device identifier, and wallet identifier obtained through decryption have passed the verification, the authentication server can use the random number obtained through decryption to encrypt the private key in the second public-private key pair using a symmetric encryption algorithm.

[0083] Step 413: The authentication server sends the encrypted private key to the first electronic device.

[0084] Step 414: The first electronic device uses the above-mentioned random number to decrypt the above-mentioned encrypted private key, and verifies the decrypted private key.

[0085] Specifically, if the decrypted private key passes verification, step 415 is executed; if the decrypted private key fails verification, the first electronic device re-initiates the authentication request.

[0086] Step 415: After confirming that the decryption and acquisition of the private key have passed verification, the first electronic device saves the third-party digital certificate and the second public-private key pair sent by the authentication server.

[0087] Figure 5 A flowchart of a digital RMB transaction payment method provided in another embodiment of this application is shown below. Figure 5 As shown, the transaction payment methods for the aforementioned digital yuan may include:

[0088] Step 501: The first electronic device obtains the user's request to register for digital RMB and open a personal sub-wallet, and sends the request to the digital RMB issuance server.

[0089] The first electronic device can be an electronic device used by the recipient, and the user can be a user of the first electronic device. In specific implementation, the user can initiate a request to register for digital RMB and open a personal sub-wallet through the digital RMB application (APP) installed on the first electronic device, and the digital RMB APP will send the above request to the digital RMB issuing server.

[0090] Step 502: The issuing server sends the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair derived from the issuing server to the first electronic device.

[0091] Step 503: The first electronic device stores the RMB digital certificate, public key, wallet identifier, account identifier and the first public-private key pair sent by the issuing server into the trusted execution environment (TEE) of the first electronic device.

[0092] Step 504: When the first electronic device is connected to the Internet, it uses a public key pre-agreed with a third-party authentication server to encrypt the account identifier, the wallet identifier, and the device identifier of the first electronic device, and sends the encrypted account identifier, the encrypted device identifier, and the encrypted wallet identifier to the authentication server.

[0093] Step 505: The first electronic device receives a third-party digital certificate and a second public-private key pair sent by the authentication server.

[0094] It should be noted that the third-party digital certificate and the second public-private key pair sent by the authentication server to the first electronic device are the third-party digital certificate and the second public-private key pair generated by the authentication server for the first electronic device.

[0095] Step 506: The first electronic device calls the interface between itself and its TEE to store the third-party digital certificate and the second public-private key pair into the TEE of the first electronic device.

[0096] In this embodiment, the specific implementation of steps 504 to 506 can be found in this application. Figure 4 The description of the illustrated embodiments will not be repeated here.

[0097] Step 507: The second electronic device stores the RMB digital certificate, public key, wallet identifier, account identifier and first public-private key pair sent by the issuing server into the TEE of the second electronic device.

[0098] The second electronic device can be an electronic device used by the payer. Before step 507, the second electronic device can execute steps 501-502 to obtain the RMB digital certificate, public key, wallet identifier, account identifier, and first public-private key pair sent by the issuing server. In this step, the RMB digital certificate, public key, wallet identifier, account identifier, and first public-private key pair sent by the issuing server are generated by the issuing server for the second electronic device and correspond to the user using the second electronic device.

[0099] Step 508: When the second electronic device is connected to the network, it uses a public key pre-agreed with a third-party authentication server to encrypt the account identifier, wallet identifier, and device identifier of the second electronic device, and sends the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier to the authentication server.

[0100] Step 509: The second electronic device receives a third-party digital certificate and a second public-private key pair sent by the authentication server.

[0101] It should be noted that the third-party digital certificate and the second public-private key pair sent by the authentication server to the second electronic device are the third-party digital certificate and the second public-private key pair generated by the authentication server for the second electronic device.

[0102] Step 510: The second electronic device calls the interface between itself and its TEE to store the third-party digital certificate and the second public-private key pair into the TEE of the second electronic device.

[0103] In practice, steps 508 to 510 can be executed in parallel with steps 504 to 506, or they can be executed sequentially. This embodiment does not limit the execution order of steps 508 to 510 and steps 504 to 506.

[0104] Step 511: When both the first electronic device and the second electronic device are offline, the first electronic device obtains the payment request from the second electronic device to make a payment using digital RMB.

[0105] Specifically, when both the first electronic device and the second electronic device are offline, the first electronic device can obtain a payment request from the second electronic device to use digital RMB by scanning the QR code displayed on the screen of the second electronic device.

[0106] Step 512: In response to the aforementioned payment request, the first electronic device sends a digital certificate of RMB to the second electronic device, so that the second electronic device can verify the digital certificate of RMB sent by the first electronic device and receive the digital certificate of RMB sent by the second electronic device.

[0107] Specifically, the first electronic device can establish a connection with the second electronic device via Bluetooth, send a digital certificate of RMB to the second electronic device via Bluetooth, and receive a digital certificate of RMB sent by the second electronic device via the aforementioned Bluetooth connection.

[0108] Step 513: The first electronic device verifies the RMB digital certificate sent by the second electronic device, and the second electronic device verifies the RMB digital certificate sent by the first electronic device.

[0109] Step 514: After the first electronic device confirms that the RMB digital certificate sent by the second electronic device has passed the verification, it uses the private key stored in the first electronic device to sign the transaction information and obtain the first signature.

[0110] Step 515: The first electronic device sends the transaction information and the first signature to the second electronic device.

[0111] Step 516: After receiving the transaction information and the first signature sent by the first electronic device, the second electronic device verifies the first signature.

[0112] Step 517: After confirming that the first signature has passed the verification, the second electronic device uses the private key stored in the second electronic device to sign the transaction information sent by the first electronic device to obtain the second signature.

[0113] Step 518: The second electronic device sends the transaction information, the first signature, and the second signature to the first electronic device.

[0114] Step 519: The first electronic device verifies the second signature and stores the transaction information, the first signature, and the second signature in the TEE of the first electronic device.

[0115] Step 520: After the first electronic device is connected to the network, the first electronic device uploads the aforementioned transaction information, the first signature, and the second signature to the third party's transaction server.

[0116] Step 521: The transaction server inserts the above transaction information into the transaction log.

[0117] Step 522: The transaction server verifies the first signature and the second signature.

[0118] Step 523: If no transaction order corresponding to the above transaction information has been created, the transaction server will insert the verification results of the first signature and the second signature and the above transaction information into the transaction table.

[0119] Step 524: After the second electronic device is connected to the network, the second electronic device uploads the aforementioned transaction information, the first signature, and the second signature to the third party's transaction server.

[0120] Step 525: The transaction server verifies the first signature and the second signature.

[0121] Step 526: If no transaction order corresponding to the above transaction information has been created, the transaction server inserts the verification results of the first signature and the second signature and the above transaction information into the transaction table.

[0122] In practice, steps 524 to 526 can be executed in parallel with steps 520 to 523 or executed sequentially. This embodiment does not limit the execution order of steps 524 to 526 and steps 520 to 523.

[0123] Step 527: The transaction server uploads the aforementioned transaction information to the digital RMB issuance server.

[0124] Step 528: The transaction server receives the transaction result corresponding to the above transaction information sent by the issuing server.

[0125] Step 529: The transaction server sends the transaction result corresponding to the above transaction information to the first electronic device.

[0126] Specifically, the transaction server can send the transaction results corresponding to the above transaction information to the first electronic device using an asynchronous notification method.

[0127] Step 530: The transaction server sends the transaction result corresponding to the above transaction information to the second electronic device.

[0128] Similarly, the transaction server can use asynchronous notification to send the transaction results corresponding to the above transaction information to the second electronic device.

[0129] It is understood that steps 529 and 530 can be executed in parallel or sequentially. This embodiment does not limit the execution order of steps 529 and 530.

[0130] The digital RMB transaction payment method provided in this application embodiment is based on a complete encryption and decryption design, ensuring the security of payments when both the payee and payer are offline. Specifically, it is manifested as follows:

[0131] (a) Before the transaction: Ensure that the user's account, wallet and device are verified.

[0132] (b) During the transaction: The transaction process is encrypted and verified to ensure that the transaction information is not hijacked or tampered with.

[0133] (c) After the transaction: The payee and the payer send the transaction information to the transaction server respectively. The transaction server sends the transaction results to the payee and the payer respectively. Not only can the transaction server verify the transaction information sent by the payee and the payer, but the payee and the payer can also seek recourse after the transaction based on the transaction results, that is, a recourse mechanism is provided.

[0134] The digital RMB transaction payment method provided in this application can be used in scenarios with poor network signals, such as offline payment and / or shared bicycles. In the long run, dual offline payment will become an essential payment method to cope with some natural disasters or other extreme scenarios. A typical example is that in extreme scenarios such as floods and / or earthquakes, dual offline payment can ensure people's normal life needs.

[0135] The foregoing has described specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0136] Figure 6 This is a schematic diagram of the structure of a digital RMB transaction payment device according to an embodiment of this application. The digital RMB transaction payment device is installed in a first electronic device used by the payee, while both the first electronic device and the second electronic device used by the payer are offline. Figure 6 As shown, the above-mentioned digital RMB transaction payment device may include: an acquisition module 61, a sending module 62, a receiving module 63, a verification module 64, a signature module 65, and a storage module 66;

[0137] Among them, the acquisition module 61 is used to acquire the payment request of the second electronic device using digital RMB for payment;

[0138] The sending module 62 is used to send a digital RMB certificate to the second electronic device in response to the aforementioned payment request, so that the second electronic device can verify the digital RMB certificate sent by the first electronic device;

[0139] The receiving module 63 is used to receive the RMB digital certificate sent by the second electronic device; wherein the RMB digital certificate comes from the digital RMB issuing server;

[0140] Verification module 64 is used to verify the RMB digital certificate sent by the second electronic device;

[0141] The signature module 65 is used to sign the transaction information using the private key stored in the first electronic device after the verification module 64 determines that the RMB digital certificate sent by the second electronic device has passed the verification, thereby obtaining the first signature.

[0142] The sending module 62 is also used to send the above transaction information and the first signature to the second electronic device; wherein the private key stored in the first electronic device is issued by a third-party authentication server;

[0143] The receiving module 63 is further configured to receive transaction information, a first signature, and a second signature sent by the second electronic device; wherein, the transaction information, the first signature, and the second signature are obtained by the second electronic device after receiving the transaction information and the first signature sent by the first electronic device, verifying the first signature, and after confirming that the first signature passes the verification, signing the transaction information sent by the first electronic device using the private key stored in the second electronic device to obtain the second signature, and then sending it to the first electronic device; wherein, the private key stored in the second electronic device is issued by a third-party authentication server;

[0144] The verification module 64 is also used to verify the second signature;

[0145] Storage module 66 is used to store the aforementioned transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device.

[0146] Figure 6 The digital yuan transaction device provided in the illustrated embodiment can be used to execute this application. Figure 1 The implementation principle and technical effects of the method embodiment shown can be further referred to the relevant description in the method embodiment.

[0147] Figure 7 This is a schematic diagram of the structure of a digital RMB transaction payment device provided in another embodiment of this application, and... Figure 6 Compared to the digital yuan transaction payment device shown, Figure 7 In the digital RMB transaction payment device shown, the sending module 62 is further configured to, after the storage module 66 stores the transaction information, the first signature and the second signature in the trusted execution environment of the first electronic device, upload the transaction information, the first signature and the second signature to a third-party transaction server after the first electronic device is connected to the network, so that the transaction server can verify the first signature and the second signature. After the first signature and the second signature pass the verification, the transaction information is uploaded to the digital RMB issuance server, and the transaction result corresponding to the transaction information sent by the issuance server is received.

[0148] The receiving module 63 is also used to receive the transaction result corresponding to the transaction information sent by the transaction server.

[0149] Furthermore, the aforementioned digital RMB transaction payment device may also include: an encryption module 67;

[0150] The acquisition module 61 is also used to acquire a user's request to register for digital RMB and open a personal sub-wallet before the sending module 62 sends the RMB digital certificate to the second electronic device; wherein, the user includes the user using the first electronic device;

[0151] The sending module 62 is also used to send the above request to the above-mentioned digital RMB issuance server;

[0152] The receiving module 63 is also used to receive the RMB digital certificate, public key, wallet identifier, account identifier and the first public-private key pair derived from the issuing server sent by the issuing server;

[0153] The storage module 66 is also used to store the RMB digital certificate, public key, wallet identifier, account identifier and first public-private key pair sent by the issuing server into the trusted execution environment of the first electronic device;

[0154] The encryption module 67 is used to encrypt the account identifier, wallet identifier, and device identifier of the first electronic device using a public key pre-agreed with a third-party authentication server;

[0155] The sending module 62 is also used to send the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier from the encryption module 67 to the authentication server;

[0156] The receiving module 63 is also used to receive a third-party digital certificate and a second public-private key pair sent by the authentication server;

[0157] The storage module 66 is also used to store the third-party digital certificate and the second public-private key pair received by the receiving module 63.

[0158] In this embodiment, the third-party digital certificate received by the receiving module 63 is obtained by the authentication server using its own private key to decrypt the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier. The decrypted account identifier, device identifier, and wallet identifier are verified. After the decrypted account identifier, device identifier, and wallet identifier pass the verification, a second public-private key pair is generated. The public key and digital certificate validity period in the second public-private key pair are encrypted using the authentication server's own private key to obtain a digital signature. The public key, digital certificate validity period, and the aforementioned digital signature are combined to form a third-party digital certificate, which is then sent to the first electronic device.

[0159] In this embodiment, the receiving module 63 may include: a signature verification submodule 631, a generation submodule 632, a key encryption submodule 633, an encryption sending submodule 634, a private key receiving submodule 635, and a decryption submodule 636;

[0160] Among them, the signature verification submodule 631 is used to verify the signature of the third-party digital certificate sent by the authentication server;

[0161] The generation submodule 632 is used to generate random numbers after the third-party digital certificate has passed verification.

[0162] The key encryption submodule 633 is used to encrypt the account identifier, the wallet identifier, the device identifier of the first electronic device, and the random number using a public key pre-agreed with the authentication server;

[0163] The encrypted sending submodule 634 is used to send the encrypted account identifier, encrypted device identifier, encrypted wallet identifier and encrypted random number to the authentication server;

[0164] The private key receiving submodule 635 is used to receive the encrypted private key sent by the authentication server. The encrypted private key is obtained by the authentication server using its own stored private key to decrypt the encrypted account identifier, encrypted device identifier, encrypted wallet identifier and encrypted random number. After verifying that the decrypted account identifier, device identifier and wallet identifier are valid, the authentication server uses the decrypted random number to encrypt the private key in the second public-private key pair and then sends it to the first electronic device.

[0165] The decryption submodule 636 is used to decrypt the encrypted private key using the above-mentioned random number;

[0166] Storage module 66 is specifically used to save the third-party digital certificate and the second public-private key pair sent by the authentication server after it is determined that the private key obtained through decryption has been verified.

[0167] In this embodiment, the first electronic device and the second electronic device establish a connection via Bluetooth; thus, the sending module 62 is specifically used to send the RMB digital certificate to the second electronic device via Bluetooth; the receiving module 63 is specifically used to receive the RMB digital certificate sent by the second electronic device via Bluetooth.

[0168] Figure 7 The digital RMB transaction payment device provided in the illustrated embodiment can be used to execute this application. Figures 1-5 The implementation principle and technical effects of the method embodiment shown can be further referred to the relevant description in the method embodiment.

[0169] Figure 8This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application, such as... Figure 8 As shown, the aforementioned electronic device may include at least one processor; and at least one memory communicatively connected to the processor, wherein the memory stores program instructions executable by the processor, and the processor can execute this application by calling the program instructions. Figures 1-5 The illustrated embodiment provides a transaction payment method for digital RMB.

[0170] The aforementioned electronic device can be used as part of this application. Figures 1-5 The first electronic device in the illustrated embodiment can be a smart electronic device such as a smartphone, tablet, or wearable device. This embodiment does not limit the form of the electronic device. It is understood that the second electronic device can also be implemented using the same structure, and this embodiment will not elaborate on that.

[0171] Figure 8 A block diagram of an exemplary electronic device suitable for implementing embodiments of this application is shown. Figure 8 The electronic device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0172] like Figure 8 As shown, the electronic device is represented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: one or more processors 410, a communication interface 420, a memory 430, and a communication bus 440 connecting different components (including the memory 430, the communication interface 420, and the processing unit 410).

[0173] Communication bus 440 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, or a local bus using any of the various bus architectures. For example, communication bus 440 may include, but is not limited to, an industry standard architecture (ISA) bus, a micro channel architecture (MCA) bus, an enhanced ISA bus, a video electronics standards association (VESA) local bus, and a peripheral component interconnection (PCI) bus.

[0174] Electronic devices typically include a variety of computer-readable media. These media can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, and removable and non-removable media.

[0175] Memory 430 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. Memory 430 may include at least one program product having a set (e.g., at least one) of program modules configured to execute this application. Figures 1-5 The functionality of the illustrated embodiment.

[0176] A program / utility having a set (at least one) of program modules can be stored in memory 430. Such program modules include—but are not limited to—an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules typically execute the present application. Figures 1-5 The functions and / or methods described in the embodiments.

[0177] Processor 410 executes various functional applications and data processing by running programs stored in memory 430, such as implementing the present application. Figures 1-5 The illustrated embodiment provides a transaction payment method for digital RMB.

[0178] This application provides a non-transitory computer-readable storage medium that stores computer instructions, which cause the computer to execute this application. Figures 1-5 The illustrated embodiment provides a transaction payment method for digital RMB.

[0179] The aforementioned non-transitory computer-readable storage medium may be any combination of one or more computer-readable media. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium that contains or stores a program that may be used by or in connection with an instruction execution system, apparatus, or device.

[0180] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including—but not limited to—electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of transmitting, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0181] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.

[0182] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as "C" or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0183] The foregoing has described specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0184] In the description of this application, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this application, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this application, as well as the features of different embodiments or examples.

[0185] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0186] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0187] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0188] It should be noted that the terminals involved in the embodiments of this application may include, but are not limited to, personal computers (PCs), personal digital assistants (PDAs), wireless handheld devices, tablet computers, mobile phones, MP3 players, MP4 players, etc.

[0189] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0190] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units.

[0191] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0192] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A transaction payment method, applied to a first electronic device used by the payee, wherein both the first electronic device and a second electronic device used by the payer are offline, characterized in that, The method includes: The system obtains a request from a user to register for digital RMB and open a personal sub-wallet; wherein, the user includes a user using the first electronic device; Send the request to the issuing server of the digital yuan; Receive the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair derived from the issuing server sent by the issuing server; The RMB digital certificate, the public key, the wallet identifier, the account identifier, and the first public-private key pair sent by the issuing server are stored in the trusted execution environment of the first electronic device; The account identifier, the wallet identifier, and the device identifier of the first electronic device are encrypted using a public key pre-agreed with a third-party authentication server, and the encrypted account identifier, the encrypted device identifier, and the encrypted wallet identifier are sent to the authentication server. The system receives and stores a third-party digital certificate and a second public-private key pair sent by the authentication server. The third-party digital certificate is generated by the authentication server using its own stored private key to decrypt the encrypted account identifier, the encrypted device identifier, and the encrypted wallet identifier. The system then verifies the decrypted account identifier, device identifier, and wallet identifier. Once the verification is successful, the system generates the second public-private key pair. The authentication server then uses its own stored private key to encrypt the public key and the digital certificate validity period in the second public-private key pair to obtain a digital signature. Finally, the system combines the public key, the digital certificate validity period, and the digital signature to form the third-party digital certificate, which is then sent to the first electronic device. Obtain the payment request made by the second electronic device using digital RMB; In response to the payment request, a digital RMB certificate is sent to the second electronic device for the second electronic device to verify the digital RMB certificate sent by the first electronic device, and the first electronic device receives the digital RMB certificate sent by the second electronic device; wherein, the digital RMB certificate comes from the digital RMB issuing server; Verify the digital certificate for RMB sent by the second electronic device; After confirming that the RMB digital certificate sent by the second electronic device has passed verification, the transaction information is signed using the private key stored in the first electronic device to obtain a first signature, and the transaction information and the first signature are sent to the second electronic device; wherein, the private key stored in the first electronic device is issued by a third-party authentication server; The system receives transaction information, a first signature, and a second signature sent by the second electronic device. The transaction information, the first signature, and the second signature are obtained by the second electronic device after receiving the transaction information and the first signature from the first electronic device. The second electronic device verifies the first signature, determines that the first signature passes verification, and then uses its private key to sign the transaction information sent by the first electronic device, obtaining the second signature, which is then sent to the first electronic device. The private key stored in the second electronic device is issued by the third-party authentication server. The second signature is verified, and the transaction information, the first signature, and the second signature are stored in the trusted execution environment of the first electronic device.

2. The method according to claim 1, characterized in that, After storing the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device, the method further includes: After the first electronic device is connected to the network, the transaction information, the first signature, and the second signature are uploaded to a third-party transaction server for the transaction server to verify the first signature and the second signature. After the first signature and the second signature pass the verification, the transaction information is uploaded to the digital RMB issuance server, and the transaction result corresponding to the transaction information is received from the issuance server. Receive the transaction result corresponding to the transaction information sent by the transaction server.

3. The method according to claim 1, characterized in that, The process of receiving and storing the third-party digital certificate and the second public-private key pair sent by the authentication server includes: Verify the signature of the third-party digital certificate sent by the authentication server; After the third-party digital certificate passes verification, a random number is generated. The account identifier, the wallet identifier, the device identifier of the first electronic device, and the random number are encrypted using a public key pre-agreed with the authentication server. The encrypted account identifier, encrypted device identifier, encrypted wallet identifier, and encrypted random number are sent to the authentication server; The authentication server receives an encrypted private key; wherein the encrypted private key is obtained by the authentication server using its own stored private key to decrypt the encrypted account identifier, the encrypted device identifier, the encrypted wallet identifier, and the encrypted random number, and after determining that the decrypted account identifier, device identifier, and wallet identifier have passed verification, the authentication server uses the decrypted random number to encrypt the private key in the second public-private key pair and then sends it to the first electronic device. The encrypted private key is decrypted using the random number. After confirming that the decryption and acquisition of the private key have passed verification, the third-party digital certificate sent by the authentication server and the second public-private key pair are saved.

4. The method according to any one of claims 1-3, characterized in that, The first electronic device and the second electronic device establish a connection via Bluetooth, and sending the RMB digital certificate to the second electronic device includes: The RMB digital certificate is sent to the second electronic device via Bluetooth connection; The receipt of the RMB digital certificate sent by the second electronic device includes: The digital certificate for RMB is received from the second electronic device via the Bluetooth connection.

5. A transaction payment device, installed in a first electronic device used by the payee, wherein both the first electronic device and a second electronic device used by the payer are offline, characterized in that, The device includes: The acquisition module is used to acquire requests from users to register for digital RMB and open personal sub-wallets; wherein, the users include users using the first electronic device; A sending module is used to send the request to the issuance server of the digital yuan; The receiving module is configured to receive the RMB digital certificate, public key, wallet identifier, account identifier, and a first public-private key pair derived from the issuing server sent by the issuing server; store the RMB digital certificate, public key, wallet identifier, account identifier, and the first public-private key pair sent by the issuing server in the trusted execution environment of the first electronic device; encrypt the account identifier, wallet identifier, and device identifier of the first electronic device using a public key pre-agreed with the third-party authentication server, and send the encrypted account identifier, encrypted device identifier, and encrypted wallet identifier to the authentication server; and receive and save the third-party digital certificate and public key pair sent by the authentication server. The second public-private key pair; wherein, the third-party digital certificate is generated by the authentication server using its own stored private key to decrypt the encrypted account identifier, the encrypted device identifier, and the encrypted wallet identifier, verifying the decrypted account identifier, device identifier, and wallet identifier, and after confirming that the decrypted account identifier, device identifier, and wallet identifier have passed verification, generating the second public-private key pair, encrypting the public key and digital certificate validity period in the second public-private key pair using the authentication server's own stored private key to obtain a digital signature, and then sending the third-party digital certificate composed of the public key, digital certificate validity period, and digital signature in the second public-private key pair to the first electronic device; The acquisition module is also used to acquire payment requests made by the second electronic device using digital RMB; The sending module is also configured to, in response to the payment request, send a digital RMB certificate to the second electronic device so that the second electronic device can verify the digital RMB certificate sent by the first electronic device; The receiving module is also used to receive a digital RMB certificate sent by the second electronic device; wherein the digital RMB certificate comes from the digital RMB issuing server; The verification module is used to verify the RMB digital certificate sent by the second electronic device; The signature module is used to sign the transaction information using the private key stored in the first electronic device after the verification module determines that the RMB digital certificate sent by the second electronic device has passed the verification, thereby obtaining a first signature. The sending module is further configured to send the transaction information and the first signature to the second electronic device; wherein the private key stored in the first electronic device is issued by a third-party authentication server; The receiving module is further configured to receive transaction information, a first signature, and a second signature sent by the second electronic device; wherein, the transaction information, the first signature, and the second signature are obtained by the second electronic device after receiving the transaction information and the first signature sent by the first electronic device, verifying the first signature, and after determining that the first signature passes the verification, signing the transaction information sent by the first electronic device using the private key stored in the second electronic device to obtain the second signature, and then sending it to the first electronic device; wherein, the private key stored in the second electronic device is issued by the third-party authentication server; The verification module is also used to verify the second signature; A storage module is used to store the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device.

6. The apparatus according to claim 5, characterized in that, The sending module is further configured to, after the storage module stores the transaction information, the first signature, and the second signature in the trusted execution environment of the first electronic device, and after the first electronic device is connected to the network, upload the transaction information, the first signature, and the second signature to a third-party transaction server so that the transaction server can verify the first signature and the second signature. After the first signature and the second signature pass the verification, the module uploads the transaction information to the digital RMB issuance server and receives the transaction result corresponding to the transaction information sent by the issuance server. The receiving module is also used to receive the transaction result corresponding to the transaction information sent by the transaction server.

7. An electronic device, characterized in that, include: At least one processor; as well as At least one memory communicatively connected to the processor, wherein: The memory stores program instructions that can be executed by the processor, and the processor can execute the method as described in any one of claims 1 to 4 by calling the program instructions.

8. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions that cause the computer to perform the method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Offline payment system and method based on block chain

    CN110458542A

  • Digital wallet supporting anonymous or real-name offline transaction and use method

    CN110766383A

  • Public key password centralized service method based on fingerprint identification

    CN111447214A

  • Digital currency double-offline payment method and payment system

    CN111899007A